A.5.29 Organizational
Information security during disruption
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (10)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CP-10mostlyaligns with — Both emphasize restoring the security posture of information and supporting systems to a defined level within required time frames after a disruption.
- CP-2mostlyaligns with — Both controls require the development and maintenance of documented plans that preserve security objectives when normal operations are interrupted.
- CP-4partialaligns with — Both require testing of continuity arrangements to verify that security controls remain effective or can be restored after an interruption.
- CP-7partialaligns with — Both address the need to sustain or re-establish security controls at an alternate processing site when primary operations are disrupted.
- IR-4partialaligns with — Both require the organization to maintain or restore security controls as part of handling incidents that interrupt normal operations.
Aligned NIST CSF 2.0 outcomes (8)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.IM-04mostlyaligns with — By mandating that information security requirements be integrated into business continuity processes and that plans be developed, tested, reviewed, and evaluated, the ISO control fulfills the CSF outcome of establishing, communicating, maintaining, and testing incident response and other cybersecurity plans that affect operations.
- PR.IR-03mostlyaligns with — The ISO control requires embedding information security controls into business continuity and ICT continuity plans so that security is maintained or restored during disruption, which directly supports the CSF outcome of implementing mechanisms to achieve resilience requirements in both normal and adverse situations.
- GV.SC-08partialaligns with — The ISO control’s emphasis on maintaining or restoring security of information for critical business processes during disruption supports the CSF outcome of including relevant suppliers and third parties in incident planning, response, and recovery activities.
- RC.RP-01partialaligns with — The ISO control’s requirement to restore information security at the required level and within defined time frames after an interruption aligns with the CSF outcome of executing the recovery portion of the incident response plan once initiated.
- RC.RP-04partialaligns with — Including information security controls in business continuity plans ensures that critical mission functions and cybersecurity risk management are considered when establishing post-incident operational norms, matching the CSF outcome.
Related OWASP ASVS 5.0 requirements (5)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (6)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1384partialmitigates — Ensures information security is maintained during physical or environmental disruptions.
- CWE-284partialmitigates — By requiring compensating controls and restoration of security mechanisms during disruption, the control limits the window in which an attacker can exploit missing or degraded access-control enforcement.
- CWE-400partialmitigates — Business-continuity plans that include resource-management controls reduce the likelihood that an attacker can trigger uncontrolled resource consumption by forcing the system into a degraded or fallback state.
- CWE-693nonenone — Requiring compensating controls when primary security functions cannot be maintained ensures that protection mechanisms are not simply disabled, thereby reducing the impact of protection-mechanism failure during disruption.
- CWE-770nonemitigates — Mandating tested continuity procedures that preserve or replace resource-limiting controls prevents an attacker from exploiting the absence of throttling mechanisms during an outage.
Prevented OWASP Web Top 10 (2025) risks (2)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialmitigates — By requiring compensating controls and the preservation of existing security settings during disruption, the control reduces the chance that emergency workarounds will leave systems running with insecure defaults or missing patches.
- A09partialmitigates — Embedding security controls into business-continuity plans ensures that logging and alerting mechanisms remain active or are replaced by equivalents, preventing gaps in visibility when normal operations are interrupted.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.