Business continuity plan
What each team does when a disruption happens: who is called, what is recovered first, where, with what, and how the return is managed.
How the register reads it
| Also called | BCP, continuity procedures |
|---|---|
| Family | Resilience and incidents |
| Document type | Plan. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The business continuity manager or COO. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 22301 or DORA or NIS2 or ISO 27001 is ticked and no line resolves to it. |
| Template | Business continuity plan. |
Which standards require it, and what each expects it to contain
5 requiring clauses, 4 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022
ISO 27001 5.29 Information security during disruptionPlan how to keep information security at the right level during disruption.
What the ISO 27002 guidance expects the document to say: Requires the organisation to plan how information security will be maintained at an appropriate level while a disruption is under way.
Common gap: Plans not updated after tests
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 22301:2019
ISO 22301 8.4.4 Business continuity plansDocument and maintain business continuity plans that guide teams through response and recovery, collectively containing the actions to continue or recover prioritized activities within predetermined time frames, the means of monitoring the disruption and the response, the pre defined thresholds and process for activating the response, procedures to deliver products and services at agreed capacity, and how the immediate consequences are managed with regard to individual welfare, prevention of further loss and environmental impact; each plan must state purpose, scope and objectives, the roles and responsibilities of the implementing team, the actions implementing the solutions, the supporting information needed to activate, operate, coordinate and communicate including activation criteria, internal and external interdependencies, resource requirements, reporting requirements and a stand down process, and must be usable and available at the time and place it is needed.
Common gap: Plans that cover activation and response but have no stand down, so the organization never formally returns to normal
Source: ISO 22301:2019
ISO 22301 8.4.1 GeneralImplement and maintain a response structure enabling timely warning and communication to relevant interested parties, with plans and procedures to manage the organization through a disruption and to activate continuity solutions, identified and documented from the output of the selected strategies and solutions, and with procedures that are specific about immediate steps, flexible to changing internal and external conditions, focused on the impact of incidents, effective at minimizing that impact, and explicit about roles and responsibilities.
Common gap: Procedures written for one rehearsed scenario, brittle against anything else
Source: ISO 22301:2019
DORA (Regulation (EU) 2022/2554)
DORA Art. 11 Response and recoveryFinancial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
Common gap: No ICT continuity/response/recovery plans
Source: DORA (Regulation (EU) 2022/2554)
The NIS2 Directive
NIS2 Art. 21(2)(c) Business continuity, backup management, disaster recovery and crisis managementThis category asks the entity to be able to keep providing its services, or to restore them, when systems fail or are attacked. Backup management means backups that are taken, protected against the same event that takes out production, and demonstrably restorable, which is why restore testing rather than backup success rate is the evidence that counts. Disaster recovery means recovery objectives that were derived from what the service can actually tolerate, and infrastructure and procedure capable of meeting them. Crisis management is the decision-making layer above both: who declares a crisis, who can commit the organisation, how the entity communicates while under pressure. Because NIS2 is concerned with continuity of service to recipients, recovery objectives set purely from internal convenience are the usual weak point.
Common gap: Backups verified as completed but never restored end to end
Source: NIS2 Directive
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerVendor security assessment procedure · Business continuity policy