Scaling implementation of ISO 22301 to facilitate implementation
How can we best scale the implementation of ISO 22301 to facilitate implementation in a range of countries and locations ranging from countries with a presence of approx. 10 people to countries with >10,000 people across multiple business streams and locations?
Assign topic to the user
First of all, implementing a certification in multiple geographic locations is a complex task and you should go for it only if it is really necessary for business strategies and objectives. Instead, you should consider the prioritization of locations and implementing the certification one location at a time.
In case there is a need for simultaneous implementation across multiple sites, a good approach would be:
- evaluate sites to identify interrelationships and dependencies between them
- define groups with similar characteristics, like size, business stream, interrelationships and dependencies
- define how to fulfill the standard's requirements considering two levels: the first level covering what is common for all defined groups (e.g., most aspects of business continuity policy, document control procedure, management review, Business Impact Analysis Methodology, etc.), and the second level covering what needs to be defined by each group, or unique location (e.g., continuity objectives, business continuity strategy, business continuity plan, etc.)
- Develop the general documents in a global way and after those are developed, then coordinate the development of specific documents in the other sites
For further information, see:
- 17 steps for implementing ISO 22301 https://advisera.com/27001academy/knowledgebase/17-steps-for-implementing-iso-22301/22301/iso-22301/
Comment as guest or Sign in
Jul 24, 2020