TechTarget.com/searchdisasterrecovery

https://www.techtarget.com/searchdisasterrecovery/tip/Use-ISO-223202018-to-prepare-an-incident-management-plan

Use ISO 22320:2018 to prepare an incident management plan

By Paul Kirvan

Before an organization initiates business continuity and disaster recovery activities, incident management is critical.

Incident management starts when an organization identifies the severity of a threat and assesses the potential ramifications of it. This determines next steps for BCDR and establishes recovery priorities.

ISO released ISO 22320:2011 Security and resilience -- Emergency management -- Guidelines for incident management to advise emergency professionals on the key issues to address when a disruptive event occurs.

ISO updated the standard in 2018 to provide additional guidance. The standard is part of the ISO 223XX series of standards for BC and related societal security disciplines.

Getting started with ISO 22320:2018

The guidance in ISO 22320:2018 can add value to incident management plan development, testing and maintenance. The standard places emphasis on collaboration, communication throughout the process and plenty of preparation.

The first key section after the introduction discusses principles of incident management, including risk management, ethics and safety:

Incident management processes and structure

Section five of the standard gets into the many different aspects of incident management. Along with a general introduction to incident management, sections 5.2 and 5.3 explain the incident management process and structure, respectively.

In section 5.2, the standard lists the processes -- both throughout the year and during an event -- that organizations must address when they develop an incident management program and plan. Along with general safety, important activities include the following:

Section 5.3 specifies that all incident management activities should adhere to the following structure:

Many of the elements described in ISO 22320:2018 are also part of the Incident Command System. Part of the National Incident Management System, the Incident Command System is a widely used framework developed by the Federal Emergency Management Agency to manage all aspects of a disaster.

Additional guidance to note

ISO 22320:2018 also includes four annexes that provide additional details on incident management planning that organizations can use to formulate plans and programs:

  1. Annex A: Additional guidance on working together. This provides guidance on collaboration, communications and establishment of communication protocols during an incident.
  2. Annex B: Additional guidance on incident management structure. This provides additional content on structure and content that can be used for building a plan and program.
  3. Annex C: Examples of incident management tasks. These can be built into plans and can serve as checklists when engaged in an incident management activity.
  4. Annex D: Incident management planning. This provides guidance on building, exercising and maintaining an incident management activity.

DR teams and emergency professionals can access the full standard on the ISO website.

23 Sep 2022

All Rights Reserved, Copyright 2008 - 2026, TechTarget | Read our Privacy Statement