The policy should:
Establishing the Business Continuity Policy - General Principles
Establishing the Business Continuity Policy - Process
Establishing the Business Continuity Policy - Outcomes
Defining the Scope of the Business Continuity Programme - General Principles
Defining the Scope of the Business Continuity Programme - Process
Defining the Scope of the Business Continuity Programme - Methods & Techniques
The outcome is a clearly-defined scope for the business continuity programme, which can be validated to ensure that the objectives of the business continuity policy are being met.
Defining the Scope of the Business Continuity Programme - Outcomes
Governance activities should include monitoring and measuring progress against key performance indicators (KPI) to confirm that the business continuity policy and programme is being implemented effectively and is aligned with organisational objectives and strategy.
There are several sources of guidance for business continuity professionals on how to develop, manage, implement, and review a business continuity programme.
The international standard for business continuity management ISO 22301:2012, identifies management and governance processes for operating, monitoring, reviewing and continually improving a business continuity management system.
Requirements for governance of business continuity are also provided in national or international standards, legislation, regulations, or industry sector specific guidelines.
Regulations in some sectors may require formal demonstration of effective business continuity management to the organisation’s top management.
Establishing Governance - General Principles
An understanding of the organisational structure, requirements, roles and responsibilities, and reporting lines to support the implementation and ongoing management of the business continuity policy and programme.
A clear definition of the authority and accountabilities relating to business continuity:
Examples of high-level metrics are:
Establishing Governance - Process
The organisation’s top management should agree:
To do this, top management should:
Establishing Governance - Outcomes
The purpose of assigning roles and responsibilities is to ensure that the tasks required to implement and maintain the business continuity programme are allocated to specific, competent individuals whose performance can be evaluated and where further training requirements can be identified.
The training and competency requirements for the business continuity professional and wider programme are covered in Embedding Business Continuity.
Top management should assign accountability, responsibility, and authority to designated teams or individuals to ensure that appropriate procedures are adopted and properly implemented in accordance with the requirements of the policy.
Top management should also ensure that these roles are communicated to the relevant interested parties.
Top management should ensure individuals carry out their roles as appropriate within the organisation.
Where the individuals are assigned business continuity responsibilities in addition to their existing role, the new responsibility should be added to their job description and communicated to all interested parties.
The performance of these individuals should be measured as part of the Validation stage of the business continuity management lifecycle on an ongoing basis.
Assigning Roles & Responsibilities - General Principles
A competent individual should be identified and appointed to manage the implementation of the business continuity policy and programme.
Depending on the size of the organisation, this may be a full or part time role.
Additional individuals or teams may be assigned to assist with the ongoing management and delivery of the business continuity programme.
These could include:
A business continuity steering group to give advice, guidance, and oversight.
Teams that will respond to an incident and that can contribute towards developing the incident response plans.
Assigning Roles & Responsibilities - Process
The outcome of assigning roles and responsibilities as part of business continuity policy and programme management are:
Assigning Roles & Responsibilities - Outcomes
The business continuity programme is an ongoing process, which adapts in response to the changing nature of an organisation’s internal and external operating environment.
Implementing a programme for the first time should involve undertaking all activities detailed in the business continuity management lifecycle, however revisions to the programme will likely involve less activity if there is no significant change in the organisation’s requirements.
During the initial implementation, sufficient time should be allocated to undertake the activities in each stage of the business continuity management lifecycle.
A flexible and comprehensive programme that is actively managed should be in place to ensure the organisation maintains its business continuity capability and continues to develop and enhance organisational resilience.
The Business Continuity Programme - General Principles
Implementing and managing the programme involves managing many interrelated tasks to achieve the objectives stated in the policy.
The business continuity professional or team, in consultation with top management should:
The Business Continuity Programme - Process
A business continuity management programme consists of the following:
The Business Continuity Programme - Outcomes
The Business Continuity Programme - Documentation