3.8 Baseline for Security – Disaster Recovery Plan

Needed capacities or functions - Disaster Recovery Plan

  1. Have a Disaster Recovery Plan ("DRP") that outlines mission-critical procedures, roles, and responsibilities of key staff during a significant system loss or emergency (e.g., data loss, natural disasters, power outages, server failure, ransomware, etc.) to ensure that the organization can continue its essential operations after a disruptive event. This plan should be reviewed annually and periodically tested. 

Important Considerations and Best Practices 

Disaster recovery planning is critical for preparing an organization in the event of an unexpected disruption or emergency, minimizing periods of downtime that can negatively impact clients, and helping recover systems and data in a timely and efficient manner.  

A DRP can also help organizations comply with regulatory requirements, such as data protection laws and business continuity standards. As best practice, a well-designed DRP would include procedures for returning to routine services once the emergency has ended.