ISO 22301 certification process
can the organization certified ISO 22301 by partially. in example: only certified in head office, or only certified in certain service, or certain department (business units). what do you propose on the scoping for first time of ISO 22301 certification process.
Assign topic to the user
Your assumption is correct. The scope of ISO 22301 can be all organization or specific services, processes, business units, or locations.
As for the scope for the first certification process, in case you are a small or mid-sized business, up to 500 employees, with only a single location, the best approach is to certify the whole organization (in such cases, the effort to keep the scope separated is not worthy).
In other cases, you should consider your business objectives and the most relevant services.
These articles will provide you a further explanation about the scope definition (they are about ISO 27001, but the same concept applies to ISO 22301):
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/
This material will also help you regarding ISO 22301:
- Book Becoming Resilient: The Definitive Guide to ISO 22301 Implementation https://advisera.com/books/becoming-resilient-the-definitive-guide-to-iso-22301-implementation/
Comment as guest or Sign in
Jul 01, 2020