7.13 Business Continuity Planning & Exercises
7.13 Business Continuity Planning & Exercises
Disaster Recovery asks: how do we restore disrupted technology?
Business Continuity asks a broader question:
How does the organisation continue delivering its most important products and services while disruption is happening?
The normal office may be inaccessible. A cloud provider may be unavailable. Half the workforce may be absent. A supplier may fail. Telecommunications may be disrupted. Ransomware may disable corporate IT.
Business Continuity prepares the organisation to continue its essential activities at an acceptable level until normal operations can be restored.
Prioritise
Identify the products, services and processes that matter most.
WHAT MUST CONTINUE?Continue
Establish alternative people, locations, technology, suppliers and procedures.
HOW DO WE KEEP OPERATING?Exercise
Practise continuity arrangements and improve them before a real disruption occurs.
DOES THE PLAN WORK?Participate in Business Continuity Planning and Exercises
ISC2 does not currently list separate sub-bullets under objective 7.13.
The lesson therefore focuses on the concepts needed to understand and participate effectively in organisational Business Continuity.
Determine what the organisation must continue delivering.
Understand what happens when those activities are disrupted.
Identify the people, technology, premises, information and suppliers required.
Establish alternative ways of continuing essential activities.
Document how continuity arrangements will be activated and operated.
Practise the plan and discover weaknesses.
Domain 1.7 vs Domain 7.13
Identify, analyse, assess, prioritise and implement Business Continuity requirements.
WHAT DOES THE BUSINESS NEED?
Participate in Business Continuity planning and exercises.
HOW DO WE PREPARE AND PRACTISE IT?
The Business Continuity Lifecycle
BC Lifecycle
Business Continuity Is About the Business
A Business Continuity Plan describes how important business or mission processes will be sustained during and after significant disruption.
Technology is important, but it is only one dependency.
Can the necessary workforce perform the activity?
Do people have somewhere safe to work?
Are required systems and communications available?
Can personnel access the data and records they need?
Are critical external products and services still available?
Can activities be performed another way?
Business Continuity vs Disaster Recovery
Keeps important business activities operating during disruption.
KEEP THE BUSINESS GOING
Restores disrupted information systems and technology capability.
RESTORE THE TECHNOLOGY
BC vs DR
BC vs DR vs Incident Response vs Emergency Management
| Discipline | Main Question |
|---|---|
| Incident Response | How do we control and resolve the security incident? |
| Emergency Response | How do we protect people and manage the immediate emergency? |
| Disaster Recovery | How do we restore disrupted technology? |
| Business Continuity | How do we keep essential business activities operating? |
Ransomware Across the Enterprise
Business Impact Analysis - BIA
The BIA examines business activities and determines how disruption affects the organisation over time.
Business Impact Is Broader Than Money
Lost revenue, penalties, additional operating costs.
Inability to deliver products or services.
Failure to satisfy legal or regulatory obligations.
Harm to employees, customers or the public.
Loss of service, trust or contractual performance.
Damage to confidence in the organisation.
โฑ๏ธ Impact Changes Over Time A disruption may be tolerable briefly but unacceptable later
After 5 minutes: minor customer inconvenience.
After 2 hours: large transaction backlog.
After 24 hours: major financial and regulatory impact.
MTD ยท RTO ยท RPO
How long can the business process be disrupted before significant harm occurs?
BUSINESS LIMIT
How quickly should the supporting capability be recovered?
RECOVERY TARGET
How far back can recovered information go without unacceptable data loss?
DATA TARGET
Time & Data
Continuity Does Not Always Mean 100% Normal Service
During disruption, the organisation may continue an important activity at a reduced but acceptable level.
Customer contact centre: 1,000 staff.
Available workforce: 400 staff.
Organisation temporarily prioritises:
Lower-priority enquiries: delayed.
๐ฏ Not Everything Is Equally Critical Prioritisation is necessary when resources are limited
If every application, process and service is labelled: critical,
then the organisation has not meaningfully prioritised.
Business Processes Depend on Resources
Employees, specialists, contractors, decision-makers.
Offices, factories, warehouses, data centres.
Applications, networks, devices, cloud services.
Databases, records, documentation and contact details.
Electricity, water, fuel, telecommunications.
External organisations providing critical goods or services.
Movement of personnel, products and materials.
Specialist machinery, workspaces and physical resources.
The Application Is Healthy
Online retailer's website: fully operational.
Payment provider: available.
Warehouse: available.
Delivery partner: has ceased operations.
Supplier Continuity
A critical supplier should be assessed as part of the continuity chain.
What happens if the supplier becomes unavailable?
Are several critical services dependent on the same provider?
Does the supplier share the same regional disruption risk?
Can another supplier provide the product or service?
What continuity arrangements does the supplier have?
Do service and recovery commitments support business requirements?
๐ Single-Supplier Dependency A highly resilient organisation can still depend on a fragile supplier
Two data centres: available.
Remote workforce: available.
Applications: highly available.
But all customer authentication depends on: one external identity provider.
How Can the Business Continue?
Move activity to another office, site or facility.
Allow personnel to operate without the normal workplace.
Redirect critical supply to another provider.
Perform a normally automated business activity manually.
Move trained personnel to the highest-priority activities.
Continue only essential products or features.
Invoke Disaster Recovery where technology is required.
Maintain spare resources required during disruption.
โ๏ธ Manual Workarounds Continue the business process without its normal technology
Supplier payments approved through: automated workflow system.
Application unavailable.
Critical payments use: documented manual dual-approval procedure.
Manual workarounds should preserve appropriate authorisation, segregation of duties, auditability and reconciliation.
Manual Workarounds Have Limits
A manual process may support only a fraction of normal workload.
Removing automation can increase human mistakes.
Normal automated controls may no longer operate.
A workaround suitable for four hours may be unsuitable for four weeks.
Remote-Working Continuity
Main office: inaccessible for three weeks.
Strategy: workforce operates remotely.
The continuity plan should consider:
Workforce Continuity
Buildings and systems may remain available while the workforce does not.
More than one person can perform critical activities.
Alternate decision-makers can assume critical authority.
Scarce personnel can be moved to the most important activities.
Staff can operate away from affected premises.
External resources may provide additional capacity.
Continuity plans must recognise the safety and practical needs of personnel.
Systems Available - People Unavailable
Data centres: healthy.
Applications: healthy.
Network: healthy.
45% of critical operations staff: unavailable.
What If the Building Is Unavailable?
Building itself: not structurally destroyed.
But authorities prohibit re-entry for: 10 days.
Information Continuity
Personnel cannot continue a critical process if the required information is unavailable.
Emergency supplier list stored: only inside unavailable corporate SharePoint.
Business Continuity Requires Communication
Where should they work and what should they do?
What is the business impact and what decisions are required?
Which services remain available?
Which continuity arrangements need activation?
Are notifications or updates required?
Is external emergency coordination required?
๐ Alternate Communications Normal communication channels may be part of the disruption
Identity platform fails.
All three become: unavailable.
When Do We Activate Business Continuity?
What disruption conditions may require continuity arrangements?
Who can activate the plan?
Which processes or locations are affected?
Who must be informed?
Which continuity arrangements should be activated?
Which activities receive scarce resources first?
What Should a Business Continuity Plan Tell You?
What does the plan protect?
When and by whom is it invoked?
What must continue?
What receives resources first?
Who does what?
Who takes over if key people are unavailable?
How does each activity continue?
What people, technology and suppliers are required?
How are stakeholders coordinated?
How are temporary arrangements withdrawn?
๐ The Plan Must Survive the Disruption Continuity documentation must remain accessible
Stored: only on internal network drive.
Ransomware: encrypts network drive.
Protect the Business Continuity Plan
Continuity documentation can contain sensitive information.
Returning to Business as Usual
Continuity mode is normally temporary.
๐ Reconcile Temporary Transactions Manual continuity activity may need to be entered into normal systems later
600 customer requests processed using: manual continuity forms.
Normal system returns.
The organisation must now:
Business Continuity Must Be Practised
Objective 7.13 explicitly requires participation in Business Continuity exercises.
Unlike objective 7.12, ISC2 does not prescribe a separate list of BC exercise types here.
In practice, organisations may use different levels of exercise depending on the objective.
Participants discuss how business activities would continue under a scenario.
Participants step through continuity arrangements and resources.
Personnel perform or simulate continuity roles under realistic conditions.
Selected continuity capability is actually used where appropriately controlled.
These are practical exercise approaches. They should not be mistaken for additional official ISC2 7.13 sub-bullets.
DR Test vs BC Exercise
Can technology recovery capability restore the affected systems?
Can the organisation continue its critical business activities?
7.12 vs 7.13
Define an Exercise Objective
"Exercise Business Continuity."
BC Exercise Cycle
The Office Is Unavailable for 30 Days
Scenario:
Structural damage makes headquarters inaccessible for one month.
Technology remains operational.
Questions
Critical Supplier Fails
Exercise inject:
sole logistics provider ceases operations immediately.
Regional Power Failure
Headquarters: without power.
Local mobile network: degraded.
Public transport: partially suspended.
Data centre: operational on backup power.
Critical SaaS Platform Unavailable
Customer relationship platform: unavailable globally.
Employees: healthy.
Offices: open.
Corporate IT Is Offline
Security isolates: large parts of the corporate network.
This may be the correct incident-response action.
But it also means:
Test the People, Not Just the Plan
Can alternates make required decisions?
Do they understand their continuity procedures?
Do they know where to work and how to communicate?
Can external continuity arrangements be activated?
Can internal and external messages be coordinated?
Are continuity workarounds maintaining an acceptable security posture?
๐ก๏ธ Continuity Mode Still Needs Security Disruption does not automatically justify abandoning controls
Employees propose:
emailing customer records to personal accounts so they can continue working.
Continuity Controls May Be Different - Not Absent
Automated transaction approval with: workflow controls and electronic audit trail.
Temporary manual process uses:
Exercise Findings Must Lead to Action
Business Continuity Plans Must Change With the Business
Continuity strategy: move call-centre staff to Office B.
Office B: sold two years ago.
Plan for Effects, Not Only Named Disasters
It can be useful to think about loss of capability rather than trying to predict every possible disaster.
Whatever caused it.
Whatever caused it.
Whatever caused it.
Whatever caused it.
Whatever caused it.
Whatever caused it.
๐ Cascading Disruption One failure can create several continuity problems
Two Suppliers - One Dependency
Organisation uses: Supplier A and Supplier B.
This appears diversified.
Exercise reveals both suppliers depend on: the same upstream manufacturer.
Make Scenarios Plausible and Challenging
Scenario should be meaningful for the organisation.
Exercise should test important continuity requirements.
Do not assume every backup resource works perfectly.
Exercise risk should remain appropriately managed.
Observe What Actually Happens
Finding Problems Is Useful
Alternate supplier: cannot provide capacity for seven days.
BIA requires: continuity within four hours.
That is an important finding.
The organisation now has an opportunity to: change its continuity strategy before a real disruption occurs.
Business Continuity Measures
How quickly were continuity arrangements invoked?
Did essential services remain available?
Could the organisation deliver the required level of service?
Were required stakeholders reached?
Did alternate supply arrangements work?
Are continuity weaknesses being corrected?
๐ CISSP Scenarios Recognise the Business Continuity principle being tested
Management asks what Business Continuity primarily protects.
Best answer?
The organisation's ability to continue critical business activities.
Management asks what Disaster Recovery primarily restores.
Best answer?
Disrupted information systems and technology capability.
Is Disaster Recovery broader than Business Continuity?
Answer?
No. Business Continuity is broader and can include DR.
A business process must continue even while its application is unavailable.
Which concept?
Business Continuity.
The organisation analyses what happens when payroll is unavailable for increasing periods.
Which activity?
Business Impact Analysis.
The process can be disrupted for no more than eight hours without significant harm.
Which concept?
MTD.
The supporting system should recover within four hours.
Which concept?
RTO.
Recovered information can be no more than 30 minutes old.
Which concept?
RPO.
The RTO exceeds the maximum period the business can tolerate.
Primary problem?
Recovery capability does not support business continuity requirements.
Every business process is classified as critical.
Primary concern?
Meaningful prioritisation has not occurred.
The organisation can deliver only its most important services during disruption.
Can this still represent continuity?
Yes, if the reduced capability satisfies established business requirements.
The servers are available but 60% of required staff cannot work.
Which continuity dependency failed?
People / workforce.
The building is safe but authorities prohibit entry for two weeks.
Which continuity problem?
Loss of premises / access.
The application works but a critical external logistics provider has failed.
Which concept?
External dependency / supplier continuity.
A company outsources payment processing.
Has it outsourced the business impact if payments stop?
No.
Two alternate suppliers both depend on the same manufacturer.
Primary concern?
Common dependency / concentration risk.
Employees relocate to another office after the normal location becomes inaccessible.
Which strategy?
Alternate workplace.
Employees continue activities from home.
Which strategy?
Remote-working continuity.
An automated approval system fails and a documented dual-person manual process is used.
Which strategy?
Manual workaround.
A manual process removes normal security controls.
Best approach?
Use appropriate compensating controls during continuity operation.
Continuity staff email sensitive customer information to personal accounts.
Primary concern?
Continuity activity is creating unacceptable security risk.
The BC plan is stored only on a failed corporate file server.
Primary problem?
The continuity plan itself is unavailable.
The plan contains personal contact details and sensitive recovery information.
What is required?
Appropriate protection while maintaining availability.
The organisation uses corporate email as its only emergency communication method.
Primary weakness?
Single communication dependency.
A facilitator asks teams how they would operate if headquarters were unavailable.
Which activity?
Business Continuity tabletop exercise.
The exercise discovers that an alternate supplier contract expired.
Is this useful?
Yes. The exercise identified a continuity gap.
The organisation successfully recovers IT but staff do not know where to work.
Which plan was insufficient?
Business Continuity arrangements.
The business continues manually while DR restores the failed application.
Can BC and DR operate together?
Yes.
Ransomware forces security to disconnect corporate systems.
What can BC provide?
Alternative ways to continue essential activities during technical recovery.
A BC exercise uses no defined objective.
Primary weakness?
Results will be difficult to evaluate meaningfully.
An exercise finds several gaps but no corrective actions are assigned.
Primary concern?
The exercise may not result in improved continuity.
A continuity gap is corrected.
What should follow where appropriate?
Retesting / re-exercising the corrected capability.
The business changes supplier after the last BC exercise.
What should be considered?
Reviewing affected continuity plans and exercises.
The continuity plan lists an alternate office that has since been sold.
Primary problem?
Plan maintenance failure.
A disruption lasts much longer than anticipated.
What should the continuity strategy consider?
Whether temporary arrangements remain sustainable over time.
A manual process handles only 20% of normal transaction volume.
What should determine whether this is acceptable?
Business continuity requirements and required minimum capability.
A continuity exercise tests people, premises and suppliers but no servers fail.
Is this a valid BC exercise?
Yes. BC is broader than IT recovery.
After normal systems return, manual transactions are never reconciled.
Primary risk?
Incomplete, duplicated or inconsistent business records.
Business Continuity procedures bypass segregation of duties indefinitely.
Primary concern?
Temporary continuity exceptions have become permanent control weaknesses.
Two different offices depend on the same electrical substation.
What should BC planners recognise?
A shared failure dependency.
A disruption to transport prevents key staff reaching the office while systems remain operational.
Which continuity dependency?
Transport / workforce accessibility.
Why should BC exercises sometimes introduce additional unexpected problems?
Best answer?
To test decision-making and resilience when assumptions fail.
The company has a backup supplier but has never contacted it during an exercise.
What remains?
An unvalidated continuity assumption.
What is the primary distinction between 7.12 and 7.13?
Answer?
7.12 tests DR plans; 7.13 participates in broader Business Continuity planning and exercises.
Management asks for the central purpose of Business Continuity.
Best answer?
Maintain the organisation's critical products, services and business activities at an acceptable level during disruption and support an orderly return to normal operations.
Recognise the Clue Words
Keep Business Operating
Broad resilience.
Business ContinuityRestore IT
Technology recovery.
Disaster RecoveryImpact of Disruption
Business analysis.
BIAWhat Must Continue?
Prioritisation.
Critical Business ActivityMaximum Disruption
Business limit.
MTDRecovery Target
Technology / service.
RTOAcceptable Data Loss
Recovery point.
RPOSupplier Stops
External dependency.
Supply Chain ContinuityAlternative Provider
Continuity option.
Supplier DiversificationOffice Unavailable
Premises.
Alternate WorkplaceStaff Work From Home
Workforce strategy.
Remote ContinuitySystem Offline ยท Process Continues
Alternative method.
Manual WorkaroundReduced Service
Essential capability.
Continuity ModeSame Provider Behind Two Suppliers
Hidden dependency.
Concentration RiskDiscuss Continuity Scenario
Exercise.
TabletopPlan No Longer Matches Business
Lifecycle.
Plan MaintenanceExercise Finds Weakness
Good outcome.
Corrective ActionNormal Systems Return
Exit continuity.
Reconciliation / NormalisationBC Plan Stored on Failed System
Plan availability.
Alternate CopyCritical Specialist Missing
People.
Cross-Training / Alternate Personnelโ ๏ธ Common CISSP Mistakes Business Continuity is broader than IT recovery
BC maintains business capability. DR restores technology.
People, premises, suppliers and processes matter too.
A critical supplier or workforce dependency may still have failed.
Continuity planning requires meaningful prioritisation.
BIA focuses on business impact from disruption and the requirements for continuity.
MTD is business tolerance. RTO is a recovery target.
RTO concerns time. RPO concerns recoverable data.
Essential capability may continue at a predefined reduced level.
Supplier failure can still create business impact.
They may share the same upstream dependency.
Connectivity, devices, identity and security must support it.
Manual workarounds still require appropriate security and authorisation.
Continuity procedures should eventually return to normal controls.
Reconciliation may be required when normal systems return.
Exercise it.
It must remain accessible during disruption.
Sensitive continuity information still requires protection.
Discovering weaknesses is a major purpose of exercising.
Assign actions and owners.
Retest where appropriate.
Organisations, technologies and suppliers change.
7.12 tests DR plans. 7.13 covers broader Business Continuity planning and exercises.
Quick Reference
| If you see... | Think... |
|---|---|
| Keep critical activity operating | Business Continuity |
| Restore technology after disaster | Disaster Recovery |
| Impact of business disruption | BIA |
| Maximum tolerated disruption | MTD |
| Target recovery time | RTO |
| Target recovery point | RPO |
| Process relies on external company | External Dependency |
| Two suppliers use same upstream provider | Concentration / Common Dependency |
| Normal office unavailable | Alternate Workplace / Remote Work |
| Application unavailable but activity continues | Manual Workaround |
| Operate only most important services | Prioritised Continuity |
| Discuss disruption scenario | BC Tabletop |
| Plan does not match current organisation | Plan Maintenance |
| Exercise identifies weakness | Corrective Action |
| Manual records entered after recovery | Reconciliation |
| Only specialist unavailable | Cross-Training / Alternate Personnel |
| Corporate communications fail | Alternate Communications |
| Supplier recovery slower than business requirement | Continuity Gap |
BC Core Memory Aid
Continuity Resource Memory Aid
Critical Distinctions
7.13 Master Memory Aid
Identify โ Analyse โ Prioritise โ Continue โ Exercise โ Improve
The Business Continuity Leader's Questions
Key Takeaways
CISSP 7.13 is: Participate in Business Continuity planning and exercises.
The current CISSP outline does not provide separate sub-bullets under objective 7.13.
Business Continuity focuses on maintaining important business activities during disruption.
Disaster Recovery focuses more specifically on recovering disrupted technology.
BC = keep the business operating. DR = restore the technology.
Disaster Recovery can therefore form part of a broader Business Continuity strategy.
Business Continuity also covers disruptions involving people, premises, suppliers, information, utilities and business processes.
A technology failure is not required before Business Continuity becomes relevant.
A pandemic, building closure, transport failure or supplier collapse can create major continuity problems while every server remains operational.
The BIA is a fundamental input to continuity planning.
It identifies important business activities and analyses how disruption affects the organisation.
Impact may include financial, operational, legal, regulatory, safety, customer and reputational consequences.
Impact usually changes as disruption continues.
Something that is tolerable for ten minutes may be unacceptable after ten hours.
Business Continuity therefore requires meaningful prioritisation.
If everything is critical, nothing has genuinely been prioritised.
MTD represents how long a business process can be disrupted before significant harm occurs.
RTO establishes the target for restoring the required capability.
RPO establishes the target for recoverable information.
MTD = business tolerance. RTO = recovery time target. RPO = recovery-data target.
Recovery capability must support the business tolerance identified by the BIA.
Continuity does not necessarily require 100% normal service.
During disruption, the organisation may deliberately provide only essential products or services at an acceptable reduced level.
Critical business processes depend on resources.
Important dependency categories include people, premises, technology, information, utilities, suppliers, facilities and transport.
Continuity planning should identify these dependencies before disruption occurs.
External dependencies are particularly important.
Outsourcing a business activity or technology service does not remove the impact if that service fails.
Outsourced service โ outsourced business risk.
Supplier concentration should also be considered.
Two suppliers may appear independent while relying on the same cloud platform, manufacturer, data centre or telecommunications provider.
Continuity strategies provide alternative ways to maintain the business activity.
They can include alternate locations, remote work, alternate suppliers, manual procedures, workforce redeployment, reduced service and technology recovery.
Manual workarounds can be useful when normal technology is unavailable.
However:
manual โ uncontrolled.
Appropriate authorisation, segregation of duties, records and reconciliation may still be required.
Manual processes may also have limited capacity and may become unsustainable during long disruptions.
Remote working can provide continuity when premises are unavailable.
It requires more than simply telling employees to work from home.
Devices, connectivity, identity, authentication, communications, capacity, support and security must all be considered.
Workforce continuity also requires cross-training and alternate personnel.
A critical process should not depend unnecessarily on one individual.
Premises continuity considers loss of access as well as physical destruction.
Authorities may make a perfectly intact building unavailable for days or weeks.
Information needed for continuity must also remain accessible.
Emergency contacts and continuity procedures stored only inside failed infrastructure may be unavailable when needed.
Continuity plans themselves can contain sensitive operational information.
They therefore need both: availability and appropriate protection.
Business Continuity communications should cover employees, management, suppliers, customers and other appropriate stakeholders.
Alternate communication mechanisms may be required when normal channels depend on affected infrastructure.
Continuity plans should identify activation criteria, authority, roles, priorities, procedures and communication arrangements.
Plans should also address how the organisation eventually returns to normal operations.
Manual or temporary transactions may need to be reconciled when normal systems return.
Temporary continuity exceptions should also be removed appropriately.
Business Continuity plans must be exercised.
Exercises can examine decisions, people, facilities, processes, suppliers and technology.
BC exercises can include discussion-based scenarios, walkthroughs, simulations and operational exercises depending on the organisation's objectives and risk.
These should not be confused with additional official ISC2 7.13 sub-bullets.
Objective 7.12 focuses specifically on testing Disaster Recovery plans.
Objective 7.13 is broader.
7.12 asks: can technology recover? 7.13 asks: can the business continue?
Exercises should have a defined objective.
Useful scenarios can test loss of premises, workforce, suppliers, communications or technology.
Exercise scenarios can also introduce unexpected complications to test decision-making.
For example, the primary decision-maker may be unavailable or an alternate supplier may also experience disruption.
Business Continuity exercises should evaluate people as well as procedures.
Teams should know what to do, where to operate and how to communicate.
Continuity mode does not create a security-free environment.
Temporary processes should preserve an acceptable security posture even when the normal control mechanism cannot operate.
Exercises should produce findings and corrective actions.
A continuity exercise that discovers a serious weakness has produced valuable information.
Finding a problem during an exercise is better than discovering it during the disruption.
Findings should be analysed, assigned to owners and corrected.
Important corrections should subsequently be exercised again.
Business Continuity plans must also be maintained as organisations change.
New technology, offices, suppliers, organisational structures and regulatory requirements can invalidate old continuity arrangements.
Planning around loss of capability can sometimes be more reusable than planning only around specific named disasters.
For example: loss of premises can occur because of fire, flooding, structural damage, security incidents or an external cordon.
Continuity planning should also recognise cascading disruption.
A regional event may simultaneously affect power, telecommunications, transport, suppliers and workforce availability.
The central CISSP principle is:
identify the business activities that must continue, understand the impact of their disruption and their critical dependencies, establish practical alternative ways to maintain those activities, document who will do what, exercise the arrangements and continuously improve them so that the organisation can continue delivering what matters when normal operations are unavailable.
๐ Sources & Further Reading Business Continuity, BIA and exercise references
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - ISO 22301:2019 - Security and resilience - Business continuity management systems - Requirements
View ISO 22301 - ISO/TS 22317:2021 - Business Continuity Management Systems - Guidelines for Business Impact Analysis
View ISO/TS 22317 - ISO/TS 22318:2021 - Guidelines for Supply Chain Continuity Management
View ISO/TS 22318 - ISO 22398:2013 - Guidelines for Exercises
View ISO 22398 - NIST SP 800-34 Rev. 1 - Contingency Planning Guide for Federal Information Systems
View NIST contingency-planning guidance - NIST IR 8286D - Using Business Impact Analysis to Inform Risk Prioritization and Response
View current NIST BIA guidance - NIST SP 800-84 - Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities
View NIST exercise guidance
