How proper document organization can support your organization before, during, and after an incident.
Over the last few months, organizations have come face-to-face with impacts and disruptions to their business as they battle the effects of COVID-19. As organizations turn to their business continuity plans and procedures for guidance, some have found that they are using disparate plans, strategies, and communication methods across different business units and physical office locations. This has dramatically impacted the response of those organizations and added stressors to an already critical situation.Why This Is Happening
You may be asking, "What caused this? Why are they relying on inadequately documented plans and procedures when they can’t afford inefficient responses?" The answer is document organization, and while simple, it is a critical element to the success of business continuity planning and your overall Business Continuity Management System (BCMS). Effective organization is a foundational element of a successful business. This becomes apparent as you begin crafting business processes into effective workflows or ensuring that reporting structures are organized to minimize downtime and distractions. These are highly visible examples of how document organization can impact your organization. But a more obscure and impactful area that you should devote resources to is document management. Management of both digital and physical documentation is crucial in the business continuity planning and management process. While each of the following areas may be implemented using different means for digital and physical assets, they must come together to support your overall BCMS effectiveness as prescribed in ISO 22301 – Societal Security - Business Continuity Management Systems. While these items are prescribed within the ISO 22301 standard, they can apply to organizations regardless of which framework you are currently aligning to for business continuity or overall governance management.Revision Control (ISO 22301 Section 7.5.2 Creating and Updating)
When an organization adheres to the practice of continuously updating, improving, and revising its business continuity management system, there is a risk of outdated material being referenced. To mitigate this risk, a formal and effective change management protocol should be in place to ensure that only the current version is actively published. The change management protocol should mandate an audit log of all changes made to the document to include who made the changes as well as a date and summary of changes made. Some documents that may demonstrate the importance of revision control in your environment are:- Evacuation Procedures
- BCMS Contact Lists
- Regulatory and Legal Requirements
- Business Continuity Policies
- Business Impact Analysis Documents
- Communication Plans
Access Control (ISO 22301 Section 7.5.3 Control of Documented Information)
Proper access control measures must be in place to guarantee that only authorized changes, preferably from the Business Continuity Manager or leadership team, are published. By incorporating effective access control measures, the documentation supporting the BCMS maintains its confidentiality, availability, and integrity. This will assist in ensuring that all documentation aligns with the organization's overall business continuity strategy and has been approved by management.Distribution and Retrieval (ISO 22301 Section 7.5.3 Control of Documented Information)
In all organizations, particularly in those with global locations or a distributed workforce, it is crucial to ensure all response and management personnel are utilizing the same recovery and preparedness documentation. This is necessary to prevent situations like those above from occurring within your own organization. Maintaining these documents digitally allows for easy retrieval and access both during preparedness and training situations as well as during times of emergencies. There are many roles in which document management serves as a crucial element. Proper document management is required to support the foundation of an established and operating BCMS, something some are discovering they do not possess. While the best time to build your BCMS environment and all the various supporting elements is during periods of relative calm (and well before the processes are needed to be utilized), the second-best time is today.Contact Us
If your organization is at the beginning of their journey towards developing a mature BCMS, or if you are looking to further mature your existing program, please request to speak to one of our qualified team members here. We’ll guide you in developing a robust BMCS that your team and customers can be confident in.
Glenn Chamberlain
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)