Skip to content

BCMS-Modul

The Business Continuity Management System (BCMS) is an essential component for ensuring business continuity in crisis situations. It helps organizations maintain their business-critical processes even during disruptions, failures, or disasters. The fuentis Suite offers a comprehensive BCMS module that guides you step by step through the implementation of standards-compliant Business Continuity Management.

Core objectives of BCMS:

  • Identification of time-critical business processes
  • Systematic analysis of damage potential and downtime
  • Development of emergency plans and recovery strategies
  • Resource planning for emergency operations
  • Continuous improvement of crisis resilience

BCM initiation must be initiated by the institutional management, as the decisions to be made have far-reaching consequences. All essential phases are documented in the fuentis Suite:

What is the scope? The scope determines which area of the institution should be secured by the BCMS. This can include:

  • The entire institution
  • Individual locations or sub-areas
  • Specific products or services
  • Common business processes or production lines

Practice Tip: The scope includes all infrastructural, organizational, personnel, and technical components that serve task fulfillment. Consider regulatory requirements and institutional objectives.

bcms-1

The conception phase includes:

Objective Setting:

  • Derive individual objectives from business processes
  • Consider legal framework conditions
  • Include institutional objectives
  • Transparent communication within the organization

Decision on Approach - Choice of BCMS Level:

  • Reactive BCMS: Minimal preparation, reaction in case of emergency
  • Standard BCMS: Complete implementation according to standard (e.g., ISO 22301)

bcms-2

Important roles in BCMS:

Business Continuity Officer (BC Officer):

  • Primarily responsible for building and implementing the BCMS
  • Supports institutional management
  • Coordinates all BCM activities

Other roles:

  • Crisis managers
  • Process owners
  • Members of the Special Organizational Structure (SOS)
  • Emergency team members

Practice Tip: Mark mandatory roles and SOS memberships already when creating roles. This facilitates later assignment and documentation.

bcms-4

Basic Resources: Certain resources are essential for the entire business operation:

  • Power and emergency power supply
  • Water supply
  • Climate control/ventilation
  • IT infrastructure
  • Telecommunications

Recovery Point Objective (RPO): Defines the maximum tolerable data loss. Mark resource categories with RPO requirements accordingly.

bcms-5

Document Categories:

  • Emergency plans
  • Recovery plans
  • Communication plans
  • Resource lists
  • Contact lists

Practice Tip: Mark mandatory document types and link uploaded documents directly with the corresponding categories.

bcms-7

bcms-8

Business processes form the basis for the Business Impact Analysis (BIA). They must:

  • Be created in asset management
  • Be assigned to the BCMS scope
  • Be linked with other processes (dependencies)
  • Be connected with relevant assets

Relationship types between processes:

  • Upstream: Process A must run before Process B
  • Downstream: Process B follows Process A
  • Parallel: Processes run simultaneously
  • Dependent: Process B needs output from Process A

Important: In BCMS, only links between business processes are displayed, but complete linking with assets is important for comprehensive analysis.

bcms-9

3. Analysis Parameters - Creating Assessment Foundations

Section titled “3. Analysis Parameters - Creating Assessment Foundations”

Standard time horizons for assessment:

  • Immediate (0-4 hours)
  • Short-term (4-24 hours)
  • Medium-term (1-7 days)
  • Long-term (> 7 days)

Format for individual time horizons:

  • w = weeks
  • d/t = days
  • h/s = hours
  • m = minutes

Example: 2w 3d 4h 30m = 2 weeks, 3 days, 4 hours, 30 minutes

bcms-10

BSI standard damage scenarios:

  • Impairment of personal safety
  • Impairment of task fulfillment
  • Violation of laws, regulations, and contracts
  • Negative internal and external impact (image damage)
  • Financial impacts

bcms-11

Standard damage categories according to BSI:

CategoryDescriptionImpact
LowMinimal, barely noticeable impactsInsignificant impairment, no consequences
MediumNoticeable impactsWork backlogs, tolerable financial damage
HighIntolerable impactsMassive restrictions, significant consequences
Very HighExistentially threatening impactsDanger to life and limb, existentially threatening damage

Intolerability Level: Defines the threshold above which damage is no longer acceptable. This determines the maximum tolerable downtime (MTPD).

bcms-12

4. Business Impact Analysis (BIA) - Assessing Criticality

Section titled “4. Business Impact Analysis (BIA) - Assessing Criticality”

BIA objectives:

  • Identification of time-critical business processes
  • Determination of failure impacts
  • Derivation of recovery requirements
  • Resource needs assessment for emergency operations

Damage potential assessment: For each time horizon, the damage potential is assessed in the defined categories. The assessment is done graphically by positioning on the damage category scale.

bcms-13

bcms-14

Maximum Tolerable Period of Disruption (MTPD):

  • Maximum tolerable downtime of a business process
  • Calculated automatically based on damage potential and intolerability level

Recovery Time Objective (RTO):

  • Target recovery time after a failure
  • Must be smaller than MTPD
  • Basis for emergency planning

Recovery Point Objective (RPO):

  • Maximum acceptable data loss
  • Determines backup strategies
  • Relevant for IT-supported processes

bcms-15

Analyze process dependencies:

  • Internal dependencies (other processes)
  • External dependencies (suppliers, service providers)
  • Technical dependencies (IT systems, infrastructure)
  • Personnel dependencies (key persons, specialized knowledge)

Determine resource requirements:

  • Minimum personnel for emergency operations
  • Critical IT systems and applications
  • Workplaces and facilities
  • Communication means
  • Special equipment or materials

bcms-16

  1. Preparation:

    • Secure management commitment
    • Appoint BC officer
    • Assemble project team
  2. Initiation:

    • Define scope
    • Determine BCMS level
    • Clarify roles and responsibilities
  3. Analysis:

    • Identify business processes
    • Conduct BIA
    • Assess criticalities
  4. Strategy Development:

    • Define emergency strategies
    • Create recovery plans
    • Plan resources
  5. Implementation:

    • Document emergency plans
    • Conduct training
    • Plan tests and exercises

ISO 22301 - Business Continuity Management: The BCMS module of the fuentis Suite is oriented to the requirements of ISO 22301:

  • Plan-Do-Check-Act (PDCA) cycle
  • Risk-oriented approach
  • Continuous improvement
  • Documented information

BSI Standard 200-4: The implementation follows BSI recommendations for Business Continuity Management:

  • Level model (Reactive, Building, Standard)
  • Standardized damage categories
  • Structured approach

Automation and Simplification:

  • Automatic calculation of MTPD and RTO
  • Graphic representation of damage potentials
  • Link with asset management
  • Integrated document management

Compliance and Audit:

  • Standards-compliant documentation
  • Traceable processes
  • Audit trail for all changes
  • Certification preparation

Challenge: Incomplete process landscape

  • Solution: Gradual capture, starting with critical processes
  • Practice tip: Workshop-based process identification with functional departments

Challenge: Unrealistic recovery times

  • Solution: Conduct realistic tests and exercises
  • Practice tip: Start with conservative estimates and optimize

Challenge: Lack of resources for emergency operations

  • Solution: Define prioritization and minimum operations
  • Practice tip: Plan alternative strategies and external resources
  1. BCMS is a top management issue: The initiation and responsibility for a BCMS lies with institutional management, while a BC officer coordinates operational implementation.

  2. Structured approach: Development occurs in clearly defined phases - from initiation through BIA to strategy development and implementation.

  3. Focus on criticality: The Business Impact Analysis identifies time-critical processes and determines maximum tolerable downtimes as the basis for emergency planning.

  4. Integration is crucial: BCMS is not an isolated discipline but closely integrated with asset management, risk management, and ISMS.

  5. Continuity as a process: Business Continuity Management is an ongoing process with regular tests, exercises, and adaptations to changed framework conditions.

  • SOS: Special Organizational Structure - Crisis organization in emergency
  • BIA: Business Impact Analysis - Assessment of failure impacts
  • MTPD: Maximum Tolerable Period of Disruption - Maximum tolerable downtime
  • RPO: Recovery Point Objective - Maximum acceptable data loss
  • RTO: Recovery Time Objective - Target recovery time