Business Continuity & Resilience · BC-Q01

Question: Has the organization defined a Business Continuity Management (BCM) policy, scope, and objectives?

Why This Matters

A clear BCM policy ensures the organization can sustain critical operations during disruption and fulfil legal and contractual obligations.

Maturity

0 — Unaware
No BCM policy or defined objectives.
1 — Ad Hoc
Continuity activities informal and uncoordinated.
2 — Defined
BCM policy approved with scope and responsibilities.
3 — Managed
Objectives mapped to critical functions and reviewed annually.
4 — Integrated
BCM aligned with risk and incident programs.
5 — Optimized
Continuous resilience governance with dashboards and KPIs.

How to Level Up

| From → To | Actions | |—|—| | 0 → 1 |Identify business functions and dependencies. | | 1 → 2 |Draft and approve BCM policy and scope. | | 2 → 3 |Set continuity objectives and review frequency. | | 3 → 4 |Integrate BCM into enterprise risk register. | | 4 → 5 |Automate reporting and dashboards. |

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

| Purpose | Tool | Notes | |—|—|—| | Policy storage | Nextcloud | Version control | | Tracking | Airtable | Objective register | | Visualization | Metabase | Status dashboard |

Common Pitfalls

Compliance Mapping

| Standard | Clauses / Notes | |—|—| | ISO/IEC 22301 | 4–8 (BCM framework) | | ISO/IEC 27001 | A.5.30 | | NIST CSF 2.0 | RS.RP | | NIRMATA Mapping | BC-Q01 defines the foundation of organizational resilience. |