PR.IR-03: Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Threats Addressed:
Subcategory is new to this version of the framework and incorporates the following item from the previous version: PR.PT-5: Mechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
1st: 1st Party Risk
Ex1: Avoid single points of failure in systems and infrastructure
Ex2: Use load balancing to increase capacity and improve reliability
Ex3: Use high-availability components like redundant storage and power supplies to improve system reliability
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
CP-1: Policy and Procedures
Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] contingency planning policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate the implementation…
CP-2: Contingency Plan
Develop a contingency plan for the system that: Identifies essential mission and business functions and associated contingency requirements; Provides recovery objectives, restoration priorities, and metrics; Addresses contingency roles, responsibilities, assigned individuals with contact information; Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure; Addresses eventual, full system restoration without deterioration…
CP-3: Contingency Training
Provide contingency training to system users consistent with assigned roles and responsibilities: Within [Assignment: organization-defined time period] of assuming a contingency role or responsibility; When required by system changes; and [Assignment: organization-defined frequency] thereafter; and Review and update contingency training content [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].
CP-4: Contingency Plan Testing
Test the contingency plan for the system [Assignment: organization-defined frequency] using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: [Assignment: organization-defined tests]. Review the contingency plan test results; and Initiate corrective actions, if needed.
CP-6: Alternate Storage Site
Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information; and Ensure that the alternate storage site provides controls equivalent to that of the primary site.
CP-7: Alternate Processing Site
Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of [Assignment: organization-defined system operations] for essential mission and business functions within [Assignment: organization-defined time period] when the primary processing capabilities are unavailable; Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or…
CP-8: Telecommunications Services
Establish alternate telecommunications services, including necessary agreements to permit the resumption of [Assignment: organization-defined system operations] for essential mission and business functions within [Assignment: organization-defined time period] when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.
CP-9: System Backup
Conduct backups of user-level information contained in [Assignment: organization-defined system components] [Assignment: organization-defined frequency]; Conduct backups of system-level information contained in the system [Assignment: organization-defined frequency]; Conduct backups of system documentation, including security- and privacy-related documentation [Assignment: organization-defined frequency] ; and Protect the confidentiality, integrity, and availability of backup information.
CP-10: System Recovery and Reconstitution
Provide for the recovery and reconstitution of the system to a known state within [Assignment: organization-defined time period consistent with recovery time and recovery point objectives] after a disruption, compromise, or failure.
CP-11: Alternate Communications Protocols
Provide the capability to employ [Assignment: organization-defined alternative communications protocols] in support of maintaining continuity of operations.
CP-12: Safe Mode
When [Assignment: organization-defined conditions] are detected, enter a safe mode of operation with [Assignment: organization-defined restrictions].
CP-13: Alternative Security Mechanisms
Employ [Assignment: organization-defined alternative or supplemental security mechanisms] for satisfying [Assignment: organization-defined security functions] when the primary means of implementing the security function is unavailable or compromised.
IR-1: Policy and Procedures
Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] incident response policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate the implementation…
IR-2: Incident Response Training
Provide incident response training to system users consistent with assigned roles and responsibilities: Within [Assignment: organization-defined time period] of assuming an incident response role or responsibility or acquiring system access; When required by system changes; and [Assignment: organization-defined frequency] thereafter; and Review and update incident response training content [Assignment: organization-defined frequency] and following [Assignment: organization-defined…
IR-3: Incident Response Testing
Test the effectiveness of the incident response capability for the system [Assignment: organization-defined frequency] using the following tests: [Assignment: organization-defined tests].
IR-4: Incident Handling
Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery; Coordinate incident handling activities with contingency planning activities; Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly; and…
IR-5: Incident Monitoring
Track and document incidents.
IR-6: Incident Reporting
Require personnel to report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period] ; and Report incident information to [Assignment: organization-defined authorities].
IR-7: Incident Response Assistance
Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of the system for the handling and reporting of incidents.
IR-8: Incident Response Plan
Develop an incident response plan that: Provides the organization with a roadmap for implementing its incident response capability; Describes the structure and organization of the incident response capability; Provides a high-level approach for how the incident response capability fits into the overall organization; Meets the unique requirements of the organization, which relate to mission, size,…
IR-9: Information Spillage Response
Respond to information spills by: Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to information spills; Identifying the specific information involved in the system contamination; Alerting [Assignment: organization-defined personnel or roles] of the information spill using a method of communication not associated with the spill; Isolating the contaminated system or system component; Eradicating…
SA-8: Security and Privacy Engineering Principles
Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: [Assignment: organization-defined systems security and privacy engineering principles].
SA-24: Design For Cyber Resiliency
Design organizational systems, system components, or system services to achieve cyber resiliency by: Defining the following cyber resiliency goals: [Assignment: organization-defined cyber resiliency goals]. Defining the following cyber resiliency objectives: [Assignment: organization-defined cyber resiliency objectives]. Defining the following cyber resiliency techniques: [Assignment: organization-defined cyber resiliency techniques]. Defining the following cyber resiliency implementation approaches: [Assignment: organization-defined…
SC-6: Resource Availability
Protect the availability of resources by allocating [Assignment: organization-defined resources] by [Assignment (one or more): priority, quota, [Assignment: organization-defined controls] ].
SC-24: Fail in Known State
Fail to a [Assignment: organization-defined known system state] for the following failures on the indicated components while preserving [Assignment: organization-defined system state information] in failure: [Assignment: organization-defined types of system failures on system components].
SC-36: Distributed Processing and Storage
Distribute the following processing and storage components across multiple [Assignment: physical locations, logical domains]: [Assignment: organization-defined processing and storage components].
SC-39: Process Isolation
Maintain a separate execution domain for each executing system process.
SI-13: Predictable Failure Prevention
Determine mean time to failure (MTTF) for the following system components in specific environments of operation: [Assignment: organization-defined system components] ; and Provide substitute system components and a means to exchange active and standby components in accordance with the following criteria: [Assignment: organization-defined mean time to failure (MTTF) substitution criteria].
NIST SP 800-171 Revision 3.0
03.16.01: Security Engineering Principles
Apply the following systems security engineering principles to the development or modification of the system and system components: [Assignment: organization-defined systems security engineering principles].
Cloud Controls Matrix v4.0
BCR-11: Equipment Redundancy
Supplement business-critical equipment with redundant equipment independently located at a reasonable minimum distance in accordance with applicable industry standards.