ISO TS 22331-2018 PDF
Name in English:
St ISO TS 22331-2018
Name in Russian:
Ст ISO TS 22331-2018
Original standard ISO TS 22331-2018 in PDF full version. Additional info + preview on request
Full title and description
ISO/TS 22331:2018 — Security and resilience — Business continuity management systems — Guidelines for business continuity strategy. This technical specification provides guidance to organizations for determining and selecting appropriate business continuity strategies to meet business continuity requirements.
Abstract
This document gives guidance for business continuity strategy determination and selection. It is applicable to all organizations regardless of type, size and nature (private, public or not-for-profit) and is intended for use by those responsible for, or participating in, strategy determination and selection.
General information
- Status: Published.
- Publication date: Published 25 September 2018 (listed on ISO as 2018-09-25 / edition 2018).
- Publisher: International Organization for Standardization (ISO).
- ICS / categories: 03.100.01 (Organisation and management in general).
- Edition / version: Edition 1 (2018).
- Number of pages: 25 (as listed by ISO).
Scope
The standard gives guidance on how to determine and select business continuity strategies that satisfy the business continuity requirements identified through business impact analysis and risk assessment. It addresses considerations such as recovery time objectives, dependencies between activities and resources, and applicability of strategy options (for example mutual aid, alternate sites, substitution of resources, or documented exclusions). The guidance is intended to be applicable across organization types and sizes.
Key topics and requirements
- Principles for determining and selecting business continuity strategies based on outputs from business impact analysis (BIA) and risk assessment.
- Consideration of recovery time objectives (RTOs) and how RTOs for resources and activities influence strategy complexity and cost.
- Evaluation of strategy options (do nothing / accept, workaround, resource substitution, mutual aid, alternate sites, outsourcing) and their feasibility in the organization’s context.
- Guidance on documenting chosen strategies, verifying that they meet business continuity requirements, and reviewing strategies as business context or risks change.
- Alignment of strategy selection with the organization’s context, legal/regulatory obligations, stakeholders and cost/benefit considerations.
Typical use and users
BCMS implementers and maintainers, business continuity managers and planners, risk managers, senior management, continuity planners, and consultants use this TS to inform strategy options during BCMS implementation and review. It is also used by organizations developing recovery plans and by those evaluating the adequacy of selected continuity strategies.
Related standards
ISO/TS 22331 sits within the ISO security and resilience / BCMS family. Key related documents include ISO 22301 (Business continuity management systems — Requirements), ISO 22313 (Guidance on the use of ISO 22301), ISO 22300 (vocabulary), and companion technical specifications such as ISO/TS 22330 (people aspects of business continuity). These documents together support a BCMS lifecycle from terms and requirements through guidance and specialist topics.
Keywords
business continuity, BCMS, strategy, recovery time objective (RTO), business impact analysis (BIA), risk assessment, resilience, continuity strategy, continuity planning.
FAQ
Q: What is this standard?
A: ISO/TS 22331:2018 is an ISO Technical Specification that provides guidance for determining and selecting business continuity strategies as part of a BCMS.
Q: What does it cover?
A: It covers guidance on how to choose strategies to meet business continuity requirements identified by business impact analysis and risk assessment, including RTO considerations, strategy options and applicability, and documentation and review of strategies.
Q: Who typically uses it?
A: Business continuity practitioners, BCMS implementers, risk managers, senior management and consultants involved in selecting or evaluating continuity strategies.
Q: Is it current or superseded?
A: The TS was published in 2018 and, according to ISO records, was reviewed and confirmed in 2022; it remains a published technical specification while related work to update or replace it is recorded in ISO’s work programme. Users should check ISO or their national body for any subsequent revisions or related project updates.
Q: Is it part of a series?
A: Yes — it is part of the ISO security and resilience / BCMS family that includes ISO 22301 (requirements), ISO 22313 (guidance on ISO 22301), ISO 22300 (vocabulary) and other TS documents (for example ISO/TS 22330 on people aspects).
Q: What are the key keywords?
A: Business continuity, continuity strategy, BCMS, business impact analysis, risk assessment, recovery time objective, resilience.