July 25, 2023

ISO 27001 Annex A.17: Information Security Aspects of Business Continuity Management

The controls in this section aim to configure an efficient system that can handle business disruptions with a focus on information security threats and controls. How can you guarantee that your business will survive after facing and resolving a threat?

By
Full name
Share this post
A woman smiles while using a tablet, surrounded by digital notifications and a data chart.

A.17.1 Security continuity

A.17.1.1 Planning information security continuity

The most successful businesses are those which plan for disaster and have clear alignment to information security threats and response scenarios. You’re not negative but, rather are covering your bases and ensuring that your company has a Plan B for when the unexpected happens.

Amid crisis, what are some of the services you’ll still need and expect your ISMS to deliver? What would happen if a significant data source from your system is affected and what would your response be?

Consider all possibilities in terms of the worst threats that could happen? Do you have an emergency plan in place to address such incidents to ensure that good planning will save your business from the negative effects of an information security breach.

A.17.1.2 Implementing information security continuity

Once you’ve plotted possible threat outcomes, it’s time to strategise. And your continuity policy must have documentation related to:

  • Trigger points that will signal if an incident is about to escalate and steps to sustain information security controls during an incident
  • Recovery procedures that you’ll implement after the start of a crisis
  • Processes you’ll use to maintain conditions that favour business continuity after the recovery phase. Descriptions of all additional roles, activities, owners and risk reduction techniques that will assign at each stage of the policy.
  • Proposed duration for the information security or business continuity plan. Estimated time frames within when business will return to normal.

A.17.1.3 Verify, review and evaluate information security continuity

All continuity controls will need to be monitored and reviewed during the recovery phase to gauge the company’s progress. Testing of these controls should have recurring schedules and the results will be used to determine if the controls need adjusting to match the system’s current recovery state..

As risk levels change, so should your processes, otherwise your procedures will no longer benefit the system. During your internal audit, you’ll be asked to present logs of all recovery controls implemented during the process. Documents of the events that followed recovery, setbacks and developments will also come into play as the recovery phase as a learning process for your firm. Make sure you take notes of those lessons.

A.17.2 Redundancies

A.17.2.1 Availability of information processing facilities

Redundancy helps your stored copies to maintain the availability of your information systems. In simple terms if one of your originals fails, you’ll have a backup copy available to replace it.

You should conduct regular tests to confirm the viability of your redundancies as It would be a major disappointment if your backup also failed. Since redundant items are of such great value to your system continuity, they must be stored either at the same level or better than your originals. Most companies these days use cloud storage to preserve their redundancies, if you have a supplier relationship, you should discuss the status of your redundancies in the cloud. They should be well informed of the risks you face related to data security. Transparency is key.

Risk Management
Compliance Reporting
Policy Management
Incident Management
Audits and Assessments

Ready to Take Control of Your Privacy Compliance?

See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

Risk Management

Identify, assess, and mitigate security risks with an integrated risk register.Hicomply’s automated risk management software maps controls across ISO 27001, SOC 2, and NIST frameworks — helping teams track risk treatment plans, assign ownership, and monitor real-time compliance status.Build a resilient ISMS that reduces audit findings and demonstrates continuous improvement.

Compliance Reporting

Generate instant, audit-ready compliance reports across multiple frameworks — from ISO 27001 and SOC 2 to GDPR, DORA, and NHS DSPT.Automated evidence collection and built-in dashboards provide a single source of truth for your compliance posture, saving weeks of manual work during audits.

Policy Management

Centralise, version, and publish all your information security policies in one place.Hicomply automates approvals, reminders, and distribution, ensuring your ISMS documentation stays current and aligned with frameworks like ISO 42001 and NIST CSF.Say goodbye to outdated PDFs — manage policies dynamically and maintain full traceability.

Incident Management

Capture, investigate, and resolve security incidents with structured workflows and automated evidence trails.Hicomply integrates with ticketing tools like Jira, Zendesk, and Azure DevOps to streamline incident response and link findings to risk and control updates — a key step for SOC 2 Type II readiness.

Audits and Assessments

Simplify internal and external audit preparation with built-in audit templates and automated task assignments.
Hicomply’s audit management platform aligns with ISO 27001, ISO 9001, and ISO 14001, giving teams a clear overview of control effectiveness, audit evidence, and corrective actions — all from one dashboard.

Staying Compliant
Computer Software
IT and Services
Professional Services
Growth