Domain 4: IS Operations and Business Resilience7 min · 3 questions

Business Continuity Planning

The BCP keeps the whole business running through a disruption; the DR plan is its IT subset. The exam tests that scope difference, and that a plan never tested or updated gives no assurance.

What this makes you able to do

Evaluate whether a business continuity plan keeps the whole organisation operating through disruption and is owned, maintained and tested.

By the end you can

  • Distinguish the business continuity plan from the disaster recovery plan.
  • Explain why a BCP must be maintained and tested, not written once.
  • Identify who is accountable for the BCP.

Transcript

Business continuity planning. This lesson draws a line between two plans that are constantly used interchangeably, and it insists that a plan is something you maintain and rehearse, not a document you produce once.

The scene. The organisation has a disaster recovery plan for its data centre, and everyone calls it the continuity plan. Then a burst pipe closes the head office for a fortnight. The servers are fine, so the D-R plan never triggers, but nobody knows where staff should work, how customers will be answered, or which processes must run manually. The technology was covered. The business was not.

So, two plans, two scopes. The business continuity plan, the B-C-P, is the broad plan for keeping the whole organisation operating through a disruption: its critical business processes, its people, its facilities, its communications. It answers, how does the business keep functioning. The disaster recovery plan, the D-R-P, is a subset, focused specifically on recovering I-T systems and technology. It answers, how do we get the systems back.

The relationship is one of scope: the D-R-P sits inside the B-C-P, and I-T recovery exists to serve business continuity, not the other way round. The burst pipe is the classic illustration, the D-R-P was intact and completely irrelevant, because the disruption was to the business, not the technology.

And a B-C-P addresses any disruption, not only natural disasters: a cyberattack, a supply-chain failure, a pandemic, a closed building. The disruption that spares the technology can still stop the business, which is exactly what the burst pipe did.

Now the second theme. A plan is a capability, not a document. A continuity plan written once and filed is worth very little, the same way a two-year-old compliance certificate was in Domain two. Two things keep a B-C-P real.

First, maintenance. The business changes, new processes, new systems, new sites, people, so the plan must be kept current, or it drifts into describing an organisation that no longer exists.

And second, testing. A plan that has never been exercised is untested theory. Testing reveals the gaps, the missing contact, the assumption that does not hold, the step that takes far longer than planned, while it is still safe to find them.

So an outdated, untested plan gives no assurance it would work when invoked, which is exactly when you cannot afford to discover it does not. When a question describes a continuity plan written years ago, never updated and never tested, that lack of assurance is the concern.

And who is accountable. Because business continuity spans the whole organisation, accountability for the B-C-P rests with senior management, as a governance responsibility, just as risk appetite sat with the board in Domain two.

That does not mean I-T is uninvolved. I-T owns and runs the D-R component. But the enterprise-wide continuity plan is not an I-T deliverable, it is a management one. Senior management sponsors it, ensures it reflects the priorities the B-I-A established, and sees that it is maintained and tested.

So carry this away. The B-C-P is the whole business; the D-R-P is the I-T subset within it, and a disruption that spares the technology can still stop the business. And an unmaintained, untested plan gives no assurance, which is the entire point, so continuity is maintained and exercised, not written once and shelved.

Knowledge check
0 / 3
  1. 1.How does a business continuity plan (BCP) differ from a disaster recovery plan (DRP)?

  2. 2.A business continuity plan was written three years ago, has never been tested, and has not been updated despite major changes to the business. What is the MAIN concern?

  3. 3.Who is ultimately accountable for the organisation's business continuity plan?

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.