Overview
ISO 22301:2019 - Security and resilience - Business continuity management systems - Requirements - specifies the requirements for establishing, implementing, maintaining and continually improving a Business Continuity Management System (BCMS). The standard is designed to help organizations protect against, prepare for, respond to and recover from disruptive incidents. It is generic and intended to be applicable to all types and sizes of organizations; the scope of application depends on the organization’s operating environment and complexity.
Key topics and requirements
ISO 22301 structures a BCMS around the Plan–Do–Check–Act (PDCA) model and the following core elements:
- Context of the organization: understand internal/external factors and interested parties that affect continuity needs.
- Leadership and commitment: top management responsibilities, business continuity policy and defined roles.
- Planning: identify risks and opportunities, set business continuity objectives and plan changes to the BCMS.
- Support: resources, competence, awareness, communication and documented information control.
- Operation: operational planning and control, business impact analysis (BIA), risk assessment, strategy selection, resource requirements, implementation of protection and mitigation measures, and development of business continuity plans and procedures.
- Exercising and testing: establish an exercise programme to validate plans and capabilities.
- Performance evaluation: monitoring, measurement, internal audit and management review to assess BCMS effectiveness.
- Improvement: nonconformity management, corrective actions and continual improvement.
Key technical topics include business impact analysis, risk assessment, incident response and recovery strategies, defined recovery objectives (acceptable predefined capacity), and testing/exercising of continuity arrangements.
Practical applications
ISO 22301 is used to:
- Build a repeatable, auditable BCMS to reduce downtime and losses during disruptions.
- Ensure continuity of critical products and services at an acceptable predefined capacity.
- Guide development of incident response, warning/communication and recovery procedures.
- Demonstrate conformity with a stated business continuity policy to customers, partners and regulators.
- Drive resilience improvements through measurement, audits and management reviews.
Typical implementations cover IT service continuity, facilities and supply chain resilience, crisis management, and operational continuity across public and private sectors.
Who should use this standard
- Business continuity managers and risk managers
- Senior leadership and governance teams
- IT, operations, supply chain and facilities managers
- Auditors, consultants and compliance officers aiming to assess or certify BCMS performance
Related standards
ISO 22301 aligns with other ISO management-system approaches and can be integrated with existing management systems that follow PDCA and documented information requirements.