ISO 27001 Information Security Management Standard - Clause A.17

Posted by Craig Thornton

Part 36 - A17 Information Security Aspects of Business Continuity Management

Business continuity management (BCM) is a hot topic at the moment.

From Wikipedia: “Business continuity planning (or business continuity and resiliency planning) is the process of creating systems of prevention and recovery to deal with potential threats to a company. In addition to prevention, the goal is to permit ongoing operation, before and during execution of disaster recovery.”

The clause starts with information security continuity.

business-continuity-concept-image

 

A.17.1 Information Security Continuity 

So the objective here is to ensure information security continuity is embedded in your organisation’s business continuity planning systems.

Here at Mango we have a detailed business continuity planning system.  We have created a Business Continuity Plan (BCP).  We involved a wide range of employees and contractors to get the plan together.

The Mango BCP is quite comprehensive and covers the following topics:

  • Company Employees
  • Disaster Recovery Team
  • Office Infrastructure
  • Applications, Hardware and Data
  • Customers
  • Post emergency process
  • Servers and PC Details

Once in place we tested sections of the plan to ensure the details were correct and that people were prepared.  With our Head Office in a major earthquake zone, business continuity is something we plan for with knowledge that things out of your control can happen at any time.

The Mango BCP is reviewed and tested annually.  An event in Mango reminds us to conduct the review and the testing of the plan.

 

A.17.2 Redundancies

The objective here is to ensure the continued availability of information processing facilities.  So you need to build in sufficient redundancy to meet your requirements if things go wrong.

Here at Mango we worked hard with our IT suppliers to build sufficient redundancy into our processing facilities.  This redundancy was documented too in our BCP.

 

Takeaways

  1. Create a BCP.
  2. Involve as many people and contractors as you can to get the BCP in place.
  3. Test each area of the plan with your employees and contractors to ensure everyone is prepared.
  4. Work with your IT suppliers to ensure there is plenty of redundancy in your processing facilities.

View previous blogs in this series "ISO 27001 Information Security Management Standard":

Part 1 - Reasons why you need to meet this standard

Part 2 - Principle 1 - Analysing the Protection of Your Information and then Applying Controls

Part 3 - Principle 2 - Awareness of the Need for Information Security

Part 4 - Principle 3 - Assignment of Responsibility for Information Security

Part 5 - Principle 4 - Incorporating Management Commitment and the Interests of Stakeholders

Part 6 - Principle 5 - Enhancing Societal Values

Part 7 - Principle 6 - Risk assessments determining appropriate controls to reach acceptable levels of risk

Part 8 - Principle 7 - Security incorporated as an essential element of information networks and systems

Part 9 - Principle 8 - Active prevention and detection of information security incidents

Part 10 - Principle 9 - Ensuring a comprehensive approach to information security management

Part 11 - Principle 10 - Continual reassessment of information security and making of modifications as appropriate

Part 12 - ISO 27001 Information Security Management Standard: Clauses 0, 0.1, 0.2, 1, 2 and 3

Part 13 - ISO 27001 Information Security Management Standard: Clauses 4.1, 4.2, 4.3 and 4.4

Part 14 - ISO 27001 Information Security Management Standard: Clause 5.1

Part 15 - ISO 27001 Information Security Management Standard: Clause 5.2

Part 16 - ISO 27001 Information Security Management Standard: Clause 5.3

Part 17 - ISO 27001 Information Security Management Standard: Clause 6.1

Part 18 - ISO 27001 Information Security Management Standard: Clause 6.2

Part 19 - ISO 27001 Information Security Management Standard: Clauses 7.1 - 7.4

Part 20 - ISO 27001 Information Security Management Standard: Clause 7.5

Part 21 - ISO 27001 Information Security Management Standard: Clauses 8.1, 8.2, 8.3

Part 22 - ISO 27001 Information Security Management Standard: Clauses 9.1, 9.2, 9.3

Part 23 - ISO 27001 Information Security Management Standard: Clauses 10.1, 10.2

Part 24 - ISO 27001 Information Security Management Standard: Clause A5

Part 25 - ISO 27001 Information Security Management Standard: Clause A6

Part 26 - ISO 27001 Information Security Management Standard: Clause A7

Part 27 - ISO 27001 Information Security Management Standard: Clause A8

Part 28 - ISO 27001 Information Security Management Standard: Clause A9

Part 29 - ISO 27001 Information Security Management Standard: Clause A10

Part 30 - ISO 27001 Information Security Management Standard: Clause A11

Part 31 - ISO 27001 Information Security Management Standard: Clause A12 

Part 32 - ISO 27001 Information Security Management Standard: Clause A13

Part 33 - ISO 27001 Information Security Management Standard: Clause A14

Part 34 - ISO 27001 Information Security Management Standard: Clause A15

Part 35 - ISO 27001 Information Security Management Standard: Clause A16

Tags: ISO 27001, information security, ISO 27001 Certification