Chapter 02
Chapter 02
Introduction
Business Continuity Standards provide auditable
criteria
Written for organizations of any size
Designed to integrate with similar standards and
management systems
ISO Standards developed by technical committees
of subject matter experts
Request made to ISO by interested parties
Consensus standards
American National Standards Institute (ANSI)
Process Approach
Process is a set of interrelated activities that
transform inputs into outputs
Process approach is the application of a system of
processes to achieve organizational objectives
Types of processes include:
Organizational Management
Resource Management
Measurement, Analysis, and Improvement
Process
Process Approach
Steps to implement process approach (ISO):
Identify the Processes of the Organization
Process Planning
Implementation and Measurement
Analysis
Corrective Action and Improvement
Process Approach
Horizontal and Vertical Management
Management System is the framework of
processes and procedures used to ensure that
an organization can fulfill all tasks required to
achieve a set of related business objectives
Plan, Do, Check, Act (PDCA)
Structures the Management System
PDCA used in most ISO Management
Standards
PDCA an Interactive Four Step Process
Business Process Improvement
Decision Making
Dr. Walter Shewhart
Plan, Do, Check, Act (PDCA)
Dr. William Edwards Deming
Variants
PDSA
OPDCA
Plan (Establish)
Define Objectives, Targets, Controls,
Processes, and Procedures
Inputs from Dependent or Upstream
Processes
Project Planning
Plan, Do, Check, Act (PDCA)
Do (Implement and Operate)
Implement Processes Indentified in
Planning Stage
May require PDCA Sub-process
Check (Monitor and Review)
Develop Metrics and Track Performance
Corrective Actions
Plan, Do, Check, Act (PDCA)
Act (Maintain and Improve)
Implement Corrective Actions
Continuous Improvement
Tasks
Milestones
Risk
Documentation
Organization of the Standards
Set context for BIA and Risk Assessment
Continuous Improvement
Clause 7 – Support
Identify and Provide Resources Necessary to
Support Program
Competence
Awareness
Communication
Documented Information
Organization of the Standards
Clause 8 – Operation
Represents the “Do” Component of PDCA
Operational Planning and Control
Business Impact Analysis and Risk Assessment
Supply Chain
Business Continuity Strategy
Resource Requirements