Business Continuity & Resilience · BC-Q11

Question: Does the organization monitor key resilience metrics and report them to management?

Why This Matters

Without metrics, continuity maturity remains subjective. Quantitative indicators help management prioritize investment and oversight.

Maturity

0 — Unaware
No resilience metrics defined.
1 — Ad Hoc
Isolated metrics collected during audits.
2 — Defined
Key performance and risk indicators established.
3 — Managed
Reports generated quarterly for management review.
4 — Integrated
Metrics integrated with risk and compliance dashboards.
5 — Optimized
Automated resilience scorecard and predictive analytics.

How to Level Up

| From → To | Actions | |—|—| | 0 → 1 |List basic resilience indicators (RTO adherence, test completion). | | 1 → 2 |Define KPIs and KRIs formally. | | 2 → 3 |Establish reporting cadence and responsibility. | | 3 → 4 |Integrate with risk dashboards. | | 4 → 5 |Automate analytics and trend insights. |

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

| Purpose | Tool | Notes | |—|—|—| | Dashboards | Metabase | BCM performance trends | | Tracking | Airtable | KPI register | | Alerts | n8n | Report reminders |

Common Pitfalls

Compliance Mapping

| Standard | Clauses / Notes | |—|—| | ISO 22301 | 9.1 / 9.3 | | ISO 27001 | A.9.1 / A.10 | | NIST CSF 2.0 | GV.MA / RS.MI | | NIRMATA Mapping | BC-Q11 embeds continuity performance management. |