Business continuity
Business continuity combines a business impact analysis (BIA) with a continuity register, covering ISO/IEC 27001 Annex A 5.29 (information security during disruption) and 5.30 (ICT readiness for business continuity). Open it from Business continuity under Controls & risk.
What you capture
Section titled “What you capture”For each critical process or service, the register records:
- Criticality — Low, Medium, High, or Critical.
- RTO / RPO — the recovery time and recovery point objectives (free text, e.g. 4 hours / 1 hour).
- Impact of disruption — what happens to the business if it’s down.
- Owner — who’s accountable for it.
Each entry moves through a status of Identified → Analyzed → Tested, so you can see which processes still need analysis and which have had their continuity actually tested. The summary tiles count total processes, how many are high/critical, how many are continuity-tested vs. untested, and how many still need an owner. Open a process to see and edit its full record, including dependencies and recovery strategy.
Build from common scenarios
Section titled “Build from common scenarios”Rather than start from a blank register, use Build from common scenarios to populate it with the disruptions most organisations plan for — loss of office access, a core cloud/SaaS outage, ransomware or a major cyber incident, data loss or corruption, key supplier failure, loss of a key person, and payment/finance systems being unavailable. Each comes pre-filled with a suggested criticality, RTO/RPO, impact, dependencies, and a recovery-strategy starting point to adapt. These are generic examples, not a finished plan — tune them to your business. It’s safe to run more than once; it won’t duplicate what’s already there.
Next steps
Section titled “Next steps”- Statement of Applicability: where Annex A 5.29 and 5.30 sit in your SoA.
- Policies: tailor a business continuity policy from the template library.