IT Infrastructure Readiness for Business Continuity according to the International Standard ISO/IEC 27031:2025 at Earthlink, the Internet Service Provider in Iraq: A case study
Main Article Content
Abstract
The research aims to assess the level of readiness of the Information and Communication Technology (ICT) infrastructure for business continuity at Earthlink Telecommunications and Internet Services Company in Iraq, in light of the requirements of the international standard ISO/IEC 27031:2025. The research adopts a case study approach as an appropriate methodological framework for understanding and analyzing the organizational and technical complexity inherent in telecommunications sector organizations.
To achieve the research objectives, a set of integrated data collection tools was employed, including field interviews with technical and administrative staff, a review of organizational documents and approved policies, as well as direct field observation of the ICT infrastructure environment. In addition, a checklist was developed based on the requirements of ISO/IEC 27031:2025 to assess the level of compliance and implementation. A seven-point Likert scale was also utilized to determine the actual level of application for each requirement of the standard. Furthermore, selected quality management tools, such as the Pareto chart and Ishikawa (fishbone) diagram, were applied to analyze gaps and diagnose the root causes affecting the level of readiness.
The analysis results revealed that the overall compliance rate with the standard’s requirements reached 53.46%, compared to an overall gap of 46.54%, indicating a moderate level of ICT infrastructure readiness in supporting business continuity. At the level of the main clauses, Clause (8), related to core requirements and infrastructure, recorded the highest compliance rate at 64.6%, reflecting an acceptable level of technical preparedness of the infrastructure supporting service continuity. In contrast, Clause (12), concerning the Minimum Business Continuity Objective (MBCO), ranked lowest with a compliance rate of 45.8%, indicating deficiencies in defining final operational business continuity objectives and aligning them with the technical capabilities of the infrastructure.
Moreover, Pareto analysis showed that only eight sub-requirements account for approximately 80% of the total gap, with the most significant weaknesses concentrated in testing and exercise programs, as well as Business Impact Analysis (BIA) requirements. In light of these findings, the study recommends adopting a formal institutional program aligned with ISO/IEC 27031:2025, developing a progressive methodology for periodic testing and exercise programs with documented improvement actions based on their outcomes, and investing in the enhancement of the existing infrastructure by strengthening redundancy capabilities and digital resilience, while directly integrating them with business continuity and disaster recovery plans.
Downloads
Article Details
References
جلال، محمد كمال. (2017). توافر نظام أمن المعلومات وفق المواصفة ISO/IEC 27001:2013 في المفوضية العليا المستقلة للانتخابات: دراسة حالة. بحث دبلوم عالي غير منشور، جامعة بغداد.
الخفاجي، نعمة عباس، والعبيدي، عبد الكريم محمد. (2020). دور إدارة المخاطر في تعزيز استمرارية الأعمال في المنظمات الخدمية. مجلة العلوم الاقتصادية والإدارية، 26(122)، 45–63.
ديمنغ، إدوارد، وهاغستروم، روبرت. (2019). إدارة الجودة الشاملة. القاهرة: دار كنوز المعرفة للنشر والتوزيع.
الزبيدي، حسنين حميد. (2012). تقويم إدارة المخاطر في المشاريع وفق المواصفة ISO 31000:2009. رسالة ماجستير غير منشورة، جامعة بغداد.
السلمي، علي. (2001). إدارة الأزمات والكوارث. القاهرة: دار غريب للطباعة والنشر.
شناوة، وسام عزيز، وحسين، أحمد محمود. (2018). إدارة المخاطر في الوحدات الاقتصادية الصناعية باستخدام مخطط باريتو. مجلة دراسات محاسبية ومالية، 13(42)، 232–248.
الطائي، يوسف حجيم، والعبادي، هاشم فوزي. (2015). إدارة الجودة الشاملة. عمّان: دار اليازوري العلمية للنشر والتوزيع.
العامري، صالح مهدي، والغالبـي، طاهر محسن. (2011). الإدارة والأعمال. عمّان: دار وائل للنشر.
العاني، محمد عبد الرحمن. (2019). إدارة استمرارية الأعمال ودورها في الحد من مخاطر الأزمات التنظيمية. مجلة الإدارة المعاصرة، 11(2)، 77–95.
عبد الحسين، علي. (2017). إمكانية تطبيق نظام إدارة جودة المشروع وفق المواصفة ISO 10006:2003. بحث دبلوم عالي غير منشور، جامعة بغداد.
العزاوي، محمد عبد الوهاب. (2010). إدارة الجودة الشاملة: مدخل استراتيجي تطبيقي. عمّان: دار إثراء للنشر والتوزيع.
العلاق، بشير عباس. (2017). الإدارة الاستراتيجية: المفاهيم والتطبيقات. عمّان: دار اليازوري العلمية.
القريشي، مدحت محمد. (2013). إدارة المخاطر في المنظمات المعاصرة. عمّان: دار المسيرة للنشر والتوزيع.
النجار، فايز جمعة، والجنابي، محمد عبد الكريم. (2012). إدارة المخاطر والتأمين. عمّان: دار الحامد للنشر والتوزيع.
ثانياً. المصادر الأجنبية:
Botha, J., & Von Solms, R. (2004). A cyclic approach to business continuity planning. Information Management & Computer Security, 12(4), 328–337.
Cerullo, V., & Cerullo, M. J. (2004). Business continuity planning: A comprehensive approach. Information Systems Management, 21(3), 70–78.
Herbane, B., Elliott, D., & Swartz, E. (2004). Business continuity management: Time for a strategic role? Long Range Planning, 37(5), 435–457.
Hiles, A. (2011). The definitive handbook of business continuity management (3rd ed.). Chichester: Wiley.
International Organization for Standardization. (2018). ISO 31000: Risk management — Guidelines. Geneva:
International Organization for Standardization. (2019). ISO 22301: Security and resilience — Business continuity management systems — Requirements. Geneva: ISO.
International Organization for Standardization. (2022). ISO 22313: Security and resilience — Business continuity management systems — Guidance. Geneva: ISO.
International Organization for Standardization. (2022). ISO/IEC 27002: Information security controls. Geneva: ISO.
International Organization for Standardization. (2025). ISO/IEC 27031: Information technology — Security techniques — Guidelines for information and communication technology readiness for business continuity. Geneva: ISO.
Snedaker, S. (2013). Business continuity and disaster recovery planning for IT professionals (2nd ed.). Amsterdam: Syngress.
Vagias, W. M. (2006). Likert-type scale response anchors. Clemson International Institute for Tourism, Department of Parks, Recreation and Tourism Management, Clemson University.
Wallace, M., & Webber, L. (2017). The disaster recovery handbook (3rd ed.). New York: AMACOM.
Zsidisin, G. A., & Ritchie, B. (2009). Supply chain risk management: Developments, issues and challenges. Springer.