Home / ISO 27001 Glossary of Terms / Business Continuity Plan (BCP)

Business Continuity Plan (BCP)

11/09/2025

Author: Stuart Barker | ISO 27001 Expert and Thought Leader

Business Continuity Plan (BCP) is a documented, strategic plan that details the procedures an organisation will follow to maintain or quickly resume critical business functions during and after a disruption. Its primary goal is to ensure the continuity of operations, protecting the organisation’s information, assets, and reputation from the effects of a disaster or security incident.

BCP vs. Disaster Recovery Plan (DRP)

While often confused, a BCP is broader than a Disaster Recovery Plan (DRP).

  • BCP focuses on keeping the entire business running in some capacity during a crisis. It covers all aspects, including people, processes, physical facilities, and communication. Think of it as a proactive strategy to avoid total business interruption.
  • DRP is a more specific subset of the BCP. It focuses on the technical recovery of an organisation’s IT systems and infrastructure after a disaster has occurred.

In short, a BCP asks, “How can we keep the business running?”, while a DRP asks, “How do we recover our IT systems?”

ISO 27001 Context

ISO 27001 requires organisations to have robust business continuity processes as part of their Information Security Management System (ISMS). This is covered in ISO 27001 Annex A 5.29 Information Security During Disruption and ISO 27001 Annex A 5.30 ICT Readiness For Business Continuity which focus on ensuring information security continuity and ICT readiness during a disruption. The standard emphasises that the BCP should be regularly tested, reviewed, and evaluated to ensure it remains effective.

About the author

Stuart Barker is an information security practitioner of over 30 years. He holds an MSc in Software and Systems Security and an undergraduate degree in Software Engineering. He is an ISO 27001 expert and thought leader holding both ISO 27001 Lead Implementer and ISO 27001 Lead Auditor qualifications. In 2010 he started his first cyber security consulting business that he sold in 2018. He worked for over a decade for GE, leading a data governance team across Europe and since then has gone on to deliver hundreds of client engagements and audits.

He regularly mentors and trains professionals on information security and runs a successful ISO 27001 YouTube channel where he shows people how they can implement ISO 27001 themselves. He is passionate that knowledge should not be hoarded and brought to market the first of its kind online ISO 27001 store for all the tools and templates people need when they want to do it themselves.

In his personal life he is an active and a hobbyist kickboxer.

His specialisms are ISO 27001 and SOC 2 and his niche is start up and early stage business.