Question about SMCA
Hello, I have a concern about the determination of activities, products and services. I would like to take a practical case of an organization whose sole activity is to operate and maintain the IT system of a bank. the Bank retains 3 critical processes that must never be interrupted: customer management, credit management, collection
We want to do the SMCA (Système de Management de la Continuité d'Activité) for the Bank's computer system. What to remember in the products and services of the SSSI (Société de Services en Systèmes d'Informations)?
i) Product: Computer System, Services: Management and maintenance of the Computer System, customer management, credit management, collection
ii) Product: IT system, Services: customer management, credit management, collection
iii) Product: Computer System, Services: Management and maintenance of the Computer System
Assign topic to the user
The proper way to identify which assets (e.g., products and services) you need to consider for ensuring the continuity of your customer process is by performing a Business Continuity analysis (BIA).
The BIA will help you identify how businesses are affected by disruptive events, and from this analysis, you can identify which assets (i.e., your products and services) you need to consider for the recovery efforts.
For further information, see:
- How to implement business impact analysis (BIA) according to ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/
- How to define activities when implementing business continuity according to ISO 22301 https://advisera.com/27001academy/blog/2013/11/11/how-to-define-activities-when-implementing-business-continuity-according-to-iso-22301/
Comment as guest or Sign in
Jul 31, 2023