ASD Strategies to Mitigate Cyber Security Incidents
Recovering Data and System Availability

ASD Strategies to Mitigate Cyber Security Incidents ASD37-35: Business continuity and disaster recovery plans (Very Good)

Business continuity and disaster recovery plans which are tested, including for the scenario of a complete loss of computing capabilities.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 209 controls across 101 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
  • NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

ISO/IEC 27031:2011 · 6 controls

  • 27031-7.1 IRBC Strategy
  • 27031-7.2 Resource Requirements
  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • 27031-D Developing performance criteria

ISO 22316 · 5 controls

  • ISO22316-01 Organizational resilience and security - business continuity policy for building security and resilience
  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities
  • ISO22316-14 Supply chain continuity
  • ISO22316-15 Communication strategy during disruption

ISO/TS 22317:2021 · 5 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-11 Continuity strategy development
  • ISO22317-12 Recovery strategy for critical activities
  • ISO22317-14 Supply chain continuity
  • ISO22317-15 Communication strategy during disruption

ISO/TS 22318:2021 · 5 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • ISO22318-13 Alternate site and resource planning
  • ISO22318-14 Supply chain continuity
  • ISO22318-15 Communication strategy during disruption

HIPAA Security Rule · 4 controls

ISO 22301:2019 · 4 controls

  • 8.4 Business continuity plans and procedures
  • 8.4.4 Business continuity plans
  • 8.5 Exercise programme
  • 8.6 Evaluation of business continuity documentation and capabilities
  • NFPA1600-4.1 Leadership and Commitment
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.2 Crisis Management and Communications
  • NFPA1600-6.4 Continuity and Recovery

NIST SP 800-53 Rev 5 · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

C5 (Germany) · 3 controls

  • C5-BCM-02 Business impact analysis policies and instructions
  • C5-BCM-03 Planning business continuity
  • C5-BCM-04 Verification, updating and testing of the business continuity

FedRAMP High · 3 controls

  • CP-2 Contingency Plan
  • CP-2(1) Coordinate with Related Plans
  • CP-4 Contingency Plan Testing

FedRAMP Moderate · 3 controls

  • CP-2 Contingency Plan
  • CP-2(1) Coordinate with Related Plans
  • CP-4 Contingency Plan Testing

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-CP-9 System Backup
  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FedRAMP-IncidentReporting FedRAMP incident reporting to PMO and US-CERT

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • ISO-22313-5.2 Policy
  • ISO-22313-6.2 Business continuity objectives and plans to achieve them
  • ISO-22313-6.3 Planning changes to the BCMS

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

NIST SP 1800-32 · 3 controls

  • PICERL-C2 System Backup
  • PICERL-R1 System Restoration
  • PICERL-R2 Security Verification

SOC 2 · 3 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • SSAE18-A1.2 A1.2 - Environmental Protections and Recovery
  • SSAE18-A1.3 A1.3 - Recovery Plan Testing
  • SSAE18-CC7.5 CC7.5 - Incident Recovery
  • IM8-RES.1 Business Continuity Planning
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing

CIS Controls v8 · 2 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-11.5 Test Data Recovery

CMMC 2.0 · 2 controls

  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • IMO-MSC-FAL-Recover-BackupRestore-ContinuityOfNavigation-LessonsLearned-Drills IMO MSC-FAL Recover Function - Backup and Restore + Continuity of Navigation + Continuity of Cargo Operations + Continuity of Propulsion + Lessons Learned + Drills + Resilience
  • IMO-MSC-FAL-Respond-IncidentResponse-Communication-FlagState-PortAuthority-CIRT-USCGNVIC IMO MSC-FAL Respond Function - Incident Response Plan + Containment + Communication + Flag State + Port Authority + USCG NVIC + Class Society Notification + CIRT

ISO 27001:2022 · 2 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

ISO 27002:2022 · 2 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

NIST SP 800-161 Rev 1 · 2 controls

  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development

PCI P2PE · 2 controls

  • PCI-P2PE-11 Business continuity planning and testing
  • PCI-P2PE-12 Disaster recovery procedures

PCI PIN Security · 2 controls

  • PCI-PIN-11 Business continuity planning and testing
  • PCI-PIN-12 Disaster recovery procedures

PCI SSF · 2 controls

  • PCI-SSF-11 Business continuity planning and testing
  • PCI-SSF-12 Disaster recovery procedures

South Korea ISMS-P · 2 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • E8-BACKUP-ML1 Regular Backups (ML1)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • 4.4.8 Business Continuity and Recovery
  • BS65000-RM-02 Integrated Approach
  • DIQ-1 Data Integration and Interoperability
  • FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)
  • GAMP5-Supplier-Operations-Change-Periodic Supplier Assessment, Operational Phase, Change Control and Periodic Review

GLBA · 1 control

  • GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines
  • HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing

HKMA SPM · 1 control

  • HKMA-SPM-OR-RR-SA-OperationalResilience HKMA SPM Operational Risk (OR-1), Operational Resilience (OR-2), Recovery Planning (RR-1), Outsourcing (SA-2)
  • IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned

IEEE 1686 · 1 control

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills

ISMAP (Japan) · 1 control

  • ISO-15189-7.8 Continuity and emergency preparedness

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process
  • ISO28001-PC-04 Supply Chain Continuity Planning

ISO/IEC 27010:2015 · 1 control

  • 27010-17.1 Compliance

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup

ISO/IEC 27043:2015 · 1 control

  • ISO27043-23 Backup and recovery procedures

ISO/SAE 21434 · 1 control

  • ISO21434-23 Backup and recovery procedures
  • JP-FSA-CYB-Incident-Response-Playbooks-Containment-Eradication-Recovery-Post-Mortem-Tabletop-CSIRT Japan FSA Cybersecurity Incident Response + Playbooks + Containment + Eradication + Recovery + Post-Mortem + Tabletop Exercises + CSIRT + FSA Notification + Customer Communication + Forensics + Lessons Learned

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA
  • MAS-TRM-Reliability-Data-Centre-Chapters-7-8-RTO-RPO-BCP-DR-System-Availability-4-Hours-12-Months MAS TRM Reliability + Data Centre + Chapters 7-8 + RTO + RPO + BCP + DR + System Availability 4 Hours 12 Months
  • NABERS-3 NABERS Water Performance Rating
  • NAIC-5 Third Party Service Provider Oversight - Section 4(F)(3) and Section 5

NERC CIP · 1 control

  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 1 control

  • NISTSP137-7 Incident Response Integration and Ongoing Authorization

NIST SP 800-144 · 1 control

  • NISTSP144-6 Availability, Resilience, BCP/DR, and SLA Management

NIST SP 800-145 · 1 control

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management

NIST SP 800-146 · 1 control

  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability

NIST SP 800-190 · 1 control

  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity

NIST SP 800-88 · 1 control

  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records

NIST SP 800-92 · 1 control

  • NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP ASVS · 1 control

OWASP MASVS · 1 control

  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

OpenSSF Scorecard · 1 control

  • OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

PTES · 1 control

  • PTESPHASE-3 Threat Modeling
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Recovering Data and System Availability

You are reading one control. How much of ASD Strategies to Mitigate Cyber Security Incidents have you already done?

ASD Strategies to Mitigate Cyber Security Incidents ASD37-35 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ASD Strategies to Mitigate Cyber Security Incidents your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 32 of 37 ASD Strategies to Mitigate Cyber Security Incidents controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 209 it maps to, and the evidence behind each claim, over MCP and REST.