# Business continuity and disaster recovery policy

Source: https://aestech.com.au/policy-templates/#business-continuity-and-disaster-recovery-policy
Markdown URL: https://aestech.com.au/policy-templates/business-continuity-and-disaster-recovery-policy.md

Use for ISO 27001 A.5.29, A.5.30, A.5.7, SOC 2 Availability, and resilience and recovery requirements.

Frameworks: ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how the company maintains and recovers critical operations during and after a disruptive event, and how information security is preserved throughout. It establishes recovery objectives and the planning, testing and review needed to meet them.

2. Scope
This policy applies to all critical business processes, supporting systems, people and facilities. It covers events such as major system outages, supplier failure, cyber incidents, loss of premises and loss of key staff.

3. Policy statements
- Critical business processes must be identified through a business impact analysis and reviewed at least annually.
- Each critical process must have a recovery time objective and, where data is involved, a recovery point objective.
- Business continuity and disaster recovery plans must be documented, accessible during a disruption and assigned to named owners.
- Information security controls must remain in force during disruption and recovery, including access control, logging and approvals.
- Continuity and recovery plans must be tested at least annually, and results must drive improvements.
- Key dependencies on suppliers and cloud providers must be assessed for continuity.
- Crisis communication arrangements must cover staff, customers, regulators and other stakeholders.

4. Roles and responsibilities
- Executive management sponsors the programme and approves recovery objectives.
- The [Continuity Lead] maintains the business impact analysis and coordinates plans and tests.
- Process and system owners maintain recovery procedures for their areas.
- The [Incident Response] team coordinates with continuity activities during major events.

5. Procedures
- Conduct and maintain a business impact analysis of critical processes and dependencies.
- Document continuity plans and technical disaster recovery procedures for critical systems.
- Define activation criteria, recovery teams and escalation paths.
- Run continuity and recovery exercises at least annually, including at least one realistic scenario test.
- Record lessons learned and track corrective actions to closure.

6. Evidence and records
Keep the business impact analysis, recovery objectives, continuity and recovery plans, exercise records, test results, corrective actions and communication templates.

7. Review cadence
This policy and the supporting plans are reviewed at least annually and after major incidents or significant business change.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md