BSI 200-4: contingency plans that hold
The standard requires plans – they only become viable through infrastructure on which recovery and restoration actually work.
- The same framework as yours – ISMS certified to ISO 27001 based on IT-Grundschutz by the BSI.
- Recovery instead of re-procurement – backup, immutable copies and restoration as bookable services.
- Evidence for your contingency manual – certificates with scope, TOMs and operational documentation.
- Geo-redundancy since 2016 – distributed operations across several locations in Germany.
What a contingency plan requires technically
BSI Standard 200-4 is staged – from a reactive BCMS to a standard BCMS. Technical requirements grow accordingly.
Backups beyond reach
With the object lock function of S3 Object Storage, backups are immutable – within the retention period they cannot be deleted, not even with stolen credentials.
Recovery instead of reprocurement
A prepared secondary environment shortens recovery to what the plan specifies – instead of waiting for hardware delivery times.
The same framework as yours
centron’s information security management system is certified to ISO 27001 based on IT-Grundschutz by the BSI (certificate BSI-IGZ-0773).
Exercises with participants
Contingency exercises need a provider that takes part. Named contacts help plan the test restore rather than administer it.
The most common emergency is not a fire but ransomware
What the standard demands in the abstract shows itself in four concrete situations from everyday administration.
Ransomware: backups out of reach
In an attack, the backups are targeted first – encrypted or deleted. Immutable backups cannot be overwritten or deleted within the retention period, not even with administrative rights – recovery remains possible without giving in to the demand.
Emergency drills without spare hardware
In the cloud, the emergency can be rehearsed without spare hardware: restore an environment from backup, verify it, document the result, switch it off again. The effort is limited to the runtime.
Geo-redundancy across German locations
Data centres are operated with enough physical separation that a single event such as flooding, fire or a wide-area power outage does not hit several at once – at centron since 2016, at the Hallstadt, Nuremberg and Frankfurt am Main locations.
Documents for the contingency manual
Certificates with their scope, TOM documentation and the operating details for your recovery plans: locations, backup procedures, reporting channels and availability – supplied by centron.
From protection needs assessment to recovery
The order is set by the standard: assess protection needs, run a business impact analysis, implement technically, exercise and evidence. The first two steps remain with you – they depend on your systems and your responsibility. From step three centron delivers: separated backups, a prepared secondary environment and the documentation your evidence trail needs.
- Protection needs – assessed by your authority
- Recovery objectives – you define RTO and RPO
- Technology – centron provides the implementation
- Exercises – test restores planned, not improvised
BSI standard 200-4: who is responsible for what
BSI standard 200-4 describes how to build business continuity management within IT-Grundschutz and is staged: from a reactive BCMS through a development BCMS to a standard BCMS. Regular tests and drills are envisaged; independently of that, Art. 32(1)(d) GDPR requires a procedure for regularly reviewing effectiveness. The procurement framework is described by the sovereign cloud for public administration.
| Task | With you | With centron |
|---|---|---|
| Protection needs assessment and business impact analysis | in full | — |
| Recovery plans and contingency manual | creation and maintenance | supply of operating details |
| Specialist applications and operating systems | configuration, patching, application recovery | managed service on request |
| Backup and restoration | definition of interval and retention | execution and provision |
| Platform and data centre | — | redundancy, monitoring, operational emergency management |
| Emergency drills | planning, execution, evaluation | provision of the test environment |
The right centron products
Clinics and medical institutions typically implement IT security with these modules – combinable and extensible at any time.
- Immutable backups
- €0.02 per GB per month
- Outbound traffic free
- 15-minute replication
- Failover in seconds
- Separate fire compartment
- 24/7 monitoring
- Update management
- Personal contacts
What infrastructure does emergency management to BSI 200-4 require?
Emergency management to BSI Standard 200-4 requires backups an attacker cannot reach and a restoration that can be exercised. The core building block is S3 Object Storage from €5.00 per month with object lock, complemented by cProtect for fast recovery and Managed Services for supported operations. The infrastructure runs in our own German data centres, certified to ISO 27001 based on IT-Grundschutz (BSI certificate BSI-IGZ-0773) and with an unqualified BSI C5:2020 Type 1 attestation. New accounts receive €200 in starting credit.
| Module | Price |
|---|---|
| S3 Object Storage | from €5.00 / month |
| cProtect | from €0.03 / month |
| Managed Services | on request |
Frequently asked questions
How does BSI 200-4 relate to the former standard 100-4?
What should be considered when moving from 100-4 to 200-4?
What belongs in an IT contingency plan?
What are RTO and RPO?
Does centron write our contingency plan?
What does geo-redundancy mean according to the BSI?
How do immutable backups protect against ransomware?
How often must an emergency drill take place?
Can contingency exercises be run with centron?
Which documents does centron supply for our contingency manual?
More for the public sector
Get expert advice
Tell us about your project. Our sales team will get back to you within one business day.
The consultation is free of charge and without obligation.