Introducing ISO 22317 – The Business Impact Analysis Standard
Written by Jacque Rupert   


WHAT IS ISO 22317?

The International Organization for Standardization (ISO) Technical Committee (TC) 292, the committee responsible for writing security, resilience, and business continuity standards, is close to releasing its latest document: ISO 22317 – Societal Security – Business Continuity Management Systems – Business Impact Analysis, the first and only international standard solely addressing the business impact analysis (BIA).

ISO 22317 reached stage 60.00 (International Standard under publication) on July 13, 2015 and is expected to be published shortly.

There are a few important points to understand before reading ISO 22317:

  • Over the past two years, participants from over a dozen countries contributed to the development of the ISO 22317 standard.
  • ISO 22317 is a Technical Specification, which means that it provides detailed technical content on how to implement a BIA process, but it is not auditable.  Said another way, organizations cannot certify their BIA to ISO 22317.  However, organizations can use ISO 22317 as guidance on how to effectively implement or mature a BIA process.
  • ISO 22317 complements (and does not contradict) ISO 22301 and ISO 22313 by building on the high-level content within these existing standards.  However, ISO 22317 can be used as a standalone document by organizations that do not use ISO 22301 or ISO 22313 content but seek guidance on how to perform the BIA process.


ISO 22317 defines a flexible BIA process that can be used by organizations, large or small, in any industry.

“The BIA process analyzes the consequences of a disruptive incident on the organization. The outcome is a statement of justification of business continuity requirements.

Note: business continuity requirements has the same meaning as continuity and recovery priorities, objectives, and targets.”

Specifically, ISO 22317:

  • Provides a new, enhanced BIA definition that is more clear with less jargon
  • Offers a BIA value proposition for organizations struggling to gain buy-in
  • Identifies the prerequisites that the organization should have in place before starting the BIA
  • Outlines a detailed process for how to effectively perform the BIA
  • Proposes the outcomes of the BIA (including outcomes of each step of the BIA)
  • Provides options for different information collecting methods, along with a pros and cons analysis of each method
  • Describes other uses for which organizations may choose to use the BIA

Altogether, ISO 22317 will help organizations effectively perform one of the most challenging elements of the business continuity life-cycle (the BIA) in a way that produces accurate and useful business continuity requirements, leading to focused, pragmatic strategy identification and plan development.


About the Author

Jacque Rupert is a Managing Consultant for Avalution Consulting, a leading provider of business continuity and IT disaster recovery consulting and software solutions. Jacque is also a member of the U.S. technical advisory group for the ISO technical committee 292 (formally 223) and served as the secretariat for the BIA standard (ISO 22317) committee.  Jacque is a frequent author and speaker, and can be reached via email at