Certified ISO 22301 Business Continuity Strategist (Disaster Recovery) (LIVE REMOTE - EASTERN TIME)
Event Information
Event Date | 02-09-2026 8:30 am |
Event End Date | 02-13-2026 4:30 pm |
Cut Off Date | 02-06-2026 5:00 pm |
Cancel Before Date | 01-26-2026 |
Individual Price | USD $4,495.00 |
Location | Remote attendance via ZOOM (Eastern Time) |
Attachment | ISO-22301-CBCS-Program.pdf |
Group Rate
Number of participants | Rate/Person (USD $) |
---|---|
5 | 3,596.00 |
Certified ISO 22301 Business Continuity Strategist Track
- Session 1 -
Learn how to assess risk and business impact of disruptions
as part of Enterprise Risk Management
(Monday - Wednesday)
Overview
Learn ISO 31000 Enterprise Risk Management, and how to leverage the ISO 31000 standard to establish and maintain an ERM program for conducting risk assessments throughout the enterprise.
Then build-out the initial risk program policy right in class!
A successful risk management initiative can affect the likelihood and consequences of risks materializing, as well as deliver benefits related to better informed strategic decisions, successful delivery of change and increased operational efficiency. Other benefits include reduced cost of capital, more accurate financial reporting, competitive advantage, improved perception of the organization, better marketplace presence and, in the case of public service organizations, enhanced political and community support.
And since information security, business continuity/disaster recovery, environmental health and safety, and other critical management systems have the primary purpose of identifying and treating risk, it is essential that your organization establish a common platform and approach for managing risk.
As the foundation session of CIS risk management training courses, this 3-day risk management training and policy workshop session provides thorough coverage of the ISO 31000, 31010, 27005, and 23894 standards, as well as setting out advice on the implementation of an ERM initiative. The purpose of the training is to:
- Describe the principles and processes of risk governance and management;
- Provide a thorough overview of the requirements of ISO 31000, ISO 31010, 27005, and 23894;
- Give practical guidance on designing and implementing a suitable enterprise risk management framework;
- Establish a firm program starting point by using ISO standards 31000:2018, 31010, 27005, and 23894 to build out the initial ERM core policy. Soft-copy editable templates are provided in the instructor-led class:
- Complete ERM Policy (18-Page template provided)
- ERM Context and Scope Document (10-Page template provided)
- ERM Risk Assessment and Risk Treatment Methodology Document (18-Page template provided)
- Procedure for Training and Development Needs Analysis document (8-Page template provided)
- ERM Program project kick-off document (9-Page template provided)
- Procedure for Identification of ERM Project Requirements document (4-Page template provided)
- Procedure for Identification of Statutory, Regulatory, and Contractual Requirements document (1-Page template provided)
- Establish a well-developed risk assessment and risk treatment methodology based upon ISO 31010, ISO 27005 and ISO 23894 best practices
- Leverage ISO best practices to properly identify, analyze, and evaluate risk
- Leverage ISO best practices to mitigate ant treat risk to align to the organization's pre-determined risk tolerance thresholds (risk acceptance criteria)
- Establish risk monitoring, communication, and reporting
- Prepare participants for the ISO 31000 CICRA exam #RM101
Class details
- Duration: 3 days, 8:30 - 4:30
- CPE Credit: 24
- Materials included with live instructor-led training:
- Class manual (complete hard copy of class presentation)
- Hardcopy policy templates
- Softcopy policy templates
- 14 days of unlimited access to online practice exams for exam #RM101
- 1 attempt for the online certification exam #RM101
- Current-year membership in the CIS Body of Certified Professionals
-
- Professional Certification: This course fulfills all prerequisite training requirements for certification exam #RM101 for professional ISO certifications:
- Certified ISO 31000 Internal Controls Risk Analyst (No further training or exam is required beyond what is included with this course)
- Certified ISO 27001 Lead Implementer (Further training and an exam is required beyond what is included with this course)
- Certified ISO 27001 Internal Controls Architect (Further training and an exam is required beyond what is included with this course)
- Certified ISO 27001 Lead Auditor (Further training and an exam is required beyond what is included with this course)
- Certified ISO 22301 Business Continuity Strategist (Further training and an exam is required beyond what is included with this course)
- Certified ISO 22301 Business Continuity Manager (Further training and an exam is required beyond what is included with this course)
- Certified ISO 42001 Lead Implementer (Further training and an exam is required beyond what is included with this course)
- Certificate included with class: Upon course completion, we will provide you with an achievement certificate for 24 continuing professional education (CPE) credits that can be used to fulfill requirements for maintaining a variety of professional credentials for fraud examination, accounting, auditing, and information security.
- Recommended prerequisite training: None
- Catering for participants attending in-person at location. (Not available for remote virtual classroom participants):
- Morning refreshments and snack
- Lunch
- Afternoon refreshments
- Hotel and/or Travel: Not included
* ISO Standards are NOT included in this risk management training, nor provided in class. ISO standards are available for purchase at www.iso.org. |
Audience
Recommended Attendance by Position
Recommended participants for this ISO 31000 enterprise risk management certification training include:
- CEO / Managing Director / Policy Approvers / Strategy Decision Makers
- Chief Information Officer (CIO / CISO)
- ISO 9001:2015 Quality Managers
- ISO 14001:2015 EMS Managers
- Information security managers
- Compliance officers
- Revenue protection managers
- IT managers
- Risk manager (s)
- Business Continuity Manager (s)
- Health, Safety, and Environment (HSE) Risk Manager (s)
- Facilities managers
- Operations department heads (business unit managers)
- Auditors
Learning Objectives
CIS Policy Workshop: ISO 31000 Enterprise Risk Management Content Outline:
- Introduction to ISO 31000, 31010, 27005 and 23894 risk management
- Nature and impact of risk
- Principles of risk management
- Review of ISO 31000
- Achieving the benefits of ERM
- Risk management architecture and strategy
- Program leadership
- Establishing the risk committee and its charter
- Program planning and designing
- Risk context development
- Creating an ERM Policy and supporting documentation
- Roles & responsibilities
- Scope
- Implementing and benchmarking
- Measuring and monitoring
- Improving and reporting
- Program leadership
- Risk assessment and risk treatment methodology (Protocol)
- Criteria development
- Scoping
- Performing risk assessments
- Risk identification
- Risk analysis
- Risk evaluation / Business Impact Assessment
- Risk treatment evaluation
- Risk treatment accreditation, risk monitoring, risk review, and risk communication
Establish a firm program starting point by using ISO 31000 to build out the initial ERM core policy. Throughout the class, our expert instructor will convert ISO standard concepts and requirements into a real ISO-conforming Enterprise Risk Policy. Bring your laptop, and you can work right along with the instructor using electronic (MS Word format) templates we provide in class!* Along with the instructor, you will get your ERM program properly initiated by constructing:
- Complete ISO 31000 ERM Policy (18-Page template provided)
- ISO 31000 ERM Context and Scope Document (10-Page template provided)
- ERM Risk Assessment and Risk Treatment Methodology Document (18-Page ISO 31010/27005 template provided)
- Procedure for Training and Development Needs Analysis document (8-Page template provided)
- ISO 31000 ERM Program project kick-off document (9-Page template provided)
- Procedure for Identification of ERM Project Requirements document (4-Page template provided)
- Procedure for Identification of Statutory, Regulatory, and Contractual Requirements document (1-Page template provided)
* ISO Standards are NOT included in this risk management training, nor provided in class. Students are encouraged to bring their own hard-copies of the standards to the class. ISO standards are available for purchase at www.iso.org.
Professional Certification/Credentialing
This program is required for the following professional certification: Certified ISO 31000 Internal Controls Risk Analyst
Certification Exam-Pass Guarantee
Preparing for Certified Information Security's professional certification exam #RM101 is serious business. This is where we can help. If you first successfully complete:
- All prerequisite course training; and
- All RM101 online practice exams
Certified Information Security guarantees your success in passing CIS exam #RM101.
If you do not pass exam #RM101 on your first attempt after completion of your required course and practice exams, Certified Information Security will allow you to re-test at no additional charge until you successfully pass your certification exam.
- Session 2 -
Learn how to establish and manage
business continuity and disaster recovery
according to ISO 22301 requirements
(Thursday - Friday)
Overview
Get a thorough understanding of the ISO 22301 standard for business continuity and disaster recovery management, how to leverage the ISO 22301 standard to establish and maintain a business continuity management system (BCMS) program. Then build-out the initial ISO 22301-conforming business continuity management program policy right in class!
Business Continuity Management
No two organizations are exactly alike. Even within the same industry and sector, every organization has unique goals, objectives, stakeholders, business processes, and risk tolerance. In order to craft incident response that best fits your organization's needs, you need to establish a system for ongoing understanding and management of those needs. Trying to develop business continuity and contingency procedures before determining what your organization needs the levels of risk it will tolerate, and the organization that will manage business continuity is akin to trying to author a book without first determining a plot. The foundation for business continuity management is established and documented in a business continuity management policy, and this class helps you create or improve that policy.
Designed to follow our 3-day ISO 31000 Enterprise Risk Management program, this 2-day ISO 22301 business continuity strategy and policy workshop continues to participants with a solid understanding of business continuity management. It is based on industry best practice and guidelines for business continuity and reviews the ISO 22301 Standard for business continuity management. Practical exercises and instructor-led discussions will help students understand the benefits of business continuity management in an organization.
This business continuity training will:
- Describe the principles and processes of business continuity management and governance;
- Provide thorough coverage of the requirements of ISO 22301;
- Give practical guidance on designing a suitable framework and business continuity management strategy;
- Give practical advice on setting up and operating business continuity management;
- Prepare you for ISO 22301 certification exams;
- Establish a firm program starting point by using ISO 22301 to build out the initial Business Continuity Management core policy.The CIS ISO 22301 policy template toolkit is included with the instructor-led class:
- Complete ISO 22301-conforming BCM Policy (29-Page template provided)
- Procedure for Training and Development Needs Analysis document (8-Page template provided)
- BCM Program project kick-off document (9-Page template provided)
Class details
- Duration: 2 days, 8:30 - 4:30
- CPE Credit: 16
- Materials included with live instructor-led training:
- Class manual (complete hardcopy of class presentation)
- Hardcopy policy templates
- Softcopy policy templates
- 14 days of unlimited access to online practice exams for exam #BCMS101
- 1 attempt for the online certification exam #BCMS101
- Current-year membership in the CIS Body of Certified Professionals
-
- Professional Certification: This course fulfills prerequisite training requirements for certification exam #BCMS101 for professional ISO 22301 Business Continuity Management certifications:
- Certificate included with class: Upon course completion, we will provide you with an achievement certificate for 16 continuing professional education (CPE) credits that can be used to fulfill requirements for maintaining a variety of professional credentials for fraud examination, accounting, auditing, and information security.
- Recommended prerequisite training: CIS Policy Workshop: ISO 31000 Enterprise Risk Management
- Catering for participants attending in-person at location. (Not available for remote virtual classroom participants):
- Morning refreshments and snack
- Lunch
- Afternoon refreshments
- Hotel and/or Travel: Not included
* ISO Standards are NOT included in this risk management training, nor provided in class. ISO standards are available for purchase at www.iso.org.
Audience
Recommended participants by role for this business continuity training include:
- Policy Approvers / Strategy Decision Makers
- Chief Information Officer (CIO / CISO)
- Business continuity managers and team members
- ISO 14001 EMS Managers
- Information security managers
- Compliance officers
- Revenue protection managers
- IT managers
- Risk managers
- Operations department heads (business unit managers)
- Auditors
Learning objectives
- Business Continuity and Disaster Recovery Management, and ISO 22301
- Principles of business continuity management, disaster recovery, and incident response
- Review of ISO 22301
- Achieving the benefits of Business Continuity and Disaster Recovery
- Business Continuity Management
- Planning and designing
- Implementing and benchmarking
- Measuring and monitoring
- Learning and reporting
- Establish a firm program starting point by using ISO 22301 to build out the initial business continuity core policy. Throughout the class, our expert instructor will convert ISO 22301 concepts and requirements into a real ISO 22301-conforming business continuity policy. Bring your laptop, and you can work right along with the instructor using electronic (MS Word format) templates we provide in class!* Along with the instructor, you will get your Business Continuity program properly initiated by constructing:
- Complete ISO 22301-conforming BRM Policy (29-Page template provided)
- Procedure for Training and Development Needs Analysis document (8-Page template provided)
- BCM Program project kick-off document (9-Page template provided)
* ISO Standards are NOT included in this course, nor provided in class. Students are encouraged to bring their own hard-copies of the standards to the class. ISO standards are available for purchase at www.iso.org.
Professional Certification/Credentialing
Certification Exam-Pass Guarantee
Preparing for Certified Information Security's professional certification exams #BCMS101 and #BCMS102 is serious business.
This is where we can help. If you first successfully complete:
- All prerequisite business continuity training and risk management training; and
- All BCMS101 online practice exams
Certified Information Security guarantees your success in passing CIS ISO 22301 CBCS certification exams #BCMS101.
If you do not pass exams #BCMS101 on your first attempt after completion of your required course and practice exams, Certified Information Security will allow you to re-test at no additional charge until you successfully pass your certification exam.
Group discounts up to 20% are available! Discounts are automatically applied when placing booking reservation. |
Speakers
Allen Keele
Facilitator
For over 25 years, I’ve worked at the intersection of governance, risk, and cybersecurity. As Principal of Certified Information Security (CIS), I’ve advised Fortune 500 companies, enterprises, heavily regulated industries (banks, governments) worldwide on implementing and sustaining:
- ISO 27001 Information Security Management Systems
- NIST Cybersecurity Framework (CSF 2.0) programs
- ISO 42001 AI Management Systems
- Enterprise Risk & Compliance strategies based on ISO 31000, ISO 37301, and ISO 22301
𝗛𝗶𝗴𝗵𝗹𝗶𝗴𝗵𝘁𝘀 𝗶𝗻𝗰𝗹𝘂𝗱𝗲:
- 4,000+ leaders and practitioners 𝘵𝘳𝘢𝘪𝘯𝘦𝘥 & 𝘤𝘦𝘳𝘵𝘪𝘧𝘪𝘦𝘥 𝘪𝘯 𝘎𝘙𝘊 and cybersecurity frameworks
- 40+ 𝘥𝘪𝘨𝘪𝘵𝘢𝘭 𝘢𝘯𝘥 𝘭𝘪𝘷𝘦 𝘵𝘳𝘢𝘪𝘯𝘪𝘯𝘨 𝘱𝘳𝘰𝘨𝘳𝘢𝘮𝘴 used by corporate teams and government agencies globally
- Enterprise engagements with organizations such as Amazon, the NSA, and dozens of central banks
- Authored 7 books on enterprise risk, cybersecurity, and governance frameworks
My focus is helping organizations bridge the gap between policy and operational reality in information security, enterprise risk, and compliance. Whenever you’re ready, here’s how I can help:
1️⃣ Executive & Practitioner Training – train & certify your team in NIST CSF 2.0, ISO 27001, ISO 31000, ISO 22301.
2️⃣ Rapid ISO 42001, 27001, & NIST CSF 2.0 Readiness Assessments – pinpoint gaps and accelerate compliance.
3️⃣ Enterprise GRC Program Design – build practical governance and risk management systems that last.Explore programs at www.certifiedinfosec.com or drop me a message to arrange a quick discovery call.
Contact: allen.keele@certifiedinfosec.com; +1 (904) 406-4311.