Objective

Ensure continuity threats, dependencies and single points of failure are assessed and risks outside tolerance are treated or formally accepted.

Control Activity

Compliance coordinates an annual and event-driven continuity risk assessment. The assessment verifies threat identification (cybersecurity attacks, natural disasters, system failures, regulatory risks, operational dependencies), single point of failure analysis (data centers, network providers, key staff expertise, supply chains), and that risk treatment strategies are assigned: Reduction (preventive controls), Transfer (insurance, outsourcing), Avoidance (ceasing risky activities), and Acceptance (low-impact risks). Risk assessments are updated when new threats or dependencies emerge. Management reviews material residual risks, treatment plans, overdue actions and formal risk acceptances.

Evidence

  • Expected evidence: Continuity risk assessment
  • Expected evidence: Scenario and dependency analysis
  • Expected evidence: Treatment plans and risk acceptances
  • Expected evidence: Management or Board escalation records
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample material risks and verify current assessment, ownership, due dates, escalation and closure evidence
  • Testing frequency: annual and after material threat, dependency or operational change

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved Business Continuity Manual version 1.0.