1. ISO 22301:2019, Security and resilience — Business continuity management systems — Requirements. International Organization for Standardization. Section 0.3, "Plan-Do-Check-Act (PDCA) model", states for "Plan": "establish business continuity policy, objectives, controls, processes and procedures relevant to improving business continuity in order to deliver results that align with the organization’s overall policies and objectives."
2. Heng, G. M. (2021). Business Continuity Management System: A Complete Guide to Organizational Resilience (ISO 22301). IT Governance Publishing. Chapter 3, "The Plan-Do-Check-Act (PDCA) cycle," details how the Plan phase (Clauses 4, 5, 6, and 7) is used to establish the BCMS.
3. Ab-Al-Hameed, H. A., Al-Shargabi, B., & Al-Mekhlafi, A. A. (2021). Implementation of Business Continuity Management System according to ISO 22301: A case study in a university. International Journal of Information Management Data Insights, 1(2), 100041. Section 3.1, "Plan Phase," describes this stage as where "the BCMS policy, objectives, processes, and procedures are established." https://doi.org/10.1016/j.jjimei.2021.100041