ISO27001:2022 – A5.29 Information security during disruption

Introduction to ISO 27001 – A5.29

ISO 27001 – A5.29 focuses on ensuring information security is maintained during any business disruption. It is closely related to several other Annex A controls, so you should also review:

What does the standard require?

“The organisation shall plan how to maintain information security at an appropriate level during disruption.”

(ISO 27001 – A5.29 – Information security during disruption)

Why is this required?

Disruptions to your business — whether due to natural disaster, cyberattack, or global pandemic — often require changes in how services are delivered or how staff operate. These changes can introduce unexpected vulnerabilities.

During COVID-19, for example, some businesses deployed insecure home devices or used free, unlicensed software, increasing exposure to threats. This control is about ensuring contingency plans preserve security standards, even if methods or tools must adapt.

What the auditor is looking for

The auditor will review your Incident Response Plan and Business Continuity Plan to confirm that contingency actions have taken information security into account.

They will also check whether supplier agreements account for maintaining security during a disruption — such as secure communication channels, escalation protocols, and continuity procedures.

What do you need to do?

  • Ensure your BCP and incident response documents reflect secure contingency measures
  • Review any arrangements (e.g., remote working, backup connectivity) to confirm they do not introduce vulnerabilities
  • Review supplier SLAs and contracts to verify their business continuity plans support your security requirements
  • Document any adaptations to standard procedures and evaluate their security implications

Q & A

How can we evidence this in our plans?

Include specific contingency scenarios in your response and continuity plans and ensure each one clearly considers how information security will be maintained. For example, if you’re switching to remote access during a disruption, your plan should specify encrypted connections, approved devices, and acceptable use policies.

Difficulty Rating

1 out of 5 – This control requires no deep technical knowledge. You simply need to review and document your continuity arrangements with a focus on maintaining information security throughout any disruption.

More Questions?

Remember, ISO27001 is about integrated thinking. Review related controls for a more complete picture. And if you’re stuck, reach out — we’re happy to help.

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” — available now on Amazon.

ISO 27001 – A5.29