Frameworks / NIST SP 800-66 Rev 2 / 164.310(a)(2)(i) What else in your programme already covers this This control maps to 29 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms 8.2.2 Business impact analysis 8.4.4 Business continuity plans 8.4.5 Recovery 8.5 Exercise programme 5.29 Information security during disruption 5.30 ICT readiness for business continuity 7.5 Protecting against physical and environmental threats SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-A1.3 A1.3 Testing recovery plan procedures SOC2-CC9.1 CC9.1 Mitigating risks of business disruption CPS230-P41 BCP Execution Capability and Tolerance Breach Reporting C5-PS-01 Physical Security and Environmental Control Requirements CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources 5.30 ICT readiness for business continuity 6.14.1 Information security continuity Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Physical Query this from an agent The graph holds this control, the 29 it maps to, and the evidence behind each claim, over MCP and REST.