Adopts ISO 22313:2012 to provide guidance based on good international practice for planning, establishing, implementing, operating, monitoring, reviewing, maintaining and continually improving a documented management system that enables organizations to prepare for, respond to and recover from disruptive incidents when they arise.
Table of contents
Header
About this publication
Preface
Foreword
Introduction
1 Scope
2 Normative references
3 Terms and definitions
4 Context of the organization
4.1 Understanding of the organization and its context
4.2 Understanding the needs and expectations of interested parties
4.2.1 General
4.2.2 Legal and regulatory requirements
4.3 Determining the scope of the management system
4.3.1 General
4.3.2 Scope of the BCMS
4.4 Business continuity management system
5 Leadership
5.1 Leadership and commitment
5.2 Management commitment
5.3 Policy
5.4 Organizational roles, responsibilities and authorities
6 Planning
6.1 Actions to address risks and opportunities
6.2 Business continuity objectives and plans to achieve them
7 Support
7.1 Resources
7.1.1 General
7.1.2 BCMS resources
7.1.3 Incident response personnel
7.2 Competence
7.3 Awareness
7.4 Communication
7.5 Documented information
7.5.1 General
7.5.2 Create and update
7.5.3 Control of documented information
8 Operation
8.1 Operational planning and control
8.1.1 Elements of BCM
8.1.2 Managing the BCM environment
8.1.3 Maintaining business continuity
8.1.4 Measuring effectiveness
8.1.5 Outcomes
8.2 Business impact analysis and risk assessment
8.2.1 General
8.2.2 Business impact analysis
8.2.3 Risk assessment
8.3 Business continuity strategy
8.3.1 Determination and selection
8.3.1.1 General
8.3.1.2 Protecting prioritized activities
8.3.1.3 Stabilizing, continuing, resuming and recovering prioritized activities
8.3.1.4 Mitigating, responding to and managing impacts
8.3.1.5 Business continuity of suppliers
8.3.2 Establishing resource requirements
8.3.2.1 General
8.3.2.2 People
8.3.2.3 Information and data
8.3.2.4 Buildings, work environment and associated utilities
8.3.2.5 Facilities, equipment and consumables
8.3.2.6 Information communications technology (ICT) systems
8.3.2.7 Transportation
8.3.2.8 Finance
8.3.2.9 Suppliers
8.3.3 Protection and mitigation
8.4 Establish and implement business continuity procedures