RC.RP-01 RC · Recover · RC.RP Incident Recovery Plan Execution

RC.RP-01 — Recovery plan execution

The recovery portion of the incident response plan is executed once initiated from the incident response process.

Also written as RC-RP-01, RC.RP-1, CSF 2.0 RC.RP-01, NIST CSF RC.RP.

What NIST CSF RC.RP-01 means

RC.RP-01 is one of 8 subcategories in the Recover (RC) function, under the Incident Recovery Plan Execution category (RC.RP). The Core states: “The recovery portion of the incident response plan is executed once initiated from the incident response process.” Recover outcomes are the least frequently tested in practice and the most commonly assumed — restoration evidence from a real test, not a backup job that reports success, is what demonstrates the outcome.

Evidence that supports RC.RP-01

To demonstrate this outcome in an assessment or audit, gather artefacts such as:

  • Recovery plan invocation records post-incident
  • Recovery task tracking to completion
  • Recovery team activation logs

ISO 27001 mapping

RC.RP-01 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.29, A.5.30. Evidence collected for one framework typically supports the other.

Map RC.RP-01 to ISO 27001 & SOC 2 →
Crosswalk this subcategory in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against RC.RP-01 in the Risk Register.

Other Incident Recovery Plan Execution subcategories

RC.RP-02 Recovery actions selected and prioritized RC.RP-03 Backup and asset integrity verified before restore RC.RP-04 Post-incident operational norms restored RC.RP-05 Asset integrity confirmed and services restored RC.RP-06 Recovery completion declared

All 8 Recover subcategories →

Frequently asked questions

Is NIST CSF RC.RP-01 mandatory?

No. CSF 2.0 is a voluntary framework of outcomes rather than a set of requirements, and there is no certification against it. RC.RP-01 becomes binding only when something else makes it so — a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

How is RC.RP-01 assessed?

Through profiles rather than pass/fail testing. You record how fully the outcome is achieved today in a Current Profile, state where it needs to be in a Target Profile, and the gap between them becomes your action plan. Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your governance around the outcome is, not whether you have met it.

Who owns RC.RP-01?

The Recover function is normally owned by the security or IT function, but RC.RP-01 still needs a specific named owner. Assessors treat an outcome with no owner as not achieved regardless of the tooling behind it, so record ownership in your profile alongside the assessment.

Does NIST CSF RC.RP-01 map to ISO 27001?

Yes — RC.RP-01 corresponds to ISO 27001:2022 Annex A control(s) A.5.29, A.5.30. Evidence collected for one framework typically supports the other, so a single control library can serve both.