– Security and Resilience – Business Continuity Management Systems – Requirements

ISO 22301:2019

ISO 22301:2019
Safety and Durability

ISO 22301:2019

 Safety and Durability

This standard is a management system standard based on a risk-based approach for the establishment, implementation, monitoring, review, maintenance and improvement of business continuity.

This standard helps organisations to establish processes, procedures, decisions and activities to ensure that, following an incident that could cause disruption to operations, the organisation’s ability to provide products or services continues at pre-determined acceptable levels, and that the organisation’s operations can continue even if a particular activity is interrupted; in other words, it helps organisations to develop proactive and reactive plans to help them avoid crises and disasters, and to ensure a swift return to normal operations should such situations occur.

The activities carried out within the scope of the Business Continuity Management System (BCMS) are determined in accordance with the organisation’s legal, regulatory, organisational and sector-specific requirements, as well as the requirements of interested parties relating to the products and services provided, the processes implemented, and the organisation’s size and structure.

 

1. Understanding the need to establish business continuity policies and objectives in line with the organisation’s requirements,
2. Operating and maintaining processes, capabilities and response structures to ensure the organisation is resilient to disruptions,
3. Monitoring and reviewing the performance and effectiveness of the Business Continuity Management System (BCMS),
4. It ensures that continuous improvements are made based on qualitative and quantitative measurements.
5. Ensures that existing and potential threats to operations are identified and managed,
6. With regard to operations: it supports strategic objectives, creates a competitive advantage, maintains and enhances its reputation and credibility, and contributes to organisational resilience,
7. Adopts a proactive approach to minimise the impact of incidents,
8. In terms of internal processes: it enhances the ability to remain effective during disruptions, demonstrates the proactive management of risks in an effective and efficient manner, and addresses operational vulnerabilities
9. Supports the continuity of critical functions during crises,
10. It ensures that the post-crisis recovery process is improved and that operational downtime is minimised during and as a result of incidents,
11. Ensures that the necessary flexibility is demonstrated to meet the needs and requirements of customers and suppliers,

Preparation and Planning

  • Application: The first step is to apply to an accredited certification body for ISO 22301:2019 – Security and Resilience – Business Continuity Management System certification.
  • Security and Resilience–Business Continuity Management System Planning: The organisation draws up a plan for the Security and Resilience–Business Continuity Management System. This plan includes the policies, objectives and management processes of the Security and Resilience–Business Continuity Management System.
  •  

System Setup and Implementation

  • Security and Resilience – Business Continuity Management System Implementation: The organisation shall establish a Security and Resilience – Business Continuity Management System in accordance with the ISO 22301:2019 standard. This includes the monitoring, measurement and analysis of the Security and Resilience – Business Continuity Management System.
  • Monitoring and evaluating the performance of the management system: The performance indicators necessary to achieve the objectives relating to the effectiveness of the management system are identified and monitored.

Internal Audit and Management Review

  • Internal Audit: The organisation carries out internal audits to assess the effectiveness of the Business, Security and Resilience – Business Continuity Management System and its compliance with the relevant standard.
  • Management Review: Management reviews the performance of the Security and Resilience–Business Continuity Management System and identifies areas for improvement.

Certification Audit

Independent Audit:

An independent audit is carried out by the certification body to assess the organisation’s Security and Resilience–Business Continuity Management System and its compliance with the standards.

    • Reporting and Feedback: The audit findings are reported and feedback is provided to facilitate the necessary improvements.