Skip to content
compliancebase
ISO 27001A.5 — Information security during disruption

A.5.29

Information security during disruption

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Plan information security continuity so security is maintained at an appropriate level during disruption.

Points of focus

  • Security needs during disruption identified
  • Continuity plans include security roles
  • Emergency access procedures controlled
  • Plans tested with security scenarios

Implementation notes

Define which controls must stay up in degraded mode (auth, logging, admin access). Pre-stage emergency accounts with monitoring. Ensure DR environments are not security orphans. Link to A.5.30 ICT readiness and A.5.26 incident response. After tests, fix gaps where failover weakened controls.

Audit tip: Show emergency access rules and a test where failover kept MFA/logging intact.

Evidence auditors typically request:

  • BC/IR continuity plan sections on security
  • Emergency access / break-glass procedures
  • Tabletop including degraded-mode security
  • Contact trees for security owners in crisis

Common gaps

  • Break-glass used without logging in crises
  • Security staff unavailable in BC roster
  • Failover environments with weaker auth

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.29This control
SOC 2CC7.5Related Trust Services Criteria themes — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Both. A.5.29 focuses on keeping information security adequate while the business operates through disruption.

Include identity, DNS, and logging dependencies in continuity planning — not only app servers.

A.5.30 emphasises ICT continuity readiness/testing; A.5.29 emphasises security posture during disruption.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above