ISO/IEC 27001:2022 Annex A · Control 5.29
Information Security During Disruption: A Practical Implementation Guide
Maintain essential security protections when normal operations, staffing or technology are disrupted.
This control ensures that information security remains at an appropriate level during business disruption.
What should the control achieve?
- Security requirements are included in continuity plans.
- Degraded-mode risks and compensating controls are defined.
- Emergency access and alternative processes are controlled.
- Normal security is restored and reviewed after disruption.
Step-by-step implementation
Identify essential security objectives
For critical services define minimum confidentiality, integrity, authentication, logging and monitoring.
Analyze disruption modes
Consider unavailable identity, network, facilities, staff, suppliers and security tools.
Design secure workarounds
Approve alternatives, limits, owners, expiry and evidence.
Control emergency access
Use time limitation, strong logging and retrospective review.
Exercise security under disruption
Test more than availability; include cyber attack and control failure.
Return to normal
Revoke temporary access, reconcile transactions and review residual risk.
What this could look like in practice
If the identity platform is unavailable, a hospital uses sealed emergency accounts for critical systems. Use generates alerts and logs; accounts are reconciled and credentials rotated after recovery.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Continuity design | Minimum security requirements are documented per critical service. | Continuity plan |
| Emergency operation | Temporary access and manual approvals are logged. | Emergency record |
| Recovery | Temporary measures are removed and data reconciled. | Restoration checklist |
Implementation evidence
- Security continuity requirements
- Degraded-mode procedures
- Emergency account register
- Alternative communication plan
- Exercise results
- Temporary exception logs
- Recovery reconciliation
- Post-disruption review
Useful metrics
- Critical plans with security requirements
- Emergency actions reviewed
- Temporary access removed on time
- Exercise security findings closed
Common mistakes
- Focusing only on uptime.
- Using uncontrolled personal tools during disruption.
- Leaving emergency access active.
- Losing logs during failover.
- Not testing supplier or staff unavailability.
Questions an auditor may ask
- Which security controls must operate during disruption?
- Show a secure workaround.
- How is emergency access controlled?
- How is normal security restored?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.