Purpose

Maintain feasible continuity and recovery arrangements that meet approved recovery objectives across people, premises, technology, data and suppliers. To mitigate disruptions, Bitkaya implements documented strategies and maintains sub-plans for each critical area.

Steps

#ActionDetailsEvidence
1Select continuity strategiesUse approved BIA and risk assessment to select strategies for each critical activityStrategy document
2Define alternate worksitesSecondary offices and reciprocal arrangementsStrategy document
3Define remote work arrangementsVPN access, MFA, encrypted communicationStrategy document
4Define data backup & recoveryGeographically distributed backups, real-time replication for mission-critical dataBackup arrangements
5Define supplier managementContinuity clauses in SLAs, backup vendors identifiedSupplier arrangements
6Maintain Principal BCM PlanCrisis command structure, emergency roles, call trees, vendor/emergency responder directories, decision-making protocolsBCM plan
7Maintain IT DR PlanProcedures for restoring IT infrastructure, applications, data; annual testingIT DR plan
8Maintain Cybersecurity Recovery PlanIncident playbooks for ransomware, DDoS, insider threatsCyber recovery plan
9Maintain Building Evacuation PlanRoutes, muster points, responsibilities, quarterly drillsEvacuation plan
10Confirm supplier continuity provisionsContinuity, recovery, and exit provisions for critical/essential outsourcing; backup-provider or transition arrangements where proportionateSupplier continuity evidence
11Verify plan completenessPlans address dependencies, recovery sequence, MTPD, RTO, RPO, minimum operating capacityVerification record
12Obtain owner approvalUpdate plans after material change, test findings, incident lessons, or supplier changesApproval record

Exceptions and Escalation

Any strategy that cannot meet an approved recovery objective shall be recorded as a risk and escalated for treatment or formal acceptance.

Records

  • Approved continuity and recovery strategies
  • BCM, disaster recovery, cyber recovery and evacuation plans
  • Backup and restoration arrangements
  • Supplier continuity and exit evidence
  • Plan review and approval records

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: annual and after material change or test finding

History

  • 2026-07-26: Created from sections 8 and 9 of the approved Business Continuity Manual.