NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.2.c: Business continuity, backup management, disaster recovery and crisis management

This category asks the entity to be able to keep providing its services, or to restore them, when systems fail or are attacked. Backup management means backups that are taken, protected against the same event that takes out production, and demonstrably restorable, which is why restore testing rather than backup success rate is the evidence that counts. Disaster recovery means recovery objectives that were derived from what the service can actually tolerate, and infrastructure and procedure capable of meeting them. Crisis management is the decision-making layer above both: who declares a crisis, who can commit the organisation, how the entity communicates while under pressure. Because NIS2 is concerned with continuity of service to recipients, recovery objectives set purely from internal convenience are the usual weak point.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 60 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
  • NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration
  • NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
  • NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

C5 (Germany) · 8 controls

  • C5-BCM-02 Business impact analysis policies and instructions
  • C5-BCM-03 Planning business continuity
  • C5-BCM-04 Verification, updating and testing of the business continuity
  • C5-OPS-06 Data Backup and Recovery - Concept
  • C5-OPS-07 Data Backup and Recovery - Monitoring
  • C5-OPS-08 Data Backup and Recovery - Regular Testing
  • C5-OPS-09 Data Backup and Recovery - Storage
  • C5-PS-02 Redundancy model

CIS Controls v8 · 4 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-11.2 Perform Automated Backups
  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data
  • CIS-11.5 Test Data Recovery

FedRAMP High · 4 controls

  • CP-10 System Recovery and Reconstitution
  • CP-2 Contingency Plan
  • CP-4 Contingency Plan Testing
  • CP-9(1) Testing for Reliability and Integrity

FedRAMP Moderate · 4 controls

  • CP-10 System Recovery and Reconstitution
  • CP-2 Contingency Plan
  • CP-4 Contingency Plan Testing
  • CP-9(1) Testing for Reliability and Integrity

ISO 27001:2022 · 4 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup
  • 8.14 Redundancy of information processing facilities

ISO 27002:2022 · 4 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup
  • 8.14 Redundancy of information processing facilities

NIST SP 800-53 Rev 5 · 4 controls

SOC 2 · 4 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption

DORA · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-32 Annual Review and Testing of Response Plans
  • CPS234-P24 Information Security Response Plans

PCI DSS 4.0 · 2 controls

  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups
  • 9.4.1.2 9.4.1.2 Annual review of offline backup location security

CMMC 2.0 · 1 control

GDPR · 1 control

  • 03.08.09 System Backup - Cryptographic Protection

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.2.c is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.