ICT Continuity
ICT continuity is the practice of making sure that an organization's information and communication technology services stay resilient and can be restored quickly enough after a disruption. It focuses on the technology, systems, and data an organization needs to keep its business running. The required level and speed of recovery are typically determined by an assessment of which ICT resources the business depends on.
ICT continuity refers to the management processes and technical arrangements that ensure required information and communication technology services are resilient and can be recovered to predetermined levels within the timescales the organization requires. In many frameworks it functions as a subset of, and support for, broader business continuity: ICT continuity requirements are commonly derived from the business impact analysis (BIA), which identifies the ICT resources needed to support prioritized business activities. It is oriented toward preserving, protecting, and recovering systems and data and toward aligning ICT capabilities with the organization's business continuity objectives, rather than encompassing all continuity of business operations. As addressed in ISO/IEC 27001 Annex A control 5.30 on ICT readiness for business continuity, its scope is the readiness of ICT systems to support business continuity objectives; the entry does not cover specific implementation, tooling, or recovery-time parameters, which vary by organization.
Why it matters
Organizations increasingly depend on information and communication technology to deliver their core activities, so a disruption to critical systems or data can quickly cascade into a wider interruption of business operations. ICT continuity matters because it establishes, in advance, which technology services must be resilient and how quickly they need to be recovered, rather than leaving these decisions to be made under the pressure of an active incident. When the underlying technology cannot be restored within the timescales the business requires, continuity plans that assume the availability of those systems may fail in practice.
ICT continuity is also significant because it connects technology recovery to business priorities rather than treating them in isolation. In many frameworks, ICT continuity requirements are derived from the business impact analysis, which identifies the subset of ICT resources needed to support prioritized business activities. This linkage helps ensure that recovery effort and investment are directed at the systems and data that genuinely matter to the organization, and it provides a defensible basis for the recovery levels and timescales an organization sets.
As a discipline oriented toward preserving, protecting, and recovering systems and data, ICT continuity supports broader organizational resilience and, where relevant, the availability, integrity, and confidentiality of critical information. It should be understood as a subset of and support for business continuity rather than a substitute for it; addressing ICT readiness alone does not, on its own, guarantee continuity of all business operations.
Who it's relevant to
Inside ICT Continuity
Common questions
Answers to the questions practitioners most commonly ask about ICT Continuity.
