last sync: 2024-May-24 18:03:04 UTC

Microsoft Managed Control 1244 - Contingency Plan | Regulatory Compliance - Contingency Planning

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1244 - Contingency Plan
Id 6a13a8f8-c163-4b1b-8554-d63569dab937
Version 1.0.0
Details on versioning
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this Contingency Planning control
Additional metadata Name/Id: ACF1244 / Microsoft Managed Control 1244
Category: Contingency Planning
Title: Contingency Plan - Develop Plan
Ownership: Customer, Microsoft
Description: The organization: Develops a contingency plan for the information system that: Identifies essential missions and business functions and associated contingency requirements; Provides recovery objectives, restoration priorities, and metrics; Addresses contingency roles, responsibilities, assigned individuals with contact information; Addresses maintaining essential missions and business functions despite an information system disruption, compromise, or failure; Addresses eventual, full information system restoration without deterioration of the security safeguards originally planned and implemented; and Is reviewed and approved by Microsoft Azure Information System Security Officer;
Requirements: The Azure Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) provide the detailed processes for contingency planning for Azure. They serve as a guide for Azure to respond, recover, and resume operations during a serious adverse event. The BCP covers the actions taken by key personnel, resources, and services required to continue critical business processes and operations. This plan is intended to address extended business disruptions. The development of the BCP follows Microsoft’s Enterprise Business Continuity Management (EBCM) implementation standards. The DRP covers the actions taken by key personnel, resources, and services required to continue critical technology processes and operations. This plan is intended to address extended service disruptions. The development of the DRP follows Microsoft’s EBCM implementation standards. Azure also maintains the Business Continuity Management System (BCMS) Manual, which contains high-level standard operating procedures associated with the Azure program. These plans are followed by all technology services; however, the individual steps for recovery are stored separately by the owning service teams and hyperlinks to each team's plans are provided to the BCM team for verification. The BCP and DRP document all program requirements and standard operating procedures used by all services covering all commonly shared processes. The individual service plans are the details of how a service recovers regardless of outage scope that can be followed by any authorized member of a service team. This allows Azure to eliminate single points of failure and ensures continuity of operations.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Microsoft.Resources/subscriptions
Microsoft.Resources/subscriptions/resourceGroups
Compliance
The following 4 compliance controls are associated with this Policy definition 'Microsoft Managed Control 1244 - Contingency Plan' (6a13a8f8-c163-4b1b-8554-d63569dab937)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
op.cont.1 Impact analysis op.cont.1 Impact analysis 404 not found n/a n/a 68
op.cont.2 Continuity plan op.cont.2 Continuity plan 404 not found n/a n/a 68
op.cont.3 Periodic tests op.cont.3 Periodic tests 404 not found n/a n/a 91
op.cont.4 Alternative means op.cont.4 Alternative means 404 not found n/a n/a 95
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type
Spain ENS 175daf90-21e1-4fec-b745-7b4c909aa94c Regulatory Compliance GA BuiltIn
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC