Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue
CP: Contingency planning – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue CP-02: CP-02 Contingency plan

The organisation develops a contingency plan that identifies essential functions and contingency requirements, sets recovery objectives, restoration priorities and metrics, assigns roles with contacts, addresses continuing essential functions through disruption, compromise or failure and full restoration without degrading controls, covers data integrity including personal information and the consequences of compromise including for personal information, addresses sharing of contingency information, and is approved by defined roles. The plan is distributed to key personnel, understood by those with roles, coordinated with incident handling, reviewed at a set frequency, updated for organisational, system and environmental changes and problems found, with changes communicated and lessons from tests, training and real events incorporated. Canada-specific addition: the plan is protected from unauthorized disclosure and modification. 8 enhancements.

Maintained by Gerard Blokdyk

Other controls in CP: Contingency planning – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.