Skip to main content

RISE 2026 Control Table

The table below lists the operational controls covered in the RISE 2026 benchmark. The controls are grouped by category so teams can use the table as a compact reference when assessing maturity, planning remediation work, or preparing evidence for internal and external reviews.

The maturity columns are intentionally left blank so organizations can record their current state, target state, or assessment notes directly against each control.

CategoryControl namelevel 1level 2level 3level 4level 5
Governance and Risk ManagementDefine a formal resilience governance model with clear accountability
Governance and Risk ManagementPerform regular resilience risk assessments and maintain a risk register
Governance and Risk ManagementDefine resilience objectives and tolerances for critical services
Governance and Risk ManagementEstablish exception management and compensating controls for unmet requirements
Governance and Risk ManagementReport resilience posture and remediation progress to leadership regularly
Third-Party and SaaS ResilienceMaintain an inventory of critical third-party and SaaS dependencies
Third-Party and SaaS ResilienceAssess concentration risk and exit readiness for critical providers
Third-Party and SaaS ResilienceDefine minimum resilience and security requirements for suppliers
Third-Party and SaaS ResilienceMonitor supplier performance, incidents, and contractual recovery commitments
Third-Party and SaaS ResilienceTest contingency plans for third-party and SaaS disruption
Data Backup and RecoveryEstablish a regular backup schedule for critical data
Data Backup and RecoveryStore backups in multiple locations (offsite and/or cloud-based storage)
Data Backup and RecoveryImplement a versioning system to track and restore previous versions of data
Data Backup and RecoveryEncrypt backups to protect sensitive data
Data Backup and RecoveryTest backup and recovery processes periodically to ensure data integrity
Network redundancy and failoverImplement redundant network connections to prevent single points of failure
Network redundancy and failoverUse load balancers to distribute traffic evenly across resources
Network redundancy and failoverEmploy network failover solutions (e.g., redundant routers, switches)
Network redundancy and failoverMonitor network performance and latency to detect potential issues
Network redundancy and failoverTest network redundancy and failover processes to ensure proper functioning
Infrastructure monitoring and alertingImplement a monitoring system to track the health and performance of cloud infrastructure
Infrastructure monitoring and alertingSet up alerts for critical events and performance thresholds
Infrastructure monitoring and alertingMonitor resource usage to identify potential bottlenecks and capacity issues
Infrastructure monitoring and alertingEstablish a centralized logging system to collect and analyze logs from various components
Infrastructure monitoring and alertingRegularly review monitoring data to identify trends and improve infrastructure resilience
Incident response planningDevelop a formal incident response plan, including roles and responsibilities
Incident response planningEstablish a communication plan for internal and external stakeholders during incidents
Incident response planningPerform regular incident response drills to test and refine the plan
Incident response planningDocument lessons learned from incidents and update the incident response plan accordingly
Incident response planningProvide training for staff on incident response processes and best practices
Business Continuity and Crisis ManagementPerform business impact analysis for critical services and processes
Business Continuity and Crisis ManagementDefine business continuity plans and manual workaround procedures
Business Continuity and Crisis ManagementEstablish a crisis management structure for severe disruptions
Business Continuity and Crisis ManagementExercise continuity and crisis scenarios with business and technical stakeholders
Business Continuity and Crisis ManagementReview continuity assumptions and recovery priorities after major change
Capacity planning and scalingRegularly assess infrastructure capacity and plan for growth
Capacity planning and scalingImplement auto-scaling strategies to handle fluctuating workloads
Capacity planning and scalingUse load testing to identify capacity limits and potential bottlenecks
Capacity planning and scalingMonitor resource usage to anticipate and address potential capacity issues
Capacity planning and scalingReview and update capacity plans based on changing business requirements and growth
Identity, Secrets, and Administrative AccessCentralize and harden privileged identity administration
Identity, Secrets, and Administrative AccessUse short-lived credentials and just-in-time access for privileged operations
Identity, Secrets, and Administrative AccessManage secrets with controlled storage, rotation, and access policies
Identity, Secrets, and Administrative AccessProtect and test emergency access and break-glass procedures
Identity, Secrets, and Administrative AccessGovern machine identities and service credentials across workloads
Security and access controlsImplement strong authentication and authorization mechanisms
Security and access controlsRegularly review and update user access permissions
Security and access controlsEnable encryption for data at rest and in transit
Security and access controlsApply security patches and updates promptly
Security and access controlsConduct regular vulnerability assessments and penetration testing
Software Delivery and Supply Chain ResilienceProtect source code, build systems, and deployment pipelines from unauthorized change
Software Delivery and Supply Chain ResilienceMaintain traceability and integrity for build artifacts and releases
Software Delivery and Supply Chain ResilienceControl dependency and base image risk through continuous inventory and update processes
Software Delivery and Supply Chain ResilienceDesign deployments for safe rollback and progressive release
Software Delivery and Supply Chain ResilienceTest CI/CD recovery and release continuity during platform disruption
Application resiliency and fault toleranceDesign applications to be stateless and horizontally scalable
Application resiliency and fault toleranceImplement circuit breakers and retries to handle transient faults
Application resiliency and fault toleranceUse health checks and load balancing to distribute traffic among instances
Application resiliency and fault toleranceIsolate application components to limit the impact of failures
Application resiliency and fault toleranceMonitor application performance and error rates to identify potential issues
Data center and geographic redundancyDeploy infrastructure across multiple data centers or availability zones
Data center and geographic redundancyUse geo-replication to store data redundantly across different regions
Data center and geographic redundancyImplement global load balancing to distribute traffic across data centers
Data center and geographic redundancyTest failover processes between data centers to ensure smooth recovery
Data center and geographic redundancyRegularly review and update data center redundancy strategies based on evolving needs
Regular resilience testing and validationConduct regular disaster recovery and failover tests
Regular resilience testing and validationUse chaos engineering techniques to simulate failures and test system resilience
Regular resilience testing and validationTest backup and recovery processes to validate data integrity
Regular resilience testing and validationPerform load and stress tests to identify capacity limits and potential bottlenecks
Regular resilience testing and validationUse the results of testing to inform updates and improvements to infrastructure resilience
Documentation and Knowledge SharingDocument architecture, processes, and best practices for cloud resilience
Documentation and Knowledge SharingMaintain a centralized knowledge base for easy access to documentation
Documentation and Knowledge SharingRegularly review and update documentation to reflect changes and improvements
Documentation and Knowledge SharingEncourage knowledge sharing and collaboration among team members
Documentation and Knowledge SharingProvide training and resources to help staff stay informed about resilience