Overview - ISO 22320:2018 in brief
ISO 22320:2018, "Security and resilience - Emergency management - Guidelines for incident management," provides practical guidance for planning, organising and coordinating incident response. The standard explains the purpose and value of incident management and describes both the incident management process and the incident management structure needed to manage emergencies, disruptions and disasters of any type or scale. It is written as guidance for single organisations and for multi‑agency or cross‑border cooperation.
Key topics and technical requirements
ISO 22320:2018 emphasises a set of core principles and operational elements that form the backbone of effective incident management:
- Principles: life and dignity (ethics), unity of command, working together, all‑hazards approach, risk management, preparedness, information sharing, safety, flexibility, human and cultural factors, and continual improvement.
- Incident management process: objective‑driven processes based on proactive information gathering, situation assessment, contingency identification and planning.
- Incident management structure: defined roles and responsibilities, tasks, resource allocation and communications to ensure clarity and single‑supervisor reporting lines.
- Working together: coordination mechanisms, common operational picture, shared processes, communication channels and joint decision‑making for multi‑organizational response.
- Supportive guidance: annexes provide additional detail on cooperation, structure, example tasks and planning considerations.
Relevant normative references include ISO 22300 (vocabulary) and links to risk management guidance such as ISO 31000.
Practical applications - who uses it and why
ISO 22320:2018 is applicable to any organisation involved in incident preparedness or response:
- Emergency services, civil protection and public safety agencies
- Local and regional governments and national authorities
- Health services, utilities (water, power, telecoms) and critical infrastructure operators
- NGOs, humanitarian organisations and private‑sector emergency planners
- Business continuity, resilience and risk management professionals
Practical uses:
- Designing or improving incident command and control systems
- Creating interoperable multi‑agency response arrangements and memoranda of understanding
- Standardising information sharing and the common operational picture across partners
- Training, exercises and after‑action reviews to support continual improvement
Related standards
- ISO 22300 - Security and resilience: vocabulary (terms and definitions used in ISO 22320)
- ISO 31000 - Risk management: guidance referenced for risk‑based incident planning
ISO 22320:2018 is a practical, principles‑based guideline for organisations seeking to strengthen incident management, interoperability and resilience across single or multiple organisational structures.