ISO/IEC FDIS 27031
(Main)Cybersecurity — Information and communication technology readiness for business continuity
Cybersecurity — Information and communication technology readiness for business continuity
This document describes the concepts and principles of information and communication technology (ICT) readiness for business continuity (IRBC). It provides a framework of methods and processes to identify and specify aspects for improving an organization's ICT readiness to ensure business continuity. This document serves the following business continuity objectives for ICT: — Maximum Tolerable Period of Disruption (MTPD), — Recovery Point Objective (RPO), — Recovery Time Objective (RTO) as part of the ICT Business Continuity Planning. This document applies to all types and sizes of organizations. This document describes how the ICT department plan and prepare to contribute to the resilience objectives desired by the organization.
Cybersécurité — Préparation des technologies de l'information et de la communication pour la continuité d'activité
General Information
Relations
Buy Standard
Standards Content (Sample)
FINAL DRAFT
International
Standard
ISO/IEC FDIS
ISO/IEC JTC 1/SC 27
Cybersecurity — Information
Secretariat: DIN
and communication technology
Voting begins on:
readiness for business continuity
2024-06-26
Voting terminates on:
2024-08-21
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
FINAL DRAFT
International
Standard
ISO/IEC FDIS
ISO/IEC JTC 1/SC 27
Cybersecurity — Information
Secretariat: DIN
and communication technology
Voting begins on:
readiness for business continuity
Voting terminates on:
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO/IEC 2024
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
© ISO/IEC 2024 – All rights reserved
ii
Contents Page
Foreword .v
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Abbreviated terms . 3
5 Structure of this document . 3
5.1 General .3
6 Integration of IRBC into BCM . 3
6.1 General .3
6.2 Enabling governance .4
6.3 Business continuity management objectives .5
6.4 Risk management and applicable controls for IRBC .6
6.5 Incident management and relationship to IRBC .6
6.6 BCM strategies and alignment to IRBC .6
7 Business expectations for IRBC . 7
7.1 Risk review .7
7.1.1 General .7
7.1.2 M onitoring, detection and analysis of threats and events .8
7.2 Inputs from business impact analysis .8
7.2.1 General .8
7.2.2 Understanding critical ICT services .8
7.2.3 Assessing ICT readiness against business continuity requirements .9
7.3 Coverage and interfaces .9
7.3.1 General .9
7.3.2 ICT dependencies for the scope .10
7.3.3 Determine any contractual aspects of dependencies .10
8 Defining prerequisites for IRBC . 10
8.1 Incident based – preparation before incident .10
8.1.1 General .10
8.1.2 ICT Recovery capabilities .11
8.1.3 Establishing an IRBC .11
8.1.4 Setting objectives .11
8.1.5 Determining possible outcomes and benefits of IRBC . 12
8.1.6 Equipment redundancy planning . 13
8.1.7 Determining the scope of ICT services related to the objectives . 13
8.2 Determining target ICT RTO and RPO .14
9 Determining IRBC strategies .15
9.1 General . 15
9.2 IRBC strategy options . 15
9.2.1 General . 15
9.2.2 Skills and knowledge .16
9.2.3 Facilities .16
9.2.4 Technology .17
9.2.5 Data .17
9.2.6 Processes .18
9.2.7 Suppliers .18
10 Determining the ICT continuity plan . 19
10.1 Prerequisites for the development of plans .19
10.1.1 Determining and setting the recovery organization .19
10.1.2 Determining time frames for plan development, reporting and testing .19
© ISO/IEC 2024 – All rights reserved
iii
10.1.3 Resources . 20
10.1.4 Competency of IRBC staff . 20
10.1.5 Technological solutions .21
10.2 Recovery plan activation .21
10.2.1 ICT BCP Activation .21
10.2.2 Escalation .21
10.3 ICT recovery plans . 22
10.3.1 RPO and RTO plans for ICT. 22
10.3.2 Facilities . 22
10.3.3 Technology . 22
10.3.4 Data . 22
10.3.5 Response and recovery procedures . 23
10.3.6 People .
...
ISO/IEC DIS FDIS 27031:20232024(E)
ISO/IEC JTC 1/SC 27
Secretariat: DIN
Date: 20232024-06-2012
Secretariat: DIN
Cybersecurity — Information and communication technology readiness for business continuity
ISO/IEC DISFDIS 27031:20232024(E)
© ISO/IEC 2023 2024
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no
part of this publication may be reproduced or utilized otherwise in any form or by any means,
electronic or mechanical, including photocopying, or posting on the internet or an intranet, without
prior written permission. Permission can be requested from either ISO at the address below or
ISO’sISO's member body in the country of the requester.
ISO copyright officeCopyright Office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
Fax: +41 22 749 09 47
Email: copyright@iso.org
Email: copyright@iso.org
Website: www.iso.orgwww.iso.org
Published in Switzerland.
ii © ISO/IEC 20232024 – All rights reserved
ISO/IEC DISFDIS 27031:20232024(E)
Contents
Foreword . 4
Introduction. 5
1 Scope . 7
2 Normative references . 7
3 Terms and definitions. 7
4 Abbreviated terms . 8
5 Structure of this document . 9
5.1 General . 9
6 Integration of IRBC into BCM . 9
6.1 General . 9
6.2 Enabling governance . 10
6.3 Business continuity management objectives . 11
6.4 Risk management and applicable controls for IRBC . 12
6.5 Incident management and relationship to IRBC . 12
6.6 The organization’s BCM strategies and alignment for IRBC . 12
7 Business Requirements for IRBC . 13
7.1 Risk review . 13
7.1.1 General . 13
7.1.2 Monitoring, detection and analysis of threats and events. 14
7.2 Inputs from business impact analysis (BIA) . 14
7.2.1 General . 14
7.2.2 Understanding critical ICT services . 14
7.2.3 Assessing ICT readiness against business continuity requirements . 15
7.3 Coverage, interfaces and dependencies . 15
7.3.1 General . 15
7.3.2 ICT dependencies for the scope. 16
7.3.3 Determine any contractual aspects of dependencies . 16
8 Defining prerequisites for IRBC . 16
8.1 Incident based – preparation before incident . 16
8.1.1 General . 16
8.1.2 ICT Recovery capabilities . 17
8.1.3 Establishing an IRBC . 17
8.1.4 Setting performance objectives . 18
8.1.5 Determing possible outcomes and benefits of IRBC . 19
8.1.6 HVAC redundancy planning . 19
8.1.7 Determine the scope of ICT services related to the objectives . 20
8.2 Determine target ICT RTO and ICT RPO . 21
9 Determine IRBC strategies . 22
9.1 General . 22
9.2 IRBC Strategy Options . 23
9.2.1 General . 23
9.2.2 Skills and Knowledge . 23
9.2.3 Facilities . 23
9.2.4 Technology . 24
9.2.5 Data. 25
© ISO/IEC 20232024 – All rights reserved iii
ISO/IEC DISFDIS 27031:20232024(E)
9.2.6 Processes . 25
9.2.7 Suppliers . 26
10 Determine ICT continuity plan . 26
10.1 Prerequisites for the development of plans . 26
10.1.1 Determine and set the recovery organization . 26
10.1.2 Determine time frames for plan development, reporting and testing. 27
10.1.3 Resources . 28
10.1.4 Competency of IRBC staff . 28
10.1.5 Technological solutions . 28
10.2 Recovery plan activation . 29
10.2.1 ICT BCP Activation . 29
10.2.2 Escalation . 29
10.3 ICT recovery plans . 30
10.3.1 ICT RPO and ICT RTO plans . 30
10.3.2 Facilities . 30
10.3.3 Technology . 30
10.3.4 Data. 30
10.3.5 Processes . 31
10.3.6 People . 31
10.4 Temporary work around plans . 31
10.5 External contacts and procedures . 31
11 Testing, exercise, and auditing . 31
11.1 Internal test requirements . 31
11.1.1 Performance criteria . 31
11.2 Testing dependencies . 32
11.2.1 Test and exercise . 32
11.2.2 Test and exercise program . 32
11.2.3 The scope of exercises . 33
11.2.4 Planning an Exercise . 33
11.2.5 Alert based and different recovery stages . 34
11.2.6 Managing an Exercise. 35
11.3 Learning from tests . 36
11.4 Auditing the IRBC . 36
11.5 Control of documented information . 37
12 Final ICT RPO and RTO . 37
12.1 General . 37
13 Top Management responsibilities regarding evaluating the IRBC. 37
13.1 General . 37
13.2 Management Responsibilities . 38
Annex A (Informative) General consideration for risk comparing ICT RTO and ICT RPO to
business objectives for ICT recovery . 39
Annex B (Informative) Risk reporting for FMEA . 40
Bibliography .
...
Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.