The Recover Function describes activities that will help an agency to develop and implement the appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity event. These activities will support the timely recovery to normal operations to reduce the impact of a cybersecurity event.
Recovery Planning
Executing and maintaining recovery processes to ensure timely restoration of systems or assets affected by cybersecurity events.
- Execute the recovery plan during or after an event.
Improvements
Improving recovery planning and processes by incorporating lessons learned into future activities.
- Incorporate lessons learned into recovery plans.
- Periodically update recovery strategies.
Communications
Coordinating restoration activities with internal and external parties, such as coordinating centers, Internet Service Providers, owners of attacking systems (i.e. owners of internal or external systems that have become compromised and were subsequently used in the attack of an internal system) , victims (i.e. inform victims of the security breach in a timely manner, what they can do to get more information, and/or need to do to protect themselves), other CSIRTs (i.e. CSIRT stands for computer security incident response team and is an external group of knowledgeable information security professionals able to offer incident response services), and vendors.
- Manage public relations.
- Address any reputation issues after an event is repaired.
- Communicate recovery activities to internal stakeholders and executive and management teams.