ISO 22301:2019
Operation, ISO 22301:2019

ISO 22301:2019 8.3.3: Selection of strategies and solutions

Select from the identified candidates on the extent to which they meet the required time frames and agreed capacity, fit the amount and type of risk the organization is prepared to take, and stand up on associated costs and benefits.

What else in your programme already covers this

This control maps to 38 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

  • NIST800-CP-11 Alternate Communications Protocols. Provide the capability to employ [organization-defined] in support of maintaining continuity of operations
  • NIST800-CP-2 Contingency plan
  • NIST800-CP-7 Alternate processing site
  • NIST800-PE-17 Alternate work site
  • NIST800-RA-7 Risk response
  • NIST800-SA-24 Design For Cyber Resiliency. Design organizational systems, system components, or system services to achieve cyber resiliency by: Defining the following cyber resiliency goals: [organization-defined]. Defining the following cyber resiliency objectives: [organization-defined]. Defining the following
  • NIST800-SC-47 Alternate Communications Paths. Establish [organization-defined] for system operations organizational command and control
  • NIST800-SI-22 Information Diversity. Identify the following alternative sources of information for [organization-defined]: [organization-defined] ; and Use an alternative information source for the execution of essential functions or services on [organization-defined] when the primary source of

ISO 27001:2022 · 4 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 7.11 Supporting utilities
  • 8.14 Redundancy of information processing facilities

ISO 27002:2022 · 4 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup
  • 8.14 Redundancy of information processing facilities

FedRAMP High · 3 controls

  • CP-2(3) Resume Mission and Business Functions
  • CP-7 Alternate Processing Site
  • CP-7(1) Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats

FedRAMP Moderate · 3 controls

  • CP-2(3) Resume Mission and Business Functions
  • CP-7 Alternate Processing Site
  • CP-7(1) Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats
  • CP-2(3) Resume Mission and Business Functions
  • CP-7 Alternate Processing Site
  • CP-7(1) Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats
  • CP-2(3) Resume Mission and Business Functions
  • CP-7 Alternate Processing Site
  • CP-7(1) Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats

ISO 19011:2018 · 2 controls

  • 5.5.3 Selecting and determining audit methods
  • 7.4 Selecting appropriate auditor evaluation method

SOC 2 · 2 controls

  • SOC2-CC5.1 COSO principle 10: Selects and develops control activities to mitigate risks
  • SOC2-CC9.1 Identifies, selects and develops risk mitigation activities
  • CFTC-SS-26 Own Resources or Contractual Arrangements to Meet the Recovery Objective

CIS Controls v8 · 1 control

  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data

ISO 9001:2015 · 1 control

  • 8.3.3 Design and development inputs
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operation, ISO 22301:2019

You are reading one control. How much of ISO 22301:2019 have you already done?

ISO 22301:2019 8.3.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.

Query this from an agent

The graph holds this control, the 38 it maps to, and the evidence behind each claim, over MCP and REST.