Live 16 practitioner certifications live · First lesson free on every course Back to main site →

Business Continuity Plan vs Disaster Recovery Plan

A BCP defines how the business keeps operating during a disruption; a DRP defines how IT systems and data are recovered after one.

A Business Continuity Plan (BCP) is a documented programme that defines how an organisation continues delivering critical business functions during and after a disruption, whether the disruption is a cyber incident, natural disaster, pandemic or supply-chain failure. Its scope is the business — people, processes, third parties, customer communications, workarounds. ISO 22301:2019 is the international standard for BCPs.

A Disaster Recovery Plan (DRP) is the IT-specific subset of the BCP. It defines how IT systems, applications, data and network connectivity are restored after a disruption. Key DRP metrics are the Recovery Time Objective (RTO — how quickly service must be restored) and Recovery Point Objective (RPO — how much data loss is acceptable). Most DRPs are exercised through table-top rehearsals and periodic failover drills.

RBI Master Direction on IT Governance 2023 requires every regulated entity to maintain both a BCP and a DRP, with defined RTOs and RPOs for each critical service and demonstrable evidence of periodic testing. SEBI CSCRF imposes an equivalent obligation. The dcomply Academy RBI Cybersecurity and SEBI CSCRF certifications walk the BCP + DRP framework and evidence templates that regulators actually inspect.

Cited authorities

  • ISO 22301:2019
  • RBI Master Direction on IT Governance 2023
  • SEBI CSCRF