ISO 22301 - Business Continuity Management Systems
- Risk assessment -
          Identify risks                  3     Evaluate
   1      of disruption                         risks
                               Analyze risks                   Treat the
                           2                               4   risks
       What can go wrong?                 ISO 31000 – Risk
                                          management.
  How likely it is to go wrong?           Guidelines
 What will be the consequences?
        What can we do?
ISO 22301 - Business Continuity Management Systems
                - Risk assessment -
Threats:                         Vulnerabilities:
           Fire
                          Inadequate fire protection
          Flood
                            Insufficient redundancy
    Hardware failure
                             Single points of failure
      Cyber attack
                              Inadequate staffing
        Staff loss
                             Poor IT infrastructure
      Power failure
                           Inadequate maintenance
  Lack of raw materials
                                        …
            …
  ISO 22301 - Business Continuity Management Systems
                  - Risk assessment -
Risk = Likelihood x Consequence
                                  Single Points of Failure (SPoF)
                                            - IT manager who
                                            knows everything
                                            - Single supplier …
Events outside the company
 ISO 22301 - Business Continuity Management Systems
                 - Risk assessment -
                          Avoidance
                          Mitigation
Risk treatment options:
                          Share
                          Accept