What ISO 22301 is and how it applies to OT operational continuity
ISO 22301 is the international standard for business continuity management systems (BCMS): it provides a structured framework to prepare for, respond to and recover from a disruptive event after its occurrence, regardless of cause - cyber, physical, natural.
The core of the standard is the Business Impact Analysis (BIA): it identifies the organisation's critical processes, the dependencies between systems and people, and defines the acceptable Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for each process.
In industrial environments, a cyber incident on an OT system - a compromised PLC, an unavailable SCADA - can physically halt production: ISO 22301 requires these scenarios to be modelled in the BIA with the same rigour as a fire or an electrical failure.
Unlike ISO 27001, which focuses on protecting information, ISO 22301 focuses on the ability to keep operating during and after an incident: the two standards are complementary and often implemented together, with ISO 27001 reducing the likelihood of an incident and ISO 22301 limiting its impact when one occurs anyway.
ISO 22301
ISO 22301:2019 - Business Continuity Management Systems
Certifiable standard for Business Continuity Management. Often required alongside ISO 27001 and explicitly cited by NIS2 (art. 21) and DORA for the operational continuity part. Relevant for any organisation whose service interruption would cause material impact.
- 01Business Impact Analysis (BIA) on critical processes
- 02Definition of RTO and RPO for each service
- 03Documented continuity strategies and plans
- 04Periodic exercises and testing of plans
- 05Monitoring of technological dependencies
OT continuity depends on the health of the industrial network. MON5 continuously monitors communications between critical assets, detects degradations before they become plant outages, and provides the BIA with an objective picture of real technological dependencies - not just declared ones.
- →Dependency map between critical OT assets
- →Early detection of degradations and anomalies
- →BIA evidence based on real traffic
- →Reusable history for RCA after events
- →Support for monitoring technological SLAs
- BCMS (Business Continuity Management System)
- The business continuity management system required by ISO 22301: policies, processes and plans to ensure the organisation's ability to keep operating during a disruption.
- BIA (Business Impact Analysis)
- Analysis that identifies critical processes, the resources needed to support them, and the impact (financial, operational, reputational) of their disruption over time.
- RTO (Recovery Time Objective)
- The maximum acceptable time within which a process or system must be restored after a disruption, before the impact becomes unacceptable for the organisation.
- RPO (Recovery Point Objective)
- The maximum acceptable amount of data or process state the organisation can afford to lose, measured as a time interval relative to the disruption.
- BCP (Business Continuity Plan)
- The operational plan describing the concrete actions to take during a disruption to maintain or restore critical processes within the defined RTO/RPO objectives.
- Testing and exercise programme
- The programme required by ISO 22301 to periodically verify, through simulations and exercises, that continuity plans actually work and not just on paper.
Is ISO 22301 about cybersecurity or business continuity?+
ISO 22301 covers Business Continuity Management (BCM). For OT environments, it ensures that critical production processes have tested recovery plans in the event of a cyber, physical or natural incident.
How does ISO 22301 integrate with OT cybersecurity?+
A cyber incident on OT can halt production. ISO 22301 requires a BIA and BCP that identify critical OT systems and acceptable recovery times (RTO/RPO) for each process.
Does MON5 support ISO 22301 compliance for industrial plants?+
Yes. MON5 provides inventory of critical OT assets, maps system dependencies, detects degradation before downtime and logs incidents — the core inputs needed to define and test BIA and BCP.
Does ISO 22301 require a separate certification from ISO 27001?+
Yes, they are distinct certifications with different scopes (business continuity vs. information security), although many organisations implement them in parallel given the strong complementarity between the two standards.
How does ISO 22301's BIA integrate with OT environments?+
It requires mapping which OT systems support which critical production processes, with what dependencies, and what economic and physical-safety impact in case of unavailability - not just traditional IT systems.
What happens if RTO and RPO aren't realistic relative to actual technical capabilities?+
The continuity plan fails exactly when it is needed: this is why objective data on real recovery times and actual system dependencies is needed, not estimates based on outdated documentation.
How often must continuity plans be tested under ISO 22301?+
The standard requires periodic testing (typically annual or more frequent for the most critical processes), with exercises ranging from documentary walkthroughs to full operational simulations.
How does MON5 support Business Impact Analysis for OT environments?+
MON5 provides an inventory of critical OT assets, maps real dependencies between systems by observing network traffic, and detects signs of degradation before a plant shutdown: objective data that feeds the BIA and RTO/RPO instead of assumption-based estimates.
Let's figure out what you really need.
Show us the OT perimeter and the regulations you need to cover: we will tell you what MON5 documents directly, where complementary work is needed, and which tier to start from - no hard selling.