{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-34","description":"Establish, document, and disseminate contingency planning policy and procedures, identify risks arising from potential business disruptions — including to critical infrastructure and essential services — and select and develop mitigation activities (including consideration of insurance and other risk transfer) proportionate to those risks. Review and update the policy and the mitigation portfolio at defined intervals and after significant disruptions.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"CP-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-8","coverage":"partial","delta":"a dedicated critical-infrastructure and key-resources protection plan addressing security and privacy, beyond naming critical infrastructure as a disruption source","framework":"nist-800-53","relationship":"intersects_with"},{"control_id":"CC9.1","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"NIS2-Art21c","coverage":"partial","delta":"implemented backup, disaster recovery, and crisis management capabilities","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate contingency planning policy and procedures, identify risks arising from potential business disruptions — including to critical infrastructure and essential services — and select and develop mitigation activities (including consideration of insurance and other risk transfer) proportionate to those risks. Review and update the policy and the mitigation portfolio at defined intervals and after significant disruptions.","title":"Maintain business continuity and contingency planning policy","unified_id":"UC-GOV-34"},"id":"uc:UC-GOV-34","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-34","sourceIds":["nis2","nist-800-53","soc2"],"sourceUrl":null,"title":"UC-GOV-34 — Maintain business continuity and contingency planning policy","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:15cd1a20fa8bc8096bd99aaf54e98f47df2c480f79019d16375d16f2586bea49","properties":{"control_id":"CP-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","sourceId":"uc:UC-GOV-34","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-1-be151c69.json","targetId":"ctrl:nist-800-53:CP-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1d05fc488bb82a51f8853521d1fcbfae211372a2da40addc5f037bee16a37d1c","properties":{"control_id":"CC9.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","sourceId":"uc:UC-GOV-34","targetDetailPath":"/data/v1/records/ctrl-soc2-cc9-1-6178c12c.json","targetId":"ctrl:soc2:CC9.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1f3f395497ce4d9de03a0b3fb04e419fc1beb8e37c57deb756cb212f8930eacd","properties":{"control_id":"PM-8","coverage":"partial","delta":"a dedicated critical-infrastructure and key-resources protection plan addressing security and privacy, beyond naming critical infrastructure as a disruption source","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","sourceId":"uc:UC-GOV-34","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-8-1546c8e6.json","targetId":"ctrl:nist-800-53:PM-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:28924eaf63c56558668827e696e6bcad38ab1711084f0eacb81df94d94ed5c11","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","targetId":"uc:UC-GOV-34","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:93817c15ca7c0c4a4f1c60da13e03e351009be1df0a08220e23ff8cbb387b35e","properties":{"control_id":"NIS2-Art21c","coverage":"partial","delta":"implemented backup, disaster recovery, and crisis management capabilities","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","sourceId":"uc:UC-GOV-34","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21c-18adf13b.json","targetId":"ctrl:nis2:NIS2-Art21c","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a4c83f9347f2c3822f73444eab68928d9538e58c47af17c84256bc804e23f817","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","sourceId":"uc:UC-GOV-34","targetDetailPath":"/data/v1/records/risk-esg-climate-transition-35e73915.json","targetId":"risk:esg-climate-transition","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b31cfc206efc91fc97e130dc732683be4fcbba6ff8e26ac0edd9f22c61b0ae4b","properties":{"rationale":"Establishing contingency/business-continuity policy and disruption-mitigation requirements remedies a missing resilience policy.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","sourceId":"uc:UC-GOV-34","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8aac1873d520133a213756c6eb8159774ddd1d167378661f648c59faa3c9463","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","targetId":"uc:UC-GOV-34","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:de616a147b2365ba5faac5120a250503e61029343d6a45b71aaca9c9c83df528","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","targetId":"uc:UC-GOV-34","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f830945fe84e4b0620e2bc65167b8a30c1a671e0059e5adab1f906d542a4879a","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","targetId":"uc:UC-GOV-34","type":"oversees"}],"schemaVersion":1}
