You've thought through what could disrupt operations, infrastructure failure, a security incident, a key vendor going down, a ransomware attack, and you have documented, tested plans for each material risk. This isn't just a BCDR plan sitting in a drawer; auditors want to see the risk assessment that identified the disruption risks, the controls selected to mitigate them, and evidence the plans are tested.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Business continuity and disaster recovery plan with annual testing
Implementation Steps
Write and publish a BCDR Plan covering: RPO and RTO targets per system tier, failover procedures for critical infrastructure, communication protocols during a disruption, and recovery validation steps
Test the BCDR Plan annually via tabletop exercise or a live failover test; a tabletop is acceptable for Type I; Type II auditors prefer evidence of a real restore or failover
Maintain a formal risk register that includes business disruption risks (ransomware, data center outage, key vendor failure, critical employee departure) with likelihood, impact, and selected mitigation
Obtain cyber insurance as a financial risk transfer control; include policy number and coverage summary in your GRC platform as evidence of CC9.1
Tools / Systems
AWS Backup / Azure Backup (recovery tooling)Jira (BCDR test ticket)PagerDuty (escalation during disruption)Datadog (system health monitoring)
Typical Control Business continuity and disaster recovery plan with annual testing
Evidence Artifacts
BCDR Plan document with effective date, RPO/RTO targets, and management sign-off
Annual BCDR test record: tabletop or failover test summary with date, participants, scenario, and findings
Risk register showing business disruption risks with mitigation strategies (cyber insurance, backup, DR site, etc.)
Cyber insurance certificate or policy summary as evidence of financial risk mitigation
📅Annual BCDR plan review and test; risk register updated quarterly or on material changes
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
CC9.2
Vendor and business partner risk management
Risk Mitigation
4 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Business continuity and disaster recovery plan with annual testing
Implementation steps
Write the BCDR Plan covering: which systems are Tier 1 (production, critical), Tier 2 (management infrastructure), and Tier 3 (non-critical); define RPO and RTO per tier
Document the recovery sequence: what gets restored first, how long each step should take, who owns each step, this becomes the playbook for a real event
Conduct an annual BCDR tabletop exercise; use a realistic scenario (e.g., primary server unrecoverable after ransomware); document participants, decisions made, gaps identified, and plan updates
Validate offsite backup restore capability annually: pull the offsite backup and restore to a spare or staging system; record time-to-restore and compare to RTO target
Tools / systems
Veeam (backup and recovery)
Ansible (automated restore runbooks)
Wazuh (log collection/HIDS) (monitoring during recovery)
BCDR Policy document
Evidence artifacts
BCDR Plan with tier definitions, RPO/RTO targets, recovery sequence, and management approval