Using ISO 27001 & ISO 22301 Toolkit for ISO 22301 implementation
Assign topic to the user
Answer:
If you purchased the ISO 22301 Documentation Toolkit, then there are no information security documents in it. On the other hand, if you purchased the ISO 27001 & ISO 22301 Premium Documentation Toolkit, and want to implement ISO 22301 only, then you should do the following:
- Implement documents from folders Procedure for document and record control, Procedure for identification of requirements, and Risk assessment and treatment
- Then move on to core business continuity documents that you'll find in the folder A.17 Business Continuity
- At last, you should implement documents from folders Training and Awareness Plan, Internal Audit Procedure, Management Review Minutes and Procedure for Corrective Action
Risk assessment methodology, with focus on asset-based risk assessme nt is completely applicable to business continuity as well; in the Risk assessment table you'll find catalogs of threats and vulnerabilities where many of those are applicable to business continuity. This article will also help you: Can ISO 27001 risk assessment be used for ISO 22301? https://advisera.com/27001academy/blog/2013/03/11/can-iso-27001-risk-assessment-be-used-for-iso-22301/
By the way, in the "List of documents" that is included in the toolkit, you can see which documents are mandatory for ISO 22301 and which for ISO 27001.
Comment as guest or Sign in
Jan 14, 2016