SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.29Information security during disruption

Plan how to maintain an appropriate level of information security during disruptions such as outages or disasters, so protection does not collapse when you need it most.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0251RTO/RPO definitions · ProcesssupportsUsing agreed recovery time and data-loss targets to drive recovery planning keeps security expectations tied to how fast systems must come back during a disruption.RCF-0253DR exercises · PolicysupportsA written commitment to exercise disaster recovery on a fixed schedule is how a company confirms its security posture survives a failover, not only that data comes back.RCF-0280Business impact analysis · PolicysupportsDocumenting which business functions matter most and how quickly each must be restored is the foundation this control needs to know what security has to protect during a disruption.RCF-0281Business impact analysis · ProcesssupportsRefreshing the business impact analysis whenever systems or priorities change keeps the disruption planning this control covers grounded in the current business, not an outdated snapshot.RCF-0283Continuity plans · PolicysupportsApproved plans describing how critical operations continue during a major disruption support this control's requirement, but a general business continuity plan does not by itself guarantee that information security is maintained through the disruption.RCF-0284Continuity plans · ProcesssupportsReviewing and updating continuity plans after every significant change keeps the security assumptions in those plans from going stale.RCF-0286Crisis management · PolicysupportsA crisis management framework naming who leads and who decides during a major disruption gives this control's security-during-disruption expectations someone accountable to enforce them.RCF-0287Crisis management · ProcesssupportsActivating crisis procedures and following the defined escalation path during major incidents is how the security posture named in this control gets maintained in practice, not only on paper.RCF-0289Alternate work sites · PolicysupportsA policy defining where and how staff keep working if the primary office is unavailable sets the baseline this control needs so security controls are not abandoned during relocation.RCF-0290Alternate work sites · ProcesssupportsExercising alternate work site arrangements confirms staff can switch locations without dropping the security controls this disruption scenario depends on.RCF-0292BCP exercises · PolicyrelatedA recurring schedule of continuity exercises is a broader commitment that also covers the disruption scenarios this control is concerned with, though its scope spans more than security.RCF-0293BCP exercises · ProcessrelatedRunning planned continuity exercises and feeding lessons back into the plan touches the security-during-disruption question indirectly, as one part of a wider continuity practice.RCF-0295Supply chain continuity · PolicysupportsAssessing whether key suppliers can keep supporting operations during a disruption extends this control's concern for security continuity beyond the company's own systems.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Disaster recovery plan and runbooks
The plan defining how long each critical system can be down (RTO/RPO) and the step-by-step guides to recover it after a serious failure.
Business continuity plan
The plan describing how the company keeps operating during a major disruption: impact analysis, critical functions, and crisis management.
From the Sekit evidence catalog

In practice

This control asks whether security controls survive a disruption, not whether the business keeps running at all, which is the more common focus of business continuity work. A company that fails over to a backup office often forgets to re-enable MFA enforcement or access logging on the temporary setup. The business impact analysis should name which systems matter most and how fast each must come back, signed off by management rather than assumed. Crisis management procedures need a named decision-maker, because during an outage the default response is often for everyone to wait for someone else to decide.

Common gaps

The business impact analysis was written years ago and does not reflect the systems the company now depends on day to day.
Security controls like MFA and access logging are not re-enabled on the disaster recovery environment when it is used for real.
Alternate work site arrangements have never been tested, so nobody knows whether the secure remote access setup can support the whole company at once.

Questions your auditor will ask

Which business functions were identified as most critical to restore?
The business impact analysis names the critical functions and systems, with target recovery times signed off by management.
Do security controls stay in place when operating from a disaster recovery site?
The DR environment is built to the same security baseline as production, verified during the last recovery exercise.
Who leads the company during a major disruption?
A crisis management framework names a decision-maker, a deputy and who speaks for the company externally, tested during exercises.

Where regulation demands it

NIS2 4.1 requires business continuity and disaster recovery plans that keep operations, and by extension security, running through a disruption.
ENS op.cont.2 requires a continuity plan covering how the organization keeps operating, including its security posture, during a major disruption.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.29?”
Also via MCP, free with account