Skip to main content
Image coming soon

BCM0906 Mastering ISO 22301 for Senior Risk and Resilience Practitioners

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering ISO 22301 for Senior Risk and Resilience Practitioners

Build unshakable business continuity programs with defensible, source-backed design decisions

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Stalled buy-in from operations or IT teams on continuity plans due to perceived formality over function

The situation this course is for

Many continuity programs fail not from poor intent, but from weak justification. When challenged, teams fall back on 'it’s in the standard' rather than demonstrating context-specific alignment, leading to low engagement, repeated revisions, and audit findings.

Who this is for

Senior practitioner in risk, resilience, or operational continuity with responsibility for designing or defending business continuity frameworks

Who this is not for

Entry-level auditors, consultants selling generic templates, or teams looking for checkbox compliance without operational integration

What you walk away with

  • Trace every ISO 22301 clause to real-world implementation examples from peer organizations
  • Defend control design choices using documented reasoning from standards bodies and regulatory interpretations
  • Anticipate pushback on plan feasibility and preemptively align with IT, facilities, and supply chain stakeholders
  • Build a living SoA (Statement of Applicability) that reflects both compliance and operational reality
  • Create reusable justification libraries for common trade-offs: RTO/RPO tolerance, resource constraints, third-party reliance

The 12 modules (with all 144 chapters)

Module 1. Understanding ISO 22301 Scope and Intent
Establish a foundational grasp of the standard’s purpose, structure, and relationship to broader risk and resilience frameworks.
12 chapters in this module
  1. Origins of ISO 22301 and global adoption patterns
  2. Core principles: preparedness over prescription
  3. Mapping clauses to business impact scenarios
  4. Differentiating from ISO 20000 and ISO 27001
  5. Role of top management in continuity governance
  6. How APRA CPS 234 aligns with ISO 22301
  7. Essential Eight considerations for incident response
  8. Privacy Act implications for data recovery
  9. Key terminology: BCM, BIA, MTPD, RTO, RPO
  10. Common misconceptions about scope
  11. Documenting organizational context
  12. Stakeholder mapping for resilience programs
Module 2. Conducting a Defensible Business Impact Analysis
Move beyond checklist templates to build a BIA grounded in financial, reputational, and operational consequence modeling.
12 chapters in this module
  1. Defining critical functions with precision
  2. Identifying time-sensitive dependencies
  3. Estimating MTPD with stakeholder input
  4. Using financial proxies for non-revenue functions
  5. Validating BIA findings with operations teams
  6. Handling conflicting priorities across departments
  7. Documenting assumptions with traceability
  8. Linking BIA results to regulatory requirements
  9. Sampling techniques for rapid validation
  10. Using BIA to justify continuity investment
  11. Avoiding over-scoping and resource drain
  12. Version control for ongoing BIA updates
Module 3. Risk Assessment Alignment with ISO 22301
Integrate threat and vulnerability analysis into continuity planning with documented linkage to control selection.
12 chapters in this module
  1. Threat modeling for continuity scenarios
  2. Using NIST CSF as a supplementary guide
  3. Assessing single points of failure
  4. Third-party risk in recovery planning
  5. Geographic and infrastructure vulnerabilities
  6. Scenario stress testing methods
  7. Quantifying likelihood without over-engineering
  8. Mapping risks to ISO 22301 clause 8.2
  9. Avoiding duplication with ISO 27001 risk registers
  10. Documenting risk treatment decisions
  11. Justifying acceptance of residual risk
  12. Review cycles for updated risk posture
Module 4. Designing Resilient Recovery Strategies
Evaluate and justify recovery options with clear trade-offs between cost, speed, and feasibility.
12 chapters in this module
  1. Alternate site selection criteria
  2. Cloud-based vs. physical failover
  3. Data replication strategies by criticality
  4. Workforce availability planning
  5. Vendor-supported recovery models
  6. Mutual aid agreements: pros and cons
  7. Cost-benefit analysis for redundancy
  8. Testing assumptions behind recovery plans
  9. Documenting rationale for executive review
  10. Aligning with M&A continuity requirements
  11. Scalability of recovery design
  12. Handling partial versus full outages
Module 5. Documenting the Business Continuity Plan
Build a living, accessible plan that survives leadership changes and integrates with day-to-day operations.
12 chapters in this module
  1. Structure of a modular continuity plan
  2. Role-specific playbooks and checklists
  3. Version control and distribution protocols
  4. Integrating with incident management systems
  5. Using ServiceNow for continuity workflows
  6. Linking to Salesforce for customer impact tracking
  7. Automating notification sequences
  8. Documenting escalation paths
  9. Incorporating lessons from past incidents
  10. Ensuring plan accessibility under duress
  11. Handling classified or sensitive recovery steps
  12. Legal review of plan content
Module 6. Building a Defensible Statement of Applicability
Justify every included and excluded control with documented reasoning, precedent, and risk treatment alignment.
12 chapters in this module
  1. Purpose and structure of the SoA
  2. Referencing ISO 22301 Annex A controls
  3. Documenting applicability decisions
  4. Using industry benchmarks for justification
  5. Linking exclusions to risk assessments
  6. Handling auditor pushback on omissions
  7. Versioning and review cycles
  8. Integrating feedback from internal audit
  9. Benchmarking against peer organizations
  10. Using the SoA in vendor assessments
  11. Maintaining consistency across subsidiaries
  12. Training teams on SoA interpretation
Module 7. Stakeholder Engagement and Change Management
Secure sustained commitment from leadership, operations, and support teams through structured engagement.
12 chapters in this module
  1. Identifying key influencers in continuity
  2. Communicating value beyond compliance
  3. Running effective continuity workshops
  4. Overcoming resistance from IT teams
  5. Incentivizing departmental participation
  6. Measuring engagement impact
  7. Reporting progress without overloading
  8. Using Power BI for real-time dashboards
  9. Integrating with ESG reporting
  10. Handling leadership turnover
  11. Onboarding new stakeholders
  12. Celebrating continuity milestones
Module 8. Testing and Exercising Continuity Plans
Design tests that validate recovery capability and generate actionable improvements, not just compliance artifacts.
12 chapters in this module
  1. Types of tests: walkthrough, simulation, full interruption
  2. Designing test objectives with stakeholders
  3. Involving external partners in exercises
  4. Measuring test effectiveness
  5. Documenting findings with traceability
  6. Prioritizing remediation actions
  7. Using test results to refine RTO/RPO
  8. Avoiding test fatigue
  9. Integrating with cyber incident response
  10. Scaling tests across global operations
  11. Reporting test outcomes to leadership
  12. Maintaining test records for auditors
Module 9. Maintaining and Improving the Program
Establish a continuous improvement cycle that adapts to organizational and environmental changes.
12 chapters in this module
  1. Review frequency for plan updates
  2. Trigger events for immediate revision
  3. Integrating lessons from near-misses
  4. Benchmarking against ISO 22301 updates
  5. Using feedback from audits and tests
  6. Managing plan obsolescence
  7. Documenting improvement initiatives
  8. Linking to enterprise risk management
  9. Using Databricks for trend analysis
  10. Automating update reminders
  11. Training refresh cycles
  12. Handover protocols for role changes
Module 10. Audit Preparation and Regulatory Alignment
Prepare for internal and external audits with confidence, using documented evidence and consistent rationale.
12 chapters in this module
  1. Common audit findings in ISO 22301
  2. Preparing documentation packets
  3. Rehearsing auditor interviews
  4. Responding to non-conformities
  5. Using SOC 2 reports as supporting evidence
  6. Aligning with APRA CPS 234 expectations
  7. Privacy Act considerations in recovery
  8. Handling multi-jurisdictional audits
  9. Demonstrating continuous improvement
  10. Maintaining independence in audit reviews
  11. Preparing for unannounced audits
  12. Post-audit action tracking
Module 11. Cross-Functional Integration
Embed continuity into cybersecurity, IT operations, and enterprise risk management workflows.
12 chapters in this module
  1. Integrating with NIST CSF
  2. Aligning with SOC 2 controls
  3. Coordinating with ISO 27001 teams
  4. Supporting PCI DSS resilience requirements
  5. Incorporating COBIT governance
  6. Working with COSO risk frameworks
  7. Supporting financial close continuity
  8. Integrating with supply chain risk programs
  9. Collaborating with legal and compliance
  10. Supporting M&A integration planning
  11. Aligning with ESG disclosures
  12. Cross-training with incident response
Module 12. Sustaining Leadership and Influence
Position yourself as the authoritative voice on resilience through consistent, source-backed communication.
12 chapters in this module
  1. Building executive credibility
  2. Using data to tell compelling stories
  3. Positioning continuity as strategic enabler
  4. Influencing budget decisions
  5. Mentoring junior practitioners
  6. Presenting to leadership committees
  7. Contributing to industry forums
  8. Publishing internal thought leadership
  9. Maintaining technical depth over time
  10. Balancing operational and strategic focus
  11. Succession planning for key roles
  12. Leaving a defensible legacy

How this maps to your situation

  • Post-incident review
  • Pre-audit preparation
  • Leadership briefing
  • Cross-functional alignment

Before vs. after

Before
Continuity plans treated as compliance artifacts, vulnerable to skepticism from operations and IT teams
After
Defensible, stakeholder-aligned programs backed by documented reasoning and real-world precedent

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3 hours per module, or 36 hours total, with self-paced access and lifetime updates.

If nothing changes
Without defensible justification, continuity programs remain vulnerable to budget cuts, low engagement, and audit findings, especially as regulatory scrutiny increases.

How this compares to the alternatives

Unlike generic online courses, this program provides specific, source-backed reasoning for every control decision, with templates tailored to real-world implementation challenges faced by senior practitioners.

Frequently asked

Is this course suitable for someone with a business development background?
Yes, especially when focused on structured risk and resilience. Your experience in integration and long-term planning positions you well to lead credible continuity programs.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Can I use this to support APRA CPS 234 compliance?
Yes, the course includes specific mappings to APRA expectations and Australian regulatory context.
$199 one-time. Approximately 3 hours per module, or 36 hours total, with self-paced access and lifetime updates..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours