ISO 22301 and ISO 20000-1 Training

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

Our ISO 22301 training prepares teams to build, exercise and audit a business continuity management system, and our ISO/IEC 20000-1 courses do the same for IT service management. SSC delivers Foundation, Internal Auditor, Lead Implementer and Lead Auditor courses, plus hands-on business impact analysis and crisis exercise workshops, live online or on-site.

Team in a crisis simulation exercise around a table with a screen showing amber alerts, representing ISO 22301 business continuity training
Exercises turn continuity plans into practised responses.

Courses at a glance

CourseTypical durationBest for
ISO 22301 Foundation2 daysContinuity coordinators, risk, operations and IT staff
Business impact analysis workshop1 dayBusiness unit leaders and continuity champions
Crisis and continuity exercise design1 dayTeams that plan and facilitate exercises
ISO 22301 Internal Auditor / Lead Auditor3 days / 5 daysInternal and professional auditors
ISO 22301 Lead Implementer5 daysBCM managers building a BCMS
ISO/IEC 20000-1 Foundation, Internal Auditor and Lead Auditor2, 3 and 5 daysIT service managers and service desk leads

ISO 22301 business continuity training

ISO 22301 specifies the requirements for a business continuity management system (BCMS). Our courses follow its core cycle: understand the organisation through a business impact analysis and risk assessment, choose continuity strategies and solutions, write plans and procedures, exercise and test them, and evaluate and improve. ISO 22313 provides the guidance that sits alongside it.

  • Business impact analysis: prioritised activities, maximum tolerable period of disruption, recovery time and recovery point objectives, and dependencies on people, sites, technology and suppliers.
  • Strategies and plans: workarounds, alternate sites, technology recovery, supplier continuity, and crisis communication.
  • Exercising: discussion-based tabletop exercises through to full simulations, with objectives, injects, observers and after-action reports.

Who should attend ISO 22301 training

  • Business continuity, resilience and crisis management managers
  • Risk, operations and IT disaster recovery leads
  • Business unit continuity champions who own plans for their area
  • Internal auditors and assurance teams reviewing continuity arrangements

For APRA-regulated entities, we connect continuity training with CPS 230 requirements for critical operations, tolerance levels and annual business continuity plan testing.

ISO/IEC 20000-1 IT service management training

IT service management training with participants at dual monitors wearing headsets, representing ISO 20000-1 training
ISO/IEC 20000-1 brings management system discipline to IT service delivery.

ISO/IEC 20000-1 sets the requirements for a service management system. Our courses cover service planning, the service catalogue, service level management, supplier management, incident and problem management, change and release, capacity and availability, and service continuity. They also show how ISO 20000-1 complements ITIL practices that many service desks already use, and how it supports managed service providers proving service quality to customers.

Recovery that works when it matters

Two engineers in a data centre aisle reviewing a recovery checklist on a tablet, representing disaster recovery and continuity training
Recovery objectives only count once they have been tested end to end.

Every ISO 22301 training course includes practical work. Participants practise with realistic scenarios such as ransomware on a core system, loss of a key site or failure of a critical supplier. They set recovery objectives, map dependencies, test a plan in a tabletop exercise and write the after-action report.

How the ISO 22301 and ISO 20000-1 training is delivered

  • Live online. Instructor-led virtual classes over Microsoft Teams or Zoom, with breakout exercises, shared workbooks and the option to split longer courses into half-day sessions across a week or two.
  • On-site at your premises. Private training for your team at your office, delivered by a consultant who can use your own policies, systems and examples in the exercises.
  • Private and tailored. Every course can be run for a single organisation, with case studies drawn from your sector and the depth adjusted to your team’s experience.

We can also facilitate your organisation’s own annual continuity exercise as part of the training.

What participants receive

  • A course workbook and the slides used in class
  • Reusable templates and checklists, such as audit checklists, risk registers and report formats, depending on the course
  • A case study pack and practice questions
  • A certificate of completion from Security Solution Consultants

Certificates and accredited exams

Every participant who completes a course receives a certificate of completion from Security Solution Consultants. Lead Auditor and Lead Implementer courses can include an accredited certification exam through our accredited training partner, for standards where the partner offers one. Your quote confirms the exam body, exam format and certificate for each course, so there are no surprises on the day.

Why train with SSC

  • Taught by practitioners. Our trainers are working consultants and auditors who build continuity programmes, run crisis exercises and audit management systems for clients, so examples come from real engagements rather than slides.
  • We hold ourselves to the same standard. SSC is certified to ISO/IEC 27001 and follows a Secure by Design approach. See our Trust Centre.
  • Hands-on with real tools. Exercises can use GRCLens, the GRC platform built by SSC, so participants practise with risk registers, control libraries and evidence the way they will at work.
  • Training that connects to delivery. If your team needs help after the course, the same people can support implementation, internal audits and certification readiness.

Related: our business continuity management services, incident response and recovery, and the GRCLens ISO 22301 and ISO 20000 modules. See all training courses.

Frequently asked questions

The requirements of a business continuity management system: business impact analysis, risk assessment, continuity strategies, plans, exercising and testing, performance evaluation and improvement.

Yes. We design and facilitate tabletop and simulation exercises, and can combine them with training so your team learns while testing real plans.

ISO 22301 covers continuity of the whole organisation's prioritised activities. ISO/IEC 20000-1 covers the management of IT services, including service continuity and availability as one part.

No. ITIL is a body of good practice guidance; ISO/IEC 20000-1 is a certifiable set of requirements. Organisations often use ITIL practices to meet ISO 20000-1 requirements.

Yes. We relate continuity concepts to CPS 230 requirements for critical operations, tolerance levels and annual testing of business continuity plans.

Plan ISO 22301 and ISO 20000-1 training for your team

Tell us how many people need training, which courses interest you, and whether you prefer live online or on-site delivery. We will come back with a tailored proposal and quote.

Prefer email? Write to info@secsolutionshub.com