Every protective measure can fail. Business continuity management picks up exactly where prevention ends: it answers not how an outage is prevented but how long the organisation can endure one, and how it keeps delivering during that time. The reference points are business processes and the services that customers, regulators and the supply chain expect, not individual systems.
How does BCM differ from information security?
An ISMS steers risks to confidentiality, integrity and availability and works largely preventively. BCM takes over the case that occurs anyway. Both systems draw on the same groundwork (the process map, the asset and provider inventory, availability protection needs) and feed each other inputs, but they do not replace one another. Running BCM as a sub-chapter of the ISMS routinely underestimates the coordination effort with the business areas outside IT. The article on running BCM and an ISMS together looks at where the two teams duplicate each other's work, what can be merged and what has to stay apart.
What is the BCM process?
| Phase | Content | Output |
|---|---|---|
| Initiation | policy, scope, roles, mandate from the management body | BCM policy and mandate |
| Analysis | business impact analysis, supplementary risk analysis | time-critical processes, time objectives, resource requirements |
| Strategy | choosing the response option per class of resource | reasoned continuity strategies |
| Implementation | preventive measures, emergency organisation, plans, alerting | documented and available procedures |
| Maintenance | tests, exercises, reviews, updates after changes | evidenced effectiveness |
The cycle follows the same logic as other management systems. The difference is that the last phase is not optional: a plan that has never been exercised is a supposition.
Why does continuity strategy come before the plan?
The most common shortcut is to start writing plans immediately. The reverse order works better. For each class of resource (people, buildings, IT systems, service providers, equipment, information), decide first which option bridges an outage. The choices include redundancy, alternative sites, manual fallback procedures, prepared replacement procurement, contractually assured third-party services, and deliberately accepting the outage. Only that decision makes the time objectives from the business impact analysis viable, and only afterwards is a plan worth writing.
Which plans, roles and exercises does BCM need?
The strategies produce business continuity plans for degraded operation, restart and recovery plans for the return to normal operation, and the emergency organisation with alerting, deputies and communication channels. Exercising is graded: a tabletop walkthrough of the plan, a crisis team exercise, a functional test of individual procedures, and finally a restart under realistic conditions. No standard prescribes an exercise interval; it has to be set on a risk basis, justified and then kept to.
Which standards and regulations require BCM?
Internationally the reference point is ISO 22301:2019, supplemented since 2024 by Amendment 1:2024. In Germany it is BSI-Standard 200-4 in Version 1.0 of May 2023, which supersedes BSI-Standard 100-4. The practical difference is the way in. The BSI standard allows a staged build-out, and the tiers are not maturity levels assigned in hindsight but build paths chosen in advance; every chapter of the standard is marked with the tier it applies to.
| Tier | What it achieves | Relationship to ISO 22301 |
|---|---|---|
| Reaktiv-BCMS | establishes the ability to respond first: alerting, responsibilities, crisis organisation; deeper analysis is deliberately deferred | no conformity intended |
| Aufbau-BCMS | adds a structured business impact analysis and documented plans | intermediate step |
| Standard-BCMS | full management system with strategies, an exercise programme and improvement | conforms to the requirements of ISO 22301:2019, and therefore certifiable to ISO 22301 |
There is no certificate for the BSI standard itself; according to the BSI, no certification to it is currently planned. For an English-speaking organisation that is the useful reading: a German counterparty naming 200-4 and a certification body naming ISO 22301 can be satisfied out of one system.
Independently of the standards, several legal acts require continuity provision expressly: the catalogue of measures in § 30(2) of the German BSI Act (BSIG) names, among other things, the maintenance of operations including backup and crisis management, and Regulation (EU) 2022/2554 (DORA) requires financial entities to have operational continuity arrangements in Chapter II, including regular testing.
Why does BCM fail when it is needed?
- The time objectives come from the business areas' wishful thinking and have no technical backing.
- Plans describe the restart of systems rather than the continuation of the business process.
- Service providers are firmly built into the plan but contractually committed to nothing.
- The emergency documentation lives solely in the environment whose failure it deals with.
- After changes to processes, sites or providers, the analysis is not brought up to date.
Where BCM and security need the same inventory
BCM and information security are usually organised separately and yet work on the same question: what depends on what. In Rizzqo that structure exists once. A business process is a primary asset, the applications, systems, sites, providers and people-functions beneath it are supporting assets, and the process's requirement, particularly for availability, is passed along the chain.
Two practical things follow. The operator of a downstream system can see which process ultimately depends on them, and justify a recovery target against that rather than by feel. And a common point of failure stands out in the number of links before it materialises. The time objectives, contingency plans and exercises themselves still come out of continuity management; Rizzqo holds the dependencies beneath, which both disciplines need.