Policies, Procedures & FormsFree

BCP & Disaster Recovery Policy Template

A business continuity and disaster recovery framework: business impact analysis, RTO/RPO targets, recovery strategies, and test plans — aligned with ISO 27001 controls A.5.29–A.5.30.

In short

A BCP & DR policy sets out how an organisation keeps services running and recovers systems after major disruption, including recovery time objectives (RTO) and recovery point objectives (RPO). ISO 27001 controls A.5.29 and A.5.30 require information security during disruption and ICT readiness for business continuity.

Format
DOCX
Size
17 KB
Price
Free

Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.

What This Document Is For

A recovery plan that has never been tested is essentially neatly typed hope. What separates organisations that recover in hours from those that take days is not document quality but whether the people involved have actually run it once.

This policy sets the frame: which processes are most critical, how quickly they must recover, who may declare a crisis, and when the plan gets tested. The RTO and RPO columns deliberately demand numbers rather than adjectives — 'as fast as possible' is not a testable target.

Most Useful For

  • Organisations whose services cannot pause long without serious commercial impact
  • Teams pursuing ISO 27001 who must satisfy ICT readiness controls
  • Companies asked by clients or regulators to evidence a continuity plan

What's Inside

01

Scope & objectives

Processes and services covered, and the level of disruption that triggers plan activation.

02

Business impact analysis

A frame for identifying critical processes and the financial, operational, and reputational impact of their loss.

03

RTO & RPO

Recovery time and recovery point objectives per critical process, stated as numbers.

04

Crisis team roles

Who may activate the plan, who leads recovery, and who communicates externally.

05

Recovery strategy

Backup approach, alternate sites, and third-party dependencies that must recover alongside you.

06

Testing & maintenance

Test types, frequency, and how test findings feed back into the plan.

Standards & Regulations It Helps Satisfy

Standard / RegulationClause / ArticleWhat this document covers
ISO/IEC 27001:2022Control A.5.29Information security during disruption.
ISO/IEC 27001:2022Control A.5.30ICT readiness for business continuity.
ISO 22301BCMSThe business continuity management system informing the impact analysis and testing structure.

This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.

Questions About This Document

How do BCP and DR differ?

BCP keeps business processes running — including manual workarounds while systems are down. DR restores the systems and their data. Organisations that prepare only DR often find systems back in four hours while the team has no idea what to do during those four hours.

How often should the plan be tested?

At least annually, and after any major change to critical systems or processes. A tabletop exercise is already far better than no testing; a full recovery test is ideal for the most critical systems.

How are realistic RTOs and RPOs set?

Derive them from the business impact analysis, not from current technical capability. First decide how long a process may stop before the impact becomes unacceptable, then compare that against what recovery can achieve today. The gap between the two is the investment management has to decide on.

Related Reading

Background that helps you fill this document in correctly, rather than merely filling it in.

Need guidance, not just a template?

A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.