ISO 22361 provides guidelines for organising and improving a crisis-management capability. It structures leadership, coordination, preparation and post-crisis learning.
ISO 22361:2022 offers guidelines for designing, deploying and evolving a crisis-management capability. Its main value is to provide a common framework — understandable by executives and operational teams alike — so that crisis management does not rest solely on individual instincts or local habits.
The standard emphasises building a coherent arrangement: leadership, structure, culture and skills. In concrete terms, that means clarifying who decides, with what responsibilities, on what information, through what modes of coordination, and with what communication mechanisms. It also helps define the relationship between the crisis-management team and the rest of the organisation, particularly the business functions, communications and technical support.
A second contribution is the life-cycle approach. ISO 22361 addresses anticipation, assessment, prevention and preparation, then response, recovery and continuous improvement. This sequencing avoids concentrating all effort on the response alone, at the expense of preparation and lessons learned.
In an implementation programme, the standard serves as the basis for establishing a framework, designing exercises and assessing maturity. It makes it easier to produce internal evidence: defined roles, procedures, drills and captured lessons. It also provides a useful reference for harmonising practices across sites, functions and countries, while leaving room for context and risk constraints.
Use ISO 22361 to move crisis management from heroics to a system: its real payoff is a repeatable capability that survives the departure of your most experienced responders.
This course prepares participants to design, implement, test, and improve an operational resilience management framework. It addresses the growing pressure to maintain critical services through cyber incidents, supplier failures, technology outages, regulatory scrutiny, and physical disruptions. Participants learn how to identify critical business services, set impact tolerances, assess risk, and coordinate response and recovery decisions. Abilene Academy teaches through consultant-led case work, realistic evidence review, and exam-focused coaching built from field practice. It is designed for resilience leaders, risk managers, business continuity professionals, internal consultants, and managers responsible for disruption readiness.
View courseThis course prepares participants to initiate, develop, implement, test, and activate a disaster recovery plan (DRP) for ICT environments. Organizations face growing exposure to natural, human, and technological disruptions that legacy response plans fail to address, leaving recovery teams without tested procedures or clear accountability. Participants work through business impact analysis, risk assessment, recovery strategy design, and post-incident review across four intensive training days. Abilene Academy delivers this training through active consultants who bring operational DRP experience from real incident scenarios, not theoretical frameworks. It targets IT managers, ICT continuity professionals, risk consultants, and DR team members who own or contribute to recovery planning.
View courseThis intensive 4-day training prepares participants to implement and manage a Business Continuity Management System (BCMS) compliant with ISO 22301:2019. It covers planning, deployment, monitoring, updates, and continual improvement, with a focus on context analysis, business impact analysis, risk.
View courseA Lead Crisis Manager builds the crisis-management capability and runs it in a live event. They organise preparation, guide the response, then steer recovery and learning.
The length of crisis management training depends on the level you are aiming for. Awareness for teams runs 1–2 days. The operational Crisis Manager credential — PECB Lead Crisis Manager — runs 5 days, exam included, and is aligned with ISO 22361:2022.
An effective crisis-management framework defines leadership, structure, culture and skills, then tests them through scenarios. It has to make decision-making, information flow and communication explicit.
Both the NIS 2 Directive and the DORA regulation require formalised incident- and crisis-management arrangements with defined notification deadlines set out in their respective articles. ISO 22361:2022 provides the methodological framework for the crisis cell that responds to both regimes.
Browse all FAQs →
Full knowledge base
Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.