ASOM-Fedv6.1Open the explorer
RC-2 · Reconstitution and Recovery

Isolated Recovery Capability

Control Statement

The means of recovery shall be held outside the trust boundary of the production identity plane, such that compromise of production credentials cannot reach, alter, or destroy them.

Purpose. To ensure the recovery capability survives the compromise it exists to recover from.

Discussion

This is the ransomware lesson stated as a control. Backups that authenticate against the production identity provider are reachable by anyone who holds production administrative credentials, which is precisely the position an adversary occupies at the moment recovery becomes necessary. The operative test is narrower and more useful than "held outside the boundary": can a production administrator credential, used adversarially, reach the recovery store? That question has a demonstrable answer, and a great many recovery architectures that satisfy the general statement fail the specific test.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Recovery means are unreachable from a compromised production identity plane.
  • Number of recovery repositories reachable using production credentials
  • Whether isolation has been tested by attempting access with production credentials

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: InformedSOC / Defensive Operations: ConsultedHunt team: ConsultedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • InformedCyber Threat Intelligence cell
  • ConsultedSOC / Defensive Operations
  • ConsultedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Place the recovery store in a trust zone separate from production.
  2. L2Record the authentication path by which the recovery store is reached.
  3. L2Raise a finding where the recovery store shares an identity provider with production.
  4. L3Test whether a production administrator credential can reach, alter or delete the recovery store, rather than inferring independence from architecture.
  5. L3Verify that the credentials governing the recovery store are issued, held and rotated independently of production.
  6. L3Apply the same independence test to the recovery store's own management plane, including its console, its orchestration and its monitoring.
  7. L3Verify immutability or retention locking where the platform supports it, and record where it does not.
  8. L4Test independence on a defined cadence and after any change to either identity plane, and trend the pass rate.
  9. L4Measure the elapsed time between an identity-plane change and the next independence test, since that interval is the exposure window.
  10. L5Re-derive the independence test from adversary tradecraft observed in engagements and in sector reporting, rather than testing only the paths the original design anticipated.

Measurement

Outcome

Result of the production-credential reachability test against the recovery store.

Performance

Currency of the last independence test relative to the last identity-plane change.

Evidence and Assessment

Evidence expected

Terrain overlay showing the recovery zone and its trust boundary; credential separation record; independence test results.

Assessment procedure

Test whether a production administrator credential can reach the recovery store; examine the authentication path for independence; test the recovery store's management plane by the same method.

Related Guidance

Inherits
  • CP-6
  • CP-9(3)
  • SC-28
Satisfies
  • RC.RP-01
  • PR.DS-11
  • PR.IR-03

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Fed By

Nothing upstream — this control starts a chain.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M11ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.1 of 11 techniques — M11.02

Terrain It Is Named On

  • T8FacilitiesIsolated recovery capability has a physical location, and its separation from production is partly a facilities property.

Artifacts It Stands On

  • producesTrusted rebuild pathA documented, walked path to rebuild each decisive point inside its recovery time budget, from media held outside the production identity plane — including a path for the identity plane itself.
  • producesIsolated recovery capability recordThe means of recovery held outside the production identity plane, and the isolation boundary that keeps it there — itself a load-bearing barrier that has to be monitored.
  • consumesTrust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
  • consumesRecovery objectives registerA declared recovery time and recovery point objective per mission service, agreed with the service owner and constrained by statutory deadlines rather than by what is currently achievable.

Roles It Puts to Work