Skip to main content

💼 CP-9 INFORMATION SYSTEM BACKUP

  • ID: /frameworks/nist-sp-800-53-r4/cp/09

Description

The organization: CP-9a. Conducts backups of user-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; CP-9b. Conducts backups of system-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; CP-9c. Conducts backups of information system documentation including security-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; and CP-9d. Protects the confidentiality, integrity, and availability of backup information at storage locations.

Similar

  • Internal
    • ID: dec-c-57dbd0fd

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v1.1 → 💼 PR.IP-4: Backups of information are conducted, maintained, and tested48no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CP-9 (1) TESTING FOR RELIABILITY _ INTEGRITYno data
💼 CP-9 (2) TEST RESTORATION USING SAMPLINGno data
💼 CP-9 (3) SEPARATE STORAGE FOR CRITICAL INFORMATIONno data
💼 CP-9 (4) PROTECTION FROM UNAUTHORIZED MODIFICATIONno data
💼 CP-9 (5) TRANSFER TO ALTERNATE STORAGE SITEno data
💼 CP-9 (6) REDUNDANT SECONDARY SYSTEMno data
💼 CP-9 (7) DUAL AUTHORIZATIONno data

Policies (1)

PolicyLogic CountFlagsCompliance
🛡️ Google Cloud SQL Instance Automated Backups are not configured🟢1🟢 x6no data