The organization should keep procedures for preventing events, being ready for them and responding to them, so the PAP system stays intact and working when situations affect it. It should set, document and implement a command and control structure with cross-discipline, cross-functional teams holding the resources, authority, experience and competence to: establish the nature and scale of a disruptive event and trigger controls; coordinate the response across functions and disciplines (for example with risk management, IT and business continuity); run the plans, processes and procedures for activating, operating, coordinating and communicating prevention, protection, mitigation, response and recovery; keep internal and external stakeholders informed, including the media, local authorities and supply chain partners; and judge the level of response, with authority to set actions for each stage and declare the situation over. Its procedures should address: protection of tangible and intangible assets; protection of people; the best ways to mitigate and respond so an event does not grow into a crisis or disaster; who may judge that an emergency exists and declare it, and how, then activate plans, assess damage and take financial decisions for continuity; internal and external communication plans, including notifying authorities and stakeholders; actions to secure physical and information assets; post-event evaluation leading to corrective and preventive action; periodic testing of the PPS in normal and abnormal conditions; the effect on the PAP system of losing critical infrastructure (power, water, communications, transport) and other dependencies such as IT; and the steps and resources for bringing the PAP system back within its recovery time objective. Procedures should be reviewed and revised, especially after incidents that escalated or nearly did, documented and updated regularly or when things change, and incident reports should feed management review.
This control maps to 4 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.