iso-27001-business-continuity-planning

By July 25th, 2026ISO Audit And Certificate3 min read

ISO 27001 Business Continuity and Disaster Recovery Planning

ISO 27001 business continuity and disaster recovery planning, governed by Annex A.17, requires organisations to determine their information security continuity requirements during adverse situations, implement controls to maintain or restore security at the required level, and verify the effectiveness of those controls through regular testing and review. This ensures that when an incident strikes, information security does not collapse.

Author: Mustafa Hasan · Published: 25 July 2026 · Last updated: 25 July 2026

Annex A.17: Information Security Continuity

Annex A.17 in ISO 27001:2022 addresses business continuity from an information security perspective. It is deliberately narrower than a full business continuity management system (BCMS) such as ISO 22301. Annex A.17 focuses specifically on ensuring that information security controls remain effective during and after a disruption. However, organisations that operate ISO 22301 will find that Annex A.17 maps naturally onto their BCMS structure.

Annex A.17 comprises two controls:

Control IDControl NameRequirement Summary
A.17.1Information security continuityDetermine continuity requirements, implement plans and verify effectiveness
A.17.2RedundanciesImplement redundant information processing facilities to meet availability requirements

Business Continuity Policy

  • The scope of information security continuity (which systems, processes and data are covered)
  • Roles and responsibilities for continuity planning and execution
  • The relationship between information security continuity and the wider BCMS
  • Continuity objectives, including target RTO and RPO for each critical system
  • Trigger criteria for activating continuity plans
  • Review and testing requirements
  • Linkage to the ISMS risk assessment and treatment process

Business Impact Analysis (BIA)

  • Identifying all information assets and the business processes they support
  • Determining the maximum acceptable outage (MAO) for each process
  • Assessing the impact of unavailability over time (financial, reputational, regulatory, contractual)
  • Calculating the recovery time objective (RTO) and recovery point objective (RPO) for each asset
  • Identifying dependencies between processes, systems and third parties
  • Documenting the minimum resource requirements for recovery
  • Prioritising assets for recovery sequencing

RTO and RPO Defined

BCP Development

  • Plan activation criteria and authorisation process
  • Roles, responsibilities and contact information for the incident response team and the recovery team
  • Step-by-step recovery procedures for each critical system
  • Communication plans for internal stakeholders, customers, regulators and the media
  • Alternative processing arrangements (manual workarounds or temporary systems)
  • Dependency maps showing the order in which systems must be restored
  • Resource requirements: personnel, equipment, software licences, third-party support
  • Escalation procedures if recovery is not achieved within RTO
  • Plan distribution and storage (including offline copies in case primary systems are unavailable)

Disaster Recovery Plan (DR Plan)

  • System inventory with RTO, RPO and recovery priority ranking
  • Detailed restoration procedures for each system, tested and documented
  • Configuration documentation for network devices, firewalls, load balancers and security appliances
  • Data restoration procedures including verification steps
  • Security control reactivation checklist (firewall rules, access controls, monitoring, anti-malware)
  • DR site specification: location, capacity, connectivity, security controls
  • Vendor escalation contacts and support contract details
  • Backup locations and retrieval procedures

Redundancies (A.17.2)

Testing and Exercises

Maintenance and Review

Common Continuity Findings in ISO 27001 Audits

Frequently Asked Questions

What is the difference between a BCP and a DR plan?

Does ISO 27001 require a separate DR site?

How often must we test our BCP?

What is the link between Annex A.17 and ISO 22301?

How do cloud services affect Annex A.17 compliance?

What should we do if we miss our RTO during a test?

How Bitrixme Can Help