ISO 27001 Business Continuity and Disaster Recovery Planning
ISO 27001 business continuity and disaster recovery planning, governed by Annex A.17, requires organisations to determine their information security continuity requirements during adverse situations, implement controls to maintain or restore security at the required level, and verify the effectiveness of those controls through regular testing and review. This ensures that when an incident strikes, information security does not collapse.
Author: Mustafa Hasan · Published: 25 July 2026 · Last updated: 25 July 2026
Annex A.17: Information Security Continuity
Annex A.17 in ISO 27001:2022 addresses business continuity from an information security perspective. It is deliberately narrower than a full business continuity management system (BCMS) such as ISO 22301. Annex A.17 focuses specifically on ensuring that information security controls remain effective during and after a disruption. However, organisations that operate ISO 22301 will find that Annex A.17 maps naturally onto their BCMS structure.
Annex A.17 comprises two controls:
| Control ID | Control Name | Requirement Summary |
|---|---|---|
| A.17.1 | Information security continuity | Determine continuity requirements, implement plans and verify effectiveness |
| A.17.2 | Redundancies | Implement redundant information processing facilities to meet availability requirements |
Business Continuity Policy
- The scope of information security continuity (which systems, processes and data are covered)
- Roles and responsibilities for continuity planning and execution
- The relationship between information security continuity and the wider BCMS
- Continuity objectives, including target RTO and RPO for each critical system
- Trigger criteria for activating continuity plans
- Review and testing requirements
- Linkage to the ISMS risk assessment and treatment process
Business Impact Analysis (BIA)
- Identifying all information assets and the business processes they support
- Determining the maximum acceptable outage (MAO) for each process
- Assessing the impact of unavailability over time (financial, reputational, regulatory, contractual)
- Calculating the recovery time objective (RTO) and recovery point objective (RPO) for each asset
- Identifying dependencies between processes, systems and third parties
- Documenting the minimum resource requirements for recovery
- Prioritising assets for recovery sequencing
RTO and RPO Defined
BCP Development
- Plan activation criteria and authorisation process
- Roles, responsibilities and contact information for the incident response team and the recovery team
- Step-by-step recovery procedures for each critical system
- Communication plans for internal stakeholders, customers, regulators and the media
- Alternative processing arrangements (manual workarounds or temporary systems)
- Dependency maps showing the order in which systems must be restored
- Resource requirements: personnel, equipment, software licences, third-party support
- Escalation procedures if recovery is not achieved within RTO
- Plan distribution and storage (including offline copies in case primary systems are unavailable)
Disaster Recovery Plan (DR Plan)
- System inventory with RTO, RPO and recovery priority ranking
- Detailed restoration procedures for each system, tested and documented
- Configuration documentation for network devices, firewalls, load balancers and security appliances
- Data restoration procedures including verification steps
- Security control reactivation checklist (firewall rules, access controls, monitoring, anti-malware)
- DR site specification: location, capacity, connectivity, security controls
- Vendor escalation contacts and support contract details
- Backup locations and retrieval procedures