Model BCM Policy
Model BCM Policy
Model BCM Policy
[Statement of intent]
1
BS25999-1: 2006 Part 1 Code of Practice for business continuity management, applicable extract:
“BCM Policy Objectives begin at high level to be developed and refined in line with improving capability“
This organisation makes every effort to ensure that it is protected against risks and threats – for
example the hazards of fire, flood, loss of vital information, services and materials - that could
materially impact upon, disrupt or interrupt its operations. However, this organisation
recognises that the unexpected could and may happen, the effect of which could compromise
the ability to meet acceptable standards of business and of ethical behaviour. For these
reasons, this organisation is implementing a business continuity management programme
[BCMP] and business continuity plan [BCP] to protect our organisation, its people, our brand /
reputation, the interests of our stakeholders and the wider community.
[BCM definition]
BS25999: “The BCM policy should define the activities required to develop and implement a business
continuity capability and its management and maintenance, into the future”
This organisation will apply business continuity management [BCM] throughout to identify,
measure, evaluate, control and respond to risks and threats that have the potential for
preventing this organisation from attaining and maintaining its stated aims, as set out in the
mission statement. This organisation will achieve this by ensuring the ability to respond to
unexpected incidents that inhibit our ability to carry out key activities and processes, by means
of:
business impact analysis and risk assessment
cost-effective loss prevention and management
good practice resilience and damage limitation measures and procedures
a business BCP that provides structured response and recovery guidance;
a system of monitoring, testing & exercising, reviewing and training that ensures that the
BCMP is accepted by all as an embedded and essential part of our activities.
1
British Standards Institute copyright acknowledged throughout.
Foresight RSA Group plc 2009
[Methodology]
BS25999: “Context: size, nature, complexity, geography and criticality. Organisational culture”
Each unit of this organisation is responsible for developing, implementing and maintaining BCM
for its activities. This organisation provides training, guidance, assistance, methodologies,
model material and ongoing guidance. Units are not required to apply a single BCM & BCP
model. However, commonality of approach is encouraged, to ensure transfer of good practice
and to permit ease of maintenance and audit.
[Executive responsibilities]
BS25999: “Assigning responsibilities (governance)”
The Executive takes final responsibility for the strategic direction of the BCMP. The --- Director
acts on behalf of the executive in ensuring that the BCM arrangements meet and continue to
meet the changing needs of this organisation.
The --- Manager is the appointed BCM co-ordinator reporting to the --- Director and is charged
with ensuring continuing co-ordination and integrity of the BCMP and that those responsible for
unit BCM maintenance, exercising and operation, have the necessary level of support and
advice. All members of management are required to ensure the ongoing currency of the
elements of the BCMP for which they are responsible, including that refresher and succession
training is to be provided to all that have roles and responsibilities within the BCP.
BCM and the BCP form a vital part of this organisation’s business protection programme and
must therefore be implemented and maintained as an integral part of managing the business.
BCM is a regular agenda item for the Executive, demonstrating the importance of this subject.
Signed (CEO) Date