ISO-22313-10.1 | Nonconformity and corrective action | 11 |
ISO-22313-10.2 | Continual improvement | 16 |
ISO-22313-4.1 | Understanding the organization and its context | 14 |
ISO-22313-4.2 | Understanding the needs and expectations of interested parties | 10 |
ISO-22313-4.3 | Determining the scope of the BCMS | 0 |
ISO-22313-4.4 | Business continuity management system | 0 |
ISO-22313-5.1 | Leadership and commitment | 15 |
ISO-22313-5.2 | Policy | 27 |
ISO-22313-5.3 | Organizational roles, responsibilities and authorities | 12 |
ISO-22313-6.1 | Actions to address risks and opportunities | 11 |
ISO-22313-6.2 | Business continuity objectives and plans to achieve them | 27 |
ISO-22313-6.3 | Planning changes to the BCMS | 27 |
ISO-22313-7.1 | Resources | 1 |
ISO-22313-7.2 | Competence | 0 |
ISO-22313-7.3 | Awareness | 1 |
ISO-22313-7.4 | Communication | 5 |
ISO-22313-7.5 | Documented information | 14 |
ISO-22313-8.1 | Operational planning and control | 12 |
ISO-22313-8.2 | Business impact analysis and risk assessment | 124 |
ISO-22313-8.3 | Business continuity strategies and solutions | 1 |
ISO-22313-8.4 | Business continuity plans and procedures | 1 |
ISO-22313-8.5 | Exercise programme | 1 |
ISO-22313-9.1 | Monitoring, measurement, analysis and evaluation | 11 |
ISO-22313-9.2 | Internal audit | 14 |
ISO-22313-9.3 | Management review | 15 |
ISO22313-10.1 | Guidance on nonconformity and corrective action | 10 |
ISO22313-10.2 | Guidance on continual improvement | 0 |
ISO22313-4.1 | Guidance on understanding context | 0 |
ISO22313-4.2 | Guidance on interested parties | 0 |
ISO22313-4.3 | Guidance on BCMS scope | 0 |
ISO22313-5.1 | Guidance on leadership and commitment | 0 |
ISO22313-5.2 | Guidance on BC policy | 0 |
ISO22313-5.3 | Guidance on roles and authorities | 0 |
ISO22313-6.1 | Guidance on risks and opportunities | 0 |
ISO22313-6.2 | Guidance on BC objectives | 0 |
ISO22313-7.2 | Guidance on competence | 0 |
ISO22313-7.4 | Guidance on communication | 0 |
ISO22313-7.5 | Guidance on documented information | 0 |
ISO22313-8.1 | Guidance on operational planning and control | 12 |
ISO22313-8.2 | Guidance on BIA and risk assessment | 0 |
ISO22313-8.3 | Guidance on BC strategies and solutions | 0 |
ISO22313-8.4 | Guidance on BC plans and procedures | 0 |
ISO22313-8.5 | Guidance on exercising and testing | 0 |
ISO22313-8.6 | Guidance on evaluation of BC documentation and capability | 0 |
ISO22313-9.1 | Guidance on monitoring and evaluation | 0 |
ISO22313-9.2 | Guidance on internal audit | 0 |
ISO22313-9.3 | Guidance on management review | 0 |
10 | 10 Improvement | 0 |
10.1 | 10.1 Nonconformity and corrective action | 0 |
10.1.1 | 10.1.1 Nonconformity and corrective action: general | 0 |
10.1.2 | 10.1.2 Occurrence of nonconformity | 0 |
10.1.3 | 10.1.3 Retention of documented information | 0 |
10.2 | 10.2 Continual improvement | 0 |
4 | 4 Context of the organization | 0 |
4.1 | 4.1 Understanding the organization and its context | 0 |
4.2 | 4.2 Understanding the needs and expectations of interested parties | 0 |
4.2.1 | 4.2.1 Understanding the needs and expectations of interested parties: general | 0 |
4.2.2 | 4.2.2 Legal and regulatory requirements | 0 |
4.3 | 4.3 Determining the scope of the business continuity management system | 0 |
4.3.1 | 4.3.1 Determining the scope of the BCMS: general | 0 |
4.3.2 | 4.3.2 Scope of the business continuity management system | 0 |
4.3.3 | 4.3.3 Exclusions to scope | 0 |
4.4 | 4.4 Business continuity management system | 0 |
5 | 5 Leadership | 0 |
5.1 | 5.1 Leadership and commitment | 0 |
5.1.2 | 5.1.2 Top management | 0 |
5.1.3 | 5.1.3 Other managerial roles | 0 |
5.2 | 5.2 Policy | 0 |
5.2.1 | 5.2.1 Establishing the business continuity policy | 0 |
5.2.2 | 5.2.2 Communicating the business continuity policy | 0 |
5.3 | 5.3 Roles, responsibilities and authorities | 0 |
6 | 6 Planning | 0 |
6.1 | 6.1 Actions to address risks and opportunities | 0 |
6.1.1 | 6.1.1 Determining risks and opportunities | 0 |
6.1.2 | 6.1.2 Addressing risks and opportunities | 0 |
6.2 | 6.2 Business continuity objectives and planning to achieve them | 0 |
6.2.1 | 6.2.1 Establishing business continuity objectives | 0 |
6.2.2 | 6.2.2 Determining business continuity objectives | 0 |
6.3 | 6.3 Planning changes to the business continuity management system | 0 |
7 | 7 Support | 0 |
7.1 | 7.1 Resources | 0 |
7.1.1 | 7.1.1 Resources: general | 0 |
7.1.2 | 7.1.2 BCMS resources | 0 |
7.2 | 7.2 Competence | 0 |
7.3 | 7.3 Awareness | 0 |
7.4 | 7.4 Communication | 0 |
7.5 | 7.5 Documented information | 0 |
7.5.1 | 7.5.1 Documented information: general | 0 |
7.5.2 | 7.5.2 Creating and updating | 0 |
7.5.3 | 7.5.3 Control of documented information | 0 |
7.5.3.1 | 7.5.3.1 Access to documented information | 0 |
7.5.3.2 | 7.5.3.2 Types of control | 0 |
8 | 8 Operation | 0 |
8.1 | 8.1 Operational planning and control | 0 |
8.1.1 | 8.1.1 Operational planning and control: general | 0 |
8.1.2 | 8.1.2 Business continuity management | 0 |
8.1.3 | 8.1.3 Maintaining business continuity | 0 |
8.2 | 8.2 Business impact analysis and risk assessment | 0 |
8.2.1 | 8.2.1 Business impact analysis and risk assessment: general | 0 |
8.2.2 | 8.2.2 Business impact analysis | 0 |
8.2.3 | 8.2.3 Risk assessment | 0 |
8.3 | 8.3 Business continuity strategies and solutions | 0 |
8.3.1 | 8.3.1 Business continuity strategies and solutions: general | 0 |
8.3.2 | 8.3.2 Identification of strategies and solutions | 0 |
8.3.2.1 | 8.3.2.1 Determination of strategies and solutions: general | 0 |
8.3.2.2 | 8.3.2.2 Protection of prioritized activities | 0 |
8.3.2.3 | 8.3.2.3 Stabilization, continuation, resumption and recovery of prioritized activities | 0 |
8.3.2.4 | 8.3.2.4 Mitigating, responding to and managing impacts | 0 |
8.3.3 | 8.3.3 Selection of strategies and solutions | 0 |
8.3.4 | 8.3.4 Resource requirements | 0 |
8.3.4.1 | 8.3.4.1 Resource requirements: general | 0 |
8.3.4.2 | 8.3.4.2 People | 0 |
8.3.4.3 | 8.3.4.3 Information and data | 0 |
8.3.4.4 | 8.3.4.4 Buildings, work sites and associated utilities | 0 |
8.3.4.5 | 8.3.4.5 Equipment and consumables | 0 |
8.3.4.6 | 8.3.4.6 ICT systems | 0 |
8.3.4.7 | 8.3.4.7 Transportation and logistics | 0 |
8.3.4.8 | 8.3.4.8 Finance | 0 |
8.3.4.9 | 8.3.4.9 Partners and supply chain | 0 |
8.3.5 | 8.3.5 Implementation of solutions | 0 |
8.4 | 8.4 Business continuity plans and procedures | 0 |
8.4.1 | 8.4.1 Business continuity plans and procedures: general | 0 |
8.4.2 | 8.4.2 Response structure | 0 |
8.4.2.1 | 8.4.2.1 Response structure: purpose | 0 |
8.4.2.2 | 8.4.2.2 Response structure: design | 0 |
8.4.2.3 | 8.4.2.3 Team capabilities | 0 |
8.4.2.4 | 8.4.2.4 Team composition and guidance | 0 |
8.4.3 | 8.4.3 Warning and communication | 0 |
8.4.3.1 | 8.4.3.1 Warning and communication: general | 0 |
8.4.3.2 | 8.4.3.2 Alerting interested parties | 0 |
8.4.4 | 8.4.4 Business continuity plans | 0 |
8.4.4.2 | 8.4.4.2 Business continuity plans: coverage and incident response | 0 |
8.4.4.3 | 8.4.4.3 Content, guidance and usability | 0 |
8.4.4.4 | 8.4.4.4 Incident management and strategic management | 0 |
8.4.4.5 | 8.4.4.5 Communication | 0 |
8.4.4.6 | 8.4.4.6 Safety and welfare | 0 |
8.4.4.7 | 8.4.4.7 Salvage and security | 0 |
8.4.4.8 | 8.4.4.8 Resumption of prioritized activities | 0 |
8.4.4.9 | 8.4.4.9 ICT systems | 0 |
8.4.5 | 8.4.5 Recovery | 0 |
8.5 | 8.5 Exercise programme | 0 |
8.5.1 | 8.5.1 Exercise programme: general | 0 |
8.5.2 | 8.5.2 Design of the exercise programme | 0 |
8.5.3 | 8.5.3 Exercising business continuity plans | 0 |
8.6 | 8.6 Evaluation of business continuity documentation and capabilities | 0 |
8.6.1 | 8.6.1 Evaluation of business continuity documentation and capabilities: general | 0 |
8.6.2 | 8.6.2 Measuring effectiveness | 0 |
8.6.3 | 8.6.3 Outcomes | 0 |
9 | 9 Performance evaluation | 0 |
9.1 | 9.1 Monitoring, measurement, analysis and evaluation | 0 |
9.1.1 | 9.1.1 Monitoring, measurement, analysis and evaluation: general | 0 |
9.1.2 | 9.1.2 Retention of evidence | 0 |
9.1.3 | 9.1.3 Performance evaluation | 0 |
9.2 | 9.2 Internal audit | 0 |
9.2.1 | 9.2.1 Internal audit: general | 0 |
9.2.2 | 9.2.2 Audit programme(s) | 0 |
9.3 | 9.3 Management review | 0 |
9.3.1 | 9.3.1 Management review: general | 0 |
9.3.2 | 9.3.2 Management review input | 0 |
9.3.3 | 9.3.3 Management review outputs | 0 |
STANDARD | ISO 22313:2020: the standard, its scope and what is held | 0 |
STATUS | Edition status: the 2020 second edition is current; guidance on ISO 22301, not certifiable | 0 |
SUPPORT_NOTE | Every guidance leaf names the ISO 22301:2019 clause it supports | 0 |