The organization documents and puts in place procedures and a management structure, staffed by people with the needed authority, experience and competence, to prevent, prepare for, mitigate and respond to a disruptive event. The structure lets staff confirm the nature and extent of the event or its potential impact on the organization, its supply chain and stakeholders; start suitable proactive and reactive measures; have plans, processes and procedures for activation, operation, coordination and communication; have resources available to carry them out and to limit impact before it occurs; and communicate with supply chain partners, stakeholders, local authorities and the media. Annex B adds documented alert criteria with timed notification sequences, clear qualification for activation, current confidential contact lists, redundant notification channels, problem and severity assessment on disruption, a defined point and authority (with first and second alternates) for declaring an emergency or crisis, and typical actions such as alerting partners, call-outs, evacuation or relocation, security protocols, moving to alternate facilities, deploying the crisis team and invoking emergency contracts.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.