ISO 27001 Business Continuity: Requirements and Planning
When a disruption occurs – whether from a cyber attack, natural disaster or system failure – an organisation must be able to continue operating or recover quickly. ISO 27001 business continuity requirements, found in Annex A.17, address the information security aspects of business continuity management (BCM). This article explores what the standard requires, how to develop a business continuity plan (BCP), and how to integrate with broader continuity frameworks such as ISO 22301.
Annex A.17 Requirements: Information Security Aspects of Business Continuity
Annex A.17 of ISO 27001:2022 contains two controls that directly address business continuity from an information security perspective:
- A.17.1 Information security continuity – The organisation must determine its requirements for information security continuity in adverse situations, including during a crisis or disruption. This includes documenting, implementing and maintaining processes, procedures and controls to ensure the continuity of information security management.
- A.17.2 Redundancies – The organisation must implement redundancy measures to maintain the availability of information processing facilities. This covers redundant infrastructure, failover systems, backup power and alternative communication channels.
| Control | Objective | Typical Implementation |
|---|---|---|
| A.17.1.1 | Plan information security continuity | BCP document, BIA, risk assessment |
| A.17.1.2 | Implement information security continuity | BCP procedures, roles and responsibilities |
| A.17.1.3 | Verify, review and evaluate information security continuity | Testing, exercises, post-incident reviews |
| A.17.2.1 | Availability of information processing facilities | Redundant servers, failover clusters, UPS |
Business Continuity Policy
Every ISO 27001 business continuity programme begins with a documented business continuity policy. This policy sets the direction, principles and framework for continuity planning across the organisation. It should be approved by top management and communicated to all relevant stakeholders.
The policy should address:
- Scope and objectives of the business continuity programme
- Roles and responsibilities for continuity planning and response
- Risk appetite and tolerance for downtime
- Minimum acceptable levels of service during a disruption
- Requirements for business impact analysis (BIA)
- Commitment to testing, review and continual improvement
BCP Development
The Business Continuity Plan (BCP) is the core document that describes how the organisation will respond to, recover from and resume operations after a disruption. Developing a BCP involves several steps:
Business Impact Analysis (BIA)
The BIA identifies critical business processes and the impact of their disruption. For each process, the BIA defines the Recovery Time Objective (RTO) and Recovery Point Objective (RPO). RTO is the maximum acceptable downtime; RPO is the maximum acceptable data loss measured in time.
| Process | RTO | RPO | Criticality Rating |
|---|---|---|---|
| Customer order processing | 4 hours | 15 minutes | Critical |
| Payroll | 24 hours | 1 day | High |
| Email and communication | 2 hours | 5 minutes | Critical |
| Internal training portal | 5 days | 1 week | Low |
| Financial reporting | 8 hours | 1 hour | High |
Risk Assessment for Business Continuity
Organisations must identify threats that could cause a disruption. Common threats include cyber attacks, power outages, fire, flood, pandemic illness, hardware failure, supply chain interruption and sabotage. Each threat is assessed for likelihood and impact.
Plan Documentation
The BCP should include step-by-step procedures for activation, communication, recovery and return-to-normal operations. It must also specify who has authority to declare a disaster and activate the plan. Contact lists, escalation paths and resource inventories should be included as appendices.
Testing and Exercises
A plan that is never tested is not a plan – it is a hope. ISO 27001 business continuity requires that the BCP is tested at planned intervals. Testing validates that the plan works, identifies gaps and builds competence among response teams.
| Exercise Type | Description | Frequency |
|---|---|---|
| Tabletop exercise | Key stakeholders walk through a scenario verbally | Quarterly |
| Technical test | IT team tests failover, backup restoration or system recovery | Quarterly |
| Simulation exercise | Realistic scenario with role-play and time pressure | Bi-annually |
| Full-scale drill | Complete activation of the BCP across all teams and locations | Annually |
Each exercise should produce a report documenting what was tested, what worked, what did not work and the corrective actions required. Lessons learned must be fed back into the BCP and associated procedures.
BC Plan Maintenance
Business continuity is not a one-time project. The BCP must be maintained as a living document. Triggers for review include:
- Organisational restructuring or changes in key personnel
- Introduction of new systems, applications or infrastructure
- Changes in regulatory or contractual obligations
- Post-incident review findings
- Results of exercises and tests
- Changes in the threat landscape (e.g. new cyber risks)
The BCP should be reviewed at least annually, with version control and change history maintained. Ownership must be assigned to a specific role, typically the business continuity manager or the information security manager.
Integration With ISO 22301
ISO 22301 is the international standard for business continuity management systems (BCMS). While ISO 27001 business continuity focuses specifically on the information security aspects of continuity, ISO 22301 takes a broader view covering all aspects of organisational resilience.
Organisations often implement both standards together. The ISO 22301 BCMS provides the overarching framework, while Annex A.17 ensures that information security continuity requirements are addressed within that framework. The two standards share a common high-level structure (the Annex SL framework), which simplifies integration.
| Aspect | ISO 27001 (Annex A.17) | ISO 22301 |
|---|---|---|
| Scope | Information security continuity | Overall business continuity |
| Key concepts | CIA triad, ISMS, security controls | BCMS, BIA, BCP, crisis management |
| Focus | Protecting information assets during disruption | Maintaining critical business operations |
| Testing requirement | Information security continuity testing | BCP testing and exercises (all functions) |
| Documentation | ISMS documentation, information security BCP | BCMS policy, BCP, BIA, exercise reports |
Roles and Responsibilities
Clear roles are essential for effective ISO 27001 business continuity management. The following table outlines the key roles and their responsibilities:
| Role | Responsibility |
|---|---|
| Top Management | Approves BC policy, allocates resources, reviews BC performance |
| Business Continuity Manager | Develops, implements and maintains the BCP; coordinates exercises |
| Information Security Manager | Ensures security controls are maintained during disruption |
| Crisis Management Team | Activates the BCP, makes strategic decisions during incidents |
| IT Manager | Maintains technical redundancies and leads IT recovery |
| Process Owners | Define continuity requirements for their business processes |
| All Employees | Follow BC procedures and report disruptions promptly |
Frequently Asked Questions
Is business continuity mandatory for ISO 27001 certification?
Yes. Annex A.17 is a required set of controls. An ISMS auditor will expect to see evidence of a business continuity policy, a BCP, testing records and documented redundancies for critical information processing facilities.
What is the difference between a BCP and a disaster recovery plan (DRP)?
A BCP covers the entire organisation and addresses all aspects of continuing operations during a disruption. A DRP is a subset of the BCP that focuses specifically on IT systems, data recovery and technical infrastructure restoration.
Can ISO 27001 business continuity replace ISO 22301 certification?
No. ISO 27001 Annex A.17 covers only the information security aspects of business continuity. ISO 22301 is a comprehensive BCMS standard. However, a strong alignment between the two is achievable and recommended.
How often should we test our business continuity plan?
Annex A.17 requires planned testing. Most organisations conduct technical tests quarterly, tabletop exercises quarterly, simulations bi-annually and a full-scale drill annually. The frequency should be risk-based and documented in the BC policy.
What is the minimum redundancy required for ISO 27001 compliance?
There is no one-size-fits-all answer. The organisation must determine redundancy requirements based on its BIA and risk assessment. Critical systems typically require hot standby or active-active failover, while less critical systems may tolerate cold standby or manual recovery.
How do we align ISO 27001 business continuity with ISO 22301?
Use the common Annex SL structure to integrate both management systems. Map Annex A.17 controls to the relevant clauses of ISO 22301, share the same BIA data and coordinate testing schedules. Many organisations achieve certification to both standards in a combined audit.
Build Your ISO 27001 Business Continuity Programme
Meeting the ISO 27001 business continuity requirements of Annex A.17 demands careful planning, robust documentation and regular testing. Our consultants have helped organisations across multiple sectors design BC programmes that protect information assets and maintain operations during crises.
Reach us directly on WhatsApp to start planning your business continuity programme today.
Tags: ISO 27001, business continuity, BCP, disaster recovery, Annex A, ISMS, ISO 22301