Use the impact analysis to set continuity priorities and requirements: settle which types of impact matter in the organization's context and the criteria for judging them; identify the activities that support delivery of products and services; assess how the impact of disrupting those activities grows over time; fix the point beyond which failing to resume would be unacceptable; within that point, set prioritized time frames for resuming the activities at a stated minimum capacity that is still acceptable; identify the prioritized activities; and establish the resources, dependencies and interdependencies they need, partners and suppliers included.
This control maps to 74 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
You are reading one control. How much of ISO 22301:2019 have you already done?
ISO 22301:2019 8.2.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.