Iso 22301 - BC
Iso 22301 - BC
Iso 22301 - BC
BUSINESS MANAGEMENT
CONTINUITY MANAGEMENT SYSTEMS
Course Objectives
• Introduction to ISO
• To develop an understanding of Business
Continuity
• Name
• Role and department you work in
• What role do you have in business
continuity
• Have you ever been involved in responding
to a business continuity incident
• Favourite sweet you had when you were
growing up!
www.england.nhs.uk 3
Introduction to ISO
• ISO is an international body that develops
international standards for over 160 countries
• Established in 1974
• It establishes international standards and operates as
an NGO
• It has developed over 22,000 standards
www.england.nhs.uk
ISO Certification process
• Develop a need (Why you need ISO certification)
• Training
• Pre-assessment – optional pre-assessment identifies
any omissions or weaknesses that need resolving.
• Assessment (Audit/Gap Analysis) – this comprises a
number of stages, depending on the chosen standard.
• Certification – 3 years
• Compliance – your client manager will carry out
ongoing assessments to support your continual
improvement activities.
www.england.nhs.uk
What is a Business Continuity?
Holistic management process that identifies potential threats to an organisation and the impacts to
business operations that those threats, if realized, might cause, and which provides a framework for
building organisational resilience with the capability for an effective response that safeguards the
interest of its key stakeholders, reputation, brand and value-creating activities.
• It enables an organization to have a more effective response and a quicker recovery, thereby reducing
any impact on people, products and the organization’s bottom line.
• ISO 22301 specifies requirements to plan, establish, implement, operate, monitor, review,
maintain and continually improve a documented management system to protect against, reduce
the likelihood of occurrence, prepare for, respond to, and recover from disruptive incidents
when they arise.
www.england.nhs.uk
Step 1 Understand the Organisation
ABC Corp
May 2022
www.england.nhs.uk 7
What is a
Business Continuity Management System?
www.england.nhs.uk 9
Some Impacts of a BC event
• Interruption of standard operating
procedures,
• Inability to meet service levels,
deadlines,
Any one of
• Cash flow issues,
• Financial losses,
these can
• Interruption of services to customers or result in the
stakeholders, failure of the
• Damaged reputation / credibility, enterprise!
• Market share,
• …
www.england.nhs.uk 10
BENEFITSs a wise investment
www.england.nhs.uk
Optical Illusion
www.england.nhs.uk
Preparation
• Before, during and after
www.england.nhs.uk
Monkey Business
Solution
www.england.nhs.uk
International BCM Standard – ISO 22301
Clause 1 : Scope
Clause 2 : Normative references
Clause 3 : Terms and definitions
Clause 4 : Context of the organisation
Clause 5 : Leadership
Clause 6 : Planning
Clause 7 : Support
Clause 8 : Operation
Clause 9 : Performance evaluation
Clause 10 : Improvement
www.england.nhs.uk
Please implement a BCMS – not just BCM
www.england.nhs.uk
Business Continuity Implementation Roadmap
www.england.nhs.uk
Clause 4 :Context of the organisation
www.england.nhs.uk
LOGO
www.england.nhs.uk 20
Determining the scope of the business
continuity management system (Extent)
www.england.nhs.uk
Plan Do Check Act Cycle 2
www.england.nhs.uk
Determining the scope of the business
continuity management system (Extent)
www.england.nhs.uk
Understanding the Organisation
Suppliers
Suppliers
&& Understanding
Understandingthe
theOrganisation
Organisation Internal
Internal
Partner
Partner Context
Context External
External
Organisations
Organisations Purpose
Purpose of of Organisation
Organisation Context
Context
Products
Products & Services
& Services Products
Products & Services
& Services Patients
Patients & Clients
& Clients
Products
Products &&
Services
Services
Activity
Activity Activity
Activity Activity
Activity Activity
Activity Activity
Activity Activity
Activity
Supporting
Supporting Dependencies
Dependencies andand
activity
activity supporting activities
supporting activities
Assets
Assets and
and
resources
resources Assets
Assets and
and resources
resources
www.england.nhs.uk 24
Business Impact Analysis
www.england.nhs.uk 25
Business Impact Analysis (BIA)
Template
• Risk assessment and treatment
www.england.nhs.uk
2
Business Impact Analysis
www.england.nhs.uk
2
Activity 2
• In your groups:
www.england.nhs.uk
2
Clause 5 : Leadership
Top management shall demonstrate leadership and commitment with respect to the BCMS by:
a) ensuring that the business continuity policy and business continuity objectives are established and are compatible with the strategic direction of the organization;
b) ensuring the integration of the BCMS requirements into the organization’s business processes;
c) ensuring that the resources needed for the BCMS are available;
d) communicating the importance of effective business continuityand of conforming to the BCMS requirements;
e) ensuring that the BCMS achieves its intended outcome(s);
f) directing and supporting persons to contribute to the effectiveness of the BCMS;
g) promoting continual improvement;
h) supporting other relevant managerial roles to demonstrate their leadership and commitment as it applies to their areas of responsibility.
www.england.nhs.uk
LOGO
Best Practices
Policy Development
• Top management shall establish a business continuity policy that:
• a) is appropriate to the purpose of the organization;
• b) provides a framework for setting business continuity objectives;
• c) includes a commitment to satisfy applicable requirements;
• d) includes a commitment to continual improvement of the BCMS.
POLICY IMPLIMENTATION
32
Elements of
Business Continuity Management 2
Business
impact
analysis
and risk
assessment
Operational Business
Exercising
and Testing planning Continuity
Strategy
and control
Establish
and
implement
BC
procedures
www.england.nhs.uk ISO22313 33
Business Continuity Strategy Options
Stakeholders
Technology
Information
Premises
Suppliers
People
www.england.nhs.uk 34
Activity 3
In your groups discuss:
www.england.nhs.uk
3
Activity 3 Summary
• This is a senior management
responsibility that:
• Is appropriate to the organisation
• Provides a framework for setting
business continuity objectives
• To continual improvement of the
business continuity management
system
www.england.nhs.uk
3
Reviewing Business Continuity
www.england.nhs.uk 37
Questions
www.england.nhs.uk
Next Steps……
www.england.nhs.uk
Clause 5 : Leadership
www.england.nhs.uk
Clause 6 : Planning
• C
www.england.nhs.uk
Clause 7 : Support
www.england.nhs.uk
Clause 8:Operation
www.england.nhs.uk
Clause 9 : Performance Evaluation
• C
www.england.nhs.uk
Clause 10 : Improvement
www.england.nhs.uk