Environmental incidents over the last 12 months, including severe weather and natural disasters across the globe, have led to greater awareness and a shift in attitudes towards business continuity management (BCM). Now with the global economy continuing to be turbulent, it is critical that organizations bring the issue of business continuity management higher up the boardroom agenda and prepare for the potential fall outs from political instability, social unrest and economic meltdown.
BSI recently sponsored the renowned Chartered Management Instituteâs (CMI) report, âPlanning for the Worst,â which shows clear advantages for organizations that have business continuity plans in place to deal with incidents and crises when they hit. Of those who had to activate plans in 2011, 82 percent said BCM enabled their organization to return to normal operations more quickly, while 81 percent agreed it reduced disruption.
The report also identifies corporate governance as the biggest external driver for BCM, as well as providing assurance that an organization will be able to continue its daily operations. Implementation of such standards will also help businesses to address the more strategic aspects of BCM such as the potential threats to their supply chains.
In short, when life sends companies a basket of thorns, they may be better prepared to find roses thanks to the release of the new ISO 22301:2012.
- ISO 22301 is the new international standard for business continuity management.
- Its official title is ISO 22301 Societal Security – Business Continuity Management System – Requirements.
- ISO 22301 is an ISO requirements standard, which effectively means it is an auditable specification.
BSI is one of the pioneers of the original BCM best practice standard, BS 25999-2:2007 and this has now been superseded by ISO 22301, due to the strong international interest in the original British standard BS 25999-2 and other regional standards. Since its introduction in 2007, BS 25999-2 has grown in acceptance worldwide. BS 25999 sold in over 100 countries, with certificates in 43 countries and certificate applications in another 15 countries. 800 sites are already certified by BSI alone with 400 pending (these will likely transition to ISO 22301).
BS 25999 was created to set out a uniform benchmark in good practice, satisfying the needs of customers, clients, government, regulators and all other interested parties. BS 25999 has formed the basis of many other BCM standards, including the US ASIS/BSI BCM.01 standard adopted by ANSI. BS 25999 and other BCM standards from across the globe provided the source material for the creation of the new international standards: ISO 22301 (requirements) and ISO 22313 (guidance).
Unlike BS 25999-2, ISO 22301 is an international standard, which will see greater international acceptance. For those certified to or aligned with BS 25999-2, the additional requirements easy to understand and adjust to.
During the latter part of 2012 or early in 2013, ISO will issue a guidance document ISO 22313. This document will take the form of good practice guidance and recommendations, indicating what practices an organization should, or may, undertake to implement effective BCM. Organizations may choose to follow all or part of the guidance, which may be used for self-assessment or between organizations. The guidance is not a specification for BCM.
ISO 22301 now comes under a wider societal security responsibility, acknowledging the important role that BCM has to play in protecting society and ensuring the ability to respond to incidents, emergencies and disasters. It specifies the requirements for setting up and managing an effective business continuity management system (BCMS) for any organization, regardless of type or size.
Even if organizations donât intend to seek certification, ISO 22301 should strongly influence their BCM program.
ISO 22301 contains only those requirements that can be objectively audited and a demonstration of successful implementation can therefore be used by an organization to assure interested parties that an appropriate BCMS is in place.
By adopting ISO 22301, organizations will benefit from global BCM best practice. ISO 22301 provides a foundation and a common vocabulary for BCM best practices and processes. Standards like ISO 22301 represent the input and recommendations of hundreds of business continuity professionals and industry experts. Rather than reinvent the wheel, you can take advantage of years of expertise and the lessons learned from your peers.
Improvements and comparison of ISO 22301:2012 to BS 25999-2:2007 â Critical aspects you should know
In comparing ISO 22301 with BS 25999-2 you will see that it includes all the core requirements of 25999-2.
- The âPlan Do Check Actâ cycle
- Business continuity policy
- Business impact analysis
- Risk assessment and risk treatments
- Exercising
- Business continuity plans and strategy
- Internal audit
- Management review
- Non conformity and corrective action
- Improvement actions
Notable shifts in emphasis from BS 25999-2:2007:
- First standard written in accordance with Guide 83
- Change in the way an organization is defined
- Clearer expectations on management
- Preventive action has been replaced with âactions to address risks and opportunitiesâ and features. Greater emphasis on setting the objectives, monitoring performance metrics, and aligning BC to top management strategic thinking
ISO 22301:2012 requires more careful planning for and preparing the resources needed for ensuring business continuity. Communication elements are more demanding and there is a defined responsibility to the wider community.
Business impact analysis (BIA) is similar but with some changes to terminology, and there is a stronger link to the organizationâs approach to risk and requires the organization to address the threats to the BCMS not being successfully established, implemented and maintained. To reflect the societal security approach some new terminology has been introduced, see ISO 22300.
Letâs look at these key changes and aspects in a little more detail.
The new high level structure
Those familiar with the format of management system standards will find that the new ISO 22301 looks very different. This is because it is based on Guide 83.
Guide 83 is not a standard but rather a roadmap for standards developers to write management systems standards; ISO 22301 is the first standard to be written in accordance with this guide.
So, why did they do this? Essentially, it provides a high-level structure and common text for all management system standards.
The guide was developed in response to standard usersâ criticism that while current standards have many common components, they are not sufficiently aligned, making it difficult for organizations to rationalize their systems and to interface and integrate them. Guide 83 provides the introduction of common terminology and less jargon.
As such, Guide 83 should make it easier to work with more than one management system standard simultaneously.
So what are the main differences?
The main differences center on:
- Objectives, monitoring performance and metrics
- Top management commitment
- Planning
- Requirements around supply chain
- Interested parties
- Recognition of legal and regulatory requirements
Objectives, monitoring performance and metrics
ISO 22301 puts greater emphasis on the setting of objectives and monitoring performance metrics â bringing business continuity much closer to the top management way of thinking. Although this is a new requirement, most organizations already produce metrics for finance, quality, health and safety or environment and can extend these to cover BCMS performance.
This is not just about saying, for instance, one has 42 plans in place, it goes much further. Examples might include, business impact analysis update frequency, number of exercises completed, or percentage of staff contactable within a specific metric.
Clause | Description |
4.0 | Clause 4.0 is a component of "plan" in the Plan Do Check Act (PDCA) cycle. It introduces requirements necessary to establish the context of the BCMS as it applies to the organization. Those familiar with BS 25999 will see that Clause 4.0 is more focused on business continuity at the organizational level. It requires that the organization demonstrate an appreciation and understanding of its reason for existence aligned with the needs and expectations of its stakeholders. This will determine its business continuity policy and objectives, how it will consider risk, and the effect of risk on its business. Consideration of an appropriate scope for the BCMS is required and a link with core objectives and stakeholder requirements should be evident. |
5.0 | Also, a component of "plan." Clause 5.0 summarizes the requirements specific to top management’s role in the BCMS, and how leadership articulates its expectations to the organization via a policy statement. Clause 5.0 introduces a new focus on top management. Top management leadership shall be demonstrable towards the management system. |
6.0 | Clause 6.0 introduces an increased focus on planning, and is very much geared toward making sure that the BCMS links with the objectives of the organization, as well as its risk appetite. A component of the "plan" describes requirements as it relates to establishing strategic objectives and guiding principles for the BCMS as a whole. The content of Clause 6.0 differs from establishing risk treatment opportunities stemming from risk assessment, as well as business impact analysis (BIA) derived recovery objectives. |
7.0 | Clause 7.0 is also a component of "plan." It supports BCMS operations as they relate to establishing competence and communication on a recurring/as-needed basis with interested parties, while documenting, controlling, maintaining and retaining required documentation. Clause 7.0 places a big focus on understanding the needs of interested parties; in fact, one will see this mentioned all the way through the new ISO. The new international standard very much considers the organization as part of the wider community, taking into account stakeholders all the way to the local environment. It goes so far as to introduce the notion of unspecified stakeholders, sweeping up more than just those stakeholders an organization might consider immediately as interested parties. Clause 7.0 also details the support required to establish, implement and maintain an effective BCMS, including: Resource requirements Competence of people involved Awareness of and communication with interested parties Requirements for document management |
8.0 | Clause 8.0, a component of "do," defines business continuity requirements, determines how to address them and develops the procedures to manage a disruptive incident. The requirements for business continuity plans, including response procedures and recovery plans are much more detailed too. |
9.0 | Clause 9.0 is a component of "check." It summarizes requirements necessary to measure BCM performance, BCMS compliance with the international standard and management’s expectations. Further, it seeks feedback from management regarding expectations. Clause 9.0 introduces a whole new element. Those of you familiar with BS 25999-2 may get concerned, because ISO 22301 places much greater emphasis on setting objectives, monitoring performance and metrics, therefore bringing business continuity much closer to the top management way of thinking. This can be difficult with a BCMS because it’s not just about documenting what you have in place, but implementing real measureable metrics that monitor the health of you BCMS. As with all management system standards there is a need to look back at what has been achieved. ISO 22301 also requires that this analysis is evaluated and conclusions drawn by the organization. |
10.0 | Clause 10.0, a component of "act," identifies and acts on BCMS non-conformance through corrective action. This clause covers non-conformity and corrective action; the term preventive action is no longer used and is now referred to as "actions to address risks and opportunities" and is covered in Clause 6.1. Nonconformities of the BCMS have to be dealt together with corrective actions to ensure they don’t happen again. As with all management system standards, continual improvement is a core requirement of the standard. |
Top management commitment
Top management responsibility and commitment have been features of management system standards for many years. ISO 22301 re-emphasizes this in a more pronounced way, mandating specific ways in which commitment shall be demonstrated.
In addition to the current requirements to set policy and objectives, roles and responsibilities, top management is now expected to define its criteria for accepting risks, actively engage in exercising and testing the BCMS and take responsibility for ensuring that the performance of the BCMS is reviewed through internal audits and management reviews.
ISO 22301 requires that organizations plan and control the operation of their business continuity management requirements. Most importantly this will include:
- A methodology and documented process for conducting a business impact analysis (BIA)
- A systematic methodology and documented process for conducting risk assessments
- A methodology for selecting business continuity strategies which will protect the most important activities of the business and ensure their resumption in the event of disruption
Business continuity procedures and plans are again required to maintain prioritized activities and their dependencies. Conformance to the standard will require objective evidence of all of these.
Planning
ISO 22301 contains extended requirements for planning. They are clearly structured over clauses 4, 5, 6, and 7. Additionally, ISO 22301 requires the integration of the BCMS with the organizationâs processes.
This features some of the common elements of ISO 9001 for quality and other ISO management system standards and seeks to avoid a situation where the BCMS exists outside normal business.
There is a requirement that organizations address any threats to the successful establishment, implementation and ongoing maintenance of the BCMS itself, as well as its operation. This means considering for example, resources to operate the BCMS, resilience of processes to operate the BCMS as well as the BCMS operations to support the organization.
ISO 22301 also requires a procedure to manage legal and regulatory requirements, the output of which should be taken into consideration in maintaining the BCMS.
Requirements around supply chain
ISO 22301 outlines more specific requirements relating to suppliers. This makes it a useful tool for validating supply chains, client and contractual requirements and ensuring third-party business continuity arrangements are consistent with the organizationâs own risk appetite.
Newly added concepts, definitions
- Context of the organization â The environment in which the organization operates
- Interested parties â replaces âstakeholdersâ
- Leadership â requirements specific to top management
- Maximum acceptable outage (MAO) â âtime it would take for adverse impacts, which might arise as a result of not providing a product/service or performing an activity, to become unacceptable.â This is effectively the same as maximum tolerable period of disruption (MTPD) that was in BS 25999-2
- Minimum business continuity objective (MBCO) â âminimum level of services and/or products that is acceptable to the organization to achieve its business objectives during a disruptionâ
- Performance evaluation â covers the measurement of BCMS and BCM effectiveness
- Warning and communication â activities undertaken during an incident
See a high-level overview and explanation of the structure of ISO 22301:2012 on the right.
Conclusion
There is a growing concern about the continued increase in business environment volatility that makes the task of managing business continuity and global supply chains tougher every day. Changes over the last few years in the social, political, technology, environment, and economic domains around the world, suggest that the business landscape and paradigm of supply-chain management has transformed permanently.
By adopting a standard approach to BCM as set out in ISO 22301, organizations can offer their customers and clients greater assurance that they will be capable of maintaining continuity of operations and supply-chain if they suffer disruptive incidents.
The standard provides a framework to build the resilience you need to respond and operate effectively during the most challenging and unexpected circumstances.
Frequently Asked Questions
Are you certified to BS 25999-2?
Organizationâs holding certification to BS 25999-2:2007 who wish to retain business continuity certification will need to demonstrate compliance to ISO 22301:2012 before the end of an agreed transition period.
- UKAS; the UKâs national accreditation body, has advised that the transitional period will end June 1, 2014
- Continuing Assessment Visits and Re-certifications for BS 25999-2:2007 will therefore cease on June 1, 2014
How will the transition take place for existing PS-Prep customers?
The process is as follows and subject to change:
- BS 25999 certified organizations will have to wait for ISO 22301 to be accepted or transition to ISO 22301 under the UKAS scheme
- DHS will review and analyze ISO 22301
- Intent to accept ISO 22301 will be posted on the federal register for public comment ~ 30 days
- Comments will be taken under consideration and acted upon if applicable
- Acceptance of ISO 22301 under ANAB Rule 37
- Process could take 3 to 6 months
- Lead auditors will have to undergo transition training
So what does your organization need to do next?
If you have not already done so, it is recommended that you obtain a copy of ISO 22301:2012. Once you have a copy of the new standard you can work through to understand how the changes specifically impact your organization.
Existing BS 25999-2 certified organizations should speak with their certification body to agree when your organization will be ready to be assessed to the new standard.
John A. DiMaria, CSSBB, HISP, MHISP, AMBCI, is the product marketing manager for BSI Group America Inc. BSI is a trusted partner to industry and government with a focus to support their business objectives through the transfer of knowledge of best practices, assurance services to identify and measure performance indicators, training services to aid the building of organizational competency and enable continual improvement, and the tools to monitor, enhance and report on compliance against the organizationâs management system objectives.
