ISO 22301:2019
Operation, ISO 22301:2019

ISO 22301:2019 8.4.3: Warning and communication

Document and keep up procedures for: communicating with relevant interested parties inside and outside the organization, covering what is said, when, to whom and how; receiving, recording and answering communications, including those from national or regional risk advisory systems; keeping the means of communication available while a disruption lasts; structured communication with emergency responders; the organization's media response and communications strategy; and recording the disruption, what was done and which decisions were taken. Where relevant, also warn parties who may be affected by a disruption that is happening or imminent, and make sure several responding organizations work together; exercise these procedures as part of the exercise programme.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 63 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
  • NIST-CSF-RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

NIST SP 800-53 Rev 5 · 6 controls

ISO 27002:2022 · 5 controls

  • 5.24 Information security incident management planning and preparation
  • 5.26 Response to information security incidents
  • 5.29 Information security during disruption
  • 5.5 Contact with authorities
  • 5.6 Contact with special interest groups

CIS Controls v8 · 4 controls

  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response

CMMC 2.0 · 4 controls

ISO 27001:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents
  • 5.29 Information security during disruption
  • 5.5 Contact with authorities
  • A.2.4 A.2.4 Emergency management liaisons
  • A.2.6 A.2.6 Notification and communication strategies (pre-incident planning)
  • A.3.1.1 A.3.1.1 Activate crisis communications

NIST SP 800-161 Rev 1 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • 4.4.3 Communication and Warning
  • SPC1-4.4.3 Communication and Warning

FedRAMP High · 2 controls

  • CP-2 Contingency Plan
  • IR-6 Incident Reporting

FedRAMP Moderate · 2 controls

  • CP-2 Contingency Plan
  • IR-6 Incident Reporting

PCI DSS 4.0 · 2 controls

  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.3 12.10.3 Incident response personnel available 24/7
  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours

APRA CPS 234 · 1 control

  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • SAFE-AEO-D Consultation, Co-operation and Communication
  • ASBv3-IR-2 Preparation - setup incident notification

C5 (Germany) · 1 control

  • C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents

COBIT 2019 · 1 control

  • DSS04.03 DSS04.03 Develop and implement a business continuity response

HIPAA Security Rule · 1 control

ISO 19011:2018 · 1 control

  • 6.4.9 Determining audit conclusions

ISO 27701:2019 · 1 control

  • 8.4.3 PII transmission controls

ISO 28002:2011 · 1 control

  • A.5.3 A.5.3 Communication and warning

ISO 9001:2015 · 1 control

  • 8.4.3 Information for external providers
  • 0057 0057 Notify personnel of heightened emergency risk

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operation, ISO 22301:2019

You are reading one control. How much of ISO 22301:2019 have you already done?

ISO 22301:2019 8.4.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.

Query this from an agent

The graph holds this control, the 63 it maps to, and the evidence behind each claim, over MCP and REST.