0% found this document useful (0 votes)
60 views4 pages

ISO 22301 - Business Continuity Management Systems - Risk Assessment

The document outlines the steps for risk assessment according to ISO 22301: identify risks of disruption and analyze them by considering likelihood and consequences; evaluate risks using ISO 31000 guidelines; and treat risks through avoidance, mitigation, sharing, or acceptance. Key risks include threats from fire, flood, hardware or cyber failures, staff loss, and power outages, as well as vulnerabilities from inadequate protections, redundancy, infrastructure, or maintenance. Single points of failure and external events also pose risks.

Uploaded by

Rahul Khanna
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
60 views4 pages

ISO 22301 - Business Continuity Management Systems - Risk Assessment

The document outlines the steps for risk assessment according to ISO 22301: identify risks of disruption and analyze them by considering likelihood and consequences; evaluate risks using ISO 31000 guidelines; and treat risks through avoidance, mitigation, sharing, or acceptance. Key risks include threats from fire, flood, hardware or cyber failures, staff loss, and power outages, as well as vulnerabilities from inadequate protections, redundancy, infrastructure, or maintenance. Single points of failure and external events also pose risks.

Uploaded by

Rahul Khanna
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 4

ISO 22301 - Business Continuity Management Systems

- Risk assessment -

Identify risks 3 Evaluate


1 of disruption risks

Analyze risks Treat the


2 4 risks

What can go wrong? ISO 31000 – Risk


management.
How likely it is to go wrong? Guidelines

What will be the consequences?

What can we do?


ISO 22301 - Business Continuity Management Systems
- Risk assessment -

Threats: Vulnerabilities:

Fire
Inadequate fire protection
Flood
Insufficient redundancy
Hardware failure
Single points of failure
Cyber attack
Inadequate staffing
Staff loss
Poor IT infrastructure
Power failure
Inadequate maintenance
Lack of raw materials


ISO 22301 - Business Continuity Management Systems
- Risk assessment -

Risk = Likelihood x Consequence


Single Points of Failure (SPoF)

- IT manager who
knows everything
- Single supplier …

Events outside the company


ISO 22301 - Business Continuity Management Systems
- Risk assessment -

Avoidance

Mitigation
Risk treatment options:

Share

Accept

You might also like