- Degeneration operations - Recovery actions 3-3 Implementation The organization should implement the countermeasures to protect their critical IT resources and disseminate the BCP policy throughout the organization. 3-4 Exercise and reviewing The organization should periodically (at least once a year) conduct the exercise to ensure that the BCP policy is appropriately understood in the organization and that the countermeasures are implemented appropriately. The organization should also review the result of the exercise, and reflect lessons learned into the revised guidelines. Reviewing should also include reevaluation of the risks to see if there is any significant change in their environment, eg. there are new risks to be considered, due to the technological advancement, etc. 4. Reference documents criteria It is desirable to refer to international standards on BCP such as ISO 22301, in order to be at par with international best practices.

Select target paragraph3