BCM under ISO 22301: BIA, strategy, exercise
Turning a continuity document into a management system: impact analysis, disruption risk, costed strategies, exercised plans and evaluation evidence.
Risk5 Sept 202622 min read
Playbooks
Each playbook takes one job, such as an ISMS, a risk register or a supplier review, and sets out the steps, the inputs, the owners, and the evidence each step leaves behind.
25 of 25
Turning a continuity document into a management system: impact analysis, disruption risk, costed strategies, exercised plans and evaluation evidence.
Risk5 Sept 202622 min read
A method for designing the business information security officer role: mandate, decision rights, placement, operating rhythm, interfaces, measures and pitfalls.
Governance5 Sept 202622 min read
A method for putting security in front of a board and getting a decision: five to seven risks, measured controls, and an outcome that is written down.
Governance5 Sept 202621 min read
A method for building one list of the controls that actually run, each with an owner, an evidence record and a test result, mapped to the frameworks they serve.
Governance5 Sept 202622 min read
A method for proving controls operated over a period: the ITGC map, complete populations, risk-based samples, workpapers a second person can re-perform.
Compliance5 Sept 202622 min read
Which Article 32 procedure applies to each product, who signs the declaration, and what the chosen route must produce before 11 December 2027.
Governance5 Sept 202622 min read
Assembling the Annex VII file, keeping it current for the retention period, and getting a declaration signed by a role that has read it.
Compliance5 Sept 202622 min read
Annex I Part II run as a process: the bill of materials, component due diligence, intake, triage, the security update, disclosure and the Article 14 record.
Risk5 Sept 202622 min read
A method for turning DORA into a running programme: scope, framework, incidents, testing, third-party risk, and the register of information built last.
Compliance5 Sept 202622 min read
A ninety-day method: inventory the mandate, the obligations and the risk picture, decide appetite and operating model, then take one decision to the board.
Governance5 Sept 202622 min read
A method for governing incidents end to end: declaration, decision records, the reporting clock across four regimes, and corrective action verified closed.
Governance5 Sept 202622 min read
Adding ISO/IEC 42001 to an existing ISMS as one system: scope and roles, the AI policy, AI risk, the impact assessment, Annex A and the certification route.
Compliance5 Sept 202622 min read
A method for turning a pile of documents into a tiered policy set with owners, review dates and exceptions, so a reader can find the rule that applies.
Governance5 Sept 202622 min read
Running the cyber security management system UN R155 requires as an operating system rather than a document set, on the clause pattern an ISMS already follows.
Governance5 Sept 202622 min read
A method for turning "we accept that risk" into a dated record: a named approver, a residual level tested against criteria, compensating controls and an expiry.
Risk5 Sept 202622 min read
Appetite written as decisions rather than adjectives, scales with sentence anchors, and acceptance thresholds a register applies and a board approves.
Risk5 Sept 202622 min read
A method for hosting the certification body: evidence architecture, the opening meeting, nonconformity handling, and findings tracked to verified closure.
Compliance5 Sept 202622 min read
Fifteen to forty scenarios a committee can decide on: risk sources with a desired end state, consequences over time, likelihood with a stated basis, and owners.
Risk5 Sept 202622 min read
A method for running an awareness programme against measured behaviour instead of completion rates, with the training records falling out as a by-product.
Governance5 Sept 202622 min read
A method for writing down how security decisions are made: the functions, the decision rights, the three lines, the interfaces and the operating calendar.
Governance5 Sept 202622 min read
A method for turning business objectives, obligations and the risk picture into five to seven measured security objectives that fit on one approved page.
Governance5 Sept 202622 min read
A lifecycle method for supplier assurance: tier first, assess by tier, contract for the rights you will need, keep assurance running, and exit on plan.
Risk5 Sept 202622 min read
A repeatable method for turning a legal instrument into control objectives, controls, evidence and owners, worked end to end on NIS2 and on the CRA.
Compliance4 Sept 202622 min read
A method for standing up an ISO/IEC 27001 management system that produces evidence in daily operation instead of a binder assembled before the audit.
Governance3 Sept 202622 min read
Risk statements that name a source, an event and a consequence; scales that survive argument; and every row closed by a named approver on a dated decision.
Risk3 Sept 202622 min read