Transcription of INTERNATIONAL ISO STANDARD 22301
1 ISO 2019 Security and resilience Business continuity management systems RequirementsS curit et r silience Syst mes de management de la continuit d'activit ExigencesINTERNATIONAL STANDAR DISO22301 Second edition2019-10 Reference numberISO 22301 :2019(E)iTeh STANDARD PREVIEW( )ISO 22301 :2019 ISO 22301 :2019(E) ii ISO 2019 All rights reservedCOPYRIGHT PROTECTED DOCUMENT ISO 2019 All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior written permission.
2 Permission can be requested from either ISO at the address below or ISO s member body in the country of the copyright officeCP 401 Ch. de Blandonnet 8CH-1214 Vernier, GenevaPhone: +41 22 749 01 11 Fax: +41 22 749 09 47 Email: in SwitzerlandiTeh STANDARD PREVIEW( )ISO 22301 :2019 ISO 22301 :2019(E) Foreword ..vIntroduction ..vi1 Scope ..12 Normative references ..13 Terms and definitions ..14 Context of the organization .. Understanding the organization and its context .. Understanding the needs and expectations of interested parties.
3 Legal and regulatory requirements .. Determining the scope of the business continuity management system .. Scope of the business continuity management system .. Business continuity management system ..85 Leadership .. Leadership and commitment .. Policy .. Establishing the business continuity policy .. Communicating the business continuity policy .. Roles, responsibilities and authorities ..96 Planning .. Actions to address risks and opportunities .. Determining risks and opportunities.
4 Addressing risks and opportunities .. Business continuity objectives and planning to achieve them .. Establishing business continuity objectives .. Determining business continuity Planning changes to the business continuity management system ..107 Support .. Resources .. Competence .. Awareness .. Communication .. Documented information .. Creating and updating .. Control of documented information ..128 Operation .. Operational planning and control .. Business impact analysis and risk assessment.
5 Business impact analysis .. Risk assessment .. Business continuity strategies and solutions .. Identification of strategies and solutions .. Selection of strategies and solutions .. Resource requirements .. Implementation of solutions .. Business continuity plans and procedures .. ISO 2019 All rights reserved iiiContents PageiTeh STANDARD PREVIEW( )ISO 22301 :2019 ISO 22301 :2019(E) Response structure .. Warning and communication .. Business continuity plans .. Recovery.
6 Exercise programme .. Evaluation of business continuity documentation and capabilities ..179 Performance evaluation .. Monitoring, measurement, analysis and evaluation .. Internal audit .. Audit programme(s) .. Management review .. Management review input .. Management review outputs ..1910 Improvement .. Nonconformity and corrective action .. Continual improvement ..20 Bibliography ..21iv ISO 2019 All rights reservediTeh STANDARD PREVIEW( )ISO 22301 :2019 ISO 22301 :2019(E)ForewordISO (the INTERNATIONAL Organization for Standardization) is a worldwide federation of national standards bodies (ISO member bodies).
7 The work of preparing INTERNATIONAL Standards is normally carried out through ISO technical committees. Each member body interested in a subject for which a technical committee has been established has the right to be represented on that committee. INTERNATIONAL organizations, governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely with the INTERNATIONAL Electrotechnical Commission (IEC) on all matters of electrotechnical standardization. The procedures used to develop this document and those intended for its further maintenance are described in the ISO/IEC Directives, Part 1.
8 In particular, the different approval criteria needed for the different types of ISO documents should be noted. This document was drafted in accordance with the editorial rules of the ISO/IEC Directives, Part 2 (see www .iso .org/ directives).Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. ISO shall not be held responsible for identifying any or all such patent rights. Details of any patent rights identified during the development of the document will be in the Introduction and/or on the ISO list of patent declarations received (see www.)
9 Iso .org/ patents).Any trade name used in this document is information given for the convenience of users and does not constitute an endorsement. For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions related to conformity assessment, as well as information about ISO s adherence to the World Trade Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www .iso .org/ iso/ foreword . document was prepared by Technical Committee ISO/TC 292, Security and second edition cancels and replaces the first edition (ISO 22301 :2012), which has been technically revised.
10 The main changes compared with the previous edition are as follows: ISO s requirements for management system standards, which have evolved since 2012, have been applied; requirements have been clarified, with no new requirements added; discipline-specific business continuity requirements are now almost entirely within Clause 8; Clause 8 has been re-structured to provide a clearer understanding of the key requirements; a number of discipline-specific business continuity terms have been modified to improve clarity and to reflect current feedback or questions on this document should be directed to the user s national standards body.