SASB Standards
Business Model and Innovation

SASB Standards SASB-1: Business Model + Innovation (BMI)

Per SASB / IFRS S2 Standards Business Model and Innovation dimension: report material sustainability factors including (a) Product Design and Lifecycle Management + (b) Business Model Resilience + (c) Supply Chain Management + (d) Materials Sourcing and Efficiency + (e) integrate with broader sustainability strategy + (f) maintain documentation supporting industry-specific SASB metrics + IFRS S2 disclosures.

What else in your programme already covers this

This control maps to 181 controls across 84 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • Ene 01 Reduction of Energy Use and Carbon Emissions
  • Hea 02 Indoor Air Quality
  • LE 03 Ecological Value and Biodiversity
  • Man 03 Responsible Construction Practices
  • Mat 03 Responsible Sourcing of Materials
  • Pol 02 NOx Emissions
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained

ISO 26000:2010 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

  • C13 Target Recalculation
  • C18 No Offsetting of Targets
  • C19 BVCM Reporting
  • SBTONE-5 Beyond Value Chain Mitigation (BVCM) and No Offsetting

API 1164 · 3 controls

  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • P2-S1 Partnership
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

IEC 62443 · 3 controls

ISO 14001 · 3 controls

ISO 27019 · 3 controls

NIST SP 1800-32 · 3 controls

  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • 3.5 Securely Dispose of Data

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • Clause 10 Change and configuration management
  • Clause 3 Suppliers and service providers
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience
  • A.1 Point-of-Care Testing Additional Requirements
  • ISO-15189-6.8 Externally provided products and services

ISO 20000-1 · 2 controls

ISO/IEC 27003:2017 · 2 controls

ISO/IEC 27031:2011 · 2 controls

ITIL 4 · 2 controls

  • ITIL4-03 Capacity and availability management
  • ITIL4-06 Change management processes
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • ASD37-20 Multi-factor authentication (Essential)
  • 3.5 Securely Dispose of Data

BSI IT-Grundschutz · 1 control

  • BSI-24 Configuration change control

COBIT 2019 · 1 control

  • CJIS-19 Supply Chain Risk Management
  • CAT-D5-4 Resilience planning and testing
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • 60601-1.13 Hazardous situations and fault conditions

ISO 19011 · 1 control

ISO 22316 · 1 control

ISO 22317 · 1 control

ISO 22318 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 30401 · 1 control

ISO 37001 · 1 control

ISO 37301 · 1 control

ISO 55001 · 1 control

ISO 9001 · 1 control

  • ISO9001-18 Cl. 6.3 Planning of changes - innovation and change management for the quality management system

ISO/IEC 23894:2023 · 1 control

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

NIST SP 800-190 · 1 control

  • PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets
  • SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement
  • SAPAIA-2 Right of Access and Request Processes
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)

South Korea ISMS-P · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Business Model and Innovation

Query this from an agent

The graph holds this control, the 181 it maps to, and the evidence behind each claim, over MCP and REST.