ISO 22301 as a working programme
Enable ISO 22301 and its 25 controls, clauses 4 to 10, recur with an owner, a due date, a description, a recommendation and a default cadence: 20 yearly, 4 quarterly and 1 half-yearly.
| Clause | Control | Default cadence |
|---|---|---|
| 8.2.1 | Business impact analysis: priorities, dependencies and resource requirements | Yearly |
| 8.2.2 | Risk assessment of disruption | Yearly |
| 8.3 | Business continuity strategies and solutions | Yearly |
| 8.4 | Business continuity plans and procedures | Yearly |
| 8.5 | Exercise programme: an annual tabletop at minimum and a live test of one critical service a year | Yearly |
| 8.6 | Evaluation of business continuity documentation and capabilities | Yearly |
| 9.1 | Monitoring, measurement, analysis and evaluation | Every 6 months |
| 9.2 / 9.3 | Internal audit and management review of the BCMS | Yearly |
| 5.1, 6.3, 10.1, 10.2 | Leadership, planning of changes, nonconformity and corrective action, continual improvement | Quarterly |
ISO 22301 is included from Pro (€99 a month), next to up to four other frameworks.
Continuity controls in your other frameworks
The incident register and its clocks
| Area | What is recorded |
|---|---|
| Classification | 12 types (data breach, account takeover, ransomware, DDoS, phishing, insider, vendor, system failure, misconfiguration, lost device, physical, other) and 4 severities |
| Phases | Investigating, contained, resolved, closed, with timestamps for detection, containment, eradication and resolution |
| Timeline | Entries of type note, update, containment, communication, evidence and decision, each with who and when |
| Clocks | GDPR Art. 33: notify within 72 hours of awareness. NIS2 Art. 23: early warning in 24 hours, notification in 72 hours, final report in one month |
| Notification | Authority, report date and case reference, data subjects notified, and the Art. 33(3) fields: DPO contact, likely consequences, measures taken |
| Learning | Root cause, mitigation, lessons learned, forensic preservation note and the linked corrective-action task |
- The NIS2 significant-incident checker (Implementing Regulation (EU) 2024/2690) evaluates the answers against your entity type and turnover and stores the outcome with the incident.
- The dashboard shows incidents by severity and the share of personal-data breaches reported within 72 hours over the last 12 months.
- Running clocks appear in the "What needs you now" list with the time left or the time over.
- On Enterprise, a public breach-report portal lets anyone report without an account; reports wait in a queue until an admin approves them into the register.
Plans, tests and policies on record
- The compliance profile holds the links to your BC/DR plan, BIA and incident runbook, and the dates of the last BC/DR test and backup-restore test.
- Prepare for Audit flags a BC/DR test or backup-restore test older than 12 months, a missing BC policy or BIA, and a missing exercise programme, BCMS audit or management review (Enterprise).
- Policies have a business continuity category, versions, an approval step and staff acknowledgement; starter templates cover incident response and backup.
- Critical suppliers sit in the vendor register with data access, review dates and contract-expiry alerts; systems in the asset inventory with owner, criticality and classification (Pro and Enterprise).