BS EN ISO 22313:2020
$215.11
Security and resilience. Business continuity management systems. Guidance on the use of ISO 22301
Published By | Publication Date | Number of Pages |
BSI | 2020 | 72 |
This document gives guidance and recommendations for applying the requirements of the business continuity management system (BCMS) given in ISO 22301. The guidance and recommendations are based on good international practice.
This document is applicable to organizations that:
-
implement, maintain and improve a BCMS;
-
seek to ensure conformity with stated business continuity policy;
-
need to be able to continue to deliver products and services at an acceptable predefined capacity during a disruption;
-
seek to enhance their resilience through the effective application of the BCMS.
The guidance and recommendations are applicable to all sizes and types of organizations, including large, medium and small organizations operating in industrial, commercial, public and not-for-profit sectors. The approach adopted depends on the organization’s operating environment and complexity.
PDF Catalog
PDF Pages | PDF Title |
---|---|
2 | undefined |
4 | European foreword Endorsement notice |
8 | Foreword |
9 | Introduction |
16 | 1 Scope 2 Normative references 3 Terms and definitions |
17 | 4 Context of the organization 4.1 Understanding the organization and its context |
18 | 4.2 Understanding the needs and expectations of interested parties 4.2.1 General 4.2.2 Legal and regulatory requirements |
19 | 4.3 Determining the scope of the business continuity management system 4.3.1 General 4.3.2 Scope of the business continuity management system 4.3.3 Exclusions to scope |
20 | 4.4 Business continuity management system 5 Leadership 5.1 Leadership and commitment 5.1.1 General 5.1.2 Top management |
21 | 5.1.3 Other managerial roles 5.2 Policy 5.2.1 Establishing the business continuity policy |
22 | 5.2.2 Communicating the business continuity policy 5.3 Roles, responsibilities and authorities |
24 | 6 Planning 6.1 Actions to address risks and opportunities 6.1.1 Determining risks and opportunities 6.1.2 Addressing risks and opportunities |
25 | 6.2 Business continuity objectives and planning to achieve them 6.2.1 Establishing business continuity objectives 6.2.2 Determining business continuity objectives 6.3 Planning changes to the business continuity management system |
26 | 7 Support 7.1 Resources 7.1.1 General 7.1.2 BCMS resources 7.2 Competence |
28 | 7.3 Awareness |
29 | 7.4 Communication |
30 | 7.5 Documented information 7.5.1 General |
31 | 7.5.2 Creating and updating 7.5.3 Control of documented information |
32 | 8 Operation 8.1 Operational planning and control 8.1.1 General |
33 | 8.1.2 Business continuity management |
34 | 8.1.3 Maintaining business continuity |
35 | 8.2 Business impact analysis and risk assessment 8.2.1 General 8.2.2 Business impact analysis |
38 | 8.2.3 Risk assessment |
40 | 8.3 Business continuity strategies and solutions 8.3.1 General 8.3.2 Identification of strategies and solutions |
43 | 8.3.3 Selection of strategies and solutions 8.3.4 Resource requirements |
49 | 8.3.5 Implementation of solutions |
50 | 8.4 Business continuity plans and procedures 8.4.1 General 8.4.2 Response structure |
51 | 8.4.3 Warning and communication |
53 | 8.4.4 Business continuity plans |
58 | 8.4.5 Recovery |
59 | 8.5 Exercise programme 8.5.1 General 8.5.2 Design of the exercise programme |
60 | 8.5.3 Exercising business continuity plans |
63 | 8.6 Evaluation of business continuity documentation and capabilities 8.6.1 General |
64 | 8.6.2 Measuring effectiveness 8.6.3 Outcomes |
65 | 9 Performance evaluation 9.1 Monitoring, measurement, analysis and evaluation 9.1.1 General 9.1.2 Retention of evidence 9.1.3 Performance evaluation |
66 | 9.2 Internal audit 9.2.1 General 9.2.2 Audit programme(s) 9.3 Management review 9.3.1 General 9.3.2 Management review input |
67 | 9.3.3 Management review outputs 10 Improvement 10.1 Nonconformity and corrective action 10.1.1 General |
68 | 10.1.2 Occurrence of nonconformity 10.1.3 Retention of documented information 10.2 Continual improvement |
70 | Bibliography |