ISO/IEC 27031:2011
Information technology — Security techniques — Guidelines for information and communication technology readiness for business continuity
Information technology — Security techniques — Guidelines for information and communication technology readiness for business continuity
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 36
- Дата публикации:
- 1 марта 2011 г.
- Издание:
- ISO/IEC IS 27031 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 27031:2011 describes the concepts and principles of information and comunication technology (ICT) readiness for business continuity, and provides a framework of methods and processes to identify and specify all aspects (such as performance criteria, design, and implementation) for improving an organization's ICT readiness to ensure business continuity. It applies to any organization (private, governmental, and non-governmental, irrespective of size) developing its ICT readiness for business continuity program (IRBC), and requiring its ICT services/infrastructures to be ready to support business operations in the event of emerging events and incidents, and related disruptions, that could affect continuity (including security) of critical business functions. It also enables an organization to measure performance parameters that correlate to its IRBC in a consistent and recognized manner. The scope of ISO/IEC 27031:2011 encompasses all events and incidents (including security related) that could have an impact on ICT infrastructure and systems. It includes and extends the practices of information security incident handling and management and ICT readiness planning and services.
Abstract
Overview - ISO/IEC 27031:2011 and ICT readiness for business continuity
ISO/IEC 27031:2011 provides guidelines for information and communication technology (ICT) readiness for business continuity (IRBC). It defines concepts, principles and a practical framework to identify, specify and improve ICT services and infrastructures so they can support critical business functions during disruptions. The standard applies to any organization - private, governmental or non‑governmental, regardless of size - that needs its ICT to be ready to respond to incidents, including security-related events.
Keywords: ISO/IEC 27031:2011, ICT readiness, IRBC, business continuity, ICT disaster recovery, resilience.
Key topics and technical requirements
ISO/IEC 27031:2011 covers the lifecycle of ICT readiness using a management-system approach (Plan‑Do‑Check‑Act). Core technical topics include:
- IRBC principles and elements - concepts that link ICT readiness with overall Business Continuity Management (BCM).
- Planning - defining ICT requirements, understanding critical ICT services, identifying gaps, and selecting IRBC strategy options.
- Performance criteria - specifying measurable ICT readiness performance parameters (qualitative and quantitative).
- Implementation and operation - people, facilities, technology, data, processes and supplier arrangements needed to deliver IRBC.
- Incident response and recovery - preparing ICT response and recovery plans, documentation and procedures.
- Awareness, competence and training - roles, responsibilities and skill sets for IRBC teams.
- Monitor, test and review - monitoring threats, testing and exercising plans, internal audit and management review to measure ICT readiness.
- Continual improvement - corrective and preventive actions to improve IRBC capability.
The standard emphasizes management responsibility, documentation control and consistent measurement of readiness against agreed criteria.
Practical applications - who uses this standard
ISO/IEC 27031 is practical for organizations that depend on ICT continuity to deliver critical services. Typical users include:
- IT managers, CIOs and infrastructure teams implementing ICT continuity and disaster recovery.
- Business continuity managers and BCMS designers integrating ICT readiness with ISO 22301.
- Information security professionals aligning IRBC with ISMS requirements (ISO/IEC 27001).
- Third‑party service providers and suppliers delivering outsourced ICT continuity or recovery services.
- Auditors and regulators assessing ICT resilience and preparedness.
Benefits include clearer ICT recovery objectives, measurable readiness metrics, improved resilience and better alignment between ICT and business continuity plans.
Related standards
- ISO/IEC 27001 - Information security management systems (ISMS)
- ISO 22301 - Business Continuity Management Systems (BCMS)
- ISO/IEC 24762:2008 - ICT disaster recovery services
Use ISO/IEC 27031:2011 to create a structured, measurable IRBC program that integrates ICT resilience into broader business continuity and information security efforts.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27031:2011
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS EN ISO 22313:2020
ДействующийSecurity and resilience. Business continuity management systems. Guidance on the use of ISO 22301.
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…