Business Continuity & Resilience · BC-Q05

Question: Are Disaster Recovery (DR) plans established for IT systems supporting critical business processes?

Why This Matters

DR plans ensure technology can be restored within acceptable timeframes, preventing data loss and extended downtime.

Maturity

0 — Unaware
No DR plans or recovery objectives defined.
1 — Ad Hoc
Backups exist but recovery process untested.
2 — Defined
DR plans created for key systems with assigned owners.
3 — Managed
Plans tested annually with documented outcomes.
4 — Integrated
Aligned with business BCPs and change management.
5 — Optimized
Automated recovery validation and continuous readiness metrics.

How to Level Up

| From → To | Actions | |—|—| | 0 → 1 |Inventory critical systems and dependencies.| | 1 → 2 |Document DR plans with RTO/RPO targets.| | 2 → 3 |Conduct restoration tests and record results.| | 3 → 4 |Integrate with BCP and change process.| | 4 → 5 |Automate backup validation and reporting.|

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

| Purpose | Tool | Notes | |—|—|—| | Backups | Restic / Veeam Free | Automated verification | | Tracking | Airtable | DR test calendar | | Dashboard | Metabase | Recovery metrics |

Common Pitfalls

Compliance Mapping

| Standard | Clauses / Notes | |—|—| | ISO 22301 | 8.4 / 8.5 | | ISO 27001 | A.5.30 / A.8.13 | | NIST CSF 2.0 | RS.RP / RS.IM | | NIRMATA Mapping | BC-Q05 strengthens technical resilience via tested DR plans. |