ISO 22300
ISO 22300:2021 Security and resilience – Vocabulary, is an international standard developed by the International Organization for Standardization Technical Committee ISO/TC 292, Security and resilience, in collaboration with the European Committee for Standardization (CEN) Technical Committee CEN/TC 391, Societal and Citizen Security. This document defines terms used in security and resilience standards and includes 360 terms and definitions.[1] This document was first developed in 2012, with the first edition being released in May of 2012. [2] The current edition used was published in February of 2021 and replaces the second edition from 2018. [3] The next version is set to release in November of 2025. [4] This standard defines many relevant terms, including those pertinent to Business Continuity Management Systems (BCMS). The terms serve as a common language to identify and describe BCSM processes.[5]
This document is the first of a large series of ISO standards that focus on security, resilience, and business continuity management systems. The next document in the series, ISO 22301, focused more on writing management system standards, while the rest give more understanding to other security and system standards.[6]
The standard is divided into the following:
- Scope
- Normative References
- Terms and Definitions
- Section 3.1: Security and Resilience
- Section 3.2: Counterfeiting Tax Stamps
- Section 3.3: Supply Chain
- Section 3.4 CCTV
Scope and Contents
[edit]ISO 22300:2021 contains definitions for the following terms [1]:
Section 3.1 (Security and Resilience):
[edit]- access
- activity
- adhesive
- affected area
- after-action report
- alert
- all clear
- all-hazards
- alternate worksite
- analysis area
- analysis system
- area at risk
- asset
- audit
- auditor
- basic social services
- benefit
- biodiversity
- business continuity
- business continuity management
- business continuity management system
- business continuity plan
- business continuity programme
- business impact analysis
- capacity
- carer
- cargo transport unit
- CCTV system
- challenge
- civil protection
- civil society
- civil society organization
- client
- colour blindness
- colour-code
- command and control
- command and control system
- communication and consultation
- community
- community-based early warning system
- community vulnerability
- competence
- complexity
- conformity
- consequence
- context
- contingency
- continual improvement
- continuity
- control
- cooperation
- coordination
- correction
- corrective action
- counterfeit
- counterfeit good
- countermeasure
- coverage
- crisis
- crisis management
- crisis management team
- critical control point
- critical customer
- critical facility
- critical indicator
- critical product and service
- critical supplier
- criticality analysis
- critically
- data analysis
- decentralized authority
- disaster
- disaster risk reduction
- disruption
- disruptive event
- document
- documented information
- drill
- duty-bearer
- duty of care
- early warning
- economic diversity
- ecosystem
- ecosystem services
- effectiveness
- emergency
- emergency management
- emergency management capability
- employee assistance programme
- entity
- evacuation
- evacuation command
- evacuation drill
- evaluation
- event
- exercise
- exercise annual plan
- exercise coordinator
- exercise programme
- exercise programme manager
- exercise project team
- exercise safety officer
- external attack
- facility
- forensic
- full-scale exercise
- functional exercise
- geo-location
- hazard
- hazard monitoring function
- host
- hue
- human interpretation
- human rights
- human rights risk analysis
- identification
- impact
- impact analysis
- impartiality
- improvisation
- incident
- incident command
- incident management system
- incident preparedness
- incident response
- information
- infrastructure
- inherently dangerous property
- inject
- integrity
- interested party
- internal attack
- internal audit
- international supply chain
- interoperability
- investment
- invocation
- key performance indicator
- landslide
- likelihood
- logical structure
- management
- management plan
- management system
- management system consultancy and/or associated risk assessment
- mass movement
- material good
- material good life cycle
- maximum tolerable period of disruption
- measurement
- minimum business continuity objective
- mitigation
- monitoring
- monitoring process owner
- mutual aid agreement
- nominated emergency contact
- nonconformity
- notification
- object
- objective
- observer
- operational information
- organization
- organizational culture
- organizational resilience
- outsource
- owner
- parameter
- participant
- partnering
- partnership
- peer review
- people aspects of business continuity
- people at risk
- performance
- performance evaluation
- personnel
- planning
- policy
- preparedness
- prevention
- prevention of hazards and threats
- preventive action
- prioritized activity
- private security service provider
- probability
- procedure
- process
- product and service
- product fraud
- protection
- psychological critical incident
- psychological education
- psychological first aid
- public warning
- public warning system
- raw material
- record
- recovery
- recovery point objective
- recovery time objective
- requirement
- residual risk
- resilience
- resource
- response plan
- response programme
- response team
- review
- review visit
- reviewer
- rights holder
- risk
- risk acceptance
- risk analysis
- risk appetite
- risk assessment
- risk communication
- risk criteria
- risk evaluation
- risk identification
- risk management
- risk mitigation
- risk owner
- risk reduction
- risk register
- risk sharing
- risk source
- risk tolerance
- risk treatment
- robustness
- scenario
- scope of exercise
- scope of service
- script
- secret
- security
- security aspect
- security cleared
- security declaration
- security incident
- security management
- security management objective
- security management policy
- security management programme
- security management target
- security operation
- security operations management
- security operations objective
- security operations personnel
- security operations policy
- security operations programme
- security personnel
- security plan
- security sensitive information
- security threat scenario
- self-defence
- sensitive information
- shelter in place
- shock
- simulation
- social protection
- source
- spontaneous volunteer
- strategic exercise
- stress
- subcontracting
- supply chain
- supply chain continuity management
- target
- target group
- test
- testing
- threat
- threat analysis
- top management
- training
- undesirable event
- urban agglomeration
- urban open area
- urban resilience
- urban system
- use of force continuum
- values
- verification
- video-surveillance
- vulnerability
- vulnerability assessment
- vulnerable group
- vulnerable person
- warning dissemination function
- work environment
- workforce
- World Customs Organization
Section 3.2 (Counterfeiting Tax Stamps):
[edit]- activation
- alteration
- applicable tax
- attack
- attribute
- attribute data management system
- authentic material good
- authentication
- authentication element
- authentication function
- authentication solution
- authentication tool
- authoritative source
- automated interpretation
- covert authentication element
- custodian copy
- direct marking
- false acceptance rate
- false rejection rate
- forensic analysis
- identifier
- identity
- illicit product
- inspector
- inspector access history
- integrated authentication element
- intrinsic authentication element
- lead interested party
- object examination function
- off-the-shelf authentication tool
- online authentication tool
- overt authentication element
- purpose-built authentication tool
- specifier
- stand-alone authentication tool
- substrate
- tamper evident
- tax authority
- tax stamp
- tax stamp applier
- tax stamp interested party
- trusted query processing function
- trusted verification function
- unique identifier
Section 3.3 (Supply Chain):
[edit]- appropriate law enforcement and other government officials
- authorized economic operator
- business partner
- certified client
- conveyance
- custody
- downstream
- goods
- organization in the supply chain
- tier 1 supplier
- tier 2 supplier
- track and trace
- upstream
Section 3.4 (CCTV):
[edit]- dynamic metadata
- metadata
- scene location
- semantic interoperability
- static metadata
- syntactic interoperability
Purpose
[edit]The purpose of this standard is to provide definitions of generic terms and subject-specific terms related to documents made by ISO/TC 292. This document covers many of the standards seen throughout the ISO 223XX family. [7] The main focus is to encourage a mutual and consistent understanding and use of uniform terms and definitions in the field of security and resilience. [1]
Application
[edit]This document can be used as a reference by competent authorities and specialists involved in standardization systems as a way to universally and accurately understand the topics shown.
Related standards
[edit]- ISO 28000, Security and resilience — Security management systems – Requirements[8]
- ISO 22301, Security and resilience — Business continuity management systems – Requirements[9]
- ISO 22313, Security and resilience — Business continuity management systems – Guidance to the use of ISO 22301[10]
- ISO/TS 22317, Security and resilience — Business continuity management systems — Guidelines for business impact analysis[11]
- ISO 22320, Security and resilience — Emergency management - Guidelines for incident management[12]
History
[edit]This standard was originally developed by the ISO Technical Committee ISO/TC 223 (Societal security) to set terms and definitions applicable to societal security.[2] The ISO/TC 223 later dissolved in June 2024, when the Technical management board (TMB) of ISO created the new ISO technical committee ISO/TC 292 (Security and resilience). [13] Since the 2nd Edition, this new technical committee has prepared ISO 22300.
The next version, the 4th Edition, is set to release in November of 2025 and is currently under development in the publication stage [4]
| Released | Description | Main Changes From Previous Editions | Number of Terms |
|---|---|---|---|
| May 2012 | ISO 22300:2012 (1st Edition)[2] | N/A | 76 |
| February 2018 | ISO 22300:2018 (2nd Edition)[3] |
|
277 |
| February 2021 | ISO 22300:2021 (3rd Edition)[1] |
|
360 |
See also
[edit]- International Organization for Standardization
- List of ISO Standards
- Security
- Resilience
- Risk Management
- Management System
- ISO/TC 292
References
[edit]- ^ a b c d "ISO 22300:2021(en) Security and resilience — Vocabulary". www.iso.org. Retrieved 2025-10-27.
- ^ a b c "ISO 22300:2012(en) Societal security — Terminology". www.iso.org. Retrieved 2025-10-27.
- ^ a b "ISO 22300:2018(en) Security and resilience — Vocabulary". www.iso.org. Retrieved 2025-10-27.
- ^ a b "ISO 22300". ISO. Retrieved 2025-10-27.
- ^ Arias Aranda, Daniel; Huafe, Knut; Dzombeta, Srdan; Vladimir, Stantchev (19 February 2025). "Business Continuity Management – a Process Reference Model". ssrn.com. Retrieved 26 October 2025.
- ^ "ISO publishes new standard for business continuity management". ISO. 2012-06-05. Retrieved 2025-10-27.
- ^ Kirvan, Paul (2024-01-20). "The ISO 223XX Standards – An Update". Risk and Resilience Hub. Retrieved 2025-10-27.
- ^ "ISO 28000:2022(en) Security and resilience — Security management systems — Requirements". www.iso.org. Retrieved 2025-10-27.
- ^ "ISO 22301:2019(en) Security and resilience — Business continuity management systems — Requirements". www.iso.org. Retrieved 2025-10-27.
- ^ "ISO 22313:2020(en) Security and resilience — Business continuity management systems — Guidance on the use of ISO 22301". www.iso.org. Retrieved 2025-10-27.
- ^ "ISO/TS 22317:2021(en) Security and resilience — Business continuity management systems — Guidelines for business impact analysis". www.iso.org. Retrieved 2025-10-27.
- ^ "ISO 22320:2018(en) Security and resilience — Emergency management — Guidelines for incident management". www.iso.org. Retrieved 2025-10-27.
- ^ "In retrospect". committee.iso.org. Retrieved 2025-10-27.
External links
[edit]- ISO 22300:2018 — Security and resilience — Vocabulary (Withdrawn, revised by ISO 22300:2021)
- ISO 22300:2021 — Security and resilience — Vocabulary