Skip to main content
Category: Business Continuity

Information Security Continuity

Also known as: Information Security Aspects of Business Continuity, Continuity of Information Security Management
Simply put

Information security continuity is the practice of making sure that an organization's protections for its information keep working even during a crisis or disaster, such as a cyber attack or natural disruption. Rather than letting security controls lapse when normal operations are interrupted, the organization plans ahead so that confidentiality, integrity, and availability of information are maintained through adverse situations. It is closely related to broader business continuity, which is a process-driven approach to keeping operations running during unplanned disruptions.

Formal definition

Information security continuity refers to the requirement that an organization determine and provide for the continuity of information security management during adverse situations, such as a crisis or disaster, so that information security controls and their supporting objectives are not degraded when normal operating conditions are disrupted. Within ISO/IEC 27001, this concern is addressed through the Annex A organisational controls; note that the 2022 revision restructured Annex A into four themes, and the placement and grouping of business continuity-related controls differs from the 2013 edition, so practitioners should reference the applicable version when citing specific controls. In practice, information security continuity is typically implemented by establishing requirements for maintaining information security through disruption, embedding those requirements into the organization's broader business continuity arrangements, and verifying that controls remain effective during and after adverse events; the specific measures selected depend on the organization's risk assessment and are documented via the Statement of Applicability. This control area addresses the persistence of information security under adverse conditions and is distinct from, though complementary to, general business continuity and disaster recovery planning.

Why it matters

When an organization suffers a crisis or disaster, whether a cyber attack or a natural disruption, there is a tendency for security controls to lapse as staff focus on restoring core operations. Information security continuity addresses this risk directly by requiring that protections for confidentiality, integrity, and availability persist through adverse situations rather than being suspended when normal operating conditions are interrupted. Without deliberate planning, the very moment an organization is most exposed can become the moment its safeguards are weakest.

Because business continuity is fundamentally a process-driven approach to maintaining operations during unplanned disruptions, information security continuity ensures that security is treated as one of those operations to be preserved, not an afterthought that resumes only once systems are stable. Embedding security requirements into broader continuity arrangements helps avoid a scenario in which recovery efforts inadvertently introduce new exposures, such as relaxed access controls or unmonitored temporary systems.

It is important to keep the boundaries of this control area in mind. Addressing information security continuity does not by itself guarantee freedom from breaches or uninterrupted availability; it establishes and maintains the requirements for security to endure through disruption, and its effectiveness depends on the organization's risk assessment, the measures selected, and how well those measures are verified in practice.

Who it's relevant to

Business Continuity and Resilience Managers
Those responsible for keeping operations running during unplanned disruptions need to treat information security as one of the capabilities to be preserved. Coordinating with security teams ensures that continuity plans do not inadvertently weaken confidentiality, integrity, or availability protections during recovery.
ISMS and Compliance Managers
Practitioners maintaining an ISO/IEC 27001 information security management system must determine requirements for continuity of information security management in adverse situations and document the selected measures through the Statement of Applicability. They should reference the applicable version of the standard, as Annex A control placement and grouping differs between the 2013 and 2022 editions.
Security Engineers and Operations Teams
Technical staff implementing and verifying controls need to ensure protections remain effective during and after a crisis or disaster, rather than lapsing under adverse operating conditions. This includes confirming that temporary or recovery arrangements do not degrade the organization's security objectives.
Auditors and Certification Bodies
Those assessing an ISMS against ISO/IEC 27001 evaluate whether the organization has determined and provided for the continuity of information security management in adverse situations, and whether those requirements are appropriately embedded in continuity arrangements and supported by the risk assessment. The specific controls examined depend on the version of the standard and the defined scope of the ISMS.

Inside Information Security Continuity

Continuity of Information Security Controls
The concept centers on maintaining information security controls during adverse or disruptive situations, rather than allowing security safeguards to lapse when normal operations are interrupted. It focuses on ensuring that the required level of protection persists through disruption.
Relationship to ISO/IEC 27001 Annex A
Information security continuity is addressed within the Annex A reference controls of ISO/IEC 27001. As with all Annex A controls, its applicability is determined through the risk assessment and documented in the Statement of Applicability, and the specific control designation depends on the version of the standard being applied (the 2013 edition versus the restructured 2022 edition).
Distinction from Business Continuity and Availability
Information security continuity concerns preserving confidentiality, integrity, and availability of information during disruption. It is related to, but distinct from, broader business continuity management and from the Availability category of the SOC 2 Trust Services Criteria, which is an optional category selected based on scope.
Planning, Implementation, and Verification
The concept typically encompasses establishing requirements for security continuity, implementing measures to sustain those requirements during adverse conditions, and periodically verifying that the continuity arrangements remain effective, though the exact expectations depend on scope and the applicable framework version.

Common questions

Answers to the questions practitioners most commonly ask about Information Security Continuity.

Is information security continuity the same thing as business continuity or disaster recovery?
No. Information security continuity focuses specifically on maintaining the confidentiality, integrity, and availability of information and information security controls during adverse or disruptive situations, whereas business continuity and disaster recovery address the broader resumption of business operations. Information security continuity is typically treated as the security dimension that should be embedded within, and aligned to, an organization's wider continuity planning rather than replacing it.
Does implementing information security continuity mean my SOC 2 report or ISO 27001 certificate guarantees no downtime or breaches?
No. A SOC 2 report attests only to the controls and the period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS; neither guarantees freedom from disruption or breach. Information security continuity provisions demonstrate that controls to preserve security during disruption were designed, and in a SOC 2 Type II or an ISO 27001 surveillance context that they operated, but they cannot promise uninterrupted availability or an absence of incidents.
How does information security continuity map between SOC 2 and ISO 27001?
Mapping is possible but partial. In SOC 2 the concept typically surfaces through the Common Criteria and, where selected in scope, the Availability category, since Availability is an optional Trust Services Criteria rather than a required one. In ISO 27001 the ISMS requirements in clauses 4 through 10 drive the approach, and relevant reference controls are selected via the Statement of Applicability from Annex A. Satisfying continuity expectations under one framework does not automatically satisfy the other, so control counts, wording, and evidence differ by framework and version.
What evidence do auditors typically expect for information security continuity?
Expectations vary by auditor, certification body, and scope, but engagements commonly look for documented continuity arrangements that explicitly address security requirements, evidence that these arrangements were established and maintained, and records showing they were periodically verified or tested. For a SOC 2 Type II examination, evidence of operating effectiveness across the review period is typically needed, whereas a SOC 2 Type I focuses on suitability of design at a point in time.
How should information security continuity be reflected in the Statement of Applicability for ISO 27001?
Under ISO 27001, Annex A reference controls are selected and justified through the Statement of Applicability, informed by the risk assessment. Where continuity-related controls are determined to be applicable, the Statement of Applicability should record their inclusion and rationale; where excluded, it should justify the exclusion. Note that Annex A was restructured in the 2022 revision, so the specific control references and how continuity is expressed depend on the version in use.
How often should information security continuity arrangements be tested or reviewed?
There is no single mandated frequency; the appropriate cadence depends on scope, risk, and the expectations of the auditor or certification body. In most engagements, organizations establish a periodic verification or testing schedule and document the results, and align this with their broader review and continual improvement activities. The key point auditors typically assess is that verification occurs at a defined, risk-appropriate interval and is evidenced.

Common misconceptions

Information security continuity is the same as disaster recovery or business continuity planning.
While related, information security continuity focuses specifically on sustaining the required level of protection for information security controls during disruption, whereas business continuity and disaster recovery address the broader restoration of operations and services. They are complementary but not interchangeable.
Because information security continuity appears in ISO 27001 Annex A, it is mandatory for every certified organization.
Annex A controls are reference controls selected through risk assessment and documented in the Statement of Applicability. Applicability depends on the organization's identified risks and scope; the certifiable requirements themselves reside in clauses 4 through 10 of ISO/IEC 27001.
Meeting the SOC 2 Availability criterion demonstrates information security continuity under ISO 27001.
The SOC 2 Trust Services Criteria and ISO 27001 Annex A controls are distinct structures. Mapping between the two frameworks is possible but partial, and satisfying the Availability category in a SOC 2 examination does not automatically satisfy the corresponding ISO 27001 requirements, or vice versa.

Best practices

Determine the applicability of information security continuity through your risk assessment and document the decision and its rationale in the Statement of Applicability when working within an ISO/IEC 27001 ISMS.
Confirm which edition of ISO/IEC 27001 governs your engagement, since the control structure and designations differ between the 2013 and 2022 revisions, and align your documentation to that version.
Distinguish information security continuity arrangements from broader business continuity and disaster recovery plans, ensuring that security controls are explicitly addressed during disruption rather than assumed to be covered.
Periodically verify and test that continuity arrangements for security controls remain effective, and retain evidence of that verification for auditors or certification bodies as appropriate to scope.
When pursuing both SOC 2 and ISO 27001, map continuity-related requirements between the frameworks carefully, recognizing the mapping is partial and that meeting one framework does not automatically satisfy the other.
Define the scope of continuity arrangements clearly, and communicate that any SOC 2 report attests only to the controls and period covered while an ISO 27001 certificate covers only the defined ISMS scope.