BS EN ISO 22301:2019
$167.15
Security and resilience. Business continuity management systems. Requirements
Published By | Publication Date | Number of Pages |
BSI | 2019 | 38 |
This document specifies requirements to implement, maintain and improve a management system to protect against, reduce the likelihood of the occurrence of, prepare for, respond to and recover from disruptions when they arise. The requirements specified in this document are generic and intended to be applicable to all organizations, or parts thereof, regardless of type, size and nature of the organization. The extent of application of these requirements depends on the organization’s operating environment and complexity. This document is applicable to all types and sizes of organizations that: a) implement, maintain and improve a BCMS; b) seek to ensure conformity with stated business continuity policy; c) need to be able to continue to deliver products and services at an acceptable predefined capacity during a disruption; d) seek to enhance their resilience through the effective application of the BCMS. This document can be used to assess an organization’s ability to meet its own business continuity needs and obligations.
PDF Catalog
PDF Pages | PDF Title |
---|---|
2 | undefined |
5 | European foreword Endorsement notice |
11 | Foreword |
12 | Introduction |
15 | 1 Scope 2 Normative references 3 Terms and definitions |
21 | 4 Context of the organization 4.1 Understanding the organization and its context 4.2 Understanding the needs and expectations of interested parties 4.2.1 General 4.2.2 Legal and regulatory requirements 4.3 Determining the scope of the business continuity management system 4.3.1 General |
22 | 4.3.2 Scope of the business continuity management system 4.4 Business continuity management system 5 Leadership 5.1 Leadership and commitment 5.2 Policy 5.2.1 Establishing the business continuity policy |
23 | 5.2.2 Communicating the business continuity policy 5.3 Roles, responsibilities and authorities 6 Planning 6.1 Actions to address risks and opportunities 6.1.1 Determining risks and opportunities 6.1.2 Addressing risks and opportunities 6.2 Business continuity objectives and planning to achieve them 6.2.1 Establishing business continuity objectives |
24 | 6.2.2 Determining business continuity objectives 6.3 Planning changes to the business continuity management system 7 Support 7.1 Resources 7.2 Competence |
25 | 7.3 Awareness 7.4 Communication 7.5 Documented information 7.5.1 General 7.5.2 Creating and updating |
26 | 7.5.3 Control of documented information 8 Operation 8.1 Operational planning and control 8.2 Business impact analysis and risk assessment 8.2.1 General |
27 | 8.2.2 Business impact analysis 8.2.3 Risk assessment 8.3 Business continuity strategies and solutions 8.3.1 General 8.3.2 Identification of strategies and solutions |
28 | 8.3.3 Selection of strategies and solutions 8.3.4 Resource requirements 8.3.5 Implementation of solutions 8.4 Business continuity plans and procedures 8.4.1 General |
29 | 8.4.2 Response structure 8.4.3 Warning and communication |
30 | 8.4.4 Business continuity plans |
31 | 8.4.5 Recovery 8.5 Exercise programme 8.6 Evaluation of business continuity documentation and capabilities 9 Performance evaluation 9.1 Monitoring, measurement, analysis and evaluation |
32 | 9.2 Internal audit 9.2.1 General 9.2.2 Audit programme(s) 9.3 Management review 9.3.1 General 9.3.2 Management review input |
33 | 9.3.3 Management review outputs 10 Improvement 10.1 Nonconformity and corrective action |
34 | 10.2 Continual improvement |
35 | Bibliography |