ISO 22301 Business Continuity Management System Consulting
ISO 22301 compliance, gap analysis, business impact analysis, business continuity planning and certification readiness for organisations that cannot afford downtime.
ISO 22301 Compliance, Gap Analysis, Business Impact Analysis, Business Continuity Planning and Certification Readiness
The greatest risk an organisation faces is not simply suffering a cyber attack, a natural disaster or a technical failure. The real risk is that business-critical processes are interrupted and the organisation cannot resume operations within an acceptable period.
Business continuity is no longer an emergency plan that comes into play only in large-scale disaster scenarios.
Cyber attacks, ransomware incidents, data centre outages, power failures, loss of internet access, the loss of a critical supplier, hardware failures, shortages of key staff, fire, earthquake, flood, epidemics, transport problems, telecommunications outages and cloud service incidents can all disrupt business processes directly.
It is therefore not enough for an organisation to say “we have backups” or “we have a disaster recovery centre”.
The critical question is this:
How long can your business-critical processes withstand an interruption, and within what period can they be brought back into service once an interruption occurs?
ISO 22301 offers a systematic approach to exactly that question.
SecureSys provides end-to-end ISO 22301 consulting to help organisations establish an ISO 22301 Business Continuity Management System (BCMS), assess their current position, carry out a business impact analysis, define business continuity and disaster recovery strategies, and prepare for certification.
Our approach is not limited to producing policies and procedures.
Business continuity is handled by assessing
business processes + people + technology + location + suppliers + data + communication + crisis management + recovery capacity
together.
The aim is not a business continuity system that exists only on paper, but a tested and sustainable Business Continuity Management System (BCMS) that will actually work during a real interruption.
What Is ISO 22301?
ISO 22301 is the international business continuity management system standard covering how organisations manage business continuity risks and maintain their critical activities at predefined levels when an interruption occurs.
ISO 22301 does not simply define what an organisation should do after a disaster.
The standard takes a broader view.
It expects the organisation to:
- Define its critical processes
- Measure the impact of interruptions
- Establish acceptable interruption periods
- Define recovery objectives
- Develop business continuity strategies
- Produce plans
- Run exercises
- Measure the results
- Continually improve the system
This is why ISO 22301 is not only a “disaster recovery” standard.
It offers a comprehensive management system approach to
Business Continuity Management
as a whole.
What Is Business Continuity?
Business continuity is an organisation's ability to maintain its critical products and services at predefined, acceptable levels during and after an interruption or exceptional event.
Put simply, business continuity answers this question:
“When something goes wrong, how will the organisation carry on working?”
That “something” can take many forms.
For example:
- A cyber attack
- Ransomware
- A data centre outage
- Server failure
- Fire
- Earthquake
- Power failure
- Loss of internet access
- Telecommunications failure
- Loss of key personnel
- A primary supplier unable to deliver
- A cloud platform outage
- An office or facility becoming unusable
Business continuity management analyses in advance which of these scenarios could affect the organisation and to what extent, and ensures the necessary preparations are made.
What Is ISO 22301 Business Continuity Consulting?
ISO 22301 consulting is the process of assessing an organisation's existing business continuity arrangements against the requirements of ISO 22301 and building the system that is needed.
The SecureSys consulting approach begins by understanding the organisation as it actually is.
Every organisation differs in its
critical processes, acceptable interruption periods, technology dependencies, workforce structure, supply chain and the service it provides to its customers.
Applying a single off-the-shelf business continuity plan to every organisation is therefore not the right approach.
A business continuity system has to be built around the organisation's real operating model.
Who Is ISO 22301 For?
ISO 22301 can be applied in almost any sector.
It matters most in organisations where interruptions can have significant operational, financial, reputational or regulatory consequences.
For example:
Banks, financial institutions, public sector bodies, energy companies, manufacturing plants, defence industry firms, technology companies, data centres, telecoms operators, e-commerce businesses, healthcare providers, logistics companies, retail chains, software firms, cloud service providers and critical infrastructure operators can all benefit from the ISO 22301 approach.
The standard is not aimed solely at large organisations, however.
It can equally be applied in mid-sized businesses to manage critical processes and operational dependencies.
What ISO 22301 Delivers to the Organisation
ISO 22301 should not be implemented purely to obtain a certificate.
Implemented properly, it increases the organisation's real resilience.
Through ISO 22301 the organisation:
- Defines its critical processes clearly
- Measures its tolerance for interruption
- Establishes business priorities
- Sees its critical technology dependencies
- Identifies its critical human resources
- Analyses supplier dependencies
- Sets RTO and RPO targets
- Measures its disaster recovery capability
- Produces business continuity plans
- Develops a crisis management structure
- Runs regular exercises
- Builds a culture of continual improvement
Business continuity thereby stops being the responsibility of the IT department alone and becomes a corporate management system.
ISO 22301 Gap Analysis
One of the first steps on the road to ISO 22301 compliance is the ISO 22301 gap analysis.
A gap analysis establishes the difference between the current position and the requirements of the ISO 22301 standard.
The SecureSys ISO 22301 gap analysis assesses areas such as:
- Existing policies and procedures
- Risk management
- Critical processes
- BIA work already carried out
- RTO and RPO targets
- Disaster recovery infrastructure
- Business continuity plans
- Crisis management
- Exercise processes
- Supplier dependencies
- Communication plans
- Management review
- Internal audit
The findings are prioritised and turned into an ISO 22301 compliance roadmap tailored to the organisation.
What Is Business Impact Analysis (BIA)?
One of the most important building blocks of ISO 22301 is Business Impact Analysis (BIA).
A BIA establishes which of the organisation's business processes are critical, and how badly the organisation would be affected if those processes were interrupted.
A business impact analysis seeks answers to questions such as:
- Which processes are critical?
- How long can each process be down?
- What financial loss does an interruption cause?
- How are customers affected?
- Are legal or contractual obligations affected?
- Would reputational damage occur?
- Which applications support this process?
- Which members of staff are critical?
- Which suppliers is the process dependent on?
- Which location or infrastructure is critical?
A BIA makes the organisation's recovery priorities far clearer.
Why Does BIA Matter?
Many organisations treat all of their systems as equally critical.
That assumption is usually wrong.
Not every system and process carries the same business value.
An accounting reporting system may tolerate a few hours of downtime, while a customer payment system can cause serious loss after a few minutes.
Before business continuity investment can be directed properly, it is therefore necessary to establish which processes are genuinely critical.
The BIA provides that prioritisation.
What Is RTO?
RTO (Recovery Time Objective) defines how quickly a process or system must be brought back into service after an interruption.
For example,
if the RTO for a critical payment system is set at two hours, the objective is for the system to be serving again within two hours of the interruption at the latest.
RTO should not be set by the technical team alone.
The value has to reflect the real needs of the business unit.
What Is RPO?
RPO (Recovery Point Objective) expresses the acceptable level of data loss.
If the RPO for a system is 15 minutes, the organisation can accept the loss of at most the last 15 minutes of data.
This target directly affects backup frequency and disaster recovery architecture.
RTO and RPO should not be confused.
RTO expresses time; RPO expresses acceptable data loss.
What Are MTPD and MAO?
Business continuity work depends not only on RTO and RPO but also on the maximum period for which an interruption can be tolerated.
The concept of Maximum Tolerable Period of Disruption (MTPD), or an equivalent, is used for this purpose.
This period expresses how long a critical activity can be interrupted before the consequences become unacceptable for the organisation.
Establishing this value is critical to the design of business continuity strategies.
Business Continuity Risk Assessment
ISO 22301 requires the organisation to assess the threats that could cause an interruption.
A risk assessment can address scenarios such as:
Cyber attack
Critical services halted by ransomware, a data breach, DDoS or account takeover.
Data centre outage
Systems taken out of service by hardware, network, power or physical events.
Power failure
Operations affected by a prolonged loss of power.
Internet and telecoms outage
Loss of the communications infrastructure.
Supplier failure
A critical service provider unable to deliver.
Loss of human resources
Staff with critical skills becoming unavailable.
Loss of a physical location
An office, factory or operations centre becoming unusable.
Business continuity strategies are then developed for the high-priority scenarios identified.
Business Continuity Strategy
Following the BIA and risk assessment, an appropriate business continuity strategy is developed for the organisation.
A strategy is not made up of technology infrastructure alone.
The alternatives for a given process might include:
- Working from an alternative location
- Remote working
- A secondary data centre
- Cloud failover
- Backup personnel
- An alternative supplier
- A manual workaround
- A backup communication channel
- An alternative network connection
- Stock of critical equipment
The right strategy is chosen by weighing business impact, cost and the target recovery time together.
What Is a Business Continuity Plan?
A Business Continuity Plan (BCP) defines how the organisation will maintain its critical activities when an interruption occurs.
A business continuity plan is not written for the technical team alone.
A plan typically covers:
- The purpose of the plan
- Scope
- Activation criteria
- Roles and responsibilities
- Contact lists
- Critical processes
- Alternative ways of working
- Escalation procedures
- Recovery steps
- Supplier communication
- Management communication
- Return to normal operation
Disaster Recovery Plan (DRP)
A Disaster Recovery Plan (DRP) focuses largely on bringing IT systems back into service after a major interruption or disaster.
A DRP is an important part of a BCP, but it is not business continuity on its own.
A disaster recovery plan can define:
- Critical systems
- Recovery priorities
- Failover methods
- Use of backups
- The disaster recovery site
- Network access
- DNS changes
- Application dependencies
- Restore procedures
- Technical owners
The Difference Between Business Continuity and Disaster Recovery
Business continuity is the broader concept.
Business continuity focuses on keeping the organisation's critical activities running.
Disaster recovery is concerned largely with recovering technology systems.
A system may be running, but if staff cannot reach the office the process may still be unable to continue.
Business continuity therefore covers
people + process + technology + location + suppliers
in full.
Crisis Management
During a major interruption, a sound decision-making structure matters as much as the technical fix.
ISO 22301 implementations therefore recommend establishing a crisis management team.
A crisis management team can include functions such as:
- Senior management
- IT
- Information security
- Human resources
- Legal
- Corporate communications
- Operations
- Business units
The purpose is to establish in advance who takes which decision during a crisis.
Emergency Communication Plan
Communication is one of the areas that causes most difficulty during an interruption.
Can key personnel be reached?
Who informs customers?
Who issues the press statement?
Who contacts suppliers?
Is notification to regulators required?
Are alternative communication channels available?
These questions have to be answered before a crisis occurs.
SecureSys consulting therefore supports the development of a crisis communication plan or emergency communication plan.
Business Continuity During Cyber Attacks
The cyber security dimension carries particular weight in ISO 22301 projects today.
Ransomware attacks can turn directly into business continuity events.
During a ransomware attack:
- Active Directory may stop
- Email access may be lost
- ERP may become unavailable
- File servers may be encrypted
- Backup systems may be affected
- VPN access may become unusable
Business continuity plans therefore have to include cyber attack scenarios.
Ransomware Business Continuity Plan
Where required, SecureSys consulting projects can produce business continuity and recovery scenarios specific to a ransomware event.
Such work can define steps including:
- Isolation of critical systems
- Alternative communication
- Backup verification
- Clean environment build
- Active Directory recovery
- Reopening the network
- Recovery of priority systems
- Forensic processes
- Crisis communication
The aim is to avoid having to make every decision from scratch during an attack.
Backup and ISO 22301
Backup is an important part of business continuity, but backup alone does not deliver ISO 22301 compliance.
An organisation may have backups and yet:
- Restore testing may not be carried out
- Backups may be deleted by an attacker
- Recovery time may not meet the RTO
- Critical systems may sit outside the backup scope
In SecureSys engagements the backup design is therefore assessed alongside the BIA results and the RTO/RPO targets.
Immutable and Offline Backup
Because of the ransomware threat, immutable backup and offline backup have become increasingly important in business continuity architecture.
Separating backup systems from the production environment, administering them through separate accounts and carrying out regular restore tests are among the critical controls for business continuity.
Data Centre and DR Centre
Some organisations use a secondary data centre or disaster recovery centre for business continuity purposes.
Owning a second data centre does not on its own deliver business continuity, however.
The answers to these questions matter:
- How quickly can the DR centre be brought into service?
- Is replication current?
- Are all critical applications present?
- Is network access working?
- Have DNS processes been tested?
- Can users reach the systems?
- Is there a failback plan?
The DR infrastructure therefore has to be tested regularly.
ISO 22301 Exercises
Business continuity plans should not be held only as documents.
The only way to know whether the plans actually work is to run exercises.
Exercises can be carried out at different levels.
Tabletop exercise
Team decision-making is assessed against a scenario.
Technical recovery test
Backup and recovery processes are tested technically.
Failover test
Moving systems to the DR environment is attempted.
Crisis simulation
A realistic scenario involving several departments is run.
Observations, shortcomings and actions are recorded at the end of each exercise.
ISO 22301 Internal Audit
The effectiveness of an ISO 22301 management system has to be assessed regularly.
The internal audit process is therefore an important stage.
SecureSys consulting can provide internal audit preparation or internal audit support.
An internal audit assesses:
- Conformity with the standard
- Whether documents are actually applied
- The adequacy of records
- Exercises
- Management system performance
Management Review
ISO 22301 should not be run by operational teams alone.
Senior management has to assess the performance of the system at defined intervals.
A management review meeting can address:
- Internal audit results
- Exercise results
- Business continuity incidents
- Risks
- Corrective actions
- Resource requirements
- Changes
- Improvement opportunities
ISO 22301 Certification Readiness
ISO 22301 is a certifiable management system standard.
Once the organisation has established the required system, it can prepare for the audit carried out by an accredited certification body.
SecureSys supports the organisation through:
- Gap analysis
- Documentation
- Implementation support
- BIA
- Risk analysis
- Exercises
- Internal audit
- Management review
- Corrective action
The certification decision and the issuing of the certificate remain the responsibility of the independent certification body.
How Does the ISO 22301 Compliance Process Work?
SecureSys ISO 22301 consulting projects are tailored to the organisation, but generally consist of the following stages:
1. Project initiation and scoping
The scope of the business continuity management system is defined.
2. Gap analysis
The current position is compared against the ISO 22301 requirements.
3. Organisation and context analysis
Internal and external issues and interested parties are assessed.
4. Risk analysis
Risks that could cause an interruption are identified.
5. Business impact analysis (BIA)
Critical processes and the effects of interruption are analysed.
6. Setting RTO/RPO
Recovery objectives are defined.
7. Building the business continuity strategy
Strategies covering people, technology, location and suppliers are developed.
8. Preparing policies and procedures
The ISO 22301 management system documentation is produced.
9. Producing the BCP and DRP
Business continuity and disaster recovery plans are created.
10. Running exercises
The effectiveness of the plans is tested.
11. Internal audit
The management system is assessed.
12. Management review
Senior management assesses system performance.
13. Certification readiness
Preparation for the external audit is completed.
ISO 22301 Consulting Deliverables
Depending on project scope, SecureSys can produce the following deliverables:
- ISO 22301 gap analysis report
- Business continuity policy
- Business impact analysis (BIA)
- Risk assessment report
- RTO/RPO matrix
- Critical process inventory
- Dependency analysis
- Business continuity strategy
- Business Continuity Plan (BCP)
- Disaster Recovery Plan (DRP)
- Crisis management plan
- Crisis communication plan
- Emergency contact lists
- Exercise plan
- Exercise results report
- Corrective action plan
- Supplier continuity assessment
- Internal audit documentation
- Management review documentation
- ISO 22301 compliance matrix
- Certification readiness report
The Difference Between ISO 22301 and ISO 27001
ISO 22301 and ISO/IEC 27001 complement one another but serve different purposes.
ISO 27001 focuses on the information security management system.
It aims to protect the
- Confidentiality
- Integrity
- Availability
of information.
ISO 22301 focuses on the sustainability and recoverability of business processes when an interruption occurs.
An organisation may hold ISO 27001 certification and still have an underdeveloped business continuity structure.
The two standards are therefore often considered together, particularly in organisations delivering critical services.
The Difference Between ISO 22301 and Disaster Recovery
ISO 22301 is not simply disaster recovery.
Disaster recovery focuses largely on bringing technology systems back into service, whereas ISO 22301 addresses a far broader scope, including:
- Business processes
- People
- Location
- Suppliers
- Technology
- Communication
- Crisis management
ISO 22301 and Cyber Resilience
Cyber security and business continuity are increasingly intertwined.
Even where an organisation's security controls cannot prevent an attack outright, the organisation still has to be able to keep operating.
This approach is described as cyber resilience.
Used together, ISO 22301, NIST CSF and ISO 27001 can strengthen an organisation's security and resilience considerably.
ISO 22301 and Supplier Continuity
An organisation's own systems may be robust, and yet operations can still halt when a critical supplier is unable to deliver.
Supplier dependencies therefore have to be assessed as part of ISO 22301.
Particular attention should be paid to:
- Cloud providers
- Telecoms companies
- Data centre service providers
- Logistics companies
- Critical software suppliers
- Outsourced service firms
Why SecureSys for ISO 22301 Consulting?
ISO 22301 consulting is not an exercise in producing template documents.
A genuine business continuity system requires an understanding of the organisation's operational reality.
The SecureSys approach assesses the perspectives of
GRC + cyber security + IT infrastructure + cloud + backup + disaster recovery + risk management
together.
This is what allows business continuity plans to align with the technology estate as it actually is.
Our approach is built on the model:
Analyse → Identify what is critical → Define the objectives → Build the strategy → Plan → Test → Improve
Frequently Asked Questions
What is ISO 22301?
ISO 22301 is the business continuity management system standard covering how organisations maintain their critical activities during interruptions.
What is a business continuity management system?
It is the structure through which an organisation systematically manages its critical processes, interruption risks, recovery objectives and continuity plans.
What is ISO 22301 certification?
Organisations that meet the ISO 22301 requirements can obtain ISO 22301 certification following an audit by an independent certification body.
What is an ISO 22301 gap analysis?
It is the process of establishing the difference between an organisation's existing business continuity arrangements and the ISO 22301 requirements.
What is a BIA?
BIA stands for business impact analysis. It establishes the effects that an interruption to critical business processes would cause.
What is RTO?
RTO expresses how quickly a system or process must be brought back into service after an interruption.
What is RPO?
RPO expresses the maximum acceptable level of data loss during an interruption.
What is a BCP?
A Business Continuity Plan sets out how an organisation will maintain its critical activities during an interruption.
What is a DRP?
A Disaster Recovery Plan defines how critical IT systems will be recovered after a disaster.
Are business continuity and disaster recovery the same thing?
No. Disaster recovery focuses largely on recovering IT systems, whereas business continuity covers the sustainability of all critical business activities.
Which organisations is ISO 22301 suitable for?
It can be applied by public sector, finance, technology, energy, defence, manufacturing, healthcare, retail, telecoms and logistics organisations, and by any organisation delivering critical services.
How long does an ISO 22301 consulting engagement take?
The duration depends on the size of the organisation, the number of locations and processes, existing business continuity maturity and the scope of certification.
Prepare Your Organisation for Interruptions with ISO 22301
You cannot always control whether an interruption occurs.
You can control how well prepared your organisation is for it.
Are your critical processes identified?
Are your RTO and RPO targets defined?
Can your backups actually be restored?
Has your disaster recovery infrastructure been tested?
Do you have an alternative when key staff or suppliers become unavailable?
How quickly could your business resume operating after a cyber attack?
The answers to these questions define your business continuity maturity.
SecureSys supports organisations in becoming more resilient to interruptions through ISO 22301 consulting, ISO 22301 gap analysis, business impact analysis (BIA), business continuity planning (BCP), disaster recovery planning (DRP), RTO/RPO analysis and ISO 22301 certification readiness.
Measure Your Business Continuity Maturity with an ISO 22301 Gap Analysis
Waiting until a crisis has occurred to work out which system or process is critical leaves you too late.
Identify your critical processes first. Measure your tolerance for interruption. Build your recovery strategy. Test your plans.
Request an ISO 22301 Business Continuity Consulting Quote
To assess your organisation's current business continuity maturity, carry out a BIA and build your ISO 22301 compliance roadmap, get in touch with the SecureSys team.
Interruptions may be inevitable. Being unprepared is not.
Want to learn more about this service?
Our expert team will reach out for a free consultation as soon as possible.