Iso 22301 Business Continuity Management PDF
Iso 22301 Business Continuity Management PDF
Iso 22301 Business Continuity Management PDF
Business Continuity
Management System
Ensure continuity of critical business
functions in the event of disruptions
White paper
This white paper provides an overview of ISO 22301, and provides key information in establishing and operating
an effective business continuity management system, as outlined in the standard.
The white paper is intended for all sectors and industries, especially those operating in high risk environment, as
well as business continuity management personnel, including management, information technology engineer and
employees who are involved in implementing or supporting an organisation’s business continuity program.
He is an appointed member of Work Group by the Technical Committee on Security and Privacy
Standards (Information Technology Standard Committee) and helped both InfoComm Development
Authority (IDA) of Singapore and SPRING Singapore to provide technical advisory services to
support the development and review of the Business Continuity / Disaster Recovery standard,
SS 507:2015. Before joining TÜV SÜD, he was with POSBank, providing quality and information
security for the bank’s developed / acquired systems, and its IT and Data Centre operations.
Competence, training and awareness In addition, an organization should Documentation – An organization must
– An effective business continuity identify any training needs associated document, either in paper or electronic
management system is based on the with its efforts to maintain the form, the core elements of its business
competence of all personnel involved. operation of its business continuity continuity management system. The
An organisation must ensure that all management system, and document all documentation shall include:
employees, as well as vendors and training efforts.
suppliers, are knowledgeable about: Scope and boundaries of the
Communication – An organization organisation’s business continuity
Benefits of having well should routinely provide employees management system
established plan and being prepared with information about new and Organisation’s business
Threats / risks and their impacts potential threats / risks that may continuity policy
to business course business disruption, the Business continuity objectives,
Right approach to risk assessment impact of these threats / risks and targets and action plans
and business impact analysis updates on changes / improvement Approach to business
Organisation business continuity its business continuity management impact analysis
strategies and its recovery plans system, and create a process Risk assessment methodology
Objectives and importance of that allows employees and others Business continuity strategy
integrated test and exercise working on its behalf to make Business continuity plan / plans
Importance of conformity with suggestions for improving the Approach for its tests / exercises
the procedures and requirements of system. If an organization decides and their plans
the organisation’s business continuity to provide information about its Documents and records as
management system business continuity policy to external required by ISO 22301
How their activities contribute to audiences, it should establish and Any other documents determined
the achievement of the organisation’s implement an appropriate method to to be necessary for the effective
business continuity goals manage this communication. management the system
The information contained in this document represents the current view of TÜV SÜD on the issues discussed as of the date of publication. Because TÜV SÜD must respond to changing market
conditions, it should not be interpreted to be a commitment on the part of TÜV SÜD, and TÜV SÜD cannot guarantee the accuracy of any information presented after the date of publication. This
White Paper is for informational purposes only. TÜV SÜD makes no warranties, express, implied or statutory, as to the information in this document. Complying with all applicable copyright laws
is the responsibility of the user. Without limiting the rights under copyright, no part of this document may be reproduced, stored in or introduced into a retrieval system, or transmitted in any form
or by any means (electronic, mechanical, photocopying, recording, or otherwise), or for any purpose, without the express written permission of TÜV SÜD. TÜV SÜD may have patents, patent
applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from TÜV SÜD,
the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property. ANY REPRODUCTION, ADAPTATION OR TRANSLATION OF
registered trademark of TÜV SÜD Group.
All reasonable measures have been taken to ensure the quality, reliability, and accuracy of the information in the content. However, TÜV SÜD is not responsible for the third-party content
contained in this newsletter. TÜV SÜD makes no warranties or representations, expressed or implied, as to the accuracy or completeness of information contained in this newsletter. This
newsletter is intended to provide general information on a particular subject or subjects and is not an exhaustive treatment of such subject(s). Accordingly, the information in this newsletter is not
intended to constitute consulting or professional advice or services. If you are seeking advice on any matters relating to information in this newsletter, you should – where appropriate – contact us
directly with your specific query or seek advice from qualified professional people. The information contained in this newsletter may not be copied, quoted, or referred to in any other publication or
materials without the prior written consent of TÜV SÜD. All rights reserved © 2013 TÜV SÜD.