Skip to content
arrow_back
search
Annex A 5.29 verified ISO/IEC 27001:2022

Maintain information security during disruptions

Plan to keep information secure even when normal operations are interrupted.

record_voice_over

Plain language

Imagine your business hits a snag, like a power outage or a cyber attack. This control is about making sure your important information stays safe and sound during such disruptions. If you don't plan for these hiccups, you could lose data or leak confidential information, which can harm your reputation and cost you money.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

The organization shall plan how to maintain information security at an appropriate level during disruption.
verified ISO/IEC 27001:2022 Annex A 5.29
priority_high

Why it matters

During disruptions, weakened controls and ad‑hoc workarounds can expose data, enable unauthorised access, and cause compliance and reputational damage.

settings

Operational notes

Regularly test disruption scenarios (DR, outages) to ensure access controls, backups, logging, and secure comms remain effective; brief staff on secure workarounds.

Mapping detail

Mapping

Direction

Controls