Chapter 3: Business Continuity Planning
Understand the four steps of the business continuity planning process
- BC planning involves four distinct phases:
- project scope & planning
- business impact assessment
- continuity planning
- approval & implementation
- Each task contributes to the overall goal of ensuring that business operations continue uninterrupted in the face of an emergency situation.
Describe how to perform the business organisation analysis
- In the BOA, the individuals responsible for leading the BCP process determine which departments & individuals have a stake in the business continuity plan.
- This analysis used as the foundation for BCP team selection and, after validation by the BCP team, is used to guide the next stages of BCP development.
List the necessary members of the BCP team
- The BCP team should contain, at a minimum:
- representatives from each of the operational & support departments
- technical experts from the IT department
- physical & IT security personnel with BCP skills
- legal representatives familiar with corporate legal, regulatory & contractual responsibilities
- representatives from senior management
- Additional team members depend on the structure & nature of the organisation.
Know the legal & regulatory requirements that face BC planners
- Business leaders must exercise due diligence to ensure that shareholders’ interests are protected in the event disaster strikes.
- Some industries are also subject to federal, state & local regulations that mandate specific BCP procedures.
- Many businesses also have contractual obligations to their clients that must be met before & after a disaster.
Explain the steps of the BIA process [TODO]
- The five steps of the BIA process are:
- Identification of priorities
- Risk identification
- Likelihood assessment
- Impact assessment
- Resource prioritisation
Describe the process used to develop a continuity strategy
- During the strategy development phase, the BCP team determines which risks will be mitigated.
- In the provisions & processes phase, mechanisms and procedures that will mitigate the risks are designed.
- The plan must then be approved by senior management and implemented.
- Personnel must also receive training on their roles in the BCP process.
Explain the importance of fully documenting an organisation’s BC plan
- Committing the plan to writing provides the organisation with a written record of the procedures to follow when disaster strikes.
- It prevents the “it’s in my head” syndrome and ensures the orderly progress of events in an emergency.