BCMS-Modul
The Business Continuity Management System (BCMS) is an essential component for ensuring business continuity in crisis situations. It helps organizations maintain their business-critical processes even during disruptions, failures, or disasters. The fuentis Suite offers a comprehensive BCMS module that guides you step by step through the implementation of standards-compliant Business Continuity Management.
Core objectives of BCMS:
- Identification of time-critical business processes
- Systematic analysis of damage potential and downtime
- Development of emergency plans and recovery strategies
- Resource planning for emergency operations
- Continuous improvement of crisis resilience
Main Concepts and Requirements
Section titled “Main Concepts and Requirements”1. BCM Initiation - Laying the Foundation
Section titled “1. BCM Initiation - Laying the Foundation”BCM initiation must be initiated by the institutional management, as the decisions to be made have far-reaching consequences. All essential phases are documented in the fuentis Suite:
1.1 Defining Scope
Section titled “1.1 Defining Scope”What is the scope? The scope determines which area of the institution should be secured by the BCMS. This can include:
- The entire institution
- Individual locations or sub-areas
- Specific products or services
- Common business processes or production lines
Practice Tip: The scope includes all infrastructural, organizational, personnel, and technical components that serve task fulfillment. Consider regulatory requirements and institutional objectives.

1.2 Conception - Strategic Alignment
Section titled “1.2 Conception - Strategic Alignment”The conception phase includes:
Objective Setting:
- Derive individual objectives from business processes
- Consider legal framework conditions
- Include institutional objectives
- Transparent communication within the organization
Decision on Approach - Choice of BCMS Level:
- Reactive BCMS: Minimal preparation, reaction in case of emergency
- Standard BCMS: Complete implementation according to standard (e.g., ISO 22301)

1.3 Roles and Responsibilities
Section titled “1.3 Roles and Responsibilities”Important roles in BCMS:
Business Continuity Officer (BC Officer):
- Primarily responsible for building and implementing the BCMS
- Supports institutional management
- Coordinates all BCM activities
Other roles:
- Crisis managers
- Process owners
- Members of the Special Organizational Structure (SOS)
- Emergency team members
Practice Tip: Mark mandatory roles and SOS memberships already when creating roles. This facilitates later assignment and documentation.

1.4 Resource Categories
Section titled “1.4 Resource Categories”Basic Resources: Certain resources are essential for the entire business operation:
- Power and emergency power supply
- Water supply
- Climate control/ventilation
- IT infrastructure
- Telecommunications
Recovery Point Objective (RPO): Defines the maximum tolerable data loss. Mark resource categories with RPO requirements accordingly.

1.5 Document Types and Key Documents
Section titled “1.5 Document Types and Key Documents”Document Categories:
- Emergency plans
- Recovery plans
- Communication plans
- Resource lists
- Contact lists
Practice Tip: Mark mandatory document types and link uploaded documents directly with the corresponding categories.


2. Business Processes - The Heart of BCMS
Section titled “2. Business Processes - The Heart of BCMS”2.1 Process Identification and Assignment
Section titled “2.1 Process Identification and Assignment”Business processes form the basis for the Business Impact Analysis (BIA). They must:
- Be created in asset management
- Be assigned to the BCMS scope
- Be linked with other processes (dependencies)
- Be connected with relevant assets
2.2 Process Linking
Section titled “2.2 Process Linking”Relationship types between processes:
- Upstream: Process A must run before Process B
- Downstream: Process B follows Process A
- Parallel: Processes run simultaneously
- Dependent: Process B needs output from Process A
Important: In BCMS, only links between business processes are displayed, but complete linking with assets is important for comprehensive analysis.

3. Analysis Parameters - Creating Assessment Foundations
Section titled “3. Analysis Parameters - Creating Assessment Foundations”3.1 Time Horizons
Section titled “3.1 Time Horizons”Standard time horizons for assessment:
- Immediate (0-4 hours)
- Short-term (4-24 hours)
- Medium-term (1-7 days)
- Long-term (> 7 days)
Format for individual time horizons:
- w = weeks
- d/t = days
- h/s = hours
- m = minutes
Example: 2w 3d 4h 30m = 2 weeks, 3 days, 4 hours, 30 minutes

3.2 Damage Scenarios
Section titled “3.2 Damage Scenarios”BSI standard damage scenarios:
- Impairment of personal safety
- Impairment of task fulfillment
- Violation of laws, regulations, and contracts
- Negative internal and external impact (image damage)
- Financial impacts

3.3 Damage Categories
Section titled “3.3 Damage Categories”Standard damage categories according to BSI:
| Category | Description | Impact |
|---|---|---|
| Low | Minimal, barely noticeable impacts | Insignificant impairment, no consequences |
| Medium | Noticeable impacts | Work backlogs, tolerable financial damage |
| High | Intolerable impacts | Massive restrictions, significant consequences |
| Very High | Existentially threatening impacts | Danger to life and limb, existentially threatening damage |
Intolerability Level: Defines the threshold above which damage is no longer acceptable. This determines the maximum tolerable downtime (MTPD).

4. Business Impact Analysis (BIA) - Assessing Criticality
Section titled “4. Business Impact Analysis (BIA) - Assessing Criticality”4.1 BIA Profile and Damage Potential
Section titled “4.1 BIA Profile and Damage Potential”BIA objectives:
- Identification of time-critical business processes
- Determination of failure impacts
- Derivation of recovery requirements
- Resource needs assessment for emergency operations
Damage potential assessment: For each time horizon, the damage potential is assessed in the defined categories. The assessment is done graphically by positioning on the damage category scale.


4.2 Critical Metrics
Section titled “4.2 Critical Metrics”Maximum Tolerable Period of Disruption (MTPD):
- Maximum tolerable downtime of a business process
- Calculated automatically based on damage potential and intolerability level
Recovery Time Objective (RTO):
- Target recovery time after a failure
- Must be smaller than MTPD
- Basis for emergency planning
Recovery Point Objective (RPO):
- Maximum acceptable data loss
- Determines backup strategies
- Relevant for IT-supported processes

4.3 Dependencies and Resources
Section titled “4.3 Dependencies and Resources”Analyze process dependencies:
- Internal dependencies (other processes)
- External dependencies (suppliers, service providers)
- Technical dependencies (IT systems, infrastructure)
- Personnel dependencies (key persons, specialized knowledge)
Determine resource requirements:
- Minimum personnel for emergency operations
- Critical IT systems and applications
- Workplaces and facilities
- Communication means
- Special equipment or materials

Implementation Aids and Best Practices
Section titled “Implementation Aids and Best Practices”Practical Tips for Implementation
Section titled “Practical Tips for Implementation”Step-by-step approach:
Section titled “Step-by-step approach:”-
Preparation:
- Secure management commitment
- Appoint BC officer
- Assemble project team
-
Initiation:
- Define scope
- Determine BCMS level
- Clarify roles and responsibilities
-
Analysis:
- Identify business processes
- Conduct BIA
- Assess criticalities
-
Strategy Development:
- Define emergency strategies
- Create recovery plans
- Plan resources
-
Implementation:
- Document emergency plans
- Conduct training
- Plan tests and exercises
Integration with ISO Standards
Section titled “Integration with ISO Standards”ISO 22301 - Business Continuity Management: The BCMS module of the fuentis Suite is oriented to the requirements of ISO 22301:
- Plan-Do-Check-Act (PDCA) cycle
- Risk-oriented approach
- Continuous improvement
- Documented information
BSI Standard 200-4: The implementation follows BSI recommendations for Business Continuity Management:
- Level model (Reactive, Building, Standard)
- Standardized damage categories
- Structured approach
How the fuentis Suite Supports
Section titled “How the fuentis Suite Supports”Automation and Simplification:
- Automatic calculation of MTPD and RTO
- Graphic representation of damage potentials
- Link with asset management
- Integrated document management
Compliance and Audit:
- Standards-compliant documentation
- Traceable processes
- Audit trail for all changes
- Certification preparation
Common Challenges and Solutions
Section titled “Common Challenges and Solutions”Challenge: Incomplete process landscape
- Solution: Gradual capture, starting with critical processes
- Practice tip: Workshop-based process identification with functional departments
Challenge: Unrealistic recovery times
- Solution: Conduct realistic tests and exercises
- Practice tip: Start with conservative estimates and optimize
Challenge: Lack of resources for emergency operations
- Solution: Define prioritization and minimum operations
- Practice tip: Plan alternative strategies and external resources
Key Messages at a Glance
Section titled “Key Messages at a Glance”-
BCMS is a top management issue: The initiation and responsibility for a BCMS lies with institutional management, while a BC officer coordinates operational implementation.
-
Structured approach: Development occurs in clearly defined phases - from initiation through BIA to strategy development and implementation.
-
Focus on criticality: The Business Impact Analysis identifies time-critical processes and determines maximum tolerable downtimes as the basis for emergency planning.
-
Integration is crucial: BCMS is not an isolated discipline but closely integrated with asset management, risk management, and ISMS.
-
Continuity as a process: Business Continuity Management is an ongoing process with regular tests, exercises, and adaptations to changed framework conditions.
Further Information
Section titled “Further Information”Glossary of important terms:
Section titled “Glossary of important terms:”- SOS: Special Organizational Structure - Crisis organization in emergency
- BIA: Business Impact Analysis - Assessment of failure impacts
- MTPD: Maximum Tolerable Period of Disruption - Maximum tolerable downtime
- RPO: Recovery Point Objective - Maximum acceptable data loss
- RTO: Recovery Time Objective - Target recovery time