Top Banner
Role of understanding the context in Business Continuity Management Experience from ISO 22301 compliant BCMS implementation Juris Puce analytica.lv
8
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: BCMS and understanding the organization

Role of understanding the context in Business Continuity Management

Experience from ISO 22301 compliant BCMS implementation

Juris Puce analytica.lv

Page 2: BCMS and understanding the organization

“Understanding the organization and its context”

• Included in ISO “management system standards” requirements

Assumption: understanding the context AND organization is especially important in cases for

Business Continiuity

Page 3: BCMS and understanding the organization

Experience• We have experience in implementation of

– Business Process Management– Information Security Management Systems (both ISO 27001 and

alternative)– IT Service Management systems (ISO 20000-1; ITIL, other principles)– Quality Management Systems (ISO 9001 and alternative approaches)– Risk management systems...

All include the idea of “understanding the organization and its context”

Page 4: BCMS and understanding the organization

Another point of view

• Understanding the organization and its context usually can be done at a “general level”– What services/products– Structure of organization– Basic grasp of “culture”

Not that easy in effective BCP (Business Continuity Planning)

Page 5: BCMS and understanding the organization

BCMS (Business Continuity Management System)

• Requires much more in-depth understanding of the organization and its context– not arguing: technically any process/management system needs the

understanding too

– But these sometimes can easily be misguided/misunderstood

• BCMS requires in-depth understanding of:– Processes, Functions– Consequences if not done, done partially, or done late– Resources the organization is ready to invest to prevent failures/maintain

processes

Page 6: BCMS and understanding the organization

Reasonable BCMS implementation?

Minimum effort (just

rebuild everything)

Maximum effort (lets

make it complicated enough so

nobody understand

s it)

Truth is in the

middle?

Page 7: BCMS and understanding the organization

Conclusion

• Doing Business Continuity (BC) Business Impact Analysis (BIA) properly allow organization to have a “clear head” view on the organization and related risks

• Useful in: risk analysis, information security, quality management, information system planning....

Page 8: BCMS and understanding the organization

COMMENTS WELCOME

Juris Puce @linkedinanalytica.lv