Crisis management plan
The structure that takes command when an event exceeds the incident plan: who leads, who speaks, how warnings and communications are issued.
How the register reads it
| Also called | crisis response plan, emergency response plan |
|---|---|
| Family | Resilience and incidents |
| Document type | Plan. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Folds into | The regimes accept it folded into the business continuity plan; when neither is listed, the gap is counted once, under the parent. |
| Expected owner | The business continuity manager or COO. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | never on its own: the register recognises it and names the clauses, but no ticked regime lists it as a separate document (its parent, business continuity plan, is). |
| Template | Crisis management plan. |
Which standards require it, and what each expects it to contain
4 requiring clauses, 3 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO 22301:2019
ISO 22301 8.4.2 Response structureImplement and maintain a structure of one or more teams responsible for responding to disruptions, with roles, responsibilities and inter team relationships clearly stated, collectively competent to assess a disruption and its impact against pre defined thresholds justifying a formal response, activate the response and the continuity solutions, plan actions, set priorities with life safety first, monitor the disruption and the response, and communicate with interested parties, authorities and the media; each team must have identified personnel and alternates with the necessary responsibility, authority and competence, and documented procedures for activation, operation, coordination and communication.
Common gap: Alternates named on paper but never included in an exercise
Source: ISO 22301:2019
ISO 22301 8.4.3 Warning and communicationDocument and maintain procedures for communicating internally and externally with relevant interested parties covering what, when, with whom and how, for receiving, documenting and responding to communications including from national or regional risk advisory systems, for keeping the means of communication available during a disruption, for structured communication with emergency responders, for the organization's media response and communications strategy, and for recording the disruption, the actions taken and the decisions made; where applicable also alert parties potentially impacted by an actual or impending disruption and ensure coordination between multiple responding organizations, and exercise these procedures within the exercise programme.
Common gap: Communication cascade depends on the corporate email and telephony that the disruption removes
Source: ISO 22301:2019
DORA (Regulation (EU) 2022/2554)
DORA Art. 14 CommunicationFinancial entities shall have crisis communication plans enabling responsible disclosure of major ICT-related incidents or vulnerabilities to clients, counterparts and the public as appropriate, and designate communication policies for internal staff and external stakeholders.
Common gap: No crisis communication plan
Source: DORA (Regulation (EU) 2022/2554)
The NIS2 Directive
NIS2 Art. 21(2)(c) Business continuity, backup management, disaster recovery and crisis managementThis category asks the entity to be able to keep providing its services, or to restore them, when systems fail or are attacked. Backup management means backups that are taken, protected against the same event that takes out production, and demonstrably restorable, which is why restore testing rather than backup success rate is the evidence that counts. Disaster recovery means recovery objectives that were derived from what the service can actually tolerate, and infrastructure and procedure capable of meeting them. Crisis management is the decision-making layer above both: who declares a crisis, who can commit the organisation, how the entity communicates while under pressure. Because NIS2 is concerned with continuity of service to recipients, recovery objectives set purely from internal convenience are the usual weak point.
Common gap: Backups verified as completed but never restored end to end
Source: NIS2 Directive
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register