ISO 22301

ISO 22301 is the international standard that sets the requirements for the establishment and management of effective business continuity management system (BCMS) in any organization, regardless of size and type of business.

 

Establishment of ISO 22301 is a response to interest of British Standard BS 25999-2, which has been recognized not only in the UK but all over the world.

 

Business continuity contributes to the development of a more robust society. ISO 22301 provides organizations with access to the requirements that will allow to prepare for incidents that may prevent the achievement of business objectives. The Standard can be used to assess the ability of organizations to meet their own needs and obligations associated with business continuity and to establish a business continuity management policy that will provide the structure to implement an effective business continuity management system.

 

ISO 22301 addresses the requirements for:

  • identify key risk factors that already affect your organization,
  • understanding of the needs and obligations of the organization,
  • the establishment, implementation and maintenance of business continuity management system,
  • measure the overall ability of your organization to manage the incident,
  • ensure compliance with the defined business continuity policy.

 

In many cases, the incidents are unacceptable, and the implementation of ISO 22301 will help your organization in establishing best approach to manage them. The Standard has been specifically designed to ensure business continuity even in the most unexpected circumstances.

ISO 22301 certification

When all requirements of the ISO 22301 standard are met, and it can be so proven by internal audits, the organization may proceed to an external audit. This external audit should be carried out by a third party – accredited certification body.

 

Certification will be carried out in 2 Stages. Stage 1 covers document review and Stage 2 checks the functioning of management system within the company.

 

 

During the ISO 22301  certification the auditor firstly will review the system documentation. This will include: business continuity management policy, scope of system. Auditor will review the business continuity assessment and check if it has established management goals and objectives that are measureable and achievable.

 

 

Secondly in separate term full audit will be carried out in order to check if the work methods that are employed are in accordance with procedures and the established goals and appropriate records are kept.

 

 

After positively completing the certification  the Auditor shall recommend that  a certificate for ISO 22301 is issued and  registered.
The next steps are surveillance audits which are aimed to assure that the management system continuous to be effective, is being improved and still in compliance with ISO 22301 standard.

What is the cost of ISO 22301 certification?

ISOQAR has an individual pricing approach for each Client. We take into consideration many factors before we make a proposal.

 


To get a proposal please complete the on-line form or call our office.

Contact us

„According to Article 13, paragraphs 1 and 2 of the General Data Protection Regulation of April 27, 2016 (hereinafter GDPR), we inform you that the administrator of your personal data is ISOQAR CEE sp. z o.o., headquartered in Warsaw, address: ul. Wąwozowa 11, 02-796 Warsaw. Your personal data will be processed for contact purposes necessary for the provision of the service, in accordance with applicable legal regulations based on Article 6(1)(f) of the GDPR.”

„I consent to the processing of my personal data by ISOQAR CEE sp. z o.o as the personal data administrator, for the purpose of receiving commercial and marketing information sent to the provided email address based on Article 6(1)(a) of the GDPR. More information in the Polityka prywatności

Cookie Policy

Klauzula informacyjna zapytanie ofertowe

Information clause regarding the request for quotation

In accordance with Article 13(1) and (2) of the General Data Protection Regulation of April 27, 2016 (hereinafter GDPR), I hereby inform you that:

1. The administrator of your personal data is ISOQAR CEE sp. z o.o., with its registered office in Warsaw, at ul. Wąwozowa 11, 02-796 Warsaw, NIP 9512091016, entered into the National Court Register kept by the District Court for the Capital City of Warsaw, XIII Commercial Division of the National Court Register under KRS number: 0000178492.

2. The Administrator has appointed a Data Protection Officer, Mr. Krzysztof Radtke, who can be contacted by e-mail at: iod@isoqar.pl.

3. Your personal data will be processed for the following purposes:

• To respond to a request for quotation, pursuant to Article 6(1)(f) GDPR. More information available at the link.

• To contact you for the purpose of providing marketing and commercial information, pursuant to Article 6(1)(a) GDPR.

• To pursue the Company’s legitimate interests, consisting of establishing or pursuing claims or defending against claims, pursuant to the Company’s legitimate interest (Article 6(1)(f) GDPR).

4. The recipients of your personal data will be the partners and employees of the Administrator, within the scope of their official duties and based on authorization.

5. Your personal data will not be transferred to any third country or international organization.

6. Your personal data will be stored until the end of cooperation or until you withdraw your consent.

7. You have the right to access your personal data and the right to rectify, erase, restrict processing, the right to data portability, the right to object, and the right to data portability.

8. You have the right to lodge a complaint with the supervisory authority—the Personal Data Protection Office—if you believe that the processing of your personal data violates the provisions of the GDPR.

9. Providing your personal data is voluntary, however it is necessary in order to execute the subject of the agreement / it is necessary due to specific legal provisions (the processing of personal data is a statutory requirement). If you do not consent to the processing of your personal data, the Administrator may refrain from concluding the contract.

10. Your data will not be processed in an automated manner, including profiling. This means no decisions that produce legal effects concerning you, or significantly affect you in a similar way, will be based solely on automated processing of personal data, nor will such automated decisions be made.