Skip to content

Latest commit

 

History

History
22 lines (22 loc) · 2.34 KB

cc91.md

File metadata and controls

22 lines (22 loc) · 2.34 KB

SOC2 - CC9.1

The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions

Considers Mitigation of Risks of Business Disruption

Risk mitigation activities include the development of planned policies, procedures, communications, and alternative processing solutions to respond to, mitigate, and recover from security events that disrupt business operations. Those policies and procedures include monitoring processes and information and communications to meet the entity's objectives during response, mitigation, and recovery efforts.

Considers the Use of Insurance to Mitigate Financial Impact Risks

The risk management activities consider the use of insurance to offset the financial impact of loss events that would otherwise impair the ability of the entity to meet its objectives.

Mapped SCF controls