| name | design-business-continuity-plan |
| description | Use when preparing an organization to keep critical business functions running through a major disruption — a facility loss, a key-supplier failure, a pandemic, or another severe operational shock — covering people, processes, and facilities broadly, not only IT systems and data recovery. |
| source | ISO 22301, "Security and Resilience — Business Continuity Management Systems," International Organization for Standardization |
| tags | ["business","operations","business-continuity","disaster-recovery","resilience","iso-22301","crisis-management"] |
| related | ["apply-iso-31000-risk-framework","design-vendor-risk-assessment","design-risk-register"] |
Design Business Continuity Plan
Prepare the organization to keep its critical business functions running through a major disruption — a facility loss, a key-supplier failure, a pandemic, or another severe operational shock — covering the full range of people, processes, and facilities the organization depends on, not only its IT systems and data recovery, which a narrower disaster-recovery plan typically addresses.
Why This Is Best Practice
Adopted by: ISO 22301, "Security and Resilience — Business Continuity Management Systems," is the internationally recognized standard for organizational business continuity management, adopted and certified against by organizations across industries seeking to formalize their preparedness for disruptions that go beyond IT infrastructure alone.
An organization with a well-developed IT disaster-recovery plan but no broader business continity plan can find its technology systems restored quickly after a disruption while still being unable to actually operate — because key personnel are unavailable, a critical physical facility is inaccessible, or an essential supplier relationship has failed — gaps a narrowly IT-focused plan doesn't address at all.
Modern organizations depend on far more than their IT systems to function — physical facilities, specific personnel and their availability, supplier and partner relationships, and manual or semi-manual processes all represent points of failure a disruption can hit, and a business continuity plan addressing only IT systems leaves these other dependencies entirely unprepared for, even if the technology recovery itself is well executed.