A.5.30 Organizational
ICT readiness for business continuity
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (13)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CP-10mostlyaligns with — Both controls focus on restoring systems and information to required states within defined timeframes after an interruption.
- CP-2mostlyaligns with — Both controls require development and maintenance of contingency plans that define recovery objectives and procedures to sustain critical operations during disruption.
- CP-4partialaligns with — Both controls mandate periodic testing and exercises of continuity plans to validate their effectiveness.
- CP-7partialaligns with — Both controls consider alternate processing capabilities as part of strategies to maintain ICT service availability after disruption.
- CP-9partialaligns with — Both controls address the need to back up and restore information to meet recovery point objectives during business continuity events.
- RA-2partialaligns with — Both controls use business impact analysis to determine the criticality of processes and the resources required to support them.
Aligned NIST CSF 2.0 outcomes (12)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.IM-04mostlyaligns with — The ISO control requires ICT continuity plans to be developed, approved, exercised, and maintained so they can be executed when disruption occurs, which directly supports the CSF outcome of establishing and maintaining incident response and other operational plans.
- PR.IR-03mostlyaligns with — By defining RTOs, RPOs, and performance requirements for ICT services and then implementing tested strategies to meet them, the control ensures mechanisms exist to achieve resilience requirements during adverse situations.
- GV.OC-04partialaligns with — The control identifies critical ICT services and their required availability levels so the organization can continue delivering products and services that external stakeholders depend on.
- ID.RA-04partialaligns with — The control uses business impact analysis to quantify the magnitude and duration of impacts from disrupted activities, which aligns with the CSF outcome of identifying potential impacts and likelihoods of threats exploiting vulnerabilities.
- ID.RA-05partialaligns with — Outputs from the BIA and risk assessment are used to select and prioritize ICT continuity strategies, matching the CSF outcome of using threats, vulnerabilities, likelihoods, and impacts to inform risk response prioritization.
- ID.RA-06partialaligns with — The control requires choosing and implementing ICT continuity strategies based on BIA and risk assessment results, which aligns with the CSF outcome of selecting, prioritizing, planning, and tracking risk responses.
Related OWASP ASVS 5.0 requirements (4)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (5)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1384partialmitigates — ICT readiness for business continuity includes resilience to environmental conditions.
- CWE-400partialmitigates — Defining RTOs and capacity requirements for ICT services during business-impact analysis forces organizations to provision sufficient resources and throttling mechanisms, reducing the likelihood that an attacker can induce denial-of-service through uncontrolled resource consumption.
- CWE-284nonenone — Requiring an organizational structure with explicit roles, responsibilities, and approval gates for ICT continuity ensures that only authorized personnel can activate recovery procedures or reconfigure services, thereby reducing opportunities for improper access control during disruption.
- CWE-770nonemitigates — Specifying performance and capacity limits for prioritized ICT services in continuity plans constrains how many resources can be allocated without explicit approval, limiting an attacker’s ability to exhaust memory, file handles, or other finite assets.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.