UK Security and Emergency Measures Direction (SEMD) - Water Industry
Cyber Security and Operational Technology

UK Security and Emergency Measures Direction (SEMD) - Water Industry SEMD-CS-3: Cyber Resilience

Companies must demonstrate holistic resilience covering both cyber protection and recovery capabilities.

What else in your programme already covers this

This control maps to 145 controls across 55 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • 4.4.8 Business Continuity and Recovery

ISO/IEC 27031:2011 · 4 controls

PCI PIN Security · 4 controls

API 1164 · 3 controls

  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

IEC 62443 · 3 controls

ISO 27019 · 3 controls

NIST SP 1800-32 · 3 controls

PCI P2PE · 3 controls

PCI SSF · 3 controls

SOC 2 · 3 controls

  • SOC2-A1.1 Maintains capacity to meet availability commitments
  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-A1.3 Recovery plan procedures support system recovery from failures

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • DIQ-1 Data Integration and Interoperability
  • RMD-1 Reference Data Management
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO 22316 · 2 controls

ISO 22317 · 2 controls

ISO 22318 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

  • SOCI-S30BC Notification of critical cyber security incidents (12 hours)
  • SOCI-S30BD Notification of other cyber security incidents (72 hours)

South Korea ISMS-P · 2 controls

COBIT 2019 · 1 control

  • CAT-D5-4 Resilience planning and testing

ISO 20000-1 · 1 control

ISO 22320:2018 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27043 · 1 control

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 27011:2024 · 1 control

ISO/SAE 21434 · 1 control

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

NIST SP 800-190 · 1 control

SASB Standards · 1 control

  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • UKAI-3 Bias Detection, Fairness, Validation
  • UKOPRES-5 Third-Party Risk, Concentration Risk

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Cyber Security and Operational Technology

Query this from an agent

The graph holds this control, the 145 it maps to, and the evidence behind each claim, over MCP and REST.