Document and keep up procedures for: communicating with relevant interested parties inside and outside the organization, covering what is said, when, to whom and how; receiving, recording and answering communications, including those from national or regional risk advisory systems; keeping the means of communication available while a disruption lasts; structured communication with emergency responders; the organization's media response and communications strategy; and recording the disruption, what was done and which decisions were taken. Where relevant, also warn parties who may be affected by a disruption that is happening or imminent, and make sure several responding organizations work together; exercise these procedures as part of the exercise programme.
This control maps to 63 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
NIST-CSF-RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging
NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
You are reading one control. How much of ISO 22301:2019 have you already done?
ISO 22301:2019 8.4.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.