graphgrc

OPS-04: Business Continuity

Objective

Ensure business operations can continue during disruptions.

Description

Business continuity and disaster recovery plans are documented and tested. Critical systems have defined RTO and RPO. Failover procedures are tested. Alternative processing sites are available.

Implementation Details

BC/DR Plan: Written plan covering key scenarios (data center outage, natural disaster, cyber attack). Roles and responsibilities defined.

RTO/RPO Targets: Production database RTO 4 hours, RPO 1 hour. Application servers RTO 2 hours (auto-scaling).

AWS Multi-Region: Critical services can failover to alternate AWS region. Route53 health checks enable automatic failover.

Annual Testing: BC/DR plan tested annually via tabletop or live failover exercise. Plan updated based on findings.

Examples

Audit Evidence


Framework Mapping

SOC 2

GDPR


Referenced By

This section is automatically generated by make generate-backlinks. Do not edit manually.

Processes: