C5 (Germany)
C5: Business Continuity Management

C5 (Germany) C5-BCM-02: Business impact analysis policies and instructions

Document, communicate and provide business impact analysis rules covering risk based scenarios, critical products and services, dependencies, threats, effects of planned and unplanned outages over time, maximum tolerable outage, restoration priorities, recovery time and data loss targets, and resources needed to resume.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 45 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 6 controls

  • 4.3.2 Scope of the business continuity management system
  • 4.4 Business continuity management system
  • 5.2.1 Establishing the business continuity policy
  • 6.2.2 Determining business continuity objectives
  • 8.2.1 General
  • 8.2.2 Business impact analysis
  • CPS230-19 Tolerance Levels for Each Critical Operation
  • CPS230-20 Prevention, Adaptation and Return to Normal Operations
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • CPS230-34 Tailoring of the Testing Program
  • CPS230-P18 Integration with the Risk Management Framework and Recovery Planning

FedRAMP High · 4 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • RA-9 Criticality Analysis (RA-9)

FedRAMP Moderate · 4 controls

  • CP-1 Policy and Procedures
  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • RA-9 Criticality Analysis (RA-9)
  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
  • NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 800-53 Rev 5 · 4 controls

  • CFTC-SS-25 Same Day Recovery Time Objective for Critical Entities
  • CFTC-SS-29 Recovery Plan Accounts for Essential Service Providers
  • CFTC-SS-9 Next Business Day Recovery Time Objective

NIST SP 800-161 Rev 1 · 3 controls

  • CCM-BCR-01 Business Continuity Management Policy and Procedures
  • CCM-BCR-02 Risk Assessment and Impact Analysis
  • CPS220-14 Scenario Analysis and Stress Testing Programs
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASBv3-GS-8 Define and implement backup and recovery strategy

DORA · 1 control

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 5.30 ICT readiness for business continuity

ISO 27002:2022 · 1 control

  • 5.30 ICT readiness for business continuity

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management

SOC 2 · 1 control

  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in C5: Business Continuity Management

You are reading one control. How much of C5 (Germany) have you already done?

C5 (Germany) C5-BCM-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of C5 (Germany) your existing evidence covers. Hold Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 and 95 of 121 C5 (Germany) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 pair alone.

Query this from an agent

The graph holds this control, the 45 it maps to, and the evidence behind each claim, over MCP and REST.