ISO 22301 Business Continuity BCM Training
ISO 22301 BCM Business Continuity Training
BCM training according to ISO 22301
and disaster recovery management
to achieve the resilience your stakeholders demand.
Designed to follow our 3-day ISO 31000 Enterprise Risk Management program, this 2-day ISO 22301 business continuity strategy and policy workshop continues to provide a solid understanding of business continuity management. It is based on industry best practice and guidelines for business continuity and reviews the ISO 22301 Standard for business continuity management. Practical exercises and instructor-led discussions will help students understand the benefits of business continuity management in an organization.
This business continuity training will:
- Describe the principles and processes of business continuity management and governance;
- Provide thorough coverage of the requirements of the 22301 standard;
- Give practical guidance on designing a suitable framework and business continuity management strategy;
- Give practical advice on setting up and operating business continuity management;
- Prepare you for ISO 22301 CBCS and ISO 22301 CBCM certification exams BCMS101 and BCMS102.
- Establish a firm program starting point by using the 22301 standard to build out the initial Business Continuity Management core policy.
The CIS ISO 22301 policy template toolkit is included with the instructor-led class:
- Complete ISO-conforming BCM Policy (29-Page template provided)
- Procedure document for identification of statutory, regulatory, contractual, and other requirements (1-Page)
- Procedure for Training and Development Needs Analysis document (8-Page template provided)
- BCM Program project kick-off document (9-Page template provided)
| * ISO Standards are NOT included in this risk management training, nor provided in class. ISO standards are available for purchase at www.iso.org. |
It’s convenient!
Certified Information Security provides the training and credentialing you need to become recognized as an authority in information security governance and risk management. You choose the method of delivery: online through our secure website, or in-person at a publicly available course or privately at your facility. We take care of the rest – from administration, to record keeping, to providing certificates of completion and certification.
Online students have the additional convenience of taking courses whenever they want without the need to travel or disrupt their busy schedules. Our program allows users to start and stop without losing their place or data. Learning and certifying expertise has never been so easy!
How to get started - two alternatives
If your employer is paying for your training and certification, we recommend purchasing a complete ISO 22301 Certified Business Continuity Manager (CBCM) certification package voucher that includes all required resources, including membership in the CIS Body of Certified Professionals, all required training programs, all recommended practice exams, and the required certification exam. This allows your employer to purchase and pay all of your necessary resources at once, while still giving you flexibility of when to use your training, practice exams, and certification exams later.

- "Pay-as-you-go" by purchasing your membership in the CIS Body of Certified Professionals, training, recommended practice exams, and the certification exams as you need them. Start by purchasing training, and then purchase practice exams when you are ready. After you complete your practice exams, you then purchase your certification exam.
A breakdown of the costs are as follows:
1. Required CIS Membership Application Fee & Membership Dues: $100.00 Learn more
2. Required Training
| Three Required Courses | Online Self-Study |
|
CIS Policy Workshop: ISO 31000 Enterprise Risk Management |
$399.95 Learn more |
|
- AND - |
|
|
CIS Policy Workshop: ISO 22301 Business Continuity Management |
$299.95 Learn more |
|
- AND - |
|
|
Deploy, exercise, and certify the organization's Business Continuity Management System |
$299.95 Learn more |
3. Optional Online Practice Exams for all exams (RM101, BCMS101, and BCMS102): $225.00 Learn more
4. Required Online Certification Exams (RM101, BCMS101, and BCMS102): $300.00 Learn more
Recommended participants by role for this business continuity training include:
- Policy Approvers / Strategy Decision Makers
- Chief Information Officer (CIO / CISO)
- Business continuity managers and team members
- ISO 14001 EMS Managers
- Information security managers
- Compliance officers
- Revenue protection managers
- IT managers
- Risk managers
- Operations department heads (business unit managers)
- Auditors
CIS Policy Workshop: ISO 22301 Business Continuity Management
Business Continuity Training Topics:
- Business Continuity and Disaster Recovery Management, and the 22301 standard
- Principles of business continuity management, disaster recovery, and incident response
- Review of the 22301 standard
- Achieving the benefits of Business Continuity and Disaster Recovery
- Business Continuity Management
- Planning and designing
- Implementing and benchmarking
- Measuring and monitoring
- Learning and reporting
- Establish a firm program starting point by using the 22301 standard to build out the initial business continuity core policy. Throughout the class, our expert instructor will convert ISO 22301 concepts and requirements into a real ISO-conforming business continuity policy. Bring your laptop, and you can work right along with the instructor using electronic (MS Word format) templates we provide in class!* Along with the instructor, you will get your Business Continuity program properly initiated by constructing:
- Complete ISO-conforming BCM Policy (29-Page template provided)
- Procedure for Training and Development Needs Analysis document (8-Page template provided)
- BCM Program project kick-off document (9-Page template provided)
* ISO Standards are NOT included in this course, nor provided in class. Students are encouraged to bring their own hard-copies of the standards to the class. ISO standards are available for purchase at www.iso.org.
Professional Certification: This course fulfills prerequisite training requirements for certification exam #BCMS101 for professional ISO 22301 Business Continuity Management certifications:
Our simple guarantee to you.
Preparing for Certified Information Security's professional certification exams #RM101, #BCMS101, and #BCMS102 is serious business.
This is where we can help you. If you first successfully complete:
- All prerequisite business continuity training and risk management training; and
- All BCMS101 and BCMS102 online practice exams
Certified Information Security guarantees your success in passing CIS 22301 certification exams #BCMS101 and #BCMS102.
If you do not pass exams #BCMS101 and #BCMS102 on your first attempt after completion of your required course and practice exams, Certified Information Security will allow you to re-test at no additional charge until you successfully pass your certification exams
Frequently Asked Questions (FAQ)
1. What is ISO 22301? Why do we need it?
ISO's 22301 standard is the international standard for a Business Continuity Management System (BCMS), providing a framework for organizations to prepare for, respond to, and recover from disruptive incidents. It helps businesses of all sizes and types to identify potential threats and minimize the impact of a disaster, such as a natural disaster, cyberattack, or supply-chain disruption.
A 22301-compliant BCMS enables an organization to:
- Identify critical processes and assets that are essential to the organization's survival.
- Create a documented, systematic approach to manage business continuity that is regularly reviewed and improved.
- Develop robust plans and procedures to continue delivering products and services at an acceptable, predefined capacity during a disruption.
Why organizations should adopt ISO's 22301 standard
Implementing the 22301 standard offers numerous strategic and operational advantages that build resilience and protect an organization's future.
- Minimize downtime: A structured BCMS helps an organization respond quickly and effectively to an emergency, reducing the duration of a disruption and minimizing financial losses.
- Ensure operational stability: By proactively identifying threats, the standard helps an organization keep its critical functions running during a crisis and improve its recovery time.
- Build a strong framework: A BCMS aligned to ISO's 22301 standard ensures that business continuity plans (BCPs) are comprehensive, tested regularly, and integrated into the organization's culture, rather than being outdated and ignored.
- Gain a competitive advantage: Certification to the standard can differentiate an organization from competitors by showing customers, partners, and stakeholders that it is resilient and reliable.
- Increase customer confidence: Proving that your business can continue to deliver critical services during and after an incident builds and maintains customer trust.
- Better risk management and compliance
- Meet legal and regulatory requirements: Adopting the 22301 standard's framework provides auditable evidence that the organization has taken necessary steps to comply with relevant business continuity laws and regulations.
- Reduce insurance costs: By having a robust BCMS in place, an organization can better evaluate its potential disaster impact and may be able to lower business interruption insurance premiums.
2. Who should use ISO 22301?
ISO's 22301 standard is intended for any organization, regardless of its size, type, or sector, that wants to protect itself from and recover quickly after a disruptive incident. This includes both small businesses and large multinational corporations, as well as public and private entities.
The 22301 standard for a Business Continuity Management System (BCMS) helps any organization increase its resilience against a wide range of threats, such as:
- Cyberattacks and data breaches
- Natural disasters (e.g., floods, earthquakes, extreme weather)
- Utility disruptions or IT system failures
- Supply chain breakdowns
- Pandemics
Organizations in high-risk or regulated industries typically have increased expectation of resilience and reliability
Some organizations, particularly those in high-risk environments or regulated sectors, should especially consider 22301 certification to prove their resilience to stakeholders, regulators, and customers. These industries include:
- Financial services and banking: To protect transactions, payment systems, and customer trust.
- Healthcare: To ensure the continuous delivery of critical patient care during an emergency.
- Information technology: To provide service reliability and security to clients, particularly those with data centers or cloud services.
- Energy, utilities and public services (such as public transportation): To meet emergency planning responsibilities and maintain essential services for the public.
- Manufacturing and supply chain: To secure production and delivery from disruptions and protect the reputation of suppliers.
- Government agencies: To ensure essential public services remain available during a crisis.
3. Is conforming to the ISO 22301 mandatory for regulatory compliance?
No, conforming to ISO's 22301 standard is not mandatory for regulatory compliance across all industries. However, it can be a legal requirement for certain sectors in some countries, and adhering to the standard can help organizations meet broader regulatory requirements for business continuity.
When ISO's 22301 standard is mandatory...
While the International Organization for Standardization (ISO) creates voluntary standards, specific regulations in certain countries or industries may make implementation mandatory. This is particularly common in highly regulated sectors where service disruption poses a significant risk to the public.
4. How does an organization get started using ISO 22301?
To get started, the organization needs to:
- Establish formal Business Continuity Management Function leadership, authority, and subject-matter expertise. One of the most critical first steps is to establish clear accountability and governance by defining who is responsible for managing risks related to business or service-level disruption. Organizations can create a cross-functional committee with representatives from legal, IT, compliance, and relevant business units. A team of cross-functional leaders (e.g., directors, vice presidents, officers, and managers) with sufficient organizational authority must be designated and trained to establish a formal business continuity governance and risk management Function/Department/Office. Optimally,the organization should even consider appointing a Business Continuity Manager to lead the effort.
- Leadership authorizes, initiates, and plans the organization's information security management system to support the organization's greater enterprise governance, risk, and compliance management.
- ISO's 22301 Business Continuity Management System standard is used to improve operations risk governance, assessment, and treatment practiced as part of enterprise risk management.
5. Can I get certified as a subject-matter expert in ISO 22301 Business Comntinuity Management Systems?
Yes! Certified Information Security is the only IRMCB-accredited and authorized training provider and certification exam proctor for the ISO ISO 22301 Business Continuity Strategist (CBCS) and Business Continuity Manager (CBCM) professional credentials.









