{"id":44204,"date":"2026-07-31T19:27:27","date_gmt":"2026-07-31T17:27:27","guid":{"rendered":"https:\/\/smartfense.com\/?p=44204"},"modified":"2026-07-31T19:27:35","modified_gmt":"2026-07-31T17:27:35","slug":"business-continuity-plan-who-can-execute-it","status":"publish","type":"post","link":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/","title":{"rendered":"The business continuity plan is approved. What&#8217;s missing is someone who knows how to run it"},"content":{"rendered":"<p>How long would it take your organization to get back to work if the systems failed to start tomorrow? Most governance teams have that answer written down in a business continuity plan, approved by the committee and reviewed in the last audit. What few of them have is any certainty that the people who are supposed to execute that document will know, at the moment of the incident, which part is theirs.<\/p>\n<p>The scenario stopped being hypothetical a while ago. Verizon\u2019s <a href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/\" target=\"_blank\" rel=\"noopener noreferrer\">2026 Data Breach Investigations Report<\/a> finds that 48% of breaches now involve ransomware, and the <a href=\"https:\/\/www.enisa.europa.eu\/publications\/enisa-threat-landscape-2024\" target=\"_blank\" rel=\"noopener noreferrer\">ENISA threat landscape<\/a> places threats against availability at the top of the ranking, ahead of ransomware and threats against data. When what gets interrupted is the operation itself, the business continuity plan stops being an audit requirement and becomes a procedure someone has to apply with no time left to read it.<\/p>\n<p>In my experience reviewing continuity frameworks, the document is almost never the problem. The problem shows up one layer down, in the question of who knows what, and since when.<\/p>\n<h2>What does ISO 22301 require about people, and why does it get implemented last?<\/h2>\n<p>ISO 22301 is the international standard that specifies the requirements for a business continuity management system. Like the other management system standards, it groups its support requirements under clause 7, and two of them point directly at people. They are competence (7.2) and awareness (7.3).<\/p>\n<p>Competence requires determining which capabilities each person with an assigned continuity role needs, and making sure they have them. Awareness has a wider reach and extends to the whole organization, not just the crisis committee. It asks that every person know the continuity policy, understand their contribution to the system, and know what departing from the procedures implies.<\/p>\n<p>Those two clauses tend to be left for last. Documenting the business impact analysis, the recovery strategies and the target times produces deliverables an auditor can review in a folder. Competence and awareness produce something less convenient to show, because they live in people\u2019s heads on the day they are needed.<\/p>\n<p>It is the same displacement that happens with <a href=\"https:\/\/smartfense.com\/en\/blog\/iso-27001-2022-control-6-3-awareness\/\">control 6.3 of ISO\/IEC 27001<\/a>, where staff training gets documented late and with less precision than the technical controls surrounding it.<\/p>\n<h2>The distance between having a plan and being able to activate it<\/h2>\n<p>An approved continuity plan proves the organization analyzed its critical processes and decided how to recover them. It does not prove it can actually do so.<\/p>\n<p>Between one thing and the other there is a gap, and it almost always shows up in the same three ways:<\/p>\n<ul>\n<li>The plan describes roles by job title, and whoever holds that title changed eight months ago without anyone updating the annex.<\/li>\n<li>The procedure assumes a communication channel that depends on the system currently down.<\/li>\n<li>Activation requires a decision nobody has delegated in writing for three in the morning on a Sunday.<\/li>\n<\/ul>\n<p>None of the three is detectable by reading the document. They are detectable when someone tries to use it.<\/p>\n<h2>Who needs to know what, and when?<\/h2>\n<p>Continuity awareness does not mean all 800 people in an organization know the full plan. It means each group knows the part that falls to them. The segmentation that works has three layers.<\/p>\n<p><strong>The crisis committee<\/strong> needs the activation criteria, the order of precedence among critical processes, and its authority to decide without escalating.<\/p>\n<p><strong>The teams with an assigned technical role<\/strong> need the recovery procedure for their own scope and the target times the organization committed to for it.<\/p>\n<p><strong>Everyone else<\/strong> needs to know three things, and only three: how they will find out there is an incident, which alternate channel the organization will use while it lasts, and what they are authorized to do with information and devices in the meantime.<\/p>\n<p>That third layer is the one skipped most often, and it is by far the largest. Someone in administration who does not know which alternate channel the organization uses will improvise one. That improvised channel tends to be the one that opens the next problem.<\/p>\n<h2>Why isn\u2019t rehearsing the plan the same as preparing people?<\/h2>\n<p>ISO 22301 asks for continuity procedures to be exercised and tested, and the crisis exercise is hard to replace. It puts the committee in the position of deciding with partial information and exposes the assumptions the document treated as settled.<\/p>\n<p>What an annual exercise cannot do is sustain behavior for the rest of the year. A drill convenes a limited group for a few hours, with advance notice, in a setting where everyone knows they are being observed. The behavior that matters on the day of the real incident belongs to someone who was never convened to any exercise and who has to recognize, unaided, that what they are seeing on their screen is not an ordinary IT failure.<\/p>\n<p>That is where continuity rests on the same ground as awareness. Observing how the organization responds to a <a href=\"https:\/\/smartfense.com\/en\/platform\/simulation-tools\/ransomware-attacks\/\">simulated ransomware attack<\/a> produces a signal the committee exercise does not, because that observation reaches the entire population on a normal working day rather than the ten names in the crisis room. That signal reads <a href=\"https:\/\/smartfense.com\/en\/blog\/ransomware-simulation-measure-behavior\/\">as behavior sustained over time<\/a>.<\/p>\n<h2>How much of the trigger depends on a person?<\/h2>\n<p>It pays to be precise here, because this figure often gets stretched. The 2026 DBIR does not claim all ransomware arrives through a click. It reports that 31% of breaches start in software vulnerabilities, a path that now exceeds stolen credentials. What the report does maintain is that the most frequent causes continue to heavily involve the human element, with social engineering, phishing and stolen credentials among them.<\/p>\n<p>For a governance framework what matters is that the trigger of a continuity event has a stable, measurable human component, and that this component is managed with instruments different from the ones that handle patching and backups. Treating <a href=\"https:\/\/smartfense.com\/en\/blog\/human-risk-cybersecurity-starts-before-click\/\">human risk as a variable you watch before the click<\/a> is what allows you to anticipate it instead of reconstructing it afterwards.<\/p>\n<h2>What should you record to make continuity auditable?<\/h2>\n<p>A competence and awareness requirement is demonstrated with records, like any other. The difference is that here the record has to answer per person and per date, not per event.<\/p>\n<p>Four questions organize what is worth having on hand:<\/p>\n<ul>\n<li>Who holds an assigned role in the continuity plan today, according to the current directory rather than the latest version of the annex?<\/li>\n<li>What training did each of those people receive, when did they receive it, and when does it expire?<\/li>\n<li>What does the rest of the organization know about the alternate communication procedure, and since when?<\/li>\n<li>Where is the evidence that the continuity policy was communicated and accepted?<\/li>\n<\/ul>\n<p>Those questions look a lot like the ones that come up when you have to <a href=\"https:\/\/smartfense.com\/en\/blog\/data-breach-notification-72-hours-compared\/\">notify a breach with a clock running<\/a>, for a simple reason. In both cases the organization has to prove, with little margin, something it decided long before.<\/p>\n<p>SMARTFENSE\u2019s <a href=\"https:\/\/smartfense.com\/en\/platform\/management-of-regulations-policies-and-procedures\/\">management of regulations, policies and procedures<\/a> covers that layer for the continuity policy, and the <a href=\"https:\/\/smartfense.com\/en\/platform\/audit\/demonstrating-compliance-in-awareness\/\">program audit records<\/a> make it possible to reconstruct who read what, when they accepted it and with what validity period, without depending on a spreadsheet somebody maintains by hand.<\/p>\n<h2>What turns a business continuity plan into a capability<\/h2>\n<p>A business continuity plan that exists only as an approved document transfers all the risk to the day of the incident. The organization ends up depending on the right people improvising well, and in time.<\/p>\n<p>When the incident also carries criminal implications, that improvisation gets expensive fast, because the decisions of the first few hours are documented and reviewed later. That is where <a href=\"https:\/\/smartfense.com\/en\/blog\/argentina-cybercrime-law-26388-risk-governance\/\">continuity becomes part of risk governance<\/a> and stops being an annex belonging to the technical team.<\/p>\n<p>The alternative lies in treating competence and awareness as two requirements with an owner, a record and an expiry date, the same way the business impact analysis and the recovery time objectives already are. Once that is settled, the plan stops being reviewed once a year and starts being a capability the organization actually has.<\/p>\n<h2>Frequently asked questions<\/h2>\n<p><strong>What does ISO 22301 require regarding staff awareness?<\/strong><br \/>\nISO 22301 includes awareness as a support requirement under clause 7.3. It asks that people in the organization know the business continuity policy, understand their contribution to the management system, and know what departing from the established procedures implies.<\/p>\n<p><strong>What is the difference between competence and awareness in business continuity?<\/strong><br \/>\nCompetence (7.2) applies to those with an assigned continuity role and requires ensuring they have the capabilities to perform it. Awareness (7.3) applies to the whole organization and operates at a more basic level, that of knowing the plan exists, what is expected of each person, and how the organization will communicate during a disruption.<\/p>\n<p><strong>Is an annual crisis exercise enough to satisfy the requirement about people?<\/strong><br \/>\nThe exercise covers the obligation to test procedures, but it involves a limited group for a few hours and with advance notice. It does not sustain the behavior of the rest of the organization over the year, which is what the response rests on the day of an unannounced incident.<\/p>\n<p><strong>Who inside the organization needs to know the continuity plan?<\/strong><br \/>\nIt is worth segmenting into three layers. The crisis committee needs the activation criteria and its decision authority; the teams with a technical role need the recovery procedure for their scope and the target times; everyone else needs to know how they will find out about the incident, which alternate channel will be used, and what they are authorized to do while it lasts.<\/p>\n<p><strong>What evidence does an auditor ask for about people\u2019s preparedness in continuity?<\/strong><br \/>\nRecords per person and per date, not per event. Who holds an assigned role according to the current directory, what training each one received with completion and expiry dates, what was communicated to the rest of the organization and since when, and where the acceptance of the continuity policy is recorded.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The business continuity plan gets approved and filed. ISO 22301 asks for competence and awareness, and those are the clauses that rarely get implemented.<\/p>\n","protected":false},"author":34,"featured_media":44201,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3,686],"tags":[2321,1362,2326,1722,2063],"class_list":["post-44204","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-business-continuity","tag-cumplimiento-normativo-en","tag-iso-22301","tag-resiliencia-organizacional-en","tag-riesgo-humano"],"acf":[],"yoast_head":" \n<title>Business continuity plan: who knows how to execute it<\/title>\n<meta name=\"description\" content=\"The business continuity plan gets approved and filed. ISO 22301 asks for competence and awareness, and those are the clauses that rarely get implemented.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Business continuity plan: who knows how to execute it\" \/>\n<meta property=\"og:description\" content=\"The business continuity plan gets approved and filed. ISO 22301 asks for competence and awareness, and those are the clauses that rarely get implemented.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/\" \/>\n<meta property=\"og:site_name\" content=\"SMARTFENSE\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-31T17:27:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-31T17:27:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-33.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1376\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Carla Caggiano\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Carla Caggiano\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/\"},\"author\":{\"name\":\"Carla Caggiano\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/f88c39d826fb9430f0e1bad25938ae2c\"},\"headline\":\"The business continuity plan is approved. What&#8217;s missing is someone who knows how to run it\",\"datePublished\":\"2026-07-31T17:27:27+00:00\",\"dateModified\":\"2026-07-31T17:27:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/\"},\"wordCount\":1668,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-33.jpg\",\"keywords\":[\"business continuity\",\"Cumplimiento Normativo\",\"ISO 22301\",\"resiliencia organizacional\",\"riesgo humano\"],\"articleSection\":[\"Blog\",\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/\",\"name\":\"Business continuity plan: who knows how to execute it\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-33.jpg\",\"datePublished\":\"2026-07-31T17:27:27+00:00\",\"dateModified\":\"2026-07-31T17:27:35+00:00\",\"description\":\"The business continuity plan gets approved and filed. ISO 22301 asks for competence and awareness, and those are the clauses that rarely get implemented.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/#primaryimage\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-33.jpg\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/hero-1-33.jpg\",\"width\":1376,\"height\":768,\"caption\":\"Sala de ensayo con las partituras abiertas sobre todos los atriles y las sillas vac\u00edas, atravesada por un haz de luz c\u00e1lida que entra por una ventana alta\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/business-continuity-plan-who-can-execute-it\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The business continuity plan is approved. What&#8217;s missing is someone who knows how to run it\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"name\":\"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/smartfense.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\",\"name\":\"SMARTFENSE\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"width\":241,\"height\":40,\"caption\":\"SMARTFENSE\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/f88c39d826fb9430f0e1bad25938ae2c\",\"name\":\"Carla Caggiano\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-Carla-Caggiano-96x96.png\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-Carla-Caggiano-96x96.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-Carla-Caggiano-96x96.png\",\"caption\":\"Carla Caggiano\"},\"description\":\"Ejecutiva en Gobierno, Riesgo y Cumplimiento (GRC), Seguridad de la Informaci\u00f3n y Continuidad del Negocio, con m\u00e1s de 8 a\u00f1os liderando equipos y proyectos en banca, salud y tecnolog\u00eda. Dise\u00f1a e implementa marcos basados en ISO 27001, ISO 22301 e ISO 31000, y traduce regulaciones complejas (SOX, NIST, GDPR, DORA, COBIT) en soluciones aplicables y sostenibles.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/carla-v-caggiano\\\/\"],\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/author\\\/carla\\\/\"}]}<\/script>\n ","yoast_head_json":{"title":"Business continuity plan: who knows how to execute it","description":"The business continuity plan gets approved and filed. ISO 22301 asks for competence and awareness, and those are the clauses that rarely get implemented.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/","og_locale":"en_US","og_type":"article","og_title":"Business continuity plan: who knows how to execute it","og_description":"The business continuity plan gets approved and filed. ISO 22301 asks for competence and awareness, and those are the clauses that rarely get implemented.","og_url":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/","og_site_name":"SMARTFENSE","article_published_time":"2026-07-31T17:27:27+00:00","article_modified_time":"2026-07-31T17:27:35+00:00","og_image":[{"width":1376,"height":768,"url":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-33.jpg","type":"image\/jpeg"}],"author":"Carla Caggiano","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Carla Caggiano","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/#article","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/"},"author":{"name":"Carla Caggiano","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/f88c39d826fb9430f0e1bad25938ae2c"},"headline":"The business continuity plan is approved. What&#8217;s missing is someone who knows how to run it","datePublished":"2026-07-31T17:27:27+00:00","dateModified":"2026-07-31T17:27:35+00:00","mainEntityOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/"},"wordCount":1668,"commentCount":0,"publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-33.jpg","keywords":["business continuity","Cumplimiento Normativo","ISO 22301","resiliencia organizacional","riesgo humano"],"articleSection":["Blog","Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/","url":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/","name":"Business continuity plan: who knows how to execute it","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/#primaryimage"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-33.jpg","datePublished":"2026-07-31T17:27:27+00:00","dateModified":"2026-07-31T17:27:35+00:00","description":"The business continuity plan gets approved and filed. ISO 22301 asks for competence and awareness, and those are the clauses that rarely get implemented.","breadcrumb":{"@id":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/#primaryimage","url":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-33.jpg","contentUrl":"https:\/\/smartfense.com\/file\/2026\/07\/hero-1-33.jpg","width":1376,"height":768,"caption":"Sala de ensayo con las partituras abiertas sobre todos los atriles y las sillas vac\u00edas, atravesada por un haz de luz c\u00e1lida que entra por una ventana alta"},{"@type":"BreadcrumbList","@id":"https:\/\/smartfense.com\/en\/blog\/business-continuity-plan-who-can-execute-it\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/smartfense.com\/en\/"},{"@type":"ListItem","position":2,"name":"The business continuity plan is approved. What&#8217;s missing is someone who knows how to run it"}]},{"@type":"WebSite","@id":"https:\/\/smartfense.com\/en\/#website","url":"https:\/\/smartfense.com\/en\/","name":"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad","description":"","publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/smartfense.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/smartfense.com\/en\/#organization","name":"SMARTFENSE","url":"https:\/\/smartfense.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","contentUrl":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","width":241,"height":40,"caption":"SMARTFENSE"},"image":{"@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/f88c39d826fb9430f0e1bad25938ae2c","name":"Carla Caggiano","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/file\/2026\/06\/cropped-Carla-Caggiano-96x96.png","url":"https:\/\/smartfense.com\/file\/2026\/06\/cropped-Carla-Caggiano-96x96.png","contentUrl":"https:\/\/smartfense.com\/file\/2026\/06\/cropped-Carla-Caggiano-96x96.png","caption":"Carla Caggiano"},"description":"Ejecutiva en Gobierno, Riesgo y Cumplimiento (GRC), Seguridad de la Informaci\u00f3n y Continuidad del Negocio, con m\u00e1s de 8 a\u00f1os liderando equipos y proyectos en banca, salud y tecnolog\u00eda. Dise\u00f1a e implementa marcos basados en ISO 27001, ISO 22301 e ISO 31000, y traduce regulaciones complejas (SOX, NIST, GDPR, DORA, COBIT) en soluciones aplicables y sostenibles.","sameAs":["https:\/\/www.linkedin.com\/in\/carla-v-caggiano\/"],"url":"https:\/\/smartfense.com\/en\/author\/carla\/"}]}},"_links":{"self":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/44204","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/users\/34"}],"replies":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/comments?post=44204"}],"version-history":[{"count":1,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/44204\/revisions"}],"predecessor-version":[{"id":44209,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/44204\/revisions\/44209"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media\/44201"}],"wp:attachment":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media?parent=44204"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/categories?post=44204"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/tags?post=44204"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}