Authorised Economic Operator (AEO) Programmes - Global Standards
AEO Conditions and Requirements (SAFE Annex IV)

Authorised Economic Operator (AEO) Programmes - Global Standards AEO-12: Crisis Management and Incident Recovery

The operator and Customs develop and document contingency plans for emergency security situations and for disaster or incident recovery, with periodic training of employees so the plans can be executed.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 30 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 3 controls

  • 8.4.2 Response structure
  • 8.4.4 Business continuity plans
  • 8.5 Exercise programme

ISO 27001:2022 · 3 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

ISO 27002:2022 · 3 controls

  • 5.24 Information security incident management planning and preparation
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

SOC 2 · 3 controls

  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption

CIS Controls v8 · 2 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-17.4 Establish and Maintain an Incident Response Process

FedRAMP High · 2 controls

  • CP-2 Contingency Plan
  • CP-3 Contingency Training

FedRAMP Moderate · 2 controls

  • CP-2 Contingency Plan
  • CP-3 Contingency Training
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process

NIST SP 800-53 Rev 5 · 2 controls

  • ASBv3-IR-1 Preparation - update incident response plan and handling process

CMMC 2.0 · 1 control

HIPAA Security Rule · 1 control

PCI DSS 4.0 · 1 control

  • 12.10.1 12.10.1 Incident response plan ready for activation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AEO Conditions and Requirements (SAFE Annex IV)

Query this from an agent

The graph holds this control, the 30 it maps to, and the evidence behind each claim, over MCP and REST.