unified
UC-IR-09 — Recover from incidents using defined initiation criteria
Define objective criteria for initiating incident recovery — such as confirmed eradication, completed forensic preservation, and management authorization — and apply them before restoration begins. Identify, develop, and execute recovery activities that restore affected systems, data, and services to a known-good state, verifying integrity before return to production and confirming with business owners that normal operations have resumed.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Incident Management & Response
- type
- corrective
- category
- technical
Details
- unified_id
- UC-IR-09
- title
- Recover from incidents using defined initiation criteria
- statement
- Define objective criteria for initiating incident recovery — such as confirmed eradication, completed forensic preservation, and management authorization — and apply them before restoration begins. Identify, develop, and execute recovery activities that restore affected systems, data, and services to a known-good state, verifying integrity before return to production and confirming with business owners that normal operations have resumed.
- domain
- Incident Management & Response
- control_type
- corrective
- control_category
- technical
- members
- framework
- nist-csf-2
- control_id
- RS.MA-05
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC7.5
- coverage
- partial
- delta
- root-cause determination, changes to prevent recurrence, and recovery-plan improvement and testing satisfied by the post-incident review and contingency-testing companion controls
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-IR-09 — Recover from incidents using defined initiation criteria mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Gating recovery on confirmed eradication and forensic preservation before restoration prevents re-compromise by a persistent adversary during return to production.
- UC-IR-09 — Recover from incidents using defined initiation criteria maps_to CC7.5 — The entity identifies, develops, and implements activities to recover from identified security incidents.
- framework
- soc2
- control_id
- CC7.5
- coverage
- partial
- delta
- root-cause determination, changes to prevent recurrence, and recovery-plan improvement and testing satisfied by the post-incident review and contingency-testing companion controls
- relationship
- intersects_with
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Incident Management Lifecycle operates UC-IR-09 — Recover from incidents using defined initiation criteria
- Cybersecurity Incident Response operates UC-IR-09 — Recover from incidents using defined initiation criteria
- SOC 2 Trust Services Readiness tests UC-IR-09 — Recover from incidents using defined initiation criteria
- UC-IR-09 — Recover from incidents using defined initiation criteria maps_to RS.MA-05 — Incident Management: The criteria for initiating incident recovery are applied
- framework
- nist-csf-2
- control_id
- RS.MA-05
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-IR-09 — Recover from incidents using defined initiation criteria mitigates Ransomware disrupting operations and data availability
- strength
- primary
- rationale
- Restoring affected systems and data to a verified known-good state directly reverses ransomware's availability and continuity impact.