ISO 22301:2019
Operation, ISO 22301:2019

ISO 22301:2019 8.6: Evaluation of business continuity documentation and capabilities

Evaluate whether the impact analysis, the risk assessment, the strategies, the solutions, the plans and the procedures are still suitable, adequate and effective. Do this through reviews, analysis, exercises, tests, reports after incidents and performance evaluations; evaluate the continuity capabilities of the partners and suppliers that matter; evaluate whether applicable laws, regulations and industry practice are complied with, and whether the organization's own policy and objectives are met; and update documentation and procedures without delay. Carry out these evaluations at planned intervals, after any incident or activation, and whenever significant change happens.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 57 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 6 controls

  • CIS-11.5 Test Data Recovery
  • CIS-17.7 Conduct Routine Incident Response Exercises
  • CIS-17.8 Conduct Post-Incident Reviews
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.4 Validate Security Measures
  • CIS-18.5 Perform Periodic Internal Penetration Tests

ISO 27002:2022 · 5 controls

  • 5.24 Information security incident management planning and preparation
  • 5.27 Learning from information security incidents
  • 5.29 Information security during disruption
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

ISO 27001:2022 · 4 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated

NIST SP 800-53 Rev 5 · 4 controls

  • CPS230-33 Systematic BCP Testing Program
  • CPS230-P45 Annual Update of the Business Continuity Plan
  • 44 Para 44 Annual BCP update

CMMC 2.0 · 2 controls

COBIT 2019 · 2 controls

  • DSS04.05 DSS04.05 Review, maintain and improve the continuity plans
  • DSS04.08 DSS04.08 Conduct post-resumption review

FedRAMP High · 2 controls

  • CA-2 Control Assessments
  • CP-4 Contingency Plan Testing

FedRAMP Moderate · 2 controls

  • CA-2 Control Assessments
  • CP-4 Contingency Plan Testing

HIPAA Security Rule · 2 controls

ISO 28002:2011 · 2 controls

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

PCI DSS 4.0 · 2 controls

  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • 6.5.2 6.5.2 Confirm PCI DSS controls after significant change
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)

C5 (Germany) · 1 control

  • C5-BCM-04 Verification, updating and testing of the business continuity
  • CFTC-SS-24 Periodic Update of the Recovery Plan and Emergency Procedures

ISO 22000:2018 · 1 control

  • 8.6 Updating the information specifying the PRPs and the hazard control plan

ISO 37001:2016 · 1 control

  • 8.6 8.6 Anti-bribery commitments

ISO 9001:2015 · 1 control

  • 8.6 Release of products and services

NIST SP 800-172 · 1 control

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 53A-3.5 Assess Security and Privacy Capabilities

SOC 2 · 1 control

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operation, ISO 22301:2019

You are reading one control. How much of ISO 22301:2019 have you already done?

ISO 22301:2019 8.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 22301:2019 your existing evidence covers. Hold APRA CPS 230 Operational Risk Management and 28 of 57 ISO 22301:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the APRA CPS 230 Operational Risk Management pair alone.

Query this from an agent

The graph holds this control, the 57 it maps to, and the evidence behind each claim, over MCP and REST.