Security Questionnaire Mapper
Incident and continuity · question family

Business continuity plan: the clause the question tests

Whether the service keeps running through a disruption, on a written and exercised plan.

How the customer usually asks it

example

"Do you have a documented business continuity plan tested at least annually?"

Read this question

Anchor clauses

7 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20225.29 Information security during disruption · 5.30 ICT readiness for business continuity
SOC 2 (Trust Services Criteria)A1.3 Recovery plan procedures support system recovery from failures
SIG (Shared Assessments)domain K Business Resiliency
CSA Cloud Controls Matrix v4.0.1BCR-04 Business Continuity Planning · BCR-06 Business Continuity Exercises
NIST Cybersecurity Framework 2.0RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
NIST SP 800-53 Rev 5CP-2 Contingency plan
HIPAA Security Rule (45 CFR 164)164.308(a)(7)(i) Contingency Plan (Standard)

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The continuity plan covering the service, the business impact analysis behind it, and the report of the last exercise with its actions.

The clauses, with what an assessor asks for

ISO 27001 5.29 Information security during disruption

Plan how to keep information security at the right level during disruption.

Evidence an assessor expects: Disruption security plan; Business continuity test reports; Security control adjustment log; Incident communication records
Where answers usually fall short: Plans not updated after tests; Missing documented approval for temporary control changes
Source: ISO/IEC 27001:2022
ISO 27001 5.30 ICT readiness for business continuity

Plan, implement, maintain and test ICT readiness against business continuity objectives.

Evidence an assessor expects: ICT continuity plan; Readiness test results; Resource allocation records; Simulation exercise reports
Where answers usually fall short: Testing frequency not aligned with risk; Plans not updated after infrastructure changes
Source: ISO/IEC 27001:2022
SOC 2 A1.3 Recovery plan procedures support system recovery from failures

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The recovery test plan for the period, showing scope, scenario, participants and the objectives being tested; Test results recording what was recovered, the time taken and whether the recovery objectives were met; Evidence of actual restoration of data from backup, verified for completeness and integrity, not only that a job reported success; Records of issues identified during testing and evidence of their remediation; Evidence of the frequency of testing and that it covers the systems within the availability commitment
Where answers usually fall short: Testing limited to a walkthrough or a single file restore, which does not test the recovery plan procedures the criterion names; Restore performed with no verification the recovered data was complete and usable
Source: SOC 2 (Trust Services Criteria)
SIG domain K Business Resiliency

What it asks for, in one line (the standard's own text is not quoted here):

Maintain business continuity and disaster recovery programs including business impact analysis, recovery objectives, plans, periodic testing, and dependencies on third party providers.

Evidence an assessor expects: Business impact analysis with RTO and RPO; Approved BCP and DR plans; Annual test reports; Supplier dependency map
Where answers usually fall short: RTO and RPO not validated against tested recovery; Critical supplier failover untested
Source: SIG (Shared Assessments)
CSA CCM BCR-04 Business Continuity Planning

What it asks for, in one line (the standard's own text is not quoted here):

Write a business continuity plan that implements the chosen resilience strategies, and keep it approved, communicated and maintained.

Evidence an assessor expects: The current business continuity plan with version and approval; Traceability from the plan back to the chosen strategies; Distribution records showing plan holders have the current version; Maintenance record showing the plan was updated after change
Where answers usually fall short: Plan holders carrying superseded versions; Plan contents not traceable to any strategy or impact analysis
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM BCR-06 Business Continuity Exercises

What it asks for, in one line (the standard's own text is not quoted here):

Run a live exercise of the continuity and resilience plans every year, repeat it whenever something significant changes, and feed what the exercise exposes back into the plans.

Evidence an assessor expects: Exercise plans and reports from the last twelve months; Scenario and scope covered by each exercise; Post-exercise findings with owners and closure evidence; Records of exercises triggered by significant change
Where answers usually fall short: Walkthrough discussions recorded as exercises without anything being tested; Findings raised at each exercise and never closed before the next
Source: CSA Cloud Controls Matrix v4.0.1
NIST CSF RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process

The recovery portion of the incident response plan is executed once initiated from the incident response process

Evidence an assessor expects: Recovery plan with triggers and decision rights; Execution log of recovery activities; Recovery team roster with on call coverage; Plan invocation tests and outcomes; Post execution review records
Where answers usually fall short: Triggers unclear in the plan; Execution log incomplete during incidents
Source: NIST Cybersecurity Framework 2.0
SP 800-53 CP-2 Contingency plan

Requires a contingency plan that identifies essential mission and business functions and their contingency requirements, sets recovery objectives, priorities and metrics, assigns roles and contacts, addresses operating through disruption and full restoration without weakening controls, is approved by defined personnel, distributed to defined recipients, coordinated with related plans, reviewed on a defined frequency and updated after change or testing.

Evidence an assessor expects: Approved contingency plan with recovery objectives, priorities and metrics; Business impact analysis identifying essential functions and dependencies; Distribution list and evidence the plan reached the defined recipients; Review and update history including changes after tests or incidents; Evidence of coordination with incident response and related organizational plans
Where answers usually fall short: Plan lists systems but never identifies the business functions they support; Contact details stale, naming people who left the organization
Source: NIST SP 800-53 Rev 5
HIPAA 164.308(a)(7)(i) Contingency Plan (Standard)

Establish policies for responding to emergencies that damage ePHI systems. NIST recommends contingency planning per SP 800-34 with business impact analysis driving recovery priorities.

Evidence an assessor expects: Contingency plan; Business impact analysis; Recovery time and point objectives; Plan distribution list
Where answers usually fall short: BIA not performed; RTO and RPO undefined
Source: HIPAA Security Rule (45 CFR 164)

Other families in incident and continuity