ISO 22301
Security and resilience - Business continuity management systems - Requirements
Overview
Specifies requirements for a business continuity management system (BCMS) to protect against, prepare for, respond to, and recover from disruptive incidents. Essential for maintaining critical operations during cybersecurity incidents.
Applicability
Business continuity and resilience planning for all organizations
Relevance to Network and Information Security Directive (NIS2)
Critical for NIS2 business continuity and disaster recovery requirements for essential/important entities
Key Coverage Areas
Standard Sections & Chapters
Context of the organization
Leadership and commitment
Planning (risk assessment, BIA)
Support and resources
Operation (incident response, recovery)
Performance evaluation
Improvement
Related Network and Information Security Directive (NIS2) Articles
Article I: SECTORS OF HIGH CRITICALITY
View Article →Enhanced business continuity for essential entities
Implementation Guidance:
Critical sectors require certified BCMS with stringent recovery objectives
Article II: OTHER CRITICAL SECTORS
View Article →Business continuity planning
Implementation Guidance:
Establish continuity plans appropriate to sector criticality
Article 20: Governance
View Article →Leadership commitment to business continuity
Implementation Guidance:
Ensure management commitment to resilience and continuity
Article 21: Cybersecurity risk-management measures
View Article →Business continuity as part of risk management
Implementation Guidance:
Include continuity planning in risk treatment
Mapped Obligations:
- Ensure business continuity through backup management and disaster recovery plans
Article 22: Union level coordinated security risk assessments of critical supply chains
View Article →Complete business continuity management system
Implementation Guidance:
Establish BCMS with BIA, continuity strategies, and recovery procedures
Quick Information
- Organization
- ISO
- Category
- Business Continuity
- Certification
- ✓ Available