Frameworks / NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems / NISTSP34-2 NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems
Business Impact Analysis
NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems NISTSP34-2: Business Impact Analysis (BIA): Critical Resources, Recovery Priorities Conduct Business Impact Analysis per NIST SP 800-34 Rev 1 Section 3.2 + Appendix B (Sample BIA Template). BIA identifies and prioritises information systems and components critical to supporting the organisations mission/business processes. BIA must (a) determine mission/business processes and recovery criticality per Section 3.2.1: identify the systems supporting each mission/business process + the impact of disruption + recovery time objective (RTO) + recovery point objective (RPO) + maximum tolerable downtime (MTD) per process, (b) identify resource requirements per Section 3.2.2: hardware + software + data + facilities + personnel + supplier dependencies + external service providers + critical records + telecommunications, (c) identify system resource recovery priorities per Section 3.2.3: order systems by criticality with documented rationale + alignment with FIPS 199 security categorisation + organisational risk tolerance. BIA output feeds Contingency Strategy Development (NISTSP34-3) + IT Contingency Plan Development (NISTSP34-4). Review BIA annually + after significant change.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 171 controls across 90 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
27031-5.1 IRBC Policy 27031-8.1 Exercising and Testing 27031-8.2 Maintaining IRBC 27031-9.3 Management Review API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests FedRAMP-IncidentReporting FedRAMP incident reporting to PMO and US-CERT GAMP5-Lifecycle-VModel-URS-FS-DS-IQOQPQ V-Model Lifecycle - URS + FS + DS + IQ + OQ + PQ + Traceability GAMP5-Risk-CriticalThinking Risk-Based Approach, Critical Thinking and 5 Key Concepts GAMP5-Supplier-Operations-Change-Periodic Supplier Assessment, Operational Phase, Change Control and Periodic Review IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA IMO-MSC-FAL-Recover-BackupRestore-ContinuityOfNavigation-LessonsLearned-Drills IMO MSC-FAL Recover Function - Backup and Restore + Continuity of Navigation + Continuity of Cargo Operations + Continuity of Propulsion + Lessons Learned + Drills + Resilience IMO-MSC-FAL-Respond-IncidentResponse-Communication-FlagState-PortAuthority-CIRT-USCGNVIC IMO MSC-FAL Respond Function - Incident Response Plan + Containment + Communication + Flag State + Port Authority + USCG NVIC + Class Society Notification + CIRT 27004-3 Terms and definitions 27004-A.2 Patching and Vulnerability Measures 27004-B.1 Example measurement definitions 27011-1 Scope 27011-3 Terms and definitions 27011-8.6 Data protection and backup 27557-1 Scope 27557-3 Terms and definitions 27557-6.2 Scope, context, and criteria for privacy 29100-1 Scope 29100-3 Terms and definitions 29100-4.1 Actors and roles MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-5 Security of Processing, Breach Notification, and DPIA 58.1 Scope 58.3 Definitions 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.8 Business Continuity and Recovery AL-DPA-1 Scope and Definitions AL-DPA-3 Lawful Basis for Processing AT-DSG-2 Section 2 - Scope and application AT-DSG-8 Section 22 - Functions and powers of the DPA GLBA-Sec6801-PolicyDuty-SafeguardingStandard GLBA Section 6801 - Privacy Obligation Policy and Safeguarding Standard GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines HKMA-CRAF-Domain1-2-Governance-Identification HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing HKMA-SPM-CG-IC-AC-Governance-Control-Audit HKMA SPM Corporate Governance (CG-1/2/3/5/6), Internal Control (IC-1/5), Auditing (AC-G) HKMA-SPM-OR-RR-SA-OperationalResilience HKMA SPM Operational Risk (OR-1), Operational Resilience (OR-2), Recovery Planning (RR-1), Outsourcing (SA-2) IATF16949-Clause10-Improvement-Nonconformity-CorrectiveAction-Problem-ErrorProof IATF 16949 Clause 10 - Improvement + Nonconformity + Corrective Action + Problem Solving + Error Proofing + Continual Improvement IATF16949-Clause9-Performance-Monitoring-InternalAudit-ManagementReview IATF 16949 Clause 9 - Performance Evaluation + Monitoring + Internal Audit + Manufacturing Process Audit + Management Review 60601-1.3 Terminology and definitions 60601-1.4.1 General requirements 27014-1 Scope 27014-3 Terms and definitions 29147-3 Terms and definitions 29147-9.2 Contact mechanisms and scope 30111-3 Terms and definitions 30111-5.1 Organizational policy IsraelPPL-Database-Registration-Definition-Document-Security-Level-Classification-Sec7-8-PPA-Registry Israel POPL Database Registration + Section 7 Database Definitions + Section 8 Registration Requirement + Database Definition Document + Security Level Classification + PPA Public Registry + Amendment 13 Threshold Changes IsraelPPL-Scope-5741-1981-Knesset-Amendment13-March2024-BasicLaw-Dignity-Sec1-Right-Privacy Israel Protection of Privacy Law 5741-1981 Scope + Knesset + Amendment No. 13 March 2024 + Basic Law Human Dignity and Liberty + Section 1 Right to Privacy + Constitutional Status + Chapter 1 Infringement of Privacy MAS-TRM-Governance-Chapters-2-3-Board-Senior-Management-Risk-Framework-Information-Asset-Management MAS TRM Governance + Chapters 2-3 + Board + Senior Management + Risk Framework + Information Asset Management MAS-TRM-Reliability-Data-Centre-Chapters-7-8-RTO-RPO-BCP-DR-System-Availability-4-Hours-12-Months MAS TRM Reliability + Data Centre + Chapters 7-8 + RTO + RPO + BCP + DR + System Availability 4 Hours 12 Months STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTSP115-1 Scope, Methodology, and Assessment Planning NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup NISTSP123-8 Governance, Policies, and ISMS Integration NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment NISTSP137-7 Incident Response Integration and Ongoing Authorization NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP144-6 Availability, Resilience, BCP/DR, and SLA Management NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports C1 Organizational Boundary C3 Scope 1 and 2 Coverage CFR211-A-3 Section 211.3 - Definitions AWWA-1.1 Security Policy and Governance AZ-DPA-2 Article 2 - Basic Concepts COBIT-BAI02 Managed requirements definition R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10) FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) CA-9 Internal System Connections CA-9 Internal System Connections FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct GLI33-EventWagering-System-Architecture GLI-33 Event Wagering System Architecture, Wager Engine, Odds Engine and Risk Management IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality 62351-2 Glossary of terms IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills 27007-5.2 Audit Programme Objectives 27050-1.4 Terms and definitions 27400-3 Terms and definitions 29115-3 Terms and definitions 29134-3 Terms and definitions ITAR-Scope-AECA-22USC2778-22CFR120-130-DDTC-USML-21Categories-DefenseArticle-Service-TechnicalData ITAR Scope + Arms Export Control Act (22 USC 2778) + 22 CFR Parts 120-130 + Directorate of Defense Trade Controls (DDTC) + United States Munitions List (USML) 21 Categories + Defense Article/Service/Technical Data Definitions ITU-Scope-Constitution-Convention-Radio-Regulations-WRC-Quadrennial-Treaty-Art1-Definitions ITU Constitution + Convention + Radio Regulations Scope + Article 1 Definitions + Article 2 Nomenclature + WRC World Radiocommunication Conference Quadrennial Treaty Process + Member States + Sector Members BIPA-SEC5-1 Biometric Identifier Definition JP-FSA-CYB-Incident-Response-Playbooks-Containment-Eradication-Recovery-Post-Mortem-Tabletop-CSIRT Japan FSA Cybersecurity Incident Response + Playbooks + Containment + Eradication + Recovery + Post-Mortem + Tabletop Exercises + CSIRT + FSA Notification + Customer Communication + Forensics + Lessons Learned NABERS-3 NABERS Water Performance Rating NAIC-5 Third Party Service Provider Oversight - Section 4(F)(3) and Section 5 NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009) PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NDPA-1 Applicability, Scope, and Carve-Outs NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation 2.2.2 2.2.2 Vendor default accounts managed SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1) PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 TEFCAREC-1 Common Agreement Conformance and Onboarding 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern USMCADIGITAL-1 Cross-Border Data Flows and Localisation VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 171 it maps to, and the evidence behind each claim, over MCP and REST.