Business Continuity & Resilience · BC-Q06

Question: Are crisis-management and communication plans defined, with clear roles and escalation paths?

Why This Matters

During crises, structured communications reduce panic and maintain stakeholder trust. Defined roles enable swift decisions.

Maturity

0 — Unaware
No defined crisis process or contacts.
1 — Ad Hoc
Ad-hoc communications after incidents.
2 — Defined
Crisis plan with command structure and contacts.
3 — Managed
Regular updates and simulation drills conducted.
4 — Integrated
Aligned with PR, HR, and incident response playbooks.
5 — Optimized
Multi-channel alerting and decision dashboards.

How to Level Up

| From → To | Actions | |—|—| | 0 → 1 |List key contacts and backups.| | 1 → 2 |Document roles, responsibilities, and escalation matrix.| | 2 → 3 |Conduct mock drills and review post exercise.| | 3 → 4 |Link plan to incident and media response processes.| | 4 → 5 |Deploy automated notification and dashboard system. |

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

| Purpose | Tool | Notes | |—|—|—| | Alerts | Gotify / ntfy | Simple broadcasts | | Tracking | Airtable | Drill records | | Docs | Nextcloud | Version control |

Common Pitfalls

Compliance Mapping

| Standard | Clauses / Notes | |—|—| | ISO 22301 | 8.4 / 8.5 | | ISO 27001 | A.5.29 | | NIST CSF 2.0 | RS.CO / RC.CO | | NIRMATA Mapping | BC-Q06 builds crisis response and communication resilience. |