Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Creating and documenting continuity plans

Critical
High
Normal
Low

Sometimes an unexpected event, such as a fire, flood, or equipment failure, can cause downtime. In order to be able to continue operations as quickly and smoothly as possible, continuity planning is carried out, i.e. planning the operations in advance for these exceptional situations.

Each continuity plan shall contain at least the following information:

  • Event for which the plan has been made
  • Goal for recovery time
  • Responsible persons and related stakeholders and contact information
  • Planned immediate actions
  • Planned recovery steps
Connected other frameworks and requirements:
T05: Jatkuvuuden hallinta
17.1.2: Implementing information security continuity
ISO 27001
ID.SC-5: Response and recovery
NIST CSF
PR.IP-9: Response and recovery plans
NIST CSF
RC.RP-1: Recovery plan
NIST CSF

Considering cyber security breaches in continuity planning

Critical
High
Normal
Low

The organization must document in advance procedures for responding to security breaches to ensure the actions of related departments, customers, and other critical partners in the event of a security breach.

Connected other frameworks and requirements:
PR.IP-9: Response and recovery plans
NIST CSF
RS.MI-2: Incident mitigation
NIST CSF
RC.RP-1: Recovery plan
NIST CSF
RC.RP: Recovery Planning
NIST CSF

Addressing disasters in continuity planning

Critical
High
Normal
Low

The organization has to include disaster recovery in their continuity planning. Relevant disasters for the planning are natural disasters (e.g floods, earthquake, hurricanes) and human caused disasters (e.g terror attack, chemical attack/incident, insider attack).

In disaster planning there is greater emphasis on the returning operations to normal levels safely than in continuity planning. After this focus moves to resuming normal operations.

The continuity plans must be updated at least annually or after significant changes.

Connected other frameworks and requirements:
PR.IP-9: Response and recovery plans
NIST CSF
No items found.