Options for business resilience are evaluated and a viable, cost-effective strategy is selected that keeps continuity, incident response and disaster recovery working through a disaster or other serious incident: scenarios likely to cause significant disruption are identified; a business impact analysis assesses how disruption to critical functions affects the business over time; the shortest time in which a process and its supporting I&T must be recovered is set from the acceptable length of interruption and the maximum tolerable outage; the conditions for invoking the plans, and who owns that decision, are determined; the likelihood of threats that would cause a loss of continuity is assessed, and measures to lower likelihood and impact through prevention and resilience are identified; continuity requirements are analysed against strategic business and technical options; each option's resource requirements and costs are identified and recommendations made; and executive business approval is secured for the chosen options.
This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.