Control Statement
Every mission service shall have a declared recovery time objective and recovery point objective, approved by the service owner, recorded on the terrain overlay before an incident occurs.
Purpose. To establish what recovery must achieve, so that restoration can succeed or fail rather than simply take however long it takes.
Discussion
Without a stated time and a stated tolerable data loss, recovery has no success condition. The approval requirement matters as much as the numbers: an objective set by the security or infrastructure function is a capability estimate, whereas one set by the service owner is a mission judgment about what the agency can survive. Those are different claims, and only the second can justify the investment the first implies. A declared objective is also not a demonstrated one — that distinction is RC-5's object, and an agency holding objectives it has never tested holds aspirations.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of mission services with a recovery time and recovery point objective recorded on the overlay
- Number of objectives approved by the service owner rather than assumed by IT
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- TM-1 Terrain Inventory and OverlayMission services represented on the terrain overlay
- FO-5 Statutory Availability FloorStatutory deadlines constraining how weak an objective may be
- Outside the frameworkBusiness impact analysis and service-owner agreement
- FC-4 Environmental ContinuityEndurance constraint on achievable recovery objectives
Produces
- RC-3 Trusted Rebuild PathThe time budget a trusted rebuild path must meet
- RC-5 Reconstitution ExerciseThe objectives that reconstitution exercises must demonstrate
- FC-4 Environmental ContinuityService dependency informing environmental continuity requirements
- RC-2 Isolated Recovery CapabilityRecovery point objectives determining retention
- EN-5 Eradication and Transition to RecoveryRecovery objectives constraining how long eradication may take
Activities
- L2Declare a recovery time objective and a recovery point objective for every mission service.
- L2Record both on the terrain overlay against the service.
- L2Flag mission services carrying no declared objective.
- L3Obtain the service owner's approval of both figures, recorded by name and date, so the objective is a mission judgment rather than a capability estimate.
- L3Verify that each objective satisfies any statutory or regulatory availability floor applying to that service (FO-5), and raise a finding where it does not.
- L3State the dependency chain for each service, since a service cannot recover faster than the identity, network and data services it depends on.
- L3Record objectives with approval provenance per GA4.
- L4Compare declared objectives against demonstrated recovery times from RC-5, and flag every objective whose demonstrated time exceeds it.
- L4Measure the proportion of mission services whose objectives have been demonstrated at all, distinguishing declared from proven.
- L5Re-base objectives from demonstrated capability and mission consequence together, rather than allowing the declared figure to persist unchallenged against repeated failure to meet it.
Measurement
Percentage of mission services with an owner-approved objective.
Percentage of objectives demonstrated within their stated period.
Evidence and Assessment
Recovery objectives table with owner approval and dates; statutory floor verification; dependency chains.
Examine the objectives table for completeness against the mission service list; interview service owners on whether the stated figures reflect a mission judgment they made; test that no objective is weaker than its statutory floor.
Related Guidance
- CP-2
- CP-2(3)
- PM-11
- RC.RP-01
- GV.OC-04
- GV.OC-05
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M11ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.3 of 11 techniques — M11.01, M11.06, M11.09
- M8Isolation / RetrogradeGive ground deliberately to preserve the force. Degrade gracefully; never fail open.1 of 17 techniques — M8.13
Terrain It Is Named On
- T4Applications and WorkloadsRecovery objectives are declared per mission service, and mission services are applications — this layer is where the objective becomes concrete.
Artifacts It Stands On
- producesRecovery objectives registerA declared recovery time and recovery point objective per mission service, agreed with the service owner and constrained by statutory deadlines rather than by what is currently achievable.
- consumesCyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- consumesStatutory availability floorThe mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.