NIST Cybersecurity Framework 2.0
PR - Protect

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.IR-03: Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

Mechanisms are implemented to achieve resilience requirements in normal and adverse situations. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 165 controls across 61 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 11 controls

FedRAMP High · 6 controls

  • CP-10 System Recovery and Reconstitution
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-7 Alternate Processing Site
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • CP-8 Telecommunications Services
  • CP-8(2) Telecommunications Services | Single Points of Failure (CP-8(2))

FedRAMP Moderate · 6 controls

  • CP-10 System Recovery and Reconstitution
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-7 Alternate Processing Site
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • CP-8 Telecommunications Services
  • CP-8(2) Telecommunications Services | Single Points of Failure (CP-8(2))

ISO 22301:2019 · 6 controls

  • 8.1 Operational planning and control
  • 8.3 Business continuity strategies and solutions
  • 8.3.2 Identification of strategies and solutions
  • 8.3.5 Implementation of solutions
  • 8.4.4 Business continuity plans
  • 8.5 Exercise programme
  • CFTC-SS-10 Geographic Dispersal of Backup Infrastructure and Personnel
  • CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category
  • CFTC-SS-25 Same Day Recovery Time Objective for Critical Entities
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources
  • CFTC-SS-9 Next Business Day Recovery Time Objective

CIS Controls v8 · 5 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-11.2 Perform Automated Backups
  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data
  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-17.4 Establish and Maintain an Incident Response Process

ISO 27001:2022 · 5 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup
  • 8.14 Redundancy of information processing facilities
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-24 Non-persistent virtualised sandboxed environment (Very Good)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

ISO 27002:2022 · 4 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.13 Information backup
  • 8.14 Redundancy of information processing facilities

NIST SP 800-161 Rev 1 · 4 controls

SOC 2 · 4 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • ISM-1438 CDNs for high availability website hosting
  • ISM-1580 Automatic failover between availability zones
  • ISM-1789 Spares for critical equipment

C5 (Germany) · 3 controls

  • C5-BCM-03 Planning business continuity
  • C5-OPS-17 Logging and Monitoring - Availability of the Monitoring Software
  • C5-PS-02 Redundancy model
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

HIPAA Security Rule · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

PCI P2PE · 3 controls

  • PCI-P2PE-11 Business continuity planning and testing
  • PCI-P2PE-12 Disaster recovery procedures
  • PCI-P2PE-14 Critical service identification

PCI PIN Security · 3 controls

  • PCI-PIN-13 Third-party dependency management
  • PCI-PIN-14 Critical service identification
  • PCI-PIN-15 Communication and escalation procedures

PCI SSF · 3 controls

  • PCI-SSF-12 Disaster recovery procedures
  • PCI-SSF-14 Critical service identification
  • PCI-SSF-15 Communication and escalation procedures
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.4 Resilience Testing
  • CPS230-20 Prevention, Adaptation and Return to Normal Operations
  • CPS230-P41 BCP Execution Capability and Tolerance Breach Reporting

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability

DORA · 2 controls

  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO/IEC 27031:2011 · 2 controls

  • 27031-8.1 Exercising and Testing
  • 27031-B High availability embedded systems
  • NISTPF-6 Protect-P Data Security (PR.DS-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

OSFI B-13 · 2 controls

  • OSFIB13-4 Third-Party Risk Management and Cloud
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination

Open Banking Security · 2 controls

  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

SASB Standards · 2 controls

  • SASB-1 Business Model + Innovation (BMI)
  • SASB-BMI-2 Business Model Resilience
  • SOCI-S30BC Notification of critical cyber security incidents (12 hours)
  • SOCI-S30BD Notification of other cyber security incidents (72 hours)
  • OB-API.4 MI Reporting Specification
  • OB-OPS.1 API Availability Requirements
  • SEMD-CS-3 Cyber Resilience
  • SEMD-ER-1 Emergency Exercise and Testing
  • E8-BACKUP-ML1 Regular Backups (ML1)
  • ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components
  • BS65000-RM-03 Leadership and Culture

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • RMD-1 Reference Data Management
  • CAT-D5-4 Resilience planning and testing

GDPR · 1 control

ISO 27701:2019 · 1 control

  • 6.14.1 Information security continuity
  • ISO20000-03 Capacity and availability management
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • PR.PT-5 PR.PT-5: Mechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations

NIST SP 800-172 · 1 control

  • 3.13.3e Confuse and Mislead Adversaries
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • SOC-CY-A1 Availability Commitments
  • SSAE18-A1.1 A1.1 - Availability Commitments and Requirements
  • SAPAIA-2 Right of Access and Request Processes
  • UKAI-3 Bias Detection, Fairness, Validation
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • CERT-1 RRA Certification to EPA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PR - Protect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.IR-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 165 it maps to, and the evidence behind each claim, over MCP and REST.