Standards
The library, clause by clause
For every requirement: its intent, the evidence an auditor will ask for, and the pitfall that fails it. These are original editorial summaries — the normative text remains its publishers’ property and must be obtained from them.
ISO/IEC standards15
Business continuity management systems — Requirements
The global reference for building, running and certifying a business continuity management system (BCMS). It states what an organisation must have in place — not how — and is the only text in the 223xx family against which an accredited body can issue a certificate.
Security and resilience — Business continuity management systems — Guidance on the use of ISO 22301
The companion manual to ISO 22301. Where 22301 says "the organization shall", 22313 explains how, with worked approaches, deliverables and pitfalls. Not certifiable, but essential when building a BCMS from scratch.
Guidelines for business impact analysis (BIA)
The only normative text devoted entirely to the BIA. It sets out the three levels of analysis (strategic, tactical, operational), how to establish maximum tolerable periods of disruption, and how to avoid the bias where every function declares itself critical.
Guidelines for supply chain continuity management
How to extend continuity beyond the organisation's own walls: mapping critical suppliers, continuity clauses in contracts, verifying third-party plans, and managing nth-tier dependencies.
Guidelines for business continuity strategy
The most frequently skipped link between the BIA and the plans. It describes how to evaluate, compare and select continuity options — and how to justify the chosen ones economically.
Crisis management — Guidelines
The international reference for crisis management since it superseded the UK PAS 200. It cleanly separates incident (known procedure) from crisis (novel, ambiguous, high-stakes) and focuses on decision-making capability rather than on the plan.
Emergency management — Guidelines for incident management
The text that structures incident command: roles, command posts, multi-agency cooperation and operational information management. It formalises what emergency services practise as ICS or Gold-Silver-Bronze.
Organizational resilience — Principles and attributes
The text that broadens the frame: resilience is not a function but an emergent property of the organisation. It identifies nine attributes — from shared vision to learning capability — and offers indicators to assess them.
Guidelines for information and communication technology readiness for business continuity (IRBC)
The bridge between business continuity and IT. It introduces ICT readiness for business continuity (IRBC) and the metrics that are now common currency: RTO, RPO, and degraded service level objectives.
Risk management — Guidelines
The common foundation for every risk discipline: principles, framework and process. Its strength is its economy — eight principles, a five-part framework, a six-step process — applying equally to operational, project and strategic risk.
Risk management — Risk assessment techniques
The catalogue of methods: over forty techniques, from fault tree analysis to bow-tie, from HAZOP to Bayesian analysis, each with its conditions of use and limitations. The tool for choosing a method rather than repeating the one you know.
Information security, cybersecurity and privacy protection — Information security management systems — Requirements
The certifiable ISMS. The 2022 edition reorganised Annex A into 93 controls across four themes and added eleven new ones, including threat intelligence and ICT readiness for business continuity — the direct junction with ISO 22301.
Guidelines for exercises
The full method for an exercise programme: policy, design, conduct, evaluation and improvement. It cleanly distinguishes awareness exercises, tabletops, functional exercises and full-scale exercises.
Security and resilience — Vocabulary
The shared dictionary of the 223xx family: over 270 defined terms, from "prioritized activity" to "exercise", by way of "disruption" and "resilience". The text that prevents misunderstanding in a crisis room.
Security and resilience — Security management systems — Requirements
A certifiable security management system, particularly relevant to physical supply chains. The 2022 edition aligned it with the Harmonized Structure and widened it beyond the maritime transport context it was designed for.
Regulations4
Digital operational resilience for the financial sector
In force since 17 January 2025, DORA imposes a single digital operational resilience baseline on some twenty categories of EU financial entities. Five pillars: ICT risk governance and management, major incident reporting, resilience testing, third-party risk management, and cyber threat information sharing.
Measures for a high common level of cybersecurity across the Union
NIS 2 substantially widens its predecessor's scope: eighteen sectors, essential and important entities, management liability and significant administrative fines. Article 21 explicitly requires business continuity and crisis management among the minimum measures.
Resilience of critical entities
The physical counterpart to NIS 2. Where NIS 2 covers cyber, CER covers the overall resilience of critical entities against natural hazards, malicious acts, health emergencies and sabotage. It mandates a risk assessment, a resilience plan and notification of disruptive incidents.
Operational resilience: impact tolerances for important business services
The UK regime, often cited as the most mature in the world. It requires identifying important business services, setting a quantified impact tolerance for each, mapping the resources needed, and testing the ability to stay within tolerance under severe but plausible scenarios.
Guidance6
Guidelines on ICT and security risk management
The text that prefigured DORA for the European banking sector. It details ICT risk governance, information security, operations management, project and change management, and ICT business continuity — at a granularity DORA largely inherited.
Guidelines on outsourcing arrangements
The European framework for banking outsourcing: register of arrangements, criticality analysis, due diligence, mandatory contract clauses, audit rights and exit strategies. DORA adopted and tightened this architecture for ICT providers.
Good Practice Guidelines for business continuity
The practitioner corpus, structured around the business continuity lifecycle: two management professional practices and four technical ones. Where ISO 22301 says what to do, the GPG says how to do it day to day, in practitioner language.
Contingency Planning Guide for Federal Information Systems
The most detailed operational guide for building an IT recovery plan. Seven steps, a crisp plan taxonomy (BCP, COOP, DRP, cyber incident response plan, crisis communications plan, occupant emergency plan), and complete templates in the annexes.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management
Revision 3 realigns incident response with CSF 2.0 and drops the four-phase cycle in favour of integration with risk management. It remains the operational reference for structuring a CSIRT.
Professional Practices for Business Continuity Management
DRI's ten professional practices, the foundation of the CBCP and MBCP certifications. More operational than the GPG on coordination with public authorities and emergency response, they usefully complement the European corpus.
Frameworks8
European framework for threat intelligence-based ethical red teaming
The framework that structures threat-led penetration testing in Europe. Three phases — preparation, testing, closure — with strict roles: white team, red team, threat intelligence provider. DORA makes it the reference for the TLPT of its Article 26.
Principles for the Sound Management of Operational Risk
The twelve principles underpinning banking operational risk management worldwide. They structure the three lines of defence, the identification and assessment toolkit (RCSA, loss data collection, key risk indicators, scenario analysis), and the governance around them.
Principles for Operational Resilience
The text that shifted the financial sector from process-based continuity to a logic of critical services and impact tolerance. Seven principles requiring identification of critical operations, mapping of the resources supporting them, and explicit tolerances.
Cybersecurity Framework 2.0
Version 2.0, published in 2024, adds a sixth function — Govern — to the historic five: Identify, Protect, Detect, Respond, Recover. It explicitly steps outside the federal perimeter to address any organisation, and strengthens supply chain coverage.
IT service continuity management
The ITIL practice linking continuity to the other service management practices: incident, problem, change, capacity and availability management. It brings the vocabulary and interfaces an IT department understands immediately.
Enterprise Risk Management — Integrating with Strategy and Performance
The enterprise risk reference framework, built on five components and twenty principles. Its major contribution is anchoring risk in strategy rather than internal control, making it the natural governance complement to ISO 31000.
CIS Critical Security Controls
Eighteen priority-ordered controls, expressed in three implementation groups by organisation size and maturity. Control 11 — data recovery — is the one most directly tied to IT continuity.
Data centre tier classification
The reference classification for data centres: Tier I to Tier IV, from no redundancy to fault tolerant. It translates a business availability requirement into a physical infrastructure requirement — and clarifies what a hosting provider is actually selling.
The texts presented here are original editorial summaries of each requirement’s intent. They do not reproduce the normative text, which must be obtained from its publisher.