Objective

Ensure critical activities, dependencies, impact tolerances and recovery objectives remain complete, approved and internally consistent.

Control Activity

Compliance and Operations review the BIA at least annually and after significant organizational or technological changes. The review confirms identified critical functions necessary for survival and compliance, documented Maximum Tolerable Period of Disruption (MTPD) for each function, Recovery Time Objectives (RTOs) to restore operations, Recovery Point Objectives (RPOs) to determine acceptable data loss, recovery priorities, minimum resources, owner approval and resolution of inconsistencies.

Evidence

  • Expected evidence: Approved BIA and change log
  • Expected evidence: Critical activity and dependency inventory
  • Expected evidence: MTPD, RTO and RPO records
  • Expected evidence: Owner and management approvals
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample critical activities and trace impacts, dependencies and approved objectives through the BIA
  • Testing frequency: annual and after significant change

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved Business Continuity Manual version 1.0.