Skip to content
SecuriFii

Management system

ISO 22301 — Business Continuity Management

Continuity planning fails in one of two ways: a plan that was never exercised, or a plan built on an assumption about recovery time that nobody checked with the business. ISO 22301 exists to prevent both.

Standard
ISO 22301:2019
Starts from
Business impact analysis
Clause structure
Annex SL
Objectives set
RTO · RPO

What ISO 22301 requires

ISO 22301:2019 specifies a business continuity management system — a BCMS. It starts from a business impact analysis: which activities deliver your products and services, what happens as each hour of disruption passes, and how long each can be interrupted before the damage is unacceptable. That analysis produces the recovery objectives everything else is built against.

From there the standard requires you to select continuity strategies proportionate to those objectives, document plans and response structures, and — the requirement organisations most often under-do — exercise and test them, then feed what you learn back in.

ISO 22301 shares the harmonised clause structure used by ISO/IEC 27001 and ISO 9001. Context, leadership, planning, support, operation, evaluation and improvement are common ground, so an organisation already running an ISMS is adding a discipline to an existing management system rather than starting a second one.

What it will ask of you

Most of the effort here is not the security team’s. It is time from the people who actually run the activities, which is the thing to plan for.

  • A business impact analysis

    Which activities deliver your products and services, what they depend on, and what happens as each hour of disruption passes. Everything else is built on this.

  • Recovery objectives somebody signed

    RTOs and RPOs agreed by the people who own the consequences, not assumed by IT. An assumed recovery time is the most common finding in this standard.

  • Plans that name people

    Response and recovery plans with named roles and explicit decision authority — a plan that names a job family has not decided who picks up the phone.

  • Exercises, and honest records of them

    The requirement organisations most often under-do. An exercise that surfaced nothing was not an exercise, and the record should say what did not work.

Why organisations hold it

  • Customer contracts and tenders increasingly require demonstrable continuity arrangements, not a statement that you have some.
  • It replaces an assumed recovery time with one agreed by the business and tested against reality.
  • It supports ISO/IEC 27001 directly — availability is an information security property, and Annex A expects continuity to be addressed.
  • Exercises surface the dependencies nobody documented, which is usually the finding with the highest value.

Where we come in, and where we stop

As with ISO/IEC 27001, an accredited certification body assesses the system and we may not — the same clause of ISO/IEC 17021-1 applies.

Ours

  • Scope, context and the obligations the BCMS has to satisfy
  • Running the business impact analysis with the activity owners
  • Disruption risk assessment, aligned to your existing risk method
  • Continuity strategy with costed options, and the plans themselves
  • Designing and facilitating the exercise programme
  • Internal audit, management review and certification readiness

An accredited certification body

  • Stage 1 and Stage 2 assessment
  • Issuing the certificate and running surveillance

How we build it

As with ISO/IEC 27001, certification is assessed by an independent accredited certification body over a Stage 1 and Stage 2 audit.

  1. 01Scope and contextWhich products and services the BCMS covers, and the obligations — regulatory, contractual, customer — it has to satisfy.
  2. 02Business impact analysisPrioritised activities, their dependencies, and agreed recovery time and recovery point objectives, signed off by the people who own the consequences.
  3. 03Risk assessmentThe disruption scenarios that could realistically stop those activities, assessed against the same method as your information security risk work.
  4. 04Continuity strategy and plansOptions chosen against the recovery objectives and their cost, then written into response and recovery plans with named roles and decision authority.
  5. 05Exercising and testingFrom tabletop walkthroughs to live tests, with the records the standard requires and an honest account of what did not work.
  6. 06Internal audit and readinessInternal audit, management review and the evidence pack for a certification body, when certification is the goal.

What you get from us

  • Business impact analysis with agreed RTOs and RPOs
  • Disruption risk assessment aligned to your existing risk method
  • Continuity strategy with costed options
  • Response and recovery plans that name people, not job families
  • Exercise programme, exercise records and lessons-learned actions
  • Internal audit and certification readiness where certification is in scope

Common questions

Do we need ISO 22301 if we hold ISO 27001?

Not necessarily. ISO/IEC 27001 requires you to address continuity for information security, which for many organisations is enough. Pursue ISO 22301 when a customer or regulator asks for it specifically, or when disruption of your operations — not just your data — is the risk that matters.

Can it be certified?

Yes, by an accredited certification body, on the same Stage 1 and Stage 2 pattern as ISO/IEC 27001. Some organisations implement it without certifying and use it purely as an internal discipline.

How is this different from disaster recovery?

Disaster recovery is largely about technology restoration. ISO 22301 covers the business: people, premises, suppliers, communications and decision-making. IT recovery is one input to it, and on its own is the commonest gap we find.

How long does implementation take?

Four to eight months for a mid-sized organisation. The business impact analysis is the long pole, because it needs time from the people who run the activities rather than from the security team.

Related insights