Plan how to maintain an appropriate level of information security during disruptions such as outages or disasters, so protection does not collapse when you need it most.
Mapping at a glance
A.5.29Information security during disruptionISO/IEC 27001:2022
What an auditor, or Sekit's evidence engine, asks for.
Disaster recovery plan and runbooks
The plan defining how long each critical system can be down (RTO/RPO) and the step-by-step guides to recover it after a serious failure.
Business continuity plan
The plan describing how the company keeps operating during a major disruption: impact analysis, critical functions, and crisis management.
From the Sekit evidence catalog
In practice
This control asks whether security controls survive a disruption, not whether the business keeps running at all, which is the more common focus of business continuity work. A company that fails over to a backup office often forgets to re-enable MFA enforcement or access logging on the temporary setup. The business impact analysis should name which systems matter most and how fast each must come back, signed off by management rather than assumed. Crisis management procedures need a named decision-maker, because during an outage the default response is often for everyone to wait for someone else to decide.
Common gaps
The business impact analysis was written years ago and does not reflect the systems the company now depends on day to day.
Security controls like MFA and access logging are not re-enabled on the disaster recovery environment when it is used for real.
Alternate work site arrangements have never been tested, so nobody knows whether the secure remote access setup can support the whole company at once.
Questions your auditor will ask
Which business functions were identified as most critical to restore?
The business impact analysis names the critical functions and systems, with target recovery times signed off by management.
Do security controls stay in place when operating from a disaster recovery site?
The DR environment is built to the same security baseline as production, verified during the last recovery exercise.
Who leads the company during a major disruption?
A crisis management framework names a decision-maker, a deputy and who speaks for the company externally, tested during exercises.
Where regulation demands it
NIS2 4.1 requires business continuity and disaster recovery plans that keep operations, and by extension security, running through a disruption.
ENS op.cont.2 requires a continuity plan covering how the organization keeps operating, including its security posture, during a major disruption.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.