Purpose
Maintain feasible continuity and recovery arrangements that meet approved recovery objectives across people, premises, technology, data and suppliers. To mitigate disruptions, Bitkaya implements documented strategies and maintains sub-plans for each critical area.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Select continuity strategies | Use approved BIA and risk assessment to select strategies for each critical activity | Strategy document |
| 2 | Define alternate worksites | Secondary offices and reciprocal arrangements | Strategy document |
| 3 | Define remote work arrangements | VPN access, MFA, encrypted communication | Strategy document |
| 4 | Define data backup & recovery | Geographically distributed backups, real-time replication for mission-critical data | Backup arrangements |
| 5 | Define supplier management | Continuity clauses in SLAs, backup vendors identified | Supplier arrangements |
| 6 | Maintain Principal BCM Plan | Crisis command structure, emergency roles, call trees, vendor/emergency responder directories, decision-making protocols | BCM plan |
| 7 | Maintain IT DR Plan | Procedures for restoring IT infrastructure, applications, data; annual testing | IT DR plan |
| 8 | Maintain Cybersecurity Recovery Plan | Incident playbooks for ransomware, DDoS, insider threats | Cyber recovery plan |
| 9 | Maintain Building Evacuation Plan | Routes, muster points, responsibilities, quarterly drills | Evacuation plan |
| 10 | Confirm supplier continuity provisions | Continuity, recovery, and exit provisions for critical/essential outsourcing; backup-provider or transition arrangements where proportionate | Supplier continuity evidence |
| 11 | Verify plan completeness | Plans address dependencies, recovery sequence, MTPD, RTO, RPO, minimum operating capacity | Verification record |
| 12 | Obtain owner approval | Update plans after material change, test findings, incident lessons, or supplier changes | Approval record |
Exceptions and Escalation
Any strategy that cannot meet an approved recovery objective shall be recorded as a risk and escalated for treatment or formal acceptance.
Records
- Approved continuity and recovery strategies
- BCM, disaster recovery, cyber recovery and evacuation plans
- Backup and restoration arrangements
- Supplier continuity and exit evidence
- Plan review and approval records
Relationships
- Policy: POL-BCM-001 Business Continuity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-BCM-004 Ensure Continuity Strategies and Sub-Plans Are Maintained
- Outsourcing procedure: PROC-OUT-007 Manage Outsourcing Continuity Exit and Sub-Outsourcing
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: annual and after material change or test finding
History
- 2026-07-26: Created from sections 8 and 9 of the approved Business Continuity Manual.