What is Business Continuity (BC)?
Business continuity planning is the process of establishing prevention and recovery systems to deal with potential threats to a company. In addition to prevention, the aim is to activate ongoing operations before and during the execution of the disaster recovery process.
What is Business Continuity Management (BCM)?
A comprehensive management process that provides a framework for creating organisational flexibility with the ability to respond effectively, identifying potential threats to an organisation and the impact these threats could have on commercial activities if they materialise, and protecting the interests of key stakeholders.
Business Continuity Management Objectives and Benefits
ISO 22301 specifies the structure and requirements for implementing and maintaining a business continuity management system (BCMS) that develops business continuity appropriate to the level and type of impact an organisation can or cannot accept after a disruption.
The outcomes of maintaining a BCMS are shaped by the organisation’s legal, regulatory, organisational, and industrial requirements, the products and services provided, the processes used, the organisation’s size and structure, and the requirements of interested parties.
A BCMS emphasises the importance of the following aspects:
- Understanding the organisation’s needs and the necessity of establishing business continuity policies and objectives.
- Operating and maintaining processes, capabilities, and response structures to ensure the organisation is not adversely affected by disruptions.
- Monitoring and reviewing the performance and effectiveness of the BCMS.
- Continuous improvement based on qualitative and quantitative measurements.
Components of Business Continuity Management
Like all other management systems, BCM includes the following components:
- A policy.
- Competent individuals with defined responsibilities.
- Management processes relating to the following:
- Implementation and operation.
- Performance evaluations.
- Management review.
- Continuous improvement.
- Documented information that supports operational control and enables performance evaluation.
Benefits of Business Continuity Management
The purpose of BCMS is to prepare, provide and maintain controls and capabilities to manage an organisation’s overall ability to continue operating during disruptions. In doing so, the organisation:
- From a business perspective:
- Supports strategic objectives,
- Creates competitive advantage,
- Maintains and enhances reputation and credibility.
- Contributes to organisational resilience.
- From a financial perspective:
- Reduces the scope of legal and financial risk.
- Reduces the direct and indirect costs of disruptions.
- From the perspective of stakeholders:
- Protects life, property and the environment.
- Takes into account the expectations of stakeholders.
- Provides confidence in the organisation’s ability to succeed.
- From the internal process perspective:
- Develops the ability to remain effective during disruptions.
- Demonstrates proactive control of risks in an effective and efficient manner.
- Manages operational security vulnerabilities.
Scope of Application of the Standard
- The standard specifies the requirements for implementing, maintaining and improving a management system to protect against disruptions when they occur, reduce their likelihood, prepare for them, respond to them and recover from them.
- The requirements specified in the standard are of a general nature and are intended to be applicable to all organisations or parts thereof, regardless of the organisation’s type, size, and nature. The degree to which these requirements are applied depends on the organisation’s working environment and complexity.
This standard applies to all types and sizes of organisations that wish to:
- Implement, maintain and improve a BCMS.
- strive to comply with the stated business continuity policy.
- continue to provide products and services at an acceptable predefined level during a disruption.
- To strive to increase their resilience through the effective implementation of a BCMS.
Main Areas of Impact
- Facilities
- People
- Suppliers
- Information Technology
- Tools
- Finance
Structure of the Standard in the Context of the Plan-Do-Check-Act (PDCA) Cycle
- ISO 22301 applies the Plan-Do-Check-Act (PDCA) cycle to implement, maintain, and continually improve the effectiveness of an organisation’s BCMS.
- This provides a degree of consistency with other management system standards such as ISO 9001, ISO 14001, ISO/IEC 20000-1, ISO/IEC 27001 and ISO 28000, thereby supporting consistent and integrated implementation and operation with relevant management systems.
PLAN
- 4 Context of the organisation
- 5 Leadership
- 6 Planning
- 7 Support
IMPLEMENT
- 8 Operation
CHECK
- 9 Performance evaluation
IMPROVE
- 10 Development
Useful Resources for Establishing Business Continuity Management
- ISO/DIS 22313 Social Security – Business continuity management systems – Guidance
- ISO 31000 Risk management – Principles and guidelines
- BS 25999-1 BC Management – Code of Practice
- Business Continuity Institute – Good Practice Guidelines
In addition to our IAS-accredited audit services for the ISO 22301 Business Continuity Management System, we also conduct internal audits and GAP analyses. We also offer awareness, internal auditor, implementation, and lead auditor training courses.