731 901 601
What happens when a company ceases to operate? ISO 22301 and business continuity management

What happens when a company ceases to operate? ISO 22301 and business continuity management

A fire in the server room, a ransomware attack, a pandemic, a flood, a failure of a key supplier – any of these events can bring a company’s operations to a standstill within a matter of hours if it is unprepared. ISO 22301 is a standard that changes the approach to such scenarios: rather than reacting to a crisis in chaos, an organisation manages it according to pre-planned and tested procedures. Business continuity ceases to be a matter of luck and becomes a matter of system.

What is ISO 22301 and where does it come from?

ISO 22301 (full title: ‘Security and resilience – Business continuity management systems – Requirements’) is an international standard developed by ISO in response to growing interest in the British standard BS 25999-2. It is the first international standard designed to help organisations maintain their operations in crisis situations. The current version is ISO 22301:2019, which replaced the 2012 edition and introduces a stronger link to a risk-based approach, as well as greater consistency with other management system standards based on the High Level Structure.

The standard is aimed at all organisations – private, public and non-profit – regardless of sector, size or legal form. The guidelines of ISO 22301 govern all processes relating to the management of an organisation’s resources, ensuring their protection and a rapid return to normality in the event of critical incidents. ISO 22301 certification is voluntary; however, it is increasingly required by business partners, financial institutions and regulatory bodies as evidence of organisational maturity.

Key terms – BIA, RTO and RPO

Understanding ISO 22301 requires knowledge of several terms that form the foundation of the entire business continuity management system.

BIA (Business Impact Analysis) – an analysis of the impact on business operations. It is a process of identifying critical business processes and assessing the consequences of their interruption over time. A BIA answers the question: which processes are essential to the organisation’s survival, and what would happen if they ceased to function for an hour, a day or a week? The results of the BIA form the basis of the entire business continuity strategy – without a thorough impact analysis, recovery priorities cannot be properly established.

RTO (Recovery Time Objective) – the maximum acceptable time for restoring a given process or system following an incident. If the RTO for the order processing system is 4 hours, this means that the organisation cannot tolerate a longer interruption to its operation without serious business consequences. The RTO sets the target for recovery plans.

RPO (Recovery Point Objective) – the maximum acceptable period of data loss, expressed in time. If the RPO for a customer database is 1 hour, the organisation must ensure that backups are taken at least every hour. The RPO sets out the requirements for data backup and replication systems.

These three parameters – BIA, RTO and RPO – form the backbone of a business continuity strategy and must be defined, documented and regularly reviewed as part of a management system compliant with ISO 22301.

System structure – from policy to testing

ISO 22301 is structured in accordance with the High Level Structure, making it compatible with ISO 9001, ISO 27001, ISO 45001 and other management system standards. The standard’s requirements cover several key elements:

Business continuity policy and objectives – management must establish and communicate a business continuity policy, set measurable objectives and provide the resources necessary to achieve them. ISO 22301 requires the explicit commitment of top management – it is not sufficient to delegate responsibility to the IT team or the risk management department.

Risk assessment and BIA – the organisation must identify threats that could disrupt its operations and carry out a Business Impact Analysis (BIA). The results of both analyses must be documented and regularly updated.

Business Continuity Plans (BCPs) – documented procedures describing how the organisation will operate during an incident and how it will restore normal operations. The plans must be realistic, known to key personnel and regularly tested.

Testing and exercises – this is one of the most important elements of the system. The standard requires regular testing of continuity plans through exercises and simulations, analysing the results and updating the plans accordingly. A plan that has never been tested is a plan that will not work in a crisis.

ISO 22301 and legal regulations and sector-specific requirements

For an increasing number of organisations, ISO 22301 is no longer a choice but is becoming a requirement arising from the regulatory or contractual environment.

The DORA Regulation, which comes into force in January 2025, imposes stringent requirements on financial institutions and their ICT service providers regarding operational resilience, business continuity planning and the testing of contingency plans. ISO 22301 is one of the most effective tools for demonstrating compliance with these requirements. The NIS2 Directive imposes similar requirements on operators of critical and important services across many sectors – including energy, transport, healthcare and digital infrastructure.

Beyond regulatory requirements, the need to hold ISO 22301 certification or to have a documented business continuity management system is increasingly appearing in public tender specifications and in the eligibility criteria of major business partners – particularly in sectors where a disruption to supplies or services poses a serious risk to the value chain.

 

Read other posts

ISO 42001 – everything you need to know about the first AI management standard

ISO 42001 – everything you need to know about the first AI management standard

Artificial intelligence has entered the day-to-day operations of businesses faster than legal frameworks and standards have been able to keep up with it. read more
Cold stores run round the clock. Bakery ovens are on from 3 a.m. ISO 50001 in food production is a whole different ball game.

Cold stores run round the clock. Bakery ovens are on from 3 a.m. ISO 50001 in food production is a whole different ball game.

The food industry has one of the highest shares of energy costs in its production cost structure. read more
Three companies, one flood – why only one resumed operations within 48 hours

Three companies, one flood – why only one resumed operations within 48 hours

July 2024. Three days of torrential rain turn an industrial hub into one vast lake. Three companies operating in the same business park are flooded: an electronics manufacturer, a logistics firm and an IT service provider. read more
More posts