Business continuity policy
The organisation's commitment to continuity: the scope, the objectives, the roles and the review, from which the plans derive.
How the register reads it
| Also called | BCMS policy, operational resilience policy |
|---|---|
| Family | Resilience and incidents |
| Document type | Policy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The business continuity manager or COO. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 22301 is ticked and no line resolves to it (ISO 27001, DORA require it too, inside a parent document, so they do not list it separately). |
| Template | No template yet. The clauses below say what the document is expected to contain. |
Which standards require it, and what each expects it to contain
3 requiring clauses, 3 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022
ISO 27001 5.29 Information security during disruptionPlan how to keep information security at the right level during disruption.
What the ISO 27002 guidance expects the document to say: Requires the organisation to plan how information security will be maintained at an appropriate level while a disruption is under way.
Common gap: Plans not updated after tests
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 22301:2019
ISO 22301 5.2.1 Establishing the business continuity policyTop management must set a business continuity policy that suits the organization's purpose, gives a frame for setting continuity objectives, and commits the organization to satisfying applicable requirements and to continually improving the BCMS.
Common gap: Generic policy text lifted from a template that says nothing about this organization's purpose
Source: ISO 22301:2019
DORA (Regulation (EU) 2022/2554)
DORA Art. 11 Response and recoveryFinancial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
Common gap: No ICT continuity/response/recovery plans
Source: DORA (Regulation (EU) 2022/2554)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register