DOC-011 ← Document Portal

Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP)

Procedures for ensuring continuity of key services and recovery from disruptive events
Document Number
DOC-011
Version
▸ 1.0
Status
DRAFT
Issue Date
▸ DD/MM/YYYY
Owner
▸ CISO / Chief Operating Officer
Approved by
▸ Board / CEO
Legal Basis
Art. 21(2)(c) NIS2; ISO 22301:2019; ISO/IEC 27001:2022 A.5.29–A.5.30
Related Documents
DOC-005 | DOC-007 | DOC-012 | DOC-020

1. Purpose and Scope

The Business Continuity Plan (BCP) defines procedures enabling the organisation to continue or rapidly restore delivery of key services following a disruptive event. The Disaster Recovery Plan (DRP) is the technical component of the BCP.

ℹ️
Backup documentation and data recovery procedures are described in detail in DOC-012.

2. Business Impact Analysis (BIA)

Based on the BIA, service criticality and recovery time objectives have been determined:

⚠ Critical – complete for each key service
Key Service Criticality MAD
(Max Allowable Downtime)
RTO
(Recovery Time Obj.)
RPO
(Recovery Point Obj.)
Owner
▸ [Service name 1, e.g. OT/SCADA system] ▸ [Critical] ▸ [e.g. 4h]per NIS2 ▸ [e.g. 2h] ▸ [e.g. 15 min] ▸ [First Last Name]
▸ [Service name 2] per NIS2
▸ [Service name 3]
Internal email ▸ [Important] ▸ [e.g. 24h] ▸ [e.g. 4h] ▸ [e.g. 1h] ▸ [IT Administrator]
ERP management system ▸ [Important]

RTO = Recovery Time Objective (from failure to full operation) | RPO = Recovery Point Objective (max. data loss looking back) | MAD = Maximum Allowable Downtime

3. Threat Scenarios and Response Procedures

ScenarioLikelihood (1–5)Impact (1–5)Emergency procedure ref.
Ransomware attack on IT systems ▸ 4▸ 5 DOC-007 PB-001 + section 4 below
Data centre / server room failure ▸ 2▸ 5 Section 4.2 below
Extended power outage ▸ 3▸ 4 Section 4.3 below
Internet / WAN link failure ▸ 3▸ 4 Section 4.4 below
Key IT staff unavailable ▸ 4▸ 3 Deputy list (DOC-004)
Natural disaster / physical catastrophe ▸ 1▸ 5 Evacuation procedure + DR site (section 4.5)

4.1 Procedure – Critical system failure (general)

  1. Detection and reporting to IT administrator and CISO → activate incident register (DOC-005).
  2. Assessment: which service is unavailable, what impact, is RTO at risk?
  3. If yes → BCP activation: notify crisis team (DOC-004).
  4. Activate backup / failover procedure (DOC-012).
  5. Status communication to users and management.
  6. Recovery → testing → return to production.
  7. Event documentation, PIR.

4.2 Procedure – Data centre failure

▸ Organisation completes – DR site location

Primary DC: ▸ [address, contact details]

DR site (secondary DC): ▸ [address / cloud / colocation – provider name, address]

Replication type: ▸ [cold / warm / hot standby]hot – RTO <1h; warm – 1–4h; cold – >4h

RPO to DR site: ▸ [e.g. 15 min, 1h, 24h]

4.3 Procedure – Power outage

  • UPS providing power for at least ▸ [30 minutes]min. 15 min for controlled shutdown.
  • Generator: ▸ [available / not available / required] – start-up time: ▸ [e.g. 30 sec].
  • Controlled server shutdown procedure during extended power failure.

4.4 Procedure – Internet link failure

▸ Organisation completes

Primary provider (link 1): ▸ [ISP name, bandwidth, contract number, support telephone]

Backup link (failover): ▸ [ISP name / LTE/5G backup / MPLS]

Switchover time to backup: ▸ [e.g. automatic / manual within 15 min]

4. BCP and DRP Testing

Requirement – tests minimum once a year (NIS2)
Test typeFrequencyScopeResponsible
Tabletop exercise (simulation) ▸ [annually]min. 1×/year – NIS2 Failure scenario with management participation ▸ CISO
Technical recovery test (DRP test) ▸ [every 6 months]min. 1×/year Failover test, recovery from backup (DOC-012) ▸ IT Administrator
Emergency communication test ▸ [quarterly] Verification of contacts and communication channels ▸ CISO

Test results are documented. Identified gaps result in plan updates within ▸ [30 days] of the test.

5. Crisis Communications – Contact Tree

⚠ Critical – list must be current and available offline
RoleName24/7 TelephoneE-mailDeputy
Crisis Coordinator (CISO)
CEO / President
IT Administrator
Legal Counsel / DPO
Press Officer

6. Change History and Tests

VersionDateAuthorDescriptionApproved by
▸ 1.0▸ DD/MM/YYYY ▸ Initial release ▸ Board
DOC-011 Business Continuity Plan (BCP/DRP) | v1.0 | NIS2/ISMS