NIS2 Directive Art.21.2.c: Business continuity, backup management, disaster recovery and crisis management
This category asks the entity to be able to keep providing its services, or to restore them, when systems fail or are attacked. Backup management means backups that are taken, protected against the same event that takes out production, and demonstrably restorable, which is why restore testing rather than backup success rate is the evidence that counts. Disaster recovery means recovery objectives that were derived from what the service can actually tolerate, and infrastructure and procedure capable of meeting them. Crisis management is the decision-making layer above both: who declares a crisis, who can commit the organisation, how the entity communicates while under pressure. Because NIS2 is concerned with continuity of service to recipients, recovery objectives set purely from internal convenience are the usual weak point.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 60 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration
NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
You are reading one control. How much of NIS2 Directive have you already done?
NIS2 Directive Art.21.2.c is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.