PlumbTrackLive demoGRC Risk System

← internal audit

Audit — CP-10 — System Recovery and Reconstitution

Framework: NIST SP 800-53 Rev.5 CP-10 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the contingency plan / disaster recovery plan to confirm it documents recovery and reconstitution procedures that restore the system to a known and secure state after a disruption, compromise, or failure, consistent with the defined RTO and RPO.
Examine Examine the results and timestamps of the most recent recovery or failover test to verify the system was recovered within the organization-defined recovery time period (CP-10(4), Restore Within Time Period).
Test Test or observe a recovery exercise (component restore or failover to the alternate processing site) to verify the system returns to a known, operational, and secure state and that dependencies are re-established in the documented order.
Examine Examine post-recovery validation records to confirm that after reconstitution the system is rebuilt to the approved hardened baseline, security patches and configurations are reapplied, and controls are verified before the system is returned to production.
Examine Examine transaction logging, journaling, or checkpoint configuration for transaction-based systems to verify roll-forward/rollback capability supports transaction recovery without data loss (CP-10(2), Transaction Recovery).
Interview Interview system administrators and designated recovery personnel to confirm they understand their assigned roles and the documented reconstitution steps, and can perform them without reliance on undocumented knowledge.
Examine Examine after-action reports and change records from recovery tests or actual events to confirm lessons learned are captured and drive updates to the recovery and reconstitution procedures.