Get 2 Documentation Toolkits for the price of 1
Limited-time offer – ends March 28, 2024

Expert Advice Community

Guest

BCM policy and a DR policy

  Quote
Guest
Guest user Created:   Apr 04, 2019 Last commented:   Apr 04, 2019

BCM policy and a DR policy

I would like to know and understand the difference between a BCM policy and a DR policy. I am trying to develop a BCM policy for my organisation so i would like to understand if i need to have both the 2 policies in place or just one.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 04, 2019

Answer:

First it is important to note that both Business Continuity Management (BCM) policy and Disaster Recovery (DR) policy are top-level documents, covering management intentions. For operational purposes, i.e., detailed step-by-step activities and responsibilities, you also have to consider Business Continuity (BC) plans and Disaster Recover (DR) plans.

Considering that, the Business Continuity Management (BCM) policy is a more comprehensive document, covering management intentions regarding keeping processes and services running at minimum agreed levels after a disruptive event, and returning them to normal operation as quick as possible, while the Disaster Recovery (DR) policy focuses on management intentions regarding only the recovery of infrastructure (e.g., physical and IT infrastructure).

Reg arding documentation, you can have a single document to cover both issues, being the DR policy a section of the BCM policy.

These articles will provide you further explanation about BCM and DR in the context of ISO 22301, the ISO standard for business continuity management:
- What is ISO 22301 https://advisera.com/27001academy/what-is-iso-22301/
- The purpose of Business continuity policy according to ISO 22301 https://advisera.com/27001academy/blog/2013/06/04/the-purpose-of-business-continuity-policy-according-to-iso-22301/
- Disaster recovery vs Business continuity https://advisera.com/27001academy/blog/2010/11/04/disaster-recovery-vs-business-continuity/
- Business continuity plan: How to structure it according to ISO 22301 https://advisera.com/27001academy/knowledgebase/business-continuity-plan-how-to-structure-it-according-to-iso-22301/

This material will also help you regarding BCM and DR:
- Book Becoming Resilient: The Definitive Guide to ISO 22301 Implementation https://advisera.com/books/becoming-resilient-the-definitive-guide-to-iso-22301-implementation/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 04, 2019

Apr 04, 2019

Suggested Topics

Guest user Created:   Nov 10, 2022 ISO 27001 & 22301
Replies: 1
0 0

BCM policy

Guest user Created:   Feb 20, 2020 ISO 27001 & 22301
Replies: 1
0 0

BCM framework and policy

Guest user Created:   Sep 25, 2019 ISO 27001 & 22301
Replies: 1
0 0

BCM policy gap analysis