Frameworks / NIST SP 800-66 Rev 2 / 164.308(a)(7)(ii)(C) What else in your programme already covers this This control maps to 34 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
5.24 Information security incident management planning and preparation 5.29 Information security during disruption 5.37 Documented operating procedures 8.13 Information backup NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms CFTC-SS-37 Protection of Swap Data Repository Data CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources CFTC-SS-9 Next Business Day Recovery Time Objective CP-2(3) Resume Mission and Business Functions CP-7 Alternate Processing Site IR-3 Incident Response Testing CP-2(3) Resume Mission and Business Functions CP-7 Alternate Processing Site IR-3 Incident Response Testing CPS230-20 Prevention, Adaptation and Return to Normal Operations CPS230-P40 Required Content of the Business Continuity Plan ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) 5.29 Information security during disruption 5.30 ICT readiness for business continuity SOC2-A1.3 A1.3 Testing recovery plan procedures SOC2-CC9.1 CC9.1 Mitigating risks of business disruption 8.4.4 Business continuity plans 6.14.1 Information security continuity Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative Query this from an agent The graph holds this control, the 34 it maps to, and the evidence behind each claim, over MCP and REST.