ISO 22301:2019
Operation, ISO 22301:2019

ISO 22301:2019 8.4.2: Response structure

Put in place and keep up a structure of one or more teams that respond to disruptions, with clearly stated roles and responsibilities and clear relationships between teams. Between them the teams must be able to: judge a disruption and its impact against thresholds set beforehand that warrant a formal response; trigger the response and the continuity solutions; plan actions; set priorities, putting the safety of life first; monitor the disruption and the response; and communicate with interested parties, the authorities and the media. Every team must have named people, with stand-ins, who hold the responsibility, authority and competence required, and documented procedures for triggering, running, coordinating and communicating.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 69 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-02 Incident reports are triaged and validated
  • NIST-CSF-RS.MA-03 Incidents are categorized and prioritized
  • NIST-CSF-RS.MA-04 Incidents are escalated or elevated as needed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

FedRAMP High · 6 controls

  • CP-2(1) Coordinate with Related Plans
  • IR-1 Policy and Procedures
  • IR-2 Incident Response Training
  • IR-4 Incident Handling
  • IR-5 Incident Monitoring
  • IR-8 Incident Response Plan

FedRAMP Moderate · 6 controls

  • CP-2(1) Coordinate with Related Plans
  • IR-1 Policy and Procedures
  • IR-2 Incident Response Training
  • IR-4 Incident Handling
  • IR-5 Incident Monitoring
  • IR-8 Incident Response Plan

NIST SP 800-53 Rev 5 · 6 controls

CIS Controls v8 · 4 controls

  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.5 Assign Key Roles and Responsibilities
  • CIS-17.9 Establish and Maintain Security Incident Thresholds

ISO 27001:2022 · 4 controls

  • 5.2 Information security roles and responsibilities
  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents
  • 5.37 Documented operating procedures

ISO 27002:2022 · 4 controls

  • 5.2 Information security roles and responsibilities
  • 5.24 Information security incident management planning and preparation
  • 5.26 Response to information security incidents
  • 5.37 Documented operating procedures
  • 5.2.7 5.2.7 Crisis management personnel
  • 7.3 7.3 Establish elements essential to incident management
  • A.2.3 A.2.3 Identify responsibilities and authorities of key personnel

PCI DSS 4.0 · 3 controls

  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.3 12.10.3 Incident response personnel available 24/7
  • 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations
  • CPS230-14 Board Setting of Senior Manager Roles and Responsibilities
  • CPS230-P40 Required Content of the Business Continuity Plan

SOC 2 · 2 controls

  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents

APRA CPS 234 · 1 control

  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • AEO-12 Crisis Management and Incident Recovery
  • ASBv3-IR-5 Detection and analysis - prioritize incidents

C5 (Germany) · 1 control

  • C5-SIM-01 Policy for security incident management
  • CFTC-SS-16 Security Incident Response Plan and Testing

CMMC 2.0 · 1 control

COBIT 2019 · 1 control

  • DSS04.03 DSS04.03 Develop and implement a business continuity response

HIPAA Security Rule · 1 control

ISO 22000:2018 · 1 control

  • 8.4.2 Handling of emergencies and incidents

ISO 27701:2019 · 1 control

  • 8.4.2 Return, transfer or disposal of PII

ISO 28002:2011 · 1 control

  • A.5.7.2 A.5.7.2 Prevention, preparedness and response structure

ISO 9001:2015 · 1 control

  • 8.4.2 Type and extent of control

ISO/IEC 38500:2024 · 1 control

  • 4.1.3 Responsible stewardship

NIST SP 800-172 · 1 control

  • 3.6.2e Establish and Maintain a Cyber Incident Response Team

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operation, ISO 22301:2019

You are reading one control. How much of ISO 22301:2019 have you already done?

ISO 22301:2019 8.4.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.

Query this from an agent

The graph holds this control, the 69 it maps to, and the evidence behind each claim, over MCP and REST.