The internal auditor can play a critical role in disaster recovery/business continuity resumption planning within an organization. This page provides resources and articles on the subject that you can use for reviews and planning for audits in this area. If you have any resources including audit programs, internal control questionnaires, checklists or other documents please consider sharing them for the benefit of the global audit community. Send your documents as attachments to firstname.lastname@example.org
Thanks to Dan Swanson for his contributions to this page.
EXECUTIVE GUIDE: DISASTER RECOVERY | SearchCIO.com
The devastating effects of hurricanes Katrina and Rita last fall made clear the importance of disaster recovery plans perhaps as well or better than any other events in recent history. This Executive Guide offers news, advice and other resources to help CIOs prepare their organizations for the worst.
ISACA global Knowledge Network - Using the search facility (at the link provided) enter “business continuity”, “disaster recovery”, “emergency management”, etc, to obtain a variety of resources to help your efforts.
Generally Accepted Business Continuity Practices – includes information on:
- Project Initiation and Management
- Risk Evaluation and Control
- Business Impact Analysis
- Developing Business Continuity Strategies
- Emergency Response and Operations
- Developing Business Continuity
- Training and Awareness
- Maintaining and Exercising Business Continuity Plans
- Public Relations and Crisis Communications
- Coordination with Public
ISO 22301 Business Continuity Management - a resource for information, links, news, events, resources and discussion for those seeking information and guidance on ISO 22301 specifically, also business continuity and emergency management in general.
A Community Risk Register - Each local resilience forum area in the UK has to provide a public Community Risk Register. This document is one of only a few that is being reviewed by central government in the UK as a contender for best practice of the publication of generic risk assessments in a local area. It was very much a multi-agency effort with over 80 contributors from at least 20 agencies.
The Internal Auditor's Role in Disaster Recovery - article from the American Association of State Compensation Insurance Funds.
Audit Programs, Internal Control Questionnaires and Checklists
- Disaster Recovery Plan
- Disaster Recovery - C ontingency Planning Audit Program
- Disaster Recovery - Contingency Planning ICQ
- Disaster Recovery Risk Evaluation (Word)(PDF)
Miscellaneous Resources Contributed by AuditNet Community Members