Business Continuity
The capability of an organization to continue delivering products and services at acceptable levels following a disruptive incident. Business continuity planning prepares for the worst so operations survive it.
Why it matters
Disruptions happen: ransomware, data center outages, natural disasters, key personnel leaving. Organizations without continuity plans improvise under pressure, which extends downtime, multiplies losses, and erodes customer trust. NIS2 and DORA now mandate business continuity capabilities for critical and important entities. ISO 22301 provides the formal framework, and ISO 27001 Annex A explicitly includes continuity controls.
In practice
Business continuity planning involves identifying critical processes, defining recovery time and recovery point objectives, documenting procedures for operating in degraded mode, and testing those procedures regularly. In vucavoid, continuity requirements are tracked as part of your compliance baselines, linked to the assets and processes they protect. Control effectiveness reports verify that continuity measures are tested, not just documented.