<  All Posts

ISO27001 Annex A.17

ISO27001 Annex A.17 – Information Security Aspects of Business Continuity Management

ISO27001 Annex A.17 control, "Information Security Aspects of Business Continuity Management," is a standard that helps businesses ensure their data and operations are protected in the event of an unexpected interruption. By implementing this control, businesses can benefit from improved protection of their information and operations, increased confidence in their ability to recover from disruptive events, and enhanced overall business resilience. This control is easy to understand and helps businesses meet their information security obligations, reduce risk, and maintain business continuity.

What are the controls, and a simple step by step guide to meet them:

Business Continuity Management Policy

How to meet this:

Develop a Business Continuity Management Policy:

Business Impact Analysis

How to meet this:

Conduct a Business Impact Analysis:

Risk Assessment

How to meet this:

Conduct a Risk Assessment:

Business Continuity Strategy

How to meet this:

Develop a Business Continuity Strategy:

Business Continuity Plans

How to meet this:

Create Business Continuity Plans:

Testing and Exercising

How to meet this:

Test and Exercise the Plans:

Maintenance

How to meet this:

Maintain the Plans:

Review

How to meet this:

Review the Program:

These controls work together to help organisations protect their information and operations in the event of an unexpected disruption, improve their overall resilience, and reduce risk.

By following these steps, most businesses can meet ISO 27001 Annex A.17 and improve their overall resilience to disruptive events.

Documents, Evidence and the Audit

The following documents and evidence can be useful in demonstrating compliance with the control and to demonstrate compliance you can present the following evidence to an auditor:

Business Continuity Management Policy

Demonstrate compliance:

Business Impact Analysis

Demonstrate compliance:

Risk Assessment

Demonstrate compliance:

Business Continuity Strategy

Demonstrate compliance:

Business Continuity Plans

Testing and Exercising Reports

Demonstrate compliance:

Maintenance Logs

Demonstrate compliance:

Review Reports

Demonstrate compliance:

Having this evidence readily available and presenting it in a clear and organised manner can help demonstrate compliance with ISO27001 Annex A.17 and provide a clear understanding of the organisation's business continuity planning and management activities.

Protecting Digital Health Solutions

Contact Periculo for expert cyber security solutions tailored to the digital health industry.

Subscribe
Stay updated with our newsletter for the latest features and releases.
By subscribing, you agree to our Privacy Policy and consent to receive updates from us.
Thank you! Subscription received.
Oops! Something went wrong. Please try again.