A.5.29
    Organizational Controls

    Information security during disruption

    The organization should plan how to maintain information security at an appropriate level during disruption.

    Purpose

    To ensure availability of information security controls during adverse conditions.

    Implementation Guidance

    Include information security in business continuity plans

    Define minimum security requirements during disruptions

    Establish alternative security controls for degraded operations

    Test security measures during continuity exercises

    Ensure security team can operate during disruptions

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.29 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.29 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.29 Information security during disruption. Built for compliance professionals.

    Try ISMS Copilot free