Frameworks / SOC 2 / SOC2-CC9.1 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC9.1: CC9.1 Mitigating risks of business disruption Measures to reduce the risk of business disruption are identified, selected and developed. Points of focus: policies, procedures, communication plans and fallback processing are prepared in advance so the organisation can respond, limit the damage and recover from disruptive security events, with monitoring and information flows to meet objectives during those efforts; and insurance is considered to cover the financial cost of loss events.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 153 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1)) CP-2 Contingency Plan CP-6 Alternate Storage Site CP-6(3) Alternate Storage Site | Accessibility (CP-6(3)) CP-7 Alternate Processing Site CP-7(2) Alternate Processing Site | Accessibility (CP-7(2)) IR-3 Incident Response Testing RA-3 Risk Assessment RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3)) RA-7 Risk Response RA-9 Criticality Analysis (RA-9) SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2)) SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1)) CP-2 Contingency Plan CP-6 Alternate Storage Site CP-6(3) Alternate Storage Site | Accessibility (CP-6(3)) CP-7 Alternate Processing Site CP-7(2) Alternate Processing Site | Accessibility (CP-7(2)) IR-3 Incident Response Testing RA-3 Risk Assessment RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3)) RA-9 Criticality Analysis (RA-9) SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2)) SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) 6.1 Actions to address risks and opportunities 6.1.2 Addressing risks and opportunities 8.1 Operational planning and control 8.2 Business impact analysis and risk assessment 8.2.1 General 8.2.2 Business impact analysis 8.3 Business continuity strategies and solutions 8.3.1 General 8.3.2 Identification of strategies and solutions 8.3.3 Selection of strategies and solutions CIS-11.1 Establish and Maintain a Data Recovery Process CIS-16.14 Conduct Threat Modeling CIS-18.2 Perform Periodic External Penetration Tests CIS-18.3 Remediate Penetration Test Findings CIS-18.5 Perform Periodic Internal Penetration Tests CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.2 Establish and Maintain a Remediation Process 5.29 Information security during disruption 5.30 ICT readiness for business continuity 5.8 Information security in project management 5.9 Inventory of information and other associated assets 8.27 Secure system architecture and engineering principles 8.28 Secure coding 8.8 Management of technical vulnerabilities CPS230-19 Tolerance Levels for Each Critical Operation CPS230-20 Prevention, Adaptation and Return to Normal Operations CPS230-26 Critical Operations Register, Continuity Plan and Activation CPS230-P12 Key Principles for Operational Risk, Resilience and Service Providers CPS230-P18 Integration with the Risk Management Framework and Recovery Planning CPS230-P40 Required Content of the Business Continuity Plan 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement 12.6.1 12.6.1 Formal security awareness program 6.1.2 6.1.2 Requirement 6 roles and responsibilities assigned 6.4.1 6.4.1 Public web application review or automated protection 6.3.1 6.3.1 Vulnerability identification and risk ranking 5.4 Planning 5.4.1 Actions to address risks and opportunities 5.6.2 Information security risk assessment 5.6.3 Information security risk treatment 6.14.1 Information security continuity 6.1 Actions to address risks and opportunities 6.1.2 AI risk assessment 6.1.3 AI risk treatment 6.1.4 AI system impact assessment 8.3 AI risk treatment CPS220-14 Scenario Analysis and Stress Testing Programs CPS220-P17 Group Liquidity Management Policy CPS220-P35 Required Content of Risk Management Policies and Procedures C5-BCM-02 Business impact analysis policies and instructions C5-BCM-03 Planning business continuity C5-SSO-05 Exit strategy for the receipt of benefits 5.29 Information security during disruption 5.30 ICT readiness for business continuity 8.14 Redundancy of information processing facilities ASD37-24 Non-persistent virtualised sandboxed environment (Very Good) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASBv3-GS-8 Define and implement backup and recovery strategy NS-5 Deploy DDOS protection E8-BACKUP-ML1 Regular Backups (ML1) SOC3-VENDOR Vendor and Subservice Management AEO-12 Crisis Management and Incident Recovery CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources Art.21.2.c Business continuity, backup management, disaster recovery and crisis management 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC9.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 153 it maps to, and the evidence behind each claim, over MCP and REST.