BCM under ISO 22301: BIA, strategy, exercise
Turning a continuity document into a management system: impact analysis, disruption risk, costed strategies, exercised plans and evaluation evidence.
Risk5 Sept 202622 min read
Toolkit
Three shelves. Playbooks set out a method end to end. Templates carry it as a file you can open on Monday. The Lab ships it as software.
01 — Playbooks
Each one covers a responsibility end to end, with the failure mode it prevents, the steps, the deliverables and what the auditor will ask.
Turning a continuity document into a management system: impact analysis, disruption risk, costed strategies, exercised plans and evaluation evidence.
Risk5 Sept 202622 min read
A method for designing the business information security officer role: mandate, decision rights, placement, operating rhythm, interfaces, measures and pitfalls.
Governance5 Sept 202622 min read
A method for putting security in front of a board and getting a decision: five to seven risks, measured controls, and an outcome that is written down.
Governance5 Sept 202621 min read
A method for building one list of the controls that actually run, each with an owner, an evidence record and a test result, mapped to the frameworks they serve.
Governance5 Sept 202622 min read
A method for proving controls operated over a period: the ITGC map, complete populations, risk-based samples, workpapers a second person can re-perform.
Compliance5 Sept 202622 min read
Which Article 32 procedure applies to each product, who signs the declaration, and what the chosen route must produce before 11 December 2027.
Governance5 Sept 202622 min read
02 — Templates
The artefacts the playbooks produce, as downloadable files under an open licence.
A three-sheet register: every AI system with its two roles and its owner, one impact assessment per system, and the Annex A statement of applicability.
Compliance5 Sept 20263 min read
A twenty-two column form that runs the AI Act decision test over one AI use case per row and closes each row with proceed, conditions or stop.
Compliance5 Sept 20263 min read
A sixteen-column register of the controls that actually run: owner, evidence producer, approver, reference controls served, evidence record and last test.
Governance5 Sept 20263 min read
A twenty-one-column record of one control test: the population, its completeness check, the sample, the procedure, the evidence and a conclusion two roles sign.
Compliance5 Sept 20263 min read
Four sheets that map the Annex VII file: one row per element per product, the declaration's Annex V items, and a retention schedule with derived end dates.
Compliance5 Sept 20263 min read
A sixteen-column register that carries every external audit finding from the auditor's wording to a verification date, with correction and cause kept apart.
Compliance5 Sept 20263 min read
03 — Lab
Working products, not slideware — the same methods published here, shipped as software.
An offline reference handbook for information security managers.
An offline reference for information security managers. The whole knowledge base ships with the app: 478 topic cards across five parts, wired together by typed cross-links and a glossary built from the topics themselves.
A working BISO operating system, running privately. Early access on request.
A single-operator workspace that runs the business information security officer function end to end. Charter and service catalogue, risk register and control library, strategy, assurance, incidents and continuity. A governed AI agent proposes changes; a person reviews them before anything is applied.