← SOC 2 · CC9 — Risk Mitigation

CC9.1 — Risk mitigation for business disruption

medium business-continuityrecoverybackup

Requirement

The entity identifies, selects and develops risk mitigation activities for risks arising from potential business disruptions.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
business continuitydisaster recoverybcpcontinuity plan
Required element 2 — any one of
backupredundan…failoverrecoverybacked up
Supporting terms — specificity signals
rtorpomulti-regionavailability zoneinsuranceannual test
Contradiction markers

Finding any of these outranks coverage — a policy that admits the gap is worse than silence.

no backups untested backups

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
ISO 27001 A.5.29 Information security during disruption business-continuity recovery
ISO 27001 A.8.13 Information backup backup recovery
HIPAA 164.308(a)(7)(ii)(B) Disaster recovery plan (R) recovery business-continuity
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected and tested backup recovery
NIST CSF 2.0 RC.RP-01 The recovery portion of the incident response plan is executed recovery business-continuity
HIPAA 164.308(a)(7)(ii)(A) Data backup plan (R) backup
HIPAA 164.308(a)(7)(ii)(C) Emergency mode operation plan (R) business-continuity
NIST CSF 2.0 RC.RP-05 Integrity of restored assets is verified recovery