Why ISO 22301 Business Continuity is a valuable addition to ISO 27001?
The question your organization needs to ask isn't whether it will face a cyber-attack, but when. That's why more and more companies are investing in information security and cyber resilience. That’s where two international standards come in: ISO 27001 for information security and ISO 22301 for business continuity. In this article, Henk-Willem Mutsaers, Lead Auditor at Kiwa, explains how the two standards reinforce each other and why combining them can help you build broader organizational resilience than either one on its own.
What are ISO 27001 and ISO 22301?
ISO 27001 helps organizations systematically manage information security risks, and put measures in place to prevent and detect incidents and limit their impact.
But cyber resilience today goes beyond securing your information and IT systems. Your company must be able to continue its critical activities when a cyber incident or other disruption occurs. In today’s reality, ISO 27001 only takes you so far. What happens if an incident does occur and your critical processes are disrupted? How do you keep your organization functioning, and get critical services back up as quickly as possible? Enter ISO 22301: the international standard for a Business Continuity Management System (BCMS). Where ISO 27001 is concerned with the confidentiality, integrity and availability of your information and systems, ISO 22301 is concerned with the continuity of your business-critical activities as a whole. Together, they cover far more ground than either standard manages alone.
How do ISO 27001 and ISO 22301 work together?
ISO 27001 does address business continuity, but its focus is information security first. With ISO 22301, business continuity is the core: it identifies which of your activities are essential, what could threaten them, and what you'd need to keep them running or get them back up as fast as possible if something goes wrong.
- ISO 27001 asks: how do we protect our information and information systems?
- ISO 22301 asks: how do we keep our organization running, or get it running again, when something disrupts it? It’s a much wider question than IT alone. It takes in your people, your locations, your suppliers, your processes, your communications, and anything else business-critical.
The two standards aren't competing with each other, they're complementary. ISO 27001 builds your cyber resilience. ISO 22301 builds your resilience more broadly.
From information security to business continuity
By applying ISO 27001, you already have the important elements of management system in place, including risk management, incident management, governance, internal audits and a process of continual improvement. ISO 22301 fits well with this and builds on it.
By integrating ISO 22301, you examine your critical activities and services, asking questions like:
- Which products, services and processes are business-critical?
- What are the consequences if a critical activity is disrupted?
- How long can a process be interrupted at most?
- Which people, locations, systems, suppliers and other resources are required?
- Which external parties and supply chains does the organization depend on?
- How can the organization continue its activities if its normal way of working is no longer possible?
- How will communication take place during a crisis, and who will make which decisions?
- How and within what timeframe will normal operations be restored?
An important tool here is the Business Impact Analysis (BIA). This enables the organization to determine the consequences of disruptions and what needs to be recovered. Based on this, you can develop continuity strategies and specific continuity and recovery plans.
What does ISO 22301 add to ISO 27001?
To understand how ISO 27001 and ISO 22301 work in practice, imagine that your company is hit by a cyber-attack. With ISO 27001 in place, you've got measures to prevent attacks, and detect one when it occurs. You can maintain information security through the incident, and make sure the ICT your critical activities depend on can be recovered. ISO 22301 asks the next question: what does this disruption actually mean for your operations?
Say a ransomware attack takes an important IT system offline for several days. Can your people work a different way in the meantime? Do you have alternative locations or working methods available? Which customers and services need to be prioritized? Which suppliers are essential to your recovery? Who's leading the response, and how is that being communicated? Addressing these issues is what gives you a complete picture of resilience, not just an informational one.
Business continuity and ISO 27001
ISO/IEC 27001:2022 does address business continuity, largely through Annex A, and two controls matter most here:
- A.5.29, "Information security during disruption," is about keeping your information security measures working even under unusual or difficult circumstances.
- A.5.30, "ICT readiness for business continuity," is about making sure the ICT facilities your critical activities depend on can be restored within the timeframe you need.
Both are useful, but their scope stays focused on information security and ICT, which is exactly the gap ISO 22301 is built to close.
From cyber resilience to organizational resilience
At a time when digital disruptions have consequences beyond the IT department, both standards are becoming increasingly relevant. A cyber incident can, for example, lead to production downtime, problems in the logistics chain, delays in service delivery or the temporary inability to serve customers. Equally, non-digital incidents can also have consequences for information security. Examples include fire, a prolonged power outage, the loss of an important supplier or the unavailability of a business location.
ISO 27001 and ISO 22301 approach these risks from different perspectives. Together, they help organizations make both their information systems and critical business activities more resilient. For organizations already certified to ISO 27001, ISO 22301 can therefore be a logical next step. Many elements of the existing management system can be used, while ISO 22301 adds specific attention to Business Impact Analysis, continuity strategies, crisis management, recovery, dependencies, and exercising and testing scenarios.
By combining the two, you have a strong, integrated approach to resilience: ISO 27001 helps the organization protect its information and information systems, while ISO 22301 helps keep the organization as a whole operational and recoverable when a disruption occurs.
Contact us
Would you like to know what combining ISO 22301 and ISO 27001 could mean for your organization? Or would you like to discuss which certification best fits your organization and ambitions?
Kiwa's experts will be happy to help you determine the right approach.