Governance, risk and compliance

SmartSuite for the IT Disaster Recovery Lead

The IT Disaster Recovery Lead owns the recovery of technology services after a disruption: recovery strategies, DR plans, recovery time and point objectives, failover testing and the link between IT recovery and business continuity plans.

What you own

  • Own IT disaster recovery plans and recovery strategies
  • Set and validate RTOs and RPOs with business continuity
  • Plan and run DR tests and failover exercises
  • Maintain the inventory of critical systems and dependencies
  • Coordinate recovery during IT incidents and disasters
  • Track DR test findings and remediation

Where the role sits

Each name opens that role's page.

Reports to

IT Operations Director

IT Operations Director

See the role
Head of Operational Resilience

Head of Operational Resilience

See the role

Direct reports

Works closely with

Business Continuity Manager

Business Continuity Manager

See the role
Systems Administrator

Systems Administrator

See the role
Incident and Problem Manager

Incident and Problem Manager

See the role
Chief Information Security Officer

Chief Information Security Officer

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

resilience

Touches

contributes or approves

issues-actions, reporting

Depends on

consumes its output

risk

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use SmartSuite

Suites that serve this role

How SmartSuite supports this role

Operational resilience. Holds DR plans, RTO/RPO targets and test schedules linked to the business services they support.

Issues and actions. Tracks DR test findings and remediation to closure.

Reporting. Reports recovery readiness against targets to resilience and IT leadership.

Industry reference

ISO/IEC 27031 and NIST SP 800-34 Rev. 1 define ICT readiness and contingency planning; ITIL 4's service continuity management practice and ISO/IEC 27001:2022 Annex A 5.30 require it as part of service and security management; ISO 22301 ties IT recovery to business impact.

Regulators test recovery. The FFIEC BCM booklet and DORA require backup policies and tested recovery for financial entities; the HIPAA Security Rule requires a contingency plan with data backup, disaster recovery and testing (45 CFR 164.308(a)(7)); federal systems follow NIST SP 800-53 contingency controls; technology providers evidence recovery for SOC 2 availability commitments.

In their words

Related roles

IT Operations Director

IT Operations Director

See the role
Head of Operational Resilience

Head of Operational Resilience

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.