NIST SP 800-53 Rev. 5 · Contingency Planning
CP-9 — System Backup
Backup missing for assets requiring it. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.
Why this matters
A critical system whose backups have silently been failing
Backups are usually configured once and then trusted. A backup job that begins failing does so quietly, and the failure is typically discovered at the worst possible moment — during an attempted recovery after ransomware or hardware loss.
Why this check earns its place. It checks that backups actually succeeded recently, rather than that a backup was configured at some point.
- What it reads
- The organization's own backup job history, compared against its inventory of systems that require backup.
- What it reports
- Systems that require a backup and have no recent successful one.
See related public disclosures on the Signals page →
The requirement
The organization must conduct backups of user-level, system-level, and system documentation information at an organization-defined frequency, and protect the confidentiality, integrity, and availability of backup information.
NIST SP 800-53 Rev. 5 — CP-9 (System Backup).
NIST requires backups at a defined frequency. Which assets require backup, the recovery point objective per asset, and what counts as a successful backup are organization-defined — supplied through the asset inventory.
What a check finds
Asset declared as requiring backup has no successful backup within twice its recovery point objective.
Choose your platform
CISA performance goals
- 3.O — Maintain system backups & restoration ability
What a result does not prove
Absence of a backup job record does not establish that data is unrecoverable. It establishes that recoverability cannot be evidenced from the queried source — which for a resilience control is the question that matters at review.