You are on page 1of 7

BUSINESS CONTINUITY

MANAGEMENT &
ISO22301
Frequently asked questions
January 2015

Protect ● Comply ● Thrive


IT Governance Green Paper

BUSINESS CONTINUITY
MANAGEMENT &
ISO22301
Business continuity management is often
“Statistics indicate that 80% of
described as a business-critical activity, but
conversation on the subject is often organisations that are faced
confused by the parallel concept of disaster with a significant business
recovery management. Understanding has
discontinuity, and do not have
not been improved by the existence of
several different business continuity related adequate and appropriate plans
standards. In May 2012, however, the to ensure business continuity,
publication of ISO/IEC 22301 provided a
single standard that replaced the prior do not survive the event.”
dominant standard, BS25999, while offering
greater clarity on the subject.
organisation and the impacts to business
So, what exactly is business continuity operations that those threats, if realised,
management, and how do the current might cause, and which provides a
standards relate to one another? framework for building organisational
1. What is business continuity resilience with the capability for an effective
management (BCM)? response that safeguards the interests of its
key stakeholders, reputation, brand and
A range of internal or external risks could value-creating activities.”
negatively impact your organisation. These
include a fuel crisis, pandemic, the loss of 2. And what is disaster recovery
business facilities due to fire, flooding, theft management (DRM)?
and vandalism, communications failure, One definition is: “the ability of an
industrial action, power failures – any event organisation to respond to a disaster or an
that interferes with the normal running of interruption in services by implementing a
your business. disaster recovery plan to stabilise and
Business continuity management is the restore the organisation’s critical functions.”
planning process and activities used to On the surface, then, it seems extremely
identify those aspects of your business similar to BCM.
activities and resources that are essential 3. So, how do the two concepts relate?
or critical.
A simple way of approaching these two
Documented and tested plans are essential concepts is to view business continuity
if your organisation is to continue with management as the overall process of
‘business as usual’ when there is a civil identifying and planning to counteract
emergency or business interruption. business continuity risks; part of that
The formal definition from ISO/IEC 22301 planning should include recovering the
is: “A holistic management process that business from a disaster scenario to get it
identifies potential threats to an back to normal working.

© IT Governance Ltd 2015 2 BCM-DR-FAQ


IT Governance Green Paper

In essence, BCM ensures that a business  ISO 22301:2012 is a specification for a


can continue to function while recovering BCM system.
from the disaster.  ISO 22313:2012 is guidance for the
DRM, meanwhile, is a broader process of implementation of the BCM system
returning a business or organisation to a described in ISO22301.
state of normality after a disastrous event. 8. What is the difference between the
This will ordinarily incorporate business
two and are they both equally
continuity, but the focus is upon total
important?
recovery.
ISO22301 provides a framework for an
4. Does BCM really matter?
effective BCM system. It provides sufficient
Statistics indicate that 80% of organisations clarity that it is the basis for an accredited
that are faced with a significant business certification scheme.
discontinuity, and do not have adequate
ISO22313 provides guidance in
and appropriate plans to ensure business
implementing ISO22301. It recognises that
continuity, do not survive the event. organisations have differing needs, and so
Sensible organisations take steps well in
the information can be followed by
advance of possible disasters to ensure
organisations anywhere, in whole or in part.
they will survive them; in today’s climate,
organisations want to be sure their The framework and guidance are
suppliers and the companies in which they complementary, but only ISO22301 is
have invested are going to be able to cope. audited for certification.
An ISO22301-accredited certificate provides 9. Where can I get copies of the two
evidence of due diligence where BCM is standards?
concerned.
Both are available for purchase from official
5. What is ISO22301? ISO distributor, IT Governance:
ISO22301 is an international standard that
 ISO/IEC 22301 (specification)
describes the function of a BCM system. It
 ISO/IEC 22313 (guidance)
follows the work established by BS25999,
which was the first formal national (British) 10. What are the benefits of BCM and
standard for business continuity ISO22301?
management, published in two parts to
It is vital that organisations are able to
worldwide interest in 2007 and 2008.
withstand serious incidents such as fire and
6. What if we have BS25999 flooding, and quickly reopen for business as
certification? normal or, even better, switch to
alternative facilities without missing a
BS25999 has been superseded by
customer.
ISO22301. From 31 May 2012 to 31 May
2014, the United Kingdom Accreditation Even a relatively short interruption to
Service (UKAS) required all certification normal activity can seriously damage
bodies to reassess organisations that had customer relationships and your reputation.
been certified for compliance with BS25999.
Implementing a best practice BCM
No new certificates or renewals for
system can help to:
BS25999 have been issued after 31
December 2013.1 This means that any  Safeguard your reputation and
BS25999 certificate your organisation holds competitive edge.
is no longer valid, so you should seriously  Preserve customer loyalty and trust.
consider certifying to ISO22301.  Protect financial income and key
7. How is ISO22301 related to business activities.
ISO22313?  Protect business assets.

© IT Governance Ltd 2015 3 BCM-DR-FAQ


IT Governance Green Paper

 Enhance business recovery following 13. What is the relationship between


serious discontinuities. ISO/IEC 22301 and ISO/IEC 27001?
 Support insurance claims. ISO 22301 is not part of the framework
11. What steps are required to achieve established in ISO27001, but there is a
certification to ISO22301? degree of overlap in requirements,
particularly with reference to ISO27001’s
There is an ISO22301 certification scheme, risk management requirements.
and organisations can have their BCM
systems audited against the specification ISO27001 and ISO22301 certification are
contained in the Standard. Please contact independent of one another, although many
us (servicecentre@itgovernance.co.uk) for of the drivers for achieving one form of
more information about how you can have certification are likely to be common for the
your ISO22301 BCM system independently other.
certified. 14. Are there toolkits that can help me
12. What other standards exist? simplify the process of creating a BCM
plan?
There are two other standards that are
important to the business continuity Yes, there are. One of the most popular is
professional – with particular reference to also the most comprehensive: the
those concerned with IT service continuity ISO22301 BCMS Implementation Toolkit. It
and disaster recovery: contains all the templates and tools that will
enable a business continuity manager to
 ISO/IEC 24762 – the international code create a BCM plan and develop a business
of practice for information and continuity management system (BCMS) in
communications technology disaster line with ISO22301.
recovery services.
 ISO/IEC 27031 – the guidelines for ICT
readiness for business continuity.

© IT Governance Ltd 2015 4 BCM-DR-FAQ


IT Governance Green Paper

Useful resources
IT Governance offers a unique range of products and services, including books, standards, pocket guides,
training courses, staff awareness solutions and professional consultancy services.

Business continuity resources


 ISO22301 BCMS Implementation Toolkit
This toolkit contains all the templates and tools that enable a business continuity manager
to quickly implement an effective BCMS in line with ISO22301.

 Disaster Recovery and Business Continuity, Third Edition


This guide shows you how to safeguard your company from viruses and phishing scams. It
explains how to store data safely, prevent assets and business intelligence from being lost
by accident, and ensure your communication links are secure and functioning when disaster
strikes.

 ISO22301 - A Pocket Guide


ISO22301: A Pocket Guide will help you understand international business continuity best
practice, and provides guidance on the best way to implement a fit-for-purpose business
continuity management system (BCMS).

 A Manager’s Guide to ISO22301


Providing a comprehensive introduction to the topic, the author explains how to develop and
implement a business continuity and disaster recovery plan based on ISO22301, the
international standard for best practice in BCM.

Standards
 ISO/IEC 22301 (Specification)
The standard provides the requirements for a business continuity management system
(BCMS) to enable a company to prepare for a disruptive incident. This standard is
essential for an ISO22301-certified BCMS.

 ISO/IEC 22313 (Guidance)


The international standard for implementing a business continuity management system
(BCMS) that meets the requirements of ISO22301.

Training
 ISO22301 Certified BCMS Foundation Training Course

This one-day Foundation course provides a comprehensive introduction to the


international standard and the requirements of a business continuity management
system.

 ISO22301 Certified BCMS Lead Implementer Training Course

© IT Governance Ltd 2015 5 BCM-DR-FAQ


IT Governance Green Paper

Gain the knowledge and skills to implement an ISO22301-compliant business continuity


management system (BCMS) in your organisation on this practical three-day course.

 ISO22301 Certified BCMS Lead Auditor Training Course

This course provides delegates with the practical knowledge and skills required to plan
and execute audits of business continuity management systems in line with the
requirements specified by the ISO 22301:2012 standard.

Consultancy
 FastTrack™ Business Continuity Management/ISO22301 Consultancy
This unique consultancy service helps you to implement a robust business continuity
management system (BCMS) and achieve certification to ISO22301, with minimal
business disruption and within a limited budget.

 ISO27001 Implementation Consultancy


This product is part of the ‘We’ll Do It For You’ ISO27001 consultancy service. It can
deliver any mix of hands-on, in-house, or mentor and coach consultancy, or any other
mix of consultancy support and services that you may need anywhere in the world to get
your organisation ready for accredited certification within an agreed time frame.

© IT Governance Ltd 2015 6 BCM-DR-FAQ


IT Governance Green Paper

IT Governance solutions
IT Governance sources, creates and delivers products and services to meet the evolving IT
governance needs of today's organisations, directors, managers and practitioners.
IT Governance is your one-stop shop for corporate and IT governance information, books,
tools, training and consultancy. Our products and services are unique in that all elements are
designed to work harmoniously together so you can benefit from them individually and also
use different elements to build something bigger and better.
Books
Through our website, www.itgovernance.co.uk, we sell the most sought after publications
covering all areas of corporate and IT governance. We also offer all appropriate standards
documents.
In addition, our publishing team develops a growing collection of titles written to provide
practical advice for staff taking part in IT governance projects, suitable for all levels of staff
knowledge, responsibility and experience.
Toolkits
Our unique documentation toolkits are designed to help small and medium-sized organisations
adapt quickly and adopt best management practice using pre-written policies, forms and
documents.
Visit www.itgovernance.co.uk/product-demos to view and trial all of our available toolkits.
Training
We offer training courses from staff awareness and foundation courses, through to advanced
programmes for IT practitioners and Certified Lead Implementers and Auditors.
Our training team organises and runs in-house and public training courses all year round,
covering a growing number of IT governance topics.
Visit www.itgovernance.co.uk/training for more information.
Through our website, you can also browse and book training courses throughout the UK that
are run by a number of different suppliers.
Consultancy
Our company is an acknowledged world leader in our field. We can use our experienced
consultants, with multi-sector and multi-standard knowledge and experience to help you
accelerate your IT GRC (governance, risk, compliance) projects.
Visit www.itgovernance.co.uk/consulting for more information.
Software
Our industry-leading software tools, developed with your needs and requirements in mind,
make information security risk management straightforward and affordable for all, enabling
organisations worldwide to be ISO27001-compliant.
Visit www.itgovernance.co.uk/software for more information.

1
http://www.ukas.com/services/Technical_Bulletins/BCM_BS25999_to_ISO_22301_Transition.asp

Contact us: + 44 (0) 845 070 1750


www.itgovernance.co.uk servicecentre@itgovernance.co.uk

© IT Governance Ltd 2015 7 BCM-DR-FAQ

You might also like