← CISSP: security, risk, and operations
07 / 10 · 30 MIN

Operations, incidents, and recovery

Coordinate containment and continuity with measurable recovery criteria.

Concept and mechanism

Incident response needs preparation, authority, and coordination before an alert. Use the approved plan to reduce impact, preserve evidence, and inform technical and business owners. A credible alert alone does not explain the complete cause. Reinstallation without collection can destroy the only available information. When logs come from misaligned clocks, keep original timestamps, document offset, and create traceable correlation. In an AI service, quality change or drift should prompt investigation; it does not alone prove attack. NIST SP 800-61 revision 3 frames response within risk management and CSF 2.0; this path uses that current reference without imposing a rigid sequence that ignores parallel actions needed in a real situation.

Guided application

Distinguish recovery time from recoverable data point. If an outage starts at 09:00 and service is validated at 09:38, 38 minutes elapsed. If data reaches only 08:51, potential loss is 9 minutes. With 45-minute RTO and 5-minute RPO, the first objective is met and the second misses by 4 minutes. A green dashboard does not change that conclusion. Test restoration with dependencies, credentials, and functional validation. Protect copies against the same identity that can compromise production. After an emergency change, review and reconcile configuration so mitigation does not disappear at the next deployment and the service has a known state.

IN PRACTICE

A completed backup still needs usable restoration; the production administrator account should not be able to destroy every recovery option alone.

Common pitfalls

Alert treated as complete cause; destroying before preserving; RTO confused with RPO; green backup treated as proven restore; unowned drift.

Related topics: Secure software and supply chain · Governance, ethics, and risk decisions

Take this idea with you

Recovery means validated service and data with evidence and assigned prevention actions.

Create account

Reference: Incident Response Recommendations and Considerations · CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29