ISO 22301 Self Assessment Checklist
ISO 22301 Self Assessment Checklist
ISO 22301 Self Assessment Checklist
Self-assessment questionnaire
Has the organization planned actions to address these risks Does the BIA enable prioritization of timeframes for
and opportunities and integrated them into the system resuming each activity (Recovery Time Objectives) and
processes? have minimum levels for resuming activities that have been
identified?
Have measureable business continuity (BC) objectives been
established, documented and communicated throughout Have these actions been documented?
the organization with a plan to achieve them?
Is the BC strategy based on the outputs of the BIA and risk
assessment?
Support Does the BC strategy protect prioritized activities and
Has the organization determined and provided the provide appropriate continuity and recovery of them,
resources needed for the establishment, implementation, their dependencies and resources?
maintenance and continual improvement of the BCMS
(including people, infrastructure and environment for the Does the BC strategy provide for mitigating, responding to
operation of processes)? and managing impacts?
Are these processes consistent with the personnel in Have prioritized time frames been set for the resumption of
the defined BCMS roles? all activities?
Has the organization determined the knowledge necessary Have the BC capabilities of suppliers been evaluated and
for those performing BCMS roles? mitigated?
Has the organization ensured that those persons who can Have the resource requirements for the selected strategy
affect the performance and effectiveness of the BCMS are options been determined, including people, information
competent on the basis of appropriate education, training and data, infrastructure, facilities, consumables, IT,
or experience, or has action been taken to ensure that transport, finance and partner/supplier services?
those persons can gain the necessary competence?
Have measures to reduce the likelihood, duration or
Has the documented information required by the standard impact of a disruption for identified risks been considered
and necessary for the effective implementation and and implemented, and are these in accordance with the
operation of the ISMS been established? organization’s risk appetite?
Is the documented information controlled in a way that it Have documented BC procedures been put in place
is available and adequately protected, distributed, stored, to manage a disruptive incident, and have continuity
retained and under change control, including documents activities based on recovery objectives been identifed in
of external origin required by the organization for the the BIA?
BCMS?
Have internal and external communication protocols been
established as part of these procedures?
Operation Is there an Incident Response Structure (IRS) which details
Have you devised and implemented a program to ensure the management structure and trained personnel in place
the BCMS achieves its outcomes? to respond to a disruptive incident?
Is there a plan for the determining the need for changes to Does the IRS and associated procedures include
the BCMS and managing their implementation? thresholds, assessment, activation, resource provision and
communication?
When changes are planned, are they carried out in a
controlled way and actions taken to mitigate any adverse Do the people in your IRS have the necessary
effects? competencies to perform their duties and are records kept
to demonstrate this?
If you have outsourced processes, are they
appropriately controlled? Is there a procedure for detecting and monitoring
incidents, which includes recording vital information,
Is there a formal and documented process for actions taken and decisions made?
understanding the organization through a Business Impact
Analysis (BIA)?
Continued >>
ISO 22301 Business Continuity Management – Self-assessment questionnaire
Visit: bsigroup.com/en-US