NIST 800-53 Rev 5

424 controls available

CP-9lowmoderatehigh

System Backup

Contingency Planning

Control Statement

Conduct backups of user-level information contained in {{ insert: param, cp-09_odp.01 }} {{ insert: param, cp-09_odp.02 }}; Conduct backups of system-level information contained in the system {{ insert: param, cp-09_odp.03 }}; Conduct backups of system documentation, including security- and privacy-related documentation {{ insert: param, cp-09_odp.04 }} ; and Protect the confidentiality, integrity, and availability of backup information.

Discussion

System-level information includes system state information, operating system software, middleware, application software, and licenses. User-level information includes information other than system-level information. Mechanisms employed to protect the integrity of system backups include digital signatures and cryptographic hashes. Protection of system backup information while in transit is addressed by [MP-5](#mp-5) and [SC-8](#sc-8) . System backups reflect the requirements in contingency plans as well as other organizational requirements for backing up information. Organizations may be subject to laws, executive orders, directives, regulations, or policies with requirements regarding specific categories of information (e.g., personal health information). Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.

Framework
NIST SP 800-53 Rev 5
Family
Contingency Planning
Baselines
low, moderate, high

Related Frameworks

13 paths across 2 frameworks
NIST 800-1711 mapping
3.8.9
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI12 mappings
CCI-000534
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000535
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000536
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000537
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000538
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000539
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000540
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004020
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004021
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004022
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004023
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004024
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

18 STIGs reach this control through 26 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Server

2 STIGs

Network Device

10 STIGs
Cisco ACI NDM Security Technical Implementation Guide
V1R22025-12-111 of 26 findings match
Cisco ASA NDM Security Technical Implementation Guide
V2R42025-12-081 of 47 findings match
Network Device Management Security Requirements Guide
V5R32025-02-111 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-101 of 105 findings match
Show 2 more STIGs in this category →

Web / Application Server

2 STIGs

Virtualization / Container

2 STIGs

Endpoint Security Management

2 STIGs
HYCU Protege Security Technical Implementation Guide
V1R22026-03-041 of 55 findings match