Reference Glossary
Business continuity plan
A documented plan for keeping critical operations — including access to the DAM and its assets — running during and after a disruption such as an outage, cyberattack, or natural disaster.
Why it matters in a DAM
Companies whose e-commerce, publishing, or campaign operations depend on the DAM to serve live imagery treat a DAM outage during a launch as a business continuity event, not an IT ticket. A business continuity plan forces the organization to name a fallback for asset delivery — a CDN cache, a local mirror, a pre-exported package of critical assets — before an incident, instead of improvising while a product launch is stalled. ISO 22301 is the reference standard most enterprises use to structure and audit such plans.
A worked example
Common mistake
Plans get written once to satisfy an audit or enterprise procurement checklist and are never rehearsed, so when an incident hits, nobody actually knows the manual steps to swap a broken DAM link for the static fallback.
A business continuity plan (BCP) is the organizational answer to “what do we do while the primary system is down,” as distinct from disaster recovery, which is the technical answer to “how do we get the primary system back.” For a company whose DAM feeds live product pages, syndicated marketplace listings, or an active ad campaign, the two are tightly linked: the BCP has to specify how imagery keeps flowing to customer-facing channels for the hours or days it takes to restore the DAM itself.
ISO 22301:2019 is the international standard for business continuity management systems. It defines business continuity as an organization’s capacity to keep delivering products and services, at a predefined capacity, within acceptable timeframes, during a disruption — and it requires the plan to be tested and improved, not just documented. Enterprise DAM buyers in regulated or high-revenue-risk industries increasingly ask vendors whether their own continuity practices are ISO 22301-aligned, and separately need their own internal plan for the case where the vendor itself is the point of failure.
In practice, a DAM-relevant BCP names specific fallbacks: which renditions are cached at the CDN edge and will keep serving even if the origin DAM is unreachable, which small set of business-critical assets (current-season product shots, active campaign creative) are kept in a manually maintained backup location outside the DAM, and who has authority to redirect systems to that fallback without waiting for a change-approval process that assumes normal operating conditions.
Frequently asked
How is a business continuity plan different from disaster recovery?
A BCP is the organizational answer to "what do we do while the primary system is down"; disaster recovery is the technical answer to "how do we get the primary system back."
What does ISO 22301 require of a business continuity plan?
It defines business continuity as the capacity to keep delivering products and services, at a predefined capacity, within acceptable timeframes during a disruption, and requires the plan to be tested and improved, not just documented.
What kind of DAM outage does a BCP treat as a continuity event?
A BCP treats a continuity event as a DAM outage where the platform is fully unavailable beyond a defined threshold — not a brief blip that resolves in minutes, but a sustained outage that blocks critical processes like publishing to e-commerce or letting the team retrieve assets during a live launch or active campaign. Below that threshold, it's an IT ticket, not a continuity trigger.
What fallbacks might a DAM-relevant BCP specify?
Which renditions are cached at the CDN edge to keep serving if the origin DAM is down, and which business-critical assets are kept in a manually maintained backup location outside the DAM.
What's the most common failure with business continuity plans?
The most common failure is a plan written once to satisfy an audit or procurement checklist, then never tested or updated again. Employees often don't know the plan exists, and by the time an incident actually hits, it describes infrastructure and contacts that no longer match reality — so nobody follows the documented steps, because the steps are stale.
Who should have authority to activate a BCP's fallback during an incident?
Authority should sit with a specific person or role named in the plan ahead of time, not decided in the moment during the incident. That named authority can redirect systems to the fallback immediately, bypassing the change-approval process built for normal operating conditions. Without a pre-designated owner, teams lose critical time arguing over who is even allowed to make the call.
Sources
- ISO 22301:2019 is the international standard for business continuity management systems (BCMS), defining requirements for organizations to prepare for, respond to, and recover from disruptive incidents. checked 2026-08-07 — ISO