Business Continuity Planning and Exercises

Preparing for disruptions and disasters ensures organizations can maintain critical operations and recover quickly through tested continuity strategies.

6 slides · 3 min read · Domain 7

Slide 1

Business continuity planning (BCP) is a prudent, often required activity for organizations in various industries. The aim of BCP is to prepare the organization for disruptive, business-altering events, such as natural disasters, disease outbreaks, geopolitical conflicts, critical personnel loss, and other risk scenarios. Ultimately, the objective is to ensure that the organization can continue operating during and after a crisis.

NIST SP 800-34 and ISO 22301 are both frameworks for business continuity and disaster recovery, but they have different focuses and scopes.

NIST SP 800-34, specifically focuses on contingency planning for federal information systems, while ISO 22301 is an international standard for business continuity management systems (BCMS) applicable to any organization.

Business Impact Analysis

With focus on maintaining mission-essential functions during any type of disruption, it is important to first identify those essential mission and business functions. This is part of conducting a business impact analysis (BIA), a process that involves analyzing operational functions and assessing the potential impact of disruptions.

Engaging with stakeholders— primarily mission and process owners, managers, and departmental staff—is the key to determining the criticality of the process, system, or service.

impact considerations. Determining the MTD is important because, without it, continuity planners may face imprecise direction on (1) selecting an appropriate recovery method, and (2) the level of detail required when developing recovery procedures, including scope and content.

  • The RTO defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources, supported mission and business processes, and the MTD. Determining the information system resource RTO is important for selecting appropriate technologies best suited for meeting the MTD.

Considerations following a disruptive event should result in estimated timelines, commonly referred to as maximum tolerable downtime (MTD), recovery time objectives (RTOs), and recovery point objectives (RPOs). Organizations can use existing NIST templates for this process. These templates offer guidance on the defining and documenting the timelines.

  • The MTD represents the total amount of time that leaders and managers are willing to accept for a mission or business process outage or disruption. The MTD includes all
  • The RPO represents the point in time before a disruption or system outage, to which mission/business process data must be recovered (based on the most recent backup copy of the data) after an outage. (

This information can help determine appropriate strategies that an organization must adopt to achieve its continuity objectives and timelines. Additionally, these objectives and timelines are likely communicated to customers as part of a service level agreement.

Test and Maintain the BCP

BCPs should be tested at scheduled intervals, at least annually, and whenever significant organizational or environmental changes occur. Stakeholders should gather to practice their emergency roles and responsibilities through exercises of varying complexity.

Tabletop exercises are commonly used to simulate emergency situations in an informal, discussion-based setting.

Functional and full-scale exercises offer the opportunity to test response capabilities in conditions that closely resemble real emergencies.

As with any other type of plan, the BCP should be reviewed, updated, and revised as part of the plan maintenance process. Some elements in the plan, such as contact lists, may require frequent updates.

Test this domain