# CP-10 System Recovery and Reconstitution

NIST SP 800-53 control. Family: CP Contingency Planning. Function: corrective. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Provide for the recovery and reconstitution of the system to a known state within [Assignment: organization-defined time period consistent with recovery time and recovery point objectives] after a disruption, compromise, or failure.
Guidance: Recovery is executing contingency plan activities to restore organizational mission and business functions. Reconstitution takes place following recovery and includes activities for returning systems to fully operational states. Recovery and reconstitution operations reflect mission and business priorities; recovery point, recovery time, and reconstitution objectives; and organizational metrics consistent with contingency plan requirements. Reconstitution includes the deactivation of interim system capabilities that may have been needed during recovery operations. Reconstitution also includes assessments of fully restored system capabilities, reestablishment of continuous monitoring activities, system reauthorization (if required), and activities to prepare the system and organization for future disruptions, breaches, compromises, or failures. Recovery and reconstitution capabilities can include automated mechanisms and manual procedures. Organizations establish recovery time and recovery point objectives as part of contingency planning.

## Enhancements (3)
- CP-10(02) Transaction Recovery. Baselines: moderate, high
- CP-10(04) Restore Within Time Period. Baselines: high
- CP-10(06) Component Protection
Withdrawn by NIST: CP-10(01) (now in CP-04); CP-10(03); CP-10(05) (now in SI-13).
Each enhancement's statement: /api/v1/controls/CP-10?fields=enhancements

## Patterns that use it (9)
- Critical (1): SP-034 Cyber Resilience
- Important (6): SP-002 Server Module; SP-008 Public Web Server Pattern; SP-023 Industrial Control Systems; SP-031 Security Monitoring and Response; SP-036 Incident Response; SP-054 CBDC and Digital Currency Infrastructure (draft)
- Standard (2): SP-001 Client Module; SP-025 Advanced Monitoring and Detection

## Clauses by framework (71 frameworks)
- iso_27001_2022: A.5.29, A.5.30. OSA's own, not in NIST's crosswalk: A.5.30
- iso_27002_2022: 5.29, 5.30
- cobit_2019: DSS04
- nist_csf_2: PR.IR-03, RC.RP-01, RC.RP-02, RC.RP-04, RC.RP-05, RS.MA-05. OSA's own, not in NIST's crosswalk: PR.IR-03, RC.RP-04, RS.MA-05
- cis_controls_v8: CIS 11
- soc2_tsc: A1.2, A1.2-POF1, A1.2-POF2, A1.2-POF3, CC7.4-POF5, CC7.5, CC9.1, CC9.1-POF1
- finos_ccc: CCC-C13
- iso_42001_2023: A.4.5
- iec_62443: 3-3 SR 7.3, 3-3 SR 7.4
- asd_e8: E8-8
- nis2: Art. 21(2)(c)
- mas_trm: 8
- bsi_grundschutz: DER.4
- anssi: Hygiene.30, Hygiene.35, SecNumCloud.18.3
- osfi_b13: B-13.2.6, B-13.3.4
- finma_circular: IV.C(70), IV.D(71), IV.D(72), IV.E(89), IV.E(90)
- gdpr: Art.32(1)(c), Art.32(1)(d)
- dora: Art.11(1), Art.11(2), Art.11(4)
- bio2: 5.29, 5.30
- rbi_csf: Annex1.19, ITGRCA.29
- fisc: FISC.O5
- lgpd_bcb: BCB.Art.3
- hkma_tme1: TME1.6.2, TME1.6.5
- mlps_2: 8.1.4.9, 8.1.10.9
- dnb_good_practice: DNB.11.1, DNB.11.4
- cra: CRA.I.2h
- cbb_tm: TM-14
- cbuae: CR-13
- nca_ecc: 2-9, 3-1, 3-2
- qatar_nia: BC, OS
- uae_ia: T12
- bog_cisd: CISD-BCM
- bom_ctrm: 5.2
- cbe_csf: OVM-2
- cbn_csf: Part3.6, Part3.7
- popia: s19
- sa_js2: JS2-7.5
- bcbs_239: Principle 5
- bot_cyber: Ch4.2
- cpmi_pfmi: CG.RR, PFMI.P17
- eba_ict: 3.7.2, 3.7.3
- ecb_croe: CROE.2.5.2
- ffiec_is: III.D
- hipaa_sr: §164.308(a)(7)(i), §164.308(a)(7)(ii)(B), §164.308(a)(7)(ii)(C), §164.312(a)(2)(ii)
- iosco_cyber: PFMI-17, RR-2, RR-3
- nydfs_500: 500.16
- sebi_cscrf: BCP-DR, RC.RP
- nerc_cip: CIP-009-6
- nrc_73_54: RG5.71-B-CP
- doe_c2m2: RESPONSE
- api_1164: Sec 11
- iaea_nss: Sec 8
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.8.1, SYSC 13.8.2
- fda_21_cfr_11: §11.10(c)
- fda_cyber: SA-6
- hitrust_csf: 09.d, 12.b
- iso_27799: 9.2, 17.2
- lloyds_ms: CRM.3, MS8.6
- naic_ds: 4F-b
- nhs_dspt: NDG-7.2
- pra_ss1_23: P-IT.3
- solvency_ii: DR.266-BCP, EIOPA-ICT-4.10
- csa_ccm_v4: BCR-09, CCC-09
- csa_aicm: BCR-09, CCC-09
- ccss_v9: 1.03.2
- mica: Art.62(6), Art.68(5)
- basel_sco60: SCO60.21, SCO60.23, SCO60.53, SCO60.63
- bssc: GSP-06, KMS-10, NOS-07
- sec_custody_digital: SEC-CD-12
- dpdpa: Rules.6(1)(d)
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CP-10
- Clauses only: /api/v1/controls/CP-10?fields=mappings
- Page for people: /controls/cp-10/
