Article 11
|
An organization shall establish a business continuity plan to ensure the minimum acceptable service level can be achieved within the recovery time objective (RTO) in the event of a disaster. It shall include but not limited to:
- Activation conditions.
- Description of participants and their responsibilities.
- To establish a business continuity management team or business continuity management commission.
- To review and determine the human resources for operation and support required for recovery of the core business.
- To appoint the person responsible for core system recovery and their agent.
- Emergency response procedures and emergency reporting procedures
- Recovery procedures and on-site and remote system recovery procedures for the core business (such as backup and recovery plans for computer equipment, communication equipment, power system, database, and computer operation system).
- Frequency of maintenance work for business continuity plan.
- Rules for trainings on business continuity.
- Response planning and appropriateness of contract with external entity.
|