FFIEC IT Examination Handbook
FFIEC IT Examination Handbook: Operational Resilience

FFIEC IT Examination Handbook FFIEC-11: Business continuity planning and testing

Business continuity planning and testing. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.

What else in your programme already covers this

This control maps to 137 controls across 63 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27031:2011 · 5 controls

PCI PIN Security · 5 controls

  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • 4.4.8 Business Continuity and Recovery

PCI SSF · 4 controls

ISO 22316 · 3 controls

  • ISO22316-01 Organizational resilience and security - business continuity policy for building security and resilience
  • ISO22316-14 Supply chain continuity
  • ISO22316-15 Communication strategy during disruption

ISO 22317 · 3 controls

ISO 22318 · 3 controls

  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained

OSFI B-13 · 3 controls

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OSFIB13-4 Third-Party Risk Management and Cloud
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination

PCI P2PE · 3 controls

SOC 2 · 3 controls

  • SOC2-A1.1 Maintains capacity to meet availability commitments
  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-A1.3 Recovery plan procedures support system recovery from failures

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience
  • NISTPF-6 Protect-P Data Security (PR.DS-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

Open Banking Security · 2 controls

  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

SASB Standards · 2 controls

  • SOCI-S30BC Notification of critical cyber security incidents (12 hours)
  • SOCI-S30BD Notification of other cyber security incidents (72 hours)
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation

COBIT 2019 · 1 control

  • CAT-D5-4 Resilience planning and testing
  • FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)

GLBA · 1 control

HKMA SPM · 1 control

IEEE 7000 · 1 control

ISO 20000-1 · 1 control

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 27010:2015 · 1 control

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

Japan AI Guidelines · 1 control

MTCS (Singapore) · 1 control

  • NATO-NCIRC-8 Cyberspace as Operational Domain + Cyber Defence Pledge + Annual Self-Assessment
  • NIS2I-3 Incident Handling Policy, Reporting Significance Criteria, and Business Continuity
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • SSAE18-A1.1 A1.1 - Availability Commitments and Requirements
  • SAPAIA-2 Right of Access and Request Processes

South Korea ISMS-P · 1 control

  • UKAI-3 Bias Detection, Fairness, Validation
  • UKOPRES-5 Third-Party Risk, Concentration Risk

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in FFIEC IT Examination Handbook: Operational Resilience

Query this from an agent

The graph holds this control, the 137 it maps to, and the evidence behind each claim, over MCP and REST.