Home / Fast Track / Business continuity & backup
Shared control area · counts toward 7 standards
Business continuity & backup
This control area ensures an organization can recover critical data and resume operations after a disruptive event. Frameworks require it to guarantee availability and resilience, minimizing the impact of system failures or disasters on business continuity.
Implement it once
- Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for all critical systems.
- Establish an automated backup schedule with encrypted copies stored in a geographically separate location from production.
- Create a written Business Continuity and Disaster Recovery (BCDR) plan detailing step-by-step recovery procedures and emergency contact lists.
- Implement "immutable" or air-gapped backups to protect against ransomware.
- Schedule and execute periodic restoration tests to verify that backups are functional and meet defined RTOs/RPOs.
Evidence it produces
- A formalized BCDR plan document, reviewed and approved by management annually.
- Backup logs demonstrating successful completion of scheduled jobs.
- Restore test reports documenting the date of the test, the data recovered, and whether recovery objectives were met.
- Documentation defining RTOs and RPOs for each critical service or application.
Where it counts
Most security standards treat availability as a core pillar alongside confidentiality and integrity. By maintaining a single set of BCDR documents and testing logs, an organization satisfies the resilience requirements common to almost all technical audits and certifications.