# RC — Recover

- **Function ID:** RC

## Subcategories

- [RC.CO-03](/md/csf/RC.CO-03.md) — Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
- [RC.CO-04](/md/csf/RC.CO-04.md) — RC.CO-04
- [RC.RP-01](/md/csf/RC.RP-01.md) — The recovery portion of the incident response plan is executed once initiated from the incident response process
- [RC.RP-02](/md/csf/RC.RP-02.md) — Recovery actions are selected, scoped, prioritized, and performed
- [RC.RP-03](/md/csf/RC.RP-03.md) — The integrity of backups and other restoration assets is verified before using them for restoration
- [RC.RP-04](/md/csf/RC.RP-04.md) — Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
- [RC.RP-05](/md/csf/RC.RP-05.md) — The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
- [RC.RP-06](/md/csf/RC.RP-06.md) — The end of incident recovery is declared based on criteria, and incident-related documentation is completed

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
