SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

BCMS scope

  Quote
Guest
Guest user Created:   May 30, 2018 Last commented:   May 30, 2018

BCMS scope

I am an Information Security Officer in a retail industry company with hypermarkets and malls in XXXX. My company is in retail industry and our core business is providing and selling goods to our customers in these hypermarkets through Point of Sales terminals. We are also doing online E-Commerce through our website.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 30, 2018

Our company has different department like
1)HR
2)Finance
3)IT
4)Facility Management
5)Admin
6)Operation
7)legal

I am implementing ISO 22301 and I need to do the scoping of the BCMS. Can you please advice me how I should perform this tasks? What are the things that I should consider while scoping and what departments should I include in scope of BCMS?

Answer: To define the BCMS scope you first need to identify the organizational context (e.g., external and internal aspects that can be severely impacted by disruptive events, business objectives, the BCMS purpose, etc.)

After that you have to define the interested parties to your BCMS and their requirements, as well as legal and regulatory requirements that must be fulf illed by your organization.

With this information you can define your BCMS in terms of products, services, and processes that must have their continuity ensured during a disruptive event. The identification of departments to be included will depend on the previously listed elements.

Quote
0 0
Guest
Bills May 30, 2018

Thank you Dejan for your reply.
Being a retail industry and having several malls and hypermarkets in the region, can I make the choice of BCMS in terms of services and processes only ignoring the location aspects. Because my company has several hypermarkets in the region and setting a redundant hypermarket during a disaster would not be possible as it may incur complexity and more cost.
After analyzing the interested parties and their expectations , can I define a scope which is will involve my core business process ( which is selling products through Point of Sales) and processes/dept. which support this core business process(Point of Sales). Can I take that approach?
Please advice

Quote
0 0
Expert
Rhand Leal Jun 01, 2018

When defining a BCMS scope you have to define the location where your business processes are performed, but you can limit them the way you wish, so there is no need to include all locations you have. An example of scope text considering your stated information is:

"The BCMS scope is the selling products process performed by the Point of Sales department in the following malls and hypermarkets: [list here the addresses of the units that will be part of the BCMS scope]."

Quote
0 0
Guest
Bills Jun 02, 2018

Thanks rhandleal for the reply.
For the certification purpose can I include in scope only IT dept and its services to start with and then in future include other dept. in the BCMS scope. My limitation is that management have given me 6 months target for getting the ISO 22301 certification.
Could it be possible that initially i will take only IT dept. in BCMS scope? Please advice

Quote
0 0
Expert
Rhand Leal Jun 05, 2018

First it is important to understand that the objective of continuity management is to ensure the continuity of processes and services impacted by disruptive events, which can cover one or more organizational units.

Considering that, you can define your scope to cover only the IT department, and expand the scope to other departments later, but you have to ensure that at this initial phase the services in the scope have little relation with, or dependency on, other departments.

Regarding your 6 month deadline, without more details about the size and complexity of your IT services, it is not possible to tell if this time frame is enough.

Quote
0 0
Guest
Bills Jun 05, 2018

Thanks Rhandleal for the reply.
Well I have decided that I will be taking my Operation dept. in scope as this dept. handles our core business which is daily sales and revenue. The business processes within this dept. is core business processes. Now if I took this dept. in scope aloing with IT dept. , do I need to perform the BIA of IT as well ? I need to write a BCP plan for my operation dept., Do I need to write the BCP for IT dept. as well?
If my scope will be a business dept. which handles my core business process and IT dept. is just an enabler for operation dept. , do I need to perform all the activities like BIA , RA and BC Strategy and BCP for IT as well.? or BIA ,RA and BCP for operations dept. will be enough.
Please advice

Thanks

Quote
0 0
Expert
Rhand Leal Jun 07, 2018

As mentioned in the previous answer, you have to think in terms of processes instead of organizational units. You have to perform the BIA and RA considering all elements that can impact your sales process, i.e., your operation department and the IT department (if one of these departments is down due to a disruptive event your process will be interrupted).

Regarding the BCP strategy and BCP itself, you have to consider the results of BIA and RA to define for which departments you will have to develop them (most probably you will have to elaborate BCP strategies and BCPs for both departments).

These materials will also help you regarding performing BIA and elaborating BCP:
- ISO 22301 Case study in the travel industry: Business continuity as a necessity in customer care https://advisera.com/27001academy/blog/2016/11/07/iso-22301-case-study-in-the-travel-industry-business-continuity-as-a-necessity-in-customer-care/
- How to implement business impact analysis (BIA) according to ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/
- Implementing Business Impact Analysis according to ISO 22301 [free webinar on demand] https://advisera.com/27001academy/webinar/implementing-business-impact-analysis-according-to-iso-22301-free-webinar-on-demand/
- Developing the business continuity strategy according to ISO 22301 [free webinar on demand] https://advisera.com/27001academy/webinar/developing-the-business-continuity-strategy-according-to-iso-22301-free-webinar-on-demand/
- Business continuity plan: How to structure it according to ISO 22301 https://advisera.com/27001academy/knowledgebase/business-continuity-plan-how-to-structure-it-according-to-iso-22301/
- Writing a business continuity plan according to ISO 22301 [free webinar on demand] https://advisera.com/27001academy/webinar/writing-a-business-continuity-plan-according-to-iso-22301-free-webinar-on-demand/

Quote
0 1
Guest
Bills Jun 08, 2018

Thanks rhandleal for the great reply. I appreciate your help and support. Now I understood that I should stress on processes rather than dept. but for the matter of scope and because I have to face the cert. audit, I need to mention the dept. in scope document.
With that being said, I will perform the BIA and RA for both the dept.'s in the as a start of my enterprise BCMS , and then include other processes /dept. in scope in future.
Also can u please share ur email address so that in case i need some advice I can write to you.
U have been a great help mate. Can I ask for more advice and suggestions in future course of my project? Please advice.
Thanks

Quote
0 0
Expert
Rhand Leal Jun 11, 2018

You can always sent your doubts to our Free Consultation Page at this link: https://advisera.com/27001academy/consultation/

From there, not only me but other ISO 22301 experts can help you with your project.

To make your effort easier and have access to even more specialized support, I suggest you to take a look at our ISO 22301 implementation toolkit at this link: https://advisera.com/27001academy/iso22301-documentation-toolkit/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 30, 2018

Jun 11, 2018