Skip to content

Business continuity

Business continuity combines a business impact analysis (BIA) with a continuity register, covering ISO/IEC 27001 Annex A 5.29 (information security during disruption) and 5.30 (ICT readiness for business continuity). Open it from Business continuity under Controls & risk.

For each critical process or service, the register records:

  • CriticalityLow, Medium, High, or Critical.
  • RTO / RPO — the recovery time and recovery point objectives (free text, e.g. 4 hours / 1 hour).
  • Impact of disruption — what happens to the business if it’s down.
  • Owner — who’s accountable for it.

Each entry moves through a status of IdentifiedAnalyzedTested, so you can see which processes still need analysis and which have had their continuity actually tested. The summary tiles count total processes, how many are high/critical, how many are continuity-tested vs. untested, and how many still need an owner. Open a process to see and edit its full record, including dependencies and recovery strategy.

Rather than start from a blank register, use Build from common scenarios to populate it with the disruptions most organisations plan for — loss of office access, a core cloud/SaaS outage, ransomware or a major cyber incident, data loss or corruption, key supplier failure, loss of a key person, and payment/finance systems being unavailable. Each comes pre-filled with a suggested criticality, RTO/RPO, impact, dependencies, and a recovery-strategy starting point to adapt. These are generic examples, not a finished plan — tune them to your business. It’s safe to run more than once; it won’t duplicate what’s already there.