Business Continuity for IT
Business continuity for IT is the planning and preparation that keeps critical technology services running, or recovers them quickly, during disruptive events like outages, disasters, or cyberattacks. It connects recovery objectives to organizational priorities and tests that the plans actually work.
itPlatform engineering and SRE | OpenSkills.info
Intro
Business Continuity for IT
Business continuity keeps essential work running through a disruption. For an IT team, that means understanding which business activities depend on technology, how long those activities can tolerate interruption, and what recovery the organization can afford.
The plan does not begin with servers. It begins with business outcomes. Payroll may need identity, banking connectivity, employee data, and a working approval path. An online store may need more than its website. Orders can also depend on payment, inventory, fulfillment, customer support, and third-party services.
This dependency view changes the question. You stop asking, “How quickly can we restore every system?” You ask, “Which services support essential work, in what order, and to what usable level?”
Continuity and recovery are related, not identical
A business continuity plan describes how the organization sustains essential functions during and after a disruption. It includes people, facilities, suppliers, communications, records, manual workarounds, and technology.
An IT disaster recovery plan describes how the organization restores technology services, applications, infrastructure, and data. Ready.gov advises developing this plan with the business continuity plan. Technology recovery must meet the needs of business recovery.
An information system contingency plan narrows the scope further. It provides procedures for recovering one system or a related set of systems. NIST uses this form to connect system recovery with broader continuity and emergency plans.
Incident response also has a different job. It contains and manages an incident. Continuity sustains essential work, while recovery restores affected capabilities. One event can activate all three disciplines, so their roles and handoffs must agree.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-34r1.pdf
Supports
- Relationship among business continuity, disaster recovery, incident response, and information system contingency plans
- Seven-step contingency planning process
- Business impact analysis, maximum tolerable downtime, recovery time objective, and recovery point objective
- Dependency-aware recovery priorities and recovery strategy tradeoffs
- Preventive controls, backups, alternate processing, alternate sites, and recovery capabilities
- Activation and notification, recovery, and reconstitution phases
- Plan roles, contacts, procedures, storage, testing, exercises, and maintenance
- Quiz answers concerning impact analysis, objectives, dependencies, restore evidence, and reconstitution
- https://csrc.nist.gov/topics/security-and-privacy/security-programs-and-operations/contingency-planning
Supports
- Contingency planning as coordinated procedures and technical measures for recovering systems, operations, and data
- Alternate equipment, alternate processing, and alternate locations as recovery approaches
- Link rationale for the NIST contingency planning topic
- https://www.ready.gov/business/emergency-plans
Supports
- Business continuity, crisis communications, emergency response, and IT disaster recovery as related preparedness concerns
- IT disaster recovery planning developed with the business continuity plan
- Technology recovery timed to business recovery needs
- Quiz answer distinguishing IT disaster recovery from broader business continuity
- Link rationale for the Ready.gov overview
- https://www.ready.gov/sites/default/files/2020-03/business-continuity-plan.pdf
Supports
- Business continuity plan sections for BIA results, recovery objectives, continuity strategies, and IT restoration
- Link rationale for applying course concepts to an official template
- https://csrc.nist.gov/pubs/sp/800/84/final
Supports
- Training personnel, exercising IT plans, and testing IT systems as distinct readiness activities
- Design, conduct, and evaluation of tabletop and functional exercises
- Using events to identify deficiencies and improve readiness
- Quiz answers concerning tabletop scope, restore evidence, and corrective action
- Link rationale for advancing from planning to exercises and tests
- https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience
Supports
- Availability of CISA tabletop packages for cyber, physical, and cyber-physical scenarios
- Package documentation for exercise planner, facilitator, evaluator, and participant roles
- Link rationale for extended exercise practice
- https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
Supports
- CSF 2.0 as organization-wide guidance for managing cybersecurity risk
- High-level outcomes for governance, communication, response, and recovery
- Link rationale connecting continuity work to cybersecurity risk management
