unified
UC-GOV-34 — Maintain business continuity and contingency planning policy
Establish, document, and disseminate contingency planning policy and procedures, identify risks arising from potential business disruptions — including to critical infrastructure and essential services — and select and develop mitigation activities (including consideration of insurance and other risk transfer) proportionate to those risks. Review and update the policy and the mitigation portfolio at defined intervals and after significant disruptions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-34
- title
- Maintain business continuity and contingency planning policy
- statement
- Establish, document, and disseminate contingency planning policy and procedures, identify risks arising from potential business disruptions — including to critical infrastructure and essential services — and select and develop mitigation activities (including consideration of insurance and other risk transfer) proportionate to those risks. Review and update the policy and the mitigation portfolio at defined intervals and after significant disruptions.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- CP-1
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PM-8
- coverage
- partial
- delta
- a dedicated critical-infrastructure and key-resources protection plan addressing security and privacy, beyond naming critical infrastructure as a disruption source
- relationship
- intersects_with
- framework
- soc2
- control_id
- CC9.1
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art21c
- coverage
- partial
- delta
- implemented backup, disaster recovery, and crisis management capabilities
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-34 — Maintain business continuity and contingency planning policy maps_to CP-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- CP-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-34 — Maintain business continuity and contingency planning policy maps_to CC9.1 — The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.
- framework
- soc2
- control_id
- CC9.1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-34 — Maintain business continuity and contingency planning policy maps_to PM-8 — Critical Infrastructure Plan
- framework
- nist-800-53
- control_id
- PM-8
- coverage
- partial
- delta
- a dedicated critical-infrastructure and key-resources protection plan addressing security and privacy, beyond naming critical infrastructure as a disruption source
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Policy Suite Review operates UC-GOV-34 — Maintain business continuity and contingency planning policy
- UC-GOV-34 — Maintain business continuity and contingency planning policy maps_to NIS2-Art21c — Business continuity, backup management and disaster recovery, crisis management
- framework
- nis2
- control_id
- NIS2-Art21c
- coverage
- partial
- delta
- implemented backup, disaster recovery, and crisis management capabilities
- relationship
- intersects_with
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-34 — Maintain business continuity and contingency planning policy mitigates Climate transition risk — carbon pricing and stranded assets
- strength
- related
- rationale
- UC-GOV-34 — Maintain business continuity and contingency planning policy mitigates Missing or insufficient security and privacy policies
- strength
- primary
- rationale
- Establishing contingency/business-continuity policy and disruption-mitigation requirements remedies a missing resilience policy.
- Security Control Assessment & POA&M Remediation tests UC-GOV-34 — Maintain business continuity and contingency planning policy
- SOC 2 Trust Services Readiness tests UC-GOV-34 — Maintain business continuity and contingency planning policy
- Policy Lifecycle Management oversees UC-GOV-34 — Maintain business continuity and contingency planning policy