Skip to content
atlas

Business continuity plan (BCP)

Also known as: BCP, continuity plan

A plan for keeping the most important work going during and after a crisis, even while the systems are down.

Draft - this entry has not been reviewed yet.

Formal

A documented set of procedures that keeps critical activities running at an agreed minimum level during a disruption, falling back on manual routines where needed, in the order of priority set by the business impact analysis.

In plain English

Like a shop that keeps selling with a paper notebook and cash when the card terminal dies.

In practice

When an attack takes a municipality's systems down for a week, its care homes follow the BCP - medicine charts on paper, phone lists printed in advance and meal orders phoned through to the central kitchen.

Why it matters

Citizens and patients still need help while IT is being repaired; without an agreed plan B, staff improvise and the most urgent tasks may be the ones that stop.

Technical deep dive

In ISO 22301:2019 the BCP is the output of a chain of requirements in clause 8. The business impact analysis (8.2.2) identifies prioritised activities, the impact of disrupting them over time and, for each, the maximum tolerable period of disruption (MTPD) and a recovery time objective that must fall within it; the risk assessment (8.2.3) looks at the causes. Clause 8.3 selects strategies and solutions, and clause 8.4 requires documented plans and procedures, including a response structure (8.4.2), warning and communication (8.4.3), the business continuity plans themselves (8.4.4) and recovery (8.4.5). Clause 8.5 requires an exercise programme and 8.6 an evaluation of the documentation and capabilities. ISO 22313 provides guidance on applying the requirements.

A usable BCP is organised around activities, not systems. For each prioritised activity it states the minimum business continuity objective (the reduced service level that is acceptable during disruption), the workaround used to reach it, the people, premises, information, suppliers and equipment the workaround depends on, and the criteria for invoking and standing down the plan. Typical workarounds are paper forms and pre-printed lists, relocation to an alternate site, shifting work to another unit, or accepting a backlog to be processed later. Because manual work creates data that must later be entered into restored systems, the plan also needs a catch-up procedure, which is frequently forgotten.

NIST SP 800-34 Rev. 1 distinguishes the BCP, which covers business processes, from the continuity of operations plan for mission-essential functions, the information system contingency plan for a single system and the disaster recovery plan for relocating systems to an alternate site. The practical boundary is that the BCP answers how the business keeps working, while the DRP answers how IT gets systems back; the recovery time objectives in the DRP must be derived from the BCP and BIA, not the other way round.

Regulation increasingly makes this explicit. NIS2 Article 21(2)(c) lists business continuity, such as backup management and disaster recovery, and crisis management among the minimum cybersecurity risk-management measures, and ISO/IEC 27001:2022 Annex A 5.29 and 5.30 address information security during disruption and ICT readiness for business continuity. A common weakness in plans tested against cyberattacks is the assumption that disruption is local and short, when ransomware can remove all systems, including email, telephony tied to the network and the documents holding the plan itself, for weeks. Plans should therefore be available offline and assume that identity services and communication tools are unavailable.

What to learn first

Everything this builds on, foundations first.

  1. Asset inventory
  2. →Availability
  3. →CIA triad
  4. →Asset
  5. →Critical assets
  6. →Impact
  7. →Business impact analysis (BIA)
  8. →Business continuity plan (BCP)

Relationships

Sources & further reading

Standards & official texts

  • ISO 22301:2019
  • NIST SP 800-34 Rev. 1

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.