{"id":497,"date":"2017-03-11T01:50:58","date_gmt":"2017-03-10T17:50:58","guid":{"rendered":"http:\/\/microdium.net\/public\/2017\/03\/11\/bci-iso-22301-and-the-business-continuity-octopus\/"},"modified":"2017-03-11T01:50:58","modified_gmt":"2017-03-10T17:50:58","slug":"bci-iso-22301-and-the-business-continuity-octopus","status":"publish","type":"post","link":"https:\/\/www.microdium.com\/public\/2017\/03\/11\/bci-iso-22301-and-the-business-continuity-octopus\/","title":{"rendered":"BCI: ISO 22301 and the business continuity octopus"},"content":{"rendered":"<p><html><body><\/p>\n<div class=\"K2FeedImage\"><img decoding=\"async\" src=\"https:\/\/www.microdium.net\/public\/wp-content\/uploads\/2017\/03\/e65aa1151e74dfc1f438af6579da33dd_S.jpg\" alt=\"BCI: ISO 22301 and the business continuity octopus\"\/><\/div>\n<div class=\"K2FeedIntroText\">\n<h6 style=\"font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-weight: bold;line-height: 1.2;margin: 0px 0px 6px;font-size: 13px;color: #999999\">The Business Continuity Institute<\/h6>\n<p style=\"padding: 0px;color: #555555;font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-size: 13px;line-height: 18px;margin: 0px 0px 9px\"><img decoding=\"async\" src=\"https:\/\/www.microdium.net\/public\/wp-content\/uploads\/2017\/03\/nl2yil6yoxavzkn37taw.jpg\" alt=\"\" style=\"max-width: 100%\"\/><\/p>\n<div class=\"mail-article\">\n<p style=\"padding: 0px;color: #555555;font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-size: 13px;line-height: 18px;margin: 0px 0px 9px\">Implementing a Business Continuity Management System which meets and exceeds ISO 22301 is a challenging, but important undertaking for an organization committed to\u00a0<a href=\"http:\/\/notifier.mynewsdesk.com\/wf\/click?upn=i1LtfWCr5IRG43ed6rkKjQQvH-2F2kqOZ3rWfi6HBidUj-2Bkekx878S2W8eE-2FFq24nORoubYnsafoQRnU0q-2BW6YmUKayEs1CATU92U-2FBC0Hm4A-3D_VQBJMzKloVp-2B8METKs9NBTEFNmEXdZTkGwkWg9-2F4llW2e9YbzDq2wQ6M1VzzZKg-2B3Gk3TLtDSKPzf4U4M7MZYr2-2F3KzrQStHe1-2BKdyIYSLj5ErmMWyKIlzVFOAAJ7QiLMWfzKiIIehDYR1ZiRweMOpPC8exfBbliz0YwpxC6ygGp4zGUXL8QsMpzVzn4Ts32NDegjqWvgKyXmD35iq83eYh8WEdbne0xvPfDBtH3WoYqaEmPBO0cmC3E9FEqLyGop2QE9Z3ID9rJqUrY0IWyg7R-2BmhZvQavwalLSZhXgyQA0z8fwXNteQ32ZuylDFfgoi1agfkGJsv9sw3VjL1MGnUgqPeAJo2hUykCB0mGaLZIBgjzw3W3h0QLU7Axww1Mr7NXz3WOa0AAn0PNVr-2BxBuw-3D-3D\" style=\"color: #3d9bbc\">business continuity<\/a>. I have recently been leading a project for\u00a0<a href=\"http:\/\/notifier.mynewsdesk.com\/wf\/click?upn=i1LtfWCr5IRG43ed6rkKjapXbWC7KD4MC-2FbPoZA0uUmQnxUDf1AictzaNx-2FUNfNG_VQBJMzKloVp-2B8METKs9NBTEFNmEXdZTkGwkWg9-2F4llW2e9YbzDq2wQ6M1VzzZKg-2B3Gk3TLtDSKPzf4U4M7MZYr2-2F3KzrQStHe1-2BKdyIYSLj5ErmMWyKIlzVFOAAJ7QiLMWfzKiIIehDYR1ZiRweMOpPC8exfBbliz0YwpxC6ygGp4zGUXL8QsMpzVzn4Ts320gaJSaU5-2Bvz521HJgqVBGCwyIZTVPKxg9TrSTqmDyIjymd37X7yUrPUfIDkfWyupzhCAKrhpDnkf0FoKnoYNOrWBWYFEO0jHvD-2B3aAnQOcLQ9W4oKTiZwLUyASSMkEDPVUoq3yDvy-2BzrnHGX5-2FW2TTWoSJRDDvypec1mPtWFbaA1FFKYYDe7MyT8urCqqDvg5WifptBLLWIZSPRxqj1gPg-3D-3D\" target=\"_blank\" style=\"color: #3d9bbc\" rel=\"noopener\">PlanB<\/a>, where we helped a marketing\/logistics firm achieve ISO 22301 (with one minor non-conformity!) This was achieved in a period of five months, and some lessons learned are shared below.<\/p>\n<p style=\"padding: 0px;color: #555555;font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-size: 13px;line-height: 18px;margin: 0px 0px 9px\">I would consider a good BCMS to operate like an octopus. It sits at the heart of the organization, but reaches into each and every function of the business. This of course requires collaboration from different parts of the organization.<\/p>\n<p style=\"padding: 0px;color: #555555;font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-size: 13px;line-height: 18px;margin: 0px 0px 9px\">Ultimately, embedding is key and this doesn\u2019t just come from conducting awareness training, or ensuring that the policy and plan(s) are visible to employees and interested parties. Embedding comes from the octopus, connecting each function or department, back to the BCMS. Information should flow along the connectors (tentacles &#8211; if we follow the octopus theme!).<\/p>\n<p style=\"padding: 0px;color: #555555;font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-size: 13px;line-height: 18px;margin: 0px 0px 9px\">I will explain how this should operate below:<\/p>\n<p style=\"padding: 0px;color: #555555;font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-size: 13px;line-height: 18px;margin: 0px 0px 9px\">1. Key to embedding is how your staff interacts with the BCMS. Are they passively involved, or do they understand as much as possible? Staff may be instructed to attend a training session. However, you should consider involving as many staff as possible. This includes involving non-management staff at the Analysis (BIA) phase up to validation, where deputies should be included in exercising and tests.<\/p>\n<p style=\"padding: 0px;color: #555555;font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-size: 13px;line-height: 18px;margin: 0px 0px 9px\">2. The BCMS must interact with departmental functions. Critically, it should embrace and involve IT, not only with regards to disaster recovery, but also day-to-day operations. Related disciplines of cyber security and information security dovetail closely with the BCMS. Risk management is also crucial, with consideration given to how BC risks are considered in line with corporate risk registers. Lastly, the BCP should be written with the approval of health and safety, particularly with regard to site evacuation and incident notifications.<\/p>\n<p style=\"padding: 0px;color: #555555;font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-size: 13px;line-height: 18px;margin: 0px 0px 9px\">3. Externally, the octopus should reach to supply chain and critical suppliers. This can often be an afterthought for BC professionals, and seen as a more \u2018mature\u2019 element of business continuity. However, there will likely be huge dependency on suppliers if a BC incident occurs, therefore you must understand what suppliers can provide by way of continuity of operations. Raising awareness to interested parties of your BC arrangements can also help build resilience.<\/p>\n<p style=\"padding: 0px;color: #555555;font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-size: 13px;line-height: 18px;margin: 0px 0px 9px\">4. Post-incident acquisition is still possible as strategy; it is not always hot data centres and Work Area Recovery. However, exercising of post-incident acquisition is essential. And this strategy should complement other recovery strategies, which have been exercised and tested. Unless exercising occurs, we are working with untested assumption, which is the last thing you want in an incident!<\/p>\n<p style=\"padding: 0px;color: #555555;font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-size: 13px;line-height: 18px;margin: 0px 0px 9px\">The above is a brief overview of the observations I noted whilst proceeding through the ISO 22301 certification process. I have tried to keep the observations high-level, to ensure these are a starting point for others implementing a BCMS. So, when implementing a BCMS for the first time, remember the business continuity octopus!<\/p>\n<p style=\"padding: 0px;color: #555555;font-family: 'Helvetica Neue',Helvetica,Arial,sans-serif;font-size: 13px;line-height: 18px;margin: 0px 0px 9px\"><strong style=\"color: #222222\"><em>Gordon Brown (AMBCI, MSc) is a consultant at PlanB Consulting, and leads on projects\u00a0<\/em><\/strong><strong style=\"color: #222222\"><em>delivering business continuity, ISO 22301 and training and exercises.<\/em><\/strong><\/p>\n<\/div>\n<\/div>\n<p>&#13;<br \/>\nSource: DRJ New feed<\/body><\/html><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Business Continuity Institute Implementing a Business Continuity Management System which meets and exceeds ISO 22301 is a challenging, but important undertaking for an organization committed to\u00a0business continuity. I have recently been leading a project for\u00a0PlanB, where we helped a marketing\/logistics firm achieve ISO 22301 (with one minor non-conformity!) This was achieved in a period [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":498,"comment_status":"false","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[15],"class_list":["post-497","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-disaster-recovery-cybersecurity-news-malaysia","tag-about"],"_links":{"self":[{"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/posts\/497","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/comments?post=497"}],"version-history":[{"count":0,"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/posts\/497\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/media?parent=497"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/categories?post=497"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.microdium.com\/public\/wp-json\/wp\/v2\/tags?post=497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}