Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC9.1Risk mitigation for business disruptionsSOC 2Risk Mitigation

Official Requirement

The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

You've thought through what could disrupt operations, infrastructure failure, a security incident, a key vendor going down, a ransomware attack, and you have documented, tested plans for each material risk. This isn't just a BCDR plan sitting in a drawer; auditors want to see the risk assessment that identified the disruption risks, the controls selected to mitigate them, and evidence the plans are tested.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Business continuity and disaster recovery plan with annual testing

Implementation steps

  1. Write the BCDR Plan covering: which systems are Tier 1 (production, critical), Tier 2 (management infrastructure), and Tier 3 (non-critical); define RPO and RTO per tier
  2. Document the recovery sequence: what gets restored first, how long each step should take, who owns each step, this becomes the playbook for a real event
  3. Conduct an annual BCDR tabletop exercise; use a realistic scenario (e.g., primary server unrecoverable after ransomware); document participants, decisions made, gaps identified, and plan updates
  4. Validate offsite backup restore capability annually: pull the offsite backup and restore to a spare or staging system; record time-to-restore and compare to RTO target

Tools / systems

Evidence artifacts

Evidence frequency: Annual plan review, tabletop, and restore test; risk register updated per new risk identified