Search
Policy Areas

Business Continuity Planning

1

Steps

Prepare/Review/Update CO/Unit Risk assessment.

Responsible Party

BCP focal point

Template/Guideline
Explanatory Notes

- This includes Security Risk Assessment (SRA) which is prepared by DSS in consultation with the Security Management Team (SMT);
- Risk Assessment should be annexed to BCP.

2

Steps

Prepare/Review/Update CO/Unit Business Impact Analysis (BIA).

Responsible Party

BCP focal point

Template/Guideline
Explanatory Notes

- Identify critical business functions and assess the impact from identified risks along with Recovery Time Objectives (RTO) of critical functions along with necessary ICT tools/equipment to continue these functions;
- Identify essential CO documents; keep hard and soft copies in off-site location/OneDrive
- This is a collective exercise that is done in consultation with senior management;
- Assessment should be annexed to BCP.

3

Steps

Prepare/review/update CO/Unit BCP Document

Responsible Party

BCP focal point

Template/Guideline
Explanatory Notes

- Based on the Risk Assessment and BIA, review/update existing BCP to ensure inclusion of most recent critical function and critical staffing list with alternates and their contact details;
- Pre-identify off-site location to ensure that in the event of an emergency, CO/Unit can operate from the alternative site. Necessary power and ICT connectivity is essential including when/if working from home or from another agency office;
- ICT Disaster Recovery Plan is to be prepared.

4

Steps

Share draft BCP with all supporting documents with BMS Directorate

Responsible Party

BCP focal point

Template/Guideline
Explanatory Notes

Via email.

5

Steps

BMS Directorate review and provide CO/Units any comments

Responsible Party

Template/Guideline
Explanatory Notes

 Via email

6

Steps

 Approve/sign off BCP Documents

Responsible Party

Head of Office

Template/Guideline
Explanatory Notes

 - All supporting documents are to be annexed to the BCP

7

Steps

Arrange for BCP Test

Responsible Party

Head of Office

Template/Guideline
Explanatory Notes

- BCP simulation exercise should test the viability of the identified critical functions
and procedures in the way that they would be performed
in a real crisis/critical 
incident;
- The test can be conducted to include CO’s Crisis Management Plan, Business 
Continuity Plan, and/or ICT Disaster
Recovery Plans (i.e. one or several 
components of the plan)
- Lessons learnt should be drawn from the exercise and the BCP should be modified 
as necessary.

8

Steps

Upload signed BCP and BCP test report

Responsible Party

BCP focal point

Template/Guideline
Explanatory Notes