October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Business Resilience Needs a Comprehensive Approach

Business resilience connects continuity planning with information-system risk management and cyber-resilient engineering. See what each framework covers and how they fit together.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Business resilience is not a single continuity plan or security tool. It is a connected management effort: identify the products, services and activities that matter; understand the disruptions and dependencies that could affect them; and coordinate continuity, risk, security, privacy, technology and supply-chain work. Business continuity management provides an operational foundation, while information-system risk management and cyber-resiliency engineering address related risks that continuity planning alone may not cover.

What a comprehensive approach to business resilience includes

Begin with the outcomes the organization must sustain or restore: its important products, services and activities. Map the people, processes, facilities, information systems, suppliers and other dependencies that support them. Then assess which disruptions could affect those outcomes and decide how the organization will prepare, respond, recover and improve.

This is a management effort, not simply a document-writing exercise. Continuity, enterprise risk, security, privacy, technology and supply-chain owners should coordinate where their responsibilities overlap. That coordination is a practical way to connect the purposes of the frameworks below; it is not a universal requirement quoted from any one of them.

How the major frameworks fit together

ISO 22301, NIST’s Risk Management Framework (RMF) and NIST’s cyber-resiliency guidance address related but distinct problems. They are complementary, not interchangeable: the first concerns a business continuity management system, the second integrates information-system risks into system development, and the third applies systems engineering to cyber resilience.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Framework Main purpose and scope Lifecycle or approach Risk emphasis
ISO 22301:2019 Requirements for a business continuity management system (BCMS). Establish, implement, operate, monitor, review, maintain and continually improve the BCMS. Disruptive incidents affecting business continuity.
NIST Risk Management Framework Risk management for information systems across different organization sizes and sectors. Integrates risk activities into the system development life cycle. Security, privacy and cyber supply-chain risk.
NIST SP 800-160 Vol. 2 Rev. 1 Cyber-resiliency engineering for systems that depend on cyber resources. Systems engineering to anticipate, withstand, recover from and adapt to adverse conditions. Adverse conditions, stresses, attacks or compromises involving cyber resources.

Use business continuity management as the operational foundation

ISO describes ISO 22301 as the international standard for business continuity management systems. A BCMS is broader than a standalone continuity plan: it is a documented system for establishing, operating, monitoring, reviewing, maintaining and continually improving how an organization manages business continuity. ISO says it is intended to help protect against disruptive incidents, reduce their likelihood and support recovery when they occur. ISO 22301:2019 — Business continuity management systems.

In practice, this gives an organization a structured way to connect its important activities to preparation and recovery arrangements, then check and improve those arrangements over time. It should not be treated as proof that every business risk has been addressed, or as a guarantee of resilience or business performance.

Check the edition and status

ISO identifies ISO 22301:2019 as edition 2, published in October 2019. Its official page lists one amendment, ISO 22301:2019/Amd 1:2024, concerning climate action changes, and says the standard is under revision. Because standards status can change, consult the official ISO page for the current status before relying on an edition for procurement, implementation or certification decisions.

Connect business continuity with information-system risk

When essential activities rely on information systems, continuity planning needs to connect with the way those systems are selected, developed, operated and managed. NIST’s RMF integrates security, privacy and cyber supply-chain risk management into the system development life cycle. NIST describes it as risk-based and usable by organizations of different sizes and sectors, so organizations can make choices suited to their circumstances rather than assume one control set fits every system. See the NIST Risk Management Framework project page and NIST SP 800-37 Rev. 2.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This connection matters when a disruption to a system, vendor or data service could prevent an important business activity from continuing or recovering. The RMF supplies an information-system risk-management lens; it does not replace an organization-wide BCMS.

Engineer systems to withstand and recover from cyber adversity

NIST SP 800-160 Vol. 2 Rev. 1 treats cyber resiliency as a systems-engineering discipline. Its aim is to build and sustain systems able to anticipate, withstand, recover from and adapt to adverse conditions involving cyber resources. NIST says its constructs can be selected and adapted to fit an organization’s technical, operational and threat environments. The publication, Developing Cyber-Resilient Systems, was published in December 2021 and supersedes the November 2019 edition.

Cyber-resiliency engineering is therefore especially relevant where important activities depend on digital systems and resources. It complements continuity arrangements by focusing on system properties and behavior under cyber adversity; it is not a substitute for managing non-cyber disruptions or for broader business continuity management.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Put the pieces into practice

  1. Identify what matters. List the products, services and activities the organization needs to sustain or restore, then map the systems, people, suppliers and other dependencies they require.
  2. Assess disruptions and risk. Consider threats to those activities and dependencies. Bring continuity and information-system risk discussions together, including security, privacy and cyber supply-chain concerns where relevant.
  3. Assign connected ownership. Make clear which leaders own continuity, risk, security, privacy, technology and supplier relationships, and establish how they share decisions when a dependency crosses teams.
  4. Choose the appropriate framework lens. Use a BCMS approach for managing business continuity, the RMF for integrating information-system risk into the system development life cycle, and cyber-resiliency engineering for systems that must cope with cyber adversity.
  5. Tailor and improve. Adapt risk and engineering choices to the organization’s operations and environment. Review arrangements and improve them as systems, dependencies and risks change.

The frameworks provide different structures for this work rather than a single universal recipe. ISO 22301:2019 sets out a BCMS; NIST’s RMF connects security, privacy and cyber supply-chain risk to system development; and NIST SP 800-160 Vol. 2 Rev. 1 addresses cyber-resilient system engineering. An organization can use their distinct purposes to build a coordinated approach without assuming that adopting one standard covers every business risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.