What ISO 22301 requires
Like other ISO management-system standards, ISO 22301 is built around a management system — context, leadership, planning, support, operation, evaluation and improvement — applied specifically to business continuity. At its heart are two disciplines: understanding which activities matter most and how quickly they must recover, and having tested plans to make that recovery happen.
Analyse
Business impact analysis
Design
Continuity strategies
Implement
Plans & resources
Validate
Exercise & test
Improve
Review & update
Business impact analysis and recovery objectives
The business impact analysis (BIA) identifies your prioritised activities and the impact of their disruption over time. From it you set recovery objectives that drive everything else.
| Metric | What it means |
|---|---|
| RTO — Recovery Time Objective | How quickly an activity must be restored after disruption |
| RPO — Recovery Point Objective | The maximum acceptable data loss, measured in time |
| MTPD — Maximum Tolerable Period of Disruption | The point beyond which disruption threatens viability |
| MBCO — Minimum Business Continuity Objective | The minimum level of service acceptable during disruption |
How to approach ISO 22301
- 1Define the scope of the BCMS and the activities it covers.
- 2Run a business impact analysis and a risk assessment.
- 3Set recovery objectives and design continuity strategies to meet them.
- 4Document and resource the continuity and recovery plans.
- 5Exercise and test the plans — untested plans are assumptions, not capability.
- 6Review, improve and, if certifying, undergo Stage 1 and Stage 2 audits.
Common pitfalls to avoid
- Writing plans that are never exercised, so recovery capability is untested.
- Setting recovery objectives that ignore the dependencies real recovery relies on.
- Treating ISO 22301 as separate from operational resilience rather than its foundation.