Business Continuity and Disaster Recovery Policy

Document Summary


Item

Value

Organization

Information Dynamics


Document Name

Business Continuity and Disaster Recovery Policy

Classification

Internal

Compliance Reference

ISO 27001:2013 and ISO 20000:2011



Document Revision History


Date

Version

Prepared By

29th Aug, 2019

1.0

Information Dynamics

26th Aug 2020

1.1

Shaik Bavajan

26th Aug 2021

1.2

Shaik Bavajan

28th Aug 2022

1.3

Shaik Bavajan




Document Review History


Reviewed By

Version

Date

Signature

Soundarrajan

1.0

29-Aug-2019


Soundarrajan

1.1

28-Aug-2020


Soundarrajan

1.2

28-Aug-2021


Soundarrajan

1.3

28-Aug-2022


Table of Contents

  1. Purpose 3

  2. Scope 3

  3. Policy 3

Risk Assessment & Business Impact Analysis (BIA) 3

Business continuity planning framework 4

Business Continuity Strategy 4

Disaster Recovery Plan (DRP) 5

Business Resumption Plan 5

Crisis Management Program 5

Testing and maintenance Program 5

  1. Purpose

    The purpose of this policy is to have practice for business continuity management and ensure practices and controls are enabled to continue and manage business operations incase of a disaster or a crisis.


    ISO 27001:2013 Domain Reference: A.17 – Information Security aspects of Business Continuity

    ISO 27001:2013 Reference

    A.17.1.1

    Planning information security continuity

    A.17.1.2

    Implementing information security continuity

    A.17.1.3

    Verify, review and evaluate information security continuity

    A.17.2.1

    Availability of information processing facilities


    ISO 20000:2011 Domain Reference: 6.3: Service Continuity and Availability Management


  2. Scope

    The scope of the policy will be applicable to all activities under the scope statement of Information Dynamics


  3. Policy


    Risk Assessment & Business Impact Analysis (BIA)


    Business process owners shall be responsible for ensuring that the key events that can cause disruption to their processes are identified, the probability of their occurrence and their potential adverse impact is documented. Threats and applicable vulnerabilities shall be identified for information assets within the process.

    Developing the business continuity plan; and

    Reviewing and updating the business continuity plan (once a year) Risk and business impact assessment shall be reported.

    Business continuity planning framework




    Business Continuity Strategy


    A single common framework shall be followed for drafting continuity plans as per business requirements, which shall include the key stakeholders and third parties.


    Business Resumption Plan

    BRP shall be the responsibility of the respective process owners.


    Business resumption plans shall include but not be limited to:

  4. Associated Documentation