ISO 22301:2012 Societal security - Business continuity management systems – Requirements

This International Standard addresses business continuity management to contribute making organizations in both public and private sectors more resilient. It provides a framework to plan, establish, implement, operate, monitor, review, maintain and continually improve a business continuity management system (BCMS). It helps organizations, regardless of their size, location or activity, to be better prepared and more confident to handle disruption of any type.

Incidents can disrupt an organization at any time and applying ISO 22301 will ensure that organizations can respond and continue its operations. Incidents take many forms ranging from large scale natural disasters and acts of terror to technology-related accidents and environmental incidents. However, most incidents are small but can have a significant impact and that makes business continuity management relevant at all times. This has led to a global awareness that organizations in the public and private sectors must know how to prepare for and respond to unexpected and disruptive incidents.

ISO 22301 may be used for third-party certification as well as for self assessment. To help users get the best out of the standard, it includes short and concise requirements describing the central elements of BCM.

ISO 22301 assists organizations in the design of a BCMS that is appropriate to its needs and meets its stakeholders’ requirements. These needs are shaped by legal, regulatory, organizational and industry factors, the organization's products and services, its size and structure, its processes, and its stakeholders.

Dave Austin (UK), the project leader responsible for the development of ISO 22301, explains:Austin

“Organizations implementing ISO 22301 will be able to demonstrate to legislators, regulators, customers, prospective customers and other interested parties that they are adhering to good practice in BCM. It may also be used within an organization to measure itself against good practice, and by auditors wishing to report to management.

To work well, ISO 22301 will need organizations to have thoroughly understood its requirements. Rather than being simply about a project or developing ‘a plan’, BCM is an ongoing management process requiring competent people working with appropriate support and structures that will perform when needed.”

ISO 22301 is the first standard published which is aligned with the new ISO format for writing management systems standards. This will ease understanding and ensure consistency with other management systems, such as ISO 9001 (quality management), ISO 14001 (environmental management) and ISO/IEC 27001 (information security management).

ISO 22301:2012, Societal security – Business continuity management systems – Requirements, is available from ISO national member institutes. It may also be obtained directly from the ISO Central Secretariat,  respectively through the ISO Store or by contacting the Marketing, Communication & Information department.

Pressrelease

Article written by Stefan Tangen and Dave Austin

Upcoming events

ISO 22341 Project team,
15 Nov, Zoom 

ISO 22341 Project team,
19 Nov, Zoom 

Communication Group meeting, 
3 Dec, Zoom 

WG 3 meeting,
[TBD] March 2019 [TBD]

WG 2 meeting,
[TBD] May 2019 [TBD]

7th ISO/TC 292 plenary meeting
[TBD] September, 2019

8th ISO/TC 292 plenary meeting
[TBD] June, 2020, in Berlin, Germany