Expert Advice Community

Guest

Business Continuity Plan in ISO 27001

  Quote
Guest
Guest user Created:   Dec 28, 2016 Last commented:   Dec 28, 2016

Business Continuity Plan in ISO 27001

Why yes or why not do we need to include the Business Continuity Plan in the ISO 27001 certification ? Can we omit it ?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Dec 28, 2016

Answer: You need to include Business Continuity Plan as an information security control considering ISO 27001 certification only if one of these situations apply:

- There is a law, contract or other legal requirement demanding you to have a business continuity plan for information security
- The Business Continuity Plan for information security is considered as a control to address risks identified as unacceptable in your risk assessments
- Your organization decides to implement Business Continuity Plan for information security as a best practice

If none of these situations happen your organization does not need to implement Business Continuity Plan for information security. In our experience, I could say to you that approximately 90% of the companies are including this control in ISO 27001 implementation.

If your organization decides to select this control, you should use the "Disaster Recovery Plan" from the toolkit to be compliant with ISO 27001.

In the video tutorials that came with your toolkit, you will see information about risk assessment, risk treatment and how identify applicable controls.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 28, 2016

Dec 28, 2016

Suggested Topics

Guest user Created:   Jun 27, 2023 ISO 27001 & 22301
Replies: 1
0 0

Business Continuity Procedure

Guest user Created:   Nov 10, 2022 ISO 27001 & 22301
Replies: 1
0 0

BCM policy