Model BCM Policy

Download as doc, pdf, or txt
Download as doc, pdf, or txt
You are on page 1of 3

Global Consulting

[2.1 - Model business continuity


management policy]
This model provides a basis upon which to develop a BCM policy that reflects your
organisation’s nature, culture and needs. To this end it is advisory and should be adapted to
reflect those requirements.

[Organisation’s mission statement]


We are committed to the highest standards of business and ethical behaviour, to fulfilling our
responsibilities to the communities that we serve and to the creation of long-term value for all
stakeholders on a socially and environmentally sustainable basis.

[Statement of intent]
1
BS25999-1: 2006 Part 1 Code of Practice for business continuity management, applicable extract:
“BCM Policy Objectives begin at high level to be developed and refined in line with improving capability“
This organisation makes every effort to ensure that it is protected against risks and threats – for
example the hazards of fire, flood, loss of vital information, services and materials - that could
materially impact upon, disrupt or interrupt its operations. However, this organisation
recognises that the unexpected could and may happen, the effect of which could compromise
the ability to meet acceptable standards of business and of ethical behaviour. For these
reasons, this organisation is implementing a business continuity management programme
[BCMP] and business continuity plan [BCP] to protect our organisation, its people, our brand /
reputation, the interests of our stakeholders and the wider community.

[BCM definition]
BS25999: “The BCM policy should define the activities required to develop and implement a business
continuity capability and its management and maintenance, into the future”
This organisation will apply business continuity management [BCM] throughout to identify,
measure, evaluate, control and respond to risks and threats that have the potential for
preventing this organisation from attaining and maintaining its stated aims, as set out in the
mission statement. This organisation will achieve this by ensuring the ability to respond to
unexpected incidents that inhibit our ability to carry out key activities and processes, by means
of:
 business impact analysis and risk assessment
 cost-effective loss prevention and management
 good practice resilience and damage limitation measures and procedures
 a business BCP that provides structured response and recovery guidance;
 a system of monitoring, testing & exercising, reviewing and training that ensures that the
BCMP is accepted by all as an embedded and essential part of our activities.

1
British Standards Institute copyright acknowledged throughout.
Foresight RSA Group plc 2009

Annual review required (date)


Global Consulting

[Objective & scope]


BS25999: “Top management to identify key products and services; extent of BCM”
Our business management continuity [BCM] objectives are to:
1. have in place cost-effective resilience and damage mitigation arrangements
2. recover key deliverables, within a suitable timeframe, following an incident or circumstances
that prevent an acceptable level of production and / or service defined via a strategic
analysis, or otherwise affect other key operations for a period in excess of define.
The scope of our business continuity plan [BCP] is that it would respond to ‘reasonably
foreseeable events’, including the following:
 man-made or natural disaster  epidemic or pandemic
 non-availability of key facilities,  non-availability of personnel
resources or materials  emergency authority action
 non-availability of information & / or  denial of access locally or regionally
communication technology/data
 regulatory or legal prohibition
 failure of utilities
 supplier, logistics or distribution failure
 death or serious injury

[Methodology]
BS25999: “Context: size, nature, complexity, geography and criticality. Organisational culture”
Each unit of this organisation is responsible for developing, implementing and maintaining BCM
for its activities. This organisation provides training, guidance, assistance, methodologies,
model material and ongoing guidance. Units are not required to apply a single BCM & BCP
model. However, commonality of approach is encouraged, to ensure transfer of good practice
and to permit ease of maintenance and audit.

[Executive responsibilities]
BS25999: “Assigning responsibilities (governance)”
The Executive takes final responsibility for the strategic direction of the BCMP. The --- Director
acts on behalf of the executive in ensuring that the BCM arrangements meet and continue to
meet the changing needs of this organisation.
The --- Manager is the appointed BCM co-ordinator reporting to the --- Director and is charged
with ensuring continuing co-ordination and integrity of the BCMP and that those responsible for
unit BCM maintenance, exercising and operation, have the necessary level of support and
advice. All members of management are required to ensure the ongoing currency of the
elements of the BCMP for which they are responsible, including that refresher and succession
training is to be provided to all that have roles and responsibilities within the BCP.
BCM and the BCP form a vital part of this organisation’s business protection programme and
must therefore be implemented and maintained as an integral part of managing the business.
BCM is a regular agenda item for the Executive, demonstrating the importance of this subject.
Signed (CEO) Date

Foresight RSA Group plc 2009 2

Annual review required (date)


Global
Click Consulting
here to return to index screen

Foresight RSA Group plc 2009 3

Annual review required (date)

You might also like