Edge Register
Regimes ยท ISO 22301

ISO 22301:2019

Attaches the business continuity plans and procedures to every site, and the plan content and recovery clauses to the sites whose link is intermittent or absent.

On the register, tick "ISO 22301:2019" and these rows appear on every site. Source framework: ISO 22301:2019.

How the duties attach

ReachesEvery site.
every site8.4.1
link intermittent8.4.4, 8.4.5
no link8.4.4, 8.4.5

The continuity sheet

Solo exports the sites grouped by link (none, intermittent, always) with the backup and the recovery objective each line states and the 8.4 rows that attach where the link drops, one printable page for the continuity plan's site annex.

The clauses, quoted

3 of 57 in the framework

Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim.

ISO 22301 8.4.1 General

Implement and maintain a response structure enabling timely warning and communication to relevant interested parties, with plans and procedures to manage the organization through a disruption and to activate continuity solutions, identified and documented from the output of the selected strategies and solutions, and with procedures that are specific about immediate steps, flexible to changing internal and external conditions, focused on the impact of incidents, effective at minimizing that impact, and explicit about roles and responsibilities.

Evidence an auditor accepts: Documented response structure; Procedures stating immediate steps and the roles that take them; Traceability from selected strategies and solutions to the documented plans
Common gap: Procedures written for one rehearsed scenario, brittle against anything else
Source framework: ISO 22301:2019
ISO 22301 8.4.4 Business continuity plans

Document and maintain business continuity plans that guide teams through response and recovery, collectively containing the actions to continue or recover prioritized activities within predetermined time frames, the means of monitoring the disruption and the response, the pre defined thresholds and process for activating the response, procedures to deliver products and services at agreed capacity, and how the immediate consequences are managed with regard to individual welfare, prevention of further loss and environmental impact; each plan must state purpose, scope and objectives, the roles and responsibilities of the implementing team, the actions implementing the solutions, the supporting information needed to activate, operate, coordinate and communicate including activation criteria, internal and external interdependencies, resource requirements, reporting requirements and a stand down process, and must be usable and available at the time and place it is needed.

Evidence an auditor accepts: Plan set with each plan carrying every required element; Activation criteria and thresholds stated in the plan itself; Interdependency and resource sections reconciled to the BIA
Common gap: Plans that cover activation and response but have no stand down, so the organization never formally returns to normal
Source framework: ISO 22301:2019
ISO 22301 8.4.5 Recovery

Maintain documented processes to restore and return business activities from the temporary measures adopted during and after a disruption.

Evidence an auditor accepts: Documented restoration and return to normal processes; Criteria for deciding that temporary measures can be withdrawn; Evidence of use, from exercises or real events, including backlog clearance
Common gap: Recovery treated as implicit once the incident is closed, with no process behind it
Source framework: ISO 22301:2019

See what it attaches to your list

Paste the site list, tick the regime, and every site it reaches carries these rows by its exposure, link, data and plant. Eight sites free, no account.

Build my edge register