ISO 22301:2019

Security and resilience — Business continuity management systems — Requirements

 

 

 

ISO 22301:2019

Security and Resilience – Business Continuity Management Systems – Requirements” is an international standard for business continuity management which allows you to implement a system that integrates all components of an organization into a single system in such a way as to protect itself from possible failures, reduce the likelihood of their occurrence, prepare for and recover from failures if they occur.

The requirements specified in this document are general and are intended to apply to all organizations or their divisions, regardless of the type, size, and nature of the organization. The extent to which these requirements are applied depends on the operating environment and the complexity of the organization.

What is it?

This standard defines the requirements for planning, creating, implementing, monitoring, analyzing, maintaining and continually improving a business continuity management system. It uses the word “must” rather than “should” to indicate that this is a specification describing specific actions an organization must take in order to comply with the standard. Specifications are subject to audit and, therefore, certification. The advantage of certification is that it can act as a useful tool that, by demonstrating that an organization’s product or service meets customers’ expectations, reinforces the company’s credibility for all interested parties. In some sectors, this may even be a legal or contractual obligation.

Who is it for?

1) Demonstrates company’s maturity, reassures the client facing contractual requirements, and provides a guarantee of solvency and business continuity;

2) Perfectly integrates with other management systems already in place, such as the quality management system (ISO 9001) or the information security management system (ISO 27001);

3) The ISO 22301: 2019 standard applies the Deming cycle for the company’s management system. Thus, it is based on continuous improvement, which allows it to be updated and adapted to potential changes in organizations.

Advantages:

1) Prove to the existing and potential customers that you have implemented a business continuity management system. 

2) Get an independent opinion, assessment on the level of their safety. Accredited certification includes regular reviews as well as internal audits of the business continuity management system to ensure continual improvement;

3) Comply with regulatory requirements. For instance, the European General Data Protection Regulation (GDPR) and the Network and Information Systems Security Directive (NIS Directive).