ISO 22301:2019
Security and resilience — Business continuity management systems — Requirements
Security and resilience — Business continuity management systems — Requirements
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 21
- Дата публикации:
- 30 октября 2019 г.
- Издание:
- ISO IS 22301 edition 2 version 1
- ICS:
- 03.100.01
This document specifies requirements to implement, maintain and improve a management system to protect against, reduce the likelihood of the occurrence of, prepare for, respond to and recover from disruptions when they arise. The requirements specified in this document are generic and intended to be applicable to all organizations, or parts thereof, regardless of type, size and nature of the organization. The extent of application of these requirements depends on the organization's operating environment and complexity. This document is applicable to all types and sizes of organizations that: a) implement, maintain and improve a BCMS; b) seek to ensure conformity with stated business continuity policy; c) need to be able to continue to deliver products and services at an acceptable predefined capacity during a disruption; d) seek to enhance their resilience through the effective application of the BCMS. This document can be used to assess an organization's ability to meet its own business continuity needs and obligations.
Abstract
Overview
ISO 22301:2019 - Security and resilience - Business continuity management systems - Requirements - specifies the requirements for establishing, implementing, maintaining and continually improving a Business Continuity Management System (BCMS). The standard is designed to help organizations protect against, prepare for, respond to and recover from disruptive incidents. It is generic and intended to be applicable to all types and sizes of organizations; the scope of application depends on the organization’s operating environment and complexity.
Key topics and requirements
ISO 22301 structures a BCMS around the Plan–Do–Check–Act (PDCA) model and the following core elements:
- Context of the organization: understand internal/external factors and interested parties that affect continuity needs.
- Leadership and commitment: top management responsibilities, business continuity policy and defined roles.
- Planning: identify risks and opportunities, set business continuity objectives and plan changes to the BCMS.
- Support: resources, competence, awareness, communication and documented information control.
- Operation: operational planning and control, business impact analysis (BIA), risk assessment, strategy selection, resource requirements, implementation of protection and mitigation measures, and development of business continuity plans and procedures.
- Exercising and testing: establish an exercise programme to validate plans and capabilities.
- Performance evaluation: monitoring, measurement, internal audit and management review to assess BCMS effectiveness.
- Improvement: nonconformity management, corrective actions and continual improvement.
Key technical topics include business impact analysis, risk assessment, incident response and recovery strategies, defined recovery objectives (acceptable predefined capacity), and testing/exercising of continuity arrangements.
Practical applications
ISO 22301 is used to:
- Build a repeatable, auditable BCMS to reduce downtime and losses during disruptions.
- Ensure continuity of critical products and services at an acceptable predefined capacity.
- Guide development of incident response, warning/communication and recovery procedures.
- Demonstrate conformity with a stated business continuity policy to customers, partners and regulators.
- Drive resilience improvements through measurement, audits and management reviews.
Typical implementations cover IT service continuity, facilities and supply chain resilience, crisis management, and operational continuity across public and private sectors.
Who should use this standard
- Business continuity managers and risk managers
- Senior leadership and governance teams
- IT, operations, supply chain and facilities managers
- Auditors, consultants and compliance officers aiming to assess or certify BCMS performance
Related standards
ISO 22301 aligns with other ISO management-system approaches and can be integrated with existing management systems that follow PDCA and documented information requirements.
Технические детали
- Технический комитет
- ISO/TC 292 - Security and resilience
- SKU
- ISO 22301:2019
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS EN ISO 22313:2020
ДействующийSecurity and resilience. Business continuity management systems. Guidance on the use of ISO 22301.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…