A tailored course, built for your situation
Direct control over BCMS deployment and audit timing under ISO 22301
Own the business continuity roadmap end to end with confidence in ISO 22301 implementation
Who this is for
Network Security Administrator at a global cloud services provider, responsible for compliance-aligned infrastructure continuity and control execution
Who this is not for
Individuals looking for general awareness of ISO standards or those without direct responsibility for control implementation and audit readiness
What you walk away with
- Define and lock BCMS deployment timelines without escalation
- Select and finalize auditor engagement thresholds independently
- Approve continuity test scope and reporting format without review
- Control documentation structure and update cycles for ISO 22301 artifacts
- Own vendor continuity validation timing and evidence requirements
The 12 modules (with all 144 chapters)
- Cl 4 Context of the organization
- Cl 4 1 Understanding organisation
- Cl 4 2 Understanding needs
- Cl 4 3 Determining scope
- Cl 4 4 BCMS scope definition
- Cl 4 4 Documentation requirements
- Mapping clause to network layers
- Integrating with existing SOC 2 controls
- Identifying cloud-specific risks
- Linking to incident response
- Common gaps in hosting providers
- Rackspace-relevant examples
- Cl 5 Leadership overview
- Cl 5 1 Leadership and commitment
- Assigning roles internally
- Policy ownership models
- Internal communication plan
- Securing buy-in laterally
- Documenting leadership input
- Policy version control
- Exception handling protocol
- Updating policy post-incident
- Version approval workflow
- No executive sign-off needed
- Cl 6 1 Actions to address risks
- Risk criteria selection
- Threat modeling for cloud
- Impact scale definition
- Likelihood calibration
- Choosing risk treatment options
- Avoiding third-party tools
- Documenting risk decisions
- Internal validation method
- Updating assessments quarterly
- Linking to change control
- Evidence preservation
- Cl 6 2 Business impact analysis
- Identifying critical functions
- Defining time thresholds
- Data dependency mapping
- Interviewing peers effectively
- Scoping without overreach
- Merging technical and business views
- Documenting findings
- Setting recovery objectives
- Presenting to stakeholders
- Updating post-incident
- Version control for BIA
- Cl 6 3 Business continuity strategy
- Recovery time objectives
- Resource identification
- Alternate site planning
- Technology replication
- Personnel availability plans
- Vendor continuity obligations
- Cloud failover design
- Testing frequency decisions
- Approving strategy changes
- Documenting rationale
- No management approval needed
- Cl 7 1 BCMS framework
- Cl 7 2 Document control
- Cl 7 3 Documented information
- Response team roles
- Activation thresholds
- Communication tree design
- Internal notification flow
- External reporting triggers
- Chain of command rules
- Updating team rosters
- Cross-shift coordination
- Documentation retention
- Document control framework
- Naming convention system
- Storage location decision
- Access permissions model
- Version numbering scheme
- Change tracking method
- Review cycle setting
- Retention periods
- Archiving process
- Updates without approval
- Rollback procedures
- Audit-readiness checklist
- Cl 8 1 Operational planning
- Cl 8 2 Exercising overview
- Test type selection
- Scope definition authority
- Scheduling windows
- Stakeholder notification
- Test plan documentation
- Simulated scenarios
- Post-test review
- Finding resolution
- Reporting format
- Publishing results
- Cl 8 3 Incident response
- Activation authority
- Initial assessment steps
- Declaring continuity mode
- Internal comms protocol
- External vendor triggers
- Resource mobilization
- Status reporting rhythm
- Recovery tracking
- Post-event review timing
- Lessons learned capture
- Updating plans
- Cl 10 1 Nonconformity handling
- Cl 10 2 Corrective action
- Root cause methodology
- Action owner assignment
- Timeline setting
- Evidence collection
- Verification method
- Closing loop
- Updating documentation
- Preventing recurrence
- Tracking in system
- Audit trail preservation
- Cl 9 1 Monitoring and measurement
- Cl 9 2 Internal audit
- Audit scope definition
- Scheduling authority
- Team selection
- Checklist creation
- Evidence collection
- Finding documentation
- Reporting format
- Follow-up timing
- Exception handling
- Closing audit cycle
- Cl 9 1 Certification timing
- Readiness assessment
- Choosing audit window
- Pre-audit briefing
- Evidence package
- Response strategy
- Handling nonconformities
- Appeal process
- Post-certification
- Maintaining certification
- Surveillance timing
- Re-engagement cycle
How this maps to your situation
- When launching a new cloud region
- After a network incident
- During vendor continuity audit
- Before annual compliance review
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, with flexible pacing across 4-6 weeks
How this compares to the alternatives
Unlike generic ISO 22301 overviews, this course is tailored to network security practitioners in cloud environments, with Rackspace-relevant implementation patterns and decision ownership models that reflect real authority paths for ICs.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.