Is there a business continuity (BC) management process in place?
A management process must be in place that defines the company’s overall BC framework. A detailed business impact analysis based on the BC plan should be drafted and tested and updated periodically. • Has the company implemented a security awareness program? Planning and documentation efforts should be accompanied by a proper IT security awareness program so that all employees receive training on information security requirements. • Was an internal audit conducted? An internal audit must be conducted to ensure compliance with the standard and adherence to the organization’s security policies and procedures. • Was a gap analysis conducted? Another important parameter to determine is the organization’s level of compliance with the 133 controls in the standard. A gap analysis helps organizations link appropriate controls with the relevant business unit and can take place during any stage of the compliance process. Many organizations conduct the gap analysis at the beginning of the complia