- Maintain the business impact analysis and the risk assessment behind it
- Keep recovery time and recovery point objectives current per activity
- Hold the continuity plans and the strategies they implement under version control
- Run the exercise programme under clause 8.6 and record what it proved
- Convert exercise findings into corrective action with named verification
ISO 22301:2019
The continuity standard, built around one question: when the thing you deliver stops, how quickly does it come back, and who decided that was fast enough.
- 4Context of the organization5
- 5Leadership4
- 6Planning4
- 7Support6
- 8Operation17
- 9Performance evaluation3
- 10Improvement2
ISO 22301, in practice.
Security and resilience. Business continuity management systems. Requirements.
Utilities, financial institutions, health providers and infrastructure operators, where an outage reaches beyond the organisation and someone outside it will ask what the plan was.
The clause numbers and titles above are the standard's own public structure. The standard itself is copyright of its issuing body and you buy it from them. What we add is the interpretation underneath, and that lives in your workspace.
Every month, on a schedule you can check.
This is the running work for this standard specifically. The general shape is the same across all of them.
- Business impact analysis with prioritised activities and objectives
- Continuity strategies and the plans that implement them
- Exercise reports with objectives, observations and follow-up actions
- Communication and warning procedures with contact records
- Performance evaluation against the recovery objectives set
Each one is filed against the requirement it satisfies as the work happens, so the pack for the next visit already exists.
Standards that share the structure.
ISO 9001:2015
The quality management standard most certified organisations start with, and the one most other management system standards borrow their structure from.
SOC 2 (TSC 2017, rev. 2022)
Not a certification but an attestation. An independent auditor reports on whether your controls were designed properly, and for Type II, whether they operated over a period.
ISO/IEC 27001:2022
The information security management standard. The management system clauses set the discipline, and Annex A supplies the control set you select from and justify.
Name a clause in ISO 22301 and we will open it.
The requirement, the control attached to it, the evidence that satisfies it, and the audit checklist it generates. Nothing prepared in advance, because there is nothing to prepare.
