ISO 22301 Gap Analysis Service Description v2

Download as pdf or txt
Download as pdf or txt
You are on page 1of 5
At a glance
Powered by AI
The key takeaways are that an ISO 22301 gap analysis can help clarify the scope of a BCMS, identify areas for improvement, set project expectations, and develop a business case for implementing an ISO 22301-compliant BCMS.

The two phases of an ISO 22301 gap analysis are: 1) An initial assessment of existing business continuity policies and procedures. 2) A report collating the findings of the assessment.

An ISO 22301 gap analysis report includes: an analysis of BCMS maturity, details of gaps vs ISO 22301 requirements, options for an effective BCMS scope, an action plan, and a clause-by-clause compliance status.

IT Governance

ISO 22301 Gap Analysis


Service Description

Protect ● Comply ● Thrive


Get a true picture of your ISO 22301 compliance posture

IT Governance’s ISO 22301 Gap Analysis service provides an informed


assessment of your organisation’s current level of compliance with ISO 22301 –
the international standard for implementing an effective business continuity
management system (BCMS).

Why conduct an ISO 22301 gap analysis?

An ISO 22301 gap analysis will enable you to:


• Clarify the scope of your BCMS;
• Identify and prioritise key areas for improvement;
• Set informed and realistic project expectations tailored to your
organisation;
• Get the detailed and customised information you need to develop a strong
business case for implementing an ISO 22301-compliant BCMS.

Service description

There are two key phases to the ISO 22301 Gap Analysis service: an initial
assessment of any existing business continuity policies and procedures followed
by a report collating the findings.

Phase 1: Assessment

You will be assigned a business continuity consultant who will assess your
organisation’s continuity policies and procedures against the requirements of
ISO 22301. Key elements of the assessment may involve:
• A desk-based review of the key continuity policies and procedures;
• An inspection of the operation of key processes, systems and
documentation; and
• Interviews with key staff, covering the existing processes and procedures
in place and initiatives currently underway and comparing these to the
following requirements of ISO 22301:

Clause Component

Understanding of the organisation and its context


4 Context of the Understanding the needs and expectations of interested
organisation parties

Determining the scope of the BCMS

Business continuity management system

Leadership and commitment


5 Leadership Management commitment

Policy

Organisational roles, responsibilities and authorities

© IT Governance Ltd 2017 Service Description Template


6 Planning Actions to be address risks and opportunities

Business continuity objectives and plans to achieve


them

Resources

Competence
7 Support
Awareness

Communication

Documented information

Operational planning and control

Business impact analysis and risk assessment


8 Operation
Business continuity strategy

Establish and implement business continuity procedures

Exercising and testing

9 Performance Monitoring, measurement, analysis and evaluation


evaluation Internal audit

Management review

10 Improvement Nonconformity and corrective action

Continual improvement

Phase 2: Report

The ISO 22301 gap analysis report collates the findings of the gap analysis and
details the extent to which your organisation complies with the requirements of
ISO 22301.

The report will include:


• An analysis of the overall state and maturity of your business continuity
arrangements;
• Specific details of the gaps between your current business continuity
arrangements and the requirements of ISO 22301;
• Options for the scope of an effective ISO 22301-compliant BCMS, and how
these options help to meet your business and strategic objectives;
• An action plan that outlines the level of internal management effort
required to implement and maintain an ISO 22301-compliant BCMS; and
• A clause-by-clause compliance status report (red/amber/green) against
the requirements of ISO 22301:2012.

Eligibility

© IT Governance Ltd 2017 Service Description Template


This service has been designed for organisations with up to 250 employees and
that have all key personnel based at a single site. This service can be delivered
to organisations in any sector or industry.

If your organisation falls outside the eligibility criteria, IT Governance offers


bespoke services that can be tailored to suit your needs.

Resource requirements

To ensure your project can proceed according to schedule and fulfil its
objectives, you will be asked to provide essential information on documents and
procedures in relation to any current BCMS arrangements.

These requests should be treated with the appropriate priority to carry out the
gap analysis service effectively and according to schedule. These requests will be
managed to minimise disruption as much as possible.

You will also need to appoint an internal project coordinator to host any
meetings with the consultant and ensure all the required information is provided
on time, and tasks and actions allocated to your staff are carried out as agreed.

Consultancy fee

We will invoice you for your project on signature. There are two payment
options: you may choose to pay the full amount over two instalments (including
a 10% fee) or you can save 10% by paying the advertised standard fee.

For the instalment option, the first invoice will be issued upon signature, while
the second invoice will be raised one month later. Payment is due within 28 days
of invoice date.

The price excludes any additional expenses such as travel, accommodation and
sustenance if needed.

Why choose IT Governance?


• Our consultants have extensive experience implementing ISO 22301-
compliant BCMSs.
• Receive a 100% guarantee of successful certification.
• We have a proven and pragmatic approach to assessing compliance with
international standards, no matter the size or nature of the organisation.
• Our pricing proposals are completely transparent, so you won’t get any
surprises.

© IT Governance Ltd 2017 Service Description Template


• You will receive expert advice and guidance from our consultant from the
outset to help you develop a business case, allowing you to secure the
necessary leadership commitment and investment.

Contact us now for an obligation-free quote

Email: [email protected]
Call us: +44 (0)333 800 7000
Request a call back: Contact us now

© IT Governance Ltd 2017 Service Description Template

You might also like