ICT Continuity
ICT continuity is an organization's ability to keep its information and communication technology (ICT) systems running, or to restore them quickly, so that essential business activities can continue during and after a disruption. It focuses on protecting and recovering the technology, data, and services that the business depends on. In practice, it is planned around which systems the business identifies as most critical.
ICT continuity encompasses the capabilities, plans, and controls that enable information and communication technology systems to support an organization's business continuity objectives, including the ability to react in advance of, or upon detection of, a disruptive event. ICT continuity requirements are typically derived from the business impact analysis (BIA), which identifies the subset of ICT resources needed to sustain prioritized business activities and their associated availability, integrity, and confidentiality needs. Within ISO/IEC 27001, this discipline is addressed by Annex A control 5.30 (ICT readiness for business continuity), which aims to ensure ICT systems can support continuity objectives; as an Annex A reference control, its applicability is determined through the Statement of Applicability and informed by risk assessment rather than being universally mandated. ICT continuity is generally scoped as a subset of broader organizational business continuity management and does not, on its own, guarantee uninterrupted service or freedom from disruption.
Why it matters
Modern organizations depend on information and communication technology for nearly every prioritized business activity, so a disruption to critical systems can quickly cascade into a disruption of the business itself. ICT continuity matters because it turns a general aspiration to "stay operational" into a planned capability: the organization identifies which systems, data, and services are most critical and puts controls and recovery arrangements in place to protect and restore them. This capability includes the ability to react in advance of a disruptive event or upon detection of one, rather than only responding after an outage has fully materialized.
A defining feature of ICT continuity is that its requirements are derived from the business impact analysis (BIA). The BIA identifies the subset of ICT resources needed to sustain prioritized business activities, along with their associated availability, integrity, and confidentiality needs. Without this linkage, continuity investment risks being misdirected, protecting systems that are not essential while leaving critical dependencies under-resourced. Grounding ICT continuity in the BIA helps ensure that recovery priorities reflect what the business actually needs to keep running.
It is important to set expectations honestly: ICT continuity is generally scoped as a subset of broader organizational business continuity management, and it does not, on its own, guarantee uninterrupted service or freedom from disruption. It reduces the likelihood and impact of ICT-related interruptions and shortens recovery, but the outcomes depend on scope, risk assessment decisions, and how thoroughly plans are tested and maintained.
Who it's relevant to
Inside ICT Continuity
Common questions
Answers to the questions practitioners most commonly ask about ICT Continuity.