New insights by RSS

Planning Resources

Standards, free guidance, our reference briefings and a working glossary. Jump to the glossary.

Continuity work runs on a short list of standards, a much longer list of free government guidance, and a vocabulary that newcomers have to pick up quickly. This page collects the references we rely on most, with a line on what each one is actually good for. Bookmark it, and send it to the next person who inherits "the plan."

Standards and frameworks

  • ISO 22301 – The international requirements standard for a business continuity management system, and the one organizations certify against.
  • ISO 22313 – Guidance on applying ISO 22301, with the practical detail the requirements standard leaves out.
  • ISO/TS 22317 – The technical specification for business impact analysis: scoping, prioritizing activities and setting recovery requirements.
  • ISO 31000 – Principles and guidelines for risk management, useful for fitting continuity into enterprise risk.
  • NFPA 1600 / NFPA 1660 – The long-standing US standard for emergency, continuity and crisis management. NFPA 1600 has now been consolidated into NFPA 1660.
  • NIST SP 800-34 – NIST's contingency planning guide for information systems, the federal reference for IT recovery planning.
  • NIST Cybersecurity Framework 2.0 – Released in 2024 and organized around six functions (govern, identify, protect, detect, respond, recover); the recover function is where cyber programs meet continuity.
  • FFIEC Business Continuity Management booklet – The 2019 examination handbook that US bank and credit union examiners use to evaluate continuity programs.

Financial firms also face service-based requirements under the EU's DORA (applying from 17 January 2025) and the UK operational resilience rules (with a 31 March 2025 deadline). Our plain-English summary of operational resilience rules covers both.

Free government guidance

Our reference briefings

Glossary

After-action report (AAR) – A written review after an exercise or real incident that records what happened, what worked, what did not, and the corrective actions, each with an owner and a date.

Alternate site – Any location other than the normal workplace where an organization can resume operations, from a second office to a vendor-provided recovery facility.

Business continuity plan (BCP) – The documented procedures an organization follows to keep or restore its critical activities during and after a disruption.

Business impact analysis (BIA) – The process of identifying critical activities, how the impact of disrupting them grows over time, and the resources and recovery targets each one needs.

Call tree – A cascading contact list in which each person notifies a set number of others; today usually backed up or replaced by a mass notification system.

Contingent business interruption (CBI) – Insurance cover for income lost when a supplier or customer, rather than your own property, suffers physical damage.

Crisis management team (CMT) – The senior group that makes strategic decisions, approves communications and sets priorities during a major incident.

Disaster recovery plan (DRP) – The technical plan for restoring IT systems, data and infrastructure after a disruption.

Emergency operations center (EOC) – A physical or virtual location where coordination, information management and resource support take place during an incident.

Full-scale exercise – An exercise in which people and equipment actually deploy and operate in real time, as close to a real event as safety allows.

Functional exercise – An exercise that tests coordination, command and control in a simulated environment, usually from an EOC or command post, without sending resources into the field.

Hot, warm and cold sites – Recovery facilities at different levels of readiness: a hot site is fully equipped and current, a warm site is partly equipped, and a cold site offers space and utilities only.

Impact tolerance – Under the UK operational resilience rules, the maximum tolerable level of disruption to an important business service, usually expressed as a length of time.

Important business service – A service provided to external customers or market participants whose disruption could cause intolerable harm to them, to market integrity or to the firm's own viability.

Incident Command System (ICS) – A standardized on-scene structure for managing incidents, with defined roles, common terminology and a span of control that scales with the event.

Maximum tolerable period of disruption (MTPD) – The point after which the impact of not resuming an activity becomes unacceptable; recovery time objectives must sit inside it.

National Incident Management System (NIMS) – The US framework that standardizes how government at every level, the private sector and nonprofits manage incidents together, with ICS at its core.

Recovery point objective (RPO) – The maximum acceptable data loss, expressed as the point in time before the disruption to which data must be restored.

Recovery time objective (RTO) – The target time for resuming an activity or system after a disruption, always shorter than the MTPD.

Single point of failure (SPOF) – Any component, person, supplier or facility whose failure alone would stop a critical activity.

Tabletop exercise – A discussion-based exercise in which participants talk through their response to a scenario, used to test plans, roles and decision-making.

Vital records – Records essential to continuing operations or protecting legal and financial rights, which must be protected and recoverable after a disruption.

Work-area recovery – Providing desks, phones and network access for displaced staff, either at a dedicated recovery center or at another company site.

Work recovery time (WRT) – The time needed after systems come back to verify data, clear backlogs and return to normal work; RTO plus WRT should fit within the MTPD.

Planning Resources | CPE World