ISO 22301
Business continuity management systems requirements
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
ISO 22301: BCM Program Management
Establishing and managing the BCM program (ISO 22301)
| Code | Title |
|---|---|
| ISO22301-01 | Business continuity policy |
| ISO22301-02 | BCM program scope and objectives |
| ISO22301-03 | Resource allocation for BCM |
| ISO22301-04 | BCM roles and responsibilities |
| ISO22301-05 | Management commitment to BCM |
ISO 22301: BCM Testing & Exercising
Validating business continuity plans (ISO 22301)
| Code | Title |
|---|---|
| ISO22301-16 | Exercise program development |
| ISO22301-17 | Tabletop and simulation exercises |
| ISO22301-18 | Full-scale testing procedures |
| ISO22301-19 | Post-exercise review and improvement |
| ISO22301-20 | Plan maintenance and update |
ISO 22301: Business Continuity Strategy
Developing continuity and recovery strategies (ISO 22301)
| Code | Title |
|---|---|
| ISO22301-11 | Continuity strategy development |
| ISO22301-12 | Recovery strategy for critical activities |
| ISO22301-13 | Alternate site and resource planning |
| ISO22301-14 | Supply chain continuity |
| ISO22301-15 | Communication strategy during disruption |
ISO 22301: Business Impact Analysis
Understanding the impact of disruptions (ISO 22301)
| Code | Title |
|---|---|
| ISO22301-06 | Business impact analysis methodology |
| ISO22301-07 | Critical activity identification |
| ISO22301-08 | Recovery time and point objectives |
| ISO22301-09 | Resource requirements assessment |
| ISO22301-10 | Interdependency mapping |
Maps to 291 other frameworks
Frequently Asked Questions
What is ISO 22301?
ISO 22301 is a compliance framework from International with 4 domains and 20 controls. Business continuity management systems requirements It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO 22301 have?
ISO 22301 has 20 controls organised across 4 domains. The largest domains are ISO 22301: BCM Program Management (5 controls), ISO 22301: BCM Testing & Exercising (5 controls), ISO 22301: Business Continuity Strategy (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO 22301 map to?
ISO 22301 maps to 291 other compliance frameworks. The top mapping partners are EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) (30% coverage), APRA CPS 230 Operational Risk Management (30% coverage), Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct (30% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO 22301 compliance?
Start your ISO 22301 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 22301 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required