Information Security Continuity
Information security continuity is the practice of making sure that an organization's protections for its information keep working even during a crisis or disaster, such as a cyber attack or natural disruption. Rather than letting security controls lapse when normal operations are interrupted, the organization plans ahead so that confidentiality, integrity, and availability of information are maintained through adverse situations. It is closely related to broader business continuity, which is a process-driven approach to keeping operations running during unplanned disruptions.
Information security continuity refers to the requirement that an organization determine and provide for the continuity of information security management during adverse situations, such as a crisis or disaster, so that information security controls and their supporting objectives are not degraded when normal operating conditions are disrupted. Within ISO/IEC 27001, this concern is addressed through the Annex A organisational controls; note that the 2022 revision restructured Annex A into four themes, and the placement and grouping of business continuity-related controls differs from the 2013 edition, so practitioners should reference the applicable version when citing specific controls. In practice, information security continuity is typically implemented by establishing requirements for maintaining information security through disruption, embedding those requirements into the organization's broader business continuity arrangements, and verifying that controls remain effective during and after adverse events; the specific measures selected depend on the organization's risk assessment and are documented via the Statement of Applicability. This control area addresses the persistence of information security under adverse conditions and is distinct from, though complementary to, general business continuity and disaster recovery planning.
Why it matters
When an organization suffers a crisis or disaster, whether a cyber attack or a natural disruption, there is a tendency for security controls to lapse as staff focus on restoring core operations. Information security continuity addresses this risk directly by requiring that protections for confidentiality, integrity, and availability persist through adverse situations rather than being suspended when normal operating conditions are interrupted. Without deliberate planning, the very moment an organization is most exposed can become the moment its safeguards are weakest.
Because business continuity is fundamentally a process-driven approach to maintaining operations during unplanned disruptions, information security continuity ensures that security is treated as one of those operations to be preserved, not an afterthought that resumes only once systems are stable. Embedding security requirements into broader continuity arrangements helps avoid a scenario in which recovery efforts inadvertently introduce new exposures, such as relaxed access controls or unmonitored temporary systems.
It is important to keep the boundaries of this control area in mind. Addressing information security continuity does not by itself guarantee freedom from breaches or uninterrupted availability; it establishes and maintains the requirements for security to endure through disruption, and its effectiveness depends on the organization's risk assessment, the measures selected, and how well those measures are verified in practice.
Who it's relevant to
Inside Information Security Continuity
Common questions
Answers to the questions practitioners most commonly ask about Information Security Continuity.