Skip to content

Working in the Business Continuity Management domain

In the Business Continuity Management (BCM) domain, you can map components of a Business Continuity Management System (BCMS) in order to control and manage them with the help of tools.

Close integration with the Information Security Management System (ISMS) in verinice allows you to leverage synergies and avoid redundant documentation.

  • Get to know the BCM domain.
  • Define the context of the organization, including the objectives and scope of your BCMS. Analyze relevant stakeholders and plan communication with them. Map the organizational and document structure of your company to transparently display responsibilities and processes.
  • Plan emergency and crisis management to remain capable of acting even without detailed emergency plans and summarize the results in an emergency manual.
  • Perform a business impact analysis (BIA) to identify time-critical business processes. Based on the analysis, determine the maximum tolerable downtime (MTPD) and the resulting recovery time objectives (RTO).
  • Compare the target recovery times with the actual recovery times achieved using a target-actual comparison. For information-based resources, also compare the RPO (Recovery Point Objective) with the actual data loss.
  • Perform a risk analysis within the ISMS domain to identify and assess risks related to business continuity.
  • Evaluate your business continuity strategies according to a uniform evaluation scheme.
  • Plan recovery, restoration, and business continuity for your time-critical resources and time-critical business processes, taking into account the defined strategies.
  • Document any correction requirements and potential improvements identified at an early stage to ensure continuous improvement of your BCMS.
  • Perform performance reviews or compliance checks:
    • Create your own catalogs of requirements or use the BSI catalog of requirements as a basis.
    • Optionally, you can create your own basic catalogs of requirements for reviewing time-critical service providers, outsourcing partners, and supply chains.