- Degeneration operations
- Recovery actions
3-3 Implementation
The organization should implement the countermeasures to protect their critical
IT resources and disseminate the BCP policy throughout the organization.
3-4 Exercise and reviewing
The organization should periodically (at least once a year) conduct the exercise
to ensure that the BCP policy is appropriately understood in the organization and
that the countermeasures are implemented appropriately. The organization should
also review the result of the exercise, and reflect lessons learned into the revised
guidelines. Reviewing should also include reevaluation of the risks to see if there is
any significant change in their environment, eg. there are new risks to be
considered, due to the technological advancement, etc.
4. Reference documents criteria
It is desirable to refer to international standards on BCP such as ISO 22301, in
order to be at par with international best practices.