Oman National Cybersecurity Framework
BC and DR

Oman National Cybersecurity Framework OMANCS-7: Business Continuity, Disaster Recovery, and Resilience

Operate business continuity + disaster recovery + resilience per Oman framework + sectoral requirements. Apply NIST SP 800-34 methodology including Business Impact Analysis + recovery strategies + ISCP development + testing + maintenance. Implement backup + alternate site + recovery procedures with documented RTO / RPO per system aligned to mission criticality. Test annually via tabletop + biennially via technical recovery exercise. Maintain alignment with broader enterprise risk + insurance + crisis management.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 85 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27031:2011 · 6 controls

  • 27031-7.1 IRBC Strategy
  • 27031-7.2 Resource Requirements
  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • 27031-D Developing performance criteria

ISO 22316 · 5 controls

  • ISO22316-01 Organizational resilience and security - business continuity policy for building security and resilience
  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities
  • ISO22316-14 Supply chain continuity
  • ISO22316-15 Communication strategy during disruption

ISO/TS 22317:2021 · 5 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-11 Continuity strategy development
  • ISO22317-12 Recovery strategy for critical activities
  • ISO22317-14 Supply chain continuity
  • ISO22317-15 Communication strategy during disruption

ISO/TS 22318:2021 · 5 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • ISO22318-13 Alternate site and resource planning
  • ISO22318-14 Supply chain continuity
  • ISO22318-15 Communication strategy during disruption
  • NFPA1600-4.1 Leadership and Commitment
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.2 Crisis Management and Communications
  • NFPA1600-6.4 Continuity and Recovery

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • ISO-22313-5.2 Policy
  • ISO-22313-6.2 Business continuity objectives and plans to achieve them
  • ISO-22313-6.3 Planning changes to the BCMS

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 1800-32 · 3 controls

  • IM8-RES.1 Business Continuity Planning
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures

NIST SP 800-53 Rev 5 · 2 controls

South Korea ISMS-P · 2 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • 4.4.8 Business Continuity and Recovery
  • BS65000-RM-02 Integrated Approach
  • DIQ-1 Data Integration and Interoperability

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup
  • ISO-15189-7.8 Continuity and emergency preparedness

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process
  • ISO28001-PC-04 Supply Chain Continuity Planning

ISO/IEC 27010:2015 · 1 control

  • 27010-17.1 Compliance

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup

ISO/IEC 27043:2015 · 1 control

  • ISO27043-23 Backup and recovery procedures

ISO/SAE 21434 · 1 control

  • ISO21434-23 Backup and recovery procedures
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 1 control

OWASP ASVS · 1 control

OWASP MASVS · 1 control

  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 85 it maps to, and the evidence behind each claim, over MCP and REST.