Skip to content

Context of the Organization

A precise analysis of the organizational framework conditions is of central importance for the successful establishment and effective operation of a BCMS. The BCMS must be designed to meet the needs and requirements of relevant stakeholders. This ensures that the BCMS is designed, implemented, and maintained in an appropriate manner.

In verinice, it is possible to record the scope objects relevant to the respective unit. These include in particular:

  • the institution,
  • the BCMS scope,
  • the stakeholders,
  • external service providers, and
  • – if necessary – individual organizational units of the institution.

A scope can contain any subject objects, including other scopes. Various organizational units can be mapped and logically grouped under a scope to ensure a structured and transparent representation of the different scopes.

The mapping of individual institutions also serves to clearly assign the respective BCMS scope to an institution. This assignment is necessary in order to be able to evaluate reports in a targeted manner. Reports are always executed via a specific scope subtype. By adding the parts, it is possible to control which objects are to be included in a report.

Identifying and modeling requirements

Once the organizational context has been defined, requirements can be identified—for example, the expectations and needs of stakeholders or requirements arising from other scopes. The specific requirements for the BCMS are then derived from this information and recorded. For stakeholders, it is also possible to assess their influence on the BCMS.

Once both the scopes and the requirements have been created in verinice, they can be linked to each other. There are two ways to do this:

  • The associated requirements can be modeled directly in the Control tab under the respective stakeholder group or another scope subtype.
  • Alternatively, the corresponding scopes – for example, interest groups – can be selected in the respective requirement under the Target Objects tab. In this case, the requirement is automatically assigned to the scope. Modeling the requirements within a scope also enables the management and tracking of the respective implementation status.

Interest group analysis

Defining the scope of the BCMS

The BCMS scope defines the specific area of application of the BCMS. Both content-related and organizational framework conditions can be documented. On the one hand, the following information can be recorded in the BCMS scope:

  • the period to be covered,
  • the selected approach,
  • the rationale for the BCMS level classification,
  • the limits and applicability of the system,
  • the objectives, and
  • the interfaces and dependencies to the BCMS.

Define scope

On the other hand, it is possible to establish relevant links – for example, to the BCMS guideline, the Business Continuity Manager (BCB), and general emergency measures.

Assign guideline, BCB, and emergency measures to the scope

Document and organizational structure

For the effective establishment and operation of the BCMS, a clear and comprehensible organizational and document structure must be defined.

Organizational structure in BCM

Define the BC organizational structure of your institution and clearly define responsibilities, roles, and competencies. The organizational structure includes both:

  • the BC preparedness organization, which includes preventive and preparatory structures, and
  • the emergency and crisis management organization (special organizational structure – BAO).

The response organization includes the crisis management team, the core teams, the situational expansion, the staff assistance, and the response teams. In verinice, these roles can be mapped as person objects. Assign the respective persons who perform these functions to the individual roles via the Parts tab. Create all employees involved in the BCMS as person objects and link them to the corresponding BC roles. This ensures that all responsibilities and accountabilities within the BC organization are clearly defined and documented in a traceable manner. In addition, a substitute can be assigned to each role. The associated tasks, responsibilities, and duties can also be documented directly in the respective role.

Manage roles and persons

Document structure in BCM

In the Documents area of verinice, you can refer to relevant evidence and control documents. This allows you to build a structured overview of the essential BCM documents, e.g.:

  • Policies
  • Guidelines
  • Emergency manuals
  • Alert and communication plans
  • Recovery plans

This structured document management enables traceable organization, versioning, and maintenance of all BCM-relevant documents.