Expert Advice Community

Guest

BCP and ISO 27031 standard

  Quote
Guest
Guest user Created:   Aug 05, 2017 Last commented:   Aug 05, 2017

BCP and ISO 27031 standard

I have started the project mentioned in my previous messages to you. As background it is a very large organisation (provincial government with 30,000 it users. I have to do a BCP for IT department and look at and review BCP’s for the 13 other departments in the organisation.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Aug 05, 2017

I have all the templates from you for ISO22301 and have used them a few times so not concerned about their use. I have gone through the ISO27031 standard and can see the difference or value add of this approach for IRBC.

I would like to know;

1. How to use ISO27031, should I use it??

Answer: I would recommend you to use ISO 27031, since it can be a valuable reference to check and improve the BC Plans for IT, usually called IT disaster recovery plans, since its recommendations can show you if your plans already cover the most common controls and safeguards or if they need adjustments.

You can think the use of ISO 27031 in the same way ISO 27002 is used for ISO 27001, where ISO 27002 provides recommendations and guidelines for implementation of ISO 2 7001 Ann ex A controls.

2. Do you have documents that show how to use ISO27031.

Answer: Specifically for ISO 27031 we do not have such material, however our DRP template is compatible with 27031.

3. Having read through the standard it looks like DRP made smarter.

Answer: Yes, this is basically what ISO 27031 does, providing recommendations and guidelines to controls and safeguards applicable to IT BC plans

4. How do I marry the two?

Answer: You can consider the use of ISO 27031 in the planing phase of business continuity. After performing the BIA and defining RTO's, RPO's and general strategy, you can use ISO 27031 to detail which controls and other measures you have to consider in your DRP plans.

This article will provide you further explanation about ISO 27031:
- Understanding IT disaster recovery according to ISO 27031 https://advisera.com/27001academy/blog/2015/09/21/understanding-it-disaster-recovery-according-to-iso-27031/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 05, 2017

Aug 05, 2017

Suggested Topics