ISO 22301:2019
Operation, ISO 22301:2019

ISO 22301:2019 8.6: Evaluation of business continuity documentation and capabilities

Evaluate whether the business impact analysis, risk assessment, strategies, solutions, plans and procedures remain suitable, adequate and effective, carrying out those evaluations through reviews, analysis, exercises, tests, post incident reports and performance evaluations, evaluating the continuity capabilities of relevant partners and suppliers, evaluating compliance with applicable legal and regulatory requirements and industry practice and conformity with the organization's own policy and objectives, and updating documentation and procedures promptly; conduct these evaluations at planned intervals, after an incident or activation, and when significant change occurs.

What else in your programme already covers this

This control maps to 58 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 6 controls

  • CIS-11.5 Test Data Recovery
  • CIS-17.7 Conduct Routine Incident Response Exercises
  • CIS-17.8 Conduct Post-Incident Reviews
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.4 Validate Security Measures
  • CIS-18.5 Perform Periodic Internal Penetration Tests

ISO 27002:2022 · 5 controls

  • 5.24 Information security incident management planning and preparation
  • 5.27 Learning from information security incidents
  • 5.29 Information security during disruption
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

ISO 27001:2022 · 4 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated

NIST SP 800-53 Rev 5 · 4 controls

  • CPS230-33 Systematic BCP Testing Program
  • CPS230-P45 Annual Update of the Business Continuity Plan

CMMC 2.0 · 2 controls

FedRAMP High · 2 controls

  • CA-2 Control Assessments
  • CP-4 Contingency Plan Testing

FedRAMP Moderate · 2 controls

  • CA-2 Control Assessments
  • CP-4 Contingency Plan Testing

HIPAA Security Rule · 2 controls

NIST SP 800-161 Rev 1 · 2 controls

  • CA-2 Control Assessments
  • CP-4 Contingency Plan Testing
  • CA-2 Control Assessments
  • CP-4 Contingency Plan Testing
  • CA-2 Control Assessments
  • CP-4 Contingency Plan Testing

NIST SP 800-66 Rev 2 · 2 controls

PCI DSS 4.0 · 2 controls

  • 12.10.2 IRP reviewed and tested annually
  • 6.5.2 Upon completion of a significant change, all applicable PCI DSS requirements are confirmed to be in place on all new or changed systems and networks, and documentation is updated as applicable
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)

C5 (Germany) · 1 control

  • C5-BCM-04 Verification, updating and testing of the business continuity
  • CFTC-SS-24 Periodic Update of the Recovery Plan and Emergency Procedures

ISO 22000:2018 · 1 control

  • 8.6 Updating the information specifying the PRPs and the hazard control plan

ISO 37001:2016 · 1 control

  • 8.6 Anti-bribery commitments

ISO 9001:2015 · 1 control

  • 8.6 Release of products and services

NIST SP 800-172 · 1 control

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 53A-3.5 Assess Security and Privacy Capabilities

SOC 2 · 1 control

  • SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operation, ISO 22301:2019

You are reading one control. How much of ISO 22301:2019 have you already done?

ISO 22301:2019 8.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.

Query this from an agent

The graph holds this control, the 58 it maps to, and the evidence behind each claim, over MCP and REST.