This practical guide to the ISO22301 business continuity management system standard shows you how to develop and implement a business continuity management (BCM) and disaster recovery plan; ensuring you get back on your feet with the minimum of fuss, should the unthinkable happen.
A concise and practical guide to the ISO22301 benchmark for business continuity management (BCM), this book is essential reading for all managers, executives and directors with any interest or involvement in operational risk or business continuity management. It shows you how to develop and implement a business continuity management and disaster recovery plan, ensuring you get back on your feet with the minimum of fuss, should the unthinkable happen.
Muu info
Learn how to create a business continuity and disaster recovery plan that will reduce risks and help protect your organisation when things go wrong.
| Introduction |
|
1 | (2) |
|
Chapter 1 Introducing Business Continuity Management |
|
|
3 | (14) |
|
What is business continuity management? |
|
|
3 | (8) |
|
|
|
11 | (6) |
|
Chapter 2 Overview of the BCM Process |
|
|
17 | (28) |
|
Context of the organisation |
|
|
21 | (4) |
|
|
|
25 | (1) |
|
|
|
26 | (1) |
|
|
|
27 | (4) |
|
|
|
31 | (3) |
|
Performance evaluation and improvement |
|
|
34 | (11) |
|
Chapter 3 Business Impact Analysis and Risk Assessment |
|
|
45 | (48) |
|
|
|
45 | (27) |
|
Risk identification, assessment and management |
|
|
72 | (21) |
|
Chapter 4 Business Continuity Strategy |
|
|
93 | (14) |
|
|
|
93 | (7) |
|
|
|
100 | (1) |
|
The rest of the resource spectrum |
|
|
101 | (3) |
|
|
|
104 | (3) |
|
Chapter 5 Business Continuity Procedures |
|
|
107 | (28) |
|
The incident response structure |
|
|
107 | (7) |
|
Triggering the BCM response -- activation |
|
|
114 | (1) |
|
Business continuity planning |
|
|
115 | (20) |
|
Chapter 6 Exercising and Testing |
|
|
135 | (6) |
|
|
|
135 | (6) |
|
Chapter 7 Performance Evaluation |
|
|
141 | (6) |
|
Monitoring and measurement |
|
|
141 | (2) |
|
|
|
143 | (4) |
|
|
|
147 | (2) |
|
Non-conformity and corrective action |
|
|
147 | (1) |
|
|
|
147 | (1) |
|
|
|
148 | (1) |
|
|
|
149 | (6) |
|
Making business continuity effective |
|
|
149 | (6) |
|
Chapter 10 Document Management and Control |
|
|
155 | (8) |
|
|
|
157 | (1) |
|
|
|
157 | (2) |
|
|
|
159 | (1) |
|
|
|
160 | (1) |
|
|
|
161 | (2) |
|
Chapter 11 Reporting and Assurance |
|
|
163 | (4) |
|
|
|
163 | (1) |
|
|
|
164 | (1) |
|
|
|
165 | (2) |
|
|
|
167 | (14) |
|
|
|
168 | (8) |
|
|
|
176 | (2) |
|
|
|
178 | (1) |
|
|
|
178 | (3) |
|
Chapter 13 Standards and Codes of Practice |
|
|
181 | (4) |
|
The Combined Code on Corporate Governance (UK) |
|
|
181 | (1) |
|
|
|
182 | (1) |
|
|
|
182 | (1) |
|
|
|
183 | (1) |
|
|
|
183 | (1) |
|
|
|
184 | (1) |
| Bibliography |
|
185 | (2) |
| Appendix 1 A BCM Policy |
|
187 | (10) |
| Appendix 2 BCM Competencies |
|
197 | (4) |
| Appendix 3 A Risk Register |
|
201 | (4) |
| Appendix 4 A Crisis Management Team |
|
205 | (4) |
| Appendix 5 A Communication Cascade |
|
209 | (4) |
| Appendix 6 Document Templates |
|
213 | (6) |
| Appendix 7 A Document Register |
|
219 | (2) |
| Appendix 8 Acronyms and Abbreviations |
|
221 | (2) |
| ITG Resources |
|
223 | |
Tony Drewitt is a professional member of the Business Continuity Institute (BCI). He has been a practising consultant in the field of operational risk management and business continuity management (BCM) since 2001, working with a wide range of small, medium and large organisations, to develop BCM policies, strategies and plans.
He started his career as a mechanical engineer in industry, and has held a range of posts in sales and marketing, general management and management consulting. He was one of the first practitioners to achieve certification under BS25999 (predecessor to ISO22301) for a client in 2008.
Tony is the author of the already successful ITGP publications ISO 22301: A Pocket Guide, A Managers Guide to ISO 22301 and Everything You Want to Know about Business Continuity.