SlideShare a Scribd company logo
1 of 22
Ā© Operational Excellence Consulting. All rights reserved.
ISO 22301:2019
SECURITY & RESILIENCE:
Business Continuity Management Systems
Ā© Operational Excellence Consulting. All rights reserved.
Ā© Operational Excellence Consulting. All rights reserved. 2
Learning Objectives
Provide
background
knowledge of
ISO 22301:2019
Gain an
overview of the
ISO 22301:2019
structure
Understand the
ISO 22301:2019
certification
process
Learn useful tips
on handling an
audit session
NOTE: As this is a PREVIEW, only selected
slides are shown. To download the complete
presentation, please visit:
http://www.oeconsulting.com.sg
Ā© Operational Excellence Consulting. All rights reserved. 3
Contents
2
3
4
ISO 22301 Structure
ISO 22301 Certification Process
Handling an Audit Session
1 Introduction to ISO 22301
Ā© Operational Excellence Consulting. All rights reserved. 4
Introduction to ISO 22301, Security and resilience
ā€“ Business continuity management systems
ā€¢ Floods, virus infection, cyber-attacks, IT breakdowns or
supply chain issues are just some of the possible threats
to the smooth running of an organization
ā€¢ If not addressed effectively, they can cause disruption or
even business failure
ā€¢ Consistent planning for what to do when disaster strikes
means a more effective response and a quicker recovery
ā€¢ ISO 22301 is an International Standard for implementing
and maintaining effective business continuity plans,
systems and processes
Ā© Operational Excellence Consulting. All rights reserved. 5
What is ISO 22301:2019?
ā€¢ ISO 22301:2019 identifies the
fundamentals of best practice
business continuity
ā€¢ It establishes a framework for
industrial plants or entire
companies to manage all
aspects of business continuity
ā€¢ Applies to any organization,
large or small, with or
nonprofit, private or public
Ā© Operational Excellence Consulting. All rights reserved. 6
Objective of ISO 22301:2019
ā€¢ ISO 22301:2019 specifies
requirements to implement,
maintain and improve a
management system to
protect against, reduce the
likelihood of the occurrence
of, prepare for, respond to
and recover from disruptions
when they arise
Ā© Operational Excellence Consulting. All rights reserved. 7
What improvements were made to ISO
22301:2019?
The structure of the standard has been reviewed
to make it easier to read and implement, with
greater clarification of what is required
The language and terminology have been
simplified to remove duplication and better reflect
todayā€™s thinking in the business continuity industry
The High Level Structure (HLS) has been
streamlined to remain in line with all other ISO
management system standards.
Ā© Operational Excellence Consulting. All rights reserved. 8
Benefits to an Organization for Implementing a
Business Continuity Management System
ā€¢ Help organizations respond to, and recover from, disruptions
effectively
ā€¢ Reduced costs and less impact on business performance should
something go wrong
ā€¢ Companies with multiple sites or divisions can rely on the same
consistent approach throughout the entire organization
ā€¢ Provides ability to reassure clients, suppliers, regulators and other
stakeholders that the organization has sound systems and
processes in place for business continuity
ā€¢ Improved business performance and organizational resilience
ā€¢ A better understanding of the business through analysis of critical
issues and areas of vulnerability
Ā© Operational Excellence Consulting. All rights reserved. 9
Overview of Annex L
ā€¢ Annex L is a framework for a generic management
system. However, it requires the addition of discipline-
specific requirements to make a fully functional standard.
Annex L
High-level
structure
Identical
core text
Common
definition
Ā© Operational Excellence Consulting. All rights reserved. 10
The ISO 22301:2019 Structure is Aligned to the Common
Structure for Management System Standards (MSS)
1. Scope
2. Normative references
3. Terms and definitions
4. Context of the organization
5. Leadership
6. Planning
7. Support
8. Operation
9. Performance evaluation
10. Improvement
Ā© Operational Excellence Consulting. All rights reserved. 11Ā© Operational Excellence Consulting. All rights reserved. 11
Plan-Do-Check-Act (PDCA) Process Model
Implement and operate
the processes of the
BCMS
Establish objectives and
processes necessary to
deliver results in
accordance with
requirements and the
organizationā€™s BCM policy
Monitor and review the
processes with regard to
the BCMS policy and
objectives and report the
results
Maintain and
continually improve the
effectiveness of the
organizationā€™s BCMS
Plan
Do
Act
Check
Ā© Operational Excellence Consulting. All rights reserved. 12
In accordance with the PDCA cycle, Clauses 4 to 10 cover
the following components
Clauses Description
4. Context of the organization
Introduces the requirements necessary to establish the context of
the BCMS applicable to the organization, as well as needs,
requirements and scope
5. Leadership
Summarizes the requirements specific to top managementā€™s role in
the BCMS, and how leadership articulates its expectations to the
organization via a policy statement
6. Planning
Describes the requirements for establishing strategic objectives
and guiding principles for the BCMS as a whole.
7. Support
Supports BCMS operations related to establishing competence
and communication on a recurring/as-needed basis with interested
parties, while documenting, controlling, maintaining and retaining
required documented information.
Ā© Operational Excellence Consulting. All rights reserved. 13
ISO 22301:2019 Clause Structure (4-10)
PLAN DO CHECK ACT
4. Context of the
organization
5. Leadership 6. Planning 7. Support 8. Operation 9. Performance
evaluation
10. Improvement
4.1 Understanding the
organization and its
context
5.1 Leadership and
commitment
6.1 Actions to address
risks and
opportunities
7.1 Resources 8.1 Operational
planning and control
9.1 Monitoring,
measurement,
analysis and
evaluation
10.1 Nonconformity
and corrective action
4.2 Understanding the
needs and
expectations of
interested parties
5.2 Policy 6.2 Business
continuity objectives
and plans to achieve
them
7.2 Competence 8.2 Business impact
analysis and risk
assessment
9.2 Internal audit 10.2 Continual
improvement
4.3 Determining the
scope of the BCMS
5.3 Roles,
responsibilities and
authorities
6.3 Planning changes
to the BCMS
7.3 Awareness 8.3 Business
continuity strategies
and solutions
9.3 Management
review
4.4 Business
continuity
management system
7.4 Communication 8.4 Business
continuity plans and
procedures
7.5 Documented
information
8.5 Exercise
programme
8.6 Evaluation of
business continuity
documentation and
capabilities
Ā© Operational Excellence Consulting. All rights reserved. 14
Becoming ISO 22301:2019 Certified
ā€¢ The certification body
examines the BCMS for
conformity to the ISO
22301:2019 standard
ā€¢ The ISO 22301:2019 audit is
a compliance audit
ā€¢ Certification means the
organization has a
documented BCMS that is
fully implemented and meets
ISO 22301:2019 requirements
Ā© Operational Excellence Consulting. All rights reserved. 15
2022
2021 Full conformance
with new
standard
Recertification
audits to new
standard
2020-
2022
2019
Transition to full
compliance
Published ISO
22301:2019
ISO 22301:2019 Certification
Transition Timeline
Recertification
audits to new
standard
2020
Organizations certified to the
2012 version must transition
to the 2019 version by
October 31, 2022
Organizations can be certified
against 2019 revision
beginning April 30, 2020
Ā© Operational Excellence Consulting. All rights reserved. 16
ISO 22301:2019 Certification Process
Implementation
of BCMS
Conduct Internal
Audit and Review
Result by Top
Management
Selection of a
Certification Body
Stage 1 AuditStage 2 Audit
Confirmation of
Registration
Continual
Improvement and
Surveillance
Audits
Ā© Operational Excellence Consulting. All rights reserved. 17
Audit Findings
Minor Non-conformity
Observation
Major Non-conformity
Ā© Operational Excellence Consulting. All rights reserved. 18
How to Handle the Audit Session?
ā€¢ Do not panic
ā€¢ Ask and clarify
ā€¢ Admit obvious non-conformities
ā€¢ Offer evidence and explain patiently
ā€¢ Take note of improvement areas highlighted by the
auditor
ā€¢ Show internal audit report, when necessary
Ā© Operational Excellence Consulting. All rights reserved. 19
Auditeeā€™s Conduct
ā€¢ Polite
ā€¢ Professional
ā€¢ Positive / Receptive
ā€¢ Sincere
ā€¢ Commitment
ā€¢ Formal but not overly
serious
Ā© Operational Excellence Consulting. All rights reserved. 20
Interacting with Auditors
ā€¢ Be honest and open
ā€¢ Recognize they may be experts
ā€¢ Realize they may not be subject
matter experts
ā€¢ Understand the purpose of the
meeting and review related records
prior to interviews
ā€¢ Turn mobile phones to silent mode
Ā© Operational Excellence Consulting. All rights reserved. 21
Interacting with Auditors
ā€¢ Assume auditors are familiar with
your organizationā€™s BCMS
ā€¢ Challenge auditors
ā€¢ Show more competence in ISO
22301:2019
ā€¢ Argue internally
ā€¢ Express unfairness
ā€¢ Ask for solution
ā€¢ Fix non-conformities on the spot
Ā© Operational Excellence Consulting. All rights reserved.
END OF PARTIAL PREVIEW
To download this presentation,
please visit:
www.oeconsulting.com.sg

More Related Content

More from Operational Excellence Consulting

Seven Advanced Tools of Quality (Seven Advanced QC Tools)
Seven Advanced Tools of Quality (Seven Advanced QC Tools)Seven Advanced Tools of Quality (Seven Advanced QC Tools)
Seven Advanced Tools of Quality (Seven Advanced QC Tools)Operational Excellence Consulting
Ā 
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness PosterISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness PosterOperational Excellence Consulting
Ā 

More from Operational Excellence Consulting (20)

Digital Strategic Business Planning Methodology
Digital Strategic Business Planning MethodologyDigital Strategic Business Planning Methodology
Digital Strategic Business Planning Methodology
Ā 
Root Cause Analysis (RCA)
Root Cause Analysis (RCA)Root Cause Analysis (RCA)
Root Cause Analysis (RCA)
Ā 
Business Process Reengineering (BPR)
Business Process Reengineering (BPR)Business Process Reengineering (BPR)
Business Process Reengineering (BPR)
Ā 
5 Steps of Problem Solving
5 Steps of Problem Solving5 Steps of Problem Solving
5 Steps of Problem Solving
Ā 
Seven Advanced Tools of Quality (Seven Advanced QC Tools)
Seven Advanced Tools of Quality (Seven Advanced QC Tools)Seven Advanced Tools of Quality (Seven Advanced QC Tools)
Seven Advanced Tools of Quality (Seven Advanced QC Tools)
Ā 
Seven Basic Tools of Quality (Seven Basic QC Tools)
Seven Basic Tools of Quality (Seven Basic QC Tools)Seven Basic Tools of Quality (Seven Basic QC Tools)
Seven Basic Tools of Quality (Seven Basic QC Tools)
Ā 
Problem Solving & Visualization Tools
Problem Solving & Visualization ToolsProblem Solving & Visualization Tools
Problem Solving & Visualization Tools
Ā 
PDCA Problem Solving Process & Tools
PDCA Problem Solving Process & ToolsPDCA Problem Solving Process & Tools
PDCA Problem Solving Process & Tools
Ā 
8D Problem Solving Process & Tools
8D Problem Solving Process & Tools8D Problem Solving Process & Tools
8D Problem Solving Process & Tools
Ā 
Digital Transformation Process Poster
Digital Transformation Process PosterDigital Transformation Process Poster
Digital Transformation Process Poster
Ā 
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness PosterISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Poster
Ā 
Four Steps of Jidoka Poster
Four Steps of Jidoka PosterFour Steps of Jidoka Poster
Four Steps of Jidoka Poster
Ā 
Lean Startup: Build-Measure-Learn Process Poster
Lean Startup: Build-Measure-Learn Process PosterLean Startup: Build-Measure-Learn Process Poster
Lean Startup: Build-Measure-Learn Process Poster
Ā 
AIDA Marketing Model Poster
AIDA Marketing Model PosterAIDA Marketing Model Poster
AIDA Marketing Model Poster
Ā 
TPM: One-Point Lessons Poster
TPM: One-Point Lessons PosterTPM: One-Point Lessons Poster
TPM: One-Point Lessons Poster
Ā 
4M Analysis Poster
4M Analysis Poster4M Analysis Poster
4M Analysis Poster
Ā 
Hoshin Planning Poster
Hoshin Planning PosterHoshin Planning Poster
Hoshin Planning Poster
Ā 
Customer-Centricity
Customer-CentricityCustomer-Centricity
Customer-Centricity
Ā 
Lean Daily Management System (LDMS) Poster
Lean Daily Management System (LDMS) PosterLean Daily Management System (LDMS) Poster
Lean Daily Management System (LDMS) Poster
Ā 
Business Model Canvas
Business Model CanvasBusiness Model Canvas
Business Model Canvas
Ā 

Recently uploaded

RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataExhibitors Data
Ā 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
Ā 
Lucknow šŸ’‹ Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow šŸ’‹ Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow šŸ’‹ Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow šŸ’‹ Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
Ā 
B.COM Unit ā€“ 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit ā€“ 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit ā€“ 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit ā€“ 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxpriyanshujha201
Ā 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
Ā 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...Aggregage
Ā 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
Ā 
Yaroslav Rozhankivskyy: Š¢Ń€Šø сŠŗŠ»Š°Š“Š¾Š²Ń– і трŠø ŠæŠµŃ€ŠµŠ“уŠ¼Š¾Š²Šø Š¼Š°ŠŗсŠøŠ¼Š°Š»ŃŒŠ½Š¾Ń— ŠæрŠ¾Š“уŠŗтŠøŠ²Š½...
Yaroslav Rozhankivskyy: Š¢Ń€Šø сŠŗŠ»Š°Š“Š¾Š²Ń– і трŠø ŠæŠµŃ€ŠµŠ“уŠ¼Š¾Š²Šø Š¼Š°ŠŗсŠøŠ¼Š°Š»ŃŒŠ½Š¾Ń— ŠæрŠ¾Š“уŠŗтŠøŠ²Š½...Yaroslav Rozhankivskyy: Š¢Ń€Šø сŠŗŠ»Š°Š“Š¾Š²Ń– і трŠø ŠæŠµŃ€ŠµŠ“уŠ¼Š¾Š²Šø Š¼Š°ŠŗсŠøŠ¼Š°Š»ŃŒŠ½Š¾Ń— ŠæрŠ¾Š“уŠŗтŠøŠ²Š½...
Yaroslav Rozhankivskyy: Š¢Ń€Šø сŠŗŠ»Š°Š“Š¾Š²Ń– і трŠø ŠæŠµŃ€ŠµŠ“уŠ¼Š¾Š²Šø Š¼Š°ŠŗсŠøŠ¼Š°Š»ŃŒŠ½Š¾Ń— ŠæрŠ¾Š“уŠŗтŠøŠ²Š½...Lviv Startup Club
Ā 
VIP Call Girls In Saharaganj ( Lucknow ) šŸ” 8923113531 šŸ” Cash Payment (COD) šŸ‘’
VIP Call Girls In Saharaganj ( Lucknow  ) šŸ” 8923113531 šŸ”  Cash Payment (COD) šŸ‘’VIP Call Girls In Saharaganj ( Lucknow  ) šŸ” 8923113531 šŸ”  Cash Payment (COD) šŸ‘’
VIP Call Girls In Saharaganj ( Lucknow ) šŸ” 8923113531 šŸ” Cash Payment (COD) šŸ‘’anilsa9823
Ā 
HONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsHONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsMichael W. Hawkins
Ā 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
Ā 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Roland Driesen
Ā 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
Ā 
Call Girls Jp Nagar Just Call šŸ‘— 7737669865 šŸ‘— Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call šŸ‘— 7737669865 šŸ‘— Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call šŸ‘— 7737669865 šŸ‘— Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call šŸ‘— 7737669865 šŸ‘— Top Class Call Girl Service Bang...amitlee9823
Ā 
Understanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key InsightsUnderstanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key Insightsseri bangash
Ā 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
Ā 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfOnline Income Engine
Ā 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
Ā 
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...Any kyc Account
Ā 

Recently uploaded (20)

RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors Data
Ā 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Ā 
Lucknow šŸ’‹ Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow šŸ’‹ Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow šŸ’‹ Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow šŸ’‹ Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Ā 
B.COM Unit ā€“ 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit ā€“ 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit ā€“ 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit ā€“ 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
Ā 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
Ā 
VVVIP Call Girls In Greater Kailash āž”ļø Delhi āž”ļø 9999965857 šŸš€ No Advance 24HRS...
VVVIP Call Girls In Greater Kailash āž”ļø Delhi āž”ļø 9999965857 šŸš€ No Advance 24HRS...VVVIP Call Girls In Greater Kailash āž”ļø Delhi āž”ļø 9999965857 šŸš€ No Advance 24HRS...
VVVIP Call Girls In Greater Kailash āž”ļø Delhi āž”ļø 9999965857 šŸš€ No Advance 24HRS...
Ā 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
Ā 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
Ā 
Yaroslav Rozhankivskyy: Š¢Ń€Šø сŠŗŠ»Š°Š“Š¾Š²Ń– і трŠø ŠæŠµŃ€ŠµŠ“уŠ¼Š¾Š²Šø Š¼Š°ŠŗсŠøŠ¼Š°Š»ŃŒŠ½Š¾Ń— ŠæрŠ¾Š“уŠŗтŠøŠ²Š½...
Yaroslav Rozhankivskyy: Š¢Ń€Šø сŠŗŠ»Š°Š“Š¾Š²Ń– і трŠø ŠæŠµŃ€ŠµŠ“уŠ¼Š¾Š²Šø Š¼Š°ŠŗсŠøŠ¼Š°Š»ŃŒŠ½Š¾Ń— ŠæрŠ¾Š“уŠŗтŠøŠ²Š½...Yaroslav Rozhankivskyy: Š¢Ń€Šø сŠŗŠ»Š°Š“Š¾Š²Ń– і трŠø ŠæŠµŃ€ŠµŠ“уŠ¼Š¾Š²Šø Š¼Š°ŠŗсŠøŠ¼Š°Š»ŃŒŠ½Š¾Ń— ŠæрŠ¾Š“уŠŗтŠøŠ²Š½...
Yaroslav Rozhankivskyy: Š¢Ń€Šø сŠŗŠ»Š°Š“Š¾Š²Ń– і трŠø ŠæŠµŃ€ŠµŠ“уŠ¼Š¾Š²Šø Š¼Š°ŠŗсŠøŠ¼Š°Š»ŃŒŠ½Š¾Ń— ŠæрŠ¾Š“уŠŗтŠøŠ²Š½...
Ā 
VIP Call Girls In Saharaganj ( Lucknow ) šŸ” 8923113531 šŸ” Cash Payment (COD) šŸ‘’
VIP Call Girls In Saharaganj ( Lucknow  ) šŸ” 8923113531 šŸ”  Cash Payment (COD) šŸ‘’VIP Call Girls In Saharaganj ( Lucknow  ) šŸ” 8923113531 šŸ”  Cash Payment (COD) šŸ‘’
VIP Call Girls In Saharaganj ( Lucknow ) šŸ” 8923113531 šŸ” Cash Payment (COD) šŸ‘’
Ā 
HONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsHONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael Hawkins
Ā 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
Ā 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...
Ā 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
Ā 
Call Girls Jp Nagar Just Call šŸ‘— 7737669865 šŸ‘— Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call šŸ‘— 7737669865 šŸ‘— Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call šŸ‘— 7737669865 šŸ‘— Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call šŸ‘— 7737669865 šŸ‘— Top Class Call Girl Service Bang...
Ā 
Understanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key InsightsUnderstanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key Insights
Ā 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
Ā 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdf
Ā 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
Ā 
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
Ā 

ISO 22301:2019 (Security & Resilience - BCMS) Awareness Training

  • 1. Ā© Operational Excellence Consulting. All rights reserved. ISO 22301:2019 SECURITY & RESILIENCE: Business Continuity Management Systems Ā© Operational Excellence Consulting. All rights reserved.
  • 2. Ā© Operational Excellence Consulting. All rights reserved. 2 Learning Objectives Provide background knowledge of ISO 22301:2019 Gain an overview of the ISO 22301:2019 structure Understand the ISO 22301:2019 certification process Learn useful tips on handling an audit session NOTE: As this is a PREVIEW, only selected slides are shown. To download the complete presentation, please visit: http://www.oeconsulting.com.sg
  • 3. Ā© Operational Excellence Consulting. All rights reserved. 3 Contents 2 3 4 ISO 22301 Structure ISO 22301 Certification Process Handling an Audit Session 1 Introduction to ISO 22301
  • 4. Ā© Operational Excellence Consulting. All rights reserved. 4 Introduction to ISO 22301, Security and resilience ā€“ Business continuity management systems ā€¢ Floods, virus infection, cyber-attacks, IT breakdowns or supply chain issues are just some of the possible threats to the smooth running of an organization ā€¢ If not addressed effectively, they can cause disruption or even business failure ā€¢ Consistent planning for what to do when disaster strikes means a more effective response and a quicker recovery ā€¢ ISO 22301 is an International Standard for implementing and maintaining effective business continuity plans, systems and processes
  • 5. Ā© Operational Excellence Consulting. All rights reserved. 5 What is ISO 22301:2019? ā€¢ ISO 22301:2019 identifies the fundamentals of best practice business continuity ā€¢ It establishes a framework for industrial plants or entire companies to manage all aspects of business continuity ā€¢ Applies to any organization, large or small, with or nonprofit, private or public
  • 6. Ā© Operational Excellence Consulting. All rights reserved. 6 Objective of ISO 22301:2019 ā€¢ ISO 22301:2019 specifies requirements to implement, maintain and improve a management system to protect against, reduce the likelihood of the occurrence of, prepare for, respond to and recover from disruptions when they arise
  • 7. Ā© Operational Excellence Consulting. All rights reserved. 7 What improvements were made to ISO 22301:2019? The structure of the standard has been reviewed to make it easier to read and implement, with greater clarification of what is required The language and terminology have been simplified to remove duplication and better reflect todayā€™s thinking in the business continuity industry The High Level Structure (HLS) has been streamlined to remain in line with all other ISO management system standards.
  • 8. Ā© Operational Excellence Consulting. All rights reserved. 8 Benefits to an Organization for Implementing a Business Continuity Management System ā€¢ Help organizations respond to, and recover from, disruptions effectively ā€¢ Reduced costs and less impact on business performance should something go wrong ā€¢ Companies with multiple sites or divisions can rely on the same consistent approach throughout the entire organization ā€¢ Provides ability to reassure clients, suppliers, regulators and other stakeholders that the organization has sound systems and processes in place for business continuity ā€¢ Improved business performance and organizational resilience ā€¢ A better understanding of the business through analysis of critical issues and areas of vulnerability
  • 9. Ā© Operational Excellence Consulting. All rights reserved. 9 Overview of Annex L ā€¢ Annex L is a framework for a generic management system. However, it requires the addition of discipline- specific requirements to make a fully functional standard. Annex L High-level structure Identical core text Common definition
  • 10. Ā© Operational Excellence Consulting. All rights reserved. 10 The ISO 22301:2019 Structure is Aligned to the Common Structure for Management System Standards (MSS) 1. Scope 2. Normative references 3. Terms and definitions 4. Context of the organization 5. Leadership 6. Planning 7. Support 8. Operation 9. Performance evaluation 10. Improvement
  • 11. Ā© Operational Excellence Consulting. All rights reserved. 11Ā© Operational Excellence Consulting. All rights reserved. 11 Plan-Do-Check-Act (PDCA) Process Model Implement and operate the processes of the BCMS Establish objectives and processes necessary to deliver results in accordance with requirements and the organizationā€™s BCM policy Monitor and review the processes with regard to the BCMS policy and objectives and report the results Maintain and continually improve the effectiveness of the organizationā€™s BCMS Plan Do Act Check
  • 12. Ā© Operational Excellence Consulting. All rights reserved. 12 In accordance with the PDCA cycle, Clauses 4 to 10 cover the following components Clauses Description 4. Context of the organization Introduces the requirements necessary to establish the context of the BCMS applicable to the organization, as well as needs, requirements and scope 5. Leadership Summarizes the requirements specific to top managementā€™s role in the BCMS, and how leadership articulates its expectations to the organization via a policy statement 6. Planning Describes the requirements for establishing strategic objectives and guiding principles for the BCMS as a whole. 7. Support Supports BCMS operations related to establishing competence and communication on a recurring/as-needed basis with interested parties, while documenting, controlling, maintaining and retaining required documented information.
  • 13. Ā© Operational Excellence Consulting. All rights reserved. 13 ISO 22301:2019 Clause Structure (4-10) PLAN DO CHECK ACT 4. Context of the organization 5. Leadership 6. Planning 7. Support 8. Operation 9. Performance evaluation 10. Improvement 4.1 Understanding the organization and its context 5.1 Leadership and commitment 6.1 Actions to address risks and opportunities 7.1 Resources 8.1 Operational planning and control 9.1 Monitoring, measurement, analysis and evaluation 10.1 Nonconformity and corrective action 4.2 Understanding the needs and expectations of interested parties 5.2 Policy 6.2 Business continuity objectives and plans to achieve them 7.2 Competence 8.2 Business impact analysis and risk assessment 9.2 Internal audit 10.2 Continual improvement 4.3 Determining the scope of the BCMS 5.3 Roles, responsibilities and authorities 6.3 Planning changes to the BCMS 7.3 Awareness 8.3 Business continuity strategies and solutions 9.3 Management review 4.4 Business continuity management system 7.4 Communication 8.4 Business continuity plans and procedures 7.5 Documented information 8.5 Exercise programme 8.6 Evaluation of business continuity documentation and capabilities
  • 14. Ā© Operational Excellence Consulting. All rights reserved. 14 Becoming ISO 22301:2019 Certified ā€¢ The certification body examines the BCMS for conformity to the ISO 22301:2019 standard ā€¢ The ISO 22301:2019 audit is a compliance audit ā€¢ Certification means the organization has a documented BCMS that is fully implemented and meets ISO 22301:2019 requirements
  • 15. Ā© Operational Excellence Consulting. All rights reserved. 15 2022 2021 Full conformance with new standard Recertification audits to new standard 2020- 2022 2019 Transition to full compliance Published ISO 22301:2019 ISO 22301:2019 Certification Transition Timeline Recertification audits to new standard 2020 Organizations certified to the 2012 version must transition to the 2019 version by October 31, 2022 Organizations can be certified against 2019 revision beginning April 30, 2020
  • 16. Ā© Operational Excellence Consulting. All rights reserved. 16 ISO 22301:2019 Certification Process Implementation of BCMS Conduct Internal Audit and Review Result by Top Management Selection of a Certification Body Stage 1 AuditStage 2 Audit Confirmation of Registration Continual Improvement and Surveillance Audits
  • 17. Ā© Operational Excellence Consulting. All rights reserved. 17 Audit Findings Minor Non-conformity Observation Major Non-conformity
  • 18. Ā© Operational Excellence Consulting. All rights reserved. 18 How to Handle the Audit Session? ā€¢ Do not panic ā€¢ Ask and clarify ā€¢ Admit obvious non-conformities ā€¢ Offer evidence and explain patiently ā€¢ Take note of improvement areas highlighted by the auditor ā€¢ Show internal audit report, when necessary
  • 19. Ā© Operational Excellence Consulting. All rights reserved. 19 Auditeeā€™s Conduct ā€¢ Polite ā€¢ Professional ā€¢ Positive / Receptive ā€¢ Sincere ā€¢ Commitment ā€¢ Formal but not overly serious
  • 20. Ā© Operational Excellence Consulting. All rights reserved. 20 Interacting with Auditors ā€¢ Be honest and open ā€¢ Recognize they may be experts ā€¢ Realize they may not be subject matter experts ā€¢ Understand the purpose of the meeting and review related records prior to interviews ā€¢ Turn mobile phones to silent mode
  • 21. Ā© Operational Excellence Consulting. All rights reserved. 21 Interacting with Auditors ā€¢ Assume auditors are familiar with your organizationā€™s BCMS ā€¢ Challenge auditors ā€¢ Show more competence in ISO 22301:2019 ā€¢ Argue internally ā€¢ Express unfairness ā€¢ Ask for solution ā€¢ Fix non-conformities on the spot
  • 22. Ā© Operational Excellence Consulting. All rights reserved. END OF PARTIAL PREVIEW To download this presentation, please visit: www.oeconsulting.com.sg