Policy Register

Business continuity plan

What each team does when a disruption happens: who is called, what is recovered first, where, with what, and how the return is managed.

How the register reads it

Also calledBCP, continuity procedures
FamilyResilience and incidents
Document typePlan. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe business continuity manager or COO.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 22301 or DORA or NIS2 or ISO 27001 is ticked and no line resolves to it.
TemplateBusiness continuity plan.

Which standards require it, and what each expects it to contain

5 requiring clauses, 4 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 5.29 Information security during disruption

Plan how to keep information security at the right level during disruption.

What the ISO 27002 guidance expects the document to say: Requires the organisation to plan how information security will be maintained at an appropriate level while a disruption is under way.

Evidence an auditor accepts: Continuity plans showing how information security is maintained while the organisation is operating in a degraded or alternative mode; the assessment of which security controls would be weakened or bypassed during disruption, and the compensating arrangements; evidence security requirements are part of continuity testing, not only recovery of function
Common gap: Plans not updated after tests
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO 22301:2019

ISO 22301 8.4.4 Business continuity plans

Document and maintain business continuity plans that guide teams through response and recovery, collectively containing the actions to continue or recover prioritized activities within predetermined time frames, the means of monitoring the disruption and the response, the pre defined thresholds and process for activating the response, procedures to deliver products and services at agreed capacity, and how the immediate consequences are managed with regard to individual welfare, prevention of further loss and environmental impact; each plan must state purpose, scope and objectives, the roles and responsibilities of the implementing team, the actions implementing the solutions, the supporting information needed to activate, operate, coordinate and communicate including activation criteria, internal and external interdependencies, resource requirements, reporting requirements and a stand down process, and must be usable and available at the time and place it is needed.

Evidence an auditor accepts: Plan set with each plan carrying every required element; activation criteria and thresholds stated in the plan itself; interdependency and resource sections reconciled to the BIA
Common gap: Plans that cover activation and response but have no stand down, so the organization never formally returns to normal
Source: ISO 22301:2019
ISO 22301 8.4.1 General

Implement and maintain a response structure enabling timely warning and communication to relevant interested parties, with plans and procedures to manage the organization through a disruption and to activate continuity solutions, identified and documented from the output of the selected strategies and solutions, and with procedures that are specific about immediate steps, flexible to changing internal and external conditions, focused on the impact of incidents, effective at minimizing that impact, and explicit about roles and responsibilities.

Evidence an auditor accepts: Documented response structure; procedures stating immediate steps and the roles that take them; traceability from selected strategies and solutions to the documented plans
Common gap: Procedures written for one rehearsed scenario, brittle against anything else
Source: ISO 22301:2019

DORA (Regulation (EU) 2022/2554)

DORA Art. 11 Response and recovery

Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.

Evidence an auditor accepts: ICT business continuity policy + response/recovery plans; records of plan testing
Common gap: No ICT continuity/response/recovery plans
Source: DORA (Regulation (EU) 2022/2554)

The NIS2 Directive

NIS2 Art. 21(2)(c) Business continuity, backup management, disaster recovery and crisis management

This category asks the entity to be able to keep providing its services, or to restore them, when systems fail or are attacked. Backup management means backups that are taken, protected against the same event that takes out production, and demonstrably restorable, which is why restore testing rather than backup success rate is the evidence that counts. Disaster recovery means recovery objectives that were derived from what the service can actually tolerate, and infrastructure and procedure capable of meeting them. Crisis management is the decision-making layer above both: who declares a crisis, who can commit the organisation, how the entity communicates while under pressure. Because NIS2 is concerned with continuity of service to recipients, recovery objectives set purely from internal convenience are the usual weak point.

Evidence an auditor accepts: Business impact analysis deriving recovery time and recovery point objectives from service tolerance; backup configuration showing isolation or immutability against destructive attack; restore test results, dated, covering the systems that carry the essential service
Common gap: Backups verified as completed but never restored end to end
Source: NIS2 Directive

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Vendor security assessment procedure · Business continuity policy