Objective
Ensure continuity threats, dependencies and single points of failure are assessed and risks outside tolerance are treated or formally accepted.
Control Activity
Compliance coordinates an annual and event-driven continuity risk assessment. The assessment verifies threat identification (cybersecurity attacks, natural disasters, system failures, regulatory risks, operational dependencies), single point of failure analysis (data centers, network providers, key staff expertise, supply chains), and that risk treatment strategies are assigned: Reduction (preventive controls), Transfer (insurance, outsourcing), Avoidance (ceasing risky activities), and Acceptance (low-impact risks). Risk assessments are updated when new threats or dependencies emerge. Management reviews material residual risks, treatment plans, overdue actions and formal risk acceptances.
Evidence
- Expected evidence: Continuity risk assessment
- Expected evidence: Scenario and dependency analysis
- Expected evidence: Treatment plans and risk acceptances
- Expected evidence: Management or Board escalation records
- Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample material risks and verify current assessment, ownership, due dates, escalation and closure evidence
- Testing frequency: annual and after material threat, dependency or operational change
Relationships
- Requirements: REQ-IT-005 Manage Computer Risk and Control Environment, REQ-IT-006 Maintain Business Continuity Management
- Policy: POL-BCM-001 Business Continuity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-BCM-003 Assess Continuity Risks and Treatment
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved Business Continuity Manual version 1.0.