4.3 Communication Protocols & Documented Information
Key Takeaways
- ISO 22301 Clause 7.4 mandates a comprehensive communication framework answering the 5 Ws and How (What, When, With whom, How, and Who communicates) for both internal and external stakeholders.
- A clear distinction must be maintained between routine BCMS governance communications (policies, training, audit results) and emergency/disruption incident communications (warning, alerting, media handling, regulatory notifications).
- Clause 7.5 establishes requirements for Documented Information, unifying traditional document creation/updating controls (7.5.2) with rigorous distribution, protection, storage, versioning, and retention controls (7.5.3).
- Business continuity documentation must be safeguarded for availability and suitability during disruptions—including maintaining offline, out-of-band, and immutable hard-copy or distributed electronic copies resistant to cyber or power outages.
- ISO 22301:2019 contains a non-negotiable list of mandatory documented information across Clauses 4 through 10 that must be retained as auditable objective evidence.
4.3 Communication Protocols & Documented Information
Executive Summary: Communication and documented information represent the nervous system and institutional memory of an ISO 22301 Business Continuity Management System. Clause 7.4 requires organizations to establish formal protocols for internal and external communications across both steady-state operations and acute disruptions. Clause 7.5 governs the creation, updating, distribution, protection, and retention of documented information, ensuring that critical continuity procedures remain accessible, accurate, and secure when primary systems fail.
1. ISO 22301 Clause 7.4: The Communication Framework
Communication during business-as-usual ensures organizational alignment, while communication during a crisis protects human life, safeguards brand reputation, and maintains stakeholder confidence. Clause 7.4 mandates that the organization determine the internal and external communications relevant to the BCMS.
The 5 Ws and How of BCMS Communication
To comply with Clause 7.4, the Lead Implementer must establish a formal Communication Matrix addressing six structural dimensions:
+-------------------------------------------------------------------------+
| THE CLAUSE 7.4 COMMUNICATION MATRIX |
+-------------------------------------------------------------------------+
| 1. WHAT | Message content: policy, objectives, alerts, status |
| 2. WHEN | Timing: scheduled cadences vs. acute incident triggers |
| 3. WITH WHOM | Target audiences: staff, board, clients, media, reg |
| 4. HOW | Channels: ENS, intranet, satellite, press, SMS |
| 5. WHO | Authorized communicator: CEO, PR lead, Incident Manager |
+-------------------------------------------------------------------------+
- On what it will communicate (What): Defining the specific scope and substance of messages (e.g., BC policy updates, annual exercise schedules, incident alert notifications, executive situation reports).
- When to communicate (When): Establishing precise triggers and cadences (e.g., within 15 minutes of crisis invocation, hourly updates during system outages, quarterly governance reports to the Board).
- With whom to communicate (With Whom): Segmenting internal audiences (executive leadership, operational recovery teams, general workforce) and external audiences (customers, Tier-1 suppliers, regulators, emergency services, media, shareholders, local community).
- How to communicate (How): Selecting robust, redundant channels (enterprise mass notification systems [ENS], encrypted mobile messaging, satellite phones, emergency conference bridges, public dark websites, press releases).
- Who communicates (Who): Identifying and authorizing official spokespersons (e.g., Crisis Communications Director, Chief Executive Officer, Corporate PR Lead, Facilities Safety Marshal).
2. Routine Governance vs. Disruption / Emergency Communications
A critical requirement tested in the Lead Implementer syllabus is the operational distinction between Routine BCMS Communications and Disruption / Emergency Communications (linking Clause 7.4 to Clause 8.4.3 and ISO 22320).
+-------------------------------------------------------------------------+
| ROUTINE VS. EMERGENCY COMMUNICATIONS |
+-------------------------------------------------------------------------+
| ROUTINE GOVERNANCE (Clause 7.4) |
| • Cadence: Scheduled (Monthly, Quarterly, Annual). |
| • Purpose: Awareness, policy rollout, BIA workshops, audit findings. |
| • Tone: Informative, collaborative, instructional. |
| • Primary Channels: Corporate email, intranet, LMS, town halls. |
+-------------------------------------------------------------------------+
| EMERGENCY & DISRUPTION (Clauses 7.4 & 8.4.3) |
| • Cadence: Trigger-based, immediate (Minutes / Hours). |
| • Purpose: Life safety alerts, crisis coordination, media control. |
| • Tone: Directive, clear, concise, authoritative. |
| • Primary Channels: Automated ENS, SMS broadcast, out-of-band comms. |
+-------------------------------------------------------------------------+
Inbound and Outbound Crisis Communication Protocols
Under Clause 7.4 and Clause 8.4.3, the organization must establish structured mechanisms to manage both inward and outward information flows during a crisis:
- Inbound Communication Protocols:
- Dedicated emergency telephone hotlines and incident reporting mobile apps for employees.
- Structured monitoring of incoming emergency service directives, meteorological warnings, and cyber threat intelligence feeds.
- Active social media listening to track rumors, customer sentiment, and unverified leaks.
- Outbound Communication Protocols:
- Pre-scripted, pre-approved "Holding Statements" for immediate release to media within 30–60 minutes of a major incident.
- Mandatory Single Point of Contact (SPOC) rules: Strict prohibition against unauthorized employees speaking to journalists or posting on social media during an active crisis.
- Regulatory Breach Reporting: Formal procedures to notify supervisory authorities within mandatory statutory timelines (e.g., 72 hours for GDPR personal data breaches; immediate notification under central bank or healthcare resilience rules).
3. ISO 22301 Clause 7.5: Documented Information Fundamentals
In ISO 22301:2019, the term "Documented Information" replaces the legacy terms "documents" (procedures, policies, guidelines) and "records" (logs, audit reports, exercise results). Documented information represents information required to be controlled and maintained by the organization and the medium on which it is contained.
The Documented Information Lifecycle
+-------------------------------------------------------------------------+
| DOCUMENTED INFORMATION LIFECYCLE (Clause 7.5) |
+-------------------------------------------------------------------------+
| 1. CREATING & UPDATING (7.5.2) |
| • Identification (Title, Ref #, Date, Author) |
| • Format & Media (Language, Software, Graphics, Web/PDF) |
| • Review & Approval (Formal Sign-off for Suitability & Adequacy) |
+-------------------------------------------------------------------------+
| 2. CONTROLLING (7.5.3) |
| • Availability & Suitability (Available where & when needed) |
| • Protection (Confidentiality, Integrity, Loss Prevention) |
| • Distribution, Access & Retrieval (Role-based access controls) |
| • Storage & Preservation (Backups, Legibility, Longevity) |
| • Version Control & Change History (Change tracking, Redlines) |
| • Retention & Disposition (Archival schedules, Secure destruction) |
+-------------------------------------------------------------------------+
Creating and Updating Controls (Clause 7.5.2)
When creating and updating documented information, the Lead Implementer must enforce three non-negotiable rules:
- Identification and Description (7.5.2a): Every document must feature unique metadata, including document title, unique reference code (e.g.,
BCP-FIN-004), publication date, author name, and designated document owner. - Format and Media (7.5.2b): Standardized typography, corporate templates, clear diagrammatic conventions, and appropriate media (electronic cloud repository, encrypted USB tokens, laminated physical binders).
- Review and Approval for Suitability and Adequacy (7.5.2c): Formal governance review workflow. A draft document cannot be published without formal, dated sign-off by designated authorities (e.g., Business Continuity Policy signed by CEO; IT Disaster Recovery Plan signed by CIO/CISO).
Control of Documented Information (Clause 7.5.3)
Clause 7.5.3 mandates that documented information required by the BCMS must be controlled to ensure:
- Availability and Suitability (7.5.3.1a): Documents must be accessible where and when they are needed. If recovery teams cannot access the BCP because the corporate intranet is down during a cyberattack, the organization is noncompliant with Clause 7.5.3.
- Adequate Protection (7.5.3.1b): Safeguarded against loss of confidentiality (e.g., unredacted staff home addresses leaked), improper use, or loss of integrity (e.g., unauthorized editing of recovery RTOs).
- Control of Changes (7.5.3.2c): Maintaining clear version histories (e.g., v1.0 Draft, v1.1 Revised, v2.0 Approved) detailing exact changes made, reasons for revision, and authorizing manager.
- Retention and Disposition (7.5.3.2d): Establishing clear retention schedules based on legal and regulatory requirements (e.g., retaining management review minutes for 7 years; exercise debrief logs for 5 years) followed by certified secure disposal (shredding or cryptographic data wiping).
- Control of External Documents: Managing third-party standards, regulatory guidelines, and vendor service level agreements with formal cataloging and review.
4. Master Inventory: Mandatory Documented Information in ISO 22301:2019
During an accredited ISO 22301 Stage 1 and Stage 2 certification audit, the Lead Auditor will methodically inspect every mandatory document and record required by the standard. Lead Implementers must maintain this complete master inventory:
| ISO 22301 Clause | Mandatory Documented Information Required | Document Type | Retention & Control Recommendation |
|---|---|---|---|
| Clause 4.3 | Scope of the BCMS & justification for any exclusions | Mandatory Document | Controlled living document; reviewed annually. |
| Clause 5.2 | Business Continuity Policy signed by Top Management | Mandatory Document | Strategic apex document; published and controlled. |
| Clause 6.2 | Business continuity objectives and plans to achieve them | Mandatory Record | Annual action plans; updated upon review. |
| Clause 7.2 | Evidence of competence (CVs, training records, certifications) | Mandatory Record | HR / BCMS records; retained throughout employment + 3 yrs. |
| Clause 7.4 | Documented communication procedures (routine & emergency) | Mandatory Document | Operational protocols; verified in drills. |
| Clause 8.2.1 | BIA and Risk Assessment methodology / process | Mandatory Document | Formal framework; approved by BCSC. |
| Clause 8.2.2 | Business Impact Analysis (BIA) context, priorities, & results | Mandatory Record | Detailed process reports, MTPD, RTO, RPO metrics. |
| Clause 8.2.3 | Disruption Risk Assessment results & treatment evaluations | Mandatory Record | Threat register, risk scores, chosen treatment options. |
| Clause 8.4.1 | Business continuity plans and incident response procedures | Mandatory Document | Step-by-step operational action plans (BCPs/DRPs). |
| Clause 8.4.3.1 | Procedures for warning, alerting, and internal/external comms | Mandatory Document | Emergency call trees, holding statements, ENS runbooks. |
| Clause 8.4.5 | Procedures for restoring and returning to normal operations | Mandatory Document | Post-incident recovery, demobilization, and rebuilding. |
| Clause 8.5 | Exercise programme, exercise plans, and post-exercise reports | Mandatory Record | Multi-year exercise schedule, scenario scripts, debriefs. |
| Clause 9.1.1 | Evidence of monitoring and measurement results & metrics | Mandatory Record | KPI dashboards, SLA compliance reports. |
| Clause 9.2.1 | Internal audit programme, audit plans, and audit reports | Mandatory Record | Formal audit reports, findings, evidence sampled. |
| Clause 9.3.1 | Evidence of Top Management Review results and decisions | Mandatory Record | Signed executive minutes, resource decisions, action items. |
| Clause 10.1 | Evidence of nonconformities, corrective actions, and results | Mandatory Record | CAPA logs, root cause analysis, verification notes. |
5. Worked Scenario: CloudMatrix Enterprise SaaS
Context
CloudMatrix provides multi-tenant ERP software to 1,200 enterprise clients. During an unannounced ransomware attack that encrypted all internal Active Directory and file server environments, the Crisis Management Team assembled to execute the Business Continuity Plan.
The Support Breakdown
When the incident occurred, the response collapsed due to severe Clause 7.4 and 7.5 failures:
- Documentation Inaccessibility (7.5.3.1): All 48 Business Continuity Plans and technical runbooks were stored solely on the internal SharePoint network, which was encrypted by the ransomware. No team member had offline access.
- Version Confusion (7.5.2): A local backup copy found on a laptop contained outdated 2022 server IP addresses and defunct vendor phone numbers.
- Communication Chaos (7.4): The Crisis Communications Lead had no out-of-band contact directory. Panicked junior engineers posted conflicting updates on public Twitter/X accounts, causing three major clients to threaten breach-of-contract lawsuits.
Remediation Action Plan
The newly appointed Lead Implementer redesigned the communication and documentation infrastructure:
- High-Availability Document Vault (7.5.3): Deployed an out-of-band, air-gapped, zero-trust cloud documentation portal accessible via biometric authentication on mobile devices, with automated offline caching.
- Cryptographic Version Control (7.5.2): Implemented automated metadata headers, quarterly review sign-offs, and an automated script that deletes cached copies exceeding 90 days.
- Emergency Communication Overhaul (7.4): Deployed an enterprise SaaS Emergency Notification System (ENS) with multi-modal alerting (SMS, voice call, push notification). Authored pre-approved crisis holding statements and established strict SPOC rules binding all personnel.
Outcome
Twelve months later, during a simulated ransomware and data center power outage exercise, CloudMatrix teams accessed their runbooks on mobile devices within 90 seconds, initiated encrypted emergency conference calls, broadcast client notifications within 15 minutes, and restored critical services within the 1-hour RTO. The ISO 22301 Stage 2 auditor awarded CloudMatrix zero nonconformities and commended the resilient support architecture.
6. Exam Warning Traps & Auditing Pitfalls
[!WARNING] PECB Exam Trap 1 (Single Point of Storage Failure): In audit scenarios, having detailed, beautifully written BCPs that are stored exclusively on primary corporate networks or shared drives represents a Major Nonconformity against Clause 7.5.3.1a (Availability). If primary systems fail, documentation must remain immediately retrievable via redundant, offline, or out-of-band channels.
[!CAUTION] PECB Exam Trap 2 (The Missing Mandatory Record): Exam questions frequently test which items are mandatory under ISO 22301. Be vigilant: While an organization has flexibility in how it formats documents, it cannot omit mandatory records such as competence evidence (7.2), exercise reports (8.5), monitoring results (9.1), internal audit reports (9.2), or management review minutes (9.3).
[!NOTE] Auditing External Communication Protocols: Lead Auditors will always inspect Clause 7.4 holding statements and regulatory notification procedures. If an organization lacks predefined templates for notifying regulators or the press during a disruption, the auditor will note a gap in crisis communication readiness.
An ISO 22301-certified company maintains all of its Business Continuity Plans, disaster recovery runbooks, and emergency contact lists exclusively on a local SharePoint server. During a cyberattack, the SharePoint server is encrypted and inaccessible. Which clause of ISO 22301:2019 has the organization failed to satisfy?
Which of the following represents a mandatory item of documented information explicitly required to be retained as evidence under ISO 22301:2019?
In the event of a critical operational disruption involving a cyber breach and data leak, which communication protocol must an organization follow to ensure compliance with ISO 22301:2019 Clause 7.4 and Clause 8.4.3?