Information security during disruption

What is Information security during disruption?

What is Information security during disruption?

ISO 27001 Information security during disruption is a guideline about keeping information safe when things go wrong. It’s about being ready for problems like a power outage or a bad storm. The main goal is to make sure your work can still get done and that your important information doesn’t get lost or stolen, even during an emergency. This rule helps companies make a plan to deal with disruptions.

Examples

  • A big storm hits the area. The company can’t get to their office. The plan would tell them how to work from home and get to their computer files on the internet.
  • A computer virus attacks the network. The plan would tell the company how to quickly disconnect the infected computers so the virus can’t spread. It would also explain how to use a backup to get things working again.

Context

This rule is a small part of a bigger set of rules called ISO 27001. This bigger set of rules is all about keeping information secure. Think of it like a guidebook for a company to follow so they can protect their information. ISO 27001 Information security during disruption is one chapter in that guidebook, specifically for when things go wrong.

Relevant ISO 27001 Controls

The following controls from the ISO/IEC 27001:2022 standard are related to information security during disruption:

In addition:

Related ISO 27001 Control / ConceptRelationship Description
ISO 27001 Annex A 5.29: Information Security During DisruptionCore Requirement: The primary control that mandates organizations to plan and implement processes to maintain information security continuity during a crisis or disruption.
ISO 27001 Annex A 5.30: ICT Readiness for Business ContinuityTechnical Foundation: Focuses on the technical capability of IT systems to be restored and remain operational, supporting the security goals during a disruption.
ISO 27001 Annex A 8.14: RedundancyOperational Resilience: Provides the backup hardware and systems needed to ensure security controls (like firewalls and logs) remain active even if the primary site fails.
Glossary: Business ContinuityOverarching Framework: Information security during disruption is a specialized subset of the broader Business Continuity plan, specifically focused on the “security” aspect of recovery.
Glossary: Disaster Recovery (DR)Technical Execution: DR is the practical process of getting systems back online, while this control ensures that those systems are secure the moment they are restored.
Glossary: AvailabilityPrimary Pillar: Disruptions are direct attacks on “Availability”; this control ensures that while restoring availability, the organization doesn’t accidentally compromise Confidentiality or Integrity.
Glossary: CIA TriadSafety Net: The main objective is to ensure that the three pillars of the CIA triad are not lost or weakened during an emergency or unplanned event.
ISO 27001 Glossary of Terms (Main Index)Parent Directory: The central index where Information Security During Disruption is categorized as a vital continuity and resilience term.
ISO 27001 Toolkit Business Edition

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top