Cybersecurity GRC 15 items
Business Continuity & Disaster Recovery Audit
Audits business continuity and disaster recovery capability including impact analysis, plans, recovery objectives, and testing.
ISO 22301ISO 27001:2022SOC 2
Free PDF · enter your email to download.
Business Impact Analysis
- Is a Business Impact Analysis (BIA) performed to identify critical processes? *
- Are Recovery Time Objectives (RTOs) defined for critical systems? *
- Are Recovery Point Objectives (RPOs) defined for critical data? *
- What is the RTO in hours for the most critical system?
Continuity & Recovery Plans
- Is a documented business continuity plan (BCP) maintained and approved? *
- Is a disaster recovery plan (DRP) documented for IT systems and infrastructure? *
- Are roles, responsibilities, and activation criteria defined in the plans? *
- Are alternate processing sites or cloud failover capabilities established? *
Backup & Redundancy
- Are backups performed on a schedule aligned with the RPO? *
- Are backups stored offsite or in a geographically separate region? *
- Are backup restorations tested to confirm recoverability? *
Testing & Maintenance
- Is the DR plan tested at least annually? *
- Are test results documented with identified gaps and corrective actions? *
- Are the BCP and DRP reviewed and updated after significant changes? *
- When was the last full DR test conducted?
Download the full Business Continuity & Disaster Recovery Audit checklist
Get it as a clean, printable PDF — free.
