Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

CP-9 — System Backup

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

8Enhancements
4Parameters
3Baseline memberships
3Assessment methods

CP — Contingency Planning · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Conduct backups of user-level information contained in [Organization-defined: system components] [Organization-defined: frequency];
  2. b.Conduct backups of system-level information contained in the system [Organization-defined: frequency];
  3. c.Conduct backups of system documentation, including security- and privacy-related documentation [Organization-defined: frequency] ; and
  4. d.Protect the confidentiality, integrity, and availability of backup information.
Official NIST discussion

Discussion

System-level information includes system state information, operating system software, middleware, application software, and licenses. User-level information includes information other than system-level information. Mechanisms employed to protect the integrity of system backups include digital signatures and cryptographic hashes. Protection of system backup information while in transit is addressed by [MP-5](#mp-5) and [SC-8](#sc-8) . System backups reflect the requirements in contingency plans as well as other organizational requirements for backing up information. Organizations may be subject to laws, executive orders, directives, regulations, or policies with requirements regarding specific categories of information (e.g., personal health information). Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

system componentssystem components for which to conduct backups of user-level information is defined;
frequencyfrequency at which to conduct backups of user-level information consistent with recovery time and recovery point objectives is defined;
frequencyfrequency at which to conduct backups of system-level information consistent with recovery time and recovery point objectives is defined;
frequencyfrequency at which to conduct backups of system documentation consistent with recovery time and recovery point objectives is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use System Backup as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to resilient operations, recovery priorities, alternate capabilities, and tested restoration.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • contingency and recovery plans
  • backup success and restoration-test records
  • exercise after-action reports
  • alternate processing or communications agreements

Common failure patterns

  • backups never restored in testing
  • recovery priorities not tied to mission impact
  • plans dependent on unavailable people or facilities
  • exercise findings not tracked to closure

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. CP-09a.backups of user-level information contained in [Organization-defined: system components] are conducted [Organization-defined: frequency];
  2. CP-09b.backups of system-level information contained in the system are conducted [Organization-defined: frequency];
  3. CP-09c.backups of system documentation, including security- and privacy-related documentation are conducted [Organization-defined: frequency];
  4. CP-09d.
    1. CP-09d.[01]the confidentiality of backup information is protected;
    2. CP-09d.[02]the integrity of backup information is protected;
    3. CP-09d.[03]the availability of backup information is protected.

Examine

  • Contingency planning policy
  • procedures addressing system backup
  • contingency plan
  • backup storage location(s)
  • system backup logs or records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with system backup responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for conducting system backups
  • mechanisms supporting and/or implementing system backups
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

CP-9(1) — Testing for Reliability and Integrity

ModerateHigh

Test backup information [Organization-defined: organization-defined frequency] to verify media reliability and information integrity.

Official discussion

Organizations need assurance that backup information can be reliably retrieved. Reliability pertains to the systems and system components where the backup information is stored, the operations used to retrieve the information, and the integrity of the information being retrieved. Independent and specialized tests can be used for each of the aspects of reliability. For example, decrypting and transporting (or transmitting) a random sample of backup files from the alternate storage or backup site and comparing the information to the same information at the primary processing site can provide such assurance.

Organization-defined parameters (3)
organization-defined frequency
frequencyfrequency at which to test backup information for media reliability is defined;
frequencyfrequency at which to test backup information for information integrity is defined;
Assessment objectives and methods
  1. CP-09(01)[01]backup information is tested [Organization-defined: frequency] to verify media reliability;
  2. CP-09(01)[02]backup information is tested [Organization-defined: frequency] to verify information integrity.

Examine

  • Contingency planning policy
  • procedures addressing system backup
  • contingency plan
  • system backup test results
  • contingency plan test documentation
  • contingency plan test results
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system backup responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for conducting system backups
  • mechanisms supporting and/or implementing system backups
Related controls
Official NIST control enhancement

CP-9(2) — Test Restoration Using Sampling

High

Use a sample of backup information in the restoration of selected system functions as part of contingency plan testing.

Official discussion

Organizations need assurance that system functions can be restored correctly and can support established organizational missions. To ensure that the selected system functions are thoroughly exercised during contingency plan testing, a sample of backup information is retrieved to determine whether the functions are operating as intended. Organizations can determine the sample size for the functions and backup information based on the level of assurance needed.

Assessment objectives and methods

a sample of backup information in the restoration of selected system functions is used as part of contingency plan testing.

Examine

  • Contingency planning policy
  • procedures addressing system backup
  • contingency plan
  • system backup test results
  • contingency plan test documentation
  • contingency plan test results
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system backup responsibilities
  • organizational personnel with contingency planning/contingency plan testing responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for conducting system backups
  • mechanisms supporting and/or implementing system backups
Related controls
Official NIST control enhancement

CP-9(3) — Separate Storage for Critical Information

High

Store backup copies of [Organization-defined: critical system software and other security-related information] in a separate facility or in a fire rated container that is not collocated with the operational system.

Official discussion

Separate storage for critical information applies to all critical information regardless of the type of backup storage media. Critical system software includes operating systems, middleware, cryptographic key management systems, and intrusion detection systems. Security-related information includes inventories of system hardware, software, and firmware components. Alternate storage sites, including geographically distributed architectures, serve as separate storage facilities for organizations. Organizations may provide separate storage by implementing automated backup processes at alternative storage sites (e.g., data centers). The General Services Administration (GSA) establishes standards and specifications for security and fire rated containers.

Organization-defined parameters (1)
critical system software and other security-related informationcritical system software and other security-related information backups to be stored in a separate facility are defined;
Assessment objectives and methods

backup copies of [Organization-defined: critical system software and other security-related information] are stored in a separate facility or in a fire rated container that is not collocated with the operational system.

Examine

  • Contingency planning policy
  • procedures addressing system backup
  • contingency plan
  • backup storage location(s)
  • system backup configurations and associated documentation
  • system backup logs or records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with contingency planning and plan implementation responsibilities
  • organizational personnel with system backup responsibilities
  • organizational personnel with information security responsibilities
Related controls
Official NIST control enhancement

CP-9(4) — Protection from Unauthorized Modification

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

CP-9(5) — Transfer to Alternate Storage Site

High

Transfer system backup information to the alternate storage site [Organization-defined: organization-defined time period and transfer rate consistent with the recovery time and recovery point objectives].

Official discussion

System backup information can be transferred to alternate storage sites either electronically or by the physical shipment of storage media.

Organization-defined parameters (3)
organization-defined time period and transfer rate consistent with the recovery time and recovery point objectives
time periodtime period consistent with recovery time and recovery point objectives is defined;
transfer ratetransfer rate consistent with recovery time and recovery point objectives is defined;
Assessment objectives and methods
  1. CP-09(05)[01]system backup information is transferred to the alternate storage site for [Organization-defined: time period];
  2. CP-09(05)[02]system backup information is transferred to the alternate storage site [Organization-defined: transfer rate].

Examine

  • Contingency planning policy
  • procedures addressing system backup
  • contingency plan
  • system backup logs or records
  • evidence of system backup information transferred to alternate storage site
  • alternate storage site agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system backup responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for transferring system backups to the alternate storage site
  • mechanisms supporting and/or implementing system backups
  • mechanisms supporting and/or implementing information transfer to the alternate storage site
Related controls
Official NIST control enhancement

CP-9(6) — Redundant Secondary System

Conduct system backup by maintaining a redundant secondary system that is not collocated with the primary system and that can be activated without loss of information or disruption to operations.

Official discussion

The effect of system backup can be achieved by maintaining a redundant secondary system that mirrors the primary system, including the replication of information. If this type of redundancy is in place and there is sufficient geographic separation between the two systems, the secondary system can also serve as the alternate processing site.

Assessment objectives and methods
  1. CP-09(06)[01]system backup is conducted by maintaining a redundant secondary system that is not collocated with the primary system;
  2. CP-09(06)[02]system backup is conducted by maintaining a redundant secondary system that can be activated without loss of information or disruption to operations.

Examine

  • Contingency planning policy
  • procedures addressing system backup
  • contingency plan
  • system backup test results
  • contingency plan test results
  • contingency plan test documentation
  • redundant secondary system for system backups
  • location(s) of redundant secondary backup system(s)
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system backup responsibilities
  • organizational personnel with information security responsibilities
  • organizational personnel with responsibility for the redundant secondary system

Test

  • Organizational processes for maintaining redundant secondary systems
  • mechanisms supporting and/or implementing system backups
  • mechanisms supporting and/or implementing information transfer to a redundant secondary system
Related controls
Official NIST control enhancement

CP-9(7) — Dual Authorization for Deletion or Destruction

Enforce dual authorization for the deletion or destruction of [Organization-defined: backup information].

Official discussion

Dual authorization ensures that deletion or destruction of backup information cannot occur unless two qualified individuals carry out the task. Individuals deleting or destroying backup information possess the skills or expertise to determine if the proposed deletion or destruction of information reflects organizational policies and procedures. Dual authorization may also be known as two-person control. To reduce the risk of collusion, organizations consider rotating dual authorization duties to other individuals.

Organization-defined parameters (1)
backup informationbackup information for which to enforce dual authorization in order to delete or destroy is defined;
Assessment objectives and methods

dual authorization for the deletion or destruction of [Organization-defined: backup information] is enforced.

Examine

  • Contingency planning policy
  • procedures addressing system backup
  • contingency plan
  • system design documentation
  • system configuration settings and associated documentation
  • system generated list of dual authorization credentials or rules
  • logs or records of deletion or destruction of backup information
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system backup responsibilities
  • organizational personnel with information security responsibilities

Test

  • Mechanisms supporting and/or implementing dual authorization
  • mechanisms supporting and/or implementing the deletion/destruction of backup information
Related controls
Official NIST control enhancement

CP-9(8) — Cryptographic Protection

ModerateHigh

Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Organization-defined: backup information].

Official discussion

The selection of cryptographic mechanisms is based on the need to protect the confidentiality and integrity of backup information. The strength of mechanisms selected is commensurate with the security category or classification of the information. Cryptographic protection applies to system backup information in storage at both primary and alternate locations. Organizations that implement cryptographic mechanisms to protect information at rest also consider cryptographic key management solutions.

Organization-defined parameters (1)
backup informationbackup information to protect against unauthorized disclosure and modification is defined;
Assessment objectives and methods

cryptographic mechanisms are implemented to prevent unauthorized disclosure and modification of [Organization-defined: backup information].

Examine

  • Contingency planning policy
  • procedures addressing system backup
  • contingency plan
  • system design documentation
  • system configuration settings and associated documentation
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system backup responsibilities
  • organizational personnel with information security responsibilities

Test

  • Mechanisms supporting and/or implementing cryptographic protection of backup information
Related controls
Source record

Authoritative sources