Lesson14 min

Sharing without diluting

What can be shared

ElementShareableNote
Context analysis (4.1)YesOne analysis, two readings
Interested parties (4.2)YesCommon register
Scope (4.3)PartiallyScopes may differ; they must then be explicitly compared
Policy (5.2)YesIntegrated policy, or two policies referring to a common base
Roles (5.3)YesA single responsibility matrix
Competence and documentation (7.2, 7.5)YesA single documentation system
Risk assessmentNoThe objects differ: information risk versus disruption risk
Internal audit (9.2)YesOne programme, auditors trained on both standards
Management review (9.3)YesA single review, with inputs from both systems
Improvement (10)YesA single nonconformity register

The typical gain is around a third of the documentation effort and close to half the audit time, since a certification body can run a combined audit.

A.5.29 and A.5.30: the junction

The 2022 edition of ISO/IEC 27001 introduced two controls that anchor continuity in the security system:

  • A.5.29 — Information security during disruption. It requires maintaining an appropriate level of security during the crisis. That is the opposite of common practice, which is to disable controls to move faster.
  • A.5.30 — ICT readiness for business continuity. It requires systems to be designed to support continuity objectives.

These controls do not duplicate ISO 22301: they require that security does not vanish at the moment it is most exposed.

The three grey zones to close

Zone 1 — Who triggers what? Does a security incident automatically become a continuity incident? The rule to write: any confirmed compromise of a system supporting a prioritised activity triggers both arrangements simultaneously.

Zone 2 — Who decides to stop the service? The SOC wants to isolate, the business wants to continue. The decision belongs to the crisis team, on the SOC's recommendation, against a threshold defined in advance.

Zone 3 — Who owns the backup? Technically infrastructure, functionally continuity, protection-wise security. With no single designated owner, isolation of the administration domain is never addressed: everybody assumes it belongs to somebody else.

Closing those three zones takes one page, inserted into both management systems. It is probably the best value-for-effort document in the whole arrangement.

Key takeaways

  • Clauses 4, 5, 7, 9 and 10 can be shared
  • A.5.29 covers security during disruption, not continuity
  • Grey zones are closed by a single escalation rule