# Recovery Planning Template ## Description Client-fillable template for the recovery objectives, backup alignment, recovery plan, and recovery testing the provider of the offering owns, with sample text, the four KSI-RPL statements it answers, and how the platform evidences the practice. ## Resolution # Recovery Planning Template **TEMPLATE - this document describes practices the provider of the offering owns, outside the GRCITSM platform. Replace the sample text with your organization's actual practice before publishing. The GRCITSM platform evidences these practices through scheduled validation checks; it does not execute them.** ## Purpose This template is the starting point for the recovery planning your organization owns for the cloud service offering: the recovery objectives you commit to, the backup and recovery capability that has to meet them, the recovery plan itself, and the testing that proves the capability works. Recovery is executed by your infrastructure and operations teams against your own environment. Fill in the sample sections with your real objectives, mechanisms, and test schedule, then keep the objectives and the plan in step as the offering changes. ## Requirements this document answers All four are Key Security Indicators in the Recovery Planning family. No FedRAMP Rule (FRR) in the 2026 Consolidated Rules names a recovery document; the obligation is the KSI outcome. | KSI | Name | Statement | |---|---|---| | KSI-RPL-RRO | Reviewing Recovery Objectives | The desired Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and persistently reviewed for alignment with the provider's business needs and capabilities. | | KSI-RPL-ABO | Aligning Backups with Objectives | The alignment of machine-based information resource backups with defined recovery objectives is persistently reviewed. | | KSI-RPL-ARP | Aligning Recovery Plan | The alignment of recovery plans with defined recovery objectives is persistently reviewed. | | KSI-RPL-TRC | Testing Recovery Capabilities | The capability to recover from incidents and contingencies aligned with defined recovery objectives is persistently tested. | "Persistently" is the operative word in all four: each of these is a standing review or test, not a one-time exercise. Set a cadence in the Organization-Defined Values table and hold it. ## Sample practice: recovery objectives **Sample text.** [Organization] defines recovery objectives per service tier. Tier 1 services, which carry federal customer data in the production path, hold an RTO of [duration] and an RPO of [duration]. Tier 2 services hold an RTO of [duration] and an RPO of [duration]. The objectives are set by [role] with [business owner role], and are derived from [basis: customer commitments, contractual SLAs, business impact analysis]. They are reviewed [cadence] and on any material change to the offering's architecture or customer commitments. The review asks two questions: do these objectives still match what the business needs, and can the current capability actually meet them. *Replace with your practice.* State real numbers per tier, name the basis, and name who signs off. An objective nobody can meet is worse than a longer objective you can. ## Sample practice: backups aligned to the objectives **Sample text.** Machine-based information resources are backed up by [mechanism] on a [frequency] schedule, with [retention] retention and copies held in [locations, including a second region or availability zone]. Backup coverage is reconciled against the asset inventory [cadence] so that a resource added to the environment does not sit outside the backup scope. Restore integrity is verified by [verification method] on a [cadence] sample. The reconciliation report states, per tier, the achieved recovery point against the declared RPO and flags any resource whose backup frequency cannot meet its tier's objective. *Replace with your practice.* Name the mechanism, the frequency, the retention, and where copies live. The alignment claim in KSI-RPL-ABO is the comparison between achieved and declared, so make sure something produces that comparison. ## Sample practice: the recovery plan **Sample text.** The [Offering] recovery plan is held at [location] and covers: the recovery sequence by service tier and dependency order, the roles and the activation authority, the alternate processing and storage arrangements, the communications path to agency customers, and the criteria for declaring recovery complete. Each recovery procedure states the objective it serves and the elapsed time it has been observed to take, so a procedure that has drifted past its RTO is visible in the plan itself. The plan is reviewed [cadence] by [role], and after every recovery test and every actual recovery event. *Replace with your practice.* Link the real plan. The alignment claim in KSI-RPL-ARP is between plan and objectives, so the plan needs to carry the objectives it serves rather than reference them elsewhere. ## Sample practice: recovery testing **Sample text.** Recovery capability is tested on a [cadence] schedule. The test program includes [test types: tabletop, functional exercise, full failover, restore-from-backup sampling], scoped so that every Tier 1 service is exercised at least [frequency]. Each test records the scenario, the participants, the measured recovery time and recovery point, the objectives they were compared against, the deficiencies found, and the corrective actions with owners and due dates. Corrective actions are tracked to closure through [tracking mechanism]. Tests that miss an objective trigger either a capability change or an objective change; the plan does not stay in a state where the test and the objective disagree. *Replace with your practice.* Name the test types and cadence, and name where the after-test corrective actions are tracked. Recording the measured time against the objective is what makes the test evidence rather than an attendance record. ## Organization-defined values | Value | Setting | Notes | |---|---|---| | Service tiers in scope | [tiers] | Drives per-tier objectives | | RTO per tier | [durations] | KSI-RPL-RRO | | RPO per tier | [durations] | KSI-RPL-RRO | | Basis for the objectives | [BIA, contractual SLA, customer commitment] | KSI-RPL-RRO | | Objective review cadence | [cadence] | KSI-RPL-RRO, "persistently" | | Backup mechanism and frequency | [mechanism; frequency per tier] | KSI-RPL-ABO | | Backup retention and copy locations | [retention; locations] | KSI-RPL-ABO | | Backup coverage reconciliation cadence | [cadence] | KSI-RPL-ABO | | Restore verification method and cadence | [method; cadence] | KSI-RPL-ABO | | Recovery plan location | [location] | KSI-RPL-ARP | | Recovery plan review cadence | [cadence] | KSI-RPL-ARP | | Recovery test types | [types] | KSI-RPL-TRC | | Recovery test cadence | [cadence] | KSI-RPL-TRC | | Corrective action tracking mechanism | [mechanism] | KSI-RPL-TRC | | Activation authority | [role] | Named in the plan | | Document owner | [role] | Fills the authority section | ## Evidence The GRCITSM platform does not run your backups, hold your recovery plan, or execute your failover. It evidences that the four Recovery Planning indicators are being met, through scheduled machine checks and validation records. See the Continuous Monitoring and Reporting Policy and Procedures for the validation tree and the check cadences. | Practice | What the platform records | |---|---| | Objectives defined and reviewed (KSI-RPL-RRO) | Validation runs on the objective review, with the review as a recurring compliance task | | Backup alignment (KSI-RPL-ABO) | Validation runs from scheduled checks on backup coverage, frequency, and achieved recovery point against the declared RPO | | Plan alignment (KSI-RPL-ARP) | Validation runs on the plan review, with the plan as a Component record of type Plan | | Recovery testing (KSI-RPL-TRC) | Validation runs per test, carrying measured recovery time and pass or fail against the objective; deficiencies open Issues tracked to closure | The recurring compliance task program already carries contingency plan functional exercise testing, contingency plan training, and the annual contingency plan review as scheduled tasks. Those tasks are where your test and review outcomes land as dated evidence. ## Authority, review, and revision *Client fills.* Name the executive who issues this document, the role that owns the recovery plan, the review cadence, and the approval path for exceptions to the objectives. Record the issue date and the revision history below. | Version | Date | Author | Change | |---|---|---|---| | [0.1] | [date] | [author] | Initial draft from template | ## Internal Memo Source: recovery-planning-template.md in the GRCITSM knowledge-base library (species: client-template; editor_type 1 = markdown). Downloaded from the public GRC-ITSM documentation site; body carried verbatim from the library source. Paste the Resolution section as the article body (description_markdown) in your GRCITSM instance and apply the Tags list. ## Tags - GRCITSM Template - Recovery Planning - FedRAMP Rev5 Class C - FedRAMP 20x Class C - KSI-RPL-ABO - KSI-RPL-ARP - KSI-RPL-RRO - KSI-RPL-TRC