RES-04Resilience and Response
Continuity and recovery objectives
Critical processes have recovery objectives, a continuity plan and a tested route back to service.
Why it exists
Objectives set before an outage are decisions; after one they are excuses.
What usually proves it
BIA, RTO and RPO, plan, exercise records.
Smaller organizations
Know which three processes matter and how long you can be down.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · A1.3
- Fully addressedISO/IEC 27001 Annex A · A.5.29
- Fully addressedNIST Cybersecurity Framework · RC.RP-01
- Deliberately absentPCI DSS — Continuity is out of scope; the standard addresses cardholder data protection.
- Fully addressedHIPAA Security Rule · 164.308(a)(7)
- Partially addressedGDPR · Art. 32(1)(c) — Timely restoration of availability.
- Deliberately absentEU AI Act — Not addressed.
- Partially addressedNIST AI Risk Management Framework · MANAGE 4.3 — Contingency planning.