Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.29

Information Security During Disruption: A Practical Implementation Guide

Maintain essential security protections when normal operations, staffing or technology are disrupted.

This control ensures that information security remains at an appropriate level during business disruption.

Practical interpretation: Emergency operation often introduces shortcuts, alternative tools and elevated access. Continuity plans must preserve critical security objectives, not only service availability.

What should the control achieve?

  • Security requirements are included in continuity plans.
  • Degraded-mode risks and compensating controls are defined.
  • Emergency access and alternative processes are controlled.
  • Normal security is restored and reviewed after disruption.

Step-by-step implementation

1

Identify essential security objectives

For critical services define minimum confidentiality, integrity, authentication, logging and monitoring.

2

Analyze disruption modes

Consider unavailable identity, network, facilities, staff, suppliers and security tools.

3

Design secure workarounds

Approve alternatives, limits, owners, expiry and evidence.

4

Control emergency access

Use time limitation, strong logging and retrospective review.

5

Exercise security under disruption

Test more than availability; include cyber attack and control failure.

6

Return to normal

Revoke temporary access, reconcile transactions and review residual risk.

What this could look like in practice

If the identity platform is unavailable, a hospital uses sealed emergency accounts for critical systems. Use generates alerts and logs; accounts are reconciled and credentials rotated after recovery.

ActivityPractical implementationEvidence
Continuity designMinimum security requirements are documented per critical service.Continuity plan
Emergency operationTemporary access and manual approvals are logged.Emergency record
RecoveryTemporary measures are removed and data reconciled.Restoration checklist

Implementation evidence

  • Security continuity requirements
  • Degraded-mode procedures
  • Emergency account register
  • Alternative communication plan
  • Exercise results
  • Temporary exception logs
  • Recovery reconciliation
  • Post-disruption review

Useful metrics

  • Critical plans with security requirements
  • Emergency actions reviewed
  • Temporary access removed on time
  • Exercise security findings closed

Common mistakes

  • Focusing only on uptime.
  • Using uncontrolled personal tools during disruption.
  • Leaving emergency access active.
  • Losing logs during failover.
  • Not testing supplier or staff unavailability.

Questions an auditor may ask

  • Which security controls must operate during disruption?
  • Show a secure workaround.
  • How is emergency access controlled?
  • How is normal security restored?
Implementation test: Exercise a critical service when identity and normal communications are unavailable and verify security remains acceptable.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.