ISO 27001A.5 — Information security during disruption
A.5.29
Information security during disruption
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Plan information security continuity so security is maintained at an appropriate level during disruption.
Points of focus
- Security needs during disruption identified
- Continuity plans include security roles
- Emergency access procedures controlled
- Plans tested with security scenarios
Implementation notes
Define which controls must stay up in degraded mode (auth, logging, admin access). Pre-stage emergency accounts with monitoring. Ensure DR environments are not security orphans. Link to A.5.30 ICT readiness and A.5.26 incident response. After tests, fix gaps where failover weakened controls.
Audit tip: Show emergency access rules and a test where failover kept MFA/logging intact.
Evidence auditors typically request:
- BC/IR continuity plan sections on security
- Emergency access / break-glass procedures
- Tabletop including degraded-mode security
- Contact trees for security owners in crisis
Common gaps
- Break-glass used without logging in crises
- Security staff unavailable in BC roster
- Failover environments with weaker auth
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.29 | This control |
| SOC 2 | CC7.5 | Related Trust Services Criteria themes — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.29)
Frequently Asked Questions
Both. A.5.29 focuses on keeping information security adequate while the business operates through disruption.
Include identity, DNS, and logging dependencies in continuity planning — not only app servers.
A.5.30 emphasises ICT continuity readiness/testing; A.5.29 emphasises security posture during disruption.