SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC9.1: CC9.1 Mitigating risks of business disruption

Measures to reduce the risk of business disruption are identified, selected and developed. Points of focus: policies, procedures, communication plans and fallback processing are prepared in advance so the organisation can respond, limit the damage and recover from disruptive security events, with monitoring and information flows to meet objectives during those efforts; and insurance is considered to cover the financial cost of loss events.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 153 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 17 controls

FedRAMP High · 14 controls

  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • CP-2 Contingency Plan
  • CP-6 Alternate Storage Site
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-7 Alternate Processing Site
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • IR-3 Incident Response Testing
  • RA-3 Risk Assessment
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • RA-7 Risk Response
  • RA-9 Criticality Analysis (RA-9)
  • SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2))
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed
  • NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms

FedRAMP Moderate · 13 controls

  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • CP-2 Contingency Plan
  • CP-6 Alternate Storage Site
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-7 Alternate Processing Site
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • IR-3 Incident Response Testing
  • RA-3 Risk Assessment
  • RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage (RA-5(3))
  • RA-9 Criticality Analysis (RA-9)
  • SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2))
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))

ISO 22301:2019 · 10 controls

  • 6.1 Actions to address risks and opportunities
  • 6.1.2 Addressing risks and opportunities
  • 8.1 Operational planning and control
  • 8.2 Business impact analysis and risk assessment
  • 8.2.1 General
  • 8.2.2 Business impact analysis
  • 8.3 Business continuity strategies and solutions
  • 8.3.1 General
  • 8.3.2 Identification of strategies and solutions
  • 8.3.3 Selection of strategies and solutions

CIS Controls v8 · 7 controls

  • CIS-11.1 Establish and Maintain a Data Recovery Process
  • CIS-16.14 Conduct Threat Modeling
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-18.5 Perform Periodic Internal Penetration Tests
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process

HIPAA Security Rule · 7 controls

ISO 27002:2022 · 7 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 5.8 Information security in project management
  • 5.9 Inventory of information and other associated assets
  • 8.27 Secure system architecture and engineering principles
  • 8.28 Secure coding
  • 8.8 Management of technical vulnerabilities
  • CPS230-19 Tolerance Levels for Each Critical Operation
  • CPS230-20 Prevention, Adaptation and Return to Normal Operations
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • CPS230-P12 Key Principles for Operational Risk, Resilience and Service Providers
  • CPS230-P18 Integration with the Risk Management Framework and Recovery Planning
  • CPS230-P40 Required Content of the Business Continuity Plan

NIST SP 800-66 Rev 2 · 6 controls

PCI DSS 4.0 · 6 controls

  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.6.1 12.6.1 Formal security awareness program
  • 6.1.2 6.1.2 Requirement 6 roles and responsibilities assigned
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking

ISO 27701:2019 · 5 controls

  • 5.4 Planning
  • 5.4.1 Actions to address risks and opportunities
  • 5.6.2 Information security risk assessment
  • 5.6.3 Information security risk treatment
  • 6.14.1 Information security continuity

ISO/IEC 42001:2023 · 5 controls

  • 6.1 Actions to address risks and opportunities
  • 6.1.2 AI risk assessment
  • 6.1.3 AI risk treatment
  • 6.1.4 AI system impact assessment
  • 8.3 AI risk treatment
  • CPS220-14 Scenario Analysis and Stress Testing Programs
  • CPS220-P17 Group Liquidity Management Policy
  • CPS220-P35 Required Content of Risk Management Policies and Procedures

C5 (Germany) · 3 controls

  • C5-BCM-02 Business impact analysis policies and instructions
  • C5-BCM-03 Planning business continuity
  • C5-SSO-05 Exit strategy for the receipt of benefits

CMMC 2.0 · 3 controls

ISO 27001:2022 · 3 controls

  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 8.14 Redundancy of information processing facilities

NIST SP 800-161 Rev 1 · 3 controls

  • ASD37-24 Non-persistent virtualised sandboxed environment (Very Good)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASBv3-GS-8 Define and implement backup and recovery strategy
  • NS-5 Deploy DDOS protection

DORA · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

  • E8-BACKUP-ML1 Regular Backups (ML1)

AICPA SOC 3 · 1 control

  • SOC3-VENDOR Vendor and Subservice Management

APRA CPS 234 · 1 control

  • AEO-12 Crisis Management and Incident Recovery
  • CFTC-SS-8 Business Continuity and Disaster Recovery Plan and Resources

EU AI Act · 1 control

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management

NIST SP 800-172 · 1 control

  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC9.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 153 it maps to, and the evidence behind each claim, over MCP and REST.