Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.5.29 Information Security During Disruption

Control Objective

The organisation shall plan how to maintain information security at an appropriate level during disruption.

Policy Statement

anDREa ensures that information security controls and data protection standards remain effective during operational disruptions or adverse situations. Resilience architectures, failover procedures, and security configurations are formally documented and executed via the Disaster Recovery Plan.


Business Continuity and Security Resilience

The DRP establishes the operational framework required to safeguard the myDRE platform and organizational assets during an outage or crisis:

  • Response Structure: Activation of a dedicated Incident Response Team with clearly assigned roles and emergency decision-making authority.
  • Operational Continuity: Procedures designed to maintain security baselines (e.g., access control, encryption) even when operating under degraded or alternative states.
  • Resource Recovery: Prioritization, risk analysis, and structured restoration timelines for all critical infrastructure resources.
  • Crisis Communication: Secure, pre-defined internal and external communication methods to ensure transparent coordination without compromising data integrity.