SC-47 Alternate Communications Paths

System and Communications Protection

New in Rev 5

Description

Establish [Assignment: organization-defined parameters] for system operations organizational command and control.

Supplemental Guidance

An incident, whether adversarial- or nonadversarial-based, can disrupt established communications paths used for system operations and organizational command and control. Alternate communications paths reduce the risk of all communications paths being affected by the same incident. To compound the problem, the inability of organizational officials to obtain timely information about disruptions or to provide timely direction to operational elements after a communications path incident, can impact the ability of the organization to respond to such incidents in a timely manner. Establishing alternate communications paths for command and control purposes, including designating alternative decision makers if primary decision makers are unavailable and establishing the extent and limitations of their actions, can greatly facilitate the organization’s ability to continue to operate and take appropriate actions during an incident.

Changes from Rev 4

New control in Rev 5.

Compliance Mappings

CIS Controls v8

CIS 17.6

NIS2 Directive

Art. 21(2)(j)

BSI IT-Grundschutz

NET.1.1

ANSSI

Hygiene.24SecNumCloud.10.7SecNumCloud.14.4SecNumCloud.18.3

FINMA Circular 2023/1

IV.C(62)IV.E(90)

EU DORA

Art.9(4)(a)

RBI CSF

Annex1.4

FISC Security Guidelines

FISC.T13FISC.T3

EU CRA

CRA.I.2i

Qatar NIA

CS

IOSCO Cyber Resilience

RR-4

SEBI CSCRF

PR.NS

BOT Cyber Resilience

Ch2.4

Solvency II

EIOPA-ICT-4.6

Lloyd's Minimum Standards

MS8.9