SlideShare une entreprise Scribd logo
1  sur  37
Télécharger pour lire hors ligne
ISO 22301
The New Standard for
Business Continuity
Best Practice
Sponsored By
Emergency Notification | Incident Management
Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein2ISO 22301 2
Agenda
1
• So what is ISO 22301?
2
• The Benefits of ISO 22301
3
• BS 25999 compared to ISO 22301
4
• Planning to comply with ISO 22301
5
• The Certification Process
6
• Q & A
Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein3ISO 22301 3
Sponsored by
Smarter Crisis Management
Emergency Notification
Incident Management
Mobile Crisis Communications
www.missionmode.com/mobile
Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein4ISO 22301 4
This presentation is from a recorded
webinar. To view and listen to the
video presentation, visit:
www.missionmode.com/webinars
Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein5ISO 22301 5
John McGill
Managing Partner, ISO 22301 Ltd.
So What Is
ISO 22301?
ISO 22301 7
ISO 22301 has sprung from a need
for global standardisation.
“I couldn’t help with the spill, I
couldn’t do anything about getting
the ship off the rocks”.
Statement 10 days after the Exxon
Valdez incident by Lawrence Rawl,
CEO Exxon Mobile
ISO 22301 8
ISO 22301 was developed by the
International Organization for
Standardization (ISO), the world’s
largest
developer of
international
standards.
ISO 22301 9
 ISO 22301 identifies the
fundamentals of best
practice business continuity.
 107 Steps to excellence
ISO 22301 10
The Automata
Fortress Model
of
Business
The Automata
Fortress Model
of
Terms and
Definitions
Understanding
The Business
Leadership
Planning
Support
Operation
Improvement
Introduction
Scope and
References
0
1/2
3
4 5
6
7
8
10
Evaluation9
The Benefits of ISO 22301
ISO 22301 12
 Establish, implement, maintain and
improve business continuity.
 Meet the requirements of your
business continuity policy.
 Give key stakeholders confidence.
 Save time and money
ISO 22301 13
So why will an organisation’s
leaders decide they want to align
with ISO 22301, or even become
certified in it?
"I think the environmental impact of
this disaster is likely to have been
very, very modest."
—Tony Hayward, BP CEO
BS 25999
vs.
ISO 22301
ISO 22301 15ISO 22301 15
All core 25999 business
continuity requirements are
in ISO 22301.
ISO 22301 16ISO 22301 16
ISO 22301 puts emphasis on:
 Interested Parties
 Understanding the organisation
 Monitoring performance and
metrics
 Legal and regulatory requirements
 Crisis Communications
ISO 22301 17ISO 22301 17
BS 25999 ISO 22301
4.1
4.1
5.2
4.3.3.3 7.4, 8.4.2, 8.4.3
4.4.3 9.1
S 3.2.1 4.3
O 3.2.1.1 6.2
P 3.2.2 5.3
3.4 7.5
4.1.2 8.2.1, 8.2.3
BS 25999 and ISO 22301
Understanding the needs and expectations of interested parties
MagnitudeArea of change
Understand the organisation
Document information
Monitoring, measurement, analysis and evaluation
Risk assessment
Business continuity policy
Communication & warning system
Management commitment
Determine the scope
Business continuity objectives
BS 25999 vs. ISO 22301
Full chart will be available for download.
Planning to comply
with ISO 22301
ISO 22301 19
ISO 22301 specifically requires
you to define your approach for
measurement and monitoring.
ISO 22301 20ISO 22301 20
ISO 22301 21ISO 22301 21
ISO 22301 22ISO 22301 22
Business Continuity
Management
System (BCMS)
ISO 22301 23ISO 22301 23
The key aspects of your ISO 22301
project:
1. Scope of business continuity
2. Business continuity Policy
3. Business continuity Objectives
4. Strategy for meeting the
objectives
The Business Impact
Analysis (BIA)
ISO 22301 25ISO 22301 25
Develop the BIA
into a risk log
and then create
Business
Continuity
Plans
Evaluate the
Recovery
Timeframes
Review the
needs of
interested
parties
Review the
initial impact
and then the
impact were
the disruption
to continue
Consider the
impact were
the resources
upon which the
PAs depend are
unavailable
Identify Priority
Activities (PA)
ISO 22301 26ISO 22301 26
Develop Incident Management
 Train
 Test
ISO 22301 27ISO 22301 27
Resource requirements:
BCMS project leader ………………………….
Project team members ………………………
Project board chairman ……………………..
Incident Management team members
Executive …………………………………………..
Staff ……………………………………...............
1,000 Hours
36 Hours
130 Hours
20 Hours
20 Hours
1 Hour
The
Certification
Process
ISO 22301 29ISO 22301 29
Certification process:
 Identify accredited certification
companies
 Meet a shortlist of companies
 Appoint a certification company
 Agree schedule with chosen company
 Schedule audit and pre-audit meetings
ISO 22301 30
ISO 22301 outlines BCMS
requirements, but does not
dictate how to plan in a
prescriptive manner.
Heads Up: The auditor cannot
act as a consultant and advise you.
ISO 22301 31
Phase 1 audit: one day
Focuses on a review of your
documents
ISO 22301 32
 Phase 1 non-conformities must be
resolved before the Phase 2 audit.
 Phase 2 will last two days and will
comprise some further review of
documents.
 The outcomes are as per the Phase
1 audit, plus the option for
certification.
ISO 22301 33
The project to obtain certification
should not be self serving.
Proof that your
business continuity
planning is following
best practice.
ISO 22301 34
The ISO 22301 Standard can be
downloaded at a cost of CHF 116
($124 /€94).
Additional guidance can be
downloaded in ISO 22313 at a cost
of CHF 154 ($165/€126).
Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein35ISO 22301
Sponsored by
Smarter Crisis Management
Emergency Notification
Incident Management
Mobile Crisis Communications
info@missionmode.com
www.missionmode.com/mobile
ISO 22301 36ISO 22301 36
John McGill
ISO22301@btinternet.com
Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein37ISO 22301
This presentation is from a recorded
webinar. To view and listen to the
video presentation, visit:
www.missionmode.com/webinars

Contenu connexe

Tendances

ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
PECB
 
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information StandardQuick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
PECB
 
business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929
Andy Willams
 
BCMS Presentation1
BCMS Presentation1BCMS Presentation1
BCMS Presentation1
barbytee
 

Tendances (20)

Iso 27001 awareness
Iso 27001 awarenessIso 27001 awareness
Iso 27001 awareness
 
Implementing a Business Continuity Management System in Telecoms
Implementing a Business Continuity Management System in TelecomsImplementing a Business Continuity Management System in Telecoms
Implementing a Business Continuity Management System in Telecoms
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
 
ISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overview
 
ISO 27001:2022 What has changed.pdf
ISO 27001:2022 What has changed.pdfISO 27001:2022 What has changed.pdf
ISO 27001:2022 What has changed.pdf
 
What is iso 27001 isms
What is iso 27001 ismsWhat is iso 27001 isms
What is iso 27001 isms
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information StandardQuick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
 
Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301
 
business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929
 
BCMS Presentation1
BCMS Presentation1BCMS Presentation1
BCMS Presentation1
 
2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdf2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdf
 
ISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to knowISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to know
 
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdfISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
 
Iso iec 27001 foundation training course by interprom
Iso iec 27001 foundation training course by interpromIso iec 27001 foundation training course by interprom
Iso iec 27001 foundation training course by interprom
 
ISO27001: Implementation & Certification Process Overview
ISO27001: Implementation & Certification Process OverviewISO27001: Implementation & Certification Process Overview
ISO27001: Implementation & Certification Process Overview
 
ISO/IEC 27001 as a Starting Point for GRC
ISO/IEC 27001 as a Starting Point for GRCISO/IEC 27001 as a Starting Point for GRC
ISO/IEC 27001 as a Starting Point for GRC
 
27001 awareness Training
27001 awareness Training27001 awareness Training
27001 awareness Training
 
c. AWARENESS ISO INTEGRATED ISO 27001 & 20000-1 PROSIA.pptx
c. AWARENESS ISO INTEGRATED ISO 27001 & 20000-1 PROSIA.pptxc. AWARENESS ISO INTEGRATED ISO 27001 & 20000-1 PROSIA.pptx
c. AWARENESS ISO INTEGRATED ISO 27001 & 20000-1 PROSIA.pptx
 
Overview of ISO 27001 ISMS
Overview of ISO 27001 ISMSOverview of ISO 27001 ISMS
Overview of ISO 27001 ISMS
 

En vedette

Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
hhuihhui
 
An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery Planning
NEBizRecovery
 
Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery Presentation
TimSchaefer
 
Disaster Recovery & Data Backup Strategies
Disaster Recovery & Data Backup StrategiesDisaster Recovery & Data Backup Strategies
Disaster Recovery & Data Backup Strategies
Spiceworks
 
Presentation on backup and recoveryyyyyyyyyyyyy
Presentation on backup and recoveryyyyyyyyyyyyyPresentation on backup and recoveryyyyyyyyyyyyy
Presentation on backup and recoveryyyyyyyyyyyyy
Tehmina Gulfam
 
Auditando un SGCN en ISO 22301 Maricarmen García de Ureña
Auditando un SGCN en ISO 22301  Maricarmen García de UreñaAuditando un SGCN en ISO 22301  Maricarmen García de Ureña
Auditando un SGCN en ISO 22301 Maricarmen García de Ureña
Maricarmen García de Ureña
 

En vedette (20)

Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
 
The A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoveryThe A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster Recovery
 
An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery Planning
 
Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery Presentation
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Business Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewBusiness Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An Overview
 
Disaster Recovery & Data Backup Strategies
Disaster Recovery & Data Backup StrategiesDisaster Recovery & Data Backup Strategies
Disaster Recovery & Data Backup Strategies
 
Business Continuity Management System ISO 22301:2012 Mind Map
Business Continuity Management System ISO 22301:2012   Mind Map Business Continuity Management System ISO 22301:2012   Mind Map
Business Continuity Management System ISO 22301:2012 Mind Map
 
Presentation on backup and recoveryyyyyyyyyyyyy
Presentation on backup and recoveryyyyyyyyyyyyyPresentation on backup and recoveryyyyyyyyyyyyy
Presentation on backup and recoveryyyyyyyyyyyyy
 
ISO 22301 Seguridad de las sociedades- Continuidad del negocio
ISO 22301 Seguridad de las sociedades- Continuidad del negocioISO 22301 Seguridad de las sociedades- Continuidad del negocio
ISO 22301 Seguridad de las sociedades- Continuidad del negocio
 
Auditando un SGCN en ISO 22301 Maricarmen García de Ureña
Auditando un SGCN en ISO 22301  Maricarmen García de UreñaAuditando un SGCN en ISO 22301  Maricarmen García de Ureña
Auditando un SGCN en ISO 22301 Maricarmen García de Ureña
 
SISTEMAS DE GETION DE CONTINUIDAD DEL NEGOCIO ISO 22301
SISTEMAS DE GETION DE CONTINUIDAD DEL NEGOCIO ISO 22301SISTEMAS DE GETION DE CONTINUIDAD DEL NEGOCIO ISO 22301
SISTEMAS DE GETION DE CONTINUIDAD DEL NEGOCIO ISO 22301
 
PECB Webinar: Estructura de la norma ISO 22301:2012. Un enfoque estratégico.
PECB Webinar: Estructura de la norma ISO 22301:2012. Un enfoque estratégico.PECB Webinar: Estructura de la norma ISO 22301:2012. Un enfoque estratégico.
PECB Webinar: Estructura de la norma ISO 22301:2012. Un enfoque estratégico.
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Auditoría del SGCN según ISO 22301
Auditoría del SGCN según ISO 22301Auditoría del SGCN según ISO 22301
Auditoría del SGCN según ISO 22301
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcp
 
How to improve resilience and respond better to Cyber Attacks with ISO 22301?
How to improve resilience and respond better to Cyber Attacks with ISO 22301?How to improve resilience and respond better to Cyber Attacks with ISO 22301?
How to improve resilience and respond better to Cyber Attacks with ISO 22301?
 
Business continuity overview slideshare
Business continuity overview slideshareBusiness continuity overview slideshare
Business continuity overview slideshare
 
2.maricarmen garcia.riesgosasociadoscontinuidadnegocioiso22301
2.maricarmen garcia.riesgosasociadoscontinuidadnegocioiso223012.maricarmen garcia.riesgosasociadoscontinuidadnegocioiso22301
2.maricarmen garcia.riesgosasociadoscontinuidadnegocioiso22301
 

Similaire à ISO 22301: The New Standard for Business Continuity Best Practice

ESGPLC - 2015 - ISO Presentation MM 2-7-15 linkin version...
ESGPLC - 2015 - ISO Presentation MM 2-7-15 linkin version...ESGPLC - 2015 - ISO Presentation MM 2-7-15 linkin version...
ESGPLC - 2015 - ISO Presentation MM 2-7-15 linkin version...
MICHAEL MORGAN
 
Audit_9001 Quality Management Systems
Audit_9001 Quality Management SystemsAudit_9001 Quality Management Systems
Audit_9001 Quality Management Systems
Ian Munro
 

Similaire à ISO 22301: The New Standard for Business Continuity Best Practice (20)

iso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdfiso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
 
Business Continuity Management: How to get started
Business Continuity Management: How to get startedBusiness Continuity Management: How to get started
Business Continuity Management: How to get started
 
What are the steps for ISO 22301 certification
What are the steps for ISO 22301 certificationWhat are the steps for ISO 22301 certification
What are the steps for ISO 22301 certification
 
BCI ISO 22301 Benchmarking Report
BCI ISO 22301 Benchmarking ReportBCI ISO 22301 Benchmarking Report
BCI ISO 22301 Benchmarking Report
 
iso 22301 lead auditor training.pdf
iso 22301 lead auditor training.pdfiso 22301 lead auditor training.pdf
iso 22301 lead auditor training.pdf
 
Microsoft azure, dynamics 365, and other online services iso27001, 27018, 2...
Microsoft azure, dynamics 365, and other online services   iso27001, 27018, 2...Microsoft azure, dynamics 365, and other online services   iso27001, 27018, 2...
Microsoft azure, dynamics 365, and other online services iso27001, 27018, 2...
 
ISO 22301 | ISO 22301 Internal Auditor Training
ISO 22301 | ISO 22301 Internal Auditor TrainingISO 22301 | ISO 22301 Internal Auditor Training
ISO 22301 | ISO 22301 Internal Auditor Training
 
Comparison of ISO 22301 with BS 25999
Comparison of ISO 22301 with BS 25999Comparison of ISO 22301 with BS 25999
Comparison of ISO 22301 with BS 25999
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
 
what is Business Continuity Management System?
what is Business Continuity Management System?what is Business Continuity Management System?
what is Business Continuity Management System?
 
PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...
PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...
PECB Webinar: Rethinking Business Continuity: Applying ISO 22301 to improve r...
 
ISO 22301 Certification What You Need to Know.pdf
ISO 22301 Certification What You Need to Know.pdfISO 22301 Certification What You Need to Know.pdf
ISO 22301 Certification What You Need to Know.pdf
 
Everything You Need To Know About ISO 22301 Certification in Oman.pdf
Everything You Need To Know About ISO 22301 Certification in Oman.pdfEverything You Need To Know About ISO 22301 Certification in Oman.pdf
Everything You Need To Know About ISO 22301 Certification in Oman.pdf
 
Gap Analysis | ISO 22301 | BCMS | By Industry Experts
Gap Analysis | ISO 22301 | BCMS | By Industry ExpertsGap Analysis | ISO 22301 | BCMS | By Industry Experts
Gap Analysis | ISO 22301 | BCMS | By Industry Experts
 
ISO 22301, The first ever ISO for BCM - Presented at BCI Qatar Forum
ISO 22301, The first ever ISO for BCM - Presented at BCI Qatar ForumISO 22301, The first ever ISO for BCM - Presented at BCI Qatar Forum
ISO 22301, The first ever ISO for BCM - Presented at BCI Qatar Forum
 
ISO 22301 | ISO 22301 Lead Auditor Taining
ISO 22301 | ISO 22301 Lead Auditor TainingISO 22301 | ISO 22301 Lead Auditor Taining
ISO 22301 | ISO 22301 Lead Auditor Taining
 
ESGPLC - 2015 - ISO Presentation MM 2-7-15 linkin version...
ESGPLC - 2015 - ISO Presentation MM 2-7-15 linkin version...ESGPLC - 2015 - ISO Presentation MM 2-7-15 linkin version...
ESGPLC - 2015 - ISO Presentation MM 2-7-15 linkin version...
 
Audit_9001 Quality Management Systems
Audit_9001 Quality Management SystemsAudit_9001 Quality Management Systems
Audit_9001 Quality Management Systems
 
ISO 22301 Lead Auditor – Two Page Brochure
ISO 22301 Lead Auditor – Two Page BrochureISO 22301 Lead Auditor – Two Page Brochure
ISO 22301 Lead Auditor – Two Page Brochure
 
PECB Webinar: ISO Internal Audits - A signpost to ISO compliance
PECB Webinar: ISO Internal Audits - A signpost to ISO compliancePECB Webinar: ISO Internal Audits - A signpost to ISO compliance
PECB Webinar: ISO Internal Audits - A signpost to ISO compliance
 

Plus de MissionMode

Plus de MissionMode (16)

Best-in-Class Crisis Preparation: Maximize Readiness with the Four T’s
Best-in-Class Crisis Preparation: Maximize Readiness with the Four T’sBest-in-Class Crisis Preparation: Maximize Readiness with the Four T’s
Best-in-Class Crisis Preparation: Maximize Readiness with the Four T’s
 
Crisis Communications 101: A Crash Course
Crisis Communications 101: A Crash CourseCrisis Communications 101: A Crash Course
Crisis Communications 101: A Crash Course
 
Crisis and Disasters Website Roundup
Crisis and Disasters Website RoundupCrisis and Disasters Website Roundup
Crisis and Disasters Website Roundup
 
Best Practices for Emergency Notification Messages
Best Practices for Emergency Notification MessagesBest Practices for Emergency Notification Messages
Best Practices for Emergency Notification Messages
 
Severe Weather Preparedness and Resiliency
Severe Weather Preparedness and ResiliencySevere Weather Preparedness and Resiliency
Severe Weather Preparedness and Resiliency
 
16 Killer Crisis Management Apps for iPhone & iPad
16 Killer Crisis Management Apps for iPhone & iPad16 Killer Crisis Management Apps for iPhone & iPad
16 Killer Crisis Management Apps for iPhone & iPad
 
Five Disciplines of Organizational Resilience
Five Disciplines of Organizational ResilienceFive Disciplines of Organizational Resilience
Five Disciplines of Organizational Resilience
 
Faster, Stronger Crisis Response With ICS for Business
Faster, Stronger Crisis Response With ICS for BusinessFaster, Stronger Crisis Response With ICS for Business
Faster, Stronger Crisis Response With ICS for Business
 
Reputation Combat: Protecting Your Company's Online Reputation
Reputation Combat: Protecting Your Company's Online ReputationReputation Combat: Protecting Your Company's Online Reputation
Reputation Combat: Protecting Your Company's Online Reputation
 
Revolutionary Mobile Crisis Communications - EarShot
Revolutionary Mobile Crisis Communications - EarShotRevolutionary Mobile Crisis Communications - EarShot
Revolutionary Mobile Crisis Communications - EarShot
 
Proactive Crisis Management Through Internal Crowdsourcing
Proactive Crisis Management Through Internal CrowdsourcingProactive Crisis Management Through Internal Crowdsourcing
Proactive Crisis Management Through Internal Crowdsourcing
 
Simplifying Internal Crisis Communications
Simplifying Internal Crisis CommunicationsSimplifying Internal Crisis Communications
Simplifying Internal Crisis Communications
 
Corporate Crisis Management - Minimize the Chaos
Corporate Crisis Management - Minimize the ChaosCorporate Crisis Management - Minimize the Chaos
Corporate Crisis Management - Minimize the Chaos
 
Successfully Managing Emergency Operations in a Distributed Environment
Successfully Managing Emergency Operations in a Distributed EnvironmentSuccessfully Managing Emergency Operations in a Distributed Environment
Successfully Managing Emergency Operations in a Distributed Environment
 
Supply Chain Recovery is a Competitive Capability
Supply Chain Recovery is a Competitive CapabilitySupply Chain Recovery is a Competitive Capability
Supply Chain Recovery is a Competitive Capability
 
Crisis Preparedness Ins and Outs - White Paper
Crisis Preparedness Ins and Outs - White PaperCrisis Preparedness Ins and Outs - White Paper
Crisis Preparedness Ins and Outs - White Paper
 

Dernier

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Dernier (20)

Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 

ISO 22301: The New Standard for Business Continuity Best Practice

  • 1. ISO 22301 The New Standard for Business Continuity Best Practice Sponsored By Emergency Notification | Incident Management
  • 2. Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein2ISO 22301 2 Agenda 1 • So what is ISO 22301? 2 • The Benefits of ISO 22301 3 • BS 25999 compared to ISO 22301 4 • Planning to comply with ISO 22301 5 • The Certification Process 6 • Q & A
  • 3. Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein3ISO 22301 3 Sponsored by Smarter Crisis Management Emergency Notification Incident Management Mobile Crisis Communications www.missionmode.com/mobile
  • 4. Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein4ISO 22301 4 This presentation is from a recorded webinar. To view and listen to the video presentation, visit: www.missionmode.com/webinars
  • 5. Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein5ISO 22301 5 John McGill Managing Partner, ISO 22301 Ltd.
  • 6. So What Is ISO 22301?
  • 7. ISO 22301 7 ISO 22301 has sprung from a need for global standardisation. “I couldn’t help with the spill, I couldn’t do anything about getting the ship off the rocks”. Statement 10 days after the Exxon Valdez incident by Lawrence Rawl, CEO Exxon Mobile
  • 8. ISO 22301 8 ISO 22301 was developed by the International Organization for Standardization (ISO), the world’s largest developer of international standards.
  • 9. ISO 22301 9  ISO 22301 identifies the fundamentals of best practice business continuity.  107 Steps to excellence
  • 10. ISO 22301 10 The Automata Fortress Model of Business The Automata Fortress Model of Terms and Definitions Understanding The Business Leadership Planning Support Operation Improvement Introduction Scope and References 0 1/2 3 4 5 6 7 8 10 Evaluation9
  • 11. The Benefits of ISO 22301
  • 12. ISO 22301 12  Establish, implement, maintain and improve business continuity.  Meet the requirements of your business continuity policy.  Give key stakeholders confidence.  Save time and money
  • 13. ISO 22301 13 So why will an organisation’s leaders decide they want to align with ISO 22301, or even become certified in it? "I think the environmental impact of this disaster is likely to have been very, very modest." —Tony Hayward, BP CEO
  • 15. ISO 22301 15ISO 22301 15 All core 25999 business continuity requirements are in ISO 22301.
  • 16. ISO 22301 16ISO 22301 16 ISO 22301 puts emphasis on:  Interested Parties  Understanding the organisation  Monitoring performance and metrics  Legal and regulatory requirements  Crisis Communications
  • 17. ISO 22301 17ISO 22301 17 BS 25999 ISO 22301 4.1 4.1 5.2 4.3.3.3 7.4, 8.4.2, 8.4.3 4.4.3 9.1 S 3.2.1 4.3 O 3.2.1.1 6.2 P 3.2.2 5.3 3.4 7.5 4.1.2 8.2.1, 8.2.3 BS 25999 and ISO 22301 Understanding the needs and expectations of interested parties MagnitudeArea of change Understand the organisation Document information Monitoring, measurement, analysis and evaluation Risk assessment Business continuity policy Communication & warning system Management commitment Determine the scope Business continuity objectives BS 25999 vs. ISO 22301 Full chart will be available for download.
  • 19. ISO 22301 19 ISO 22301 specifically requires you to define your approach for measurement and monitoring.
  • 20. ISO 22301 20ISO 22301 20
  • 21. ISO 22301 21ISO 22301 21
  • 22. ISO 22301 22ISO 22301 22 Business Continuity Management System (BCMS)
  • 23. ISO 22301 23ISO 22301 23 The key aspects of your ISO 22301 project: 1. Scope of business continuity 2. Business continuity Policy 3. Business continuity Objectives 4. Strategy for meeting the objectives
  • 25. ISO 22301 25ISO 22301 25 Develop the BIA into a risk log and then create Business Continuity Plans Evaluate the Recovery Timeframes Review the needs of interested parties Review the initial impact and then the impact were the disruption to continue Consider the impact were the resources upon which the PAs depend are unavailable Identify Priority Activities (PA)
  • 26. ISO 22301 26ISO 22301 26 Develop Incident Management  Train  Test
  • 27. ISO 22301 27ISO 22301 27 Resource requirements: BCMS project leader …………………………. Project team members ……………………… Project board chairman …………………….. Incident Management team members Executive ………………………………………….. Staff ……………………………………............... 1,000 Hours 36 Hours 130 Hours 20 Hours 20 Hours 1 Hour
  • 29. ISO 22301 29ISO 22301 29 Certification process:  Identify accredited certification companies  Meet a shortlist of companies  Appoint a certification company  Agree schedule with chosen company  Schedule audit and pre-audit meetings
  • 30. ISO 22301 30 ISO 22301 outlines BCMS requirements, but does not dictate how to plan in a prescriptive manner. Heads Up: The auditor cannot act as a consultant and advise you.
  • 31. ISO 22301 31 Phase 1 audit: one day Focuses on a review of your documents
  • 32. ISO 22301 32  Phase 1 non-conformities must be resolved before the Phase 2 audit.  Phase 2 will last two days and will comprise some further review of documents.  The outcomes are as per the Phase 1 audit, plus the option for certification.
  • 33. ISO 22301 33 The project to obtain certification should not be self serving. Proof that your business continuity planning is following best practice.
  • 34. ISO 22301 34 The ISO 22301 Standard can be downloaded at a cost of CHF 116 ($124 /€94). Additional guidance can be downloaded in ISO 22313 at a cost of CHF 154 ($165/€126).
  • 35. Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein35ISO 22301 Sponsored by Smarter Crisis Management Emergency Notification Incident Management Mobile Crisis Communications info@missionmode.com www.missionmode.com/mobile
  • 36. ISO 22301 36ISO 22301 36 John McGill ISO22301@btinternet.com
  • 37. Reputation Combat: Protecting Your Company’s Online Reputation ©Copyright 2011, Jonathan Bernstein37ISO 22301 This presentation is from a recorded webinar. To view and listen to the video presentation, visit: www.missionmode.com/webinars