RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms.
5
artefacts
2
held by a system
2
at each review
moderate
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Recovery time objective tracking dashboard · Cloud console / configuration management
- Post restoration monitoring reports · Backup / DR tooling
periodic reviewEvidence produced at each review
- User acceptance evidence per restored service · Document repository
- Recovery deviation records and rationale · Document repository
governing documentDocuments that govern the control
- Service restoration verification procedure · Policy repository / GRC workspace
First move
Start with the 2 of 5 artefacts that already live in a system (Cloud console / configuration management); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- RTO measured but not enforced
- Verification absent for dependent services
- User acceptance signed off generically
- Post restoration monitoring brief
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetRC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration · RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed