01 · 1990s–2006
Continuity professionalisation
Financial, infrastructure and technology disruptions drove formal business-impact analysis and continuity standards, including BS 25999.
ASSURANCE DNA · BUSINESS CONTINUITY
A business-continuity management system that identifies priority activities, interruption tolerances, response capability and exercised recovery.
What must continue, at what minimum level, for how long, and through whose exercised capability?
It is wider than disaster recovery and more demanding than a generic plan. Contract-specific recovery still depends on real capacity, dependencies and exercises. Source-bounded interpretation: no certification, protected text reproduction or award prediction.
LIVING EXPERIMENT · DISRUPTION
A service pathway is interrupted at selectable points. Recovery claims only reconnect the route when time objectives, dependencies, owners and exercised evidence agree.
ORIGIN × EVOLUTION × CURRENT PRACTICE
Critical infrastructure, technology, outsourcing, health, finance, logistics and public-service providers where disruption affects essential outcomes.
01 · 1990s–2006
Financial, infrastructure and technology disruptions drove formal business-impact analysis and continuity standards, including BS 25999.
02 · 2012
ISO created international certifiable requirements for societal security and business continuity.
03 · 2019
The current edition clarified structure and requirements for planning, operation, evaluation and improvement.
04 · 2024–2026
A climate amendment was published in 2024; ISO records a successor project in development.
A generic continuity plan does not validate a contract-specific recovery promise. Capacity, dependencies and exercise results must match the proposed service.
OFFICIAL SOURCE FRESHNESS MONITOR
Monthly official-source reachability and change review.
The check records source reachability and a content fingerprint. It does not silently change the page or claim that an edition changed.
PUBLICLY DESCRIBABLE ANATOMY
These are navigational interpretations, not substitute clauses. Use the official publication for normative wording.
Define continuity scope around the products, services, locations, technology and partners that sustain the promised buyer outcome.
Name continuity leadership, policy, authority and resources before recovery promises are written.
Use impact analysis to define tolerances, minimum service, dependencies and recovery priorities.
Design people, site, technology, supplier and data solutions that can meet the tolerances.
Create usable plans, communications, role cards and buyer interfaces.
Exercise credible scenarios, record findings and review capability at management level.
Correct capability gaps and update solution, contract assumptions and training.
BEFORE × INTERVENTION × AFTER
A fictional service has a two-hour maximum tolerable interruption and relies on telephony, CRM, identity, two sites and three critical suppliers.
Scenario evidence demonstrates design visibility, not future uptime.
The response promises a 30-minute recovery because a cloud brochure says so; people, telephony routing and concurrent contract demand are absent.
The team builds a contract BIA, maps end-to-end dependencies, proves alternate capacity and exercises a combined site-plus-identity failure.
The promise separates detection, invocation, minimum service and full recovery, with buyer communications and residual constraints made explicit.
PROPORTIONATE IMPLEMENTATION
It is wider than disaster recovery and more demanding than a generic plan. Contract-specific recovery still depends on real capacity, dependencies and exercises.
Impact sheet, substitute plan, exercise notes
BIA, capacity test, supplier assurance
Portfolio BIA, exercise programme, action closure
SOURCE TRAIL · REVIEWED 21 AUG 2026
Publication status can change. Exact conformity questions belong with the current licensed publication and competent assurance.