
SS ISO 22313 : 2020
6
COPYRIGHT
8 Operation ............................................................................................................................................. 35
8.1 Operational planning and control ................................................................................................... 35
8.1.1 General .................................................................................................................................................. 35
8.1.2 Business continuity management.............................................................................................. 36
8.1.3 Maintaining business continuity ................................................................................................ 37
8.2 Business impact analysis and risk assessment ......................................................................... 38
8.2.1 General .................................................................................................................................................. 38
8.2.2 Business impact analysis ............................................................................................................... 38
8.2.3 Risk assessment ................................................................................................................................ 42
8.3 Business continuity strategies and solutions ............................................................................. 43
8.3.1 General .................................................................................................................................................. 43
8.3.2 Identification of strategies and solutions ............................................................................... 44
8.3.3 Selection of strategies and solutions ........................................................................................ 46
8.3.4 Resource requirements.................................................................................................................. 47
8.3.5 Implementation of solutions ........................................................................................................ 54
8.4 Business continuity plans and procedures ................................................................................. 55
8.4.1 General .................................................................................................................................................. 55
8.4.2 Response structure .......................................................................................................................... 55
8.4.3 Warning and communication ...................................................................................................... 56
8.4.4 Business continuity plans ............................................................................................................. 58
8.4.5 Recovery ............................................................................................................................................... 64
8.5 Exercise programme ............................................................................................................................ 66
8.5.1 General .................................................................................................................................................. 66
8.5.2 Design of the exercise programme ............................................................................................ 66
8.5.3 Exercising business continuity plans ....................................................................................... 67
8.6 Evaluation of business continuity documentation and capabilities ................................. 70
8.6.1 General .................................................................................................................................................. 70
8.6.2 Measuring effectiveness ................................................................................................................ 71
8.6.3 Outcomes ............................................................................................................................................. 72
9 Performance evaluation ................................................................................................................. 72
9.1 Monitoring, measurement, analysis and evaluation ............................................................... 72
9.1.1 General .................................................................................................................................................. 72
9.1.2 Retention of evidence ..................................................................................................................... 73
9.1.3 Performance evaluation ................................................................................................................ 73
9.2 Internal audit ........................................................................................................................................... 73
9.2.1 General .................................................................................................................................................. 73
9.2.2 Audit programme(s) ....................................................................................................................... 73
9.3 Management review ............................................................................................................................. 74
9.3.1 General .................................................................................................................................................. 74
9.3.2 Management review input ............................................................................................................ 74
9.3.3 Management review outputs ....................................................................................................... 75
10 Improvement ...................................................................................................................................... 75
10.1 Nonconformity and corrective action ........................................................................................... 75
10.1.1 General................................................................................................................................................. 75
10.1.2 Occurrence of nonconformity .................................................................................................... 75
10.1.3 Retention of documented information ................................................................................... 76
10.2 Continual improvement ...................................................................................................................... 76
Bibliography ................................................................................................................................................... 78