Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Guided Defense Playbooks

Continuity and Recovery

Map mission dependencies, plan for disruption, protect capacity and backups, execute recovery, verify restored operations, communicate progress, and improve through exercises.

5Guided phases
18CSF outcomes
67Mapped controls
21D3FEND techniques

Operational resilience playbook · Editorial sequence over source-controlled framework relationships

Open the complete Defense Map →

Mission and audience

Restore trustworthy mission capability within agreed priorities after cyber, technology, supplier, or environmental disruption.

Recovery is not simply restoring a backup. It requires business priorities, dependencies, capacity, communications, trust validation, and criteria for returning to normal operations.

Built forContinuity teams · Infrastructure teams · Security leaders · System owners · Executives
01

Guided phase

Understand mission dependencies

Identify critical services, external expectations, organizational dependencies, and prioritized assets.

Actions to take

  • Map mission functions to systems, data, people, facilities, suppliers, and communications.
  • Define impact, priority, RTO, RPO, and minimum service levels.
  • Identify single points of failure and concentration risk.
GV.OC-04Govern · Organizational Context

External Stakeholder Dependencies

Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated

5 controls1 800-172
ID.AM-05Identify · Asset Management

Asset Prioritization

Assets are prioritized based on classification, criticality, resources, and impact on the mission

3 controls1 800-1713 800-1727 D3FEND4 mitigations
02

Guided phase

Plan resilience and capacity

Maintain operational plans and mechanisms that support normal and adverse conditions.

Actions to take

  • Define continuity, disaster recovery, cyber recovery, and crisis coordination boundaries.
  • Plan alternate capacity, identity, communications, and dependencies.
  • Document degraded-mode and manual-workaround decisions.
ID.IM-04Identify · Improvement

Improve Incident Response and Cybersecurity Plans

Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

4 controls3 800-171
PR.IR-03Protect · Technology Infrastructure Resilience

Resilience Mechanisms

Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

9 controls1 800-1712 D3FEND4 mitigations
03

Guided phase

Protect and test recovery assets

Create protected backups and use tests and exercises to validate plans and identify improvements.

Actions to take

  • Protect backup data, systems, credentials, and administration paths.
  • Test restoration, failover, communications, and decision-making.
  • Track exercise findings through closure.
ID.IM-02Identify · Improvement

Improvements from Tests and Exercises

Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

40 controls15 800-17113 800-17221 D3FEND17 mitigations
04

Guided phase

Initiate and perform recovery

Apply recovery criteria, select actions, verify restoration assets, and restore prioritized services.

Actions to take

  • Define who can initiate recovery and under what conditions.
  • Prioritize restoration based on mission and dependency order.
  • Verify backups and build sources before use.
RC.RP-01Recover · Incident Recovery Plan Execution

Execute the Recovery Plan

The recovery portion of the incident response plan is executed once initiated from the incident response process

3 controls2 800-1714 800-1723 D3FEND2 mitigations
RC.RP-02Recover · Incident Recovery Plan Execution

Select and Perform Recovery Actions

Recovery actions are selected, scoped, prioritized, and performed

3 controls2 800-1714 800-1723 D3FEND2 mitigations
RC.RP-03Recover · Incident Recovery Plan Execution

Verify Backups and Restoration Assets

The integrity of backups and other restoration assets is verified before using them for restoration

3 controls1 800-1712 800-172
05

Guided phase

Verify, communicate, and improve

Validate restored assets, establish operational norms, declare completion, and communicate progress.

Actions to take

  • Validate identity, configuration, data, monitoring, and business function.
  • Communicate recovery progress using approved messages.
  • Complete documentation and convert lessons into owned improvements.
RC.RP-04Recover · Incident Recovery Plan Execution

Establish Post-Incident Operational Norms

Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms

5 controls2 800-171
RC.RP-05Recover · Incident Recovery Plan Execution

Verify Restored Assets and Normal Operations

The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed

1 controls1 800-172
RC.RP-06Recover · Incident Recovery Plan Execution

Declare the End of Recovery

The end of incident recovery is declared based on criteria, and incident-related documentation is completed

2 controls2 800-1713 800-1723 D3FEND2 mitigations
RC.CO-03Recover · Incident Recovery Communication

Communicate Recovery Progress

Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders

3 controls2 800-1714 800-1723 D3FEND2 mitigations
RC.CO-04Recover · Incident Recovery Communication

Share Public Recovery Updates

Public updates on incident recovery are shared using approved methods and messaging

2 controls1 800-1713 800-1723 D3FEND2 mitigations

Completion evidence

What should exist when this playbook is working?

  • Business impact, dependency, and critical-service map.
  • Approved recovery priorities, RTOs, RPOs, and minimum service levels.
  • Continuity, disaster recovery, cyber recovery, and communication plans.
  • Protected backup and alternate-capacity evidence.
  • Exercise, failover, and restoration test results.
  • Recovery validation, declaration, communication, and improvement records.

Relationship boundaries

Use the playbook as a decision aid.

Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.