BCP & Disaster Recovery Policy Template
A business continuity and disaster recovery framework: business impact analysis, RTO/RPO targets, recovery strategies, and test plans — aligned with ISO 27001 controls A.5.29–A.5.30.
In short
A BCP & DR policy sets out how an organisation keeps services running and recovers systems after major disruption, including recovery time objectives (RTO) and recovery point objectives (RPO). ISO 27001 controls A.5.29 and A.5.30 require information security during disruption and ICT readiness for business continuity.
- Format
- DOCX
- Size
- 17 KB
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
A recovery plan that has never been tested is essentially neatly typed hope. What separates organisations that recover in hours from those that take days is not document quality but whether the people involved have actually run it once.
This policy sets the frame: which processes are most critical, how quickly they must recover, who may declare a crisis, and when the plan gets tested. The RTO and RPO columns deliberately demand numbers rather than adjectives — 'as fast as possible' is not a testable target.
Most Useful For
- Organisations whose services cannot pause long without serious commercial impact
- Teams pursuing ISO 27001 who must satisfy ICT readiness controls
- Companies asked by clients or regulators to evidence a continuity plan
What's Inside
Scope & objectives
Processes and services covered, and the level of disruption that triggers plan activation.
Business impact analysis
A frame for identifying critical processes and the financial, operational, and reputational impact of their loss.
RTO & RPO
Recovery time and recovery point objectives per critical process, stated as numbers.
Crisis team roles
Who may activate the plan, who leads recovery, and who communicates externally.
Recovery strategy
Backup approach, alternate sites, and third-party dependencies that must recover alongside you.
Testing & maintenance
Test types, frequency, and how test findings feed back into the plan.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Control A.5.29 | Information security during disruption. |
| ISO/IEC 27001:2022 | Control A.5.30 | ICT readiness for business continuity. |
| ISO 22301 | BCMS | The business continuity management system informing the impact analysis and testing structure. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
How do BCP and DR differ?
BCP keeps business processes running — including manual workarounds while systems are down. DR restores the systems and their data. Organisations that prepare only DR often find systems back in four hours while the team has no idea what to do during those four hours.
How often should the plan be tested?
At least annually, and after any major change to critical systems or processes. A tabletop exercise is already far better than no testing; a full recovery test is ideal for the most critical systems.
How are realistic RTOs and RPOs set?
Derive them from the business impact analysis, not from current technical capability. First decide how long a process may stop before the impact becomes unacceptable, then compare that against what recovery can achieve today. The gap between the two is the investment management has to decide on.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
Policy, Procedure & Form Template Pack
A ready-to-use collection of information security policy, procedure, and form templates.
Free DownloadAI Usage Policy Template
A generative AI acceptable-use policy template for employees: permitted use, confidential data input restrictions, output review, and accountability — aligned with the direction of ISO/IEC 42001.
Free DownloadAcceptable Use Policy (AUP) Template
Ground rules for company devices, networks, email, and internet use — including prohibited activities, user responsibilities, and consequences, aligned with ISO 27001 control A.5.10.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.