Controls/Monitoring & Response/10.5
L2 StandardManual verification

10.5 Recovery and Rollback

10. Monitoring & ResponseHow do we detect and respond?

Description

Agents MUST support recovery to a known-good state.

Rationale

After an incident, rapid recovery reduces downtime and removes compromised configurations.

Audit Procedure

1. Verify rollback mechanism exists
2. Check backup procedures
3. Verify memory/context can be reset

Remediation

1. Implement version rollback
2. Backup configurations regularly
3. Implement context/memory reset

Framework Mappings

CIS Control 11NIST RC.RP-1