Skip to main content

💼 CP-9 System Backup

  • ID: /frameworks/nist-sp-800-53-r5/cp/09

Description

a. Conduct backups of user-level information contained in [Assignment: organization-defined system components] [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; b. Conduct backups of system-level information contained in the system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; c. Conduct backups of system documentation, including security- and privacy-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; and
d. Protect the confidentiality, integrity, and availability of backup information.

Similar

  • Sections
    • /frameworks/aws-fsbp-v1.0.0/dynamodb/02
    • /frameworks/aws-fsbp-v1.0.0/efs/02
    • /frameworks/aws-fsbp-v1.0.0/elasticache/01
    • /frameworks/aws-fsbp-v1.0.0/fsx/02
    • /frameworks/aws-fsbp-v1.0.0/rds/11
    • /frameworks/aws-fsbp-v1.0.0/rds/14
    • /frameworks/aws-fsbp-v1.0.0/redshift/03
    • /frameworks/aws-fsbp-v1.0.0/redshift/06
    • /frameworks/aws-fsbp-v1.0.0/s3/13
  • Internal
    • ID: dec-c-e8e4c9c8

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [DynamoDB.2] DynamoDB tables should have point-in-time recovery enabled11no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [EFS.2] Amazon EFS volumes should be in backup plansno data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [ElastiCache.1] ElastiCache (Valkey and Redis OSS) clusters should have automatic backups enabled1no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [FSx.2] FSx for Lustre file systems should be configured to copy tags to backupsno data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [RDS.11] RDS instances should have automatic backups enabled1no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [RDS.14] Amazon Aurora clusters should have backtracking enabledno data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [Redshift.3] Amazon Redshift clusters should have automatic snapshots enabledno data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [Redshift.6] Amazon Redshift should have automatic upgrades to major versions enabledno data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [S3.13] S3 general purpose buckets should have Lifecycle configurations11no data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 FedRAMP High Security Controls → 💼 CP-9 System Backup (L)(M)(H)5410no data
💼 FedRAMP Low Security Controls → 💼 CP-9 System Backup (L)(M)(H)9no data
💼 NIST CSF v2.0 → 💼 PR.DS-01: The confidentiality, integrity, and availability of data-at-rest are protected148no data
💼 NIST CSF v2.0 → 💼 PR.DS-10: The confidentiality, integrity, and availability of data-in-use are protected142no data
💼 NIST CSF v2.0 → 💼 PR.DS-11: Backups of data are created, protected, maintained, and tested12no data
💼 NIST CSF v2.0 → 💼 RC.RP-03: The integrity of backups and other restoration assets is verified before using them for restoration6no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CP-9(1) System Backup _ Testing for Reliability and Integrityno data
💼 CP-9(2) System Backup _ Test Restoration Using Samplingno data
💼 CP-9(3) System Backup _ Separate Storage for Critical Informationno data
💼 CP-9(4) System Backup _ Protection from Unauthorized Modificationno data
💼 CP-9(5) System Backup _ Transfer to Alternate Storage Siteno data
💼 CP-9(6) System Backup _ Redundant Secondary Systemno data
💼 CP-9(7) System Backup _ Dual Authorization for Deletion or Destructionno data
💼 CP-9(8) System Backup _ Cryptographic Protection1no data

Policies (6)

PolicyLogic CountFlagsCompliance
🛡️ AWS DynamoDB Table Point In Time Recovery is not enabled🟢1🟢 x6no data
🛡️ AWS ElastiCache Redis Cluster automatic backups are not enabled🟢1🟢 x6no data
🛡️ AWS RDS Instance automated backups are not enabled🟢1🟢 x6no data
🛡️ AWS S3 Bucket Lifecycle Configuration is not enabled🟢1🟢 x6no data
🛡️ AWS S3 Bucket Versioning is not enabled🟢1🟢 x6no data
🛡️ Google Cloud SQL Instance Automated Backups are not configured🟢1🟢 x6no data