{"id":4346,"date":"2015-06-15T21:49:04","date_gmt":"2015-06-15T21:49:04","guid":{"rendered":"https:\/\/multiacademstg.wpengine.com\/27001academy\/blog\/015\/06\/15\/how-to-use-iso-22301-for-the-implementation-of-business-continuity-in-iso-27001\/"},"modified":"2025-07-10T16:52:04","modified_gmt":"2025-07-10T16:52:04","slug":"how-to-use-iso-22301-for-the-implementation-of-business-continuity-in-iso-27001","status":"publish","type":"post","link":"https:\/\/advisera.com\/27001academy\/blog\/2015\/06\/15\/how-to-use-iso-22301-for-the-implementation-of-business-continuity-in-iso-27001\/","title":{"rendered":"How to use ISO 22301 for the implementation of business continuity in ISO 27001"},"content":{"rendered":"<p>One of the biggest mysteries in <a href=\"\/27001academy\/what-is-iso-27001\/\" rel=\"noopener noreferrer\" target=\"_blank\">ISO 27001<\/a>\u00a0implementation is the Annex A section A.17, which speaks about business continuity management. How does business continuity relate to information security, and why is it included in ISO 27001? Unfortunately, ISO 27001 does not provide much detail when it comes to business continuity.<\/p>\n<p>To add to the confusion, ISO 27001 speaks of \u201cinformation security aspects of business continuity management\u201d \u2013 what does this mean? This basically means that a company should enable its information security to continue its operations after an incident; however, since information security by itself (without main business and IT processes) makes no sense, companies typically plan their business continuity for all the important operations (both business and IT).<\/p>\n<h2 style=\"padding-top: 10px; padding-bottom: 10px;\">How are ISO 27001 and ISO 22301 similar?<\/h2>\n<p>First of all, information security and business continuity have one very important thing in common: they both protect the availability of the information \u2013 this is why ISO 27001 needed to include business continuity controls in its Annex A.<\/p>\n<p>ISO 22301 is the leading international business continuity standard (see the overview here: <a href=\"https:\/\/advisera.com\/27001academy\/what-is-iso-22301\/\" rel=\"noopener noreferrer\" target=\"_blank\">What is ISO 22301?<\/a>), and like all ISO management standards, it is based on the Plan-Do-Check-Act cycle. This means it has practically the same management elements as ISO 27001 and other ISO standards: document control, <a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-documentation-toolkit\/?rel=internal-audit&amp;doc=internal-audit-procedure\" rel=\"noopener noreferrer\" target=\"_blank\">internal audit<\/a>, <a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-documentation-toolkit\/?rel=management-system&amp;doc=corrective-action-form\" rel=\"noopener noreferrer\" target=\"_blank\">corrective actions<\/a>, <a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-documentation-toolkit\/?rel=management-system&amp;doc=management-review-minutes\" rel=\"noopener noreferrer\" target=\"_blank\">management review<\/a>, <a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-documentation-toolkit\/?rel=management-system&amp;doc=training-and-awareness-plan\" rel=\"noopener noreferrer\" target=\"_blank\">training &amp; awareness<\/a>, etc.<\/p>\n<p>So, if you already implemented all these elements for ISO 27001, then you\u2019re already fully compliant with ISO 22301 when it comes to managing the system. There are also some other elements of ISO 27001 that are fully compatible with ISO 22301 \u2013 e.g., the risk management \u2013 see this article for details: <a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-risk-assessment-treatment-management\/#section22\" rel=\"noopener\" target=\"_blank\">Can ISO 27001 risk assessment be used for ISO 22301?<\/a><br \/>\n<div id=\"middle-banner\" class=\"banner-shortcode\"><\/div><script>loadMiddleBanner();<\/script><br \/>\n<div id=\"side-banner-trigger\" class=\"banner-shortcode\"><\/div><\/p>\n<h2 style=\"padding-top: 10px; padding-bottom: 10px;\">Where they are different<\/h2>\n<p>ISO 27001 is rather poor when it comes to business continuity documentation \u2013 it is basically enough to write a\u00a0<a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-documentation-toolkit\/?rel=business-continuity&amp;doc=disaster-recovery-plan\" rel=\"noopener noreferrer\" target=\"_blank\">Disaster recovery plan<\/a>\u00a0to cover the control A.17.1.2 (which requires the implementation of continuity procedures) and control A.17.2.1 (which requires the availability of IT, i.e., the redundancy). See also: <a href=\"\/27001academy\/knowledgebase\/list-of-mandatory-documents-required-by-iso-27001-revision\/\" rel=\"noopener noreferrer\" target=\"_blank\">List of mandatory documents required by ISO 27001 (2013 revision)<\/a>.<\/p>\n<p>On the other hand, as might be expected, ISO 22301 requires the development of more documents, most of them for these core business continuity elements:<\/p>\n<ul>\n<li><a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-22301-premium-documentation-toolkit\/?rel=business-continuity&amp;doc=business-continuity-policy\" rel=\"noopener\" target=\"_blank\">Business continuity policy<\/a> (see also: <a href=\"https:\/\/advisera.com\/27001academy\/blog\/2013\/06\/04\/the-purpose-of-business-continuity-policy-according-to-iso-22301\/\">The purpose of Business continuity policy according to ISO 22301<\/a>)<\/li>\n<li>Business impact analysis (see also: <a href=\"\/27001academy\/knowledgebase\/how-to-implement-business-impact-analysis-bia-according-to-iso-22301\/\" rel=\"noopener noreferrer\" target=\"_blank\">How to implement business impact analysis (BIA) according to ISO 22301<\/a>)<\/li>\n<li><a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-22301-premium-documentation-toolkit\/?rel=business-continuity&amp;doc=business-continuity-strategy\" rel=\"noopener\" target=\"_blank\">Business continuity strategy<\/a> (see also: <a href=\"https:\/\/advisera.com\/27001academy\/blog\/2010\/03\/15\/can-business-continuity-strategy-save-your-money\/\" rel=\"noopener\" target=\"_blank\">Can business continuity strategy save your money?<\/a>)<\/li>\n<li><a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-22301-premium-documentation-toolkit\/?rel=business-continuity&amp;doc=business-continuity-plan\" rel=\"noopener\" target=\"_blank\">Business continuity plan<\/a>s (see also: <a href=\"https:\/\/advisera.com\/27001academy\/knowledgebase\/business-continuity-plan-how-to-structure-it-according-to-iso-22301\/\" rel=\"noopener noreferrer\" target=\"_blank\">Business continuity plan: How to structure it according to ISO 22301<\/a>)<\/li>\n<li>Exercising and testing (see also: <a href=\"https:\/\/advisera.com\/27001academy\/blog\/2015\/02\/02\/how-to-perform-business-continuity-exercising-and-testing-according-to-iso-22301\/\">How to perform business continuity exercising and testing according to ISO 22301<\/a>)<\/li>\n<\/ul>\n<p>So, what does this mean in practice? Although ISO 27001 allows you to implement your business continuity with one document only; in reality, if you want to prepare your company properly, you\u2019ll need more. And ISO 22301 gives you the know-how.<\/p>\n<h2 style=\"padding-top: 10px; padding-bottom: 10px;\">How to use ISO 22301 for ISO 27001<\/h2>\n<p>In my opinion, the best way to use this know-how from ISO 22301 is to implement it as a sub-project of ISO 27001 \u2013 this means, you should implement your ISO 27001 as you have planned for, and when it comes to section A.17 you should implement the above-mentioned core business continuity elements from ISO 22301.<\/p>\n<p>In effect, since all the other elements of ISO 22301 are the same as in ISO 27001, you will implement both of these standards at the same time. And, the best thing of all \u2013 this additional effort is only 10% of the whole ISO 27001 implementation effort.<\/p>\n<p>So, it is true that you can achieve compliance with section A.17 in ISO 27001 by writing a single document \u2013 the <a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-documentation-toolkit\/?rel=business-continuity&amp;doc=disaster-recovery-plan\" rel=\"noopener\" target=\"_blank\">Disaster recovery plan<\/a>. However, ISO 22301 enables you to do much more \u2013 to prepare your company to really continue all of its crucial operations if a real disaster struck. Is this worth the additional 10% effort?<\/p>\n<p><em>To implement ISO 27001 &amp; ISO 22301 easily and efficiently, use our <\/em><a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-22301-premium-documentation-toolkit\/\" rel=\"noopener\" target=\"_blank\">ISO 27001 &amp; ISO 22301 Premium Documentation Toolkit<\/a><em> that provides step-by-step guidance and all documents for full ISO 27001 &amp; ISO 22301 compliance.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the biggest mysteries in ISO 27001\u00a0implementation is the Annex A section A.17, which speaks about business continuity management. How does business continuity relate to information security, and why is it included in ISO 27001? Unfortunately, ISO 27001 does not provide much detail when it comes to business continuity. To add to the confusion, &#8230;<\/p>\n","protected":false},"author":26,"featured_media":82996,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[278,378,379,380,381,382],"class_list":["post-4346","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-risk-management","tag-business-continuity","tag-information-security","tag-iso-22301","tag-iso-27001","tag-pdca-cycle"],"acf":[],"_links":{"self":[{"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/posts\/4346","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/users\/26"}],"replies":[{"embeddable":true,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/comments?post=4346"}],"version-history":[{"count":2,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/posts\/4346\/revisions"}],"predecessor-version":[{"id":104371,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/posts\/4346\/revisions\/104371"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/media\/82996"}],"wp:attachment":[{"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/media?parent=4346"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/categories?post=4346"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/tags?post=4346"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}