ISO 27001 vs ISO 22301 comes up whenever a customer questionnaire asks about
resilience and somebody points out that ISO 27001 already covers continuity. It partly does —
and the gap between “partly” and “enough” is what this comparison is about.
ISO 27001 vs ISO 22301: what each standard is for
ISO/IEC 27001:2022 specifies an information security management system. Its
subject is the confidentiality, integrity and availability of information, and its central mechanism
is risk assessment against those three properties, with controls selected from Annex A and declared
in a Statement of Applicability.
ISO 22301:2019 specifies a business continuity management system. Its subject is
the continued delivery of products and services during disruption, and its central mechanism is the
business impact analysis: how long each prioritized activity can be down before the consequences
become unacceptable.
Different questions. In ISO 27001 vs ISO 22301 terms, ISO 27001 asks what could compromise your information. ISO 22301 asks how
long you can survive without your operations, whatever caused the outage.
Where ISO 27001 vs ISO 22301 overlap
ISO 27001 vs ISO 22301 overlap structurally a great deal. Both follow the harmonized structure, so clauses 4, 5, 6, 7, 9 and 10
are near-identical in shape: context, leadership, planning, support, performance evaluation and
improvement. If you hold one, that machinery transfers almost entirely to the other — the same
document control, internal audit, management review and corrective action processes serve both.
Substantively, ISO 27001’s Annex A does contain continuity controls. That is exactly where the
confusion starts.
ISO 27001 vs ISO 22301: why the Annex A continuity controls are not enough
The Annex A continuity controls address continuity of information security —
making sure security is maintained during disruption, and that information processing has adequate
redundancy. That is a subset, and a deliberately narrow one.
What they do not require is the machinery ISO 22301 is built on: a business impact analysis
producing recovery time and recovery point objectives per activity, continuity strategies costed and
resourced to meet those objectives, plans with activation criteria and a response structure, and an
exercise programme that tests whether any of it works. An organisation can hold ISO
27001 and have no idea how long it could operate without its primary site.
Both systems, both document sets.
The ISO 27001 Toolkit covers the ISMS end to end including the Statement of Applicability; the ISO 22301 Toolkit covers the BCMS with the BIA workbook, continuity strategies, plans and the exercise programme.
ISO 27001 vs ISO 22301: which one do you actually need?
ISO 27001 if the question is security. It is the standard customers, tenders and
security questionnaires ask for, by a wide margin. If you are answering one questionnaire this
quarter, it is almost certainly asking for ISO 27001 or SOC 2, not ISO 22301.
ISO 22301 if downtime is the risk that would actually hurt you — or if you
are in a sector where regulators ask about operational resilience. Financial services, healthcare,
utilities and critical suppliers increasingly get asked directly, and “we have ISO 27001” is not a
sufficient answer to a continuity question.
Both, sequenced, is the common path for organisations that need to demonstrate
resilience to enterprise customers. Do ISO 27001 first if you have no certification: it is more widely
recognised, and the management system it establishes makes ISO 22301 substantially cheaper to add.
What adding the second standard actually costs
Less than the first, materially. The shared clauses are already evidenced, the auditors can run a
combined audit, and your document control and audit machinery is reused. The genuinely new work for
ISO 22301 is clause 8: the BIA, the strategies, the plans and the exercise programme. For ISO 27001
coming second, it is the risk assessment, the Statement of Applicability and the Annex A controls.
See our guides to ISO 27001 implementation,
ISO 22301 implementation and the
business impact analysis.
References
- ISO/IEC 27001:2022 — the ISMS standard on iso.org.
- ISO 22301:2019 — the BCMS standard on iso.org.