ISO 27701:2019
PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

ISO 27701:2019 6.14.1: Information security continuity

Planning, implementing and then verifying, reviewing and evaluating information security continuity apply as the base guidance requires, read as keeping the protections around personal data in force through a disruption.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 55 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 9 controls

HIPAA Security Rule · 6 controls

NIST SP 800-66 Rev 2 · 6 controls

ISO 27002:2022 · 4 controls

  • 5.24 Information security incident management planning and preparation
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup
  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
  • ASBv3-BR-4 Regularly test backup
  • ASBv3-GS-8 Define and implement backup and recovery strategy
  • BR-1 Ensure regular automated backups

SOC 2 · 3 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption

C5 (Germany) · 2 controls

  • C5-BCM-03 Planning business continuity
  • C5-BCM-04 Verification, updating and testing of the business continuity

CIS Controls v8 · 2 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-11.5 Test Data Recovery

FedRAMP High · 2 controls

  • CP-2 Contingency Plan
  • CP-4 Contingency Plan Testing

FedRAMP Moderate · 2 controls

  • CP-2 Contingency Plan
  • CP-4 Contingency Plan Testing

ISO 27001:2022 · 2 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity

ISO/IEC 29100:2024 · 2 controls

  • 29100-6.10 Information security
  • ISO29100-5.10.10 Information Security

NIST SP 800-161 Rev 1 · 2 controls

CMMC 2.0 · 1 control

ISO 27017:2015 · 1 control

  • 17.1 Information security continuity

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 6.14.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 55 it maps to, and the evidence behind each claim, over MCP and REST.