Business Continuity & Resilience · BC-Q08

Question: Are lessons from incidents and tests tracked and incorporated into updated continuity and recovery plans?

Why This Matters

Improvement loops convert experience into resilience. Without review, the same gaps reappear in future crises.

Maturity

0 — Unaware
No post-incident review or lessons log.
1 — Ad Hoc
Findings shared verbally without tracking.
2 — Defined
Template for lessons learned and action log.
3 — Managed
Actions assigned and tracked to closure.
4 — Integrated
Outputs feed risk register and training updates.
5 — Optimized
Automated trends and predictive insights shared quarterly.

How to Level Up

| From → To | Actions | |—|—| | 0 → 1 |Record key lessons from past incidents.| | 1 → 2 |Adopt standard template for lessons log.| | 2 → 3 |Assign owners and due dates for actions.| | 3 → 4 |Link to risk and training programs.| | 4 → 5 |Automate trends and dashboards. |

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

| Purpose | Tool | Notes | |—|—|—| | Tracking | Airtable | Lessons register | | Dashboards | Metabase | Trend analysis | | Collab | Nextcloud | Versioned plans |

Common Pitfalls

Compliance Mapping

| Standard | Clauses / Notes | |—|—| | ISO 22301 | 10.2 / 9.1 | | ISO 27001 | A.10 (Improvement) | | NIST CSF 2.0 | GV.MA / RS.IM | | NIRMATA Mapping | BC-Q08 institutionalizes learning and resilience growth. |