BS 25999, ISO 27031 and ISO 22301

Steelhenge ensures that all work conducted for clients is aligned with the British Standard in Business Continuity Management, BS 25999 and the International Standard for ICT Continuity Management, ISO 27031.  ISO 27031 was published in March 2011 and supersedes BS 25777 which is now withdrawn.

We ourselves are certified to BS 25999 and a member of the British Standard Institutes' Associate Consultant Programme for BS 25999 and ISO 27001. This means that not only do we have a demonstrable track record in successfully assisting clients in their preparation for certification but also that our customers may be confident in our own continuity readiness as a supplier.

BS 25999

BS 25999 establishes the process, principles and terminology of business continuity management (BCM). The purpose of this Standard is to provide a basis for understanding, developing and implementing business continuity within an organisation and to provide confidence in the organisation's dealings with customers and other organisations. It also enables the organisation to measure its BCM capability in a consistent and recognised manner.

BS 25999 is published by the British Standards Institution. It comprises two parts: BSM Lifecycle

  • Part 1: The Code of Practice
    This provides BCM best practice recommendations. It establishes the process, principles and terminology of business continuity management, providing a basis for understanding, developing and implementing business continuity within an organisation and to provide confidence in business-to-business and business-to-customer dealings.
  • Part 2: The Specification
    This details the requirements for a Business Continuity Management System (BCMS) based on BCM best practice and is used as the basis for the certification process.

The BSI has subsequently expanded on BS 25999 with three Published Documents (PD) offering additional guidance for Human Aspects of Business Continuity (PD 25111:2010), Guidance on Exercising and Testing for Continuity and Contingency Programmes (PD 25666:2010) and Guidance on Organizational Recovery following Disruptive Events (PD 25888:2011).

ISO 27031

ISO 27031 describes the concepts and principles of ICT readiness for business continuity and provides a framework of methods and processes to identify and specify all aspects for improving an organisation's ICT readiness to ensure business continuity.  ISO 27031 is a guideline and certification is possible only for ISO/DIS 22301 once it is published.

ISO 22301 and ISO 22313

ISO 22301 is the specification document for the pending International Standard on Societal Security – Business Continuity Management Systems, against which organisations will seek certification.  The earliest date it is likely to be published is mid 2012.

ISO 22313 is the guidance document to support the specification document (ISO 22301).  

We are actively keeping abreast of both of these new Standards.