Logo

CISOBot - Your AI CISO Assistant

BCD-06

Ongoing Contingency Planning

Weight: 8/10
Description

Mechanisms exist to update contingency plans due to changes affecting: (1) People (e.g., personnel changes); (2) Processes (e.g., new, altered or decommissioned business practices, including third-party services) (3) Technologies (e.g., new, altered or decommissioned technologies); (4) Data (e.g., changes to data flows and/or data repositories); (5) Facilities (e.g., new, altered or decommissioned physical infrastructure); and/or (6) Feedback from contingency plan testing activities.

Control Question

Does the organization update contingency plans due to changes affecting: (1) People (e.g., personnel changes); (2) Processes (e.g., new, altered or decommissioned business practices, including third-party services) (3) Technologies (e.g., new, altered or decommissioned technologies); (4) Data (e.g., changes to data flows and/or data repositories); (5) Facilities (e.g., new, altered or decommissioned physical infrastructure); and/or (6) Feedback from contingency plan testing activities?

Control Metadata
Domain:

Business Continuity & Disaster Recovery

Validation Cadence:

Annual

Evidence Request List:

E-BCM-05

Have questions about this control?

Ask CISOBot for implementation guidance and best practices