Sharing without diluting
What can be shared
| Element | Shareable | Note |
|---|---|---|
| Context analysis (4.1) | Yes | One analysis, two readings |
| Interested parties (4.2) | Yes | Common register |
| Scope (4.3) | Partially | Scopes may differ; they must then be explicitly compared |
| Policy (5.2) | Yes | Integrated policy, or two policies referring to a common base |
| Roles (5.3) | Yes | A single responsibility matrix |
| Competence and documentation (7.2, 7.5) | Yes | A single documentation system |
| Risk assessment | No | The objects differ: information risk versus disruption risk |
| Internal audit (9.2) | Yes | One programme, auditors trained on both standards |
| Management review (9.3) | Yes | A single review, with inputs from both systems |
| Improvement (10) | Yes | A single nonconformity register |
The typical gain is around a third of the documentation effort and close to half the audit time, since a certification body can run a combined audit.
A.5.29 and A.5.30: the junction
The 2022 edition of ISO/IEC 27001 introduced two controls that anchor continuity in the security system:
- A.5.29 — Information security during disruption. It requires maintaining an appropriate level of security during the crisis. That is the opposite of common practice, which is to disable controls to move faster.
- A.5.30 — ICT readiness for business continuity. It requires systems to be designed to support continuity objectives.
These controls do not duplicate ISO 22301: they require that security does not vanish at the moment it is most exposed.
The three grey zones to close
Zone 1 — Who triggers what? Does a security incident automatically become a continuity incident? The rule to write: any confirmed compromise of a system supporting a prioritised activity triggers both arrangements simultaneously.
Zone 2 — Who decides to stop the service? The SOC wants to isolate, the business wants to continue. The decision belongs to the crisis team, on the SOC's recommendation, against a threshold defined in advance.
Zone 3 — Who owns the backup? Technically infrastructure, functionally continuity, protection-wise security. With no single designated owner, isolation of the administration domain is never addressed: everybody assumes it belongs to somebody else.
Closing those three zones takes one page, inserted into both management systems. It is probably the best value-for-effort document in the whole arrangement.
Key takeaways
- Clauses 4, 5, 7, 9 and 10 can be shared
- A.5.29 covers security during disruption, not continuity
- Grey zones are closed by a single escalation rule