ISO 22361:2022 and ISO 22301:2019 are two complementary standards in the security-and-resilience family. ISO 22301 defines a certifiable Business Continuity Management System (BCMS). ISO 22361 provides guidelines for crisis management — the point at which an incident exceeds the scope of the continuity plan.
ISO 22301:2019, Security and resilience — Business continuity management systems — Requirements, defines the requirements of a certifiable BCMS. It structures preparation for business disruptions: Business Impact Analysis (BIA), recovery objectives (RTO, RPO), continuity plans and recovery plans.
ISO 22361:2022, Security and resilience — Crisis management — Guidelines, applies at the moment an incident goes beyond the planned scope of the continuity plan. It structures the crisis cell, decision-making under pressure, multi-stakeholder communication and the post-crisis phase.
In practice, ISO 22301 handles the known: anticipated disruptions, mapped scenarios, an activated continuity plan. ISO 22361 handles the out-of-scope: an unanticipated crisis, irreducible ambiguity, and cascading consequences that demand executive decisions.
The two arrangements work as successive layers. The PECB Lead Business Continuity Manager (ISO 22301) and Lead Crisis Manager (ISO 22361) certifications follow on naturally within a Resilience Officer or Head of Resilience career path.
Think of ISO 22301 as the plan and ISO 22361 as what you do when the plan runs out. Mature resilience teams invest in both, in that order.
This course prepares participants to design, implement, test, and improve an operational resilience management framework. It addresses the growing pressure to maintain critical services through cyber incidents, supplier failures, technology outages, regulatory scrutiny, and physical disruptions. Participants learn how to identify critical business services, set impact tolerances, assess risk, and coordinate response and recovery decisions. Abilene Academy teaches through consultant-led case work, realistic evidence review, and exam-focused coaching built from field practice. It is designed for resilience leaders, risk managers, business continuity professionals, internal consultants, and managers responsible for disruption readiness.
View courseThis course prepares participants to initiate, develop, implement, test, and activate a disaster recovery plan (DRP) for ICT environments. Organizations face growing exposure to natural, human, and technological disruptions that legacy response plans fail to address, leaving recovery teams without tested procedures or clear accountability. Participants work through business impact analysis, risk assessment, recovery strategy design, and post-incident review across four intensive training days. Abilene Academy delivers this training through active consultants who bring operational DRP experience from real incident scenarios, not theoretical frameworks. It targets IT managers, ICT continuity professionals, risk consultants, and DR team members who own or contribute to recovery planning.
View courseThis intensive 4-day training prepares participants to implement and manage a Business Continuity Management System (BCMS) compliant with ISO 22301:2019. It covers planning, deployment, monitoring, updates, and continual improvement, with a focus on context analysis, business impact analysis, risk.
View courseA Lead Crisis Manager builds the crisis-management capability and runs it in a live event. They organise preparation, guide the response, then steer recovery and learning.
The length of crisis management training depends on the level you are aiming for. Awareness for teams runs 1–2 days. The operational Crisis Manager credential — PECB Lead Crisis Manager — runs 5 days, exam included, and is aligned with ISO 22361:2022.
An effective crisis-management framework defines leadership, structure, culture and skills, then tests them through scenarios. It has to make decision-making, information flow and communication explicit.
Both the NIS 2 Directive and the DORA regulation require formalised incident- and crisis-management arrangements with defined notification deadlines set out in their respective articles. ISO 22361:2022 provides the methodological framework for the crisis cell that responds to both regimes.
Browse all FAQs →
Full knowledge base
Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.