Skip to content

Disaster Recovery Plan

What is Disaster Recovery Plan?

A documented set of policies and procedures designed to enable the recovery or continuation of vital technology infrastructure and systems following a natural or human-induced disaster.

Information Security

Each of these is named in at least one of the same controls as disaster recovery plan. The number is how many controls name both.

What the standards actually require on disaster recovery plan

Requirements naming disaster recovery plan across 6 standards, quoted from the control text.

Maintain a business continuity and disaster recovery plan, emergency procedures, backup facilities and physical, technological and personnel resources sufficient to enable timely recovery and resumption of operations and of the ongoing fulfilment of the regist...

CFTC-SS-8 · Business Continuity and Disaster Recovery Plan and Resources

Establish procedures to restore lost data and resume operations. NIST recommends documented recovery procedures, alternate site arrangements, and aligned dependencies.

164.308(a)(7)(ii)(B) · Disaster Recovery Plan (Required)

Establish procedures to restore lost data and resume operations. NIST recommends documented recovery procedures, alternate site arrangements, and aligned dependencies.

164.308(a)(7)(ii)(B) · Disaster Recovery Plan (Required)

Business continuity and disaster recovery plans which are tested, including for the scenario of a complete loss of computing capabilities.

ASD37-35 · Business continuity and disaster recovery plans (Very Good)

Agencies must conduct regular testing of business continuity and disaster recovery plans to ensure effectiveness.

IM8-RES.4 · Resilience Testing

The CISO contributes to the development, implementation and maintenance of business continuity and disaster recovery plans for their organisation to ensure that business-critical services are supported appropriately in the event of a disaster.

ISM-0734 · The CISO contributes to the development, implementation and maintenance of business contin

Questions people ask about disaster recovery plan

What is Disaster Recovery Plan?
A documented set of policies and procedures designed to enable the recovery or continuation of vital technology infrastructure and systems following a natural or human-induced disaster.
Why is Disaster Recovery Plan important for compliance?
Disaster Recovery Plan is a key concept in Information Security. Understanding disaster recovery plan helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Disaster Recovery Plan?
Disaster Recovery Plan appears in the requirement text of CFTC System Safeguards (17 CFR 37, 38, 39, 49), HIPAA Security Rule, NIST SP 800-66 Rev 2, ASD Strategies to Mitigate Cyber Security Incidents, Singapore Government Instruction Manual on ICT&SS Management (IM8). Across these standards we have identified 15 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Disaster Recovery Plan?
Explore our compliance framework pages to see how disaster recovery plan applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Disaster Recovery Plan applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.