Compliance

Do you have a business continuity plan?

How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.

Expert answer

Maintain a business continuity plan covering critical functions, dependencies, and recovery procedures, tested through exercises. Pair it with disaster recovery for technical systems and review both periodically.

What the security reviewer is checking

The single word reviewers care about here is "tested." Nearly every vendor claims to have a business continuity plan; far fewer can show when it was last exercised and what the results were. Reviewers look for concrete recovery time objectives (RTO) and recovery point objectives (RPO), evidence that backup restoration has actually been performed rather than assumed, and a review cadence that keeps the plan current as your architecture changes. They also distinguish business continuity (people, processes, communications during disruption) from disaster recovery (technical restoration) — a mature answer addresses both.

Example response you can adapt

This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.
Yes. We maintain a documented business continuity plan and a companion disaster recovery plan, both reviewed and approved annually by leadership. Our disaster recovery targets are an RTO of 4 hours and an RPO of 1 hour for production services, supported by automated database backups with point-in-time recovery and infrastructure defined as code that allows full environment rebuild in an alternate cloud region. We test these plans on a defined schedule: quarterly backup restoration verification into an isolated environment, and an annual disaster recovery exercise plus a business continuity tabletop covering scenarios such as regional cloud outage and loss of key personnel. Results, gaps, and remediation actions from each test are documented. The most recent exercise met both recovery objectives, and findings were incorporated into the current plan revision.

Evidence reviewers expect you to attach

  • Business continuity plan and disaster recovery plan documents (or their tables of contents)
  • Most recent DR test or tabletop exercise report with measured RTO/RPO results
  • Backup configuration and restoration verification evidence
  • SOC 2 report section covering availability commitments (A1 criteria)

Follow-up questions reviewers ask next

  • When was the plan last tested, and did you meet your stated RTO and RPO?
  • Can you fail over to a different region or data center, and how long does it take?
  • How often are backups taken, and are they stored in a separate location?
  • What were the findings from your last continuity exercise, and were they remediated?
  • How would customers be notified during a prolonged outage?

Answer every security questionnaire in minutes

Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demo