Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Regular testing and review of continuity plans

Critical
High
Normal
Low

The organisation should regularly, at least annually, test and review its information security continuity plans to ensure that they are valid and effective in adverse situations.

Testing of continuity plans shall involve, as appropriate, stakeholders critical to each plan. The organisation should identify and document the necessary contacts with suppliers and partners

In addition, the adequacy of continuity plans and associated management mechanisms should be reassessed in the event of significant changes in operations.

Connected other frameworks and requirements:
17.1.3: Verify, review and evaluate information security continuity
ISO 27001
ID.SC-5: Response and recovery
NIST CSF
PR.IP-10: Response and recovery plan tests
NIST CSF
RS.IM-2: Response strategies update
NIST CSF
RC.IM-2: Recovery strategies
NIST CSF
No items found.