In the absence of formal business continuity and disaster recovery planning, information security
management should assume that information security requirements remain the same in adverse
situations, compared to normal operational conditions. Alternatively, an organization could perform
a business impact analysis for information security aspects to determine the information security
requirements applicable to adverse situations.