simpl.
Cybersecurity GRC 15 items

Business Continuity & Disaster Recovery Audit

Audits business continuity and disaster recovery capability including impact analysis, plans, recovery objectives, and testing.

ISO 22301ISO 27001:2022SOC 2

Free PDF · enter your email to download.

Business Impact Analysis

  • Is a Business Impact Analysis (BIA) performed to identify critical processes? *
  • Are Recovery Time Objectives (RTOs) defined for critical systems? *
  • Are Recovery Point Objectives (RPOs) defined for critical data? *
  • What is the RTO in hours for the most critical system?

Continuity & Recovery Plans

  • Is a documented business continuity plan (BCP) maintained and approved? *
  • Is a disaster recovery plan (DRP) documented for IT systems and infrastructure? *
  • Are roles, responsibilities, and activation criteria defined in the plans? *
  • Are alternate processing sites or cloud failover capabilities established? *

Backup & Redundancy

  • Are backups performed on a schedule aligned with the RPO? *
  • Are backups stored offsite or in a geographically separate region? *
  • Are backup restorations tested to confirm recoverability? *

Testing & Maintenance

  • Is the DR plan tested at least annually? *
  • Are test results documented with identified gaps and corrective actions? *
  • Are the BCP and DRP reviewed and updated after significant changes? *
  • When was the last full DR test conducted?

Download the full Business Continuity & Disaster Recovery Audit checklist

Get it as a clean, printable PDF — free.