RES-04Resilience and Response

Continuity and recovery objectives

Critical processes have recovery objectives, a continuity plan and a tested route back to service.

Why it exists

Objectives set before an outage are decisions; after one they are excuses.

What usually proves it

BIA, RTO and RPO, plan, exercise records.

Smaller organizations

Know which three processes matter and how long you can be down.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · A1.3
  • Fully addressedISO/IEC 27001 Annex A · A.5.29
  • Fully addressedNIST Cybersecurity Framework · RC.RP-01
  • Deliberately absentPCI DSS — Continuity is out of scope; the standard addresses cardholder data protection.
  • Fully addressedHIPAA Security Rule · 164.308(a)(7)
  • Partially addressedGDPR · Art. 32(1)(c) — Timely restoration of availability.
  • Deliberately absentEU AI Act — Not addressed.
  • Partially addressedNIST AI Risk Management Framework · MANAGE 4.3 — Contingency planning.