Policy formulation is the BCMS process that is used to develop a business continuity policy that sets out an operating framework. According to ISO 22301, the organization shall establish a business continuity policy that is appropriate to the purpose and context of the organization and provides a framework for setting business continuity objectives. The policy shall also demonstrate top management’s commitment to the BCMS and its continual improvement1. The policy formulation process involves the following steps2:
Define the scope and objectives of the policy
Identify the relevant internal and external issues and requirements
Analyze the current state of the BCMS and the gaps to be addressed
Draft the policy statement and the key principles and guidelines
Review and approve the policy by the top management
Communicate and distribute the policy to the relevant stakeholders
Monitor and update the policy as needed References:
ISO 22301:2019, clause 5.3
ISO 22301 Auditing eBook, page 24
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit