Skip to content

Business Continuity Management according to BSI Standard 200-4

Business Continuity Management (BCM) is a systematic approach to ensuring business continuity in emergency and crisis situations. According to BSI Standard 200-4, BCM enables organizations to maintain time-critical business processes even during severe disruptions, thereby minimizing damage. Its relevance is continuously increasing due to growing cyber threats, natural disasters, and complex infrastructure dependencies.

The Reactive BCMS is designed for organizations that want to become operational quickly:

  • Target Group: Institutions with no prior BCM experience
  • Approach: Use of existing security measures and available resources
  • Scope: Protection of selected time-critical business processes
  • Limitation: Strongly simplified entry level that must be developed further after one BCM cycle
  • Advantage: Rapid establishment of emergency response capability

The Development BCMS allows for step-by-step BCMS implementation:

  • Target Group: Organizations with limited resources or little BCM experience
  • Approach: Focus on a limited scope of the most time-critical processes
  • Advantage: Gradual resource planning and adaptation based on experience
  • Development Path: Lays the foundation for a successful transition to the Standard BCMS
  • Effectiveness: Significantly stronger protection than Reactive BCMS

The Standard BCMS represents full BCM implementation:

  • Scope: Analysis of all business processes within the BCMS scope
  • Safeguards: Risk-appropriate protection of time-critical processes
  • Certification: Achieves the maturity required for ISO 22301 certification
  • Stakeholders: Meets the requirements of all relevant stakeholders

Practical Tip: Start with Development BCMS if you have basic BCM knowledge. Reactive BCMS should only be used as an emergency entry point.

The normal organizational structure (AAO) is often unsuitable in crises because complex coordination paths prevent quick decisions. The BAO addresses this issue by:

Three-Level Structure:

  • Strategic Level: Defines objectives and priorities
  • Tactical Level: Situation analysis, decision-making, monitoring
  • Operational Level: Execution of measures and feedback

Crisis Team Characteristics:

  • Operates outside regular organizational structures
  • Has predefined decision-making authority
  • Staffed with subject matter experts from various areas
  • Each role has at least one deputy

Infrastructure Requirements:

  • Secure and well-equipped crisis team room
  • Backup room for fallback scenarios
  • Communication technology and alerting systems

Business Continuity Manager (BCM):

  • Planning and conducting the Business Impact Analysis
  • Coordinating BCM processes
  • Developing emergency plans

BC Officer:

  • Overall coordination
  • Professional support for BCM
  • Acts as liaison to senior management
  • Disruption: Short-term interruption with minor damage, resolvable in normal operations
  • Emergency: Intolerable interruption of time-critical processes with significant damage; requires emergency plans and BAO
  • Crisis: Severe interruption with no existing plans or when measures fail; requires extended crisis management structures

Central Reporting Office:

  • Receives and documents all incident reports
  • Categorizes them as disruptions, emergencies, or crises
  • Manages contact information and priorities

Escalation Criteria:

  • Immediate BAO activation for emergencies and crises
  • 24/7 availability outside business hours
  • Clear, precise alerts with action instructions

Emergency Plans:

  • Business Continuity Plans (BCP): Maintain critical processes
  • Restart Plans: Reintegrate failed resources
  • Recovery Plans: Return to normal operations

The BIA forms the foundation of BCM by:

  • Identifying business-critical processes
  • Determining performance levels in normal and emergency operations
  • Defining maximum tolerable downtime (MTPD)
  • Providing Transparency on process dependencies

Pre-Scoping:

  • Hierarchical process identification via the Process Levels Pyramid
  • Data collection through interviews, workshops, or surveys
  • Documentation of process attributes and responsibilities

Damage Periods (Standardized):

  • From ≤1 hour to ≤14 days
  • Provides a uniform evaluation basis for all business areas
  • Considers time-sensitive processes (e.g., annual closing, payroll)

MTPD Determination:

  • Assigning damage criticality (1–4) to damage periods
  • Automated calculation via predefined formulas
  • Manual input for exceptional time-critical cases

Dependency Analysis:

  • Mandatory: No alternatives available
  • Existing but non-mandatory: Replaceable within damage period
  • No dependency: Alternatives already in use during regular operations
  • Differentiates between internal and external dependencies

Examines the following resource categories:

  • IT: Servers, networks, applications
  • Personnel: Specialists, key competencies
  • Buildings: Locations, workplaces
  • Services: Deliveries, contracts, construction services
  • Infrastructure: Production resources, utilities

The fuentis Suite supports BCM through:

Process Management:

  • Central capture and management of business processes
  • Automated BIA execution and evaluation
  • Dependency modeling and visualization

Crisis Management:

  • Predefined alert chains and escalation paths
  • Mobile crisis team communication
  • Documentation and tracking of measures

Compliance and Reporting:

  • Automated reports for management and authorities
  • Continuous monitoring of BCM KPIs
  • Preparation for ISO 22301 certification
  • Top Management Commitment: Visible support from leadership
  • Clear Responsibilities: Defined roles and resources
  • Regular Exercises: Testing emergency plans and BAO structures
  • Lessons Learned: Systematic evaluation after each incident
  • Regular BIA Updates: Adjustments for organizational changes
  • Stakeholder Integration: Involvement of internal and external partners
  • Create Redundancies: Backup systems and alternative sites
  • Use Automation: Reduce manual interventions in critical situations
  • Testing and Monitoring: Ongoing verification of BCM measures

Practical Tip: Start with a small pilot group of time-critical processes and gradually expand BCM coverage. This way, you gain valuable experience and can iteratively improve the system.

  • Special requirements for critical infrastructure operators
  • Mandatory incident reporting
  • Increased documentation and audit requirements
  • International recognition of BCM maturity
  • Requires continuous improvement
  • External audits and regular recertification
  • Alignment with ISO 27001 requirements
  • Joint risk analysis and treatment
  • Synergies in documentation and processes
  1. Step-by-Step Approach: Use the BSI maturity model to implement BCM in stages – from Reactive BCMS to Development BCMS to Standard BCMS.
  2. Organizational Flexibility: Establish a Special Organizational Structure (BAO) with clear decision-making powers for effective crisis response.
  3. Foundation in Business Impact Analysis: Conduct a systematic BIA to identify time-critical processes and define maximum tolerable downtimes.
  4. Clear Terminology: Distinguish precisely between disruptions, emergencies, and crises to activate appropriate responses.
  5. Continuous Improvement: Treat BCM as a living process with exercises, lessons learned, and regular updates.