Skip to content

BCMS Module

The Business Continuity Management System (BCMS) is an essential component for ensuring business continuity in crisis situations. It helps organizations maintain their business-critical processes even during disruptions, failures, or disasters. The BCMS module guides you step by step through implementing standards-compliant business continuity management.

Core objectives of BCMS:

  • Identifies time-critical business processes
  • Analyzes damage potential and downtime systematically
  • Develops emergency plans and recovery strategies
  • Plans the resources needed for emergency operations
  • Improves crisis resilience continuously

The five phases below are the organizational roadmap. How you carry each step out in the module is covered below under Setting up the BCMS step by step.

  1. Preparation:

    • Secure management commitment
    • Appoint BC officer
    • Assemble project team
  2. Initiation:

    • Define scope
    • Determine BCMS level
    • Clarify roles and responsibilities
  3. Analysis:

    • Identify business processes
    • Conduct BIA
    • Assess criticalities
  4. Strategy Development:

    • Define emergency strategies
    • Create recovery plans
    • Plan resources
  5. Implementation:

    • Document emergency plans
    • Conduct training
    • Plan tests and exercises

Institutional management must launch BCM, because the decisions involved carry far-reaching consequences. All essential phases are documented in the fuentis Suite:

What is the scope? The scope determines which area of the institution should be secured by the BCMS. This can include:

  • The entire institution
  • Individual locations or sub-areas
  • Specific products or services
  • Common business processes or production lines

Practice Tip: The scope includes all infrastructural, organizational, personnel, and technical components that support the organization’s core tasks. Consider regulatory requirements and institutional objectives.

Navigation: BCMS → BCM initiation → Scope

Creating a scope

The concept phase covers:

Objective Setting:

  • Derive individual objectives from business processes
  • Consider legal framework conditions
  • Include institutional objectives
  • Communicate transparently within the organization

Choosing your approach: the BCMS level

  • Reactive BCMS: Minimal preparation, reaction in case of emergency
  • Standard BCMS: Complete implementation according to standard (e.g., ISO 22301)

Navigation: BCMS → BCM initiation → Conception

Conception: objectives and requirements

Important roles in BCMS:

Business Continuity Officer (BC Officer):

  • Primarily responsible for building and implementing the BCMS
  • Supports institutional management
  • Coordinates all BCM activities

Other roles:

  • Crisis managers
  • Process owners
  • Members of the special crisis organization (BAO, German: Besondere Aufbauorganisation)
  • Emergency team members

Practice Tip: Mark mandatory roles and BAO memberships already when creating roles. This makes later assignment and documentation easier.

Navigation: BCMS → BCM initiation → Roles

Roles and responsibilities

Basic Resources: Certain resources are essential for the entire business operation:

  • Power and emergency power supply
  • Water supply
  • Climate control/ventilation
  • IT infrastructure
  • Telecommunications

Recovery Point Objective (RPO): Defines the maximum tolerable data loss. Mark resource categories with RPO requirements accordingly.

Navigation: BCMS → BCM initiation → Resource categories

Resource categories

Document Categories:

  • Emergency plans
  • Recovery plans
  • Communication plans
  • Resource lists
  • Contact lists

Practice Tip: Mark mandatory document types and link uploaded documents directly to the corresponding categories.

Navigation: BCMS → BCM initiation → Document types

Document types

Key documents

Business processes are the basis for the Business Impact Analysis (BIA). Create them in asset management, assign them to the BCMS scope, link them to the processes they depend on, and connect them to the relevant assets.

Relationship types between processes:

  • Upstream: Process A must run before Process B
  • Downstream: Process B follows Process A
  • Parallel: Processes run simultaneously
  • Dependent: Process B needs output from Process A

Note: BCMS only displays links between business processes. A complete analysis also requires linking to assets.

Navigation: BCMS → Business processes

Business process overview

Standard time horizons for assessment:

  • Immediate (0-4 hours)
  • Short-term (4-24 hours)
  • Medium-term (1-7 days)
  • Long-term (> 7 days)

Format for individual time horizons:

  • w = weeks
  • d/t = days
  • h/s = hours
  • m = minutes

Example: 2w 3d 4h 30m = 2 weeks, 3 days, 4 hours, 30 minutes

Navigation: BCMS → Analysis parameters → Time horizons

Time horizons

BSI standard damage scenarios:

  • Threatens personal safety
  • Disrupts task performance
  • Violates laws, regulations or contracts
  • Damages internal or external reputation
  • Financial impacts

Navigation: BCMS → Analysis parameters → Damage scenarios

Damage scenarios

Standard damage categories according to BSI:

CategoryDescriptionImpact
LowMinimal, barely noticeable impactsInsignificant impairment, no consequences
MediumNoticeable impactsWork backlogs, tolerable financial damage
HighIntolerable impactsMassive restrictions, significant consequences
Very HighExistentially threatening impactsDanger to life and limb, existentially threatening damage

Intolerability Level: Defines the threshold above which damage is no longer acceptable. This determines the maximum tolerable downtime (MTPD).

Navigation: BCMS → Analysis parameters → Damage categories

Damage categories

BIA objectives:

  • Identifies time-critical business processes
  • Determines the impact of a failure
  • Derives the recovery requirements
  • Assesses the resources needed for emergency operations

Damage potential assessment: For each time horizon, the damage potential is assessed in the defined categories. You rate it by placing it on the damage-category scale.

Navigation: BCMS → Business processes → Process → Business Impact Analysis

BIA: damage potential over time

BIA: objectives per damage scenario

Maximum Tolerable Period of Disruption (MTPD):

  • Maximum tolerable downtime of a business process
  • Calculated automatically based on damage potential and intolerability level

Recovery Time Objective (RTO):

  • Target recovery time after a failure
  • Must be smaller than MTPD
  • Basis for emergency planning

Recovery Point Objective (RPO):

  • Maximum acceptable data loss
  • Determines backup strategies
  • Relevant for IT-supported processes

Navigation: BCMS → Business processes → Process → Business Impact Analysis

RTO detail view

Analyze process dependencies:

  • Internal dependencies (other processes)
  • External dependencies (suppliers, service providers)
  • Technical dependencies (IT systems, infrastructure)
  • Personnel dependencies (key persons, specialized knowledge)

Determine resource requirements:

  • Minimum personnel for emergency operations
  • Critical IT systems and applications
  • Workplaces and facilities
  • Communication means
  • Special equipment or materials

Navigation: BCMS → Business processes → Process → Business Impact Analysis

Process dependencies

ISO 22301: Business Continuity Management The BCMS module in the fuentis Suite follows the requirements of ISO 22301:

  • Plan-Do-Check-Act (PDCA) cycle
  • Risk-oriented approach
  • Continuous improvement
  • Documented information

BSI Standard 200-4: The implementation follows BSI recommendations for Business Continuity Management:

  • Level model (Reactive, Standard)
  • Standardized damage categories
  • Structured approach

The BCMS does not stand alone: business processes are maintained in asset management and assigned to the BCMS scope there. Damage assessment follows the same logic as risk management in the ISMS.

  • BAO: Besondere Aufbauorganisation (special crisis organization, activated in an emergency)
  • BIA: Business Impact Analysis (assessment of failure impacts)
  • MTPD: Maximum Tolerable Period of Disruption (maximum tolerable downtime)
  • RPO: Recovery Point Objective (maximum acceptable data loss)
  • RTO: Recovery Time Objective (target recovery time)