ISO27001:2022 A5.30
ICT Readiness for Business Continuity
Introductions to ISO 27001 – A5.30
ISO 27001 – A5.30 is one of the newer additions in ISO27001:2022 and plays a critical role in your broader Incident Management and Business Continuity framework. For full context, be sure to review related controls:
- A5.24 – Information security incident management planning and preparation
- A5.25 – Assessment and decision on information security events
- A5.26 – Response to information security incidents
- A5.27 – Learning from information security incidents
- A5.28 – Collection of evidence
- A5.29 – Information security during disruption
What does ISO 27001 – A5.30 require?
“ICT readiness shall be planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements.”
(ISO 27001 – A5.30 – ICT Readiness for Business Continuity)
The control breaks down into four actionable areas:
- Planned: Identify which ICT systems are critical to your business
- Implemented: Put in place backup and resilience measures
- Maintained: Ensure backup infrastructure and DR plans remain current
- Tested: Regularly test your DR and ICT continuity arrangements
Why is this required?
Modern businesses are highly reliant on ICT infrastructure. A failure in key systems, such as email, finance tools, or CRM platforms, could severely disrupt operations and erode customer trust. Planning for ICT continuity ensures your business can survive and recover from disruptions with minimal damage.
What the auditor is looking for
ICT Readiness Shall Be Planned
The auditor will expect to see a Business Impact Analysis (BIA) that identifies critical ICT systems and their associated Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
ICT Readiness Shall Be Implemented
Evidence of implemented measures such as backup systems, mirrored servers, cloud redundancy, or Disaster Recovery Plans (DRP) will be reviewed. Documentation and communication of these plans are essential.
ICT Readiness Shall Be Maintained
The auditor will want to know how often standby systems are updated and tested. For example, if you store a spare router or offline laptop, how do you ensure it’s patched and up to date?
ICT Readiness Shall Be Tested
Even a well-designed DRP is useless if it hasn’t been tested. Auditors will ask to see records of tests or drills where ICT recovery processes were trialed and evaluated.
What do you need to do?
- Start with a BIA to determine critical functions and their dependencies on ICT
- Work with IT to define RTOs and RPOs
- Create and maintain Disaster Recovery Plans specific to critical systems
- Confirm that your ICT infrastructure has appropriate resilience (e.g., multi-region cloud, backup hardware, failover systems)
- Test these plans under realistic conditions and document the outcomes
Q & A
What should we include in the DRP?
DRPs should be technical in nature and written with your IT team. At minimum, they should contain:
- List of critical systems and applications
- Network diagrams and infrastructure topology
- Configuration and restoration procedures
- Contact details for internal and external recovery support
- Backup processes and location of recovery media
Difficulty Rating
3 out of 5 – This control does require some technical understanding. You’ll need to liaise closely with your IT team and possibly external vendors to fully capture your ICT resilience strategy and document recovery processes.
More Questions?
Remember that ISO27001 is about aligning people, processes, and technology. Don’t isolate this control—use it in conjunction with the rest of your Business Continuity and Incident Response framework.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” — available now on Amazon.
