Appendix 2. Business Continuity Planning (BCP)
1. Objective
This appendix is intended to encourage governments to ensure the availability of
critical IT resources in the government and CII operators, by implementing
necessary countermeasures against disruptions in their IT resources and putting in
place appropriate BCP policies.
2. Expectation for government
It is desirable that the government ensures that government agencies and CII
operators identify necessary IT resources in their organizations, take appropriate
countermeasures to protect them, and make sure that the BCP management cycle is
effectively working in their respective organizations. It is also desirable that the
government provides policies or guidelines for government agencies and CII
operators to encourage them to make their BCP more effective, as well as advices or
supports if needed.
3. BCP management cycle
In order to make BCP effective, it is desirable to establish BCP management cycle
in each governmental organization or CII operator.
BCP management cycle contains the following 4 items:
3-1 Understanding the organization
An organization should understand the internal/external environment
surrounding their organization. It also has to recognize the characteristic of risks
they may face, and evaluate the impact of these risks. Once they become clear, the
organization should identify critical IT resources to be protected, utilizing
evaluating method such as a Business Impact Analysis (BIA)
3-2 BCP planning and BCP policy development
The organization should plan necessary countermeasures to mitigate risks on
the critical IT resources that were identified in the understanding phase (3-1).
Moreover, the organization should establish a BCP policy which describes basic
ideas and instructions that members of the organization should follow:
The items in the BCP policy should include:
- Objective of BCP
- Risks to be mitigated
- Identified critical IT resources
- Response team and their responsibilities
- Initial actions