ISO 22301 2012 is now
obsolete. See ISO 22301 2019. ISO 22301
2012 is a business
continuity management standard.
|
4. Context4.1. Understand your organization and its unique context. •
Understand your
organization and its purpose before •
Consider the issues that could influence the outcomes •
Consider how your
business continuity policy •
Understand your organization's context before • Clarify your organization's objectives. •
Identify the particular factors that create your • Establish your organization's risk criteria. • Define the purpose of your BCMS. 4.2. Define the needs and expectations of your interested parties. 4.2.1. Clarify who interested parties are and specify their requirements. • Identify all of the parties that have an interest in your BCMS. • Identify their requirements including their needs and expectations. 4.2.2. Consider legal and regulatory requirements when designing BCMS. •
Establish a
procedure to manage your legal and •
Document your organization's legal, regulatory, •
Consider all relevant legal, regulatory, and other •
Discuss changes in legal, regulatory, and other 4.3. Figure out what your BCMS should apply to and clarify its scope. 4.3.1. Think about what your organization's BCMS should cover. •
Consider what your organization's BCMS should cover and what
•
Consider how disruptive incidents could impact your
organization •
Consider all of the factors that create your •
Consider the parties that have an interest in your •
Consider all relevant legal, regulatory, and other
requirements •
Consider all the issues that could influence what your BCMS •
Consider what the boundaries of your BCMS should 4.3.2. Establish your requirements and define the scope of BCMS. •
Establish your organization's BCMS requirements •
Consider your organization's mission and goals •
Consider your organization's legal and regulatory •
Consider your organization's internal and external •
Consider the needs and expectations of your organization's • Figure out what should be included in your BCMS. • Define the scope of your organization's BCMS. 4.4. Develop a BCMS that meets your needs and complies with this standard. • Establish a BCMS in accordance with the ISO 22301 2012 standard. • Establish the processes that your organization's BCMS needs. • Specify how your processes should interact. |
5. Leadership5.1. Provide leadership for your organization's BCMS. •
Provide leadership and support for your organization's •
Make sure that your managers demonstrate •
Make sure that your managers encourage 5.2. Show that you support your organization's BCMS. • Demonstrate a commitment to your BCMS. • Ensure that BCMS policies are established. • Ensure that BCMS objectives are established. • Ensure that BCMS achieves its intended outcomes. •
Ensure that BCMS requirements become an •
Ensure that necessary BCMS resources
• Communicate a commitment to your BCMS. •
Make sure that
personnel understand how 5.3. Establish a suitable BCMS policy for your organization. • Establish a business continuity policy. • Document your business continuity policy. • Implement your business continuity policy. • Review your business continuity policy. 5.4. Assign responsibility and authority for your BCMS. •
Allocate responsibility and authority for carrying out
business |
6. Planning6.1. Specify actions to manage your risks and address your opportunities. •
Identify the risks and opportunities that could influence
the •
Figure out what you need to do to address the risks and
opportunities that •
Define actions and prepare plans to address the risks and
opportunities that 6.2. Set business continuity objectives and develop plans to achieve them. • Establish your organization's business continuity objectives. • Establish plans to achieve your business continuity objectives. |
7. Support7.1. Support your BCMS by providing the necessary resources. • Identify the resources that your organization's BCMS needs. • Provide the resources that your organization's BCMS needs. 7.2. Support your BCMS by making sure that people are competent. •
Identify the
competence requirements of the people under your •
Acquire the necessary competence whenever current personnel
•
Evaluate the effectiveness of any actions taken to 7.3. Support your BCMS by making people aware of their responsibilities. • Make your people aware of your organization's BCMS. •
Make sure that the people who work for your organization •
Make sure that the people who work for your organization
understand •
Make sure that the people who work for your organization
understand their •
Make sure that the people who work for your organization
understand 7.4. Support your BCMS by establishing communication procedures. • Identify your organization's pre-incident BCMS communication needs. • Identify your organization's internal BCMS communication needs. • Identify your organization's external BCMS communication needs. • Establish pre-incident BCMS communication procedures. 7.5. Support your BCMS by managing all relevant information. 7.5.1. Provide the information and documents that your BCMS needs. • Document the information that your organization's BCMS needs. •
Ensure that BCMS documents and records are unique to your •
Establish, retain, and maintain the documented •
Develop, retain, and maintain the documents and records that
your 7.5.2. Supervise the creation and modification of BCMS documents. •
Supervise the creation and modification of your •
Make sure that your BCMS documents and •
Make sure that your BCMS documents and •
Make sure that your BCMS documents and 7.5.3. Control your organization's BCMS information and documents. • Control your organization's BCMS documents and records. • Control how BCMS documents and records are created. • Control how BCMS documents and records are identified. • Control how BCMS documents and records are approved. • Control how BCMS documents and records are distributed. • Control how BCMS documents and records are stored. • Control how BCMS documents and records are retrieved. • Control how BCMS documents and records are accessed. • Control how BCMS documents and records are used. • Control how BCMS documents and records are protected. • Control how BCMS documents and records are changed. • Control how BCMS documents and records are preserved. |
8. Operation8.1. Carry out process planning and establish controls. • Plan the development of your BCMS processes. • Develop your organization's BCMS processes. • Implement your organization's BCMS processes. • Control your organization's BCMS processes. • Maintain your organization's BCMS processes. 8.2. Study disruptions and risks and set your priorities. 8.2.1. Establish a process to analyze impacts and assess risks. •
Establish a formal process that your organization •
Document the process that your organization uses •
Implement the process that your organization uses •
Maintain the process that your organization uses 8.2.2. Evaluate and set business continuity and recovery priorities. •
Establish a formal process that your organization can • Document your priority setting process. • Implement your priority setting process. • Maintain your priority setting process. 8.2.3. Assess risks and identify risk treatment options. • Establish a formal risk assessment process. • Document your risk assessment process. • Implement your risk assessment process. • Identify your business interruption risks. • Analyze your business interruption risks. • Evaluate your business interruption risks. • Communicate your business interruption risks. • Maintain your risk assessment process. • Identify your risk treatment options. 8.3. Develop a business continuity strategy to handle disruptions. 8.3.1. Use impact analysis and risk assessment to develop strategy. • Consider possible business continuity strategies. •
Base your business continuity strategy on the •
Base your business continuity strategy on the • Develop your business continuity strategy. •
Make sure that your strategy explains how you plan to •
Make sure that your strategy explains how you plan to 8.3.2. Identify the resources that you need to implement strategy. •
Identify the resources that your organization needs 8.3.3. Select and implement risk treatment measures to manage risks. • Consider treatments to manage your organization's risks. • Consider risk treatments that reduce the likelihood of disruption. • Consider risk treatments that shorten the period of disruption. • Consider risk treatments that limit the impact of disruption. • Select treatments to manage your organization's risks. • Implement your organization's risk treatment measures. 8.4. Establish and implement business continuity plans and procedures. 8.4.1. Establish disruption and continuity management procedures. •
Develop procedures to manage disruptive
incidents
•
Document procedures to manage disruptive incidents •
Implement procedures to manage disruptive incidents •
Maintain procedures to manage disruptive incidents 8.4.2. Establish an incident response structure and procedures. • Establish your incident response processes and procedures. • Establish your incident response management structure. 8.4.3. Establish disruption warning and communication procedures. • Establish your warning and communication procedures. • Establish procedures for detecting incidents when they occur. • Establish procedures for monitoring incidents as they occur. • Establish procedures for sharing information during a disruption. • Establish procedures for recording information about incidents. •
Establish procedures for operating your organization's •
Establish procedures for ensuring that your means of • Implement your warning and communication procedures. • Maintain your warning and communication procedures. 8.4.4. Establish incident response and business continuity procedures. •
Consider your organization's business continuity needs when
•
Make sure that your plans and procedures explain how •
Make sure that your plans and procedures address the needs •
Develop your organization's incident response •
Define incident response and business •
Design a process that you can use to activate •
Explain how you plan to manage immediate •
Specify how and when you intend to communicate •
Document your organization's incident response •
Describe how you plan to ensure that your prioritized 8.4.5. Establish suitable business recovery and restoration procedures. •
Establish procedures to restore and return prioritized
business •
Document your organization's business 8.5. Conduct exercises and test business continuity plans and procedures. • Establish business continuity management exercises and tests. •
Develop exercises and tests to ensure that your
organization's • Conduct your business continuity management exercises and tests. • Examine how well your organization handles disruptive scenarios. • Produce accurate and complete post-exercise reports. • Review your business continuity exercises and tests. |
9. Evaluation9.1. Monitor, measure, and evaluate your organization's BCMS. 9.1.1. Monitor and measure the performance of your BCMS. •
Figure out how you're going to monitor and measure •
Develop procedures to monitor and measure the •
Monitor and measure the performance and •
Establish a record of your organization's BCMS 9.1.2. Evaluate your business continuity procedures and capabilities. •
Establish a process to evaluate your organization's •
Evaluate your organization's business •
Modify business continuity procedures and capabilities
whenever 9.2. Set up an internal audit program and use it to evaluate your BCMS. • Plan the development of an internal BCMS audit program. •
Make sure that your audit program is capable of determining
•
Make sure that your audit program is capable of determining
• Establish your organization's internal BCMS audit program. • Implement your organization's internal BCMS audit program. • Maintain your organization's internal BCMS audit program. 9.3. Review the performance of your organization's BCMS. • Establish a BCMS review process. • Plan your BCMS review process. • Review the performance of your BCMS. • Generate management review outputs. • Communicate your management review results. • Retain a record of management review results. |
10. Improvement10.1. Identify nonconformities and take corrective actions. • Identify nonconformities when they occur. • React to your organization's nonconformities. • Evaluate the need to eliminate causes. • Implement corrective actions to address causes. • Review the effectiveness of your corrective actions. • Change your BCMS if necessary or desirable. 10.2. Enhance the overall performance of your BCMS. • Continuously improve the performance of your BCMS. • Continuously improve the suitability of your BCMS. • Continuously improve the adequacy of your BCMS. • Continuously improve the effectiveness of your BCMS. |
Updated on October 5, 2020. First published on March 23, 2013.
Praxiom Research Group Limited help@praxiom.com 780-461-4514 |
Legal Restrictions on the Use of this
Page Copyright © 2013 - 2020 by Praxiom Research Group Limited. All Rights Reserved. |