This standard is a subset of ISO 22301. It focuses purely on the digital, technical, and data components required to keep the business running.
Write step-by-step ICT disaster recovery plans (DRPs). Define who has the authority to declare a disaster and trigger a system failover. 3. Check (Monitor and Review)
The official document (currently the 2011 edition, as ISO 27031 has not been revised as frequently as 27001) includes:
Establishing clear, documented procedures for failover and recovery.
The most critical step is integrating ICT plans into the wider Business Continuity Management System (BCMS). If the Business Continuity Plan says "Employees will work from home," the ICT Readiness Plan must ensure the VPN and server capacity can handle 100% remote workforce—a lesson widely learned during the COVID-19 pandemic.
Detail every software, hardware, and network asset. Map these assets to critical business functions to determine their individual RTOs and RPOs.
To comply with ISO 27031, an organization must address six main categories: Skills and Knowledge