{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Incident Management & Response","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-09","description":"Define objective criteria for initiating incident recovery — such as confirmed eradication, completed forensic preservation, and management authorization — and apply them before restoration begins. Identify, develop, and execute recovery activities that restore affected systems, data, and services to a known-good state, verifying integrity before return to production and confirming with business owners that normal operations have resumed.","details":{"control_category":"technical","control_type":"corrective","domain":"Incident Management & Response","guidance":[],"members":[{"control_id":"RS.MA-05","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"CC7.5","coverage":"partial","delta":"root-cause determination, changes to prevent recurrence, and recovery-plan improvement and testing satisfied by the post-incident review and contingency-testing companion controls","framework":"soc2","relationship":"intersects_with"}],"statement":"Define objective criteria for initiating incident recovery — such as confirmed eradication, completed forensic preservation, and management authorization — and apply them before restoration begins. Identify, develop, and execute recovery activities that restore affected systems, data, and services to a known-good state, verifying integrity before return to production and confirming with business owners that normal operations have resumed.","title":"Recover from incidents using defined initiation criteria","unified_id":"UC-IR-09"},"id":"uc:UC-IR-09","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-09","sourceIds":["nist-csf-2","soc2"],"sourceUrl":null,"title":"UC-IR-09 — Recover from incidents using defined initiation criteria","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:19af8d390c683ffcb3d00e55c317843f13efad665104555c71a75a09a6ecda8a","properties":{"rationale":"Gating recovery on confirmed eradication and forensic preservation before restoration prevents re-compromise by a persistent adversary during return to production.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-09-6caefe96.json","sourceId":"uc:UC-IR-09","targetDetailPath":"/data/v1/records/risk-cyber-coordinated-campaign-b5879769.json","targetId":"risk:cyber-coordinated-campaign","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4882f091e28b3b9056302a734101095ffbddbce2ea27b6aa406ae94d126e0bc3","properties":{"control_id":"CC7.5","coverage":"partial","delta":"root-cause determination, changes to prevent recurrence, and recovery-plan improvement and testing satisfied by the post-incident review and contingency-testing companion controls","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-09-6caefe96.json","sourceId":"uc:UC-IR-09","targetDetailPath":"/data/v1/records/ctrl-soc2-cc7-5-580af9de.json","targetId":"ctrl:soc2:CC7.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5900c12d0cec0820dedc1b80fb61ae168c2a3838afffe83957abdce90655dc89","properties":{},"sourceDetailPath":"/data/v1/records/wf-g7-9762f11b.json","sourceId":"wf:G7","targetDetailPath":"/data/v1/records/uc-uc-ir-09-6caefe96.json","targetId":"uc:UC-IR-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b746028679f157109859c2538d9c13e66819262672ce20517e71578ef35c4acc","properties":{},"sourceDetailPath":"/data/v1/records/wf-c3-4a88b225.json","sourceId":"wf:C3","targetDetailPath":"/data/v1/records/uc-uc-ir-09-6caefe96.json","targetId":"uc:UC-IR-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:be0e2862cdf0b0a75e22f777dff9ae482c1e09bb69f6b9c5d5292cc603e97698","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-ir-09-6caefe96.json","targetId":"uc:UC-IR-09","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c69f55a97a999747ca6e642f5696f65c1f90dca47d3db8493dc89b0c3e8148a4","properties":{"control_id":"RS.MA-05","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-09-6caefe96.json","sourceId":"uc:UC-IR-09","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-rs-ma-05-e3876d8d.json","targetId":"ctrl:nist-csf-2:RS.MA-05","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e24ce36670cc51b40478fe74ee4ee3acc2c28621fa5df534736bb12c574adbc4","properties":{"rationale":"Restoring affected systems and data to a verified known-good state directly reverses ransomware's availability and continuity impact.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-09-6caefe96.json","sourceId":"uc:UC-IR-09","targetDetailPath":"/data/v1/records/risk-sdlc-ransomware-32ab67f4.json","targetId":"risk:sdlc-ransomware","type":"mitigates"}],"schemaVersion":1}
