PPIVTR-D

R. Response (recover)

The model with the Recover segment of the loop highlighted.
Figure 122
STARTS WHENEradication verified.
DONE WHENSystems in production under enhanced monitoring, owner sign-off on file.

Work the checks in order before anything returns to production. The indicator scan comes last, because scanning a half-patched box tells you nothing about the build that ships.

Pre-restoration verification

#Item
1Root cause remediated. Vulnerability patched, credentials rotated, or misconfiguration corrected, matched to the root cause analysis.
2Patching current. Operating system, firmware, and application updates missed while offline.
3Persistence removed. Every identified mechanism confirmed gone.
4Backup validated. For restores, the backup predates initial compromise according to the incident timeline.
5Rebuild verified. For rebuilds, trusted sources and clean installation media.
6Controls live. EDR installed and reporting, host firewall configured, logging enabled.
7Indicator scan, last. Every indicator from scoping and eradication, against the final build.

Then the rest

#Item
8Validation testing performed against a written test plan
9System owner acceptance recorded: what was tested, by whom, limitations accepted, formal sign-off
10Enhanced monitoring configured before go-live: advanced audit policies, PowerShell script block logging on Windows, auditd rules on Linux, logs confirmed flowing to the SIEM
11Detection rules written during contain and eradicate enabled on the restored system
12Production restoration coordinated across teams
13Containment measures removed deliberately, each one decided rather than left in place
14Recovery metrics captured for the debrief