Standards

The library, clause by clause

For every requirement: its intent, the evidence an auditor will ask for, and the pitfall that fails it. These are original editorial summaries — the normative text remains its publishers’ property and must be obtained from them.

ISO/IEC standards15

ISO 22301:2019 Certifiable

Business continuity management systems — Requirements

The global reference for building, running and certifying a business continuity management system (BCMS). It states what an organisation must have in place — not how — and is the only text in the 223xx family against which an accredited body can issue a certificate.

ISO2019
ISO 22313:2020

Security and resilience — Business continuity management systems — Guidance on the use of ISO 22301

The companion manual to ISO 22301. Where 22301 says "the organization shall", 22313 explains how, with worked approaches, deliverables and pitfalls. Not certifiable, but essential when building a BCMS from scratch.

ISO2020
ISO/TS 22317:2021

Guidelines for business impact analysis (BIA)

The only normative text devoted entirely to the BIA. It sets out the three levels of analysis (strategic, tactical, operational), how to establish maximum tolerable periods of disruption, and how to avoid the bias where every function declares itself critical.

ISO2021
ISO/TS 22318:2021

Guidelines for supply chain continuity management

How to extend continuity beyond the organisation's own walls: mapping critical suppliers, continuity clauses in contracts, verifying third-party plans, and managing nth-tier dependencies.

ISO2021
ISO/TS 22331:2018

Guidelines for business continuity strategy

The most frequently skipped link between the BIA and the plans. It describes how to evaluate, compare and select continuity options — and how to justify the chosen ones economically.

ISO2018
ISO 22361:2022

Crisis management — Guidelines

The international reference for crisis management since it superseded the UK PAS 200. It cleanly separates incident (known procedure) from crisis (novel, ambiguous, high-stakes) and focuses on decision-making capability rather than on the plan.

ISO2022
ISO 22320:2018

Emergency management — Guidelines for incident management

The text that structures incident command: roles, command posts, multi-agency cooperation and operational information management. It formalises what emergency services practise as ICS or Gold-Silver-Bronze.

ISO2018
ISO 22316:2017

Organizational resilience — Principles and attributes

The text that broadens the frame: resilience is not a function but an emergent property of the organisation. It identifies nine attributes — from shared vision to learning capability — and offers indicators to assess them.

ISO2017
ISO/IEC 27031:2011

Guidelines for information and communication technology readiness for business continuity (IRBC)

The bridge between business continuity and IT. It introduces ICT readiness for business continuity (IRBC) and the metrics that are now common currency: RTO, RPO, and degraded service level objectives.

ISO/IEC2011
ISO 31000:2018

Risk management — Guidelines

The common foundation for every risk discipline: principles, framework and process. Its strength is its economy — eight principles, a five-part framework, a six-step process — applying equally to operational, project and strategic risk.

ISO2018
IEC 31010:2019

Risk management — Risk assessment techniques

The catalogue of methods: over forty techniques, from fault tree analysis to bow-tie, from HAZOP to Bayesian analysis, each with its conditions of use and limitations. The tool for choosing a method rather than repeating the one you know.

IEC2019
ISO/IEC 27001:2022 Certifiable

Information security, cybersecurity and privacy protection — Information security management systems — Requirements

The certifiable ISMS. The 2022 edition reorganised Annex A into 93 controls across four themes and added eleven new ones, including threat intelligence and ICT readiness for business continuity — the direct junction with ISO 22301.

ISO/IEC2022
ISO 22398:2013

Guidelines for exercises

The full method for an exercise programme: policy, design, conduct, evaluation and improvement. It cleanly distinguishes awareness exercises, tabletops, functional exercises and full-scale exercises.

ISO2013
ISO 22300:2021

Security and resilience — Vocabulary

The shared dictionary of the 223xx family: over 270 defined terms, from "prioritized activity" to "exercise", by way of "disruption" and "resilience". The text that prevents misunderstanding in a crisis room.

ISO2021
ISO 28000:2022 Certifiable

Security and resilience — Security management systems — Requirements

A certifiable security management system, particularly relevant to physical supply chains. The 2022 edition aligned it with the Harmonized Structure and widened it beyond the maritime transport context it was designed for.

ISO2022

Regulations4

Règlement (UE) 2022/2554 — DORA

Digital operational resilience for the financial sector

In force since 17 January 2025, DORA imposes a single digital operational resilience baseline on some twenty categories of EU financial entities. Five pillars: ICT risk governance and management, major incident reporting, resilience testing, third-party risk management, and cyber threat information sharing.

Union européenne2022
Directive (UE) 2022/2555 — NIS 2

Measures for a high common level of cybersecurity across the Union

NIS 2 substantially widens its predecessor's scope: eighteen sectors, essential and important entities, management liability and significant administrative fines. Article 21 explicitly requires business continuity and crisis management among the minimum measures.

Union européenne2022
Directive (UE) 2022/2557 — CER

Resilience of critical entities

The physical counterpart to NIS 2. Where NIS 2 covers cyber, CER covers the overall resilience of critical entities against natural hazards, malicious acts, health emergencies and sabotage. It mandates a risk assessment, a resilience plan and notification of disruptive incidents.

Union européenne2022
PRA SS1/21 & FCA PS21/3

Operational resilience: impact tolerances for important business services

The UK regime, often cited as the most mature in the world. It requires identifying important business services, setting a quantified impact tolerance for each, mapping the resources needed, and testing the ability to stay within tolerance under severe but plausible scenarios.

Bank of England / FCA2021

Guidance6

EBA/GL/2019/04

Guidelines on ICT and security risk management

The text that prefigured DORA for the European banking sector. It details ICT risk governance, information security, operations management, project and change management, and ICT business continuity — at a granularity DORA largely inherited.

EBA2019
EBA/GL/2019/02

Guidelines on outsourcing arrangements

The European framework for banking outsourcing: register of arrangements, criticality analysis, due diligence, mandatory contract clauses, audit rights and exit strategies. DORA adopted and tightened this architecture for ICT providers.

EBA2019
BCI Good Practice Guidelines

Good Practice Guidelines for business continuity

The practitioner corpus, structured around the business continuity lifecycle: two management professional practices and four technical ones. Where ISO 22301 says what to do, the GPG says how to do it day to day, in practitioner language.

BCI2023
NIST SP 800-34 Rev. 1

Contingency Planning Guide for Federal Information Systems

The most detailed operational guide for building an IT recovery plan. Seven steps, a crisp plan taxonomy (BCP, COOP, DRP, cyber incident response plan, crisis communications plan, occupant emergency plan), and complete templates in the annexes.

NIST2010
NIST SP 800-61 Rev. 3

Incident Response Recommendations and Considerations for Cybersecurity Risk Management

Revision 3 realigns incident response with CSF 2.0 and drops the four-phase cycle in favour of integration with risk management. It remains the operational reference for structuring a CSIRT.

NIST2025
DRI International Professional Practices

Professional Practices for Business Continuity Management

DRI's ten professional practices, the foundation of the CBCP and MBCP certifications. More operational than the GPG on coordination with public authorities and emergency response, they usefully complement the European corpus.

DRI International2021

Frameworks8

TIBER-EU

European framework for threat intelligence-based ethical red teaming

The framework that structures threat-led penetration testing in Europe. Three phases — preparation, testing, closure — with strict roles: white team, red team, threat intelligence provider. DORA makes it the reference for the TLPT of its Article 26.

Banque centrale européenne2018
BCBS 195 / PSMOR (révisé 2021)

Principles for the Sound Management of Operational Risk

The twelve principles underpinning banking operational risk management worldwide. They structure the three lines of defence, the identification and assessment toolkit (RCSA, loss data collection, key risk indicators, scenario analysis), and the governance around them.

BCBS2021
BCBS 516 — Principes de résilience opérationnelle

Principles for Operational Resilience

The text that shifted the financial sector from process-based continuity to a logic of critical services and impact tolerance. Seven principles requiring identification of critical operations, mapping of the resources supporting them, and explicit tolerances.

BCBS2021
NIST Cybersecurity Framework 2.0

Cybersecurity Framework 2.0

Version 2.0, published in 2024, adds a sixth function — Govern — to the historic five: Identify, Protect, Detect, Respond, Recover. It explicitly steps outside the federal perimeter to address any organisation, and strengthens supply chain coverage.

NIST2024
ITIL 4 — Service Continuity Management

IT service continuity management

The ITIL practice linking continuity to the other service management practices: incident, problem, change, capacity and availability management. It brings the vocabulary and interfaces an IT department understands immediately.

PeopleCert / AXELOS2019
COSO ERM 2017

Enterprise Risk Management — Integrating with Strategy and Performance

The enterprise risk reference framework, built on five components and twenty principles. Its major contribution is anchoring risk in strategy rather than internal control, making it the natural governance complement to ISO 31000.

COSO2017
CIS Controls v8.1

CIS Critical Security Controls

Eighteen priority-ordered controls, expressed in three implementation groups by organisation size and maturity. Control 11 — data recovery — is the one most directly tied to IT continuity.

CIS2024
Uptime Institute Tier Standard Certifiable

Data centre tier classification

The reference classification for data centres: Tier I to Tier IV, from no redundancy to fault tolerant. It translates a business availability requirement into a physical infrastructure requirement — and clarifies what a hosting provider is actually selling.

Uptime Institute2018

The texts presented here are original editorial summaries of each requirement’s intent. They do not reproduce the normative text, which must be obtained from its publisher.