← Glossary·Risk

Business Continuity & Disaster Recovery (BC/DR)

Also known as: BCP · DRP
SOC 2ISO 27001HIPAA

Tested plans to maintain or restore operations after disruptive events; measured by RTO/RPO.

Business Continuity Planning (BCP) addresses how the business continues operating during a disruption; Disaster Recovery (DR) addresses the technical recovery of systems and data. Recovery Time Objective (RTO) and Recovery Point Objective (RPO) are the operative metrics.

Why it matters
Untested BC/DR is the single most common ISO 27001 A.5.30 finding. Annual restoration tests from offsite backups are the minimum credible evidence.

Related terms

Incident Response (IR)
Documented, tested process for detecting, containing, eradicating, and recovering from security incidents.
RTO / RPO
RTO = time to restore service after disruption. RPO = max acceptable data loss measured in time.

Does your program actually cover Business Continuity & Disaster Recovery (BC/DR)?

Run a free ComplianceIQ audit against SOC 2 and we'll surface every gap on this — and the other controls auditors flag — with the exact clause references to fix.

Free SOC 2 auditBack to glossary