SPRING DISCOUNT
Get 30% off on toolkits, course exams, and books.
Limited-time offer – ends May 26, 2022
Use promo code:
SPRING30

Expert Advice Community

Guest

BC strategy and plans

  Quote
Guest
Guest user Created:   Jan 10, 2017 Last commented:   Jan 10, 2017

BC strategy and plans

While working on BCMS for my organization I realized that there is a similarity between BC strategy and BC plan regarding the command center requirements (see 4.1.3 in BC strategy and 3.9 and BC plan). This makes me wonder where I will find such duplication and whether its necessary to fill in both documents.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jan 10, 2017

Answer: There is indeed similarity between BC strategy and BC plan because the BC plan is a detailing of BC strategy when specific situations are considered (you can see this difference in the section one of both documents - Purpose, scope and users). For example, in BC strategy you may identify the type of database to be available for all BC plans, and in each BC plan you will detail where this database is located (e.g., server, physical address, etc.) for each business unit or site that specific BC plan covers.

So, you will find this type of duplication in every situation where you need to define high level guidelines and these must be implemented in different ways for each interested party. For example, in the BC strategy you define the general RTO (Recovery Time Objective) and RPO (Recovery Point Objective) to be achieved by the organization, and each business plan define its own RTO and RPO considering its own scenario (e.g., IT systems, financial processes, etc.) and the strategic RTO and RPO to be achieved.

Regarding if you need to fill both documents, the main criteria to consider this is the number of different conditions and BC plans you have. If you have many plans and each one of them has different conditions, it is better you have a BC strategy document to define high level conditions.

This article will provide you further explanation about business continuity strategy and plans:
- Can business continuity strategy save your money? https://advisera.com/27001academy/blog/2010/03/15/can-business-continuity-strategy-save-your-money/
- Business continuity plan: How to structure it according to ISO 22301 https://advisera.com/27001academy/knowledgebase/business-continuity-plan-how-to-structure-it-according-to-iso-22301/

By the way, in the video tutorials that came with your toolkit, you will find information about BC strategy and how to fill out BC plans.
Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 09, 2017

Jan 09, 2017

Suggested Topics

Guest user Created:   Apr 06, 2022 ISO 27001 & 22301
Replies: 1
0 0

27001 question

Guest user Created:   Feb 18, 2021 ISO 27001 & 22301
Replies: 1
0 0

BCP Plans and procedures

Guest user Created:   Jun 09, 2020 ISO 27001 & 22301
Replies: 1
0 0

Business continuity