Appendix B: Regulatory and Compliance Considerations

Organizational Resilience and Black Swan Events · 3:49

Listen on 93

Lyrics

[Verse 1]
When black swans strike without a warning sign
Your business plan must cross the compliance line
SOC 2 Trust demands availability's there
While NIST frameworks show contingency care

[Chorus]
S-O-C, H-I-P, G-D-P-R too
Banking, healthcare, critical infrastructure
Regulations guide what we must do
Plan for black swans with compliance in view
Every framework has a role to play
Keep your business running every day

[Verse 2]
HIPAA Security Rule sets the standard clear
Contingency plans for data we hold dear
GDPR requires resilience and might
Data availability must stay in sight

[Chorus]
S-O-C, H-I-P, G-D-P-R too
Banking, healthcare, critical infrastructure
Regulations guide what we must do
Plan for black swans with compliance in view
Every framework has a role to play
Keep your business running every day

[Verse 3]
Banking follows OCC and FFIEC ways
Healthcare meets CMS participation days
Critical systems heed CISA's call
CMMC protections covering it all

[Bridge]
SLA commitments to your partners bind
Contractual duties always keep in mind
Eight hundred seventy one from NIST
No regulation can be missed

[Chorus]
S-O-C, H-I-P, G-D-P-R too
Banking, healthcare, critical infrastructure
Regulations guide what we must do
Plan for black swans with compliance in view
Every framework has a role to play
Keep your business running every day

[Outro]
When the unexpected comes to test your will
Regulatory guidance keeps you climbing uphill
Black swan planning with compliance as your guide
Business continuity with rules by your side

← Appendix A: Recommended Reading | Exercise 8.2: The Annual Black Swan Review →