GlossaryCompliance operations

Business continuity plan

Short answer

A business continuity plan (BCP) sets out how an organisation keeps its critical activities running, or restores them quickly, during and after a disruption such as a cyberattack, a cloud outage or the loss of an office. It defines priorities, recovery times, roles and procedures.

Business impact analysis

A BCP starts with a business impact analysis (BIA), which identifies the critical processes, the systems and suppliers they depend on, and how long the company can operate without each one.

RTO and RPO

Two figures shape the recovery strategy. The RTO (Recovery Time Objective) is the maximum acceptable time to restore a process or system. The RPO (Recovery Point Objective) is the maximum amount of data, measured in time, that the company can afford to lose, and it determines how often backups are made. An RPO of four hours means backups at least every four hours.

BCP vs disaster recovery

The BCP covers the whole business: people, offices, suppliers and communication. The disaster recovery plan (DRP) is its technical part, focused on restoring IT systems and data. Both should account for ransomware, which can disable systems and backups at the same time.

Where it shows up in compliance

ISO 27001 requires information security during disruption and ICT readiness for business continuity (Annex A 5.29 and 5.30). ISO 22301 is the standard for a full business continuity management system. The ENS, NIS2 and DORA all require continuity measures, and DORA requires them to be tested. A plan that has never been tested should not be relied on.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub