4 - Context
of the organization:
-
This clause introduces requirements necessary to
establish the context of the BCMS as it applies to the organization, as well as
needs, requirements and scope.
-
ISO 22301 requires an organization to 'determine
external and internal issues that are relevant to its purpose and that affect
its ability to achieve the expected outcomes of its BCMS'. Understanding the
organization and how it sits within its environment is an essential step to
ensure any BCMS and BCM solutions developed are fit for purpose and relevant to
the organization and interested parties.
1st
step:
-
Understanding of the organization and its context by determining
external and internal factors that are relevant to establishing, implementing and
maintaining the organization's BCMS.
External
factors examples:
-
Interested parties outside the organization.
-
Political, legal and regulatory environment.
-
Supply chain commitments and relationships.
-
Economic, culture and technology.
Internal
factors examples:
-
Interested parties within the organization.
-
Activities and resources.
-
Policies, objectives and culture.
2nd
step:
-
Identify all the needs and requirements of interested parties.
- The action needed in relation to interested parties.
-
Document legal and regulatory requirements.
3rd
step:
-
Clearly define the scope of the BCMS and it according to
the size, nature and complexity of the organization.
- The scope should identify the key products and services that support the organization's objectives.
- Make sure that you cover all of activities, locations, resources, suppliers and outsourcing partners in the scope.
-
If part of an organization is excluded from the scope of
its BCMS, the organization should document the exclusion with the reason of
exclusion.
Thanks for the article, Waleed!
ReplyDeleteAre these documented within the BCMS or as a separate document? Pls advice. Thanks!
Azhal
azhalvannan@gmail.com
Hi Azhal,
ReplyDeleteYes its documented within the BCMS and you can find details on the ISO 22313 and the GPG.
BR,
Waleed
There is so much to learn from this piece. You are a great help and I would surely try to follow all the learning.
ReplyDeleteISO 22301 Certification
nice post.
ReplyDeleteISO 22301 certification