Skip to content
Cyber Horizon
All frameworks

// Information Security

ISO 22301 Business Continuity Management Compliance Software

International standard for organisational resilience and continuity planning.

Framework at a glance

Short name

ISO 22301

Version

Category

Information Security

Controls

30

What ISO 22301 covers

30 controls across 27 domains — every one tracked, owned and evidenced in Cyber Horizon.

Organisational Context

1 controls
  • 4.1 Understanding the organisation

Stakeholders

1 controls
  • 4.2 Interested parties

Scope

1 controls
  • 4.3 Scope of BCMS

Management System

1 controls
  • 4.4 BCMS establishment

Management Commitment

1 controls
  • 5.1 Leadership commitment

Policy

1 controls
  • 5.2 Policy

Governance

1 controls
  • 5.3 Roles and responsibilities

Risk Management

1 controls
  • 6.1 Actions to address risks

Objectives

1 controls
  • 6.2 BC objectives

Resources

2 controls
  • 7.1 Resources
  • 8.4.2 Resource requirements

Training

1 controls
  • 7.2 Competence

Awareness

1 controls
  • 7.3 Awareness

Communication

2 controls
  • 7.4 Communication
  • 8.5.2 Warning and communication

Documentation

1 controls
  • 7.5 Documented information

Operations

1 controls
  • 8.1 Operational planning and control

BIA

1 controls
  • 8.2 Business impact analysis

Risk Assessment

1 controls
  • 8.3 Risk assessment

Strategy

1 controls
  • 8.4 BC strategy

Controls

1 controls
  • 8.4.3 Protection and mitigation

BC Plans

2 controls
  • 8.5 BC plans and procedures
  • 8.5.3 BC plan contents

Incident Response

1 controls
  • 8.5.1 Incident response structure

Testing

1 controls
  • 8.6 Exercise programme

Monitoring

1 controls
  • 9.1 Monitoring and measurement

Audit

1 controls
  • 9.2 Internal audit

Management Review

1 controls
  • 9.3 Management review

Corrective Action

1 controls
  • 10.1 Nonconformity and corrective action

Improvement

1 controls
  • 10.2 Continual improvement

How Cyber Horizon automates ISO 22301

Every ISO 22301 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is ISO 22301 Business Continuity Management?

International standard for organisational resilience and continuity planning.

How many controls does ISO 22301 Business Continuity Management have?

ISO 22301 Business Continuity Management has 30 controls in Cyber Horizon's catalogue, organised across 27 domains.

How does Cyber Horizon help with ISO 22301 Business Continuity Management?

Cyber Horizon maps ISO 22301 Business Continuity Management into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 22301 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See ISO 22301 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 22301 in Cyber Horizon.