Expertise · ISO 22301

Business continuity as a governance discipline

Understand, decide, prepare, test and improve an organisation's ability to sustain its critical activities — whether struck by a cyberattack, a technology failure, a human, industrial or organisational crisis.

Governance of business continuity — the BCMS

A Business Continuity Management System (BCMS) is not a collection of emergency plans. It is a governance system: a structured set of decisions, processes and capabilities that allow an organisation to keep delivering its critical activities, whatever the source of disruption. The distinction is fundamental. A continuity plan not anchored in governance remains a document. A BCMS conformant with ISO 22301 is a living system, steered by leadership, tested regularly and continually improved.

Key concept · Critical activities

The activities whose interruption, beyond a defined time threshold, would cause unacceptable consequences for the organisation — whether financial, reputational, regulatory or contractual. Identifying these activities, quantifying their criticality and determining the conditions for sustaining them is at the heart of the BCMS approach.

For a board of directors or executive leadership, business continuity is not a technical question — it is a governance question. An organisation's ability to sustain its essential functions in the face of adversity shapes its reputation, its relationship with stakeholders and, in regulated sectors, its compliance with NIS2 and DORA requirements. It is leadership that decides the level of resilience the organisation is able to assume — and that bears responsibility for it.

ISO 22301 structures that responsibility: it provides the framework within which governance decisions relating to continuity are made, documented, tested and audited. It does not prescribe how to sustain activities — it requires the organisation to demonstrate that it has decided, prepared and verified that it can.

The decision instruments — BIA, MTPD, RTO, RPO

BIA, MTPD, RTO, RPO — these four acronyms are not definitions to memorise for an exam. They are the instruments that allow an organisation to answer three fundamental questions before a crisis occurs: which activities cannot stop? For how long can they be interrupted? And to what recovery point must they be restored?

These instruments form a coherent decision chain. Each element follows logically from the previous one and conditions the next. A high-performing BCMS is a system in which all these decisions align without contradiction — from the BIA to the continuity plans, through strategies and solutions.

BIA

Critical activities & impacts

MTPD

Max. tolerable duration

RTO / RPO

Recovery objectives

Strategies

Continuity approaches

Solutions

Concrete arrangements

BCP

Operational plans

Business Impact Analysis (BIA)

The BIA is the foundation of the BCMS. It identifies the organisation's critical activities, qualifies and quantifies the impacts of their interruption over time — financial, operational, reputational, regulatory — and maps dependencies: human resources, information systems, suppliers, infrastructure, data. The BIA is not a list of important processes. It is an analysis of the progressive consequences of their interruption, which allows recovery priorities to be ranked and continuity efforts to be sized appropriately.

MTPD — Maximum Tolerable Period of Disruption

The MTPD is the time limit beyond which the interruption of a critical activity would cause unacceptable consequences for the organisation. Derived directly from the BIA, it constitutes the absolute constraint that any continuity strategy must respect. It is expressed per critical activity, not globally. The MTPD is a governance decision — not a technical estimate. It is leadership that sets this threshold of unacceptability, assuming the budgetary and organisational implications that follow.

RTO and RPO — Recovery objectives

The RTO (Recovery Time Objective) defines the maximum delay within which an activity must be restored to a sufficient operational level. It must always be shorter than the MTPD — a condition for the BCMS's internal consistency. The RPO (Recovery Point Objective) defines the maximum acceptable data loss, expressed as a unit of time: it directly determines backup frequency and the continuity requirements for information systems.

RTO and RPO are not technical targets set by the IT department. They are governance decisions that translate the organisation's commitments to its stakeholders — customers, regulators, shareholders — and that directly shape investment in continuity solutions.

Continuity strategies and solutions

Continuity strategies define the approach chosen to sustain critical activities within the MTPD: degraded operation, relocation, outsourcing, redundancy, manual workaround procedures. Several strategies may coexist for the same activity depending on the disruption scenario. Continuity solutions translate these strategies into concrete, previously verified arrangements: fallback sites, substitute human resources, backup systems, service contracts, standby equipment. The consistency between strategies, solutions and recovery objectives is one of the effectiveness criteria of a BCMS — and one of the checkpoints of the certification audit.

Business Continuity Plans (BCP)

The BCP translates strategies and solutions into operational procedures: who does what, in what order, with what resources, following what decision and communication chain. An effective BCP is designed to be usable under pressure, by people who may not have contributed to it. It is sober, precise, unambiguous — and its readability in a crisis situation is a quality criterion in its own right. Designing a high-performing BCP is as much an exercise in rigour as in editorial clarity.

Exercises, tests, audit and continual improvement

An untested BCMS is a BCMS whose ability to function is unknown. Exercises — from tabletop simulations to real-condition failover drills — are the only means of validating that strategies are realistic, that plans are operational and that people know their role. Audit verifies the system's conformity with ISO 22301 and the real effectiveness of its arrangements. Continual improvement closes the loop: every exercise, every incident, every organisational, regulatory or technological change is an opportunity to strengthen resilience — and the obligation to do so is written into the standard.

The full normative corpus — beyond ISO 22301

ISO 22301 is the international reference certification standard. Yet it represents only part of the business continuity normative corpus. This training covers the full set of associated standards and technical specifications — an essential differentiator for professionals who want to master the discipline in all its depth, understand the relationships between frameworks and build a BCMS grounded in international best practice.

ISO 22301

Business Continuity Management System — international reference certification standard

Associated standards and technical specifications

ISO 22313

Guidance for the implementation of a BCMS · Interpretation and application of ISO 22301

ISO/TS 22317

Business Impact Analysis (BIA) · Structured process framework for identifying critical activities

ISO/TS 22318

Supply chain continuity · Management of critical supplier dependencies

ISO 22320

Emergency management · Command, coordination and operational communication in a crisis situation

ISO/IEC 27031

ICT readiness for business continuity · The link between the BCMS, the ISMS and information systems resilience

Differentiator · ISO/IEC 27031 — The bridge between the BCMS and ICT

ISO/IEC 27031 (ICT readiness for business continuity) is the bridge between the Business Continuity Management System and the digital infrastructure on which almost all of a modern organisation's critical activities depend. It translates the continuity objectives defined in the BCMS — RTO, RPO, critical activities — into concrete requirements for information systems and ICT infrastructure. It also establishes the link with the Information Security Management System (ISO/IEC 27001): information security and business continuity share risks, resources and objectives that must be governed coherently.

Without ISO/IEC 27031, there is a blind spot between the governance decision (the BCMS) and its operational implementation (ICT). This standard is rarely taught outside the most advanced training programmes — its inclusion in this curriculum is a genuine differentiator.
Intersections — the BCMS within an integrated resilience governance

A high-performing BCMS does not exist in a silo. It is part of a governance ecosystem that connects information security, risk management, data protection and regulatory obligations. Understanding these intersections makes it possible to build a coherent resilience architecture — and to avoid multiplying parallel management systems.

Governance frameworks

ISO/IEC 27001

Information security · Shared risk assessment · ISMS–BCMS alignment · Continuity controls (Annex A)

ISO 31000

Risk management · Common methodological framework for organisational risk management

ISO/IEC 42001

AI governance · New dependencies and new disruption scenarios to integrate into the BIA

European regulatory framework

NIS2

Continuity requirements for essential and important entities · Incident response plans

DORA

Digital operational resilience · Continuity and recovery plans for financial entities · Resilience testing

ISO/IEC 27701

Personal data protection · Continuity of personal data processing · Alignment with GDPR

A component of integrated resilience governance

NIS2 requires essential and important entities to have verifiable continuity and recovery plans. DORA requires financial institutions to maintain periodically tested digital operational resilience plans, covering the most severe disruption scenarios — including third-party provider failures. ISO 31000 provides the common methodological framework for risk management across the organisation, of which continuity risks are only one component. ISO/IEC 42001 introduces new dependencies related to artificial intelligence, which must be integrated into the impact analysis for the BIA to remain relevant.

This integrated vision is what allows a continuity manager, a CISO or a risk manager to build coherent governance — rather than a collection of parallel frameworks that stack up without ever speaking to one another.

International experience

This approach is nurtured by operational experience acquired with organisations facing high requirements for resilience and continuity — major international groups, national defence organisations, entities regulated under NIS2 and DORA, and international training organisations, in France, Luxembourg and Scandinavia.

It draws on field practice that allows standards to be approached not as theoretical texts, but as governance instruments applied to varied operational contexts — with real continuity stakes, BIA processes conducted in complex environments, and exercises testing crisis situations whose consequences are tangible.

PECB Master ISO 22301 — this personal certification anchors this teaching. It ensures that the pedagogical depth conveyed is that of a practitioner who has gone through the most demanding process in the normative corpus themselves, not that of a reader of standards.

The question is not whether your organisation will face a crisis. The question is whether you have decided, prepared and tested before it arrives. A high-performing BCMS is not a response to crisis — it is a decision made before it.

Dominique Bourra  ·  PECB Master ISO 22301 · PECB Platinum Trainer

Going further

ISO 22301 is best considered alongside your other certifications — security, risk, governance. Discover how to build a coherent skills trajectory rather than accumulating isolated certifications → Strategic Capability Architecture

Train your teams, certify a continuity manager or prepare a Lead Implementer?
On site or remote, in French or English.

Request a programme →