Business Continuity & Resilience · BC-Q07

Question: Are continuity and DR plans tested periodically through tabletop or full-scale exercises?

Why This Matters

Testing validates that plans work under pressure and that teams understand their roles during a real disruption.

Maturity

0 — Unaware
No testing conducted.
1 — Ad Hoc
Tests performed informally and not documented.
2 — Defined
Annual tabletop drills for key processes.
3 — Managed
Full-scale or cross-functional tests with action plans.
4 — Integrated
Testing aligned to risk and incident framework.
5 — Optimized
Continuous scenario simulation and digital exercises.

How to Level Up

| From → To | Actions | |—|—| | 0 → 1 |Schedule a basic tabletop for critical processes.| | 1 → 2 |Define test scope, criteria, and roles.| | 2 → 3 |Conduct multi-team exercises and record lessons.| | 3 → 4 |Integrate findings into risk and improvement plans.| | 4 → 5 |Introduce digital simulations and continuous readiness. |

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

| Purpose | Tool | Notes | |—|—|—| | Tracking | Airtable | Test register | | Recording | OBS / Zoom | Exercise capture | | Visualization | Metabase | Trend charts |

Common Pitfalls

Compliance Mapping

| Standard | Clauses / Notes | |—|—| | ISO 22301 | 8.5 / 9.1 | | ISO 27001 | A.5.30 | | NIST CSF 2.0 | RS.IM / GV.MA | | NIRMATA Mapping | BC-Q07 validates continuity plans through structured testing. |