SlideShare a Scribd company logo
Comparison of ISO 22301 and BS 25999-2
Business Continuity Management Standards
Headline Differences
enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
What is in this Slide Pack?
 What is ISO 22301?
 Key features of ISO 22301
 How does it compare with BS 25999-2?
 What’s new in ISO 22301 vs BS 25999-2
 Support in implementing ISO 22301
What is ISO 22301?
enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
What is ISO 22301?
• ISO 22301 is the International Standard for Business
Continuity Management Systems – Requirements
• It encapsulates international business continuity best
practice into a specification of requirements for planning
and implementing a business continuity management
system (BCMS)
• Organisations wishing to certify their BCMS will be
externally audited against the requirements in ISO
22301
What is ISO 22301?
• ISO 22301 is supported by a Guidance document
published as a separate Standard, ISO 22313
• Both Standards were developed by Technical
Committee 223 – Societal Security (ISO TC 223) of the
International Standards Organisation
• ISO 22301 was published May 2012
• ISO 22313 was published December 2012
Key Features of ISO 22301
enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
Performance Evaluation
Support
Context of the Organisation
Planning
Operation
Leadership
Improvement
4
5
6
7
8
9
10
Key Features of ISO 22301
• Amalgamation of National BC Standards
• Enables global organisations to apply one Standard
• Conforms to ISO’s new Management Systems 10 clause structure
(Annex SL) which will guide all future Standards:
Scope, References, Definitions
1,2
3
How does ISO 22301 compare to BS 25999-2?
BS 25999-2 – Withdrawn; transition period to June 2014
BS 25999-1 – Withdrawn
enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
ISO 22301 vs BS 25999-2
• BS 25999 was the key reference for the business
continuity content of ISO 22301
• The BC-specific requirements are mainly in Clause 8;
the other clauses relate to operational planning and
management of the system
• The BC requirements eg BIA/RA are largely the same
as in BS 25999 but with some some changes in
terminology and emphasis, such as supply chain
continuity
• 105 shall’s in 22301 vs 56 in 25999
ISO 22301 vs BS 25999-2
The next slide maps the clauses of ISO 22301 against the
Business Continuity Lifecycle in BS 25999-2
8.2
BIA and RA
8.3
BC Strategy
Risk Treatment
8.4
Plans
8.5
Exercising & Testing
7.2 Competence
7.3 Awareness
Clauses 4, 5, 6, 7, 8.1, 9 & 10
What’s New in ISO 22301 vs BS 25999-2?
enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
What’s New in ISO 22301?
• Formal requirements (Clause 4) to define and document
the context of the organisation to ensure the BCMS is
relevant to it
• Context considers such things as defining what the
organisation does, its strategic objectives, what are the
risks and opportunities it faces, what’s its risk appetite,
what is it dependent on, who does it influence, what
regulatory requirements does it have to meet
What’s New in ISO 22301?
• More specific requirements (Clause 5) for leadership
and ongoing commitment to implementation of the
BCMS by senior management
• More clarity around setting realistic and measurable BC
objectives and how they will be achieved
• Much of the ‘embedding’ part of BS 25999 is met by the
competency and awareness requirements in clause 7.
What’s New in ISO 22301?
• A new clause (7.4) on communication with internal and
external interested parties during disruption: who, what,
when, how (testing of communication capability and
interoperability required)?
• A new clause (8.4.3) on Warning and Communication
throughout the incident lifecycle. How will an incident be
detected and monitored, how will people be told about it,
how will information and decisions be recorded
What’s New in ISO 22301?
• A short but significant new requirement for recovery
plans (8.4.5) detailing how activities will return from their
temporary state post-incident to normal (or new normal)
eg movement back from a recovery site to the office
• A new clause (9) on Performance Evaluation of the
whole BCMS – are we doing what we said we would do,
is it doing what we want it to do, how do we know, does
anything need updating, changing? Includes the Internal
Audit and Management Reviews requirements from BS
25999
The New ISO BCM Lifecycle
source ISO 22313
What Steelhenge can do to assist you
• Advice and support in implementing ISO 22301
• Transitioning from BS 25999-2 to ISO 22301
• Gap analysis and reviews of your BCMS
requirements
• Implementing a full BCMS
• Assisting you with parts of the BCMS such as BIAs,
training and exercising
enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
www.steelhenge.co.uk
enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117

More Related Content

What's hot

PCI DSS Compliance Checklist
PCI DSS Compliance ChecklistPCI DSS Compliance Checklist
PCI DSS Compliance Checklist
ControlCase
 
PwC Point of View on Cybersecurity Management
PwC Point of View on Cybersecurity ManagementPwC Point of View on Cybersecurity Management
PwC Point of View on Cybersecurity Management
CA Technologies
 
What is an ITGP Documentation Toolkit?
What is an ITGP Documentation Toolkit?What is an ITGP Documentation Toolkit?
What is an ITGP Documentation Toolkit?
IT Governance Ltd
 
Integrated Security Operations Center (ISOC) for Cybersecurity Collaboration
Integrated Security Operations Center (ISOC) for Cybersecurity CollaborationIntegrated Security Operations Center (ISOC) for Cybersecurity Collaboration
Integrated Security Operations Center (ISOC) for Cybersecurity Collaboration
Priyanka Aash
 
Definisi dan Metode Business Impact Analysis (BIA) dan Risk Assessment (RA) _...
Definisi dan Metode Business Impact Analysis (BIA) dan Risk Assessment (RA) _...Definisi dan Metode Business Impact Analysis (BIA) dan Risk Assessment (RA) _...
Definisi dan Metode Business Impact Analysis (BIA) dan Risk Assessment (RA) _...
Kanaidi ken
 
Presentation on iso 27001-2013, Internal Auditing and BCM
Presentation on iso 27001-2013, Internal Auditing and BCMPresentation on iso 27001-2013, Internal Auditing and BCM
Presentation on iso 27001-2013, Internal Auditing and BCM
Shantanu Rai
 
Présentation Méthode EBIOS Risk Manager
Présentation Méthode EBIOS Risk ManagerPrésentation Méthode EBIOS Risk Manager
Présentation Méthode EBIOS Risk Manager
Comsoce
 
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and DifferencesCMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
PECB
 
SOC 2 Compliance and Certification
SOC 2 Compliance and CertificationSOC 2 Compliance and Certification
SOC 2 Compliance and Certification
ControlCase
 
Cybersecurity roadmap : Global healthcare security architecture
Cybersecurity roadmap : Global healthcare security architectureCybersecurity roadmap : Global healthcare security architecture
Cybersecurity roadmap : Global healthcare security architecture
Priyanka Aash
 
Helping Utilities with Cybersecurity Preparedness: The C2M2
Helping Utilities with Cybersecurity Preparedness: The C2M2Helping Utilities with Cybersecurity Preparedness: The C2M2
Helping Utilities with Cybersecurity Preparedness: The C2M2
Smart Grid Interoperability Panel
 
Nist.sp.800 61r2
Nist.sp.800 61r2Nist.sp.800 61r2
Nist.sp.800 61r2
Jesús Yustas Romo
 
Conix - EBIOS Risk Manager
Conix - EBIOS Risk ManagerConix - EBIOS Risk Manager
Conix - EBIOS Risk Manager
Thierry Pertus
 
Как построить SOC?
Как построить SOC?Как построить SOC?
Как построить SOC?
Aleksey Lukatskiy
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
PECB
 
Infographic: Symantec Healthcare IT Security Risk Management Study
Infographic: Symantec Healthcare IT Security Risk Management StudyInfographic: Symantec Healthcare IT Security Risk Management Study
Infographic: Symantec Healthcare IT Security Risk Management Study
CheapSSLsecurity
 
Guide ANSSI : 40 règles d'hygiène informatique en 13 images de questions dig...
Guide ANSSI :  40 règles d'hygiène informatique en 13 images de questions dig...Guide ANSSI :  40 règles d'hygiène informatique en 13 images de questions dig...
Guide ANSSI : 40 règles d'hygiène informatique en 13 images de questions dig...
Eric DUPUIS
 
Déclaration d'applicabilité (DdA) - ISO27002:2013
Déclaration d'applicabilité (DdA) - ISO27002:2013Déclaration d'applicabilité (DdA) - ISO27002:2013
Déclaration d'applicabilité (DdA) - ISO27002:2013
Bachir Benyammi
 
Cyber Security and Business Continuity an Integrated Discipline
Cyber Security and Business Continuity an Integrated DisciplineCyber Security and Business Continuity an Integrated Discipline
Cyber Security and Business Continuity an Integrated Discipline
Graeme Parker
 
Cybersecurity Incident Management Powerpoint Presentation Slides
Cybersecurity Incident Management Powerpoint Presentation SlidesCybersecurity Incident Management Powerpoint Presentation Slides
Cybersecurity Incident Management Powerpoint Presentation Slides
SlideTeam
 

What's hot (20)

PCI DSS Compliance Checklist
PCI DSS Compliance ChecklistPCI DSS Compliance Checklist
PCI DSS Compliance Checklist
 
PwC Point of View on Cybersecurity Management
PwC Point of View on Cybersecurity ManagementPwC Point of View on Cybersecurity Management
PwC Point of View on Cybersecurity Management
 
What is an ITGP Documentation Toolkit?
What is an ITGP Documentation Toolkit?What is an ITGP Documentation Toolkit?
What is an ITGP Documentation Toolkit?
 
Integrated Security Operations Center (ISOC) for Cybersecurity Collaboration
Integrated Security Operations Center (ISOC) for Cybersecurity CollaborationIntegrated Security Operations Center (ISOC) for Cybersecurity Collaboration
Integrated Security Operations Center (ISOC) for Cybersecurity Collaboration
 
Definisi dan Metode Business Impact Analysis (BIA) dan Risk Assessment (RA) _...
Definisi dan Metode Business Impact Analysis (BIA) dan Risk Assessment (RA) _...Definisi dan Metode Business Impact Analysis (BIA) dan Risk Assessment (RA) _...
Definisi dan Metode Business Impact Analysis (BIA) dan Risk Assessment (RA) _...
 
Presentation on iso 27001-2013, Internal Auditing and BCM
Presentation on iso 27001-2013, Internal Auditing and BCMPresentation on iso 27001-2013, Internal Auditing and BCM
Presentation on iso 27001-2013, Internal Auditing and BCM
 
Présentation Méthode EBIOS Risk Manager
Présentation Méthode EBIOS Risk ManagerPrésentation Méthode EBIOS Risk Manager
Présentation Méthode EBIOS Risk Manager
 
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and DifferencesCMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
CMMC, ISO/IEC 27701, and ISO/IEC 27001 — Best Practices and Differences
 
SOC 2 Compliance and Certification
SOC 2 Compliance and CertificationSOC 2 Compliance and Certification
SOC 2 Compliance and Certification
 
Cybersecurity roadmap : Global healthcare security architecture
Cybersecurity roadmap : Global healthcare security architectureCybersecurity roadmap : Global healthcare security architecture
Cybersecurity roadmap : Global healthcare security architecture
 
Helping Utilities with Cybersecurity Preparedness: The C2M2
Helping Utilities with Cybersecurity Preparedness: The C2M2Helping Utilities with Cybersecurity Preparedness: The C2M2
Helping Utilities with Cybersecurity Preparedness: The C2M2
 
Nist.sp.800 61r2
Nist.sp.800 61r2Nist.sp.800 61r2
Nist.sp.800 61r2
 
Conix - EBIOS Risk Manager
Conix - EBIOS Risk ManagerConix - EBIOS Risk Manager
Conix - EBIOS Risk Manager
 
Как построить SOC?
Как построить SOC?Как построить SOC?
Как построить SOC?
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
 
Infographic: Symantec Healthcare IT Security Risk Management Study
Infographic: Symantec Healthcare IT Security Risk Management StudyInfographic: Symantec Healthcare IT Security Risk Management Study
Infographic: Symantec Healthcare IT Security Risk Management Study
 
Guide ANSSI : 40 règles d'hygiène informatique en 13 images de questions dig...
Guide ANSSI :  40 règles d'hygiène informatique en 13 images de questions dig...Guide ANSSI :  40 règles d'hygiène informatique en 13 images de questions dig...
Guide ANSSI : 40 règles d'hygiène informatique en 13 images de questions dig...
 
Déclaration d'applicabilité (DdA) - ISO27002:2013
Déclaration d'applicabilité (DdA) - ISO27002:2013Déclaration d'applicabilité (DdA) - ISO27002:2013
Déclaration d'applicabilité (DdA) - ISO27002:2013
 
Cyber Security and Business Continuity an Integrated Discipline
Cyber Security and Business Continuity an Integrated DisciplineCyber Security and Business Continuity an Integrated Discipline
Cyber Security and Business Continuity an Integrated Discipline
 
Cybersecurity Incident Management Powerpoint Presentation Slides
Cybersecurity Incident Management Powerpoint Presentation SlidesCybersecurity Incident Management Powerpoint Presentation Slides
Cybersecurity Incident Management Powerpoint Presentation Slides
 

Viewers also liked

The BCI GPG Presentation @ The BCI
The BCI GPG Presentation @ The BCI The BCI GPG Presentation @ The BCI
The BCI GPG Presentation @ The BCI
Muhammad Ghazali MBCI, ISO22301 LA, CRISC, BCM Trainer
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
alanlund
 
Crisis Communications_Plans and Exercises
Crisis Communications_Plans and ExercisesCrisis Communications_Plans and Exercises
Crisis Communications_Plans and Exercises
ReginaPhelps
 
ISO 22301 Business Continuity Management
ISO 22301 Business Continuity ManagementISO 22301 Business Continuity Management
ISO 22301 Business Continuity Management
Ramiro Cid
 
Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery Presentation
TimSchaefer
 
An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery Planning
NEBizRecovery
 
The A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoveryThe A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster Recovery
Sirius
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
hhuihhui
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
Narudom Roongsiriwong, CISSP
 
ISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best Practice
MissionMode
 
Crisis management - Types and Examples
Crisis management - Types and ExamplesCrisis management - Types and Examples
Crisis management - Types and Examples
Nupur Bhardwaj
 

Viewers also liked (11)

The BCI GPG Presentation @ The BCI
The BCI GPG Presentation @ The BCI The BCI GPG Presentation @ The BCI
The BCI GPG Presentation @ The BCI
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Crisis Communications_Plans and Exercises
Crisis Communications_Plans and ExercisesCrisis Communications_Plans and Exercises
Crisis Communications_Plans and Exercises
 
ISO 22301 Business Continuity Management
ISO 22301 Business Continuity ManagementISO 22301 Business Continuity Management
ISO 22301 Business Continuity Management
 
Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery Presentation
 
An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery Planning
 
The A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoveryThe A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster Recovery
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
ISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best Practice
 
Crisis management - Types and Examples
Crisis management - Types and ExamplesCrisis management - Types and Examples
Crisis management - Types and Examples
 

Similar to Comparison of ISO 22301 with BS 25999

iso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdfiso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
VictorNagesparan
 
tuvsud-ISO-9001-2015-guidance.pdf
tuvsud-ISO-9001-2015-guidance.pdftuvsud-ISO-9001-2015-guidance.pdf
tuvsud-ISO-9001-2015-guidance.pdf
HalaGhaziAyoub
 
CMMI for Services v2.0 Changes, Practice Areas, Appraisals
CMMI for Services v2.0 Changes, Practice Areas, AppraisalsCMMI for Services v2.0 Changes, Practice Areas, Appraisals
CMMI for Services v2.0 Changes, Practice Areas, Appraisals
Integration Technologies Group Inc
 
Smu mba sem 4 tqm fall 2016 assignments
Smu mba sem 4 tqm fall 2016 assignmentsSmu mba sem 4 tqm fall 2016 assignments
Smu mba sem 4 tqm fall 2016 assignments
solved_assignments
 
Business Continuity Audit
Business Continuity AuditBusiness Continuity Audit
Iso 2008 vs 2015
Iso 2008 vs 2015Iso 2008 vs 2015
Iso 2008 vs 2015
Haya Haroon
 
ISO 9001:2015 Overview: Revisions & Impact - Part 1
ISO 9001:2015 Overview: Revisions & Impact - Part 1ISO 9001:2015 Overview: Revisions & Impact - Part 1
ISO 9001:2015 Overview: Revisions & Impact - Part 1
DQS Inc.
 
Gap Analysis | ISO 22301 | BCMS | By Industry Experts
Gap Analysis | ISO 22301 | BCMS | By Industry ExpertsGap Analysis | ISO 22301 | BCMS | By Industry Experts
Gap Analysis | ISO 22301 | BCMS | By Industry Experts
himalya sharma
 
Achieving IT Governance and compliance using Kovair
Achieving IT Governance and compliance using KovairAchieving IT Governance and compliance using Kovair
Achieving IT Governance and compliance using Kovair
Kovair
 
How to effectively use ISO 27001 Certification and SOC 2 Reports
How to effectively use ISO 27001 Certification and SOC 2 ReportsHow to effectively use ISO 27001 Certification and SOC 2 Reports
How to effectively use ISO 27001 Certification and SOC 2 Reports
Salvi Jansen
 
ISO 9001 2015 highlight of changes
ISO 9001 2015 highlight of changesISO 9001 2015 highlight of changes
ISO 9001 2015 highlight of changes
Bywater Training
 
Business Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewBusiness Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An Overview
Ahmed Riad .
 
Benefits of Integrating ISO and CMMI Service Management System Frameworks
Benefits of Integrating ISO and CMMI Service Management System FrameworksBenefits of Integrating ISO and CMMI Service Management System Frameworks
Benefits of Integrating ISO and CMMI Service Management System Frameworks
Integration Technologies Group Inc
 
Business Continuity Management & ISO 22301
Business Continuity Management & ISO 22301Business Continuity Management & ISO 22301
Business Continuity Management & ISO 22301
IT Governance Ltd
 
Transition to ISO 9001:2015
Transition to ISO 9001:2015Transition to ISO 9001:2015
Transition to ISO 9001:2015
PECB
 
Babo kv2.0
Babo kv2.0Babo kv2.0
Babo kv2.0
Rahul Rathore
 
Babok v2.0
Babok v2.0Babok v2.0
Introduction to ISO29110
Introduction to ISO29110Introduction to ISO29110
Introduction to ISO29110
Krit Kamtuo
 
Iso
IsoIso
ISO 22000 2018 -- what has changed
ISO 22000   2018 -- what has changedISO 22000   2018 -- what has changed

Similar to Comparison of ISO 22301 with BS 25999 (20)

iso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdfiso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
 
tuvsud-ISO-9001-2015-guidance.pdf
tuvsud-ISO-9001-2015-guidance.pdftuvsud-ISO-9001-2015-guidance.pdf
tuvsud-ISO-9001-2015-guidance.pdf
 
CMMI for Services v2.0 Changes, Practice Areas, Appraisals
CMMI for Services v2.0 Changes, Practice Areas, AppraisalsCMMI for Services v2.0 Changes, Practice Areas, Appraisals
CMMI for Services v2.0 Changes, Practice Areas, Appraisals
 
Smu mba sem 4 tqm fall 2016 assignments
Smu mba sem 4 tqm fall 2016 assignmentsSmu mba sem 4 tqm fall 2016 assignments
Smu mba sem 4 tqm fall 2016 assignments
 
Business Continuity Audit
Business Continuity AuditBusiness Continuity Audit
Business Continuity Audit
 
Iso 2008 vs 2015
Iso 2008 vs 2015Iso 2008 vs 2015
Iso 2008 vs 2015
 
ISO 9001:2015 Overview: Revisions & Impact - Part 1
ISO 9001:2015 Overview: Revisions & Impact - Part 1ISO 9001:2015 Overview: Revisions & Impact - Part 1
ISO 9001:2015 Overview: Revisions & Impact - Part 1
 
Gap Analysis | ISO 22301 | BCMS | By Industry Experts
Gap Analysis | ISO 22301 | BCMS | By Industry ExpertsGap Analysis | ISO 22301 | BCMS | By Industry Experts
Gap Analysis | ISO 22301 | BCMS | By Industry Experts
 
Achieving IT Governance and compliance using Kovair
Achieving IT Governance and compliance using KovairAchieving IT Governance and compliance using Kovair
Achieving IT Governance and compliance using Kovair
 
How to effectively use ISO 27001 Certification and SOC 2 Reports
How to effectively use ISO 27001 Certification and SOC 2 ReportsHow to effectively use ISO 27001 Certification and SOC 2 Reports
How to effectively use ISO 27001 Certification and SOC 2 Reports
 
ISO 9001 2015 highlight of changes
ISO 9001 2015 highlight of changesISO 9001 2015 highlight of changes
ISO 9001 2015 highlight of changes
 
Business Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewBusiness Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An Overview
 
Benefits of Integrating ISO and CMMI Service Management System Frameworks
Benefits of Integrating ISO and CMMI Service Management System FrameworksBenefits of Integrating ISO and CMMI Service Management System Frameworks
Benefits of Integrating ISO and CMMI Service Management System Frameworks
 
Business Continuity Management & ISO 22301
Business Continuity Management & ISO 22301Business Continuity Management & ISO 22301
Business Continuity Management & ISO 22301
 
Transition to ISO 9001:2015
Transition to ISO 9001:2015Transition to ISO 9001:2015
Transition to ISO 9001:2015
 
Babo kv2.0
Babo kv2.0Babo kv2.0
Babo kv2.0
 
Babok v2.0
Babok v2.0Babok v2.0
Babok v2.0
 
Introduction to ISO29110
Introduction to ISO29110Introduction to ISO29110
Introduction to ISO29110
 
Iso
IsoIso
Iso
 
ISO 22000 2018 -- what has changed
ISO 22000   2018 -- what has changedISO 22000   2018 -- what has changed
ISO 22000 2018 -- what has changed
 

Recently uploaded

The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...
Adam Smith
 
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdfikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
agatadrynko
 
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s DholeraTata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Avirahi City Dholera
 
Mastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnapMastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnap
Norma Mushkat Gaffin
 
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta MatkaDpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...
Adam Smith
 
Structural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for BuildingsStructural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for Buildings
Chandresh Chudasama
 
buy old yahoo accounts buy yahoo accounts
buy old yahoo accounts buy yahoo accountsbuy old yahoo accounts buy yahoo accounts
buy old yahoo accounts buy yahoo accounts
Susan Laney
 
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
SOFTTECHHUB
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
Adnet Communications
 
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
my Pandit
 
BeMetals Investor Presentation_June 1, 2024.pdf
BeMetals Investor Presentation_June 1, 2024.pdfBeMetals Investor Presentation_June 1, 2024.pdf
BeMetals Investor Presentation_June 1, 2024.pdf
DerekIwanaka1
 
Creative Web Design Company in Singapore
Creative Web Design Company in SingaporeCreative Web Design Company in Singapore
Creative Web Design Company in Singapore
techboxsqauremedia
 
Observation Lab PowerPoint Assignment for TEM 431
Observation Lab PowerPoint Assignment for TEM 431Observation Lab PowerPoint Assignment for TEM 431
Observation Lab PowerPoint Assignment for TEM 431
ecamare2
 
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdfModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
fisherameliaisabella
 
Chapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .pptChapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .ppt
ssuser567e2d
 
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
AnnySerafinaLove
 
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
bosssp10
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
JeremyPeirce1
 
Business storytelling: key ingredients to a story
Business storytelling: key ingredients to a storyBusiness storytelling: key ingredients to a story
Business storytelling: key ingredients to a story
Alexandra Fulford
 

Recently uploaded (20)

The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...
 
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdfikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
 
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s DholeraTata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
 
Mastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnapMastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnap
 
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta MatkaDpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
 
The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...
 
Structural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for BuildingsStructural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for Buildings
 
buy old yahoo accounts buy yahoo accounts
buy old yahoo accounts buy yahoo accountsbuy old yahoo accounts buy yahoo accounts
buy old yahoo accounts buy yahoo accounts
 
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
Hamster Kombat' Telegram Game Surpasses 100 Million Players—Token Release Sch...
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
 
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
 
BeMetals Investor Presentation_June 1, 2024.pdf
BeMetals Investor Presentation_June 1, 2024.pdfBeMetals Investor Presentation_June 1, 2024.pdf
BeMetals Investor Presentation_June 1, 2024.pdf
 
Creative Web Design Company in Singapore
Creative Web Design Company in SingaporeCreative Web Design Company in Singapore
Creative Web Design Company in Singapore
 
Observation Lab PowerPoint Assignment for TEM 431
Observation Lab PowerPoint Assignment for TEM 431Observation Lab PowerPoint Assignment for TEM 431
Observation Lab PowerPoint Assignment for TEM 431
 
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdfModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
 
Chapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .pptChapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .ppt
 
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
 
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
 
Business storytelling: key ingredients to a story
Business storytelling: key ingredients to a storyBusiness storytelling: key ingredients to a story
Business storytelling: key ingredients to a story
 

Comparison of ISO 22301 with BS 25999

  • 1. Comparison of ISO 22301 and BS 25999-2 Business Continuity Management Standards Headline Differences enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
  • 2. What is in this Slide Pack?  What is ISO 22301?  Key features of ISO 22301  How does it compare with BS 25999-2?  What’s new in ISO 22301 vs BS 25999-2  Support in implementing ISO 22301
  • 3. What is ISO 22301? enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
  • 4. What is ISO 22301? • ISO 22301 is the International Standard for Business Continuity Management Systems – Requirements • It encapsulates international business continuity best practice into a specification of requirements for planning and implementing a business continuity management system (BCMS) • Organisations wishing to certify their BCMS will be externally audited against the requirements in ISO 22301
  • 5. What is ISO 22301? • ISO 22301 is supported by a Guidance document published as a separate Standard, ISO 22313 • Both Standards were developed by Technical Committee 223 – Societal Security (ISO TC 223) of the International Standards Organisation • ISO 22301 was published May 2012 • ISO 22313 was published December 2012
  • 6. Key Features of ISO 22301 enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
  • 7. Performance Evaluation Support Context of the Organisation Planning Operation Leadership Improvement 4 5 6 7 8 9 10 Key Features of ISO 22301 • Amalgamation of National BC Standards • Enables global organisations to apply one Standard • Conforms to ISO’s new Management Systems 10 clause structure (Annex SL) which will guide all future Standards: Scope, References, Definitions 1,2 3
  • 8. How does ISO 22301 compare to BS 25999-2? BS 25999-2 – Withdrawn; transition period to June 2014 BS 25999-1 – Withdrawn enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
  • 9. ISO 22301 vs BS 25999-2 • BS 25999 was the key reference for the business continuity content of ISO 22301 • The BC-specific requirements are mainly in Clause 8; the other clauses relate to operational planning and management of the system • The BC requirements eg BIA/RA are largely the same as in BS 25999 but with some some changes in terminology and emphasis, such as supply chain continuity • 105 shall’s in 22301 vs 56 in 25999
  • 10. ISO 22301 vs BS 25999-2 The next slide maps the clauses of ISO 22301 against the Business Continuity Lifecycle in BS 25999-2
  • 11. 8.2 BIA and RA 8.3 BC Strategy Risk Treatment 8.4 Plans 8.5 Exercising & Testing 7.2 Competence 7.3 Awareness Clauses 4, 5, 6, 7, 8.1, 9 & 10
  • 12. What’s New in ISO 22301 vs BS 25999-2? enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
  • 13. What’s New in ISO 22301? • Formal requirements (Clause 4) to define and document the context of the organisation to ensure the BCMS is relevant to it • Context considers such things as defining what the organisation does, its strategic objectives, what are the risks and opportunities it faces, what’s its risk appetite, what is it dependent on, who does it influence, what regulatory requirements does it have to meet
  • 14. What’s New in ISO 22301? • More specific requirements (Clause 5) for leadership and ongoing commitment to implementation of the BCMS by senior management • More clarity around setting realistic and measurable BC objectives and how they will be achieved • Much of the ‘embedding’ part of BS 25999 is met by the competency and awareness requirements in clause 7.
  • 15. What’s New in ISO 22301? • A new clause (7.4) on communication with internal and external interested parties during disruption: who, what, when, how (testing of communication capability and interoperability required)? • A new clause (8.4.3) on Warning and Communication throughout the incident lifecycle. How will an incident be detected and monitored, how will people be told about it, how will information and decisions be recorded
  • 16. What’s New in ISO 22301? • A short but significant new requirement for recovery plans (8.4.5) detailing how activities will return from their temporary state post-incident to normal (or new normal) eg movement back from a recovery site to the office • A new clause (9) on Performance Evaluation of the whole BCMS – are we doing what we said we would do, is it doing what we want it to do, how do we know, does anything need updating, changing? Includes the Internal Audit and Management Reviews requirements from BS 25999
  • 17. The New ISO BCM Lifecycle source ISO 22313
  • 18. What Steelhenge can do to assist you • Advice and support in implementing ISO 22301 • Transitioning from BS 25999-2 to ISO 22301 • Gap analysis and reviews of your BCMS requirements • Implementing a full BCMS • Assisting you with parts of the BCMS such as BIAs, training and exercising enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117
  • 19. www.steelhenge.co.uk enquiries@steelhenge.co.uk | @Steelhenge | www.crisisthinking.co.uk | 0845 094 2117