N.5.05 Recovery plan OT-systemen
Control Overview
This control mandates that the organization develops, documents, implements, and tests a formal business continuity and disaster recovery plan specifically for Operational Technology (OT) systems. The plan must establish explicit recovery time objectives (RTOs) for critical cyber-physical components, clearly assign incident response roles to internal and external stakeholders, and guarantee the immediate availability of essential recovery resources (such as configuration files, technical documentation, and physical spare parts). These recovery paths must be validated regularly through live drills or structured simulations.
Applicability Status
- Applicable for anDREa: NO
Justification & Strategic Approach
This control focuses on managing physical production downtime, coordinating local hardware supply chains (spare parts), and building disaster recovery runbooks for specialized industrial machinery or SCADA infrastructure. As a fully remote, cloud-native SaaS/PaaS provider, anDREa operates the myDRE data platform entirely within the virtualized infrastructure of Microsoft Azure.
Because anDREa's operational footprint is exclusively software-defined:
- The organization owns or controls no physical production lines, laboratory machinery, or industrial facilities.
- There are no cyber-physical OT systems that require specialized recovery times or hardware-bound safety procedures.
- Maintaining an inventory of physical machinery spare parts or specialized OT-system restoration runbooks is outside the scope of our business operations.
Consequently, all requirements under the NIS 2 Operational Technology (OT) disaster recovery domain are Not Applicable.
Platform-wide business continuity, logical system failovers, and cloud availability objectives are instead comprehensively managed under our IT continuity framework. This is governed explicitly by Control N.4.06 (Redundancy of Infrastructure) and executed via our Disaster Recovery Plan and *Baseline Recovery of myDRE Service playbooks.
Audit Summary
- Compliance Status: Not Applicable (Exempt via Architecture)
- Gaps Identified: None. The justification for non-applicability perfectly matches anDREa's cloud architecture. No further action is required.