The organization keeps procedures to prevent and protect against a disruptive event, limit its consequences and keep operating, based on resilience objectives drawn from the risk assessment. Procedures follow a prioritised hierarchy of controls ordered by the likelihood of a crisis: avoiding the risk by removing exposure entirely; reducing it by changing activities, processes, equipment or materials; isolating or moving assets away from the risk; engineering controls that detect, contain and delay the hazard or threat; administrative controls such as work methods and procedures; and protecting assets where the risk cannot be removed or reduced. Annex B adds architectural, operational and technological deterrence and detection strategies, physical security planning in layers from the site perimeter inward (detection at the greatest practical distance from what is protected, delay near it, detection linked to assessment and response), and mitigation strategies with immediate, interim and long-term actions and continuously monitored resources such as emergency equipment, fire systems, alternate sites and off-site backups.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.