Recovery is the phase of the defensive lifecycle where an organization restores normal operations after an incident has been contained and eradicated. It follows response and precedes the post-incident review. The goal is to bring systems and services back safely, confirming that the threat is gone and that restored systems are trustworthy. Recovery balances speed against assurance, since rushing can reintroduce compromise while moving too slowly prolongs business impact.
This pillar covers the work of returning to a known good state.
- Recovery strategy and objectives define how restoration will proceed and set targets such as recovery time objective and recovery point objective that guide decisions.
- Operations and service restoration rebuild, clean, and bring systems back online in a prioritized and verified order.
- Business continuity keeps essential functions running during and after the incident, often through alternate processes or sites.
- Evaluation of the recovery itself confirms that services are fully restored, stable, and free of residual compromise before the incident is closed.
References#
- NIST SP 800-61, Computer Security Incident Handling Guide
- NIST SP 800-34, Contingency Planning Guide for Federal Information Systems
- SANS Institute, business continuity and recovery resources