Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

N.1.23 ICT preparation for business continuity

Control Overview

This control mandates that the organization develops and maintains a formalized plan to ensure ICT continuity during a disruptive incident (such as a major cyberattack or infrastructure failure). The organization must explicitly define its business continuity objectives, including the Maximum Tolerable Downtime (MTD) and recovery objectives for all essential information systems. To satisfy this requirement, a combination of organizational and technical measures—including robust backup architectures, failover mechanisms, and validated crisis management procedures—must be implemented and regularly tested to guarantee that operations can survive and recover within acceptable parameters.

Applicability Note: This control is fully applicable to the anDREa platform and directly shapes the high-availability and disaster recovery architectures of our core customer environments.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, aligning business continuity commitments directly with the operational realities of our cloud-native stack.

Rather than making unrealistic or generic service guarantees, anDREa explicitly defines its availability objectives within our Service Level Agreement (SLA) and maps them technically via the myDRE CIA-AA Classification matrix. Our documentation takes a transparent, mature approach to the cloud Shared Responsibility Model. Because our platform runs on Microsoft Azure, classical Recovery Time Objective (RTO) and Recovery Point Objective (RPO) parameters are bounded by cloud infrastructure limits. To mitigate this dependency, we maintain an independent Baseline Recovery of myDRE Service plan to handle non-Azure level disruptions, ensuring that automated backups and disaster recovery runbooks are explicitly defined, isolated, and tested regularly.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.30 - ICT readiness for business continuityMandates that ICT readiness is planned, implemented, maintained, and tested based on business continuity objectives and requirements.
Contractual CommitmentsService Level AgreementLegally defines the Maximum Tolerable Downtime (MTD) and operational availability commitments provided to our clients.
Continuity ArchitectureBaseline Recovery of myDRE ServiceThe technical disaster recovery manual detailing specific restoration vectors for incidents operating outside of standard Azure cloud fabric failures.
Risk Classificationmydre CIA-AA ClassificationThe foundational categorization matrix that aligns technical infrastructure nodes to their strict business impact and recovery priorities.
Crisis ManagementDisaster Recovery Plan, & Backup Logs`The operational response plan and automated verification histories proving that configuration states and backups are regularly tested and restorable.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Core platform availability targets, SLA parameters, disaster recovery strategies, and backup restoration validations are completely active. Continuous Improvement: To further optimize compliance, formally document internal RTO/RPO targets specifically for the secondary internal tooling and support services under your direct control (e.g., ticketing systems and internal corporate administration tools). This will complement the primary SaaS infrastructure continuity already established.