Policy Register

Pandemic response plan

How the organisation keeps operating when a large part of its people cannot come to work at once.

How the register reads it

Also calledinfectious disease plan
FamilyResilience and incidents
Document typePlan. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the business continuity plan; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe business continuity manager or COO.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whennever on its own: the register recognises it and names the clauses, but no ticked regime lists it as a separate document (its parent, business continuity plan, is).
TemplatePandemic response plan.

Which standards require it, and what each expects it to contain

1 requiring clauses, 1 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO 22301:2019

ISO 22301 8.4.4 Business continuity plans

Document and maintain business continuity plans that guide teams through response and recovery, collectively containing the actions to continue or recover prioritized activities within predetermined time frames, the means of monitoring the disruption and the response, the pre defined thresholds and process for activating the response, procedures to deliver products and services at agreed capacity, and how the immediate consequences are managed with regard to individual welfare, prevention of further loss and environmental impact; each plan must state purpose, scope and objectives, the roles and responsibilities of the implementing team, the actions implementing the solutions, the supporting information needed to activate, operate, coordinate and communicate including activation criteria, internal and external interdependencies, resource requirements, reporting requirements and a stand down process, and must be usable and available at the time and place it is needed.

Evidence an auditor accepts: Plan set with each plan carrying every required element; activation criteria and thresholds stated in the plan itself; interdependency and resource sections reconciled to the BIA
Common gap: Plans that cover activation and response but have no stand down, so the organization never formally returns to normal
Source: ISO 22301:2019

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Incident response plan · Security event reporting procedure