iso-27001-business-continuity

By July 25th, 2026ISO Audit And Certificate7 min read

ISO 27001 Business Continuity: Requirements and Planning

When a disruption occurs – whether from a cyber attack, natural disaster or system failure – an organisation must be able to continue operating or recover quickly. ISO 27001 business continuity requirements, found in Annex A.17, address the information security aspects of business continuity management (BCM). This article explores what the standard requires, how to develop a business continuity plan (BCP), and how to integrate with broader continuity frameworks such as ISO 22301.

Annex A.17 Requirements: Information Security Aspects of Business Continuity

Annex A.17 of ISO 27001:2022 contains two controls that directly address business continuity from an information security perspective:

  • A.17.1 Information security continuity – The organisation must determine its requirements for information security continuity in adverse situations, including during a crisis or disruption. This includes documenting, implementing and maintaining processes, procedures and controls to ensure the continuity of information security management.
  • A.17.2 Redundancies – The organisation must implement redundancy measures to maintain the availability of information processing facilities. This covers redundant infrastructure, failover systems, backup power and alternative communication channels.
ControlObjectiveTypical Implementation
A.17.1.1Plan information security continuityBCP document, BIA, risk assessment
A.17.1.2Implement information security continuityBCP procedures, roles and responsibilities
A.17.1.3Verify, review and evaluate information security continuityTesting, exercises, post-incident reviews
A.17.2.1Availability of information processing facilitiesRedundant servers, failover clusters, UPS

Business Continuity Policy

Every ISO 27001 business continuity programme begins with a documented business continuity policy. This policy sets the direction, principles and framework for continuity planning across the organisation. It should be approved by top management and communicated to all relevant stakeholders.

The policy should address:

  • Scope and objectives of the business continuity programme
  • Roles and responsibilities for continuity planning and response
  • Risk appetite and tolerance for downtime
  • Minimum acceptable levels of service during a disruption
  • Requirements for business impact analysis (BIA)
  • Commitment to testing, review and continual improvement

BCP Development

The Business Continuity Plan (BCP) is the core document that describes how the organisation will respond to, recover from and resume operations after a disruption. Developing a BCP involves several steps:

Business Impact Analysis (BIA)

The BIA identifies critical business processes and the impact of their disruption. For each process, the BIA defines the Recovery Time Objective (RTO) and Recovery Point Objective (RPO). RTO is the maximum acceptable downtime; RPO is the maximum acceptable data loss measured in time.

ProcessRTORPOCriticality Rating
Customer order processing4 hours15 minutesCritical
Payroll24 hours1 dayHigh
Email and communication2 hours5 minutesCritical
Internal training portal5 days1 weekLow
Financial reporting8 hours1 hourHigh

Risk Assessment for Business Continuity

Organisations must identify threats that could cause a disruption. Common threats include cyber attacks, power outages, fire, flood, pandemic illness, hardware failure, supply chain interruption and sabotage. Each threat is assessed for likelihood and impact.

Plan Documentation

The BCP should include step-by-step procedures for activation, communication, recovery and return-to-normal operations. It must also specify who has authority to declare a disaster and activate the plan. Contact lists, escalation paths and resource inventories should be included as appendices.

Testing and Exercises

A plan that is never tested is not a plan – it is a hope. ISO 27001 business continuity requires that the BCP is tested at planned intervals. Testing validates that the plan works, identifies gaps and builds competence among response teams.

Exercise TypeDescriptionFrequency
Tabletop exerciseKey stakeholders walk through a scenario verballyQuarterly
Technical testIT team tests failover, backup restoration or system recoveryQuarterly
Simulation exerciseRealistic scenario with role-play and time pressureBi-annually
Full-scale drillComplete activation of the BCP across all teams and locationsAnnually

Each exercise should produce a report documenting what was tested, what worked, what did not work and the corrective actions required. Lessons learned must be fed back into the BCP and associated procedures.

BC Plan Maintenance

Business continuity is not a one-time project. The BCP must be maintained as a living document. Triggers for review include:

  • Organisational restructuring or changes in key personnel
  • Introduction of new systems, applications or infrastructure
  • Changes in regulatory or contractual obligations
  • Post-incident review findings
  • Results of exercises and tests
  • Changes in the threat landscape (e.g. new cyber risks)

The BCP should be reviewed at least annually, with version control and change history maintained. Ownership must be assigned to a specific role, typically the business continuity manager or the information security manager.

Integration With ISO 22301

ISO 22301 is the international standard for business continuity management systems (BCMS). While ISO 27001 business continuity focuses specifically on the information security aspects of continuity, ISO 22301 takes a broader view covering all aspects of organisational resilience.

Organisations often implement both standards together. The ISO 22301 BCMS provides the overarching framework, while Annex A.17 ensures that information security continuity requirements are addressed within that framework. The two standards share a common high-level structure (the Annex SL framework), which simplifies integration.

AspectISO 27001 (Annex A.17)ISO 22301
ScopeInformation security continuityOverall business continuity
Key conceptsCIA triad, ISMS, security controlsBCMS, BIA, BCP, crisis management
FocusProtecting information assets during disruptionMaintaining critical business operations
Testing requirementInformation security continuity testingBCP testing and exercises (all functions)
DocumentationISMS documentation, information security BCPBCMS policy, BCP, BIA, exercise reports

Roles and Responsibilities

Clear roles are essential for effective ISO 27001 business continuity management. The following table outlines the key roles and their responsibilities:

RoleResponsibility
Top ManagementApproves BC policy, allocates resources, reviews BC performance
Business Continuity ManagerDevelops, implements and maintains the BCP; coordinates exercises
Information Security ManagerEnsures security controls are maintained during disruption
Crisis Management TeamActivates the BCP, makes strategic decisions during incidents
IT ManagerMaintains technical redundancies and leads IT recovery
Process OwnersDefine continuity requirements for their business processes
All EmployeesFollow BC procedures and report disruptions promptly

Frequently Asked Questions

Is business continuity mandatory for ISO 27001 certification?

Yes. Annex A.17 is a required set of controls. An ISMS auditor will expect to see evidence of a business continuity policy, a BCP, testing records and documented redundancies for critical information processing facilities.

What is the difference between a BCP and a disaster recovery plan (DRP)?

A BCP covers the entire organisation and addresses all aspects of continuing operations during a disruption. A DRP is a subset of the BCP that focuses specifically on IT systems, data recovery and technical infrastructure restoration.

Can ISO 27001 business continuity replace ISO 22301 certification?

No. ISO 27001 Annex A.17 covers only the information security aspects of business continuity. ISO 22301 is a comprehensive BCMS standard. However, a strong alignment between the two is achievable and recommended.

How often should we test our business continuity plan?

Annex A.17 requires planned testing. Most organisations conduct technical tests quarterly, tabletop exercises quarterly, simulations bi-annually and a full-scale drill annually. The frequency should be risk-based and documented in the BC policy.

What is the minimum redundancy required for ISO 27001 compliance?

There is no one-size-fits-all answer. The organisation must determine redundancy requirements based on its BIA and risk assessment. Critical systems typically require hot standby or active-active failover, while less critical systems may tolerate cold standby or manual recovery.

How do we align ISO 27001 business continuity with ISO 22301?

Use the common Annex SL structure to integrate both management systems. Map Annex A.17 controls to the relevant clauses of ISO 22301, share the same BIA data and coordinate testing schedules. Many organisations achieve certification to both standards in a combined audit.

Build Your ISO 27001 Business Continuity Programme

Meeting the ISO 27001 business continuity requirements of Annex A.17 demands careful planning, robust documentation and regular testing. Our consultants have helped organisations across multiple sectors design BC programmes that protect information assets and maintain operations during crises.

Reach us directly on WhatsApp to start planning your business continuity programme today.

Tags: ISO 27001, business continuity, BCP, disaster recovery, Annex A, ISMS, ISO 22301