The organization must fix and record what its OR management system covers: which parts of the organization fall inside it (all of it or named parts); the resilience requirements that flow from its mission, aims, duties to stakeholders and legal obligations; the objectives, assets, functions, services and products critical to its operations; the risk scenarios, from events inside or outside, that could strike them; and a coverage suited to its size, nature and complexity. The scope must safeguard the organization's integrity and its ties with suppliers, outsourcing partners, customers, shareholders and the community, and a Statement of Applicability must set, on the strength of the risk assessment and impact analysis, how much strategic weight goes to each of security, preparedness, emergency, disaster, crisis and business continuity management.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.