Continuity planning, in a nutshell, means ensuring that an organisation is able to carry on doing business when problems arise and privacy information – or entire information processing facilities – becomes compromised or unavailable.
Business continuity is closely linked to backup and disaster recovery (BUDR) – a technical ICT concept that encompasses redundancy layers, backups, asset duplication and alerting.
ISO 27701 focuses on two key areas of continuity management, privacy information security and redundancy, across 4 sub-clauses:
Each sub-clause contains guidance information from ISO 27002, applied within the context of privacy information security.
Organisations should consider privacy information security as an integral part of broader business continuity management procedure.
ISO asks organisation to focus on two key areas when formulating business continuity plans:
Privacy information security integrity should be maintained at all times. Should PII or privacy-related assets become compromised in any way, organisations should do as much as they can to restore them in a timely and efficient manner, and to the same pre-disruption levels.
Organisations should:
If it’s not possible to sustain privacy information security controls at any given time (especially during periods of disruption), organisations should enact ‘compensating’ controls that strive to achieve as high a level of information security as is possible.
See ISO 27701 Clause 6.14.1.1
Book a tailored hands-on session
based on your needs and goals
Book your demo
See ISO 27701 Clause 6.14.1.1
Organisations should strive to ensure that business services and privacy information systems are operable at all times.
ISO recommends duplication as a redundancy mechanism – organisations should keep an inventory of spare parts, duplicate hardware and software components, spare network devices and peripherals that are able to be swapped out for malfunctioning assets across the network.
Alerts should be setup to first identify failed privacy information processing facilities, and for alternate systems to be brought as quickly as possible.
Organisations should:
ISO 27701 Clause Identifier | ISO 27701 Clause Name | ISO 27002 Control | Associated GDPR Articles |
---|---|---|---|
6.14.1.1 | Planning Information Security Continuity | 5.29 – Information Security During Disruption for ISO 27002 | None |
6.14.1.2 | Implementing Information Security Continuity | 5.29 – Information Security During Disruption for ISO 27002 | None |
6.14.1.3 | Verify, Renew and Evaluate Information Security Continuity | 5.29 – Information Security During Disruption for ISO 27002 | None |
6.14.2.1 | Availability of Information Processing Facilities | 8.14 – Redundancy of Information Processing Facilities for ISO 27002 | None |
Our ISMS.online solutions make it easy for organisations to achieve project oversight, ensuring that the data controller and processor policies and procedures are in line with the ISO standard.
Our online system also ensures that system implementers have a single place for reference and collaboration. Our Assured Results Method (ARM) enables you to be confident that you are ticking all the boxes you need to comply with the standard.
Find out more by booking a hands on demo.
Book a tailored hands-on session
based on your needs and goals
Book your demo