{"licence":{"name":"CC BY-SA 4.0","spdx":"CC-BY-SA-4.0","url":"https://creativecommons.org/licenses/by-sa/4.0/","attribution":"Atlas, a bilingual technical dictionary (https://cmaintz.github.io/tech-atlas/)"},"id":"security/business-continuity-plan","url":{"en":"https://cmaintz.github.io/tech-atlas/en/terms/security/business-continuity-plan/","da":"https://cmaintz.github.io/tech-atlas/da/terms/security/business-continuity-plan/"},"term":{"en":"Business continuity plan (BCP)","da":"Business continuity plan (BCP)"},"aka":{"en":["BCP","continuity plan"],"da":["BCP","kontinuitetsplan"]},"domain":["security"],"cluster":"incident-response","layer":"governance","status":"current","summary":{"en":"A plan for keeping the most important work going during and after a crisis, even while the systems are down.","da":"En plan for at holde det vigtigste arbejde i gang under og efter en krise, også mens systemerne er nede."},"body":{"formal":{"en":"A documented set of procedures that keeps critical activities running at an agreed minimum level during a disruption, falling back on manual routines where needed, in the order of priority set by the business impact analysis.","da":"Et dokumenteret sæt procedurer, der holder kritiske aktiviteter kørende på et aftalt minimumsniveau under en afbrydelse, om nødvendigt med manuelle rutiner, i den prioritering, konsekvensanalysen har fastlagt."},"plain":{"en":"Like a shop that keeps selling with a paper notebook and cash when the card terminal dies.","da":"Ligesom en butik, der bliver ved med at sælge med en notesblok og kontanter, når kortterminalen går ned."},"inPractice":{"en":"When an attack takes a municipality's systems down for a week, its care homes follow the BCP - medicine charts on paper, phone lists printed in advance and meal orders phoned through to the central kitchen.","da":"Da et cyberangreb lægger en kommunes systemer ned i en uge, følger plejehjemmene BCP'en - medicinskemaer på papir, telefonlister printet på forhånd og madbestillinger ringet ind til centralkøkkenet."},"whyItMatters":{"en":"Citizens and patients still need help while IT is being repaired; without an agreed plan B, staff improvise and the most urgent tasks may be the ones that stop.","da":"Borgere og patienter har stadig brug for hjælp, mens IT bliver repareret; uden en aftalt plan B improviserer medarbejderne, og de mest presserende opgaver kan være dem, der går i stå."}},"deepDive":{"en":"In ISO 22301:2019 the BCP is the output of a chain of requirements in clause 8. The business impact analysis (8.2.2) identifies prioritised activities, the impact of disrupting them over time and, for each, the maximum tolerable period of disruption (MTPD) and a recovery time objective that must fall within it; the risk assessment (8.2.3) looks at the causes. Clause 8.3 selects strategies and solutions, and clause 8.4 requires documented plans and procedures, including a response structure (8.4.2), warning and communication (8.4.3), the business continuity plans themselves (8.4.4) and recovery (8.4.5). Clause 8.5 requires an exercise programme and 8.6 an evaluation of the documentation and capabilities. ISO 22313 provides guidance on applying the requirements.\n\nA usable BCP is organised around activities, not systems. For each prioritised activity it states the minimum business continuity objective (the reduced service level that is acceptable during disruption), the workaround used to reach it, the people, premises, information, suppliers and equipment the workaround depends on, and the criteria for invoking and standing down the plan. Typical workarounds are paper forms and pre-printed lists, relocation to an alternate site, shifting work to another unit, or accepting a backlog to be processed later. Because manual work creates data that must later be entered into restored systems, the plan also needs a catch-up procedure, which is frequently forgotten.\n\nNIST SP 800-34 Rev. 1 distinguishes the BCP, which covers business processes, from the continuity of operations plan for mission-essential functions, the information system contingency plan for a single system and the disaster recovery plan for relocating systems to an alternate site. The practical boundary is that the BCP answers how the business keeps working, while the DRP answers how IT gets systems back; the recovery time objectives in the DRP must be derived from the BCP and BIA, not the other way round.\n\nRegulation increasingly makes this explicit. NIS2 Article 21(2)(c) lists business continuity, such as backup management and disaster recovery, and crisis management among the minimum cybersecurity risk-management measures, and ISO/IEC 27001:2022 Annex A 5.29 and 5.30 address information security during disruption and ICT readiness for business continuity. A common weakness in plans tested against cyberattacks is the assumption that disruption is local and short, when ransomware can remove all systems, including email, telephony tied to the network and the documents holding the plan itself, for weeks. Plans should therefore be available offline and assume that identity services and communication tools are unavailable.","da":"I ISO 22301:2019 er BCP'en resultatet af en kæde af krav i afsnit 8. Konsekvensanalysen (8.2.2) identificerer de prioriterede aktiviteter, konsekvensen af at afbryde dem over tid og for hver af dem den maksimalt tålelige afbrydelsesperiode (MTPD) og et mål for genoprettelsestid, der skal ligge inden for den; risikovurderingen (8.2.3) ser på årsagerne. Afsnit 8.3 udvælger strategier og løsninger, og afsnit 8.4 kræver dokumenterede planer og procedurer, herunder en beredskabsorganisation (8.4.2), varsling og kommunikation (8.4.3), selve kontinuitetsplanerne (8.4.4) og genopretning (8.4.5). Afsnit 8.5 kræver et øvelsesprogram og 8.6 en evaluering af dokumentation og kapabiliteter. ISO 22313 giver vejledning i at anvende kravene.\n\nEn brugbar BCP er organiseret omkring aktiviteter, ikke systemer. For hver prioriteret aktivitet angiver den det minimale kontinuitetsniveau (det reducerede serviceniveau, der er acceptabelt under afbrydelsen), den nødprocedure, der bruges til at nå det, de medarbejdere, lokaler, oplysninger, leverandører og det udstyr, nødproceduren afhænger af, og kriterierne for at aktivere og afslutte planen. Typiske nødprocedurer er papirblanketter og forudprintede lister, flytning til et alternativt sted, overførsel af arbejdet til en anden enhed eller accept af et efterslæb, der behandles senere. Fordi manuelt arbejde skaber data, der senere skal tastes ind i de genoprettede systemer, skal planen også have en procedure for at indhente efterslæbet, og den bliver ofte glemt.\n\nNIST SP 800-34 Rev. 1 skelner mellem BCP'en, der dækker forretningsprocesser, continuity of operations-planen for missionskritiske funktioner, beredskabsplanen for et enkelt informationssystem (ISCP) og disaster recovery-planen for at flytte systemer til et alternativt sted. Den praktiske grænse er, at BCP'en svarer på, hvordan forretningen bliver ved med at arbejde, mens DRP'en svarer på, hvordan IT får systemerne tilbage; målene for genoprettelsestid i DRP'en skal udledes af BCP'en og konsekvensanalysen, ikke omvendt.\n\nRegulering gør det i stigende grad eksplicit. NIS2 artikel 21, stk. 2, litra c, nævner driftskontinuitet, fx backupstyring og disaster recovery, samt krisestyring blandt minimumsforanstaltningerne for styring af cybersikkerhedsrisici, og ISO/IEC 27001:2022 bilag A 5.29 og 5.30 omhandler informationssikkerhed under afbrydelser og IKT-parathed til driftskontinuitet. En typisk svaghed i planer, der afprøves mod cyberangreb, er antagelsen om, at afbrydelsen er lokal og kortvarig, mens ransomware kan fjerne alle systemer, inklusive mail, netværksbaseret telefoni og de dokumenter, planen selv ligger i, i flere uger. Planerne bør derfor findes offline og forudsætte, at identitetstjenester og kommunikationsværktøjer ikke er tilgængelige."},"edges":[{"type":"requires","to":"security/business-impact-analysis","confidence":"high","strength":"normal"},{"type":"part-of","to":"security/contingency-plan","confidence":"high","strength":"normal"},{"type":"contrasts-with","to":"security/disaster-recovery-plan","why":{"en":"The BCP keeps the business working during the crisis; the DRP gets the technology back afterwards.","da":"BCP holder forretningen kørende under krisen; DRP får teknikken tilbage bagefter."},"confidence":"high","strength":"primary"},{"type":"used-with","to":"security/crisis-management","confidence":"high","strength":"normal"}],"depth":4,"sources":[{"title":"Cyber Security Fast Track - Ordliste","tier":"course-material"},{"title":"ISO 22301:2019","tier":"standard"},{"title":"NIST SP 800-34 Rev. 1","tier":"standard"}],"draft":true}