AS ISO 22301:2017 pdf free.Societal security – Business continuity management systems – Requirements.
4 Context of the organization
4.1 Understanding of the organization and its context
The organization shall determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcome(s) of its BCMS.
These issues shall be taken into account when establishing, implementing and maintaining the organization’s BCMS.
The organization shall identify and document the following:
a) the organization’s activities, functions, services, products, partnerships, supply chains, relationships with interested parties, and the potential impact related to a disruptive incident;
b) links between the business continuity policy and the organization’s objectives and other policies, including its overall risk management strategy; and
c) the organization’s risk appetite.
In establishing the context, the organization shall
1) articulate its objectives, including those concerned with business continuity.
2) define the external and internal factors that create the uncertainty that gives rise to risk,
3) set risk criteria taking into account the risk appetite, and
4) define the purpose of the BCMS.
4.2 Understanding the needs and expectations of interested parties
4.2.1 General
When establishing its BCMS. the organization shall determine
a) the interested parties that are relevant to the BCMS, and
b) the requirements of these interested parties (i.e. their needs and expectations whether stated, generally implied or obligatory).
4.2.2 Legal and regulatory requirements
The organization shall establish, implement and maintain a procedure(s) to identify, have access to, and assess the applicable legal and regulatory requirements to which the organization subscribes related to the continuity of its operations, products and services, as well as the interests of relevant interested parties.
The organization shall ensure that these applicable legal, regulatory and other requirements to which the organization subscribes are taken into account in establishing, implementing and maintaining its BCMS.
The organization shall document this information and keep it up-to-date. New or variations to legal, regulatory and other requirements shall be communicated to affected employees and other interested parties.
4.3 Determining the scope of the business continuity management system
4.3.1 General
The organization shall determine the boundaries and applicability of the BCMS to establish its scope.
When determining this scope, the organization shall consider
— the external and internal issues referred to in 4.1, and
— the requirements referred to in 4.2.AS ISO 22301 pdf download.

