Control statement
- a.Conduct backups of user-level information contained in [Organization-defined: system components] [Organization-defined: frequency];
- b.Conduct backups of system-level information contained in the system [Organization-defined: frequency];
- c.Conduct backups of system documentation, including security- and privacy-related documentation [Organization-defined: frequency] ; and
- d.Protect the confidentiality, integrity, and availability of backup information.
Discussion
System-level information includes system state information, operating system software, middleware, application software, and licenses. User-level information includes information other than system-level information. Mechanisms employed to protect the integrity of system backups include digital signatures and cryptographic hashes. Protection of system backup information while in transit is addressed by [MP-5](#mp-5) and [SC-8](#sc-8) . System backups reflect the requirements in contingency plans as well as other organizational requirements for backing up information. Organizations may be subject to laws, executive orders, directives, regulations, or policies with requirements regarding specific categories of information (e.g., personal health information). Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use System Backup as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to resilient operations, recovery priorities, alternate capabilities, and tested restoration.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- contingency and recovery plans
- backup success and restoration-test records
- exercise after-action reports
- alternate processing or communications agreements
Common failure patterns
- backups never restored in testing
- recovery priorities not tied to mission impact
- plans dependent on unavailable people or facilities
- exercise findings not tracked to closure
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- CP-09a.backups of user-level information contained in [Organization-defined: system components] are conducted [Organization-defined: frequency];
- CP-09b.backups of system-level information contained in the system are conducted [Organization-defined: frequency];
- CP-09c.backups of system documentation, including security- and privacy-related documentation are conducted [Organization-defined: frequency];
- CP-09d.
- CP-09d.[01]the confidentiality of backup information is protected;
- CP-09d.[02]the integrity of backup information is protected;
- CP-09d.[03]the availability of backup information is protected.
Examine
- Contingency planning policy
- procedures addressing system backup
- contingency plan
- backup storage location(s)
- system backup logs or records
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with system backup responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for conducting system backups
- mechanisms supporting and/or implementing system backups
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
CP-9(1) — Testing for Reliability and Integrity
Test backup information [Organization-defined: organization-defined frequency] to verify media reliability and information integrity.
Official discussion
Organizations need assurance that backup information can be reliably retrieved. Reliability pertains to the systems and system components where the backup information is stored, the operations used to retrieve the information, and the integrity of the information being retrieved. Independent and specialized tests can be used for each of the aspects of reliability. For example, decrypting and transporting (or transmitting) a random sample of backup files from the alternate storage or backup site and comparing the information to the same information at the primary processing site can provide such assurance.
Organization-defined parameters (3)
Assessment objectives and methods
- CP-09(01)[01]backup information is tested [Organization-defined: frequency] to verify media reliability;
- CP-09(01)[02]backup information is tested [Organization-defined: frequency] to verify information integrity.
Examine
- Contingency planning policy
- procedures addressing system backup
- contingency plan
- system backup test results
- contingency plan test documentation
- contingency plan test results
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with system backup responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for conducting system backups
- mechanisms supporting and/or implementing system backups
Related controls
CP-9(2) — Test Restoration Using Sampling
Use a sample of backup information in the restoration of selected system functions as part of contingency plan testing.
Official discussion
Organizations need assurance that system functions can be restored correctly and can support established organizational missions. To ensure that the selected system functions are thoroughly exercised during contingency plan testing, a sample of backup information is retrieved to determine whether the functions are operating as intended. Organizations can determine the sample size for the functions and backup information based on the level of assurance needed.
Assessment objectives and methods
a sample of backup information in the restoration of selected system functions is used as part of contingency plan testing.
Examine
- Contingency planning policy
- procedures addressing system backup
- contingency plan
- system backup test results
- contingency plan test documentation
- contingency plan test results
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with system backup responsibilities
- organizational personnel with contingency planning/contingency plan testing responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for conducting system backups
- mechanisms supporting and/or implementing system backups
Related controls
CP-9(3) — Separate Storage for Critical Information
Store backup copies of [Organization-defined: critical system software and other security-related information] in a separate facility or in a fire rated container that is not collocated with the operational system.
Official discussion
Separate storage for critical information applies to all critical information regardless of the type of backup storage media. Critical system software includes operating systems, middleware, cryptographic key management systems, and intrusion detection systems. Security-related information includes inventories of system hardware, software, and firmware components. Alternate storage sites, including geographically distributed architectures, serve as separate storage facilities for organizations. Organizations may provide separate storage by implementing automated backup processes at alternative storage sites (e.g., data centers). The General Services Administration (GSA) establishes standards and specifications for security and fire rated containers.
Organization-defined parameters (1)
Assessment objectives and methods
backup copies of [Organization-defined: critical system software and other security-related information] are stored in a separate facility or in a fire rated container that is not collocated with the operational system.
Examine
- Contingency planning policy
- procedures addressing system backup
- contingency plan
- backup storage location(s)
- system backup configurations and associated documentation
- system backup logs or records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with contingency planning and plan implementation responsibilities
- organizational personnel with system backup responsibilities
- organizational personnel with information security responsibilities
Related controls
CP-9(4) — Protection from Unauthorized Modification
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
CP-9(5) — Transfer to Alternate Storage Site
Transfer system backup information to the alternate storage site [Organization-defined: organization-defined time period and transfer rate consistent with the recovery time and recovery point objectives].
Official discussion
System backup information can be transferred to alternate storage sites either electronically or by the physical shipment of storage media.
Organization-defined parameters (3)
Assessment objectives and methods
- CP-09(05)[01]system backup information is transferred to the alternate storage site for [Organization-defined: time period];
- CP-09(05)[02]system backup information is transferred to the alternate storage site [Organization-defined: transfer rate].
Examine
- Contingency planning policy
- procedures addressing system backup
- contingency plan
- system backup logs or records
- evidence of system backup information transferred to alternate storage site
- alternate storage site agreements
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with system backup responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for transferring system backups to the alternate storage site
- mechanisms supporting and/or implementing system backups
- mechanisms supporting and/or implementing information transfer to the alternate storage site
Related controls
CP-9(6) — Redundant Secondary System
Conduct system backup by maintaining a redundant secondary system that is not collocated with the primary system and that can be activated without loss of information or disruption to operations.
Official discussion
The effect of system backup can be achieved by maintaining a redundant secondary system that mirrors the primary system, including the replication of information. If this type of redundancy is in place and there is sufficient geographic separation between the two systems, the secondary system can also serve as the alternate processing site.
Assessment objectives and methods
- CP-09(06)[01]system backup is conducted by maintaining a redundant secondary system that is not collocated with the primary system;
- CP-09(06)[02]system backup is conducted by maintaining a redundant secondary system that can be activated without loss of information or disruption to operations.
Examine
- Contingency planning policy
- procedures addressing system backup
- contingency plan
- system backup test results
- contingency plan test results
- contingency plan test documentation
- redundant secondary system for system backups
- location(s) of redundant secondary backup system(s)
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with system backup responsibilities
- organizational personnel with information security responsibilities
- organizational personnel with responsibility for the redundant secondary system
Test
- Organizational processes for maintaining redundant secondary systems
- mechanisms supporting and/or implementing system backups
- mechanisms supporting and/or implementing information transfer to a redundant secondary system
Related controls
CP-9(7) — Dual Authorization for Deletion or Destruction
Enforce dual authorization for the deletion or destruction of [Organization-defined: backup information].
Official discussion
Dual authorization ensures that deletion or destruction of backup information cannot occur unless two qualified individuals carry out the task. Individuals deleting or destroying backup information possess the skills or expertise to determine if the proposed deletion or destruction of information reflects organizational policies and procedures. Dual authorization may also be known as two-person control. To reduce the risk of collusion, organizations consider rotating dual authorization duties to other individuals.
Organization-defined parameters (1)
Assessment objectives and methods
dual authorization for the deletion or destruction of [Organization-defined: backup information] is enforced.
Examine
- Contingency planning policy
- procedures addressing system backup
- contingency plan
- system design documentation
- system configuration settings and associated documentation
- system generated list of dual authorization credentials or rules
- logs or records of deletion or destruction of backup information
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with system backup responsibilities
- organizational personnel with information security responsibilities
Test
- Mechanisms supporting and/or implementing dual authorization
- mechanisms supporting and/or implementing the deletion/destruction of backup information
Related controls
CP-9(8) — Cryptographic Protection
Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Organization-defined: backup information].
Official discussion
The selection of cryptographic mechanisms is based on the need to protect the confidentiality and integrity of backup information. The strength of mechanisms selected is commensurate with the security category or classification of the information. Cryptographic protection applies to system backup information in storage at both primary and alternate locations. Organizations that implement cryptographic mechanisms to protect information at rest also consider cryptographic key management solutions.
Organization-defined parameters (1)
Assessment objectives and methods
cryptographic mechanisms are implemented to prevent unauthorized disclosure and modification of [Organization-defined: backup information].
Examine
- Contingency planning policy
- procedures addressing system backup
- contingency plan
- system design documentation
- system configuration settings and associated documentation
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with system backup responsibilities
- organizational personnel with information security responsibilities
Test
- Mechanisms supporting and/or implementing cryptographic protection of backup information
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.