0% found this document useful (0 votes)
27 views

Diagram of ISO 22301 Implementation Process

xsa
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
27 views

Diagram of ISO 22301 Implementation Process

xsa
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 1

Diagram of ISO 22301 Implementation Process

Note: This diagram shows the steps for ISO 22301


implementation and certification; it does not
Obtain
show the complete Plan-Do-Check-Act (PDCA)
management Cycle.
support

To learn more about ISO 22301 click here.

Establish the Project plan Budget; Human


project (not (not mandatory) resources plan
mandatory)

List of interested parties,


Identify statutary, regulatory and
requirements contractual requirements

Define scope, Business


management Business continuity continuity
intention, policy; objectives
responsibilities Scope document

Implement Procedures for document


support control, internal audit,
procedures corrective action
(not mandatory)

Risk assessment Risk assessment Preventive


Identify risks methodology + table actions
of disruptive risk appetite (not mandatory) (not mandatory)
incidents (not mandatory)

Business impact Business impact


Identify
analysis analysis
continuity
methodology questionnaires
priorities and
(not mandatory) (not mandatory)
objectives
Monitoring & measurement + records of results + preventive actions
Communication with interested parties + records of communication

Determine Training &


priorities, required Business continuity strategy; awareness
resources and Training and awareness plan; records
mitigation Preparation plan

Define Media
Business continuity plan(s); Incident
business statement
response plan(s); Recovery plan(s);
continuity templates
Transportation plan;
procedures
Communication procedures, etc.

Exercising and
Corrective
Exercising testing report
actions
and testing (not mandatory)

In case Post incident


review Corrective
disruptive actions
incident occurs (not mandatory)

Regular review
of plans and Corrections,
business corrective
continuity actions
arrangements

Conduct Internal Corrective


internal audit audit report actions

Management
Management review
review minutes

Stage 1
Stage 1 Corrective
certification audit
audit report actions
(Documentation
Mandatory only for

for the certification

Review)
companies going

Stage 2 Stage 2 Corrective


certification audit audit report actions
(Main audit)

Courtesy of: 27001Academy


Copyright © 2020 Advisera Expert Solutions Ltd.

You might also like