A.5.29A.5 Organizational controls

Information security during disruption

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.29 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Plan how to keep information security at an appropriate level throughout periods of disruption.

How to meet this control

In short: Plan how to maintain security at an appropriate level during disruption.

  1. Step 01Address information security explicitly within business continuity and disaster recovery plans, not just uptime
  2. Step 02Determine how each control must adapt during disruption and document the adapted state
  3. Step 03Define compensating controls for any control that cannot be sustained during disruption
  4. Step 04Test continuity plans and confirm security is restored to the required level within the required timeframe
  5. Step 05Keep security tooling and supporting systems within the scope of continuity and recovery plans

Tip: Address security explicitly in your business continuity plan, not just uptime.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Determine how security controls need to adapt during disruption
  • ›Build information security requirements into business continuity management processes
  • ›Develop, implement, test and review plans to maintain or restore security for critical processes
  • ›Restore security to the required level within the required time frames
  • ›Keep security controls, supporting systems and tools within continuity and ICT continuity plans
  • ›Maintain processes to keep existing controls running during disruption
  • ›Put compensating controls in place for any controls that cannot be sustained during disruption

Audit evidence to keep

  • - Business continuity plan with explicit information security provisions
  • - Documented compensating controls for use during disruption
  • - Continuity test or exercise records confirming security was maintained
  • - Evidence security tooling is covered within recovery plans

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.5.29. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.