BS EN ISO 22301-2019 PDF
Name in English:
STB BS EN ISO 22301-2019
Name in Russian:
СТБ BS EN ISO 22301-2019
Original standard BS EN ISO 22301-2019 in PDF full version. Additional info + preview on request
Full title and description
STB BS EN ISO 22301-2019 — Security and resilience. Business continuity management systems. Requirements. Specifies the requirements for establishing, implementing, maintaining and continually improving a Business Continuity Management System (BCMS) to protect against, reduce the likelihood of, prepare for, respond to and recover from disruptive incidents.
Abstract
BS EN ISO 22301:2019 is the European/BS-adopted version of ISO 22301:2019. It sets out the mandatory requirements for a BCMS using the ISO High Level Structure so organisations can identify threats to continuity, implement proportionate continuity strategies and procedures, exercise and test plans, and continually improve resilience. The 2019 edition replaced earlier versions and aligns business continuity with other management system standards.
General information
- Status: Published / Current (national adoption of ISO 22301:2019).
- Publication date: ISO edition: October 2019 (Edition 2); BS EN publication / BSI adoption: 30 November 2019.
- Publisher: British Standards Institution (BSI) — adoption of the International Standard published by ISO (International Organization for Standardization).
- ICS / categories: 03.100.01 (Company organisation and management in general); 03.100.70 (Management systems).
- Edition / version: ISO 22301:2019 (Edition 2) — published as EN ISO 22301:2019 for European/BSI use; later consolidated editions or amendments (e.g., A1:2024) may exist in national catalogues.
- Number of pages: Core ISO PDF: 21 pages (note: national/adopted PDF versions and consolidated publications including amendments may have more pages — commonly published BSI/EN copies range up to ~32 pages depending on formatting and included amendments).
Scope
This standard specifies requirements for a BCMS to enable an organisation to plan, establish, implement, operate, monitor, review, maintain and continually improve a documented management system to protect against, reduce the likelihood of, prepare for, respond to and recover from disruptive incidents when they arise. It is applicable to any organisation, regardless of type, size or nature, and is designed to be used for internal management, certification and contractual purposes.
Key topics and requirements
- Establishing the context of the organisation and determining the scope of the BCMS.
- Leadership and commitment, roles and responsibilities for business continuity.
- Planning: risk assessment, business impact analysis (BIA), objectives and continuity strategy.
- Support: resources, competence, awareness, communication and documented information management.
- Operation: development and implementation of business continuity plans, procedures, response and recovery arrangements.
- Exercise and testing of plans and arrangements; validation of continuity strategies.
- Performance evaluation: monitoring, measurement, internal audit and management review.
- Improvement: handling nonconformities, corrective actions and continual improvement of the BCMS.
- Integration with other management systems and alignment with the ISO High Level Structure (Annex/reference to ISO 22300 vocabulary and related guidance).
Typical use and users
Used by organisations of all sizes and sectors to develop or improve business continuity capability. Typical users include business continuity managers, risk and resilience teams, senior management, internal and external auditors, consultants, certification bodies, procurement/supply-chain teams (to meet contractual or tendering requirements) and regulators seeking assurance of continuity arrangements.
Related standards
Key related publications include ISO 22313 (Guidance on the use of ISO 22301), ISO 22300 (vocabulary), ISO 22320 (incident management), ISO 22316 (organisational resilience), ISO 31000 (risk management), and information-security standards such as ISO/IEC 27001. Historic national standards such as BS 25999 have been superseded by the ISO 22301 family.
Keywords
Business continuity, BCMS, resilience, recovery, business impact analysis, continuity planning, incident response, disaster recovery, ISO 22301, EN ISO, BSI, risk assessment.
FAQ
Q: What is this standard?
A: BS EN ISO 22301:2019 is the British/European adoption of ISO 22301:2019 — the international standard that specifies requirements for a Business Continuity Management System (BCMS) to protect organisations from disruptive incidents and to ensure recovery of critical functions.
Q: What does it cover?
A: It covers the full BCMS lifecycle: context and scope, leadership, planning (including BIA and risk assessment), support (resources and documented information), operational continuity plans and procedures, testing and exercises, performance evaluation (monitoring, audit, management review) and continual improvement.
Q: Who typically uses it?
A: Organisations of any size or sector use it; primary users include continuity/resilience teams, senior management, auditors, consultants and certification bodies. It is also referenced in tenders and regulatory/governance frameworks where demonstrable continuity capability is required.
Q: Is it current or superseded?
A: ISO 22301:2019 is the current edition published in 2019 and replaced the 2012 edition. National/adopted versions (BS EN ISO 22301:2019) were published in late 2019. Be aware that consolidated national publications or amendments (for example A1 amendments published later) may be issued—check the publisher’s catalogue for the most recent consolidated text before purchase or certification activities.
Q: Is it part of a series?
A: Yes — ISO 22301 is part of the ISO 22300-series (security and resilience / business continuity family). It is typically used together with ISO 22313 (guidance) and other ISO standards covering resilience, incident management and risk.
Q: What are the key keywords?
A: Business continuity, BCMS, resilience, business impact analysis (BIA), continuity planning, incident response, recovery, ISO 22301, EN ISO, BSI.