SlideShare a Scribd company logo
1 of 4
Download to read offline
ISO 22301 (BUSINESS
CONTINUITY) CHECKLIST
Page 1
NQA/BCMS/Checklist/FEB21
Before you can begin to design your
business continuity plans you need to
be able to define your organization.
An organization is not just defined by
what its output is, but also by what
shapes and influences it.
There may be stakeholders and
regulations that have a say in what
matters to your organization. They
might influence your planning.
CLAUSE 4
1 Know your organization
By knowing your organization
and armed with your mission or
business goals, you can set a
boundary to your Business Continuity
Management System (BCMS).
You probably don’t need a plan for
the entire organization; constrain the
scope to the things that matter.
CLAUSE 4
2 Limit your BCMS to what really matters

Just as senior leaders direct and
resource an organization so it fulfills
its purpose, they must do the same
for business continuity management.
It starts with a policy that is a
statement of intent, which in turn
drives the need, the activities and the
resources.
CLAUSE 5
3 Make sure your top management is committed to business continuity
Make sure someone from your senior leadership is
responsible for the BCMS and document what their
responsibilities are:
Define roles and responsibilities for business continuity:
Disseminate the policy to everyone affected by it (both
internal and external):
Write a Business Continuity Policy:
Document and explain the exclusions:
List the outputs (Products and Services) that should be
in the scope:
List what parts of the organization that should be in the
scope:
List relevant laws and regulations and have a process for
this:
List your stakeholders and their requirements:
List the internal and external issues that drive the need
for business continuity planning:
Page 2

Once you have a business continuity
policy, you can start planning.
Business continuity is not without its
risks and its opportunities for your
organization. If you know what they
are you can set some objectives.
CLAUSE 6
4 Have some objectives
Set some business continuity objectives and what you
need to achieve them and who is responsible:
Decide what you need to do to address them and
implement those actions into your operational
processes:
Figure out what the risks and opportunities are at the
organizational level:
Make sure you’ve got change control processes for the
BCMS in place:
Decide how you’re going to monitor and measure
performance towards the objectives:
People are an important resource in a
business continuity plan and you will
need equipment and supplies: Who,
What, Why, When, How and Where.
CLAUSE 7
5 Are your resources capable, competent and sufficient?
Have a communications plan for the wider organization
and external interested parties:
Confirm that they’re present in your organization:
Decide what resources are required (personnel,
technology and infrastructure). In the case of personnel
determine the knowledge and skills required:
Document everything required by the standard (there’s
a list at the end of this checklist) and anything else you
think necessary. Control the changes to your documents:
NQA/BCMS/Checklist/FEB21
ISO 22301:2019 MANDATORY DOCUMENTS
CLAUSE DOCUMENT CLAUSE DOCUMENT
4.2.2 Applicable legal requirements, regulations or laws, and any
other identified requirements
8.4.2.4 Documented procedures for each response team
4.3.1 The scope of the BCMS 8.4.3.1 Warning and communication procedures
4.3.2 Exclusions from the scope of the BCMS 8.4.4.1 Business continuity plans
5.2.2 The Business Continuity Policy 8.4.5 Recovery and restoration processes
6.2.1 Business Continuity objectives 8.5 Post-exercise reports
7.2 Evidence of personnel competence 9.1 Results of monitoring, measurement, analysis and
evaluation of the performance of the BCMS
7.5.1 Documentation required by the standard (this list) and
anything else considered necessary for the effectiveness of
the BCMS
9.2.2 Evidence of the implementation of the audit programme
and the audit results
8.1 Information necessary to have confidence that the
operational planning and control processes are being
carried out as planned
9.3.3.2 Results of the management reviews
8.4.1 Business continuity plans and procedures 10.1.3 The nature of non-conformities and what was done about
them, and the results of the corrective action
Page 3
When bad things happen, it can be
immediately or over a period. The
consequences can continue for some
time after.
You need to know what’s important
to the organization, what are the
consequences of their disruption over
time, and how long you can tolerate
it. You work this out with a Business
Impact Analysis (BIA).
CLAUSE 8
6 Conduct a Business Impact Analysis
Identify the internal and external resources required
to deliver these products and activities (Personnel,
Equipment, Technology (IT)), Supplies, Infrastructure):
List the key activities that comprise your products and
services:
Define some impacts and their criteria for performing the
BIA. This will ensure the assessments are consistent and
repeatable:
Decide how long it will be before the business impacts
become unacceptable (MTPD):
Use the criteria to work out the business impact over
time to the key activities:
Set timeframes for recovering the activities to minimum
acceptable levels (MBCO):
Once the impacts have been
determined, you need to decide
which activities should have priority
for recovery, then:
List the key activities that comprise your products and
services:
Define some impacts and their criteria for performing the
BIA. This will ensure the assessments are consistent and
repeatable:
Now you know what your key activities are you need to consider the risks to them. This will help
you determine how likely it is they will be disrupted and therefore the impact to the business.
Prioritise the risks for treatment, which drives the business continuity strategies and then the
plans. ISO 31000 is a good risk assessment resource.
CLAUSE 8
7 Conduct a Risk Assessment
Your strategies should address your risks and requirements from the BIA.
Because this a risk-based approach there will be a cost-benefit consideration. And they need to
be realistic, by taking into account the availability of whatever resources you think are needed
to achieve success.
CLAUSE 8
8 Build business continuity strategies and solutions
NQA/BCMS/Checklist/FEB21
Page 4
Procedures:
CLAUSE 8
9 Define procedures and plans to achieve the strategies
Have roles and responsibilities defined:
Establish a crisis management team(s):
Need to be both specific to address
immediate steps but also sufficiently
flexible to cope with the inevitable
ambiguity in an incident:
Must manage internal and external
communications:
Define a response structure for the
responsible team:
This is where you define your response to incidents. It’s about the mobilization of the resources identified in
your strategies in a timely and controlled manner.
Protect the welfare of individuals:
Specify criteria for invoking activities:
Provide guidance to teams on how to
respond, including the order of activities:
What actions need to be taken:
Recovery to normal operations
Develop a plan and processes to ensure
a smooth transition from disaster recovery
phase to normal operations.
NQA/BCMS/Checklist/FEB21
Plans:
It’s well known that very few plans survive their first use. It’s far better to test plans before
they’re really needed. An exercise programme is the best way to ensure the plans work and to
prevent knowledge fade. Evaluating the organization’s capabilities is an essential part of the
continual improvement cycle required by the standard.
CLAUSE 8
10 Test, test and test again
Given everything defined in the preceding clauses, this is where you measure how well your
BCMS is performing. You need to know what you should measure, by whom, how and by
when. The standard tells you: - you need an ongoing internal audit programme and regular
management reviews.
CLAUSE 9
11 Continuously monitor your business continuity performance
Sometimes things go wrong (non-
conformities) so you must have a
process for:
CLAUSE 10
12 Continuously improving
Working out why they went wrong:
Fixing them:
Controlling them:
Taking steps to prevent it happening again:

More Related Content

What's hot

Business Continuity Management & ISO 22301
Business Continuity Management & ISO 22301Business Continuity Management & ISO 22301
Business Continuity Management & ISO 22301IT Governance Ltd
 
Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301PECB
 
SOC 2 Compliance and Certification
SOC 2 Compliance and CertificationSOC 2 Compliance and Certification
SOC 2 Compliance and CertificationControlCase
 
Soc 2 attestation or ISO 27001 certification - Which is better for organization
Soc 2 attestation or ISO 27001 certification - Which is better for organizationSoc 2 attestation or ISO 27001 certification - Which is better for organization
Soc 2 attestation or ISO 27001 certification - Which is better for organizationVISTA InfoSec
 
Control Standards for Information Security
Control Standards for Information SecurityControl Standards for Information Security
Control Standards for Information SecurityJohnHPazEMCPMPITIL5G
 
Iso 27001 isms presentation
Iso 27001 isms presentationIso 27001 isms presentation
Iso 27001 isms presentationMidhun Nirmal
 
ISO/IEC 27001:2022 Transition Arragements
ISO/IEC 27001:2022 Transition ArragementsISO/IEC 27001:2022 Transition Arragements
ISO/IEC 27001:2022 Transition ArragementsISONIKELtd
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
ISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdfISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdfControlCase
 
Konsep Fundamental ISO 22301_BCMS & Crisis Management _ Materi Training BCMS...
Konsep Fundamental  ISO 22301_BCMS & Crisis Management _ Materi Training BCMS...Konsep Fundamental  ISO 22301_BCMS & Crisis Management _ Materi Training BCMS...
Konsep Fundamental ISO 22301_BCMS & Crisis Management _ Materi Training BCMS...Kanaidi ken
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001PECB
 
ISO 37301 Compliance Management Systems
ISO 37301 Compliance Management SystemsISO 37301 Compliance Management Systems
ISO 37301 Compliance Management SystemsNimonik
 
Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management systemsubbusai82
 
Implementing a Business Continuity Management System in Telecoms
Implementing a Business Continuity Management System in TelecomsImplementing a Business Continuity Management System in Telecoms
Implementing a Business Continuity Management System in TelecomsGlobal Risk Forum GRFDavos
 
Business impact assessment (bia)
Business impact assessment (bia)Business impact assessment (bia)
Business impact assessment (bia)Shashwat Shankar
 

What's hot (20)

Business Continuity Management & ISO 22301
Business Continuity Management & ISO 22301Business Continuity Management & ISO 22301
Business Continuity Management & ISO 22301
 
ISO 27001 - Information Security Management System
ISO 27001 - Information Security Management SystemISO 27001 - Information Security Management System
ISO 27001 - Information Security Management System
 
Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301
 
SOC 2 Compliance and Certification
SOC 2 Compliance and CertificationSOC 2 Compliance and Certification
SOC 2 Compliance and Certification
 
ISO 27001:2022 What has changed.pdf
ISO 27001:2022 What has changed.pdfISO 27001:2022 What has changed.pdf
ISO 27001:2022 What has changed.pdf
 
Soc 2 attestation or ISO 27001 certification - Which is better for organization
Soc 2 attestation or ISO 27001 certification - Which is better for organizationSoc 2 attestation or ISO 27001 certification - Which is better for organization
Soc 2 attestation or ISO 27001 certification - Which is better for organization
 
ISO 27005:2022 Overview 221028.pdf
ISO 27005:2022 Overview 221028.pdfISO 27005:2022 Overview 221028.pdf
ISO 27005:2022 Overview 221028.pdf
 
Iso 27001 awareness
Iso 27001 awarenessIso 27001 awareness
Iso 27001 awareness
 
Control Standards for Information Security
Control Standards for Information SecurityControl Standards for Information Security
Control Standards for Information Security
 
Iso 27001 isms presentation
Iso 27001 isms presentationIso 27001 isms presentation
Iso 27001 isms presentation
 
ISO/IEC 27001:2022 Transition Arragements
ISO/IEC 27001:2022 Transition ArragementsISO/IEC 27001:2022 Transition Arragements
ISO/IEC 27001:2022 Transition Arragements
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
ISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdfISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdf
 
Konsep Fundamental ISO 22301_BCMS & Crisis Management _ Materi Training BCMS...
Konsep Fundamental  ISO 22301_BCMS & Crisis Management _ Materi Training BCMS...Konsep Fundamental  ISO 22301_BCMS & Crisis Management _ Materi Training BCMS...
Konsep Fundamental ISO 22301_BCMS & Crisis Management _ Materi Training BCMS...
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001
 
ISO 37301 Compliance Management Systems
ISO 37301 Compliance Management SystemsISO 37301 Compliance Management Systems
ISO 37301 Compliance Management Systems
 
ISO 27002-2022.pdf
ISO 27002-2022.pdfISO 27002-2022.pdf
ISO 27002-2022.pdf
 
Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management system
 
Implementing a Business Continuity Management System in Telecoms
Implementing a Business Continuity Management System in TelecomsImplementing a Business Continuity Management System in Telecoms
Implementing a Business Continuity Management System in Telecoms
 
Business impact assessment (bia)
Business impact assessment (bia)Business impact assessment (bia)
Business impact assessment (bia)
 

Similar to NQA ISO 22301 Business Continuity Checklist

IMSM - Road to Implementation
IMSM - Road to ImplementationIMSM - Road to Implementation
IMSM - Road to ImplementationDelrae Eden
 
How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?Abdul Naseer
 
05 integrated management system telkom 2016 penanganan bencana - tanggap da...
05 integrated management system   telkom 2016 penanganan bencana - tanggap da...05 integrated management system   telkom 2016 penanganan bencana - tanggap da...
05 integrated management system telkom 2016 penanganan bencana - tanggap da...wisnu wardhana, i nyoman
 
Assessment 1 – Case Study Project Overview and context You.docx
Assessment 1 – Case Study Project Overview and context You.docxAssessment 1 – Case Study Project Overview and context You.docx
Assessment 1 – Case Study Project Overview and context You.docxgalerussel59292
 
How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...
How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...
How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...Innovation Enterprise
 
Ensemble - Process, Strategy and Performance Management
Ensemble - Process, Strategy and Performance ManagementEnsemble - Process, Strategy and Performance Management
Ensemble - Process, Strategy and Performance ManagementRefik Tuncer
 
Continous process improvement
Continous process improvementContinous process improvement
Continous process improvementSarfraz Ashraf
 
QESH Training slides with Check list for
QESH Training slides with Check list forQESH Training slides with Check list for
QESH Training slides with Check list forGobiNava1
 
Controlling and evaluation mechanism
Controlling and evaluation mechanismControlling and evaluation mechanism
Controlling and evaluation mechanismxtrm nurse
 
ISO 9001: 2015 QUALITY MANAGEMENT PRINCIPLES
ISO 9001: 2015 QUALITY MANAGEMENT PRINCIPLES ISO 9001: 2015 QUALITY MANAGEMENT PRINCIPLES
ISO 9001: 2015 QUALITY MANAGEMENT PRINCIPLES ParmiGajjar
 
SMU Solved Assignment MB0052
SMU Solved Assignment MB0052SMU Solved Assignment MB0052
SMU Solved Assignment MB0052Revlon
 
Hitchhikers guide to_data_center_facility_ops
Hitchhikers guide to_data_center_facility_opsHitchhikers guide to_data_center_facility_ops
Hitchhikers guide to_data_center_facility_opsavdsouza
 
AUDIT - AUDITING STRATEGIES.pptx
AUDIT - AUDITING STRATEGIES.pptxAUDIT - AUDITING STRATEGIES.pptx
AUDIT - AUDITING STRATEGIES.pptxMohamed Fazil M
 
Establishing Your Workforce Capability Framework
Establishing Your Workforce Capability FrameworkEstablishing Your Workforce Capability Framework
Establishing Your Workforce Capability FrameworkAcorn
 
Implementing Business Continuity With The Bs25999 Standard By Dennis
Implementing Business Continuity With The Bs25999 Standard By DennisImplementing Business Continuity With The Bs25999 Standard By Dennis
Implementing Business Continuity With The Bs25999 Standard By DennisDiscover JKUAT
 
New trends in the revised iso 9001:2015
New trends in the revised iso 9001:2015New trends in the revised iso 9001:2015
New trends in the revised iso 9001:2015PMILebanonChapter
 
Encouraging Business Excellence through Continuous Improvement
Encouraging Business Excellence through Continuous ImprovementEncouraging Business Excellence through Continuous Improvement
Encouraging Business Excellence through Continuous ImprovementGroup50 Consulting
 

Similar to NQA ISO 22301 Business Continuity Checklist (20)

IMSM - Road to Implementation
IMSM - Road to ImplementationIMSM - Road to Implementation
IMSM - Road to Implementation
 
Mb0052 set 2
Mb0052 set 2Mb0052 set 2
Mb0052 set 2
 
How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?
 
05 integrated management system telkom 2016 penanganan bencana - tanggap da...
05 integrated management system   telkom 2016 penanganan bencana - tanggap da...05 integrated management system   telkom 2016 penanganan bencana - tanggap da...
05 integrated management system telkom 2016 penanganan bencana - tanggap da...
 
Assessment 1 – Case Study Project Overview and context You.docx
Assessment 1 – Case Study Project Overview and context You.docxAssessment 1 – Case Study Project Overview and context You.docx
Assessment 1 – Case Study Project Overview and context You.docx
 
How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...
How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...
How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...
 
Ensemble - Process, Strategy and Performance Management
Ensemble - Process, Strategy and Performance ManagementEnsemble - Process, Strategy and Performance Management
Ensemble - Process, Strategy and Performance Management
 
Continous process improvement
Continous process improvementContinous process improvement
Continous process improvement
 
QESH Training slides with Check list for
QESH Training slides with Check list forQESH Training slides with Check list for
QESH Training slides with Check list for
 
Controlling and evaluation mechanism
Controlling and evaluation mechanismControlling and evaluation mechanism
Controlling and evaluation mechanism
 
ISO 9001: 2015 QUALITY MANAGEMENT PRINCIPLES
ISO 9001: 2015 QUALITY MANAGEMENT PRINCIPLES ISO 9001: 2015 QUALITY MANAGEMENT PRINCIPLES
ISO 9001: 2015 QUALITY MANAGEMENT PRINCIPLES
 
balanced score card
balanced score cardbalanced score card
balanced score card
 
SMU Solved Assignment MB0052
SMU Solved Assignment MB0052SMU Solved Assignment MB0052
SMU Solved Assignment MB0052
 
Hitchhikers guide to_data_center_facility_ops
Hitchhikers guide to_data_center_facility_opsHitchhikers guide to_data_center_facility_ops
Hitchhikers guide to_data_center_facility_ops
 
AUDIT - AUDITING STRATEGIES.pptx
AUDIT - AUDITING STRATEGIES.pptxAUDIT - AUDITING STRATEGIES.pptx
AUDIT - AUDITING STRATEGIES.pptx
 
Establishing Your Workforce Capability Framework
Establishing Your Workforce Capability FrameworkEstablishing Your Workforce Capability Framework
Establishing Your Workforce Capability Framework
 
Implementing Business Continuity With The Bs25999 Standard By Dennis
Implementing Business Continuity With The Bs25999 Standard By DennisImplementing Business Continuity With The Bs25999 Standard By Dennis
Implementing Business Continuity With The Bs25999 Standard By Dennis
 
New trends in the revised iso 9001:2015
New trends in the revised iso 9001:2015New trends in the revised iso 9001:2015
New trends in the revised iso 9001:2015
 
Encouraging Business Excellence through Continuous Improvement
Encouraging Business Excellence through Continuous ImprovementEncouraging Business Excellence through Continuous Improvement
Encouraging Business Excellence through Continuous Improvement
 
Qsm guidelines
Qsm guidelinesQsm guidelines
Qsm guidelines
 

More from NQA

NQA ISO 27001 27017 27018 27701 Mapping
NQA ISO 27001 27017 27018 27701 MappingNQA ISO 27001 27017 27018 27701 Mapping
NQA ISO 27001 27017 27018 27701 MappingNQA
 
NQA ISO 13485 Introduction Guide
NQA ISO 13485 Introduction GuideNQA ISO 13485 Introduction Guide
NQA ISO 13485 Introduction GuideNQA
 
NQA Measuring Operational Resilience Guide
NQA Measuring Operational Resilience GuideNQA Measuring Operational Resilience Guide
NQA Measuring Operational Resilience GuideNQA
 
NQA ISO 22301 Transition Gap Guide
NQA ISO 22301 Transition Gap GuideNQA ISO 22301 Transition Gap Guide
NQA ISO 22301 Transition Gap GuideNQA
 
NQA Ten Tips for Planning and Preparing
NQA Ten Tips for Planning and PreparingNQA Ten Tips for Planning and Preparing
NQA Ten Tips for Planning and PreparingNQA
 
NQA ISO 13485 Implementation Guide
NQA ISO 13485 Implementation GuideNQA ISO 13485 Implementation Guide
NQA ISO 13485 Implementation GuideNQA
 
NQA Your Risk Assurance Partner
NQA Your Risk Assurance PartnerNQA Your Risk Assurance Partner
NQA Your Risk Assurance PartnerNQA
 
NQA Your Complete Guide to ISO 27001
NQA Your Complete Guide to ISO 27001NQA Your Complete Guide to ISO 27001
NQA Your Complete Guide to ISO 27001NQA
 
NQA ISO 50001 Implementation Guide
NQA ISO 50001 Implementation GuideNQA ISO 50001 Implementation Guide
NQA ISO 50001 Implementation GuideNQA
 
NQA ISO 45001 Implementation Guide
NQA ISO 45001 Implementation GuideNQA ISO 45001 Implementation Guide
NQA ISO 45001 Implementation GuideNQA
 
NQA ISO 45001 Gap Guide
NQA ISO 45001 Gap GuideNQA ISO 45001 Gap Guide
NQA ISO 45001 Gap GuideNQA
 
NQA ISO 27701 Implementation Guide
NQA ISO 27701 Implementation GuideNQA ISO 27701 Implementation Guide
NQA ISO 27701 Implementation GuideNQA
 
NQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation GuideNQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation GuideNQA
 
NQA ISO 22000 Implementation Guide
NQA ISO 22000 Implementation GuideNQA ISO 22000 Implementation Guide
NQA ISO 22000 Implementation GuideNQA
 
NQA ISO 14001 Implementation Guide
NQA ISO 14001 Implementation GuideNQA ISO 14001 Implementation Guide
NQA ISO 14001 Implementation GuideNQA
 
NQA ISO 9001 Implementation Guide
NQA ISO 9001 Implementation GuideNQA ISO 9001 Implementation Guide
NQA ISO 9001 Implementation GuideNQA
 
NQA Journey to Certification
NQA Journey to CertificationNQA Journey to Certification
NQA Journey to CertificationNQA
 
NQA 10 Steps to IMS Guide
NQA 10 Steps to IMS GuideNQA 10 Steps to IMS Guide
NQA 10 Steps to IMS GuideNQA
 
NQA ISO 22000 Food Safety Transition Gap Guide
NQA ISO 22000 Food Safety Transition Gap GuideNQA ISO 22000 Food Safety Transition Gap Guide
NQA ISO 22000 Food Safety Transition Gap GuideNQA
 
NQA ISO 13485 Gap Guide – what’s changed?
NQA ISO 13485 Gap Guide – what’s changed?NQA ISO 13485 Gap Guide – what’s changed?
NQA ISO 13485 Gap Guide – what’s changed?NQA
 

More from NQA (20)

NQA ISO 27001 27017 27018 27701 Mapping
NQA ISO 27001 27017 27018 27701 MappingNQA ISO 27001 27017 27018 27701 Mapping
NQA ISO 27001 27017 27018 27701 Mapping
 
NQA ISO 13485 Introduction Guide
NQA ISO 13485 Introduction GuideNQA ISO 13485 Introduction Guide
NQA ISO 13485 Introduction Guide
 
NQA Measuring Operational Resilience Guide
NQA Measuring Operational Resilience GuideNQA Measuring Operational Resilience Guide
NQA Measuring Operational Resilience Guide
 
NQA ISO 22301 Transition Gap Guide
NQA ISO 22301 Transition Gap GuideNQA ISO 22301 Transition Gap Guide
NQA ISO 22301 Transition Gap Guide
 
NQA Ten Tips for Planning and Preparing
NQA Ten Tips for Planning and PreparingNQA Ten Tips for Planning and Preparing
NQA Ten Tips for Planning and Preparing
 
NQA ISO 13485 Implementation Guide
NQA ISO 13485 Implementation GuideNQA ISO 13485 Implementation Guide
NQA ISO 13485 Implementation Guide
 
NQA Your Risk Assurance Partner
NQA Your Risk Assurance PartnerNQA Your Risk Assurance Partner
NQA Your Risk Assurance Partner
 
NQA Your Complete Guide to ISO 27001
NQA Your Complete Guide to ISO 27001NQA Your Complete Guide to ISO 27001
NQA Your Complete Guide to ISO 27001
 
NQA ISO 50001 Implementation Guide
NQA ISO 50001 Implementation GuideNQA ISO 50001 Implementation Guide
NQA ISO 50001 Implementation Guide
 
NQA ISO 45001 Implementation Guide
NQA ISO 45001 Implementation GuideNQA ISO 45001 Implementation Guide
NQA ISO 45001 Implementation Guide
 
NQA ISO 45001 Gap Guide
NQA ISO 45001 Gap GuideNQA ISO 45001 Gap Guide
NQA ISO 45001 Gap Guide
 
NQA ISO 27701 Implementation Guide
NQA ISO 27701 Implementation GuideNQA ISO 27701 Implementation Guide
NQA ISO 27701 Implementation Guide
 
NQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation GuideNQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation Guide
 
NQA ISO 22000 Implementation Guide
NQA ISO 22000 Implementation GuideNQA ISO 22000 Implementation Guide
NQA ISO 22000 Implementation Guide
 
NQA ISO 14001 Implementation Guide
NQA ISO 14001 Implementation GuideNQA ISO 14001 Implementation Guide
NQA ISO 14001 Implementation Guide
 
NQA ISO 9001 Implementation Guide
NQA ISO 9001 Implementation GuideNQA ISO 9001 Implementation Guide
NQA ISO 9001 Implementation Guide
 
NQA Journey to Certification
NQA Journey to CertificationNQA Journey to Certification
NQA Journey to Certification
 
NQA 10 Steps to IMS Guide
NQA 10 Steps to IMS GuideNQA 10 Steps to IMS Guide
NQA 10 Steps to IMS Guide
 
NQA ISO 22000 Food Safety Transition Gap Guide
NQA ISO 22000 Food Safety Transition Gap GuideNQA ISO 22000 Food Safety Transition Gap Guide
NQA ISO 22000 Food Safety Transition Gap Guide
 
NQA ISO 13485 Gap Guide – what’s changed?
NQA ISO 13485 Gap Guide – what’s changed?NQA ISO 13485 Gap Guide – what’s changed?
NQA ISO 13485 Gap Guide – what’s changed?
 

Recently uploaded

Call Girls In {Connaught Place Delhi} 9667938988 IndianRussian High Profile E...
Call Girls In {Connaught Place Delhi} 9667938988 IndianRussian High Profile E...Call Girls In {Connaught Place Delhi} 9667938988 IndianRussian High Profile E...
Call Girls In {Connaught Place Delhi} 9667938988 IndianRussian High Profile E...aakahthapa70
 
JABALPUR CALL GIRL 92628/71154 JABALPUR K
JABALPUR CALL GIRL 92628/71154 JABALPUR KJABALPUR CALL GIRL 92628/71154 JABALPUR K
JABALPUR CALL GIRL 92628/71154 JABALPUR KNiteshKumar82226
 
Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.
Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.
Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.riyadelhic riyadelhic
 
Mysore Call girl service 6289102337 Mysore escort service
Mysore Call girl service 6289102337 Mysore escort serviceMysore Call girl service 6289102337 Mysore escort service
Mysore Call girl service 6289102337 Mysore escort servicemaheshsingh64440
 
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGARJAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGARNiteshKumar82226
 
MYSORE CALL GIRLS ESCORT SER 92628/71154
MYSORE CALL GIRLS ESCORT SER 92628/71154MYSORE CALL GIRLS ESCORT SER 92628/71154
MYSORE CALL GIRLS ESCORT SER 92628/71154NiteshKumar82226
 
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579Best VIP Call Girl Noida Sector 48 Call Me: 8700611579
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579diyaspanoida
 
Radhika Call Girls In Jaipur 9358660226 Escorts service
Radhika Call Girls In Jaipur 9358660226 Escorts serviceRadhika Call Girls In Jaipur 9358660226 Escorts service
Radhika Call Girls In Jaipur 9358660226 Escorts servicerahul222jai
 
Call Girls in Mukherjee Nagar Delhi 8826158885 Genuine Escorts Service
Call Girls in Mukherjee Nagar Delhi 8826158885 Genuine Escorts ServiceCall Girls in Mukherjee Nagar Delhi 8826158885 Genuine Escorts Service
Call Girls in Mukherjee Nagar Delhi 8826158885 Genuine Escorts Serviceteencall080
 
RAJKOT CALL GIRLS 92628/71154 RAJKOT CAL
RAJKOT CALL GIRLS 92628/71154 RAJKOT CALRAJKOT CALL GIRLS 92628/71154 RAJKOT CAL
RAJKOT CALL GIRLS 92628/71154 RAJKOT CALNiteshKumar82226
 
Low Rate Russian Call Girls In Lajpat Nagar ➡️ 7836950116 Call Girls Service ...
Low Rate Russian Call Girls In Lajpat Nagar ➡️ 7836950116 Call Girls Service ...Low Rate Russian Call Girls In Lajpat Nagar ➡️ 7836950116 Call Girls Service ...
Low Rate Russian Call Girls In Lajpat Nagar ➡️ 7836950116 Call Girls Service ...riyasharma00119
 
Call Girls in B-18 Islamabad || 🔝 03274100048
Call Girls in B-18 Islamabad || 🔝 03274100048Call Girls in B-18 Islamabad || 🔝 03274100048
Call Girls in B-18 Islamabad || 🔝 03274100048Ifra Zohaib
 
9891550660 Call Girls In Noida Sector 62 Short 1500 Night 6000
9891550660 Call Girls In Noida Sector 62 Short 1500 Night 60009891550660 Call Girls In Noida Sector 62 Short 1500 Night 6000
9891550660 Call Girls In Noida Sector 62 Short 1500 Night 6000teencall080
 
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls AgencyHire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls AgencyJia Oberoi
 
Call Girls in Luxus Grand Hotel | 💋 03274100048
Call Girls in Luxus Grand Hotel | 💋 03274100048Call Girls in Luxus Grand Hotel | 💋 03274100048
Call Girls in Luxus Grand Hotel | 💋 03274100048Ifra Zohaib
 
Call Girls in Rawalpindi | 🍆💦 03280288848
Call Girls in Rawalpindi | 🍆💦 03280288848Call Girls in Rawalpindi | 🍆💦 03280288848
Call Girls in Rawalpindi | 🍆💦 03280288848Ifra Zohaib
 
Russian Call Girls in Goa %(9316020077)# Russian Call Girls in Goa By Russi...
Russian Call Girls  in Goa %(9316020077)# Russian Call Girls  in Goa By Russi...Russian Call Girls  in Goa %(9316020077)# Russian Call Girls  in Goa By Russi...
Russian Call Girls in Goa %(9316020077)# Russian Call Girls in Goa By Russi...Goa Call Girls Service Goa escort agency
 

Recently uploaded (20)

Call Girls In {Connaught Place Delhi} 9667938988 IndianRussian High Profile E...
Call Girls In {Connaught Place Delhi} 9667938988 IndianRussian High Profile E...Call Girls In {Connaught Place Delhi} 9667938988 IndianRussian High Profile E...
Call Girls In {Connaught Place Delhi} 9667938988 IndianRussian High Profile E...
 
JABALPUR CALL GIRL 92628/71154 JABALPUR K
JABALPUR CALL GIRL 92628/71154 JABALPUR KJABALPUR CALL GIRL 92628/71154 JABALPUR K
JABALPUR CALL GIRL 92628/71154 JABALPUR K
 
Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.
Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.
Call Now ☎9870417354|| Call Girls in Noida Sector 12 Escort Service Noida N.C.R.
 
➥🔝9953056974 🔝▻ Anand Vihar Call-girl in Women Seeking Men 🔝Delhi🔝 NCR
➥🔝9953056974 🔝▻ Anand Vihar Call-girl in Women Seeking Men 🔝Delhi🔝 NCR➥🔝9953056974 🔝▻ Anand Vihar Call-girl in Women Seeking Men 🔝Delhi🔝 NCR
➥🔝9953056974 🔝▻ Anand Vihar Call-girl in Women Seeking Men 🔝Delhi🔝 NCR
 
Mysore Call girl service 6289102337 Mysore escort service
Mysore Call girl service 6289102337 Mysore escort serviceMysore Call girl service 6289102337 Mysore escort service
Mysore Call girl service 6289102337 Mysore escort service
 
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGARJAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
 
9953056974 Call Girls In Ashok Nagar, Escorts (Delhi) NCR.
9953056974 Call Girls In Ashok Nagar, Escorts (Delhi) NCR.9953056974 Call Girls In Ashok Nagar, Escorts (Delhi) NCR.
9953056974 Call Girls In Ashok Nagar, Escorts (Delhi) NCR.
 
MYSORE CALL GIRLS ESCORT SER 92628/71154
MYSORE CALL GIRLS ESCORT SER 92628/71154MYSORE CALL GIRLS ESCORT SER 92628/71154
MYSORE CALL GIRLS ESCORT SER 92628/71154
 
Call Girls In Goa For Fun 9316020077 By Goa Call Girls For Pick Up Night
Call Girls In  Goa  For Fun 9316020077 By  Goa  Call Girls For Pick Up NightCall Girls In  Goa  For Fun 9316020077 By  Goa  Call Girls For Pick Up Night
Call Girls In Goa For Fun 9316020077 By Goa Call Girls For Pick Up Night
 
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579Best VIP Call Girl Noida Sector 48 Call Me: 8700611579
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579
 
Radhika Call Girls In Jaipur 9358660226 Escorts service
Radhika Call Girls In Jaipur 9358660226 Escorts serviceRadhika Call Girls In Jaipur 9358660226 Escorts service
Radhika Call Girls In Jaipur 9358660226 Escorts service
 
Call Girls in Mukherjee Nagar Delhi 8826158885 Genuine Escorts Service
Call Girls in Mukherjee Nagar Delhi 8826158885 Genuine Escorts ServiceCall Girls in Mukherjee Nagar Delhi 8826158885 Genuine Escorts Service
Call Girls in Mukherjee Nagar Delhi 8826158885 Genuine Escorts Service
 
RAJKOT CALL GIRLS 92628/71154 RAJKOT CAL
RAJKOT CALL GIRLS 92628/71154 RAJKOT CALRAJKOT CALL GIRLS 92628/71154 RAJKOT CAL
RAJKOT CALL GIRLS 92628/71154 RAJKOT CAL
 
Low Rate Russian Call Girls In Lajpat Nagar ➡️ 7836950116 Call Girls Service ...
Low Rate Russian Call Girls In Lajpat Nagar ➡️ 7836950116 Call Girls Service ...Low Rate Russian Call Girls In Lajpat Nagar ➡️ 7836950116 Call Girls Service ...
Low Rate Russian Call Girls In Lajpat Nagar ➡️ 7836950116 Call Girls Service ...
 
Call Girls in B-18 Islamabad || 🔝 03274100048
Call Girls in B-18 Islamabad || 🔝 03274100048Call Girls in B-18 Islamabad || 🔝 03274100048
Call Girls in B-18 Islamabad || 🔝 03274100048
 
9891550660 Call Girls In Noida Sector 62 Short 1500 Night 6000
9891550660 Call Girls In Noida Sector 62 Short 1500 Night 60009891550660 Call Girls In Noida Sector 62 Short 1500 Night 6000
9891550660 Call Girls In Noida Sector 62 Short 1500 Night 6000
 
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls AgencyHire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
 
Call Girls in Luxus Grand Hotel | 💋 03274100048
Call Girls in Luxus Grand Hotel | 💋 03274100048Call Girls in Luxus Grand Hotel | 💋 03274100048
Call Girls in Luxus Grand Hotel | 💋 03274100048
 
Call Girls in Rawalpindi | 🍆💦 03280288848
Call Girls in Rawalpindi | 🍆💦 03280288848Call Girls in Rawalpindi | 🍆💦 03280288848
Call Girls in Rawalpindi | 🍆💦 03280288848
 
Russian Call Girls in Goa %(9316020077)# Russian Call Girls in Goa By Russi...
Russian Call Girls  in Goa %(9316020077)# Russian Call Girls  in Goa By Russi...Russian Call Girls  in Goa %(9316020077)# Russian Call Girls  in Goa By Russi...
Russian Call Girls in Goa %(9316020077)# Russian Call Girls in Goa By Russi...
 

NQA ISO 22301 Business Continuity Checklist

  • 1. ISO 22301 (BUSINESS CONTINUITY) CHECKLIST Page 1 NQA/BCMS/Checklist/FEB21 Before you can begin to design your business continuity plans you need to be able to define your organization. An organization is not just defined by what its output is, but also by what shapes and influences it. There may be stakeholders and regulations that have a say in what matters to your organization. They might influence your planning. CLAUSE 4 1 Know your organization By knowing your organization and armed with your mission or business goals, you can set a boundary to your Business Continuity Management System (BCMS). You probably don’t need a plan for the entire organization; constrain the scope to the things that matter. CLAUSE 4 2 Limit your BCMS to what really matters Just as senior leaders direct and resource an organization so it fulfills its purpose, they must do the same for business continuity management. It starts with a policy that is a statement of intent, which in turn drives the need, the activities and the resources. CLAUSE 5 3 Make sure your top management is committed to business continuity Make sure someone from your senior leadership is responsible for the BCMS and document what their responsibilities are: Define roles and responsibilities for business continuity: Disseminate the policy to everyone affected by it (both internal and external): Write a Business Continuity Policy: Document and explain the exclusions: List the outputs (Products and Services) that should be in the scope: List what parts of the organization that should be in the scope: List relevant laws and regulations and have a process for this: List your stakeholders and their requirements: List the internal and external issues that drive the need for business continuity planning:
  • 2. Page 2 Once you have a business continuity policy, you can start planning. Business continuity is not without its risks and its opportunities for your organization. If you know what they are you can set some objectives. CLAUSE 6 4 Have some objectives Set some business continuity objectives and what you need to achieve them and who is responsible: Decide what you need to do to address them and implement those actions into your operational processes: Figure out what the risks and opportunities are at the organizational level: Make sure you’ve got change control processes for the BCMS in place: Decide how you’re going to monitor and measure performance towards the objectives: People are an important resource in a business continuity plan and you will need equipment and supplies: Who, What, Why, When, How and Where. CLAUSE 7 5 Are your resources capable, competent and sufficient? Have a communications plan for the wider organization and external interested parties: Confirm that they’re present in your organization: Decide what resources are required (personnel, technology and infrastructure). In the case of personnel determine the knowledge and skills required: Document everything required by the standard (there’s a list at the end of this checklist) and anything else you think necessary. Control the changes to your documents: NQA/BCMS/Checklist/FEB21 ISO 22301:2019 MANDATORY DOCUMENTS CLAUSE DOCUMENT CLAUSE DOCUMENT 4.2.2 Applicable legal requirements, regulations or laws, and any other identified requirements 8.4.2.4 Documented procedures for each response team 4.3.1 The scope of the BCMS 8.4.3.1 Warning and communication procedures 4.3.2 Exclusions from the scope of the BCMS 8.4.4.1 Business continuity plans 5.2.2 The Business Continuity Policy 8.4.5 Recovery and restoration processes 6.2.1 Business Continuity objectives 8.5 Post-exercise reports 7.2 Evidence of personnel competence 9.1 Results of monitoring, measurement, analysis and evaluation of the performance of the BCMS 7.5.1 Documentation required by the standard (this list) and anything else considered necessary for the effectiveness of the BCMS 9.2.2 Evidence of the implementation of the audit programme and the audit results 8.1 Information necessary to have confidence that the operational planning and control processes are being carried out as planned 9.3.3.2 Results of the management reviews 8.4.1 Business continuity plans and procedures 10.1.3 The nature of non-conformities and what was done about them, and the results of the corrective action
  • 3. Page 3 When bad things happen, it can be immediately or over a period. The consequences can continue for some time after. You need to know what’s important to the organization, what are the consequences of their disruption over time, and how long you can tolerate it. You work this out with a Business Impact Analysis (BIA). CLAUSE 8 6 Conduct a Business Impact Analysis Identify the internal and external resources required to deliver these products and activities (Personnel, Equipment, Technology (IT)), Supplies, Infrastructure): List the key activities that comprise your products and services: Define some impacts and their criteria for performing the BIA. This will ensure the assessments are consistent and repeatable: Decide how long it will be before the business impacts become unacceptable (MTPD): Use the criteria to work out the business impact over time to the key activities: Set timeframes for recovering the activities to minimum acceptable levels (MBCO): Once the impacts have been determined, you need to decide which activities should have priority for recovery, then: List the key activities that comprise your products and services: Define some impacts and their criteria for performing the BIA. This will ensure the assessments are consistent and repeatable: Now you know what your key activities are you need to consider the risks to them. This will help you determine how likely it is they will be disrupted and therefore the impact to the business. Prioritise the risks for treatment, which drives the business continuity strategies and then the plans. ISO 31000 is a good risk assessment resource. CLAUSE 8 7 Conduct a Risk Assessment Your strategies should address your risks and requirements from the BIA. Because this a risk-based approach there will be a cost-benefit consideration. And they need to be realistic, by taking into account the availability of whatever resources you think are needed to achieve success. CLAUSE 8 8 Build business continuity strategies and solutions NQA/BCMS/Checklist/FEB21
  • 4. Page 4 Procedures: CLAUSE 8 9 Define procedures and plans to achieve the strategies Have roles and responsibilities defined: Establish a crisis management team(s): Need to be both specific to address immediate steps but also sufficiently flexible to cope with the inevitable ambiguity in an incident: Must manage internal and external communications: Define a response structure for the responsible team: This is where you define your response to incidents. It’s about the mobilization of the resources identified in your strategies in a timely and controlled manner. Protect the welfare of individuals: Specify criteria for invoking activities: Provide guidance to teams on how to respond, including the order of activities: What actions need to be taken: Recovery to normal operations Develop a plan and processes to ensure a smooth transition from disaster recovery phase to normal operations. NQA/BCMS/Checklist/FEB21 Plans: It’s well known that very few plans survive their first use. It’s far better to test plans before they’re really needed. An exercise programme is the best way to ensure the plans work and to prevent knowledge fade. Evaluating the organization’s capabilities is an essential part of the continual improvement cycle required by the standard. CLAUSE 8 10 Test, test and test again Given everything defined in the preceding clauses, this is where you measure how well your BCMS is performing. You need to know what you should measure, by whom, how and by when. The standard tells you: - you need an ongoing internal audit programme and regular management reviews. CLAUSE 9 11 Continuously monitor your business continuity performance Sometimes things go wrong (non- conformities) so you must have a process for: CLAUSE 10 12 Continuously improving Working out why they went wrong: Fixing them: Controlling them: Taking steps to prevent it happening again: