Continuity controls
The 50 controls in the continuity pillar and how they relate to strategies and plans.
The continuity pillar
There are 50 controls, the continuity slice of the shared library, mapped onto ISO 22301. They cover business impact analysis, recovery time and point objectives, operational continuity plans, tests and simulation exercises, and the continuity management system itself.
The distribution by supplier profile is 28 at P1, 42 cumulative at P2, and all 50 at P3 — continuity, like privacy, starts early, because a small supplier's unavailability can interrupt a large process.
Two different readings
It is worth separating where each thing shows up. These controls' maturity in your organization's self-assessment says how structured your continuity program is. The same control family answered by a supplier says how structured theirs is — and that is what feeds the service-unavailability risk category.
Relationship to strategies
A continuity control does not replace a recovery strategy, or the other way round. The control asserts that a practice exists — that there is a documented plan, that there is a periodic exercise. The strategy is the concrete answer to a specific scenario. A mature control program alongside uncovered processes in the coverage view is a possible combination, and one worth paying attention to.