ISO 27001 5.30, how using Harpe can help with business continuity and respond in the event of an incident
Connor Bell
Control 5.30 is a specific guideline within the ISO 27001 standard, which focuses on ensuring that information and communication technology (ICT) services remain operational and effective during and after any business disruption.
The control emphasises the importance of maintaining the integrity and availability of information, especially in the face of unforeseen events such as technical failures, cyberattacks, or natural disasters.
The end goal is to ensure that information integrity and availability is maintained before, during and after a period of business disruption.
To ensure that businesses can respond in the event of an incident, it's important to have documented recovery steps for each of your assets and suppliers (if applicable).
In today's technology landscape, we typically rely upon third parties to deliver services as part of our product - this means we rely heavily upon these third parties. Using Harpe, you can use the supplier tab to keep a register of all your suppliers and the services they provide in the asset tab.
For each supplier, Harpe has the ability to document assurance activities to ensure that each supplier meets your standard for information security as well as having recovery steps if this supplier were to become unavailable.
Then for each asset you will also have a documented assurance tab and recovery steps, these will then form into your business continuity plan allowing you to respond appropriately in the event of an incident (which Harpe also has a register for but that's a topic for another day).
Our goal is to make security and compliance easy and accessible to all businesses.
Book a demoFree 14-day trial
No credit-card required