C5 (Germany) C5-BCM-02: Business impact analysis policies and instructions
Document, communicate and provide business impact analysis rules covering risk based scenarios, critical products and services, dependencies, threats, effects of planned and unplanned outages over time, maximum tolerable outage, restoration priorities, recovery time and data loss targets, and resources needed to resume.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 45 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
You are reading one control. How much of C5 (Germany) have you already done?
C5 (Germany) C5-BCM-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of C5 (Germany) your existing evidence covers. Hold Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 and 95 of 121 C5 (Germany) controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 pair alone.