Plan, implement, maintain and test ICT readiness to ensure information availability during disruption.
Also written as A5.30, Annex A 5.30, ISO 27001:2022 A.5.30, ISO27001 A.5.30.
ICT readiness for business continuity is one of 37 Organisational Controls in ISO/IEC 27001:2022 Annex A. Plan, implement, maintain and test ICT readiness to ensure information availability during disruption. Organisational controls are judged on governance rather than tooling: an auditor wants a named owner, an approval trail, and evidence the control is exercised on a defined cadence rather than written once and filed.
When preparing your Statement of Applicability (SoA) for A.5.30, gather artefacts such as:
What actually gets raised against A.5.30, in rough order of how often it comes up:
A.5.30 is new in ISO 27001:2022. Cloud-hosted organisations sometimes argue the provider handles it — that is only partly true. Provider redundancy covers infrastructure failure; it does not cover your own misconfiguration, ransomware, or account loss, and the exit and recovery responsibility for your data remains yours.
If you run more than one framework, the same evidence usually satisfies all of them. A.5.30 aligns with:
SOC 2: CC9.1 Business disruption risk mitigation, A1.2 Environmental protections, backup and recovery infrastructure, A1.3 Recovery plan testing
NIST CSF 2.0: PR.IR-03 Resilience mechanisms, PR.IR-04 Adequate resource capacity, RC.RP-01 Recovery plan execution
A.5.30 is a new control introduced in the 2022 revision with no direct 2013 equivalent. Treat it as a fresh requirement when transitioning from ISO 27001:2013.
See all 37 Organisational Controls →
Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.5.30 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.
In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.
ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.
A.5.30 aligns with SOC 2 CC9.1, A1.2, A1.3 and NIST CSF PR.IR-03, PR.IR-04, RC.RP-01. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.
Yes. A.5.30 is one of the 11 controls introduced in the 2022 revision and has no direct ISO 27001:2013 equivalent, so a transitioning ISMS has no prior evidence to re-point and should treat it as a fresh implementation.
RTO and RPO stated in the plan but never tested, so nobody knows whether they are achievable. Backup verification presented as recovery testing.