RC · RECOVER

Wiederherstellen

Von einem Vorfall betroffene Assets und Geschäftsabläufe werden rechtzeitig wiederhergestellt, um die Auswirkungen zu verringern.

2 Kategorien · 8 Ergebnisziele

RC.RP

Ausführung des Wiederherstellungsplans (Incident Recovery Plan Execution)

Wiederherstellungsmaßnahmen werden durchgeführt, um die Verfügbarkeit betroffener Systeme und Dienste sicherzustellen.

RC.RP-01

Der Wiederherstellungsteil des Vorfallreaktionsplans wird nach Auslösung ausgeführt.

Eigenrisiko

NIST-Originalwortlaut: The recovery portion of the incident response plan is executed once initiated from the incident response process

Umsetzungsbeispiele (2)
  • Begin recovery procedures during or after incident response processes
  • Make all individuals with recovery responsibilities aware of the plans for recovery and the authorizations required to implement each aspect of the plans
RC.RP-02

Wiederherstellungsmaßnahmen werden ausgewählt, abgegrenzt, priorisiert und durchgeführt.

Eigenrisiko

NIST-Originalwortlaut: Recovery actions are selected, scoped, prioritized, and performed

Umsetzungsbeispiele (2)
  • Select recovery actions based on the criteria defined in the incident response plan and available resources
  • Change planned recovery actions based on a reassessment of organizational needs and resources
RC.RP-03

Die Integrität von Sicherungen und anderen Wiederherstellungs-Assets wird vor ihrer Nutzung verifiziert.

Eigenrisiko

NIST-Originalwortlaut: The integrity of backups and other restoration assets is verified before using them for restoration

Umsetzungsbeispiele (1)
  • Check restoration assets for indicators of compromise, file corruption, and other integrity issues before use
RC.RP-04

Kritische Missionsfunktionen und Risikomanagement werden berücksichtigt, um Betriebsnormen nach dem Vorfall festzulegen.

Eigenrisiko

NIST-Originalwortlaut: Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms

Umsetzungsbeispiele (3)
  • Use business impact and system categorization records (including service delivery objectives) to validate that essential services are restored in the appropriate order
  • Work with system owners to confirm the successful restoration of systems and the return to normal operations
  • Monitor the performance of restored systems to verify the adequacy of the restoration
RC.RP-05

Die Integrität wiederhergestellter Assets wird verifiziert; Systeme und Dienste werden wiederhergestellt und der Normalbetrieb bestätigt.

Eigenrisiko

NIST-Originalwortlaut: The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed

Umsetzungsbeispiele (2)
  • Check restored assets for indicators of compromise and remediation of root causes of the incident before production use
  • Verify the correctness and adequacy of the restoration actions taken before putting a restored system online
RC.RP-06

Das Ende der Wiederherstellung wird anhand von Kriterien deklariert und die vorfallbezogene Dokumentation abgeschlossen.

Eigenrisiko

NIST-Originalwortlaut: The end of incident recovery is declared based on criteria, and incident-related documentation is completed

Umsetzungsbeispiele (2)
  • Prepare an after-action report that documents the incident itself, the response and recovery actions taken, and lessons learned
  • Declare the end of incident recovery once the criteria are met
RC.CO

Kommunikation zur Wiederherstellung (Incident Recovery Communication)

Wiederherstellungsaktivitäten werden mit internen und externen Parteien abgestimmt.

RC.CO-04

Öffentliche Updates zur Wiederherstellung werden über genehmigte Methoden und Botschaften geteilt.

Eigenrisiko

NIST-Originalwortlaut: Public updates on incident recovery are shared using approved methods and messaging

Umsetzungsbeispiele (2)
  • Follow the organization's breach notification procedures for recovering from a data breach incident
  • Explain the steps being taken to recover from the incident and to prevent a recurrence
RC.CO-03

Wiederherstellungsaktivitäten und Fortschritte werden an benannte interne und externe Stakeholder kommuniziert.

EigenrisikoDrittrisiko

NIST-Originalwortlaut: Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders

Umsetzungsbeispiele (4)
  • Securely share recovery information, including restoration progress, consistent with response plans and information sharing agreements
  • Regularly update senior leadership on recovery status and restoration progress for major incidents
  • Follow the rules and protocols defined in contracts for incident information sharing between the organization and its suppliers
  • Coordinate crisis communication between the organization and its critical suppliers