ISO/IEC 27031:2025
ISO/IEC 27031:2025 is a compliance framework from International with 9 domains and 68 controls. The largest domains are Determining the ICT continuity plan – ISO/IEC 27031:2025 (18 controls), Business expectations for IRBC – ISO/IEC 27031:2025 (11 controls), Testing, exercise, and auditing – ISO/IEC 27031:2025 (11 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (9)
Business expectations for IRBC – ISO/IEC 27031:2025
| Code | Title |
|---|---|
| iso-iec-27031-2025::7.1.1 | General |
| iso-iec-27031-2025::7.1.2 | Monitoring, detection and analysis of threats and events |
| iso-iec-27031-2025::7.2.1 | General |
| iso-iec-27031-2025::7.2.2 | Understanding critical ICT services |
| iso-iec-27031-2025::7.2.3 | Assessing ICT readiness against business continuity requirements |
| iso-iec-27031-2025::7.3.1 | General |
| iso-iec-27031-2025::7.3.2 | ICT dependencies for the scope |
| iso-iec-27031-2025::7.3.3 | Determine any contractual aspects of dependencies |
Defining prerequisites for IRBC – ISO/IEC 27031:2025
| Code | Title |
|---|---|
| iso-iec-27031-2025::8.1.1 | General |
| iso-iec-27031-2025::8.1.2 | ICT Recovery capabilities |
| iso-iec-27031-2025::8.1.3 | Establishing an IRBC |
| iso-iec-27031-2025::8.1.4 | Setting objectives |
| iso-iec-27031-2025::8.1.5 | Determining possible outcomes and benefits of IRBC |
| iso-iec-27031-2025::8.1.6 | Equipment redundancy planning |
| iso-iec-27031-2025::8.1.7 | Determining the scope of ICT services related to the objectives |
| iso-iec-27031-2025::8.2 | Determining target ICT RTO and RPO |
Determining IRBC strategies – ISO/IEC 27031:2025
| Code | Title |
|---|---|
| iso-iec-27031-2025::9.1 | General |
| iso-iec-27031-2025::9.2.1 | General |
| iso-iec-27031-2025::9.2.2 | Skills and knowledge |
| iso-iec-27031-2025::9.2.3 | Facilities |
| iso-iec-27031-2025::9.2.4 | Technology |
| iso-iec-27031-2025::9.2.5 | Data |
| iso-iec-27031-2025::9.2.6 | Processes |
| iso-iec-27031-2025::9.2.7 | Suppliers |
Determining the ICT continuity plan – ISO/IEC 27031:2025
| Code | Title |
|---|---|
| iso-iec-27031-2025::10.1.1 | Determining and setting the recovery organization |
| iso-iec-27031-2025::10.1.2 | Determining time frames for plan development, reporting and testing |
| iso-iec-27031-2025::10.1.3 | Resources |
| iso-iec-27031-2025::10.1.4 | Competency of IRBC staff |
| iso-iec-27031-2025::10.1.5 | Technological solutions |
| iso-iec-27031-2025::10.2.1 | ICT BCP Activation |
| iso-iec-27031-2025::10.2.2 | Escalation |
| iso-iec-27031-2025::10.3.1 | RPO and RTO plans for ICT |
| iso-iec-27031-2025::10.3.2 | Facilities |
| iso-iec-27031-2025::10.3.3 | Technology |
| iso-iec-27031-2025::10.3.4 | Data |
| iso-iec-27031-2025::10.3.5 | Response and recovery procedures |
| iso-iec-27031-2025::10.3.6 | People |
| iso-iec-27031-2025::10.4 | Temporary work around plans |
| iso-iec-27031-2025::10.5 | External contacts and procedures |
Final MBCO – ISO/IEC 27031:2025
| Code | Title |
|---|---|
| iso-iec-27031-2025::12 | Final MBCO |
Integration of IRBC into BCM – ISO/IEC 27031:2025
| Code | Title |
|---|---|
| iso-iec-27031-2025::6.1 | General |
| iso-iec-27031-2025::6.2 | Enabling governance |
| iso-iec-27031-2025::6.3 | Business continuity management objectives |
| iso-iec-27031-2025::6.4 | Risk management and applicable controls for IRBC |
| iso-iec-27031-2025::6.5 | Incident management and relationship to IRBC |
| iso-iec-27031-2025::6.6 | BCM strategies and alignment to IRBC |
Structure of this document – ISO/IEC 27031:2025
Testing, exercise, and auditing – ISO/IEC 27031:2025
| Code | Title |
|---|---|
| iso-iec-27031-2025::11.1 | Performance criteria |
| iso-iec-27031-2025::11.2.1 | Test and exercise |
| iso-iec-27031-2025::11.2.2 | Test and exercise program |
| iso-iec-27031-2025::11.2.3 | Scope of exercises |
| iso-iec-27031-2025::11.2.4 | Planning an exercise |
| iso-iec-27031-2025::11.2.5 | Alert based and different recovery stages |
| iso-iec-27031-2025::11.2.6 | Managing an exercise |
| iso-iec-27031-2025::11.3 | Learning from tests |
| iso-iec-27031-2025::11.4 | Auditing the IRBC |
| iso-iec-27031-2025::11.5 | Control of documented information |
Top management responsibilities regarding evaluating the IRBC – ISO/IEC 27031:2025
| Code | Title |
|---|---|
| iso-iec-27031-2025::13.1 | General |
| iso-iec-27031-2025::13.2 | Management responsibilities |
What is ISO/IEC 27031:2025 and who does it apply to?
ISO/IEC 27031:2025 is a compliance framework from International with 9 domains and 68 controls. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27031:2025 actually require?
ISO/IEC 27031:2025 has 68 controls organised across 9 domains. The largest domains are Determining the ICT continuity plan – ISO/IEC 27031:2025 (18 controls), Business expectations for IRBC – ISO/IEC 27031:2025 (11 controls), Testing, exercise, and auditing – ISO/IEC 27031:2025 (11 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27031:2025 do I already cover?
ISO/IEC 27031:2025 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO/IEC 27031:2025?
Start your ISO/IEC 27031:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27031:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 68 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required