Continuity work runs on a short list of standards, a much longer list of free government guidance, and a vocabulary that newcomers have to pick up quickly. This page collects the references we rely on most, with a line on what each one is actually good for. Bookmark it, and send it to the next person who inherits "the plan."
Standards and frameworks
- ISO 22301 – The international requirements standard for a business continuity management system, and the one organizations certify against.
- ISO 22313 – Guidance on applying ISO 22301, with the practical detail the requirements standard leaves out.
- ISO/TS 22317 – The technical specification for business impact analysis: scoping, prioritizing activities and setting recovery requirements.
- ISO 31000 – Principles and guidelines for risk management, useful for fitting continuity into enterprise risk.
- NFPA 1600 / NFPA 1660 – The long-standing US standard for emergency, continuity and crisis management. NFPA 1600 has now been consolidated into NFPA 1660.
- NIST SP 800-34 – NIST's contingency planning guide for information systems, the federal reference for IT recovery planning.
- NIST Cybersecurity Framework 2.0 – Released in 2024 and organized around six functions (govern, identify, protect, detect, respond, recover); the recover function is where cyber programs meet continuity.
- FFIEC Business Continuity Management booklet – The 2019 examination handbook that US bank and credit union examiners use to evaluate continuity programs.
Financial firms also face service-based requirements under the EU's DORA (applying from 17 January 2025) and the UK operational resilience rules (with a 31 March 2025 deadline). Our plain-English summary of operational resilience rules covers both.
Free government guidance
- Ready.gov Business – Planning steps, hazard-specific toolkits and templates, aimed especially at small and midsize organizations.
- FEMA for businesses and organizations – FEMA's hub for private-sector coordination, including the National Business Emergency Operations Center.
- FEMA Independent Study Program – Free online courses, including the ICS and NIMS basics (IS-100, IS-200, IS-700 and IS-800).
- CISA critical infrastructure security and resilience – Guidance across the 16 critical infrastructure sectors, plus CISA's regional offices for local assessments and exercise support.
- National Weather Service safety – Hazard-by-hazard guidance on floods, hurricanes, tornadoes, heat, winter storms and more.
Our reference briefings
- Disasters that shaped business continuity planning – The history of the discipline, told through the events that changed it.
- Annotated sample table of contents for a business continuity plan – What belongs in each section of a usable plan.
- Business continuity certifications compared – The main credentials and who each one suits.
- Business continuity careers: roles and paths – The job family, entry routes, skills and how to move up.
- Surviving a BCM audit or regulatory examination – Preparing evidence, working with examiners and closing findings.
- Inside an emergency operations center – How an EOC is organized and how it runs during an activation.
- Public–private partnerships in emergency management – How businesses connect with FEMA, state EOCs, ISACs and local agencies.
- Pandemic and infectious-disease continuity planning – Absenteeism, triggers and remote operations for long-running health emergencies.
- Business interruption insurance and continuity planning – How business interruption cover works and how a good plan supports a claim.
- Ransomware downtime: why the outage costs more than the ransom – Where the real costs of a ransomware event come from.
- Duty of care and business continuity – What employers owe their people before, during and after a disruption.
Glossary
After-action report (AAR) – A written review after an exercise or real incident that records what happened, what worked, what did not, and the corrective actions, each with an owner and a date.
Alternate site – Any location other than the normal workplace where an organization can resume operations, from a second office to a vendor-provided recovery facility.
Business continuity plan (BCP) – The documented procedures an organization follows to keep or restore its critical activities during and after a disruption.
Business impact analysis (BIA) – The process of identifying critical activities, how the impact of disrupting them grows over time, and the resources and recovery targets each one needs.
Call tree – A cascading contact list in which each person notifies a set number of others; today usually backed up or replaced by a mass notification system.
Contingent business interruption (CBI) – Insurance cover for income lost when a supplier or customer, rather than your own property, suffers physical damage.
Crisis management team (CMT) – The senior group that makes strategic decisions, approves communications and sets priorities during a major incident.
Disaster recovery plan (DRP) – The technical plan for restoring IT systems, data and infrastructure after a disruption.
Emergency operations center (EOC) – A physical or virtual location where coordination, information management and resource support take place during an incident.
Full-scale exercise – An exercise in which people and equipment actually deploy and operate in real time, as close to a real event as safety allows.
Functional exercise – An exercise that tests coordination, command and control in a simulated environment, usually from an EOC or command post, without sending resources into the field.
Hot, warm and cold sites – Recovery facilities at different levels of readiness: a hot site is fully equipped and current, a warm site is partly equipped, and a cold site offers space and utilities only.
Impact tolerance – Under the UK operational resilience rules, the maximum tolerable level of disruption to an important business service, usually expressed as a length of time.
Important business service – A service provided to external customers or market participants whose disruption could cause intolerable harm to them, to market integrity or to the firm's own viability.
Incident Command System (ICS) – A standardized on-scene structure for managing incidents, with defined roles, common terminology and a span of control that scales with the event.
Maximum tolerable period of disruption (MTPD) – The point after which the impact of not resuming an activity becomes unacceptable; recovery time objectives must sit inside it.
National Incident Management System (NIMS) – The US framework that standardizes how government at every level, the private sector and nonprofits manage incidents together, with ICS at its core.
Recovery point objective (RPO) – The maximum acceptable data loss, expressed as the point in time before the disruption to which data must be restored.
Recovery time objective (RTO) – The target time for resuming an activity or system after a disruption, always shorter than the MTPD.
Single point of failure (SPOF) – Any component, person, supplier or facility whose failure alone would stop a critical activity.
Tabletop exercise – A discussion-based exercise in which participants talk through their response to a scenario, used to test plans, roles and decision-making.
Vital records – Records essential to continuing operations or protecting legal and financial rights, which must be protected and recoverable after a disruption.
Work-area recovery – Providing desks, phones and network access for displaced staff, either at a dedicated recovery center or at another company site.
Work recovery time (WRT) – The time needed after systems come back to verify data, clear backlogs and return to normal work; RTO plus WRT should fit within the MTPD.
