Back to Frameworks

ISO/TS 22317:2021

International (ISO/TC 292); adopted as PD ISO/TS 22317 (UK) and by other national bodies
v2021 (second edition)
4 domains
25 controls

The ISO technical specification for the business impact analysis process behind ISO 22301: prerequisites of context, scope, roles and commitment; the process from planning and the agreed impact types, criteria and time frames through product and service prioritization, prioritized activities with RTOs and their resource and dependency requirements, to consolidation and approval; and review. Clauses 4 to 5.3.2 from the held preview text, the rest on their titles, the front matter's eight outcomes and the held ISO 22301; guidance, not certifiable.

Verified

ISO/TS 22317:2021 is a compliance framework from International (ISO/TC 292); adopted as PD ISO/TS 22317 (UK) and by other national bodies with 4 domains and 25 controls that map to 120 other frameworks. The largest domains are Clause 5: The BIA process – ISO/TS 22317:2021 (14 controls), Clause 4: Prerequisites – ISO/TS 22317:2021 (5 controls), Annexes A to D (informative) – ISO/TS 22317:2021 (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Annexes A to D (informative) – ISO/TS 22317:2021

4 controls
Controls in the Annexes A to D (informative) – ISO/TS 22317:2021 domain of ISO/TS 22317:20214 controls
CodeTitle
iso-ts-22317-2021::AAnnex A BIA within the BCMS of ISO 22301:2019 (informative)
iso-ts-22317-2021::BAnnex B BIA information collection methods (informative)
iso-ts-22317-2021::CAnnex C Other uses for the BIA process (informative)
iso-ts-22317-2021::DAnnex D Examples for performing a BIA (informative)

Clause 4: Prerequisites – ISO/TS 22317:2021

5 controls
Controls in the Clause 4: Prerequisites – ISO/TS 22317:2021 domain of ISO/TS 22317:20215 controls
CodeTitle
iso-ts-22317-2021::4.2.14.2.1 Context
iso-ts-22317-2021::4.2.24.2.2 Scope
iso-ts-22317-2021::4.3.24.3.2 BIA leader
iso-ts-22317-2021::4.3.34.3.3 Activity owners
iso-ts-22317-2021::4.44.4 Commitment

Clause 5: The BIA process – ISO/TS 22317:2021

14 controls
Controls in the Clause 5: The BIA process – ISO/TS 22317:2021 domain of ISO/TS 22317:202114 controls
CodeTitle
iso-ts-22317-2021::5.15.1 Fundamentals
iso-ts-22317-2021::5.25.2 Plan BIA
iso-ts-22317-2021::5.3.15.3.1 Understand impacts
iso-ts-22317-2021::5.3.25.3.2 Define impact types and criteria
iso-ts-22317-2021::5.3.35.3.3 Define time frames
iso-ts-22317-2021::5.3.45.3.4 Define methodology
iso-ts-22317-2021::5.4.35.4.3 Product and service priority determination
iso-ts-22317-2021::5.5.35.5.3 Identify activities
iso-ts-22317-2021::5.5.45.5.4 Set RTO for the activities
iso-ts-22317-2021::5.5.55.5.5 Define the prioritized activities
iso-ts-22317-2021::5.6.15.6.1 Identify resource and other dependency requirements
iso-ts-22317-2021::5.6.25.6.2 Resource requirements
iso-ts-22317-2021::5.75.7 Analyse and consolidate BIA results
iso-ts-22317-2021::5.85.8 Obtain top management approval for BIA results

Clause 6: Review BIA – ISO/TS 22317:2021

2 controls
Controls in the Clause 6: Review BIA – ISO/TS 22317:2021 domain of ISO/TS 22317:20212 controls
CodeTitle
iso-ts-22317-2021::6.16.1 Review BIA process and methodology
iso-ts-22317-2021::6.26.2 Review BIA results

Your Compliance Coverage

If you comply with ISO/TS 22317:2021, you already cover:

Maps to 120 other frameworks

61 total controls
PSD2 SCA
5 source controls mapped|1 target controls covered
8%
OSFI B-13
5 source controls mapped|1 target controls covered
8%
Open Banking Security
5 source controls mapped|1 target controls covered
8%
Oman National Cybersecurity Framework
5 source controls mapped|1 target controls covered
8%
NIS2 Directive Implementing Acts
5 source controls mapped|1 target controls covered
8%
Nevada Gaming Control Board Cybersecurity Requirements
5 source controls mapped|1 target controls covered
8%
Monetary Authority of Singapore Technology Risk Management Guidelines
5 source controls mapped|1 target controls covered
8%
ISO/IEC 27031:2011
5 source controls mapped|6 target controls covered
8%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
5 source controls mapped|4 target controls covered
8%
ASIS SPC.1-2009 - Organizational Resilience Standard
5 source controls mapped|1 target controls covered
8%
ASD Strategies to Mitigate Cyber Security Incidents
5 source controls mapped|3 target controls covered
8%
South Korea ISMS-P
5 source controls mapped|3 target controls covered
8%
FFIEC IT Examination Handbook
5 source controls mapped|2 target controls covered
8%
ISO 22316
5 source controls mapped|5 target controls covered
8%
PCI P2PE
5 source controls mapped|2 target controls covered
8%
SOC for Cybersecurity - Cybersecurity Risk Management Examination
5 source controls mapped|1 target controls covered
8%
PCI PIN Security
5 source controls mapped|2 target controls covered
8%
NFPA 1600 - Standard on Continuity, Emergency, and Crisis Management
5 source controls mapped|4 target controls covered
8%
ISO/TS 22318:2021
5 source controls mapped|5 target controls covered
8%
PCI SSF
5 source controls mapped|2 target controls covered
8%
ISO 22301:2019
4 source controls mapped|3 target controls covered
7%
5%
NIST Privacy Framework
3 source controls mapped|2 target controls covered
5%
NERC CIP
3 source controls mapped|2 target controls covered
5%
API 1164
3 source controls mapped|6 target controls covered
5%
IEC 62443
3 source controls mapped|6 target controls covered
5%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|3 target controls covered
5%
ISO/IEC 27011:2024
3 source controls mapped|2 target controls covered
5%
NIST SP 800-53 Rev 5
3 source controls mapped|5 target controls covered
5%
ISO/IEC 27019:2024
3 source controls mapped|6 target controls covered
5%
UK Security and Emergency Measures Direction (SEMD) - Water Industry
3 source controls mapped|2 target controls covered
5%
NIST Cybersecurity Framework 2.0
3 source controls mapped|6 target controls covered
5%
NIST SP 1800-32
3 source controls mapped|6 target controls covered
5%
TISAX - Trusted Information Security Assessment Exchange
3 source controls mapped|4 target controls covered
5%
5%
APRA CPS 230 Operational Risk Management
3 source controls mapped|3 target controls covered
5%
ISO 22313:2020 - Guidance on Business Continuity Management Systems
3 source controls mapped|3 target controls covered
5%
Annex 11 to EU GMP - Computerised Systems
3 source controls mapped|2 target controls covered
5%
ISO/IEC 27010:2015
3 source controls mapped|2 target controls covered
5%
BS 65000:2014 - Guidance on Organizational Resilience
3 source controls mapped|1 target controls covered
5%
ISO 28001:2007 Supply Chain Security Management
3 source controls mapped|2 target controls covered
5%
TSA Pipeline Cybersecurity Directives
2 source controls mapped|1 target controls covered
3%
SLSA
2 source controls mapped|1 target controls covered
3%
SIG (Shared Assessments)
2 source controls mapped|1 target controls covered
3%
PTES
2 source controls mapped|1 target controls covered
3%
OWASP SAMM
2 source controls mapped|1 target controls covered
3%
OWASP MASVS
2 source controls mapped|1 target controls covered
3%
OpenSSF Scorecard
2 source controls mapped|1 target controls covered
3%
NIST SP 800-92
2 source controls mapped|1 target controls covered
3%
NIST SP 800-88
2 source controls mapped|1 target controls covered
3%
NIST SP 800-63-4
2 source controls mapped|1 target controls covered
3%
NIST SP 800-61
2 source controls mapped|1 target controls covered
3%
NIST SP 800-146
2 source controls mapped|1 target controls covered
3%
NIST SP 800-145
2 source controls mapped|1 target controls covered
3%
NIST SP 800-144
2 source controls mapped|1 target controls covered
3%
NIST SP 800-137
2 source controls mapped|1 target controls covered
3%
NIST SP 800-123
2 source controls mapped|1 target controls covered
3%
NAIC Insurance Data Security Model Law (MDL-668)
2 source controls mapped|1 target controls covered
3%
NABERS - National Australian Built Environment Rating System
2 source controls mapped|1 target controls covered
3%
MTCS (Singapore)
2 source controls mapped|1 target controls covered
3%
MITRE ATT&CK
2 source controls mapped|1 target controls covered
3%
Japan FSA Cybersecurity Guidelines for Financial Institutions
2 source controls mapped|1 target controls covered
3%
ISO 22320:2018
2 source controls mapped|1 target controls covered
3%
ISO/SAE 21434
2 source controls mapped|1 target controls covered
3%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
2 source controls mapped|1 target controls covered
3%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
2 source controls mapped|1 target controls covered
3%
SOC 2
2 source controls mapped|2 target controls covered
3%
NIST SP 800-190
2 source controls mapped|1 target controls covered
3%
SSAE 18 - Attestation Standards (SOC Reporting)
2 source controls mapped|3 target controls covered
3%
ISO/IEC 27043:2015
2 source controls mapped|1 target controls covered
3%
SANS Incident Handler's Handbook and PICERL Methodology
2 source controls mapped|3 target controls covered
3%
ISO 27017
2 source controls mapped|1 target controls covered
3%
ISO 27018
2 source controls mapped|1 target controls covered
3%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
2 source controls mapped|1 target controls covered
3%
ISO 50001:2018 - Energy Management Systems
2 source controls mapped|2 target controls covered
3%
ISO 13485:2016
2 source controls mapped|2 target controls covered
3%
UK Gambling Commission - Cyber Resilience Requirements
1 source controls mapped|1 target controls covered
2%
UK FCA/PRA Operational Resilience Framework
1 source controls mapped|1 target controls covered
2%
SA8000:2014 - Social Accountability Standard
1 source controls mapped|1 target controls covered
2%
SASB Standards
1 source controls mapped|2 target controls covered
2%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|1 target controls covered
2%
OWASP Top 10 for LLM Applications 2025
1 source controls mapped|1 target controls covered
2%
Modern Slavery Act 2018 (Australia)
1 source controls mapped|2 target controls covered
2%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|1 target controls covered
2%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
2%
German Supply Chain Due Diligence Act (LkSG)
1 source controls mapped|2 target controls covered
2%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
2%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|3 target controls covered
2%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|1 target controls covered
2%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
1 source controls mapped|2 target controls covered
2%
ISO 26000:2010
1 source controls mapped|1 target controls covered
2%
FBI CJIS Security Policy
1 source controls mapped|1 target controls covered
2%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|1 target controls covered
2%
Space ISAC (Information Sharing and Analysis Center) - Threat Framework
1 source controls mapped|1 target controls covered
2%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|3 target controls covered
2%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|1 target controls covered
2%
Automotive SPICE (ASPICE) v4.1 - Process Assessment Model
1 source controls mapped|1 target controls covered
2%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|1 target controls covered
2%
AS9100D - Aerospace Quality Management System
1 source controls mapped|1 target controls covered
2%
Sigstore - Software Artifact Signing and Verification
1 source controls mapped|1 target controls covered
2%
Solvency II
1 source controls mapped|3 target controls covered
2%
UK Telecommunications (Security) Act 2021
1 source controls mapped|1 target controls covered
2%
Security of Critical Infrastructure Act 2018 (SOCI)
1 source controls mapped|1 target controls covered
2%
2%
ISO/IEC 27003:2017
1 source controls mapped|2 target controls covered
2%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|1 target controls covered
2%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
2%
BREEAM - Building Research Establishment Environmental Assessment Method
1 source controls mapped|1 target controls covered
2%
ISO 55001:2014
1 source controls mapped|1 target controls covered
2%
ISO 37301:2021
1 source controls mapped|1 target controls covered
2%
ISO 37001:2016
1 source controls mapped|1 target controls covered
2%
ISO 27701:2019
1 source controls mapped|1 target controls covered
2%
ISO 9001:2015
1 source controls mapped|1 target controls covered
2%
ISO 10006:2003
1 source controls mapped|1 target controls covered
2%

Coverage is not the same as your position

This page shows what ISO/TS 22317:2021 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is ISO/TS 22317:2021 and who does it apply to?

ISO/TS 22317:2021 is a compliance framework from International (ISO/TC 292); adopted as PD ISO/TS 22317 (UK) and by other national bodies with 4 domains and 25 controls. The ISO technical specification for the business impact analysis process behind ISO 22301: prerequisites of context, scope, roles and commitment; the process from planning and the agreed impact types, criteria and time frames through product and service prioritization, prioritized activities with RTOs and their resource and dependency requirements, to consolidation and approval; and review. Clauses 4 to 5.3.2 from the held preview text, the rest on their titles, the front matter's eight outcomes and the held ISO 22301; guidance, not certifiable. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/TS 22317:2021 actually require?

ISO/TS 22317:2021 has 25 controls organised across 4 domains. The largest domains are Clause 5: The BIA process – ISO/TS 22317:2021 (14 controls), Clause 4: Prerequisites – ISO/TS 22317:2021 (5 controls), Annexes A to D (informative) – ISO/TS 22317:2021 (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/TS 22317:2021 do I already cover?

ISO/TS 22317:2021 maps to 120 other compliance frameworks. The top mapping partners are PSD2 SCA (8% coverage), OSFI B-13 (8% coverage), Open Banking Security (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ISO/TS 22317:2021?

Start your ISO/TS 22317:2021 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/TS 22317:2021 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 25 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required