Business Continuity Management and Planning - The Key Processes

In order to implement and continually improve apotential risk points are to be assessed for either
healthy Business Continuity Management Program,mitigation or acceptance. Acceptance of risk
the following program attributes and processespoints should occur at the Senior Executive level.
are essential:Continuity Strategies
Structure & PolicyStrategies should be developed which reflect the
All organizations should maintain a managementrequirements identified in the BIA's. Strategies are
structure that has clear and documented rolesto be reviewed on an on-going basis to ensure
and responsibilities. The structure should supportthat they continue to remain effective in light of
the development of a program that is aligned tochanging business requirements.
the organizations Business Continuity ManagementBusiness Continuity Plans
Policy.Plans are to be developed, documented and
A common structure includes a Sponsor, amaintained to ensure that business continuity
Business Continuity Manager, and a Crisisstrategies can be readily actioned. The plans are
Management Team that consists of members ofto enable the resumption of critical business
the organizations Senior Management.functions at an alternate location(s) within agreed
Business Impact Analysis (BIA's)time periods.
BIA's should be conducted on all of theTesting & Exercising, Maintenance and Audit
organizations business units or areas. This analysisOngoing testing of the contingency capability
will determine the level of planning that is requiredshould be carried out in order to prove its overall
for each identified critical function, as well asfitness for purpose as defined by the BIA
define the maximum period of time theprocess, as well as to identify errors and issues
organization can tolerate the critical function notwith existing plans, documentation, and
being performed. The BIA will provide the cost /procedures. It is generally accepted that a BCP
impact justification necessary to support theshould be tested at least annually.
implementation of the various continuityActivate and Execution
strategies.The recovery capability is to be maintained in a
Threat and Risk Assessmentconstant state of readiness so as to provide the
The organization should undergo formal riskbest possible means of recovering from a
assessments of both Physical and Operationalcatastrophic incident affecting any of the
Risks on an on-going basis. Once identified,organizations locations.