Frameworks / ISO 22301:2019 / 8.3.5 What else in your programme already covers this This control maps to 65 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements 9.4.1.1 9.4.1.1 Secure storage location for offline backups 9.4.1.2 9.4.1.2 Annual review of offline backup location security 6.3.3 6.3.3 Timely installation of security patches 6.5.1 6.5.1 Change control procedure for production 6.5.2 6.5.2 Confirm PCI DSS controls after significant change 5.30 ICT readiness for business continuity 5.8 Information security in project management 8.13 Information backup 8.14 Redundancy of information processing facilities 8.32 Change management SOC2-A1.1 A1.1 Managing processing capacity SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-A1.3 A1.3 Testing recovery plan procedures SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure CIS-11.1 Establish and Maintain a Data Recovery Process CIS-11.2 Perform Automated Backups CIS-11.3 Protect Recovery Data CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data CP-6 Alternate Storage Site CP-9 System Backup PE-11 Emergency Power (PE-11) PE-13 Fire Protection CP-6 Alternate Storage Site CP-9 System Backup PE-11 Emergency Power (PE-11) PE-13 Fire Protection 5.30 ICT readiness for business continuity 7.11 Supporting utilities 7.5 Protecting against physical and environmental threats 8.13 Information backup NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations E8-BACKUP-ML1 Regular Backups (ML1) E8-BACKUP-ML3 Regular Backups (ML3) ASD37-34 Regular backups (Essential) ASD37-36 System recovery capabilities (Very Good) BR-1 Ensure regular automated backups BR-2 Protect backup and recovery data CPS230-P41 BCP Execution Capability and Tolerance Breach Reporting CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources A.5.7.3 A.5.7.3 Incident prevention, protection and mitigation 8.3.5 Design and development outputs Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Operation, ISO 22301:2019 You are reading one control. How much of ISO 22301:2019 have you already done? ISO 22301:2019 8.3.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.
Query this from an agent The graph holds this control, the 65 it maps to, and the evidence behind each claim, over MCP and REST.