Expert Advice Community

Guest

BCP and DR

  Quote
Guest
Guest user Created:   Apr 22, 2020 Last commented:   Apr 22, 2020

BCP and DR

Hello, I am having a hard time understanding the difference between BCP and DR.  I know for our ISO cert we have to include a.17.4.6 right?  That is the Disaster Recovery Plan, but our certifier is saying we do not have to complete the Business Continuity Plan, which is the rest of a.17, why is that?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 22, 2020

BCP is wider than a DR. BCP aims to ensure the business continues to operate after a disruptive event, while the DR aims to handle the impacts at the affected area and bring operations back to normal conditions.

ISO 27001 aspects on business continuity process (section A.17 from ISO 27001 Annex A) are related to ensuring the availability of information and information systems during either crisis or disaster situations, so a full Business Continuity Plan is not mandatory for this standard, and you will only need the DR template included in your toolkit.

These articles will provide you further explanation about BCPs and DRPs:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 22, 2020

Apr 22, 2020

Suggested Topics

Guest user Created:   Mar 17, 2020 ISO 27001 & 22301
Replies: 1
0 0

BCP and DR: ISO 22301

Guest user Created:   Jun 03, 2019 ISO 27001 & 22301
Replies: 1
0 0

Auditing BCP and DRP

Guest user Created:   Jan 10, 2018 ISO 27001 & 22301
Replies: 2
0 0

BCP and DRP tests