Policy Register

Business continuity policy

The organisation's commitment to continuity: the scope, the objectives, the roles and the review, from which the plans derive.

How the register reads it

Also calledBCMS policy, operational resilience policy
FamilyResilience and incidents
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe business continuity manager or COO.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 22301 is ticked and no line resolves to it (ISO 27001, DORA require it too, inside a parent document, so they do not list it separately).
TemplateNo template yet. The clauses below say what the document is expected to contain.

Which standards require it, and what each expects it to contain

3 requiring clauses, 3 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 5.29 Information security during disruption

Plan how to keep information security at the right level during disruption.

What the ISO 27002 guidance expects the document to say: Requires the organisation to plan how information security will be maintained at an appropriate level while a disruption is under way.

Evidence an auditor accepts: Continuity plans showing how information security is maintained while the organisation is operating in a degraded or alternative mode; the assessment of which security controls would be weakened or bypassed during disruption, and the compensating arrangements; evidence security requirements are part of continuity testing, not only recovery of function
Common gap: Plans not updated after tests
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO 22301:2019

ISO 22301 5.2.1 Establishing the business continuity policy

Top management must set a business continuity policy that suits the organization's purpose, gives a frame for setting continuity objectives, and commits the organization to satisfying applicable requirements and to continually improving the BCMS.

Evidence an auditor accepts: Approved policy carrying an explicit commitment to applicable requirements and to improvement; approval record naming the top management body and the date; traceability from the policy to the continuity objectives set under it
Common gap: Generic policy text lifted from a template that says nothing about this organization's purpose
Source: ISO 22301:2019

DORA (Regulation (EU) 2022/2554)

DORA Art. 11 Response and recovery

Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.

Evidence an auditor accepts: ICT business continuity policy + response/recovery plans; records of plan testing
Common gap: No ICT continuity/response/recovery plans
Source: DORA (Regulation (EU) 2022/2554)

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Business continuity plan · Business impact analysis