INTERNATIONAL ISO This Is A Preview Of ISO 22301:2019 .

Transcription

ISOINTERNATIONALThis is a preview of "ISO 22301:2019". Click here to purchase the full version from the ANSI store.22301STANDARDSecond edition2019-10Security and resilience — Businesscontinuity management systems —RequirementsSécurité et résilience — Systèmes de management de la continuitéd'activité — ExigencesReference numberISO 22301:2019(E) ISO 2019

ISO 22301:2019(E) This is a preview of "ISO 22301:2019". Click here to purchase the full version from the ANSI store.COPYRIGHT PROTECTED DOCUMENT ISO 2019All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication maybe reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or postingon the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the addressbelow or ISO’s member body in the country of the requester.ISO copyright officeCP 401 Ch. de Blandonnet 8CH-1214 Vernier, GenevaPhone: 41 22 749 01 11Fax: 41 22 749 09 47Email: copyright@iso.orgWebsite: www.iso.orgPublished in Switzerlandii ISO 2019 – All rights reserved

ISO 22301:2019(E) This is a preview of "ISO 22301:2019". Click here to purchase the full version from the ANSI store.Contents PageForeword.vIntroduction. vi12345678Scope. 1Normative references. 1Terms and definitions. 1Context of the organization. 74.1Understanding the organization and its context. 74.2Understanding the needs and expectations of interested parties. 74.2.1General. 74.2.2Legal and regulatory requirements. 74.3Determining the scope of the business continuity management system. 74.3.1General. 74.3.2Scope of the business continuity management system. 84.4Business continuity management system. 8Leadership. 85.1Leadership and commitment. 85.2Policy. 85.2.1Establishing the business continuity policy. 85.2.2Communicating the business continuity policy. 95.3Roles, responsibilities and authorities. 9Planning. 96.1Actions to address risks and opportunities. 96.1.1Determining risks and opportunities. 96.1.2Addressing risks and opportunities. 96.2Business continuity objectives and planning to achieve them. 96.2.1Establishing business continuity objectives. 96.2.2Determining business continuity objectives. 106.3Planning changes to the business continuity management system. 10Support. 107.1Resources. 107.2Competence. 107.3Awareness. 117.4Communication. 117.5Documented information. 117.5.1General. 117.5.2Creating and updating. 117.5.3Control of documented information. 12Operation. 128.1Operational planning and control. 128.2Business impact analysis and risk assessment. 128.2.1General. 128.2.2Business impact analysis. 138.2.3Risk assessment. 138.3Business continuity strategies and solutions. 138.3.1General. 138.3.2Identification of strategies and solutions. 138.3.3Selection of strategies and solutions. 148.3.4Resource requirements. 148.3.5Implementation of solutions. 148.4Business continuity plans and procedures. 148.4.1General. 14 ISO 2019 – All rights reserved iii

ISO 22301:2019(E) This is a preview of "ISO 22301:2019". Click here to purchase the full version from the ANSI store.9108.58.68.4.2Response structure. 158.4.3Warning and communication. 158.4.4Business continuity plans. 168.4.5Recovery. 17Exercise programme. 17Evaluation of business continuity documentation and capabilities. 17Performance evaluation.179.1Monitoring, measurement, analysis and evaluation. 179.2Internal audit. 189.2.1General. 189.2.2Audit programme(s). 189.3Management review. 189.3.1General. 189.3.2Management review input. 189.3.3Management review outputs. 19Improvement.1910.1 Nonconformity and corrective action. 1910.2 Continual improvement. 20Bibliography. 21iv ISO 2019 – All r

ISO 22301:2019(E) This document does not include requirements specific to other management systems, though its elements can be aligned or integrated with those of other management systems. This document contains requirements that can be used by an organization to implement a BCMS and to assess conformity. An organization that wishes to demonstrate conformity to this document can do so