BCMS Module
The Business Continuity Management System (BCMS) is an essential component for ensuring business continuity in crisis situations. It helps organizations maintain their business-critical processes even during disruptions, failures, or disasters. The BCMS module guides you step by step through implementing standards-compliant business continuity management.
Core objectives of BCMS:
- Identifies time-critical business processes
- Analyzes damage potential and downtime systematically
- Develops emergency plans and recovery strategies
- Plans the resources needed for emergency operations
- Improves crisis resilience continuously
The approach at a glance
Section titled “The approach at a glance”The five phases below are the organizational roadmap. How you carry each step out in the module is covered below under Setting up the BCMS step by step.
-
Preparation:
- Secure management commitment
- Appoint BC officer
- Assemble project team
-
Initiation:
- Define scope
- Determine BCMS level
- Clarify roles and responsibilities
-
Analysis:
- Identify business processes
- Conduct BIA
- Assess criticalities
-
Strategy Development:
- Define emergency strategies
- Create recovery plans
- Plan resources
-
Implementation:
- Document emergency plans
- Conduct training
- Plan tests and exercises
Setting up the BCMS step by step
Section titled “Setting up the BCMS step by step”1. BCM initiation
Section titled “1. BCM initiation”Institutional management must launch BCM, because the decisions involved carry far-reaching consequences. All essential phases are documented in the fuentis Suite:
1.1 Defining Scope
Section titled “1.1 Defining Scope”What is the scope? The scope determines which area of the institution should be secured by the BCMS. This can include:
- The entire institution
- Individual locations or sub-areas
- Specific products or services
- Common business processes or production lines
Practice Tip: The scope includes all infrastructural, organizational, personnel, and technical components that support the organization’s core tasks. Consider regulatory requirements and institutional objectives.
Navigation: BCMS → BCM initiation → Scope

1.2 Concept
Section titled “1.2 Concept”The concept phase covers:
Objective Setting:
- Derive individual objectives from business processes
- Consider legal framework conditions
- Include institutional objectives
- Communicate transparently within the organization
Choosing your approach: the BCMS level
- Reactive BCMS: Minimal preparation, reaction in case of emergency
- Standard BCMS: Complete implementation according to standard (e.g., ISO 22301)
Navigation: BCMS → BCM initiation → Conception

1.3 Roles and Responsibilities
Section titled “1.3 Roles and Responsibilities”Important roles in BCMS:
Business Continuity Officer (BC Officer):
- Primarily responsible for building and implementing the BCMS
- Supports institutional management
- Coordinates all BCM activities
Other roles:
- Crisis managers
- Process owners
- Members of the special crisis organization (BAO, German: Besondere Aufbauorganisation)
- Emergency team members
Practice Tip: Mark mandatory roles and BAO memberships already when creating roles. This makes later assignment and documentation easier.
Navigation: BCMS → BCM initiation → Roles

1.4 Resource Categories
Section titled “1.4 Resource Categories”Basic Resources: Certain resources are essential for the entire business operation:
- Power and emergency power supply
- Water supply
- Climate control/ventilation
- IT infrastructure
- Telecommunications
Recovery Point Objective (RPO): Defines the maximum tolerable data loss. Mark resource categories with RPO requirements accordingly.
Navigation: BCMS → BCM initiation → Resource categories

1.5 Document Types and Key Documents
Section titled “1.5 Document Types and Key Documents”Document Categories:
- Emergency plans
- Recovery plans
- Communication plans
- Resource lists
- Contact lists
Practice Tip: Mark mandatory document types and link uploaded documents directly to the corresponding categories.
Navigation: BCMS → BCM initiation → Document types


2. Business processes
Section titled “2. Business processes”2.1 Process Identification and Assignment
Section titled “2.1 Process Identification and Assignment”Business processes are the basis for the Business Impact Analysis (BIA). Create them in asset management, assign them to the BCMS scope, link them to the processes they depend on, and connect them to the relevant assets.
2.2 Process Linking
Section titled “2.2 Process Linking”Relationship types between processes:
- Upstream: Process A must run before Process B
- Downstream: Process B follows Process A
- Parallel: Processes run simultaneously
- Dependent: Process B needs output from Process A
Note: BCMS only displays links between business processes. A complete analysis also requires linking to assets.
Navigation: BCMS → Business processes

3. Analysis parameters
Section titled “3. Analysis parameters”3.1 Time Horizons
Section titled “3.1 Time Horizons”Standard time horizons for assessment:
- Immediate (0-4 hours)
- Short-term (4-24 hours)
- Medium-term (1-7 days)
- Long-term (> 7 days)
Format for individual time horizons:
- w = weeks
- d/t = days
- h/s = hours
- m = minutes
Example: 2w 3d 4h 30m = 2 weeks, 3 days, 4 hours, 30 minutes
Navigation: BCMS → Analysis parameters → Time horizons

3.2 Damage Scenarios
Section titled “3.2 Damage Scenarios”BSI standard damage scenarios:
- Threatens personal safety
- Disrupts task performance
- Violates laws, regulations or contracts
- Damages internal or external reputation
- Financial impacts
Navigation: BCMS → Analysis parameters → Damage scenarios

3.3 Damage Categories
Section titled “3.3 Damage Categories”Standard damage categories according to BSI:
| Category | Description | Impact |
|---|---|---|
| Low | Minimal, barely noticeable impacts | Insignificant impairment, no consequences |
| Medium | Noticeable impacts | Work backlogs, tolerable financial damage |
| High | Intolerable impacts | Massive restrictions, significant consequences |
| Very High | Existentially threatening impacts | Danger to life and limb, existentially threatening damage |
Intolerability Level: Defines the threshold above which damage is no longer acceptable. This determines the maximum tolerable downtime (MTPD).
Navigation: BCMS → Analysis parameters → Damage categories

4. Business Impact Analysis (BIA)
Section titled “4. Business Impact Analysis (BIA)”4.1 BIA Profile and Damage Potential
Section titled “4.1 BIA Profile and Damage Potential”BIA objectives:
- Identifies time-critical business processes
- Determines the impact of a failure
- Derives the recovery requirements
- Assesses the resources needed for emergency operations
Damage potential assessment: For each time horizon, the damage potential is assessed in the defined categories. You rate it by placing it on the damage-category scale.
Navigation: BCMS → Business processes → Process → Business Impact Analysis


4.2 Critical Metrics
Section titled “4.2 Critical Metrics”Maximum Tolerable Period of Disruption (MTPD):
- Maximum tolerable downtime of a business process
- Calculated automatically based on damage potential and intolerability level
Recovery Time Objective (RTO):
- Target recovery time after a failure
- Must be smaller than MTPD
- Basis for emergency planning
Recovery Point Objective (RPO):
- Maximum acceptable data loss
- Determines backup strategies
- Relevant for IT-supported processes
Navigation: BCMS → Business processes → Process → Business Impact Analysis

4.3 Dependencies and Resources
Section titled “4.3 Dependencies and Resources”Analyze process dependencies:
- Internal dependencies (other processes)
- External dependencies (suppliers, service providers)
- Technical dependencies (IT systems, infrastructure)
- Personnel dependencies (key persons, specialized knowledge)
Determine resource requirements:
- Minimum personnel for emergency operations
- Critical IT systems and applications
- Workplaces and facilities
- Communication means
- Special equipment or materials
Navigation: BCMS → Business processes → Process → Business Impact Analysis

Implementation Support and Best Practices
Section titled “Implementation Support and Best Practices”Integration with ISO Standards
Section titled “Integration with ISO Standards”ISO 22301: Business Continuity Management The BCMS module in the fuentis Suite follows the requirements of ISO 22301:
- Plan-Do-Check-Act (PDCA) cycle
- Risk-oriented approach
- Continuous improvement
- Documented information
BSI Standard 200-4: The implementation follows BSI recommendations for Business Continuity Management:
- Level model (Reactive, Standard)
- Standardized damage categories
- Structured approach
Related modules
Section titled “Related modules”The BCMS does not stand alone: business processes are maintained in asset management and assigned to the BCMS scope there. Damage assessment follows the same logic as risk management in the ISMS.
Further Information
Section titled “Further Information”Glossary of important terms:
Section titled “Glossary of important terms:”- BAO: Besondere Aufbauorganisation (special crisis organization, activated in an emergency)
- BIA: Business Impact Analysis (assessment of failure impacts)
- MTPD: Maximum Tolerable Period of Disruption (maximum tolerable downtime)
- RPO: Recovery Point Objective (maximum acceptable data loss)
- RTO: Recovery Time Objective (target recovery time)