ISO 22301

Business continuity management: be prepared for worst-case scenarios.

Emergency and disaster recovery plans can be of immense importance for operations in the event of disruptive incidents. However, this is only the case if they cover actual requirements, are up-to-date and are regularly reviewed for effectiveness – a practised Business Continuity Management System (BCMS) in accordance with ISO 22301 ensures this. 

Awareness among managers is on the rise – certifications for business continuity management are becoming a global trend. Following the publication of the first edition of the international standard ISO 22301 in 2012, the second edition has now been available since 2019.

In terms of content, the BCM standard has become even more compact. Now 21 pages long in the current second edition, the standard sets out the requirements for planning, introducing, implementing, operating, reviewing, maintaining and continuously improving a documented management system for business continuity.

The standard requirements of ISO 22301 are deliberately kept general by the authors so that organizations of all sizes and industries can apply them. The Plan-Do-Check-Act process improvement model, which has proven itself in both quality management and information security, is also a central element for the operation of BCM systems.

Your advantages

  • Preparation for events that interrupt operations
  • Avoidance of production downtime and stoppages
  • Proof of protective measures to maintain business processes as a competitive advantage

Context and scope of application

Firstly, the relevant internal and external topics as well as the interested parties and their requirements must be determined, from which the scope, objectives and strategies of the BCMS can be derived.

Leadership
As with other management systems, it is essential that the top management of the organisation assumes leadership responsibility and creates a BCM policy that is appropriate, suitable and communicated for the organisation, with basic values and objectives contained therein. The definition and assignment of roles with corresponding tasks and authorisations must also be taken into account, not least for reporting to top management.

Planning
For the introduction and continuous development of the BCMS, internal and external issues that have already been identified, the requirements of interested parties and the risks and opportunities for the BCMS must be determined and addressed so that the management system can fulfil its intended purpose. Business continuity objectives must be formulated for all relevant functions and levels of the organisation, their achievement monitored and adjusted if necessary.

Support
In order to achieve the defined BCMS objectives, the organisation must identify and provide sufficient resources and ensure the necessary competencies for the human resources part.

Employees and relevant external service providers must be given an appropriate awareness of the organisation’s business continuity policy and its contribution to achieving the business continuity objectives. The communication required for business continuity management and the scope and control of the necessary documented information must also be ensured.

Operation
The processes required for the operation of the BCMS must be planned, introduced and controlled. Evidence of this must be available as documented information. Outsourced operational processes must be included. The processes for the operation of the BCMS include

  • Conducting business impact analyses and risk assessments
  • Identification and selection of business continuity strategies that consider options before, during and after disruptive events
  • Development of business continuity plans and measures based on the selected business continuity strategies
  • Creating and managing programmes for regularly planned business continuity exercises
  • Regularly evaluating and updating the business impact analyses and risk assessments, the selected BCM strategies and the BCM plans and BCM solutions developed

Evaluation of the performance of the BCMS
As with other management systems, the performance of the BCMS is assessed using the following criteria

  • Monitoring of established key figures for business continuity management
  • Internal audits in the area of established processes for the BCMS
  • Review of the BCMS by top management

Improvement of the BCMS
Continuous improvement and the correction of identified deviations are an inherent part of the Business Continuity Management System in accordance with ISO 22301.

Certification

With the state accreditation for system certifications according to ISO 22301, CIS is a pioneer in Austria and is also one of the first global players internationally to be able to carry out certifications for business continuity management systems. The certification process according to ISO 22301 conforms to the structure of certification projects according to ISO/IEC 27001 for information security and ISO/IEC 20000 for service management, so that system integration is seamlessly possible and useful synergies can be utilised through combined certification audits.

Information on the project phases and the certification process can be found here.

Innovations on the climate crisis

The International Organisation for Standardisation (ISO) and the International Accreditation Forum (IAF) have published a joint communiqué due to the climate crisis and its effects. These requirements have been valid since 23 February 2024.

This communiqué sets out changes to ensure that companies and organisations address these issues. These changes are anchored in the following chapters of the standard
Chapter 4.1: ‘The organisation shall determine whether climate change is a relevant topic.’
Original text: ‘The organisation shall determine whether climate change is a relevant issue.
Chapter 4.2.1: ‘Note: Relevant interested parties may have requirements related to climate change.
Original text: ‘NOTE: Relevant interested parties can have requirements related to climate change.’

News

From the field of IT resilience and business continuity

Filter Dropdown

Request

We are delighted that you are interested in our services. We will be happy to send you further information. Please provide us with the following information:

    Field

    Contact details

    Note: Please fill in all fields marked with an asterisk (*).

    Do you have any specific questions?

    max. 2000 characters

    privacy policy

    Training Overview