NIST SP 800-53 Rev. 5 · Contingency Planning

CP-9 — System Backup

Backup missing for assets requiring it. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.

Why this matters

A critical system whose backups have silently been failing

Backups are usually configured once and then trusted. A backup job that begins failing does so quietly, and the failure is typically discovered at the worst possible moment — during an attempted recovery after ransomware or hardware loss.

Why this check earns its place. It checks that backups actually succeeded recently, rather than that a backup was configured at some point.

What it reads
The organization's own backup job history, compared against its inventory of systems that require backup.
What it reports
Systems that require a backup and have no recent successful one.

See related public disclosures on the Signals page →

The requirement

The organization must conduct backups of user-level, system-level, and system documentation information at an organization-defined frequency, and protect the confidentiality, integrity, and availability of backup information.

NIST SP 800-53 Rev. 5 — CP-9 (System Backup).

NIST requires backups at a defined frequency. Which assets require backup, the recovery point objective per asset, and what counts as a successful backup are organization-defined — supplied through the asset inventory.

What a check finds

Asset declared as requiring backup has no successful backup within twice its recovery point objective.

Choose your platform

CISA performance goals

  • 3.O — Maintain system backups & restoration ability

Full coverage map →

What a result does not prove

Absence of a backup job record does not establish that data is unrecoverable. It establishes that recoverability cannot be evidenced from the queried source — which for a resilience control is the question that matters at review.