The organization defines and documents the objectives and scope of its resilience management policy, naming the particular internal and external context factors. In doing so it: sets the boundaries covered, which may be the whole organization, one or more units, or components of one or more end-to-end product or service flows in the supply chain; derives resilience management requirements from what the organization exists to do, its goals, and the duties it owes inside and outside, stakeholder and legal duties among them; considers critical objectives, assets, activities, functions, goods and services; identifies risks from internal and external disruptions that could harm operations and functions, in terms of likely impact; and sizes the scope to the scale, nature and complexity of its operations with continual improvement in view. The scope must allow the organization to protect and keep whole itself and its supply chain, including relationships with stakeholders, key suppliers, outsourcing partners and others (supply chain partners, customers, shareholders, the local community). Based on its risk assessment, it also gives strategic weightings to security, preparedness, mitigation, crisis, emergency, business continuity and disaster recovery management (see 4.4).
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.