Expert Advice Community

Guest

ISOs 27000 and 22301

  Quote
Guest
Guest user Created:   Jun 09, 2020 Last commented:   Jun 09, 2020

ISOs 27000 and 22301

Does ISO 27000 cover disaster recovery? Or is it required to use ISO22301? Is this better to do a live consultation for this question?

0 0

Assign topic to the user

ISO 27001/ISO 22301 INCIDENT RESPONSE PLAN

Steps on how to respond to major incidents that can disrupt a business.

ISO 27001/ISO 22301 INCIDENT RESPONSE PLAN

Steps on how to respond to major incidents that can disrupt a business.

Expert
Rhand Leal Jun 09, 2020

I'm assuming you are talking about ISO 27001, which defines requirements for the ISMS. ISO 27000 defines the vocabulary for ISO 27001 series of standards.

Considering that, regarding disaster recovery, ISO 27001 defines objectives and controls (what must be achieved) related to information security aspects of business continuity, on Annex A, section A.17, but it does not provide guidance on how to implement such controls.

But please note that disaster recovery is required by ISO 27001 only if you have relevant risks, or legal requirements (e.g., laws, regulations, and contracts), that require the implementation of disaster recovery.

In this case, for guidance, you can use either ISO 27002, which provides guidance on the implementation of ISO 27001 Annex A controls, or ISO 22301, but please note that neither are required to be used for ISO 27001 implementation.

These articles will provide you a further explanation about ISO 27002 and ISO 22301:

This material will also help you regarding controls implementation:

Quote
0 1

Comment as guest or Sign in

HTML tags are not allowed

Jun 09, 2020

Jun 09, 2020