{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Business Continuity & Disaster Recovery","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-01","description":"Maintain documented, management-approved business continuity and disaster recovery plans that cover critical business functions and ICT services, recovery time and recovery point objectives, assigned roles, and how information security is preserved at required levels during disruption. Base the plans on a business impact analysis, distribute them to responsible personnel, and review and update them at least annually and after significant organizational or technology changes.","details":{"control_category":"administrative","control_type":"corrective","domain":"Business Continuity & Disaster Recovery","guidance":[],"members":[{"control_id":"CP-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"DSS04","coverage":"partial","delta":"continuity testing, training, and post-incident review satisfied by companion controls","framework":"cobit-2019","relationship":"intersects_with"},{"control_id":"A.5.29","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"A.5.30","coverage":"partial","delta":"periodic ICT readiness testing satisfied by the testing control","framework":"iso-27001","relationship":"intersects_with"},{"control_id":"500.16","coverage":"partial","delta":"plan testing, training, and backup restore verification satisfied by companion controls","framework":"nydfs-500","relationship":"intersects_with"}],"statement":"Maintain documented, management-approved business continuity and disaster recovery plans that cover critical business functions and ICT services, recovery time and recovery point objectives, assigned roles, and how information security is preserved at required levels during disruption. Base the plans on a business impact analysis, distribute them to responsible personnel, and review and update them at least annually and after significant organizational or technology changes.","title":"Maintain business continuity and disaster recovery plans","unified_id":"UC-BCDR-01"},"id":"uc:UC-BCDR-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-01","sourceIds":["cobit-2019","iso-27001","nist-800-53","nydfs-500"],"sourceUrl":null,"title":"UC-BCDR-01 — Maintain business continuity and disaster recovery plans","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2dd1693b0f792eb20e6784f0968b02a491db0771423c109c75f29f16e99c13ea","properties":{"rationale":"maintaining a documented, approved, annually-reviewed BCP/DR plan directly cures the absent-plan condition","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","sourceId":"uc:UC-BCDR-01","targetDetailPath":"/data/v1/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.json","targetId":"risk:bcdr-no-tested-continuity-plan","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3792d36eb098d2bb19e0607931a001fe7aee1cee96ce18d08d776a922528f1c7","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","targetId":"uc:UC-BCDR-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:431c40a712233a54d834bcd73e9d690c190e8961ff93bc02a0bed592c4145ba0","properties":{"control_id":"CP-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","sourceId":"uc:UC-BCDR-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-2-46491517.json","targetId":"ctrl:nist-800-53:CP-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4c619442506fe595907cec0c29140d76d135eac51922f06e18251d204d100750","properties":{"control_id":"A.5.30","coverage":"partial","delta":"periodic ICT readiness testing satisfied by the testing control","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","sourceId":"uc:UC-BCDR-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-30-08880829.json","targetId":"ctrl:iso-27001:A.5.30","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:523a02ed41baf910806e759f33f602a9a7c8fa1127ebf731fae5490b892c41ee","properties":{"rationale":"the BIA-based plan identifies single points of failure and prescribes failover arrangements","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","sourceId":"uc:UC-BCDR-01","targetDetailPath":"/data/v1/records/risk-bcdr-single-point-concentration-91008453.json","targetId":"risk:bcdr-single-point-concentration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:744a97f39594bd347bec7116b495124f8681cc5bf4e5f1de30f82df3ba056c56","properties":{"rationale":"the BIA-based continuity plan prepares alternate operations for climate-driven facility disruption","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","sourceId":"uc:UC-BCDR-01","targetDetailPath":"/data/v1/records/risk-esg-climate-physical-210261c0.json","targetId":"risk:esg-climate-physical","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7843c3f12abcbdae8c0226c23f8a2d755a402c4d56140aecef697acc9b4fe5df","properties":{"control_id":"DSS04","coverage":"partial","delta":"continuity testing, training, and post-incident review satisfied by companion controls","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","sourceId":"uc:UC-BCDR-01","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss04-2d611bca.json","targetId":"ctrl:cobit-2019:DSS04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:99c97e797190f26c810022f7b92ca57025f6d3039e3bda9cb9905a60caff5f98","properties":{"control_id":"500.16","coverage":"partial","delta":"plan testing, training, and backup restore verification satisfied by companion controls","framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","sourceId":"uc:UC-BCDR-01","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-16-19fe7459.json","targetId":"ctrl:nydfs-500:500.16","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c1f2c4a4ddc829ff28a8233d24d7a516fb98a13c98f69f4531253db789ba24df","properties":{},"sourceDetailPath":"/data/v1/records/wf-c14-c6170cdd.json","sourceId":"wf:C14","targetDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","targetId":"uc:UC-BCDR-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cd56bdb5232e801282f9017b4dcaff51109527907a5163696a94c6924aeebd4a","properties":{"rationale":"the contingency plan provides alternate arrangements for loss of power/HVAC/telecoms","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","sourceId":"uc:UC-BCDR-01","targetDetailPath":"/data/v1/records/risk-tech-loss-essential-services-b7feae05.json","targetId":"risk:tech-loss-essential-services","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f8611c3a55644212e48bf360d4c2a232964e53b4e26a9d51bb92b53b3cee9daf","properties":{"control_id":"A.5.29","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","sourceId":"uc:UC-BCDR-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-29-e6db7f58.json","targetId":"ctrl:iso-27001:A.5.29","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fe43036f9f35d71c401c278a6874f3fbef3bc12c421ac6b08b6e293a97b00698","properties":{"rationale":"the plan provides continuity arrangements to recover after a facility-damaging disaster","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","sourceId":"uc:UC-BCDR-01","targetDetailPath":"/data/v1/records/risk-phys-damage-physical-assets-disaster-23118626.json","targetId":"risk:phys-damage-physical-assets-disaster","type":"mitigates"}],"schemaVersion":1}
