Disaster
Recovery
Business Continuity Audit Program
ISO 27001 - ISO 27002 - ISO 22301
HIPAA - SOX - PCI-DSS Compliant
Janco has found that less than 40% of all Disaster Recovery Business Continuity Plans are without a major defect
This Disaster Recovery / Business Continuity Audit program identifies control objectives that are meet by the audit program. There are 36 specific items that the audit covers in the 13 page audit program. Included are references to specific Janco products that directly address the areas the audit covers.
This program can be used as standalone audit program or in concert with the following Janco offerings:
- Disaster Recovery / Business Continuity Template
- Security Manual Template
- Security Audit Program Template
- Business and IT Impact Questionnaire
- IT Service Management for Service Oriented Architecture
- Metrics for the Internet and Information Technology
The Disaster Recovery / Business Continuity Audit program covers the following control objectives are:
- Ensure that adequate and effective contingency plans have been established to support the prompt recovery of crucial enterprise functions and IT facilities in the event of major failure or disaster;
- Ensure that all mandated disaster recovery, business continuity, and security requirements have adequate compliance policies and procedures in place;
- Ensure the survival of the business and to minimize the implications of a major enterprise and/or I T failure;
- Ensure that all the potential risks to the enterprise and its IT facilities are identified and assessed in preparation of the contingency plans;
- Ensure the optimum contingency arrangements are selected and cost effectively provided;
- Ensure that an authorized and documented disaster recovery / business continuity plan is created, maintained up-to-date, and securely stored;
- Ensure that the recovery plan is periodically tested for its relevance and effectiveness;
- Ensure that all internal and external parties to the recovery process are fully aware of their responsibilities and commitments;
- Ensure that appropriate liaison is maintained with external parties (i.e. insurers, emergency services, suppliers, etc.);
- Ensure that both the damaged and recovery sites are secure and that systems are securely operated in support of the enterprise;
- Ensure that systems and procedures are adequately and accurately documented to aid the recovery process; and
- Ensure that public and media relations would be effectively addressed during an emergency in order to minimize adverse publicity and business implications.
Included with this program area Microsoft (.docx format) Word Document and an a PDF version of the Audit Program.
See also Rating Disaster Recovery Risk






Security Audit Program
Disaster Recovery Business Continuity Audit Program










