# CP-09 System Backup

NIST SP 800-53 control. Family: CP Contingency Planning. Function: corrective. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Conduct backups of user-level information contained in [Assignment: organization-defined system components] [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; b. Conduct backups of system-level information contained in the system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; c. Conduct backups of system documentation, including security- and privacy-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; and d. Protect the confidentiality, integrity, and availability of backup information.
Guidance: System-level information includes system state information, operating system software, middleware, application software, and licenses. User-level information includes information other than system-level information. Mechanisms employed to protect the integrity of system backups include digital signatures and cryptographic hashes. Protection of system backup information while in transit is addressed by MP-05 and SC-08. System backups reflect the requirements in contingency plans as well as other organizational requirements for backing up information. Organizations may be subject to laws, executive orders, directives, regulations, or policies with requirements regarding specific categories of information (e.g., personal health information). Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.

## Enhancements (7)
- CP-09(01) Testing for Reliability and Integrity. Baselines: moderate, high
- CP-09(02) Test Restoration Using Sampling. Baselines: high
- CP-09(03) Separate Storage for Critical Information. Baselines: high
- CP-09(05) Transfer to Alternate Storage Site. Baselines: high
- CP-09(06) Redundant Secondary System
- CP-09(07) Dual Authorization for Deletion or Destruction
- CP-09(08) Cryptographic Protection. Baselines: moderate, high
Withdrawn by NIST: CP-09(04) (now in CP-09).
Each enhancement's statement: /api/v1/controls/CP-09?fields=enhancements

## Patterns that use it (13)
- Critical (2): SP-034 Cyber Resilience; SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (7): SP-001 Client Module; SP-002 Server Module; SP-008 Public Web Server Pattern; SP-023 Industrial Control Systems; SP-031 Security Monitoring and Response; SP-039 Client-Side Encryption and Data Privacy; SP-051 Tokenised Asset Security Architecture (draft)
- Standard (4): SP-013 Data Security Pattern; SP-019 Secure Ad-Hoc File Exchange Pattern; SP-021 Realtime Collaboration Pattern; SP-053 Zero-Knowledge Proof Architecture (draft)

## Clauses by framework (71 frameworks)
- iso_27001_2022: A.5.29, A.5.30, A.5.33, A.8.13. OSA's own, not in NIST's crosswalk: A.5.30
- iso_27002_2022: 5.29, 5.30, 8.13
- cobit_2019: DSS04
- nist_csf_2: PR.DS-01, PR.DS-10, PR.DS-11, PR.IR-03, RC.RP-03. OSA's own, not in NIST's crosswalk: PR.IR-03
- cis_controls_v8: CIS 11, CIS 11.1, CIS 11.2, CIS 11.3, CIS 11.4, CIS 11.5
- soc2_tsc: A1.2, CC7.5
- finos_ccc: CCC-C13
- iso_42001_2023: A.4.3
- iec_62443: 3-3 SR 7.3
- asd_e8: E8-8, E8-8 ML1, E8-8 ML2, E8-8 ML3
- nis2: Art. 21(2)(c)
- mas_trm: 8
- bsi_grundschutz: CON.3, DER.4
- anssi: Hygiene.30, SecNumCloud.13.5
- osfi_b13: B-13.2.6
- finma_circular: IV.D(82), IV.E(89), IV.E(90), IV.E(91)
- gdpr: Art.32(1)(c)
- dora: Art.12(1), Art.12(2), Art.12(3), Art.12(5)
- bio2: 5.29, 5.30, 8.13
- rbi_csf: ITGRCA.29
- fisc: FISC.O5
- lgpd_bcb: BCB.Art.3
- hkma_tme1: TME1.6.5
- mlps_2: 8.1.4.9, 8.1.10.9, 8.2
- dnb_good_practice: DNB.11.3, DNB.11.4
- cra: CRA.I.2h
- swift_cscf: SWIFT.6.3
- cbb_tm: TM-14
- cbuae: CR-13
- nca_ecc: 2-9, 3-1, 3-2
- qatar_nia: BC, OS
- uae_ia: T7, T12
- bog_cisd: CISD-BCM
- bom_ctrm: 5.2
- cbe_csf: OVM-2
- cbn_csf: Part3.6, Part3.7
- popia: s19
- sa_js2: JS2-7.5
- bot_cyber: Ch4.2
- cpmi_pfmi: CG.RR, PFMI.P17
- eba_ict: 3.7.2
- ecb_croe: CROE.2.5.2
- hipaa_sr: §164.308(a)(7)(i), §164.308(a)(7)(ii)(A), §164.310(d)(2)(iv)
- iosco_cyber: PFMI-17, RR-2, RR-3, TEST-5
- nydfs_500: 500.16
- sebi_cscrf: BCP-DR, RC.RP
- cmmc_2: MP
- nerc_cip: CIP-009-6
- nrc_73_54: RG5.71-B-CP
- doe_c2m2: RESPONSE
- api_1164: Sec 11
- iaea_nss: Sec 8
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.8.1, SYSC 13.8.2
- fda_21_cfr_11: §11.10(b), §11.10(c)
- fda_cyber: SA-6
- hitrust_csf: 09.d, 12.b
- iso_27799: 12.3, 17.2
- lloyds_ms: MS8.6
- naic_ds: 4F-b
- nhs_dspt: NDG-7.2, NDG-7.3
- pra_ss1_23: P-IT.3
- solvency_ii: DR.266-BCP, EIOPA-ICT-4.10
- csa_ccm_v4: BCR-08, CCC-09, CEK-18, CEK-20
- csa_aicm: BCR-08, CCC-09, CEK-18, CEK-20
- ccss_v9: 1.03.2, 1.03.3, 1.03.4, 1.03.7
- mica: Art.47(1), Art.62(5), Art.62(6), Art.68(5)
- basel_sco60: SCO60.21, SCO60.23, SCO60.53, SCO60.63, SCO60.65
- bssc: GSP-06, KMS-10, NOS-07
- sec_custody_digital: SEC-CD-06, SEC-CD-12
- dpdpa: Act.8(5), Rules.6(1)(d), Rules.Sch1.B.7
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CP-09
- Clauses only: /api/v1/controls/CP-09?fields=mappings
- Page for people: /controls/cp-09/
