The business continuity policy and scope are defined in line with the objectives of the enterprise and its stakeholders so that business resilience improves: the business processes and service activities, in-house and outsourced, that are critical to operations or needed to meet legal and contractual obligations are identified; key stakeholders are identified, along with the roles and responsibilities for setting and agreeing the policy and scope; the minimum objectives and scope for resilience that have been agreed are defined and documented; and the essential supporting processes and I&T services are identified.
This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.