01
BIA and risk assessment as one step (clause 8.2)
The standard requires both as the foundation: understanding impact and assessing continuity risks. You run the BIA at process, service or asset level, assess risks on the same object and define RTO, RPO, MTPD and MBCO per process. Registers and objects are the same as in the ISMS, nothing is entered twice.
02
Strategies with a justified selection (clause 8.3)
BIA results become continuity requirements, from which you derive strategies and solutions. Each option documents cost, feasibility and resource needs, because the standard requires a justified selection, not just an outcome.
03
Plans and procedures for the real event (clause 8.4)
BC plans capture roles, activation, communication and decision authority. Versioning, approval, distribution and acknowledgement run in the same workflow as policies. That way, every role knows its part before it is needed.
04
Plans are only worth as much as the last exercise (clause 8.5)
The standard requires an ongoing exercise programme with defined objectives, from tabletop walkthroughs through functional tests to full-scale exercises. Findings and follow-up actions are documented directly on the tested plan; the exercise history is fully evidenced at audit.
05
Performance evaluation and management review (clauses 9.1 to 9.3)
Metrics, internal audit and management review are separate obligations in the standard. KaitoSec brings exercise results, incidents and review decisions together in one place; every improvement stays traceable to its trigger.