Skip to content

Disaster Recovery

What is Disaster Recovery?

The process of restoring IT systems and data after a catastrophic event. Typically governed by a Disaster Recovery Plan (DRP) with defined RTOs and RPOs.

Risk Management

What the standards actually require on disaster recovery

Requirements naming disaster recovery across 6 standards, quoted from the control text.

Address business continuity and disaster recovery planning and resources within the program, including regular periodic testing and review of those capabilities and the controls described in the recovery paragraphs of the section.

CFTC-SS-22 · Business Continuity and Disaster Recovery Planning Category

Agencies must establish disaster recovery procedures and infrastructure to restore critical systems within defined timeframes.

IM8-RES.2 · Disaster Recovery

Disaster recovery procedures. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.

FFIEC-12 · Disaster recovery procedures

Establish procedures to restore lost data and resume operations. NIST recommends documented recovery procedures, alternate site arrangements, and aligned dependencies.

164.308(a)(7)(ii)(B) · Disaster Recovery Plan (Required)
ISMAP (Japan)2 controls

ISMAP Personnel + Resilience + Supply Chain controls extend security beyond own perimeter. (1) Personnel Security and Background Checks: per ISMAP requirements + tiered background checks for personnel with access to customer data + (a) Standard CSP employees -...

ISMAP-Personnel-BackgroundChecks-Resilience-BCP-DR-SupplyChain-ThirdParty-Subcontractor-FlowDown · ISMAP Personnel Security + Background Checks + Business Continuity + Disaster Recovery + Resilience + Supply Chain Risk Management + Third Party + Subcontractor Flow-Down + Japanese Sovereignty

Questions people ask about disaster recovery

What is Disaster Recovery?
The process of restoring IT systems and data after a catastrophic event. Typically governed by a Disaster Recovery Plan (DRP) with defined RTOs and RPOs.
Why is Disaster Recovery important for compliance?
Disaster Recovery is a key concept in Risk Management. Understanding disaster recovery helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Disaster Recovery?
Key concepts related to Disaster Recovery include Business Continuity, RTO (Recovery Time Objective), RPO (Recovery Point Objective). Understanding these interconnected concepts provides a more comprehensive view of Risk Management requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Disaster Recovery?
Disaster Recovery appears in the requirement text of CFTC System Safeguards (17 CFR 37, 38, 39, 49), Singapore Government Instruction Manual on ICT&SS Management (IM8), FFIEC IT Examination Handbook, HIPAA Security Rule, ISMAP (Japan). Across these standards we have identified 22 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Disaster Recovery?
Explore our compliance framework pages to see how disaster recovery applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Disaster Recovery applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.