Expert Advice Community

Guest

BC Plan

  Quote
Guest
Bills Created:   Mar 16, 2020 Last commented:   Mar 18, 2020

BC Plan

Hi 
I have implemented BCMS with one department/business unit as the scope and got certified as well. Now I am increasing my BCMS scope and I am done with the BIA with another dept. and now I am ready to make the strategy and plan for them. I need clarification on below points. I have initially made the BC strategy document for the business unit and is specific to them

Do I need to edit the same BC strategy document and add BC strategy for a new business unit or can I create a new BC strategy document for each department?
Do I need to write the workaround of the processes/activities which I recognise in BIA conducted with the departments, in the BC plan?

Can I have a single document of both the BC strategy and plan in a single document for each business unit?

Please advice

Thanks

 

 

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 18, 2020

Do I need to edit the same BC strategy document and add BC strategy for a new business unit or can I create a new BC strategy document for each department?

ISO 22301 does not prescribe how documents need to be developed, so organizations are free to develop them as best to fulfill their needs.

You can create a new BC strategy document for the new department, but you should evaluate if the effort to review and maintain two separate documents are worthy.

Both single and separated documents are accepted approaches. A single document is better to centralize strategies and make systemic review easier, but it can become too big and complex document to handle, while separated documents are easier to handle, but increases the administrative effort to review and maintain them.

A mixed approach would be to create a document with parts that are common for all strategies and then create separate documents with only the specifics of each department.

This article will provide you an idea about developing one o several documents:

This material can also help you with the business continuity strategy:

Do I need to write the workaround of the processes/activities which I recognize in BIA conducted with the departments, in the BC plan?

I'm assuming that by "workaround" you mean a temporary fix to be used as a bypass of a recognized problem.

ISO 22301 requires you to create strategy/solutions and BC plans based on the BIA results - therefore, this should not be a workaround, rather it should be the update of those documents (if you already have them).

These articles will provide you an idea about developing BCPs:

This material can also help you with the business continuity plan:

Can I have a single document of both the BC strategy and plan in a single document for each business unit?

This is acceptable considering compliance with ISO 22301, but during a disruption, you will need rather short and clear documents to execute (i.e. the BC plans), and if such documents also include the BCP strategy they will become unnecessarily complex and will be difficult to execute.  

Additionally, you also should evaluate if the effort to review and maintain two separate documents is worthy, and sometimes the business continuity strategy contains sensitive information that should not be shared together with the BCP document.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 16, 2020

Mar 18, 2020

Suggested Topics

Guest user Created:   May 15, 2019 ISO 27001 & 22301
Replies: 1
0 0

Best practice for BC Plans

Guest user Created:   Jun 08, 2021 ISO 27001 & 22301
Replies: 1
0 0

BC strategy and ISO 9001