Services important to the enterprise are identified, services and resources mapped to business processes with their dependencies, and the impact of unavailable resources fully agreed and accepted by the customer, with the business impact of prolonged unavailability assessed for critical business functions: only the solutions and services critical to availability and capacity management are selected; they are mapped to the applications and IT and facility infrastructure they depend on; availability patterns are collected from failure logs and performance monitoring with modelling tools predicting failure from past usage and management's expectations of the new environment; scenarios describe future availability situations and the capacity levels needed to meet the objective; the likelihood of not meeting the objective is determined; the scenarios' impact on business performance measures (revenue, profit, customer service) is determined with business-line, functional and regional leaders engaged; and process owners understand and agree the analysis and provide the list of unacceptable risk scenarios requiring a response.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.