Crisis Management Plan Development with ISO22361 Elements 
Developing a comprehensive and actionable crisis management plan is critical in preparing an organization for crises. Phase 5: Crisis Management (CM) Plan Development of the CM Planning Methodology emphasizes the creation of a detailed, structured plan that outlines the processes for activating crisis response protocols, allocating resources, and ensuring clear communication during a crisis.
This phase involves translating the strategic insights from earlier phases into concrete steps, providing the organisation with a clear and practical guide to handle crises. The CM Plan integrates business continuity plans to ensure critical business functions continue operating during a disruption.
In parallel, ISO 22361:2022 provides a structured framework for developing a CM Plan, detailing the necessary components and processes that must be included to meet global preparedness standards.
The standard outlines specific requirements for crisis activation protocols, communication strategies, and decision-making procedures, ensuring that the CM Plan is comprehensive and aligns with the organisation’s strategic goals and regulatory obligations. This comparison chart examines the similarities and differences between the methodology's CM Plan.
The development phase and the corresponding requirements of ISO 22361:2022 highlight the critical elements both frameworks prioritise in crafting a robust CM plan.
Detailed Comparison Between Phase 5: CM Plan Development of CM Planning Methodology vs. ISO 22361:2022 Standard
Objective of the Crisis Management Plan
|
Crisis Management Planning Methodology: Phase 5 - CM Plan Development |
|
|
ISO 22361:2022 Standard |
|
|
This phase focuses on developing a comprehensive CM Plan that serves as the organisation’s playbook for responding to crises. The CM Plan is designed based on previous phases: risk assessment, business impact analysis, and strategy. It includes specific, actionable steps to handle a crisis. |
|
|
ISO 22361 similarly emphasizes the development of a documented CM Plan that should be flexible and comprehensive. The CM Plan under ISO 22361 is intended to guide preparation, response, and recovery efforts while supporting organisational resilience and long-term recovery. |
|
|
The CM Plan outlines the activation protocols, communication guidelines, resource allocation, and decision-making processes for various crisis scenarios. It also integrates business continuity plans to ensure continuity of critical operations. |
|
|
ISO 22361 requires that the CM Plan should include provisions for crisis preparedness, response procedures, and recovery plans. It should be integrated with resilience practices and stakeholder requirements, ensuring alignment with the overall risk and governance frameworks. |
|
Comparison: Both frameworks emphasize the need for a comprehensive CM Plan. However, ISO 22361 ensures that the CM Plan aligns with the organisation’s broader resilience objectives and evolves in response to changing risks and stakeholder needs.
Crisis Activation Protocols
|
Crisis Management Planning Methodology: Phase 5 - CM Plan Development |
|
|
ISO 22361:2022 Standard |
|
|
This phase outlines the development of crisis activation protocols, which define the criteria and procedures for activating the crisis management plan. These protocols provide clear guidelines on when and how a crisis should be declared, who has the authority to make that decision, and how to trigger the crisis management team’s response. |
|
|
ISO 22361 mandates the development of crisis activation protocols, ensuring a structured process for identifying, declaring, and managing crises. The standard highlights that these protocols should be flexible, allowing organizations to adapt to various crisis scenarios. It emphasizes escalation processes and ensures timely decision-making based on predefined criteria. |
|
|
Organisations are encouraged to develop pre-defined triggers and assign responsibility to a designated crisis response team to initiate the crisis response. |
|
|
ISO 22361 integrates the activation protocols into the organisation’s governance framework, ensuring compliance with internal policies, stakeholder expectations, and regulatory requirements. It emphasises agility in activation to allow for a swift and proportionate response. |
|
Comparison
Both emphasise the need for crisis activation protocols, but ISO 22361 focuses on ensuring they are flexible and adaptable and integrating them with organisational governance and broader resilience efforts.
Crisis Response Procedures
|
Crisis Management Planning Methodology: Phase 5 - CM Plan Development |
|
|
ISO 22361:2022 Standard |
|
|
The CM Plan outlines detailed response procedures for various crises, ensuring that each scenario has a clear set of steps to follow. These procedures cover communication, decision-making, resource allocation, and coordination with external stakeholders. |
|
|
ISO 22361 requires that crisis response procedures are well-documented, tested, and reviewed regularly. It emphasizes that these procedures should ensure organisational resilience and maintain critical functions during a crisis. Procedures should also be scalable and tailored to specific types of crises. |
|
|
The CM Plan’s response procedures should be aligned with the organisation’s crisis management strategy and tested to ensure they are effective in practice. |
|
|
ISO 22361 focuses on the importance of resilience integration, ensuring that the response procedures manage the crisis, ensure continuity of critical services, and protect the organization’s reputation and stakeholder trust. |
|
Comparison
While both frameworks emphasize the importance of response procedures, ISO 22361 stresses that these procedures must be aligned with resilience practices and regularly tested to ensure effectiveness and scalability.
Communication Plan
|
Crisis Management Planning Methodology: Phase 5 - CM Plan Development |
|
|
ISO 22361:2022 Standard |
|
|
A core element of the CM Plan is developing a communication plan that includes clear internal and external communication protocols during a crisis. This includes identifying key spokespersons, preparing pre-approved messaging, and selecting appropriate communication channels. |
|
|
ISO 22361 mandates that communication plans be part of the CM Plan and emphasizes proactive and transparent communication with stakeholders. It highlights the need to maintain consistent messaging across all channels and ensure that communication is timely, accurate, and aligned with the organization’s overall resilience strategy. |
|
|
The communication plan should maintain transparency and ensure stakeholders are informed throughout the crisis. This includes media relations, customer communication, and employee updates. |
|
|
ISO 22361 stresses the importance of communication in protecting the organisation’s reputation and ensuring stakeholder trust. It highlights the need for communication frameworks that adapt to the severity and type of crisis, ensuring coordinated messaging with external partners, regulators, and the public. |
|
Comparison
Both approaches emphasise the importance of a clear communication plan. However, ISO 22361 integrates communication deeply into the resilience strategy, ensuring that communication is aligned with stakeholder expectations and supports the organisation’s long-term reputation.
Business Continuity and Integration
|
Crisis Management Planning Methodology: Phase 5 - CM Plan Development |
|
|
ISO 22361:2022 Standard |
|
|
The CM Plan must include provisions to ensure business continuity, especially for critical operations during and after a crisis. This includes integrating business continuity plans into the CM Plan, providing the organisation can maintain essential functions and recover quickly. |
|
|
ISO 22361 emphasizes a close integration between crisis management plans and business continuity efforts. The standard ensures that CM Plans support continuity of operations and are fully aligned with broader organisational resilience and recovery efforts. |
|
|
The CM Plan should outline clear recovery plans that detail how the organization will resume normal operations post-crisis, including timelines, resource allocation, and restoration of critical systems. |
|
|
ISO 22361 promotes the development of recovery strategies that ensure long-term resilience. It stresses that these recovery plans should be dynamic, allowing organisations to recover quickly and sustainably, incorporating the lessons learned into future planning. |
|
Comparison
Both emphasise business continuity integration within the CM Plan, but ISO 22361 focuses more on ensuring recovery efforts support long-term resilience and align with the broader resilience framework.
Testing and Validation
|
Crisis Management Planning Methodology: Phase 5 - CM Plan Development |
|
|
ISO 22361:2022 Standard |
|
|
Once the CM Plan is developed, it must be tested to ensure its effectiveness. This involves conducting simulations, drills, and tabletop exercises to evaluate how well the plan performs in practice. Testing helps identify gaps and areas for improvement. |
|
|
ISO 22361 mandates that CMPs undergo regular testing and validation to ensure their effectiveness under real-world conditions. Testing should involve scenario-based exercises, and the results should be used to update and improve the plan continuously. |
|
|
Testing should include participation from the Crisis Management Team (CMT) and other key stakeholders to ensure everyone understands their roles and responsibilities. |
|
|
ISO 22361 emphasises the importance of stakeholder involvement in testing. It stresses that the CM Plan should be regularly reviewed based on changing risks, organisational changes, and lessons learned from previous crises or tests. |
|
Comparison
Both frameworks underscore the need for testing and validating the CM Plan. Still, ISO 22361 stresses the need for continuous updates to the plan based on testing outcomes, organisational changes, and emerging risks.
Documentation and Dissemination
|
Crisis Management Planning Methodology: Phase 5 - CM Plan Development |
|
|
ISO 22361:2022 Standard |
|
|
The CM Plan should be thoroughly documented and clearly outline all procedures, roles, and actions to be taken during a crisis. It must also be easily accessible to all relevant personnel. |
|
|
ISO 22361 emphasises that the CM Plan should be well-documented and widely disseminated across the organization. It highlights the importance of ensuring that all key personnel are familiar with and have easy access to the plan, particularly during a crisis. |
|
|
Organisations are encouraged to create a living document that is continually updated and revised based on feedback, testing, and changes in the organisational environment. |
|
|
ISO 22361 stresses the need for ongoing dissemination and education about the CM Plan. This ensures that employees across all levels are aware of the crisis management procedures and know how to access and implement the plan during an emergency. |
|
Comparison
Both emphasise the importance of documentation and dissemination. Still, ISO 22361 extends this by ensuring that the CM Plan is documented and embedded within the organisational culture, focusing on ongoing education and accessibility.
Summary of Key Differences and Similarities
The comparison between Phase 5: CM Plan Development of the CM Planning Methodology and ISO 22361:2022 reveals key insights:
Similarities
Both emphasise the importance of developing a comprehensive, actionable CM Plan, testing the plan, and ensuring business continuity.
Differences
ISO 22361 goes beyond the planning methodology by ensuring that the CM Plan is part of a broader resilience framework, is flexible, and continuously integrates lessons learned from ongoing tests and crisis experiences.
ISO 22361 offers a more structured, holistic, and resilience-focused approach. It ensures that crisis management is not an isolated effort but is integrated into the organisation's governance, business continuity, and long-term resilience strategies.
Summing up ...
The Crisis Management Planning Methodology and ISO 22361:2022 emphasize the importance of a comprehensive and well-structured crisis management plan.
While both approaches share common objectives, ISO 22361:2022 provides a more structured and integrated framework. Key differences include ISO 22361's emphasis on aligning the CM Plan with broader resilience objectives, its focus on continuous review and updates, and its integration with organizational governance.
Both methodologies are valuable tools for organizations seeking to build a proactive and effective crisis management capability.