Management gives evidence of its engagement in the resilience policy across its whole life, from setting it up and running it to watching, reviewing, keeping up and improving it, by: setting the policy; making sure objectives and implementation plans are set; defining roles, competencies and responsibilities for resilience management; appointing one or more competent people accountable for the policy, with defined authority to implement and maintain the system; telling the organization why meeting resilience objectives and the policy matters, including legal compliance duties and continual improvement; providing enough resources for the whole cycle; setting criteria for acceptable risk and tolerable risk levels; ensuring internal audits of the policy are carried out; conducting management reviews; and showing commitment to continual improvement. Annex B adds that top management should drive the system top down so every level sees it as a priority, and form a resilience planning team and support teams that include senior leaders of all main units.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.