ISO 27002:2022 5.29: Information security during disruption
The organization is to plan how it will keep information security at a suitable level while operations are disrupted. Purpose: protect information and associated assets during disruption. Guidance: work out how security controls need to be adapted during disruption and build security requirements into business continuity management. Develop, put in place, test, review and evaluate plans that keep or restore the security of information supporting critical business processes after an interruption or failure, recovering it to the required level within the required time. Implement and maintain security controls and their supporting systems and tools within the business and ICT continuity plans, processes that keep existing security controls working during disruption, and compensating controls for any that cannot be kept running. Other information: continuity planning may call for security requirements that differ from normal operation depending on the type of disruption; the impact analysis and risk assessment done for continuity should weigh and prioritize loss of confidentiality and integrity as well as availability; ISO 22301, ISO 22313 and ISO/TS 22317 give further guidance.
This control maps to 123 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.29 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.