Annex A.5.30: ICT readiness for business continuity
The new 27001:2022 control that tripped half the certified companies. What it really takes to clear it.
Tag
10 articles
The new 27001:2022 control that tripped half the certified companies. What it really takes to clear it.
Three things: a DR plan, evidence of drills, change tracking. Everything else is garnish.
BIA usually means endless Excel sheets. Here is a lightweight format that produces useful results in four hours.
AgID, qualifications, ISO 27001 / 27017 / 27018: the updated 2026 map of what is needed to bid in Italian public tenders.
The Annex A controls that directly involve DR and continuity: A.5.30, A.8.13, A.8.14. What auditors actually ask for.
Fourteen questions to ask a cloud provider during selection. Which answers are acceptable, which should stop the deal.
Typical cost (€15-35k year one), concrete sales upside and the two verticals where you cannot bid without certification.
ISO 27001 is the framework. 27017 and 27018 are cloud-specific extensions. Which certification stack you actually need to bid for public-sector contracts.
A four-page business continuity policy that passes ISO 27001 audit without questions. Markdown, fully editable.
A blended qualitative-quantitative method that yields a usable risk-impact matrix in four hours — not another PDF to file away.