{"data":{"id":"CP-09","name":"System Backup","family":"CP","family_name":"Contingency Planning","withdrawn":false,"description":"a. Conduct backups of user-level information contained in [Assignment: organization-defined system components] [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];\nb. Conduct backups of system-level information contained in the system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];\nc. Conduct backups of system documentation, including security- and privacy-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; and\nd. Protect the confidentiality, integrity, and availability of backup information.","supplemental_guidance":"System-level information includes system state information, operating system software, middleware, application software, and licenses. User-level information includes information other than system-level information. Mechanisms employed to protect the integrity of system backups include digital signatures and cryptographic hashes. Protection of system backup information while in transit is addressed by MP-05 and SC-08. System backups reflect the requirements in contingency plans as well as other organizational requirements for backing up information. Organizations may be subject to laws, executive orders, directives, regulations, or policies with requirements regarding specific categories of information (e.g., personal health information). Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.","enhancements":[{"id":"CP-09(01)","name":"Testing for Reliability and Integrity","statement":"Test backup information [Assignment: organization-defined frequency] to verify media reliability and information integrity.","baselines":["moderate","high"]},{"id":"CP-09(02)","name":"Test Restoration Using Sampling","statement":"Use a sample of backup information in the restoration of selected system functions as part of contingency plan testing.","baselines":["high"]},{"id":"CP-09(03)","name":"Separate Storage for Critical Information","statement":"Store backup copies of [Assignment: organization-defined critical system software and other security-related information] in a separate facility or in a fire rated container that is not collocated with the operational system.","baselines":["high"]},{"id":"CP-09(04)","name":"Protection from Unauthorized Modification","withdrawn":true,"incorporated_into":["CP-09"]},{"id":"CP-09(05)","name":"Transfer to Alternate Storage Site","statement":"Transfer system backup information to the alternate storage site [Assignment: organization-defined time period and transfer rate consistent with the recovery time and recovery point objectives].","baselines":["high"]},{"id":"CP-09(06)","name":"Redundant Secondary System","statement":"Conduct system backup by maintaining a redundant secondary system that is not collocated with the primary system and that can be activated without loss of information or disruption to operations.","baselines":[]},{"id":"CP-09(07)","name":"Dual Authorization for Deletion or Destruction","statement":"Enforce dual authorization for the deletion or destruction of [Assignment: organization-defined backup information].","baselines":[]},{"id":"CP-09(08)","name":"Cryptographic Protection","statement":"Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup information].","baselines":["moderate","high"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"CP-09","name":"System Backup","description":"a. Conduct backups of user-level information contained in [Assignment: organization-defined system components] [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];\nb. Conduct backups of system-level information contained in the system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];\nc. Conduct backups of system documentation, including security- and privacy-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; and\nd. Protect the confidentiality, integrity, and availability of backup information.","discussion":"System-level information includes system state information, operating system software, middleware, application software, and licenses. User-level information includes information other than system-level information. Mechanisms employed to protect the integrity of system backups include digital signatures and cryptographic hashes. Protection of system backup information while in transit is addressed by MP-05 and SC-08. System backups reflect the requirements in contingency plans as well as other organizational requirements for backing up information. Organizations may be subject to laws, executive orders, directives, regulations, or policies with requirements regarding specific categories of information (e.g., personal health information). Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.","related_controls":["CP-02","CP-06","CP-10","MP-04","MP-05","SC-08","SC-12","SC-13","SI-04","SI-13"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Information System Backup' Parameter added for conducting backups of user-level information contained in specific system components Removes restrictive control text ‘at storage locations’ Discussion expanded"}},"compliance_mappings":{"iso_27001_2022":["A.5.29","A.5.30","A.5.33","A.8.13"],"iso_27002_2022":["5.29","5.30","8.13"],"cobit_2019":["DSS04"],"pci_dss_v4":[],"nist_csf_2":["PR.DS-01","PR.DS-10","PR.DS-11","PR.IR-03","RC.RP-03"],"cis_controls_v8":["CIS 11","CIS 11.1","CIS 11.2","CIS 11.3","CIS 11.4","CIS 11.5"],"soc2_tsc":["A1.2","CC7.5"],"finos_ccc":["CCC-C13"],"iso_42001_2023":["A.4.3"],"iec_62443":["3-3 SR 7.3"],"asd_e8":["E8-8","E8-8 ML1","E8-8 ML2","E8-8 ML3"],"nis2":["Art. 21(2)(c)"],"apra_cps_234":[],"mas_trm":["8"],"pra_op_resilience":[],"bsi_grundschutz":["CON.3","DER.4"],"anssi":["Hygiene.30","SecNumCloud.13.5"],"osfi_b13":["B-13.2.6"],"finma_circular":["IV.D(82)","IV.E(89)","IV.E(90)","IV.E(91)"],"gdpr":["Art.32(1)(c)"],"dora":["Art.12(1)","Art.12(2)","Art.12(3)","Art.12(5)"],"bio2":["5.29","5.30","8.13"],"rbi_csf":["ITGRCA.29"],"fisc":["FISC.O5"],"lgpd_bcb":["BCB.Art.3"],"hkma_tme1":["TME1.6.5"],"mlps_2":["8.1.4.9","8.1.10.9","8.2"],"dnb_good_practice":["DNB.11.3","DNB.11.4"],"cra":["CRA.I.2h"],"swift_cscf":["SWIFT.6.3"],"cbb_tm":["TM-14"],"cbuae":["CR-13"],"nca_ecc":["2-9","3-1","3-2"],"qatar_nia":["BC","OS"],"uae_ia":["T7","T12"],"bog_cisd":["CISD-BCM"],"bom_ctrm":["5.2"],"cbe_csf":["OVM-2"],"cbn_csf":["Part3.6","Part3.7"],"popia":["s19"],"sa_js2":["JS2-7.5"],"bot_cyber":["Ch4.2"],"cpmi_pfmi":["CG.RR","PFMI.P17"],"eba_ict":["3.7.2"],"ecb_croe":["CROE.2.5.2"],"hipaa_sr":["§164.308(a)(7)(i)","§164.308(a)(7)(ii)(A)","§164.310(d)(2)(iv)"],"iosco_cyber":["PFMI-17","RR-2","RR-3","TEST-5"],"nydfs_500":["500.16"],"sebi_cscrf":["BCP-DR","RC.RP"],"cmmc_2":["MP"],"nerc_cip":["CIP-009-6"],"nrc_73_54":["RG5.71-B-CP"],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":["RESPONSE"],"api_1164":["Sec 11"],"awia":[],"iaea_nss":["Sec 8"],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.8.1","SYSC 13.8.2"],"fda_21_cfr_11":["§11.10(b)","§11.10(c)"],"fda_cyber":["SA-6"],"hitrust_csf":["09.d","12.b"],"iso_27799":["12.3","17.2"],"lloyds_ms":["MS8.6"],"naic_ds":["4F-b"],"nhs_dspt":["NDG-7.2","NDG-7.3"],"pra_ss1_23":["P-IT.3"],"solvency_ii":["DR.266-BCP","EIOPA-ICT-4.10"],"owasp_masvs_v2":[],"csa_ccm_v4":["BCR-08","CCC-09","CEK-18","CEK-20"],"csa_aicm":["BCR-08","CCC-09","CEK-18","CEK-20"],"ccss_v9":["1.03.2","1.03.3","1.03.4","1.03.7"],"mica":["Art.47(1)","Art.62(5)","Art.62(6)","Art.68(5)"],"basel_sco60":["SCO60.21","SCO60.23","SCO60.53","SCO60.63","SCO60.65"],"bssc":["GSP-06","KMS-10","NOS-07"],"sec_custody_digital":["SEC-CD-06","SEC-CD-12"],"dpdpa":["Act.8(5)","Rules.6(1)(d)","Rules.Sch1.B.7"]},"attack_techniques":[{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Regular system-level backups that include Active Directory and credential store snapshots enable restoration of known-good authentication databases after credential dumping incidents, limiting the window during which harvested credentials remain valid."},{"id":"T1005","name":"Data from Local System","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Comprehensive backup procedures ensure that data collected or exfiltrated from local systems can be restored from known-good copies, reducing the long-term impact of data theft and enabling forensic comparison against baseline states."},{"id":"T1025","name":"Data from Removable Media","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Backing up data from removable media repositories to protected storage ensures that information stolen from portable devices can be recovered, and backup integrity checks can reveal unauthorized modifications to media contents."},{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Protected backups of system logs and audit trails preserve forensic evidence even when adversaries attempt indicator removal, enabling investigators to reconstruct attack timelines from backup copies of deleted or tampered log data."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Regular backups provide baseline data states that enable detection of automated collection activities by comparing current data volumes and access patterns against known-good backup snapshots, revealing bulk data staging anomalies."},{"id":"T1485","name":"Data Destruction","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Immutable, regularly tested backups directly counter data destruction attacks by providing recoverable copies of all critical information, enabling rapid restoration of destroyed data and minimising operational disruption from destructive malware."},{"id":"T1486","name":"Data Encrypted for Impact","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Protected offline or immutable backups are the primary countermeasure against ransomware encryption, enabling organisations to restore encrypted data without paying ransoms, provided backups are isolated from the production environment and tested regularly."},{"id":"T1490","name":"Inhibit System Recovery","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Backup procedures that store copies in isolated, protected locations directly counter attempts to inhibit system recovery by ensuring that even if adversaries delete shadow copies, disable recovery partitions, or corrupt system restore points, restorable copies remain available."},{"id":"T1491","name":"Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"System and application backups enable rapid restoration of defaced websites and internal systems to their legitimate state, minimising the reputational and operational impact of both internal and external defacement attacks."},{"id":"T1561","name":"Disk Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Regular backups stored on isolated media or immutable cloud storage provide the recovery capability needed to restore systems after disk wipe attacks, enabling full reconstruction of wiped endpoints from known-good images."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Backup integrity verification enables detection of data manipulation by comparing current data states against historical backup copies, and regular backups ensure that manipulated data can be restored to its authentic pre-tampering state."},{"id":"T1003.003","name":"NTDS","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Backing up the NTDS.dit database to secure, access-controlled storage enables restoration of the Active Directory credential store to a known-good state after a compromise, while also providing forensic comparison to identify injected or modified accounts."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Protected backups of Windows event logs preserve forensic evidence even when adversaries clear event logs to cover their tracks, enabling security teams to reconstruct attack activities from backup copies of the deleted audit records."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Backing up Linux and macOS system logs to isolated, protected storage ensures that adversary attempts to clear local log files do not eliminate all forensic evidence, preserving audit trails for incident investigation."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Regular mailbox backups preserve email data that adversaries attempt to delete to cover their tracks, enabling recovery of purged messages and forensic analysis of email-based attack vectors even after mailbox data clearing."},{"id":"T1485.001","name":"Lifecycle-Triggered Deletion","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Protected backups counter lifecycle-triggered deletion by preserving data copies independent of the application lifecycle policies that adversaries manipulate, ensuring that data scheduled for malicious deletion can be recovered from backup repositories."},{"id":"T1491.001","name":"Internal Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Backups of internal-facing web applications and portals enable rapid restoration after internal defacement, returning compromised dashboards and intranet sites to their legitimate state and preserving evidence of the original modification."},{"id":"T1491.002","name":"External Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Regular backups of external-facing website content and configurations enable swift recovery from external defacement attacks, minimising public-facing reputational damage by restoring legitimate content from verified backup copies."},{"id":"T1561.001","name":"Disk Content Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Isolated backups provide the recovery capability to restore full disk contents after adversaries perform content-level disk wipes, enabling reconstruction of user data, applications, and configurations from protected backup repositories."},{"id":"T1561.002","name":"Disk Structure Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Backups of system images and disk structure metadata enable recovery from disk structure wipe attacks that destroy partition tables and file system headers, allowing full system reconstruction even after low-level destructive operations."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Regular backups of critical data stores create authoritative reference points that enable detection and reversal of stored data manipulation, as comparison between current data and backup copies reveals unauthorized modifications."},{"id":"T1565.003","name":"Runtime Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"System state backups that capture application configurations and runtime parameters enable restoration to known-good states after runtime data manipulation, and provide forensic baselines for detecting in-memory or in-process data alterations."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.5.33 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 PR.DS-01, PR.DS-10 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"corrective","used_by_patterns":["SP-001","SP-002","SP-008","SP-013","SP-019","SP-021","SP-023","SP-031","SP-034","SP-039","SP-051","SP-053","SP-054"]}}