ISO 22317
ISO 22317: Business Impact Analysis

ISO 22317 ISO22317-08: Recovery time and point objectives

Recovery time and point objectives. Control from ISO 22317 framework, domain: ISO 22317: Business Impact Analysis.

What else in your programme already covers this

This control maps to 115 controls across 69 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

IEC 62443 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 27031:2011 · 3 controls

  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 1800-32 · 3 controls

ISO 22316 · 2 controls

ISO 22318 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

SOC 2 · 2 controls

  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-A1.3 Recovery plan procedures support system recovery from failures

South Korea ISMS-P · 2 controls

  • 4.4.8 Business Continuity and Recovery
  • DIQ-1 Data Integration and Interoperability

ISO 22320:2018 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27043 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/SAE 21434 · 1 control

MITRE ATT&CK · 1 control

MTCS (Singapore) · 1 control

  • NAIC-5 Third Party Service Provider Oversight - Section 4(F)(3) and Section 5

NERC CIP · 1 control

  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • NIS2I-3 Incident Handling Policy, Reporting Significance Criteria, and Business Continuity
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 1 control

  • NISTSP137-7 Incident Response Integration and Ongoing Authorization

NIST SP 800-144 · 1 control

  • NISTSP144-6 Availability, Resilience, BCP/DR, and SLA Management

NIST SP 800-145 · 1 control

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management

NIST SP 800-146 · 1 control

  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability

NIST SP 800-190 · 1 control

NIST SP 800-61 · 1 control

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity

NIST SP 800-88 · 1 control

  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records

NIST SP 800-92 · 1 control

  • NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP MASVS · 1 control

  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

OpenSSF Scorecard · 1 control

  • OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security

PCI P2PE · 1 control

PCI PIN Security · 1 control

PCI SSF · 1 control

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

PTES · 1 control

  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ISO 22317: Business Impact Analysis

Query this from an agent

The graph holds this control, the 115 it maps to, and the evidence behind each claim, over MCP and REST.