ISO 22300

ISO 22300:2025 Security and resilience – Vocabulary, is an international standard developed by the International Organization for Standardization Technical Committee ISO/TC 292, Security and resilience, in collaboration with the European Committee for Standardization (CEN) Technical Committee CEN/TC 391, Societal and Citizen Security. This document defines terms used in security and resilience standards and includes 130 terms and definitions.[1] This document was first developed in 2012, with the first edition being released in May of 2012. [2] The current edition used was published in November of 2025 and replaces the third edition from 2021. [3]

This standard defines many relevant terms, including those pertinent to Business Continuity Management Systems (BCMS). The terms serve as a common language to identify and describe BCSM processes.[4]

This document is the first of a large series of ISO standards that focus on security, resilience, and business continuity management systems. The next document in the series, ISO 22301, focused more on writing management system standards, while the rest give more understanding to other security and system standards.[5]

The standard is divided into the following:

  • Scope
  • Normative references
  • Terms and definitions
    • Section 3.1: Terms related to security and resilience
    • Section 3.2: Terms related to risk
    • Section 3.3: Terms related to management system

Purpose

[edit]

The purpose of this standard is to provide definitions of generic terms and subject-specific terms related to documents made by ISO/TC 292. This document covers many of the standards seen throughout the ISO 223XX family. [6] The main focus is to encourage a mutual and consistent understanding and use of uniform terms and definitions in the field of security and resilience. [1]

Application

[edit]

This document can be used as a reference by competent authorities and specialists involved in standardization systems as a way to universally and accurately understand the topics shown.

[edit]
  • ISO 28000, Security and resilience — Security management systems – Requirements[7]
  • ISO 22301, Security and resilience — Business continuity management systems – Requirements[8]
  • ISO 22313, Security and resilience — Business continuity management systems – Guidance to the use of ISO 22301[9]
  • ISO/TS 22317, Security and resilience — Business continuity management systems — Guidelines for business impact analysis[10]
  • ISO 22320, Security and resilience — Emergency management - Guidelines for incident management[11]

History

[edit]

This standard was originally developed by the ISO Technical Committee ISO/TC 223 (Societal security) to set terms and definitions applicable to societal security.[2] The ISO/TC 223 later dissolved in June 2024, when the Technical management board (TMB) of ISO created the new ISO technical committee ISO/TC 292 (Security and resilience). [12] Since the 2nd Edition, this new technical committee has prepared ISO 22300.

The next version, the 4th Edition, is set to release in November of 2025 and is currently under development in the publication stage [13]

Released Description Main Changes From Previous Editions Number of Terms
May 2012 ISO 22300:2012 (1st Edition)[2] N/A 76
February 2018 ISO 22300:2018 (2nd Edition)[3]
  • Terms added from recent published documents and documents transferred to ISO/TC 292
277
February 2021 ISO 22300:2021 (3rd Edition)[1]
  • Terms added from recent published documents and documents transferred to ISO/TC 292
  • Terminological entries separated into subclauses by subject matter
360
November 2025 ISO 22300:2025 (4th Edition)[1]
  • Terms added from recent published documents and documents transferred to ISO/TC 292
  • Terminological entries separated into subclauses by subject matter
130

See also

[edit]

References

[edit]
  1. ^ a b c d "ISO 22300:2025(en) Security and resilience — Vocabulary". www.iso.org. Retrieved 2025-10-27.
  2. ^ a b c "ISO 22300:2012(en) Societal security — Terminology". www.iso.org. Retrieved 2025-10-27.
  3. ^ a b "ISO 22300:2018(en) Security and resilience — Vocabulary". www.iso.org. Retrieved 2025-10-27.
  4. ^ Arias Aranda, Daniel; Huafe, Knut; Dzombeta, Srdan; Vladimir, Stantchev (19 February 2025). "Business Continuity Management – a Process Reference Model". ssrn.com. Retrieved 26 October 2025.
  5. ^ "ISO publishes new standard for business continuity management". ISO. 2012-06-05. Retrieved 2025-10-27.
  6. ^ Kirvan, Paul (2024-01-20). "The ISO 223XX Standards – An Update". Risk and Resilience Hub. Retrieved 2025-10-27.
  7. ^ "ISO 28000:2022(en) Security and resilience — Security management systems — Requirements". www.iso.org. Retrieved 2025-10-27.
  8. ^ "ISO 22301:2019(en) Security and resilience — Business continuity management systems — Requirements". www.iso.org. Retrieved 2025-10-27.
  9. ^ "ISO 22313:2020(en) Security and resilience — Business continuity management systems — Guidance on the use of ISO 22301". www.iso.org. Retrieved 2025-10-27.
  10. ^ "ISO/TS 22317:2021(en) Security and resilience — Business continuity management systems — Guidelines for business impact analysis". www.iso.org. Retrieved 2025-10-27.
  11. ^ "ISO 22320:2018(en) Security and resilience — Emergency management — Guidelines for incident management". www.iso.org. Retrieved 2025-10-27.
  12. ^ "In retrospect". committee.iso.org. Retrieved 2025-10-27.
  13. ^ "ISO 22300". ISO. Retrieved 2025-10-27.
[edit]
  • ISO 22300:2018 — Security and resilience — Vocabulary (Withdrawn, revised by ISO 22300:2021)
  • ISO 22300:2021 — Security and resilience — Vocabulary