# Business Continuity & Disaster Recovery Policy

> **Template — adapt before use.** Replace `[bracketed]` placeholders, set real RTO/RPO targets, and test the plan. Not compliance advice.

| | |
|---|---|
| **Owner** | [Role] | **Approved** | [YYYY-MM-DD] | **Review/test** | Annual | **Version** | 1.0 |

Maps to: ISO 27001 A.5.29–5.30 & A.8.13 · SOC 2 A1.2–A1.3 · PCI DSS 12.10 · HIPAA §164.308(a)(7).

## 1. Purpose & scope
Ensures [Company Name] can continue or quickly restore critical operations during a disruption (outage, disaster, supplier failure, cyber incident).

## 2. Objectives
For each critical service, define:
| Service | RTO (max downtime) | RPO (max data loss) | Owner |
|---|---|---|---|
| [e.g. production app] | [4 hours] | [1 hour] | [role] |

## 3. Backups
- Critical data is backed up [frequency]; backups are encrypted and stored [location, separate from production].
- Restores are tested at least [quarterly]; results are recorded.

## 4. Recovery procedures
- Documented runbooks for restoring each critical service from known-good state.
- Defined recovery team, roles, and an alternate communication channel.
- Dependencies (cloud regions, key vendors) and their failover approach.

## 5. Testing
Conduct at least an annual continuity/DR exercise; record scenario, participants, results, and corrective actions.

## 6. Review
Review after any major change to infrastructure, after any invocation, and at least annually.

## Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | [YYYY-MM-DD] | [Name] | Initial issue |
