ISO 22301:2019 sets requirements for a business continuity management system. The standard concerns the organisation's ability to continue or restore critical deliveries when something disrupts operations. The cause may be a cyber attack, a supplier failure, a fire, a pandemic or failing infrastructure. The standard is not concerned with the cause, but with the ability to handle the disruption.
Many organisations have plans. Fewer have exercised them, and fewer still know whether the plans match what the organisation can actually do. This service is therefore about more than writing documents. The organisation should establish, exercise and document a real ability to handle disruption.
Who this is for
- Organisations with deliveries that cannot tolerate a stoppage, internally or towards customers.
- Organisations in scope of NIS2 or sector requirements where continuity is explicitly required.
- Organisations with critical supplier dependencies they do not fully oversee.
- Organisations that have been through an incident and want to fix what it revealed.
- Organisations meeting documented continuity requirements in tenders and customer agreements.
What Berigo can deliver
- Mapping of critical products and services, and what they depend on.
- Business Impact Analysis with consequences over time.
- Risk and threat assessments related to disruption.
- An overview of internal and external dependencies, including suppliers and systems.
- Acceptable outage times and recovery objectives, decided by leadership.
- Continuity strategies that answer those objectives, with cost and realism assessed.
- Emergency plans, continuity plans and recovery plans.
- Crisis leadership with roles, authority and notification lines.
- Crisis communication towards staff, customers, owners, authorities and media.
- Exercises and tests matched to maturity, from tabletop to actual recovery.
- Evaluation after exercises and incidents, with improvements that are followed up.
- Measurement, internal audit and management review.
- Preparation for the certification audit, and support through it.
From plan to capability
The difference between a document and a capability is that the capability has been tested. We therefore build exercises into the work early, and use the findings to correct the plans while they are still being built. A plan that has never been exercised is an assumption. A plan that has been exercised is documentation that the organisation knows what to do.
What you gain
- Clarity about what is genuinely critical, decided by leadership rather than assumed by individuals.
- Known recovery objectives, and plans dimensioned to meet them.
- Roles and authority settled before the crisis rather than during it.
- Exercised plans, with documentation of what was tested and what was improved.
- A basis for answering continuity requirements from customers, supervisors and insurers.
TrustAlign in the work
TrustAlign is Berigo's own portal for governance, risk, compliance and audit support. It is used as the working surface through implementation and onwards into operation, so that requirements, work and evidence sit together instead of being scattered across spreadsheets and shared folders.
- Frameworks and requirements, with compliance status per framework.
- Risk register with risk assessment and follow-up of treatment.
- Control register with status, owners and deadlines.
- Statement of Applicability, with justification per control.
- Policies and governance documents.
- Audit programme, audit plans and the running of audits.
- Findings classified as nonconformity, observation or opportunity for improvement, with root cause, corrective action and verified closure.
- Incidents, vulnerabilities, assets and suppliers.
- Evidence and documentation attached to what it belongs to.
- Management review built on the audit programme.
- Reports and exports of risks, controls, findings, incidents, policies, suppliers and vulnerabilities.
- Norwegian and English interface, a separate organisation per client, roles for administrator, manager and viewer, two-factor sign-in and an audit log.
TrustAlign additionally has a dedicated area for Business Impact Analysis, covering dependencies, impact assessment and recovery objectives.
TrustAlign can be used as a standalone portal, and can by agreement and technical clarification be connected to relevant document and data sources. The portal by itself provides neither certification nor regulatory compliance. It structures the work that has to be done, and makes it verifiable.
Who does what
Berigo is an adviser and implementation partner. The certification audit is carried out by an independent certification body that you choose yourselves. We issue no certificates, we do not influence the auditor's judgement, and we do not guarantee a particular outcome. We prepare the organisation as well as we can, and support you through the audit and the work that follows.