Objective

Ensure continuity and recovery arrangements are approved, current and capable of meeting recovery objectives.

Control Activity

Operations and Technology review continuity strategies and the principal BCM, IT disaster recovery, cyber recovery and evacuation plans at least annually and after material change or test findings. The review verifies: Alternate Worksites (secondary offices and reciprocal arrangements); Remote Work (VPN access, MFA, encrypted communication); Data Backup & Recovery (geographically distributed backups, real-time replication for mission-critical data); and Supplier & Vendor Management (continuity clauses in SLAs, backup vendors identified). The Principal BCM Plan must outline crisis command structure, emergency roles, call trees, directories of vendors and emergency responders, and decision-making protocols. The IT Disaster Recovery Plan must specify procedures for restoring IT infrastructure, applications, and data, with annual testing. The Cybersecurity Recovery Plan must include detailed incident playbooks for ransomware, DDoS attacks, and insider threats. The Building Evacuation Plan must include routes, muster points, responsibilities, and quarterly drills. Supplier continuity and exit arrangements are included for critical or essential outsourcing.

Evidence

  • Expected evidence: Approved continuity and recovery strategies
  • Expected evidence: Current BCM and recovery sub-plans
  • Expected evidence: Backup and restoration design
  • Expected evidence: Supplier continuity, recovery and exit evidence
  • Expected evidence: Plan approval and version history
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository, SYS-OUT-001 Outsourcing Register; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample critical activities and trace approved objectives to current plan steps, resources, dependencies and supplier arrangements
  • Testing frequency: annual and after material change, incident or exercise finding

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved Business Continuity Manual version 1.0.