International

ISO/IEC 27031:2025

59 controls. 0 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

59 controls 0 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

No measured overlap with another framework in the corpus.

Every control

CodeControlAlso in
10.1Prerequisites for the development of plans0
10.1.1Determining and setting the recovery organization0
10.1.2Determining time frames for plan development, reporting and testing0
10.1.3Resources0
10.1.4Competency of IRBC staff0
10.1.5Technological solutions0
10.2Recovery plan activation0
10.2.1ICT BCP Activation0
10.2.2Escalation0
10.3ICT recovery plans0
10.3.1RPO and RTO plans for ICT0
10.3.2Facilities0
10.3.3Technology0
10.3.4Data0
10.3.5Response and recovery procedures0
10.3.6People0
10.4Temporary work around plans0
10.5External contacts and procedures0
11.1Performance criteria0
11.2Testing dependencies0
11.2.1Test and exercise0
11.2.2Test and exercise program0
11.2.3Scope of exercises0
11.2.4Planning an exercise0
11.2.5Alert based and different recovery stages0
11.2.6Managing an exercise0
11.3Learning from tests0
11.4Auditing the IRBC0
11.5Control of documented information0
12Final MBCO0
13.2Management responsibilities0
6.2Enabling governance0
6.3Business continuity management objectives0
6.4Risk management and applicable controls for IRBC0
6.5Incident management and relationship to IRBC0
6.6BCM strategies and alignment to IRBC0
7.1Risk review0
7.1.2Monitoring, detection and analysis of threats and events0
7.2Inputs from business impact analysis0
7.2.2Understanding critical ICT services0
7.2.3Assessing ICT readiness against business continuity requirements0
7.3Coverage and interfaces0
7.3.2ICT dependencies for the scope0
7.3.3Determine any contractual aspects of dependencies0
8.1Incident based, preparation before incident0
8.1.2ICT Recovery capabilities0
8.1.3Establishing an IRBC0
8.1.4Setting objectives0
8.1.5Determining possible outcomes and benefits of IRBC0
8.1.6Equipment redundancy planning0
8.1.7Determining the scope of ICT services related to the objectives0
8.2Determining target ICT RTO and RPO0
9.2IRBC strategy options0
9.2.2Skills and knowledge0
9.2.3Facilities0
9.2.4Technology0
9.2.5Data0
9.2.6Processes0
9.2.7Suppliers0

Tell me when ISO/IEC 27031:2025 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO/IEC 27031:2025, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition