Control Statement
For every decisive point, the organization shall maintain a documented and tested path to rebuild the element from trusted media within its declared recovery time objective.
Purpose. To ensure that what must not be lost can be rebuilt, from a source the adversary did not touch, inside the time the mission requires.
Discussion
Most rebuild procedures assume a working identity plane — they begin with authenticating to something. Where identity is itself the decisive point that was compromised, the procedure contains a circular dependency, and it surfaces at the worst possible moment. The identity plane's own rebuild path therefore has to be tested independently and first, because every other path in the estate depends on it. The trusted-media requirement carries the second half of the problem: media stored, indexed or validated by the compromised environment is not trusted media regardless of where it physically sits.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of decisive points with a documented rebuild path
- Measured rebuild time against the declared recovery time objective
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- KT-1 Decisive Point IdentificationDesignated decisive points requiring a rebuild path
- RC-1 Recovery ObjectivesRecovery time objective setting the budget
- RC-2 Isolated Recovery CapabilityIsolated trusted media
- EN-5 Eradication and Transition to RecoveryVerified-clean state the rebuild path proceeds from
Produces
- RC-5 Reconstitution ExerciseThe paths that reconstitution exercises must walk
- CE-5 Remediation Backlog PrioritizationUntested or over-budget paths entering the backlog
- RC-4 Recovery Integrity VerificationRebuilt systems awaiting verification
Activities
- L2Document a rebuild path for every designated decisive point.
- L2Identify the media source each path rebuilds from.
- L2Record the most recent rebuild test and its elapsed time.
- L3Verify that each media source is independently trusted — not stored, indexed or validated by the environment being rebuilt.
- L3Test the rebuild path for the identity plane itself, and sequence it first, since every other path depends on a working identity service.
- L3Record the dependency order across rebuild paths, so reconstitution can be sequenced rather than attempted in parallel.
- L3Compare each tested elapsed time against the element's declared recovery time objective (RC-1) and raise a finding where it exceeds.
- L4Test each decisive point's rebuild path on a defined cadence and trend the elapsed times, since procedures decay as platforms change.
- L4Measure the proportion of decisive points whose rebuild path has been tested at all, distinguishing documented from tested.
- L5Re-engineer paths whose tested time persistently exceeds the objective, rather than repeatedly recording the same finding.
Measurement
Percentage of decisive points with a tested rebuild path meeting their objective.
Median age of the most recent rebuild test per decisive point.
Evidence and Assessment
Rebuild procedure per decisive point; record of the most recent rebuild test and its elapsed time; media provenance verification; dependency sequence.
Examine the procedures for currency; test one rebuild against its stated recovery time objective; verify the media source is independently trusted; test whether the identity plane's own rebuild path has been exercised.
Related Guidance
- CP-10
- SI-7
- CM-2
- RC.RP-04
- PR.PS-02
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M11ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.4 of 11 techniques — M11.03, M11.04, M11.10, M11.11
Terrain It Is Named On
- T1IdentityA trusted rebuild path has to include the identity plane, or recovery re-admits whoever compromised it.
- T4Applications and WorkloadsThe trusted rebuild path is defined against this layer, and its central requirement is not to run through the compromised pipeline.
Artifacts It Stands On
- producesTrusted rebuild pathA documented, walked path to rebuild each decisive point inside its recovery time budget, from media held outside the production identity plane — including a path for the identity plane itself.
- consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
- consumesRecovery objectives registerA declared recovery time and recovery point objective per mission service, agreed with the service owner and constrained by statutory deadlines rather than by what is currently achievable.
- consumesIsolated recovery capability recordThe means of recovery held outside the production identity plane, and the isolation boundary that keeps it there — itself a load-bearing barrier that has to be monitored.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.