BS 65000:2014 - Guidance on Organizational Resilience
Resilience Model

BS 65000:2014 - Guidance on Organizational Resilience RM-03: Leadership and Culture

Board-level ownership of resilience. Culture of awareness, learning, and adaptation. Employee empowerment to identify and escalate risks. Investment in resilience capabilities.

What else in your programme already covers this

This control maps to 101 controls across 53 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

SOC 2 · 3 controls

  • SOC2-A1.1 Maintains capacity to meet availability commitments
  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-A1.3 Recovery plan procedures support system recovery from failures

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO/IEC 27031:2011 · 2 controls

  • NISTPF-6 Protect-P Data Security (PR.DS-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

OSFI B-13 · 2 controls

  • OSFIB13-4 Third-Party Risk Management and Cloud
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination

Open Banking Security · 2 controls

  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

SASB Standards · 2 controls

  • SOCI-S30BC Notification of critical cyber security incidents (12 hours)
  • SOCI-S30BD Notification of other cyber security incidents (72 hours)
  • ASD37-20 Multi-factor authentication (Essential)

COBIT 2019 · 1 control

  • CAT-D5-4 Resilience planning and testing

GLBA · 1 control

HKMA SPM · 1 control

IEEE 7000 · 1 control

ISO 20000-1 · 1 control

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

Japan AI Guidelines · 1 control

MTCS (Singapore) · 1 control

  • NATO-NCIRC-8 Cyberspace as Operational Domain + Cyber Defence Pledge + Annual Self-Assessment
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • SSAE18-A1.1 A1.1 - Availability Commitments and Requirements
  • SAPAIA-2 Right of Access and Request Processes
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)
  • UKAI-3 Bias Detection, Fairness, Validation
  • UKOPRES-5 Third-Party Risk, Concentration Risk

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Resilience Model

Query this from an agent

The graph holds this control, the 101 it maps to, and the evidence behind each claim, over MCP and REST.