ASOM-Fedv6.1Open the explorer
RC-4 · Reconstitution and Recovery

Recovery Integrity Verification

Control Statement

Restored data and rebuilt systems shall be verified against an integrity record maintained independently of the system being restored, before the service is returned to use.

Purpose. To ensure restoration returns the mission to a known-good state rather than reinstating the compromise.

Discussion

Recovery has a failure mode that looks exactly like success: restoring from a point after the intrusion began returns the service, the data and the adversary together. The integrity record therefore has to satisfy two conditions rather than one — it must be maintained independently of the system being restored, *and* it must predate the earliest plausible compromise. The second condition is what connects this control to dwell estimation: if adversary dwell may have been ninety days, an integrity baseline taken thirty days ago verifies nothing useful, and the restore point has to be chosen against the dwell estimate rather than against the last known-good backup.

Goals and Metrics

A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.

Restored systems are verified before return to use.
  • Percentage of restorations verified against an independent integrity record before service resumption
  • Number of restorations returned to use without verification

Accountability

Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.

AOCTISOCHUNTPLATISSO
Authorizing Official / CISO: AccountableCyber Threat Intelligence cell: ConsultedSOC / Defensive Operations: InformedHunt team: ConsultedPlatform and product owners: ResponsibleGovernance / RMF / ISSO: Informed

AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO

  • AccountableAuthorizing Official / CISO
  • ConsultedCyber Threat Intelligence cell
  • InformedSOC / Defensive Operations
  • ConsultedHunt team
  • ResponsiblePlatform and product owners
  • InformedGovernance / RMF / ISSO

Inputs and Outputs

Consumes

Produces

Activities

  1. L2Record the integrity source used to verify each recovery store.
  2. L2Verify restored data and rebuilt systems against that source before returning the service to use.
  3. L2Record the verification result.
  4. L3Verify that the integrity record is maintained independently of the system being restored, including independently of its identity plane.
  5. L3Verify that the record predates the earliest plausible compromise, selecting the restore point against the engagement reconstruction (EN-2) where one exists and against the dwell estimate (TA-2) otherwise, rather than against the most recent backup.
  6. L3Define what happens when verification fails, including the authority to refuse return to service.
  7. L3Retain verification results as evidence rather than as a transient check.
  8. L4Measure the interval covered by retained integrity records against the current dwell estimate, and raise a finding where retention is shorter than plausible dwell.
  9. L4Trend verification failure rates from exercise, since a rate of zero usually means verification is not discriminating.
  10. L5Extend integrity record retention and granularity where dwell estimates or observed engagements show the current window is insufficient.

Measurement

Outcome

Percentage of restorations verified before return to service.

Performance

Integrity record retention window against the current dwell estimate.

Evidence and Assessment

Evidence expected

Integrity verification results for the most recent restoration or exercise; restore point rationale; retention window record.

Assessment procedure

Examine the verification method and its independence; test a restoration for verification before return to service; test whether the integrity record retention exceeds the current dwell estimate.

Related Guidance

Inherits
  • CP-9(1)
  • SI-7(1)
  • AU-9
Satisfies
  • RC.RP-05
  • RC.RP-03

Position in the Chain

Derived from the other controls’ own declarations, so the two directions cannot disagree.

Where This Control Is Used

Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.

Forms of Maneuver It Assesses

  • M11ReconstitutionRestore the mission on evidence, not on hope — and prove it before you need it.2 of 11 techniques — M11.05, M11.11

Terrain It Is Named On

  • T5DataRecovery integrity verification is what distinguishes restored data from data an adversary was content to let you restore.

Artifacts It Stands On

  • producesRecovery integrity verification recordRestored data verified against an independently held integrity record, so that recovery is a demonstrated claim rather than an assumption that the backup was clean.
  • consumesTrusted rebuild pathA documented, walked path to rebuild each decisive point inside its recovery time budget, from media held outside the production identity plane — including a path for the identity plane itself.
  • consumesIsolated recovery capability recordThe means of recovery held outside the production identity plane, and the isolation boundary that keeps it there — itself a load-bearing barrier that has to be monitored.

Roles It Puts to Work