Business Continuity Management (BCM)

Business continuity management (BCM) is the management process by which an organisation makes sure that time-critical business processes survive an interruption. It determines which processes have to be available again and how quickly, holds strategies and plans ready for that, and demonstrates their effectiveness in tests and exercises.

ISMSLast reviewed:

Every protective measure can fail. Business continuity management picks up exactly where prevention ends: it answers not how an outage is prevented but how long the organisation can endure one, and how it keeps delivering during that time. The reference points are business processes and the services that customers, regulators and the supply chain expect, not individual systems.

How does BCM differ from information security?

An ISMS steers risks to confidentiality, integrity and availability and works largely preventively. BCM takes over the case that occurs anyway. Both systems draw on the same groundwork (the process map, the asset and provider inventory, availability protection needs) and feed each other inputs, but they do not replace one another. Running BCM as a sub-chapter of the ISMS routinely underestimates the coordination effort with the business areas outside IT. The article on running BCM and an ISMS together looks at where the two teams duplicate each other's work, what can be merged and what has to stay apart.

What is the BCM process?

PhaseContentOutput
Initiationpolicy, scope, roles, mandate from the management bodyBCM policy and mandate
Analysisbusiness impact analysis, supplementary risk analysistime-critical processes, time objectives, resource requirements
Strategychoosing the response option per class of resourcereasoned continuity strategies
Implementationpreventive measures, emergency organisation, plans, alertingdocumented and available procedures
Maintenancetests, exercises, reviews, updates after changesevidenced effectiveness

The cycle follows the same logic as other management systems. The difference is that the last phase is not optional: a plan that has never been exercised is a supposition.

Why does continuity strategy come before the plan?

The most common shortcut is to start writing plans immediately. The reverse order works better. For each class of resource (people, buildings, IT systems, service providers, equipment, information), decide first which option bridges an outage. The choices include redundancy, alternative sites, manual fallback procedures, prepared replacement procurement, contractually assured third-party services, and deliberately accepting the outage. Only that decision makes the time objectives from the business impact analysis viable, and only afterwards is a plan worth writing.

Which plans, roles and exercises does BCM need?

The strategies produce business continuity plans for degraded operation, restart and recovery plans for the return to normal operation, and the emergency organisation with alerting, deputies and communication channels. Exercising is graded: a tabletop walkthrough of the plan, a crisis team exercise, a functional test of individual procedures, and finally a restart under realistic conditions. No standard prescribes an exercise interval; it has to be set on a risk basis, justified and then kept to.

Which standards and regulations require BCM?

Internationally the reference point is ISO 22301:2019, supplemented since 2024 by Amendment 1:2024. In Germany it is BSI-Standard 200-4 in Version 1.0 of May 2023, which supersedes BSI-Standard 100-4. The practical difference is the way in. The BSI standard allows a staged build-out, and the tiers are not maturity levels assigned in hindsight but build paths chosen in advance; every chapter of the standard is marked with the tier it applies to.

TierWhat it achievesRelationship to ISO 22301
Reaktiv-BCMSestablishes the ability to respond first: alerting, responsibilities, crisis organisation; deeper analysis is deliberately deferredno conformity intended
Aufbau-BCMSadds a structured business impact analysis and documented plansintermediate step
Standard-BCMSfull management system with strategies, an exercise programme and improvementconforms to the requirements of ISO 22301:2019, and therefore certifiable to ISO 22301

There is no certificate for the BSI standard itself; according to the BSI, no certification to it is currently planned. For an English-speaking organisation that is the useful reading: a German counterparty naming 200-4 and a certification body naming ISO 22301 can be satisfied out of one system.

Independently of the standards, several legal acts require continuity provision expressly: the catalogue of measures in § 30(2) of the German BSI Act (BSIG) names, among other things, the maintenance of operations including backup and crisis management, and Regulation (EU) 2022/2554 (DORA) requires financial entities to have operational continuity arrangements in Chapter II, including regular testing.

Why does BCM fail when it is needed?

  • The time objectives come from the business areas' wishful thinking and have no technical backing.
  • Plans describe the restart of systems rather than the continuation of the business process.
  • Service providers are firmly built into the plan but contractually committed to nothing.
  • The emergency documentation lives solely in the environment whose failure it deals with.
  • After changes to processes, sites or providers, the analysis is not brought up to date.

Where BCM and security need the same inventory

BCM and information security are usually organised separately and yet work on the same question: what depends on what. In Rizzqo that structure exists once. A business process is a primary asset, the applications, systems, sites, providers and people-functions beneath it are supporting assets, and the process's requirement, particularly for availability, is passed along the chain.

Two practical things follow. The operator of a downstream system can see which process ultimately depends on them, and justify a recovery target against that rather than by feel. And a common point of failure stands out in the number of links before it materialises. The time objectives, contingency plans and exercises themselves still come out of continuity management; Rizzqo holds the dependencies beneath, which both disciplines need.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework