Apply the criteria for initiating incident recovery
Moving to recovery too early can reintroduce threats before they are fully eradicated, while waiting too long prolongs downtime and business impact. Defined recovery criteria give the incident commander a clear checklist of conditions that must be satisfied before systems are restored. This control prevents the common mistake of declaring an incident over based on intuition rather than verified evidence of containment and remediation.
Implementation steps
- 1
Document recovery initiation criteria in the IR plan
Define the specific conditions that must be met before recovery begins. These typically include: threat actor removed from environment, all affected systems identified, root cause determined, and relevant stakeholders have approved the transition to recovery.
confluencenotiongoogle-docs - 2
Conduct a pre-recovery checklist review
Before initiating recovery, the incident commander runs through the documented checklist with the response team. Each criterion is confirmed as met or acknowledged as an accepted exception with documented rationale.
jiraservicenowconfluence - 3
Record the recovery decision and transition the incident
Document the outcome of the pre-recovery review in the incident ticket, including who approved the transition and which checklist items were satisfied. Update the incident status to reflect the move from response to recovery phase.
jiraservicenowpagerduty
Evidence required
Recovery initiation checklist records
Completed checklists or approval records showing that defined criteria were met before recovery was started.
- · Jira or ServiceNow ticket with recovery approval sign-off
- · Completed IR checklist attached to the incident record
- · Meeting notes or chat log showing team confirmation of recovery criteria
Documented recovery criteria
A written definition of the conditions that must be satisfied before incident recovery may begin.
- · IR plan or playbook section defining recovery entry criteria
- · Confluence page listing required pre-recovery verification steps
- · Incident closure policy with approval workflow
Related controls
Execute the incident response plan in coordination with relevant third parties
Incident Management
Triage and validate incident reports
Incident Management
Categorize and prioritize incidents
Incident Management
Escalate or elevate incidents as needed
Incident Management