Regulated Incident Management Ecosystem Versão portuguesa

Service sheet SO-06

Business Continuity and Recovery

Business impact analysis, definition of recovery objectives, a continuity plan and an exercise that tests it.

The problem it solves

Backups exist, but have never been restored. Plans exist, but nobody has run them. The first time a plan is tested should not be during the incident.

Who it is for

  • Organisations critically dependent on systems;
  • Public entities delivering services to citizens;
  • Manufacturing and logistics.

Deliverables

  • Business impact analysis;
  • Recovery time and recovery point objectives by process;
  • Continuity and recovery plan;
  • Test exercise and lessons-learnt report.

Method

  1. 01

    Analyse

    Processes and impacts.

  2. 02

    Define

    Recovery objectives.

  3. 03

    Plan

    Procedures and roles.

  4. 04

    Test

    Exercise and correction.

Regulatory basis

  • ISO 22301, on business continuity management systems;
  • ISO/IEC 27001:2022 and ISO/IEC 27002:2022.

Expected results

  • Recovery times known and agreed;
  • A plan tested, not merely written;
  • Less actual downtime.

Ecosystem links

Security that is not measured is not managed

Start with a maturity assessment or ask for a proposal to structure the role.