Skip to main content
BCD

Business Continuity & Disaster Recovery

58 controls

Maintain a resilient capability to sustain business-critical functions while successfully responding to and recovering from incidents through well-documented and exercised processes.

SCF # Control Name Weight NIST CSF Frameworks
BCD-01 Business Continuity Management System (BCMS) 10 — Critical Govern 111
BCD-01.1 Coordinate with Related Plans 5 — Medium Recover 33
BCD-01.2 Coordinate With External Service Providers 5 — Medium Recover 17
BCD-01.3 Transfer to Alternate Processing / Storage Site 5 — Medium Recover 4
BCD-01.4 Recovery Time / Point Objectives (RTO / RPO) 5 — Medium Recover 41
BCD-01.5 Recovery Operations Criteria 6 — Medium Govern 10
BCD-01.6 Recovery Operations Communications 3 — Low Govern 7
BCD-02 Identify Critical Assets 9 — Critical Recover 57
BCD-02.1 Resume All Missions & Business Functions 8 — High Recover 31
BCD-02.2 Continue Essential Mission & Business Functions 8 — High Recover 28
BCD-02.3 Resume Essential Missions & Business Functions 8 — High Recover 30
BCD-02.4 Data Storage Location Reviews 8 — High Recover 7
BCD-03 Contingency Training 5 — Medium Recover 45
BCD-03.1 Simulated Events 3 — Low Recover 22
BCD-03.2 Automated Training Environments 1 — Low Recover 4
BCD-04 Contingency Plan Testing & Exercises 6 — Medium Recover 73
BCD-04.1 Coordinated Testing with Related Plans 3 — Low Recover 26
BCD-04.2 Alternate Storage & Processing Sites 5 — Medium Recover 14
BCD-05 Contingency Plan Root Cause Analysis (RCA) & Lessons Learned 9 — Critical Detect 60
BCD-06 Ongoing Contingency Planning 8 — High Recover 52
BCD-06.1 Contingency Planning Components 8 — High Recover 2
BCD-06.2 Contingency Plan Update Notifications 5 — Medium Recover 1
BCD-07 Alternative Security Measures 9 — Critical Protect 6
BCD-08 Alternate Storage Site 9 — Critical Protect 38
BCD-08.1 Separation from Primary Site 7 — High Protect 24
BCD-08.2 Accessibility 5 — Medium Protect 21
BCD-09 Alternate Processing Site 9 — Critical Protect 39
BCD-09.1 Separation from Primary Site 7 — High Protect 22
BCD-09.2 Accessibility 5 — Medium Recover 23
BCD-09.3 Alternate Site Priority of Service 6 — Medium Recover 20
BCD-09.4 Preparation for Use 5 — Medium Protect 10
BCD-09.5 Inability to Return to Primary Site 5 — Medium Protect 4
BCD-10 Telecommunications Services Availability 6 — Medium Recover 30
BCD-10.1 Telecommunications Priority of Service Provisions 6 — Medium Recover 21
BCD-10.2 Separation of Primary / Alternate Providers 5 — Medium Protect 13
BCD-10.3 Provider Contingency Plan 5 — Medium Protect 16
BCD-10.4 Alternate Communications Channels 5 — Medium Protect 12
BCD-11 Data Backups 10 — Critical Protect 110
BCD-11.1 Testing for Reliability & Integrity 9 — Critical Recover 53
BCD-11.2 Separate Storage for Critical Information 8 — High Protect 41
BCD-11.3 Recovery Images 8 — High Recover 4
BCD-11.4 Cryptographic Protection 9 — Critical Protect 37
BCD-11.5 Test Restoration Using Sampling 5 — Medium Protect 23
BCD-11.6 Transfer to Alternate Storage Site 5 — Medium Protect 18
BCD-11.7 Redundant Secondary System 5 — Medium Protect 12
BCD-11.8 Dual Authorization For Backup Media Destruction 5 — Medium Protect 4
BCD-11.9 Backup Access 9 — Critical Protect 4
BCD-11.10 Backup Modification and/or Destruction 9 — Critical Protect 4
BCD-12 Technology Assets, Applications and/or Services (TAAS) Recovery & Reconstitution 9 — Critical Protect 60
BCD-12.1 Transaction Recovery 9 — Critical Recover 24
BCD-12.2 Failover Capability 8 — High Recover 15
BCD-12.3 Electronic Discovery (eDiscovery) 8 — High Respond 5
BCD-12.4 Restore Within Time Period 5 — Medium Respond 11
BCD-13 Backup & Restoration Hardware Protection 8 — High Protect 18
BCD-13.1 Restoration Integrity Verification 7 — High Govern 5
BCD-14 Isolated Recovery Environment 5 — Medium Recover 6
BCD-15 Reserve Hardware 7 — High Recover 2
BCD-16 AI & Autonomous Technologies Incidents 10 — Critical Respond 3

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.