A5.29 Information security during disruption
2 min read
Disruptions—such as cyberattacks, natural disasters, system failures, or pandemics—can severely impact business operations and compromise information security. ISO 27001 emphasizes the need for resilience in handling such situations to ensure business continuity, data protection, and operational stability.
A strong Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) should integrate information security measures to minimize risks and recover quickly from disruptions.
Implementation Guide #
Step 1: Identify Critical Assets & Risks
- Conduct a Business Impact Analysis (BIA) to identify mission-critical systems, data, and operations.
- Evaluate risks such as ransomware attacks, data breaches, power failures, supply chain disruptions, or geopolitical risks.
- Prioritize security measures for systems essential to operations.
Step 2: Develop a Business Continuity and Disaster Recovery Plan (BCP & DRP)
- Establish a BCP team responsible for handling disruptions.
- Define roles and responsibilities for IT, security, legal, and operations teams.
- Develop a DRP to restore critical systems, applications, and data.
- Ensure alternative solutions for IT services, including backup servers and cloud redundancy.
Step 3: Secure Backup and Data Recovery Mechanisms
- Implement real-time or scheduled backups of critical data.
- Use secure offsite or cloud backups (AWS S3, Google Cloud, Azure Backup, Veeam).
- Encrypt backups to prevent data leaks or tampering.
- Test backup restoration regularly to ensure data integrity.
Step 4: Implement Redundant Security Controls
- Use multi-factor authentication (MFA) for critical accounts even during disruption.
- Deploy alternative communication channels (secure messaging, VPNs, emergency email servers).
- Maintain redundant security monitoring tools (SIEM, IDS/IPS, endpoint protection).
Step 5: Maintain Security in Remote Work & Crisis Situations
- Ensure secure access to company resources via VPNs, Zero Trust Network Access (ZTNA), or Secure Access Service Edge (SASE).
- Restrict access to sensitive data based on user roles (least privilege principle).
- Train employees on phishing risks, device security, and safe communication practices.
Step 6: Test and Update Continuity Plans Regularly
- Conduct Tabletop Exercises (TTX) to simulate disruptions.
- Run disaster recovery drills at least twice a year.
- Update plans based on lessons learned from real incidents.
Example Scenario #
Incident: A ransomware attack encrypts all corporate files, disrupting business operations.
Actions Taken:
- BCP is activated, and the IT team follows the DRP procedures.
- Backup systems are restored, minimizing downtime.
- Alternative communication channels (secure messaging, VPNs) are used while the main network is secured.
- Incident Response (IR) and forensic analysis identify the attack vector.
- Security policies are updated to prevent future occurrences.
Common Mistakes in Security During Disruptions #
- No tested BCP/DRP – Without regular testing, plans may fail during an actual crisis.
- Unsecured backup data – Backups should be encrypted and protected from ransomware.
- Ignoring access controls – Overlooking privilege restrictions can lead to insider threats.
- Lack of crisis communication plans – Employees should know whom to contact and what to do.
Templates for Implementation #
- Business Continuity & Disaster Recovery Plan (BCP & DRP) Template
- Risk Assessment & Impact Analysis Template
- Emergency Response Checklist
How to Pass an Audit #
Key Documents to Prepare:
- Business Continuity and Disaster Recovery Plans (BCP & DRP).
- Risk assessment reports and impact analysis documentation.
- Logs from past incidents and actions taken.
What the Auditor Will Check:
- Are there documented procedures for maintaining security during disruptions?
- Are backup and recovery processes tested regularly?
- Does the organization have alternative communication and security measures?
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.5.29 Information Security During Disruption | Preventive, Detective, Corrective, Resilience-Based |
| Purpose | Ensure data security and operational continuity during crises |
| Applicability | All organizations handling critical data or operations |
| ISO 27001 Domains | Business Continuity, Disaster Recovery, Risk Management |
Cyberattacks and disruptions are inevitable—how an organization prepares and responds determines the impact. A strong continuity plan, tested recovery strategies, and secure access controls ensure that operations remain resilient and protected.
Action Step:
Evaluate your BCP/DRP today—is it strong enough to handle a real-world cyber incident? If not, start improving it now!