A business continuity plan and a disaster recovery plan are developed from the strategy, recording every procedure needed to keep critical activities going during an incident: incident response actions and communications are defined, along with roles, responsibilities and accountability for policy and implementation; key suppliers and outsourcing partners are required to have effective continuity plans of their own, with audited evidence where required; the conditions and procedures for resuming processing are defined, including updating and reconciling databases so integrity is preserved; operational plans set out procedures for keeping critical processes running or for temporary arrangements, including links to the plans of outsourced providers; the people, facilities and infrastructure required are defined and documented; backup requirements supporting the plans cover data and also the plans themselves and paper documents, with security and off-site storage; the skills needed by those carrying out the plan are determined; and the plans are distributed securely to authorised parties and can be reached in any disaster scenario.
This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.