Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-RS.MA-05 What else in your programme already covers this This control maps to 120 controls across 70 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-A1.3 A1.3 Testing recovery plan procedures SOC2-CC7.4 CC7.4 Responding to security incidents SOC2-CC7.5 CC7.5 Recovering from security incidents API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents 27031-8.1 Exercising and Testing 27031-8.2 Maintaining IRBC 27031-9.3 Management Review PICERL-C2 System Backup PICERL-R1 System Restoration PICERL-R2 Security Verification SSAE18-A1.2 A1.2 - Environmental Protections and Recovery SSAE18-A1.3 A1.3 - Recovery Plan Testing SSAE18-CC7.5 CC7.5 - Incident Recovery ISO22316-08 Recovery time and point objectives ISO22316-12 Recovery strategy for critical activities ISO22317-08 Recovery time and point objectives ISO22317-12 Recovery strategy for critical activities ISO22318-08 Recovery time and point objectives ISO22318-12 Recovery strategy for critical activities NFPA1600-5.3 Resource Needs Assessment NFPA1600-6.4 Continuity and Recovery NISTSP61-5 Containment, Eradication, and Recovery RS.MA-05 RS.MA-05 Recovery initiation criteria applied, weighing operational disruption IM8-RES.2 Disaster Recovery IM8-RES.4 Resilience Testing ISMSP-PI-06 Personal Information Destruction ISMSP-SYS-06 Business Continuity and Disaster Recovery 4.4.8 Business Continuity and Recovery ASBv3-GS-8 Define and implement backup and recovery strategy C5-BCM-02 Business impact analysis policies and instructions DIQ-1 Data Integration and Interoperability FFIEC-12 Disaster recovery procedures FEDRAMP-CP-9 System Backup ISO-22320-5.2 Incident management process 5.29 Information security during disruption 27011-8.6 Data protection and backup ISO27043-23 Backup and recovery procedures ISO21434-23 Backup and recovery procedures Art.21.2.c Business continuity, backup management, disaster recovery and crisis management NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup NISTSP137-7 Incident Response Integration and Ongoing Authorization NISTSP144-6 Availability, Resilience, BCP/DR, and SLA Management NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management OMANCS-7 Business Continuity, Disaster Recovery, and Resilience OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security PCI-P2PE-12 Disaster recovery procedures PCI-PIN-12 Disaster recovery procedures PCI-SSF-12 Disaster recovery procedures PSDTWO-2 SCA Exemptions and Risk-Based Authentication PTESPHASE-3 Threat Modeling SHAREASSESS-4 Vulnerability Management, Patching, Application Security SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SOC-CY-A2 Disaster Recovery TSAPIPE-2 OT/IT Network Segmentation and Access Control SEMD-CS-3 Cyber Resilience CYB-5 Cyber Incident Response Plan Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in RS - Respond You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-RS.MA-05 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 120 it maps to, and the evidence behind each claim, over MCP and REST.