APRA CPS 230 Operational Risk Management
Business Continuity

APRA CPS 230 Operational Risk Management CPS230-26: Critical Operations Register, Continuity Plan and Activation

The entity must define, identify and maintain a register of its critical operations, take reasonable steps to minimise the likelihood and impact of disruption to them, maintain a credible business continuity plan setting out how it would hold critical operations within tolerance levels through disruption including disaster recovery planning for critical information assets, activate that plan when needed and return to normal operations promptly.

What else in your programme already covers this

This control maps to 112 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 5 controls

  • 4.3.1 General
  • 4.3.2 Scope of the business continuity management system
  • 8.2.2 Business impact analysis
  • 8.4 Business continuity plans and procedures
  • 8.4.4 Business continuity plans

HIPAA Security Rule · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

  • NIST800-CP-1 Policy and procedures for contingency planning
  • NIST800-CP-2 Contingency plan
  • NIST800-PM-8 Critical Infrastructure Plan. Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan
  • NIST800-RA-9 Criticality analysis

NIST SP 800-66 Rev 2 · 4 controls

FedRAMP High · 3 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions

FedRAMP Moderate · 3 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions

ISO 22316 · 3 controls

  • ISO22316-01 Organizational resilience and security - business continuity policy for building security and resilience
  • ISO22316-14 Supply chain continuity
  • ISO22316-15 Communication strategy during disruption

ISO 22317 · 3 controls

ISO 22318 · 3 controls

ISO/IEC 27031:2011 · 3 controls

  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions
  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions
  • ASBv3-GS-8 Define and implement backup and recovery strategy
  • BR-1 Ensure regular automated backups

C5 (Germany) · 2 controls

  • C5-BCM-02 Business impact analysis policies and instructions
  • C5-BCM-03 Planning business continuity
  • CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources

DORA · 2 controls

  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures

ISO 27002:2022 · 2 controls

  • 5.29 Information security during disruption
  • 5.9 Inventory of information and other associated assets

NIST SP 800-161 Rev 1 · 2 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan

PCI P2PE · 2 controls

PCI PIN Security · 2 controls

PCI SSF · 2 controls

APRA CPS 234 · 1 control

  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • 4.4.8 Business Continuity and Recovery

CIS Controls v8 · 1 control

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)

GLBA · 1 control

HKMA SPM · 1 control

ISO 27001:2022 · 1 control

  • 5.29 Information security during disruption

ISO/IEC 27010:2015 · 1 control

  • NIS2I-3 Incident Handling Policy, Reporting Significance Criteria, and Business Continuity
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

SOC 2 · 1 control

  • SOC2-CC9.1 Identifies, selects and develops risk mitigation activities

South Korea ISMS-P · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Business Continuity

You are reading one control. How much of APRA CPS 230 Operational Risk Management have you already done?

APRA CPS 230 Operational Risk Management CPS230-26 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of APRA CPS 230 Operational Risk Management your existing evidence covers. Hold NIST Cybersecurity Framework 2.0 and 30 of 43 APRA CPS 230 Operational Risk Management controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 4 were rejected on the NIST Cybersecurity Framework 2.0 pair alone.

Query this from an agent

The graph holds this control, the 112 it maps to, and the evidence behind each claim, over MCP and REST.