Policy Register

Crisis management plan

The structure that takes command when an event exceeds the incident plan: who leads, who speaks, how warnings and communications are issued.

How the register reads it

Also calledcrisis response plan, emergency response plan
FamilyResilience and incidents
Document typePlan. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the business continuity plan; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe business continuity manager or COO.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whennever on its own: the register recognises it and names the clauses, but no ticked regime lists it as a separate document (its parent, business continuity plan, is).
TemplateCrisis management plan.

Which standards require it, and what each expects it to contain

4 requiring clauses, 3 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO 22301:2019

ISO 22301 8.4.2 Response structure

Implement and maintain a structure of one or more teams responsible for responding to disruptions, with roles, responsibilities and inter team relationships clearly stated, collectively competent to assess a disruption and its impact against pre defined thresholds justifying a formal response, activate the response and the continuity solutions, plan actions, set priorities with life safety first, monitor the disruption and the response, and communicate with interested parties, authorities and the media; each team must have identified personnel and alternates with the necessary responsibility, authority and competence, and documented procedures for activation, operation, coordination and communication.

Evidence an auditor accepts: Team structure chart with roles, responsibilities and inter team relationships; pre defined activation thresholds and the authority to invoke them; named team members and alternates with competence evidence
Common gap: Alternates named on paper but never included in an exercise
Source: ISO 22301:2019
ISO 22301 8.4.3 Warning and communication

Document and maintain procedures for communicating internally and externally with relevant interested parties covering what, when, with whom and how, for receiving, documenting and responding to communications including from national or regional risk advisory systems, for keeping the means of communication available during a disruption, for structured communication with emergency responders, for the organization's media response and communications strategy, and for recording the disruption, the actions taken and the decisions made; where applicable also alert parties potentially impacted by an actual or impending disruption and ensure coordination between multiple responding organizations, and exercise these procedures within the exercise programme.

Evidence an auditor accepts: Communication procedures covering internal, external, responder and media routes; verified alternate communication means that survive loss of primary systems; incident log template and completed logs from exercises or real events
Common gap: Communication cascade depends on the corporate email and telephony that the disruption removes
Source: ISO 22301:2019

DORA (Regulation (EU) 2022/2554)

DORA Art. 14 Communication

Financial entities shall have crisis communication plans enabling responsible disclosure of major ICT-related incidents or vulnerabilities to clients, counterparts and the public as appropriate, and designate communication policies for internal staff and external stakeholders.

Evidence an auditor accepts: Crisis communication plan for major ICT incidents
Common gap: No crisis communication plan
Source: DORA (Regulation (EU) 2022/2554)

The NIS2 Directive

NIS2 Art. 21(2)(c) Business continuity, backup management, disaster recovery and crisis management

This category asks the entity to be able to keep providing its services, or to restore them, when systems fail or are attacked. Backup management means backups that are taken, protected against the same event that takes out production, and demonstrably restorable, which is why restore testing rather than backup success rate is the evidence that counts. Disaster recovery means recovery objectives that were derived from what the service can actually tolerate, and infrastructure and procedure capable of meeting them. Crisis management is the decision-making layer above both: who declares a crisis, who can commit the organisation, how the entity communicates while under pressure. Because NIS2 is concerned with continuity of service to recipients, recovery objectives set purely from internal convenience are the usual weak point.

Evidence an auditor accepts: Business impact analysis deriving recovery time and recovery point objectives from service tolerance; backup configuration showing isolation or immutability against destructive attack; restore test results, dated, covering the systems that carry the essential service
Common gap: Backups verified as completed but never restored end to end
Source: NIS2 Directive

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Business impact analysis · Disaster recovery plan