Overview
ISO 22336:2024 - Security and resilience - Organizational resilience - Guidelines for resilience policy and strategy provides practical guidance for designing and developing an organizational resilience policy and strategy. Applicable to any industry or sector and usable throughout an organization’s life cycle, the standard explains how to formulate policy, design strategy to meet policy objectives, set implementation priorities, and build cooperative, coordinated capabilities to enhance resilience. It does not, however, provide step‑by‑step guidance on building an organizational resilience capability.
Key topics and technical requirements
ISO 22336:2024 structures guidance around principles, attributes and a process-driven framework. Key topics include:
-
Policy formulation
- Defining a clear, shared vision and purpose for resilience policy.
- Understanding and influencing internal and external context.
- Fostering a culture supportive of resilience.
-
Strategy design
- Translating policy objectives into strategy that anticipates, absorbs and manages change.
- Aligning resilience strategy with organizational goals and shared knowledge flows.
- Establishing prioritized resilience objectives and timelines.
-
Strategy implementation
- Developing strategic implementation plans, allocating resources, and defining roles and responsibilities.
- Ensuring coordinated, aligned systems and empowered leadership to deliver resilience initiatives.
-
Enabling behaviours and attributes
- Promoting behaviours such as adaptability, inclusiveness, integration, reflection, preparedness, robustness and innovation.
-
Process, evaluation and continual improvement
- Context analysis (internal/external), horizon scanning, communication, KPIs, monitoring, reporting and continual improvement cycles.
-
Leadership and commitment
- Senior leadership engagement and institutional commitment to enhancing resilience.
Practical applications - who should use this standard
ISO 22336 is designed for organizations seeking to strengthen resilience at enterprise level. Typical users include:
- Senior leadership and governance bodies developing resilience policy
- Resilience, continuity, security, risk and emergency management professionals
- Strategy and change managers aligning resilience with business objectives
- Consultants and auditors assessing resilience policy and strategic alignment
Practical applications include creating a resilience policy, developing prioritized resilience strategies, establishing implementation plans, defining resilience KPIs, and improving coordination across departments and stakeholders.
Related standards
- ISO 22316 (foundational principles for organizational resilience) - referenced in ISO 22336:2024.
- Work by ISO/TC 292 (Security and resilience) - for broader context and complementary guidance.
Keywords: ISO 22336:2024, organizational resilience, resilience policy, resilience strategy, security and resilience, resilience objectives, resilience KPIs, policy formulation, strategy implementation.