Under active development Content is continuously updated and improved · Last updated Feb 18, 2026, 2:55 AM UTC

RC.RP-04Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms

>Control Description

This incident recovery plan execution subcategory ensures that critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms. Key activities include: Use business impact and system categorization records (including service delivery objectives) to validate that essential services are restored in t...; Work with system owners to confirm the successful restoration of systems and the return to normal operations; Monitor the performance of restored systems to verify the adequacy of the restoration.

>Cross-Framework Mappings

>Informative References

Official NIST mappings to external frameworks and standards. Source: NIST CSF 2.0

CRI Profile v2.0

RC.RP-04
RC.RP-04.01

ISO/IEC 27001:2022

Mandatory Clause: 8.1
Annex A Controls: None

NICE Framework

DD-WRL-002
IO-WRL-005
OG-WRL-011
OG-WRL-014
OG-WRL-015
PD-WRL-003

PCI DSS

12.10.1
12.5.1
1.2.3
1.2.4
10.2.1

SCF

BCD-01
BCD-01.4
BCD-02
BCD-02.1

SP 800-171 Rev 3

03.06.05
03.15.01

SP 800-53 Rev 5.1.1

PM-08
PM-09
PM-11
IR-01
IR-08

SP 800-53 Rev 5.2.0

PM-08
PM-09
PM-11
IR-01
IR-08

Ask AI

Configure your API key to use AI features.