{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Business Continuity & Disaster Recovery","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-10","description":"Test business continuity, disaster recovery, and restoration capabilities at least annually through scenario exercises, failover and restore tests, and, where required for critical systems, advanced or threat-led penetration testing. Train all personnel with contingency roles on their responsibilities upon assignment and periodically thereafter. Review test and exercise results and remediate identified gaps.","details":{"control_category":"administrative","control_type":"detective","domain":"Business Continuity & Disaster Recovery","guidance":[],"members":[{"control_id":"CP-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"CP-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A1.3","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"DORA-Art24-27","coverage":"partial","delta":"vulnerability assessments and the Art 25 security-testing catalogue satisfied by companion controls; TLPT regime specifics - three-yearly cadence, authority-approved scope, independent/certified testers (Arts 26-27), and tester independence (Art 24(4)) - require dedicated controls","framework":"dora","relationship":"intersects_with"}],"statement":"Test business continuity, disaster recovery, and restoration capabilities at least annually through scenario exercises, failover and restore tests, and, where required for critical systems, advanced or threat-led penetration testing. Train all personnel with contingency roles on their responsibilities upon assignment and periodically thereafter. Review test and exercise results and remediate identified gaps.","title":"Test recovery capabilities and train contingency personnel","unified_id":"UC-BCDR-10"},"id":"uc:UC-BCDR-10","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-10","sourceIds":["dora","nist-800-53","soc2"],"sourceUrl":null,"title":"UC-BCDR-10 — Test recovery capabilities and train contingency personnel","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1d531e42d1d715ed599e863ffe36bae6966a39a6b05d5b0d83bc9e66693e2a39","properties":{"rationale":"annual exercises, failover/restore tests, and gap remediation directly cure the untested-plan condition","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.json","targetId":"risk:bcdr-no-tested-continuity-plan","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:22ff62f8a198d23e64dcf7728f0b1a4bdb22d1834ffcd2ebcdcb9e01463e5300","properties":{"rationale":"training all contingency-role personnel reduces single-person dependency for recovery execution","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/risk-hr-talent-loss-succession-50c0fc0a.json","targetId":"risk:hr-talent-loss-succession","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2a4cb1cf4b3bc12321bc556ef2ef799ae4d99a2cacb64894f72cffffad144d4b","properties":{"rationale":"testing failover/restore and remediating gaps reduces the likelihood that DR fails to activate in a real outage","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/risk-bcdr-it-resilience-outage-18dfc108.json","targetId":"risk:bcdr-it-resilience-outage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4d05733b4419190e661422dd121970d63c89fd4fa6f9ef72852ee10977c94901","properties":{"control_id":"CP-4","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-4-43fe9c9e.json","targetId":"ctrl:nist-800-53:CP-4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:61400058960e74453bf67e913c8094529fa4804cb7f815ff211aeb01a0421dca","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","targetId":"uc:UC-BCDR-10","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6d6078a852b7d9fb169bcc555d8c10e0d35d96dc8f824fba6fc625b33734792f","properties":{"control_id":"CP-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-3-bd1c9854.json","targetId":"ctrl:nist-800-53:CP-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:755930a2267db14151071e27c7edf890aabd6da76eb71af9ba66b69b52bbe266","properties":{"control_id":"A1.3","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/ctrl-soc2-a1-3-b64a7d41.json","targetId":"ctrl:soc2:A1.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:85e3fe15b6aecae5530dd0e132ddcc858e1e6040ce834f04a59cf58b13927548","properties":{},"sourceDetailPath":"/data/v1/records/wf-c14-c6170cdd.json","sourceId":"wf:C14","targetDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","targetId":"uc:UC-BCDR-10","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:875cfbac8df6a236a2e1428c73589c803433cea9a99404efd5a39e80e7f3dab9","properties":{},"sourceDetailPath":"/data/v1/records/wf-d11-12a96993.json","sourceId":"wf:D11","targetDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","targetId":"uc:UC-BCDR-10","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb8674403229a0ce2c5ec8c9080da85bd8087859e0a852a85af0bac50d670a98","properties":{"control_id":"DORA-Art24-27","coverage":"partial","delta":"vulnerability assessments and the Art 25 security-testing catalogue satisfied by companion controls; TLPT regime specifics - three-yearly cadence, authority-approved scope, independent/certified testers (Arts 26-27), and tester independence (Art 24(4)) - require dedicated controls","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art24-27-dc4b8836.json","targetId":"ctrl:dora:DORA-Art24-27","type":"maps_to"}],"schemaVersion":1}
