International (ISO/TC 292); adopted as PD ISO/TS 22317 (UK) and by other national bodies

ISO/TS 22317:2021

72 controls. 125 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

72 controls 125 frameworks share controls with it International (ISO/TC 292); adopted as PD ISO/TS 22317 (UK) and by other national bodies verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
ISO22317-01Business continuity policy0
ISO22317-02BCM program scope and objectives0
ISO22317-03Resource allocation for BCM0
ISO22317-04BCM roles and responsibilities0
ISO22317-05Management commitment to BCM2
ISO22317-06Business impact analysis methodology1
ISO22317-07Critical activity identification0
ISO22317-08Recovery time and point objectives69
ISO22317-09Resource requirements assessment1
ISO22317-10Interdependency mapping0
ISO22317-11Continuity strategy development27
ISO22317-12Recovery strategy for critical activities69
ISO22317-13Alternate site and resource planning0
ISO22317-14Supply chain continuity77
ISO22317-15Communication strategy during disruption40
ISO22317-16Exercise program development0
ISO22317-17Tabletop and simulation exercises0
ISO22317-18Full-scale testing procedures0
ISO22317-19Post-exercise review and improvement0
ISO22317-20Plan maintenance and update0
ISO22317-4.1BIA Programme Establishment0
ISO22317-4.2BIA Methodology and Approach0
ISO22317-5.1Prioritized Activities Identification0
ISO22317-5.2Impact Categories and Tolerances0
ISO22317-5.3Maximum Tolerable Period of Disruption (MTPD)0
ISO22317-5.4Recovery Time Objective (RTO)0
ISO22317-5.5Recovery Point Objective (RPO)0
ISO22317-5.6Minimum Business Continuity Objective (MBCO)0
ISO22317-5.7Resource Requirements Analysis1
ISO22317-5.8Interdependencies and Single Points of Failure0
ISO22317-6.1BIA Data Collection0
ISO22317-6.2BIA Validation and Sign Off0
ISO22317-7.1BIA Outputs Reporting0
ISO22317-7.2Linking BIA to Continuity Strategy0
ISO22317-8.1BIA Maintenance and Refresh0
ISO22317-8.2BIA Programme Assurance0
44 Prerequisites0
4.24.2 Context and scope0
4.2.14.2.1 Context0
4.2.24.2.2 Scope0
4.34.3 Roles and responsibilities0
4.3.24.3.2 BIA leader0
4.3.34.3.3 Activity owners0
4.44.4 Commitment0
55 The BIA process0
5.15.1 Fundamentals0
5.25.2 Plan BIA0
5.35.3 Agree approach for undertaking BIA process0
5.3.15.3.1 Understand impacts0
5.3.25.3.2 Define impact types and criteria0
5.3.35.3.3 Define time frames0
5.3.45.3.4 Define methodology0
5.45.4 Determine products and services' priorities with top management0
5.4.35.4.3 Product and service priority determination0
5.55.5 Determine the prioritized activities0
5.5.35.5.3 Identify activities0
5.5.45.5.4 Set RTO for the activities0
5.5.55.5.5 Define the prioritized activities0
5.65.6 Identify resources and other dependencies0
5.6.15.6.1 Identify resource and other dependency requirements0
5.6.25.6.2 Resource requirements0
5.75.7 Analyse and consolidate BIA results0
5.85.8 Obtain top management approval for BIA results0
66 Review BIA0
6.16.1 Review BIA process and methodology0
6.26.2 Review BIA results0
AAnnex A BIA within the BCMS of ISO 22301:2019 (informative)0
BAnnex B BIA information collection methods (informative)0
CAnnex C Other uses for the BIA process (informative)0
DAnnex D Examples for performing a BIA (informative)0
STANDARDISO/TS 22317:2021: the specification, its scope and what is held0
STATUSEdition status: the 2021 second edition is current; the framework renamed from 'ISO 22317' and its version corrected from 20150

Tell me when ISO/TS 22317:2021 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Internal audit reports on BIA
  • Peer review or external assurance reports
  • Improvement action log
  • compliance assessment reports
  • regulatory inventory
  • corrective action plans
  • Acquisition workflow with C-SCRM gates
  • Requirements templates with C-SCRM clauses
  • Source selection evaluation criteria
  • Award documentation

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/TS 22317:2021, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition