Back to blog
Frameworks

ISO 22301 and business continuity: RTO, RPO and the BIA

How ISO 22301 structures business continuity - the business impact analysis, recovery objectives, plans and exercises - and why resilience is now a control area in ISO 27001, the NCA ECC, SAMA CSF and DORA.
GRC Copilot Team
ISO 22301 and business continuity: RTO, RPO and the BIA

ISO 22301 is the international standard for a Business Continuity Management System (BCMS) - the discipline of keeping critical services running through disruption and recovering them predictably when they stop. Resilience has moved from a niche concern to a control area in ISO 27001, the NCA ECC, SAMA CSF and DORA, so this work now serves several frameworks at once.

Start with the Business Impact Analysis

The BIA is the foundation. It identifies your critical activities and quantifies what disruption costs over time. For each activity you determine:

  • Maximum Tolerable Period of Disruption (MTPD) - the point beyond which damage becomes unacceptable.
  • Recovery Time Objective (RTO) - how quickly the activity must be restored, set inside the MTPD.
  • Recovery Point Objective (RPO) - how much data loss is tolerable, which drives backup frequency.
  • Minimum Business Continuity Objective - the reduced level of service acceptable while recovering.
  • Dependencies - people, systems, facilities, suppliers and data each activity relies on.

RTO and RPO are business decisions, not IT preferences. If the business says four hours and your architecture delivers two days, you have found a gap worth funding.

From analysis to plans

  1. Risk assessment - what could realistically cause disruption: outage, cyber attack, supplier failure, facility loss, key-person absence.
  2. Continuity strategies - redundancy, failover, alternate sites, manual workarounds, alternate suppliers.
  3. Business continuity plans - who does what, in what order, with what authority.
  4. Disaster recovery plans - the technical restoration procedures for systems and data.
  5. Crisis communication - how you inform staff, customers, regulators and the public, and who is authorised to speak.
  6. Exercises - because an untested plan is an assumption.

Turn continuity plans into evidenced controls

GRC Copilot assesses you against ISO 22301, links your BIA, plans and exercise records to the resilience controls in every framework you report against, and flags tests that are overdue.

Testing: the part everyone under-does

Auditors ask for evidence of exercises, not the existence of a plan. Escalating levels of rigour:

  • Plan walkthrough - the team reads and validates the plan.
  • Tabletop exercise - a facilitated scenario discussion with decisions recorded.
  • Technical restoration test - actually restore a system from backup and verify integrity.
  • Failover test - switch to the secondary environment and run on it.
  • Full simulation - end-to-end, including communications.

Whatever the level, record the date, participants, scenario, what failed and what you changed as a result. A test that surfaced problems and drove fixes is stronger evidence than one that reported flawless success.

A backup you have never restored is a hypothesis. The restoration test is what converts it into a control.

Where resilience shows up in other frameworks

  • ISO 27001 - continuity of information security and ICT readiness controls in Annex A.
  • NCA ECC - Cybersecurity Resilience is one of the four main domains.
  • SAMA CSF - continuity requirements within operations and technology.
  • SOC 2 - the Availability criteria, where committed.
  • DORA - operational resilience testing for EU financial entities.

One BIA, one set of plans and one exercise programme can evidence all of them.

Frequently asked questions

What is the difference between RTO and RPO?

RTO is how quickly you must restore a service; RPO is how much data you can afford to lose. RTO drives recovery architecture, RPO drives backup and replication frequency.

Is business continuity the same as disaster recovery?

No. Disaster recovery is the technical restoration of systems and data. Business continuity is the wider capability of keeping the business operating, including people, facilities, suppliers and communications.

How often should continuity plans be tested?

At least annually for critical services, and after significant change. Backup restoration tests should be more frequent - many organisations test quarterly.

Do we need ISO 22301 certification?

Only if customers or regulators require it. Many organisations adopt the methodology - BIA, RTO and RPO, plans, exercises - without certifying, and use it to satisfy resilience controls in their other frameworks.

Key takeaways

  • The BIA sets RTO and RPO, and those are business decisions.
  • Plans without exercises are assumptions - test and record the results.
  • Restoration testing is the evidence auditors ask for, not backup logs.
  • One continuity programme evidences resilience controls across several frameworks.
#iso22301 #business-continuity #bcms #resilience #disaster-recovery