| Scope and covered activity | SP 800-61 Rev. 3 focuses on cybersecurity incident response and recovery. Use NIST SP 800-61 Rev. 3 to define the in-scope system, product, service, supplier, release, incident, or governance process before mapping evidence. | ISO 22301:2019 specifies a BCMS for protecting against, preparing for, responding to, and recovering from disruptions. Its scope is the organization or part of the organization covered by the BCMS, including prioritized activities and the products and services they support. | Define the cyber systems and incident boundary for Rev. 3, then define the organizational boundary, prioritized activities, dependencies, and continuity objectives for the BCMS. Neither boundary automatically sets the other. |
|---|
| Who must act | Rev. 3 involves leadership, incident handlers, technology and asset owners, legal, communications, providers, and recovery participants according to the incident. | ISO 22301 places accountability on top management for the BCMS and requires defined roles, responsibilities, and authorities. Business continuity, operational, facilities, communications, supplier, technology, and service owners carry out the planned response and recovery work. | Name the incident lead and the continuity response structure separately. Define who may invoke continuity plans, set priorities, communicate with interested parties, approve workarounds, and authorize the return to normal operations. |
|---|
| Trigger or threshold | NIST SP 800-61 Rev. 3: rerun the workflow when an adverse cybersecurity event, suspected incident, incident-response plan change, lessons-learned finding, or recovery activity changes the incident record. | Invoke the relevant continuity procedure when disruption criteria in the plan are met. Reassess the BCMS after exercises, actual disruptions, significant organizational or dependency changes, audit findings, management review, or changed continuity needs. | Connect the incident declaration criteria to explicit continuity escalation thresholds, such as loss of a critical dependency or a forecast breach of an acceptable outage. Record who made each decision and when. |
|---|
| Core obligations | Rev. 3 connects incident preparation, event analysis, declaration, prioritization, containment, eradication, recovery, communications, evidence preservation, and improvement to CSF 2.0 outcomes. | ISO 22301 requires BCMS context and scope, leadership, objectives, resources, documented information, business impact analysis and risk assessment, continuity strategies and solutions, plans, exercises, evaluation, audit, management review, and improvement. | Map shared actions only after the distinct duties are visible. A restored server may satisfy an incident recovery step while the BCMS still requires validation that the prioritized service is operating at the required capacity. |
|---|
| Evidence and records | Rev. 3 evidence includes incident declarations and priorities, investigation records, incident data, communications, containment and eradication actions, restoration validation, after-action reporting, and improvements. | BCMS evidence includes the scope and policy, business impact analysis, risk assessment, continuity objectives, selected strategies, resource requirements, plans and procedures, exercise results, capability evaluations, audit records, management-review outputs, nonconformities, and corrective actions. | Link incident timestamps, impact estimates, communications, restoration tests, and lessons learned into the BCMS record where they support a continuity requirement. Keep certification evidence controlled under the BCMS. |
|---|
| Timing and cadence | Rev. 3 is final guidance published in April 2025 and supersedes Rev. 2. It has no certification cycle or universal reporting clock; organizations define review and response cadence and overlay external duties. | ISO 22301 requires planned exercises, evaluation of continuity documentation and capabilities, monitoring, internal audit, management review, and improvement. It does not set one universal cyber-notification clock or fixed recovery time; the organization derives continuity objectives from its context and business impact analysis. | Track internal incident targets, continuity objectives, exercise and review schedules, contractual commitments, legal reporting deadlines, and certification-audit dates separately. |
|---|
| Enforcement or assurance route | Rev. 3 has no standalone certification or penalty route. Evidence may be reviewed through federal requirements, internal governance, contracts, customer assurance, or another incorporating authority. | ISO 22301 is a requirements standard against which a defined BCMS scope may be assessed and certified. Certification is not created by the standard itself and is voluntary unless law, contract, policy, or another authority requires it. | Record the certification scope and audit criteria. An ISO 22301 certificate does not by itself establish that every Rev. 3 incident-response outcome is implemented, and use of Rev. 3 does not establish BCMS conformity. |
|---|
| Overlap and reuse | Rev. 3 explicitly recommends synchronizing business continuity plans with incident-response plans because cyber incidents can undermine business resilience. | The BCMS can use incident impact estimates, dependency failures, communications, recovery results, and lessons learned to update business impact analysis, strategies, procedures, and exercises. | Share facts and artifacts, not conclusions. Document separately whether the cyber incident is contained, whether affected systems are securely restored, and whether prioritized products and services have recovered to the required capacity. |
|---|
| Practical decision rule | Choose Rev. 3 when the primary decision concerns cybersecurity incident preparation, handling, recovery, communications, evidence, or continuous improvement. | Choose ISO 22301 first when the decision concerns continuity scope, acceptable disruption impacts, prioritized activities, recovery capacity, alternative arrangements, exercise, management review, or BCMS certification. | For an active cyber incident, run the Rev. 3 response process and invoke continuity procedures when business thresholds are met. Neither process should wait for the other before urgent containment or continuity action. |
|---|