eBook 2: Chapter 5
Business Continuity Strategy Phase of the BCM Planning Methodology for
The Saudi Mortgage Guarantees Services Company
Introduction
![[BCM] [Damanat] [E2] [C5] Business Continuity Strategy](https://no-cache.hubspot.com/cta/default/3893111/a27d7e1e-8571-421d-9467-cc02614820e1.png)
The Business Continuity Strategy (BCS) phase is the stage of the Business Continuity Management (BCM) Planning Methodology in which The Saudi Mortgage Guarantees Services Company (Damanat) determines how its Critical Business Functions (CBFs) will be protected, continued and recovered following a disruptive incident.
The preceding Risk Analysis and Review (RAR) phase identifies the threats, vulnerabilities and single points of failure that could disrupt Damanat.
The Business Impact Analysis (BIA) establishes which business functions and supporting activities require priority recovery, how quickly they must be restored and what minimum resources are required.
The Business Continuity Strategy phase translates these findings into practical solutions.
In simple terms:
-
RAR identifies what could cause disruption.
-
BIA identifies what must be recovered and by when.
-
BCS determines how continuity and recovery will be achieved.
For Damanat, business continuity strategies should address the combination of people, processes, technology, information, premises, suppliers and external interfaces required to support mortgage guarantee operations and other Critical Business Functions.
The selected strategies should incorporate three complementary forms of resilience:
Prevention – reducing the likelihood of disruption.
Mitigation – reducing the severity of the consequences when disruption occurs.
Recovery – restoring affected Critical Business Functions and resources within predetermined recovery objectives.
The objective is not to eliminate every possible disruption. That is neither realistic nor economically practical. Instead, Damanat should establish a balanced portfolio of preventive, mitigating and recovery capabilities that allows priority business activities to remain within acceptable levels of disruption.
Purpose of the BC Strategy Phase
The purpose of the BCS phase is to identify, evaluate, select and approve continuity solutions that enable Damanat to achieve the recovery requirements established during the BIA.
The phase should answer questions such as:
- How will critical work continue if the primary office cannot be used?
- How will Damanat operate if critical employees are unavailable?
- How will technology services be restored following a major failure?

- How will critical data be recovered?
- How will Damanat continue operating if a key supplier becomes unavailable?
- How will mortgage guarantee applications be processed if normal systems are unavailable?
- How will participating financial institutions communicate with Damanat during a disruption?
- What minimum level of service must be maintained?
- What alternative arrangements must be established before an incident occurs?
- How quickly must recovery resources become available?
The resulting strategy should provide the foundation for the next BCM phase: Plan Development (PD).
Principles for Selecting Business Continuity Strategies
Business Continuity Strategies should not be selected simply because they represent common industry practices.
Each strategy should be supported by the results of Damanat's RAR and BIA.
The selection process should consider:
Recovery Requirements
The strategy must be capable of meeting the approved Recovery Time Objective (RTO), Recovery Point Objective (RPO), Maximum Acceptable Outage (MAO) and Minimum Business Continuity Objective (MBCO), where applicable.
Risk Exposure
Higher-risk functions may require greater resilience or redundancy.
Operational Feasibility
The solution must work under realistic disruption conditions.
Resource Availability
The required people, facilities, technology, information, and suppliers must be available when the strategy is activated.
Cost
Implementation and maintenance costs should be proportionate to the potential consequences of disruption.
Regulatory Requirements
The strategy should meet applicable legal, regulatory and supervisory expectations.
Dependency Requirements
The strategy should take account of internal and external dependencies.
Scalability
The strategy should remain effective against disruptions of varying durations and severities.
Sustainability
Damanat should be able to operate under the continuity arrangement for the period required to restore normal operations.
Regulatory Alignment of Damanat's Continuity Strategy
The Saudi Central Bank's Business Continuity Management Framework requires a business continuity strategy to be formally defined, approved, implemented, maintained, and aligned with the organisation's strategic objectives.
The framework also requires BIA results to identify recovery objectives, interdependencies, and supporting resources, while continuity plans must support the continuation of critical activities within those recovery objectives.
The SAMA framework also addresses alternative business workspaces, technology disaster recovery, backup and recovery processes, critical service providers, and contractual arrangements supporting continuity.
It specifies that alternative workspaces should support the delivery of critical processes in accordance with BIA recovery objectives, and that IT Disaster Recovery Plans should align with the BIA and restore critical technology infrastructure, data, systems, networks, and applications.
For Damanat, this means strategy selection should be demonstrably linked to:
BIA Requirement → Selected Strategy → Required Capability → Recovery Evidence
For example:
RTO of four hours → Alternative processing capability → Remote access and standby technology → Recovery test evidence
This traceability demonstrates that continuity arrangements are based on established business requirements rather than arbitrary technical solutions.
Business Continuity Strategies for Damanat's Critical Business Functions
Business Continuity Strategies for Damanat's Critical Business Functions should establish the capabilities necessary to maintain an acceptable level of mortgage guarantee and supporting operations during disruption.
A Critical Business Function normally depends upon several resources simultaneously. A recovery strategy should therefore not focus only on a single dimension such as technology.
For example, recovering a mortgage guarantee application system will not restore Mortgage Guarantee Origination if:
- employees cannot access the system;
- authorised approvers are unavailable;
- application data cannot be retrieved;
- participating financial institutions cannot connect;
- supporting risk information is unavailable; or
- the operating premises cannot be accessed.
Damanat should therefore develop strategies across the following resource dimensions:
People
→ Processes
→ Technology
→ Information and Data
→ Premises
→ Suppliers and Third Parties
→ Communications
→ External Dependencies
Each Critical Business Function should have an appropriate combination of strategies covering these dimensions.
Prevention Strategies
Prevention strategies reduce the likelihood of disruption.
These arrangements generally operate before an incident and form part of normal business operations.
For Damanat, preventive measures may include:
- infrastructure redundancy;
- preventive system maintenance;
- cybersecurity controls;
- resilient telecommunications;
- capacity monitoring;
- access-control mechanisms;
- change-management controls;
- staff cross-training;
- succession planning;
- supplier due diligence;
- preventive equipment maintenance;
- backup power arrangements;
- information-security controls;
- segregation of critical infrastructure;
- process quality controls; and
- monitoring of key service providers.
Example: Mortgage Guarantee Origination
If Mortgage Guarantee Origination depends heavily on a central processing platform, preventive strategies might include:
- resilient infrastructure;
- redundant network paths;
- high-availability application components;
- database replication;
- proactive monitoring; and
- controlled system-change processes.
These measures reduce the probability that a single technical fault causes a complete processing outage.
Mitigation Strategies
Mitigation strategies reduce the consequences of a disruptive incident after it has occurred or when disruption cannot be completely prevented.
Examples for Damanat may include:
- manual workarounds;
- alternative communication channels;
- workload prioritisation;
- temporary suspension of lower-priority activities;
- cross-trained backup personnel;
- alternative approval authorities;
- remote working;
- emergency supplier arrangements;
- alternative processing routes;
- predefined escalation procedures; and
- temporary reduced-service operating models.
Example
Suppose the normal guarantee application interface with a participating financial institution becomes unavailable.
A mitigation strategy might permit priority applications to be securely exchanged through an approved alternative channel until the primary interface is restored.
This does not prevent the outage. It reduces the operational consequences.
Recovery Strategies
Recovery strategies restore interrupted activities and supporting resources following disruption.
They normally include:
- technology disaster recovery;
- restoration from backup;
- application failover;
- alternative workplaces;
- replacement equipment;
- alternative suppliers;
- restoration of communications;
- recovery of critical data;
- relocation of personnel;
- return-to-office arrangements; and
- staged recovery of business processes.
Recovery strategies should be designed to achieve the recovery objectives established during the BIA.
People Continuity Strategies
People are fundamental to Damanat's capability for continuity.
Critical activities may depend on employees possessing specialist knowledge, approval authority, system privileges or relationships with external stakeholders.
Potential strategies include:
Cross-Training
Train multiple employees to perform critical activities.
Succession Arrangements
Identify alternates for critical managerial and specialist roles.
Delegated Authority
Define alternative approval authorities for disruptions.
Remote Working
Enable employees to perform critical activities from approved remote locations.
Workforce Relocation
Transfer employees temporarily to alternative premises.
Split-Team Arrangements
Separate critical employees across locations or working arrangements to reduce concentration exposure.
Temporary Redeployment
Reassign suitably skilled employees from lower-priority functions.
Damanat Example
If only two employees can authorise high-priority guarantee decisions, their simultaneous unavailability could create a significant processing bottleneck.
A continuity strategy might therefore require:
- nominated alternate approvers;
- documented delegation authority;
- cross-training;
- secure remote approval capability; and
- regular validation of system-access privileges.
Business Process Continuity Strategies
Some processes can continue even when normal operating arrangements become unavailable.
Strategies may include:
- simplified emergency procedures;
- manual processing;
- alternative workflows;
- deferred processing;
- workload prioritisation;
- reduced service levels;
- temporary centralisation;
- temporary decentralisation;
- alternative approval sequences; and
- backlog management.
Example: Mortgage Guarantee Application Processing
During a major systems disruption, Damanat might prioritise:
- transactions already close to guarantee issuance;
- time-sensitive approved applications;
- high-priority participating financial institution requests;
- other applications once normal capacity is restored.
The strategy should also determine how transactions processed through temporary arrangements will later be reconciled with the main system.
Technology Continuity Strategies
Technology resilience is particularly important for activities involving electronic application processing, decision support, record management, communications and interfaces with financial institutions.
Potential strategies include:
- high-availability architecture;
- infrastructure redundancy;
- application clustering;
- database replication;
- alternate data-centre capability;
- cloud resilience;
- network redundancy;
- backup telecommunications;
- automated failover;
- technology disaster recovery;
- alternative authentication arrangements;
- system restoration procedures; and
- manual workarounds during extended outages.
SAMA's BCM Framework requires IT disaster recovery arrangements for critical technology infrastructure to be aligned with BIA requirements, including data, systems, networks, services and applications.
It also specifies backup and recovery arrangements, as well as an appropriately located alternative data centre for applicable member organisations.
Damanat Example
For a platform supporting Mortgage Guarantee Origination, the technology strategy may provide:
Primary Environment → Failure Detection → DR Activation → Alternate Processing Environment → Data Validation → Business Resumption
Technology recovery should then be tested against the recovery objectives established through the BIA.
Information and Data Recovery Strategies
Recovering an application is insufficient if critical business data is unavailable or unreliable.
Damanat should therefore establish strategies covering:
- regular backups;
- offsite backup;
- data replication;
- immutable backup where appropriate;
- protected storage;
- recovery-point requirements;
- restoration procedures;
- transaction reconciliation;
- alternative access to critical records;
- integrity verification; and
- retention of essential documentation.
Example
Suppose Damanat's RPO for a critical guarantee-processing database is 30 minutes.
The selected backup and replication arrangement should demonstrate that data can ordinarily be recovered to within that approved tolerance.
If the technology can only restore data from a backup taken 24 hours earlier, the strategy would not meet the BIA requirement.
Premises Continuity Strategies
Loss of the primary workplace should not prevent priority activities from being performed beyond their allowable interruption period.
Possible strategies include:
- remote working;
- alternate business workspace;
- another Damanat facility;
- temporary leased workspace;
- third-party recovery facility;
- split-site operations;
- work-from-home arrangements; and
- hybrid recovery arrangements.
The SAMA BCM Framework states that applicable organisations should have sufficient alternative business workspace to relocate required resources and to deliver critical processes in accordance with BIA recovery objectives.
Damanat Example
Damanat could establish a strategy under which:
First Response: Priority employees switch to remote working.
If disruption continues: Designated teams operate from an alternate workplace.
If disruption becomes prolonged: Additional resources are transferred to the alternate operating environment.
This provides scalability according to incident duration.
Supplier and Third-Party Continuity Strategies
Damanat's recovery capability may depend on external organisations over which it does not have direct operational control.
Strategies may include:
- dual suppliers;
- alternative service providers;
- contractual recovery obligations;
- minimum service-level requirements during disruption;
- supplier BCP requirements;
- supplier participation in exercises;
- alternative processing arrangements;
- service substitution;
- inventory or capacity reserves; and
- insourcing procedures where practical.
The SAMA BCM Framework addresses the continuity capabilities of vendors, suppliers, and service providers and requires key providers supporting critical activities to maintain continuity arrangements and to be tested periodically.
Damanat Example
If a third-party provider supports an important technology interface, Damanat should determine:
- the provider's recovery time;
- whether it meets Damanat's required RTO;
- whether alternate infrastructure exists;
- how incidents will be escalated;
- whether an alternative provider is available; and
- what temporary arrangements Damanat can implement.
A supplier with an RTO of 48 hours cannot support a Damanat function that must recover within four hours unless another continuity arrangement exists.
Participating Financial Institution Continuity Strategies
Mortgage guarantee activities involve interactions with financial institutions.
Damanat should therefore consider continuity arrangements for external communication and the exchange of transactions.
Strategies may include:
- multiple communication channels;
- alternative secure submission methods;
- predefined emergency contact points;
- manual confirmation procedures;
- secure alternative document exchange;
- delayed batch synchronisation;
- transaction reconciliation; and
- agreed escalation arrangements.
Example
If the normal application interface is unavailable, Damanat may activate a predefined alternative method for receiving specifically prioritised applications.
The strategy would need to address:
- authentication;
- information security;
- data integrity;
- authorisation;
- transaction tracking; and
- later reconciliation.
Communication Strategies
Effective continuity operations require reliable communications.
Damanat should consider:
- primary corporate communications;
- mobile communications;
- alternative email capability;
- emergency notification systems;
- collaboration platforms;
- external stakeholder communication channels;
- regulator communication;
- supplier communication;
- employee notification; and
- emergency contact directories.
Multiple channels should be available where communication itself represents a critical dependency.
Cyber Disruption Strategies
A cyber incident may require different continuity approaches from a conventional technology outage.
Immediately restoring compromised infrastructure may not be appropriate if the security threat remains active.
Cyber continuity strategies may therefore include:
- isolation of affected environments;
- clean recovery environments;
- immutable backups;
- alternative communications;
- manual business procedures;
- privileged-access recovery;
- cyber incident response coordination;
- forensic preservation;
- controlled restoration; and
- validation before business resumption.
The continuity strategy should therefore integrate BCM, IT disaster recovery, cybersecurity, and incident management requirements.
Strategies for Prolonged Disruption
Damanat should distinguish between short-term workarounds and arrangements that can support prolonged disruption.
For example, employees may be able to use a manual spreadsheet for several hours, but this may not remain practical for several weeks.
Strategies should therefore consider different stages:
Immediate
Maintain essential operations during the first hours.
Interim
Operate priority functions for several days.
Extended
Sustain operations during prolonged disruption.
Recovery
Restore normal or replacement operating capability.
Return to Normal
Transfer from continuity arrangements to normal operations.
Minimum Business Continuity Objective
Where appropriate, Damanat should establish the Minimum Business Continuity Objective (MBCO) for Critical Business Functions.
The MBCO represents the minimum acceptable level of service or activity that must be achieved during continuity operations.
For example, normal Mortgage Guarantee Origination might process 100 per cent of applications.
During a severe disruption, the approved strategy might initially support:
- 30 percent of normal transaction capacity;
- priority applications only;
- specified participating institutions;
- limited operating hours; or
- essential decisions and guarantee issuance only.
The strategy must therefore answer not only how quickly the activity recovers, but also at what minimum operating capacity.
Developing Strategy Options
Damanat should normally consider more than one strategy option before selecting the preferred solution.
For example, for loss of premises:
Option A — Dedicated Alternate Site
Higher cost but strong readiness.
Option B — Remote Working
Lower infrastructure cost but dependent on employee connectivity and remote-access capability.
Option C — Shared Recovery Workspace
Potentially cost-effective but may involve availability limitations.
Option D — Hybrid Approach
Remote working for most employees with reserved alternate-site capacity for essential roles.
Each option should be evaluated against the BIA requirement.
Strategy Evaluation Criteria
A structured evaluation may consider:
|
Criterion |
Key Question |
|
RTO Compliance |
Can the strategy recover the activity within the required time? |
|
RPO Compliance |
Can acceptable data loss be maintained? |
|
MBCO |
Can minimum required service levels be achieved? |
|
Operational Feasibility |
Can the strategy actually be activated? |
|
Resource Availability |
Will people, technology and facilities be available? |
|
Dependency Risk |
Does the strategy introduce another critical dependency? |
|
Sustainability |
How long can the arrangement operate? |
|
Security |
Are information and physical security maintained? |
|
Regulatory Alignment |
Does the approach meet applicable requirements? |
|
Cost |
Is the solution financially proportionate? |
|
Complexity |
Can employees realistically execute it? |
|
Testability |
Can the arrangement be validated regularly? |
Example Strategy Evaluation for Damanat
Consider the loss of Damanat's primary office.
Option 1 — Wait for Building Restoration
Advantage: Minimal additional cost.
Disadvantage: Recovery time is unpredictable.
Assessment: Unsuitable for functions requiring rapid recovery.
Option 2 — Remote Working
Advantage: Rapid activation for suitable roles.
Disadvantage: Depends on connectivity, equipment and remote system access.
Assessment: Suitable for many knowledge-based functions if capacity is validated.
Option 3 — Alternate Recovery Site
Advantage: Controlled environment and dedicated recovery resources.
Disadvantage: Higher cost.
Assessment: Suitable for functions requiring secure infrastructure or physical coordination.
Preferred Approach
Damanat could adopt a hybrid strategy, combining remote work with alternate-site capacity for functions that cannot be performed entirely remotely.
Business Continuity Strategies for Damanat's Critical Business Functions — Text Format
The following provides an illustrative strategy model for Damanat's Critical Business Functions.
Mortgage Guarantee Origination
Damanat should ensure that applications can continue to be received, assessed, approved and issued when normal operating arrangements are disrupted.
Strategies may include resilient processing systems, remote access, alternative application submission arrangements, cross-trained assessment personnel, alternate approval authorities, data recovery, technology disaster recovery and temporary manual processing procedures.
Guarantee Administration
Guarantee records and servicing activities should remain accessible through redundant systems, recoverable data repositories and alternative working arrangements.
Critical updates may be prioritised during reduced-capacity operations.
Claims Management
Damanat should maintain access to claim information, authorised decision-makers and supporting documents.
Temporary manual workflows and alternative communication channels may be required where normal claims-processing technology is unavailable.
Financial and Payment-Related Operations
Priority financial obligations should be identified and supported by alternate authorised personnel, secure remote banking capability, alternative processing arrangements and defined escalation procedures.
Regulatory Reporting
Critical regulatory deadlines should be identified in advance.
Strategies should provide alternative access to required data, backup personnel, documented report-production procedures and secure communication channels with regulators.
Customer and Financial Institution Support
Alternative telephone, email and digital channels should support priority communications where normal channels are unavailable.
Emergency contact and escalation arrangements should be established for participating financial institutions.
Technology Services
Critical applications, infrastructure, networks and data should be supported by disaster recovery, backup, redundancy, alternative connectivity and tested restoration arrangements.
Corporate Support Functions
Human Resources, facilities, procurement, legal, risk, compliance and other support functions should maintain continuity capabilities proportionate to their role in supporting critical operations.
Business Continuity Strategies for Damanat's Critical Business Functions
Table Format
|
Critical Business Function / Resource |
Key Disruption |
Prevention Strategy |
Mitigation Strategy |
Recovery Strategy |
|
Mortgage Guarantee Origination |
Processing platform failure |
High availability, monitoring, controlled changes |
Prioritise urgent applications; temporary workaround |
DR platform and application recovery |
|
Application Intake |
External interface unavailable |
Redundant interface and monitoring |
Alternative secure submission channel |
Restore interface and reconcile transactions |
|
Eligibility and Risk Assessment |
Specialist personnel unavailable |
Cross-training and succession |
Redistribute workload |
Activate alternate trained assessors |
|
Guarantee Approval |
Authorised approvers unavailable |
Multiple delegated approvers |
Remote approval |
Activate alternate approval authority |
|
Guarantee Certificate Generation |
Application/service failure |
Redundant system components |
Temporary confirmation procedures |
Restore certificate-generation capability |
|
Guarantee Administration |
Core system unavailable |
Resilient infrastructure |
Priority servicing only |
Recover application and database |
|
Claims Management |
Claims system or staff unavailable |
Cross-training and system resilience |
Manual priority claims handling |
Restore claims platform and records |
|
Financial Operations |
Payment capability unavailable |
Multiple authorised personnel and resilient banking channels |
Prioritise critical obligations |
Activate alternate payment arrangement |
|
Regulatory Reporting |
Reporting platform/data unavailable |
Backup reporting data and cross-trained personnel |
Manual data consolidation |
Restore reporting environment |
|
Customer / FI Support |
Contact channel unavailable |
Multiple communications channels |
Redirect calls/email to alternatives |
Restore normal communication services |
|
Critical Data |
Corruption or loss |
Replication, backup, access controls |
Use last validated dataset |
Restore within approved RPO |
|
Primary Workplace |
Building inaccessible |
Geographic and workspace planning |
Remote working |
Relocate priority teams to alternate site |
|
Critical Personnel |
Widespread unavailability |
Cross-training and succession |
Reduce activity to MBCO |
Redeploy alternates |
|
Telecommunications |
Carrier outage |
Diverse connectivity |
Mobile or alternative communications |
Restore primary telecommunications |
|
Third-Party Technology |
Provider failure |
Supplier resilience assessment |
Alternative manual/service route |
Activate alternative provider or provider DR |
|
Cyber Incident |
Systems compromised |
Cybersecurity controls and monitoring |
Isolate affected systems; manual procedures |
Clean-system recovery from validated backups |
The specific strategy for each Critical Business Function should ultimately be determined from its approved BIA and RAR results rather than from generic assumptions.
Strategy Documentation
Damanat should document the selected strategy for each Critical Business Function.
A strategy record could contain:
|
Field |
Description |
|
CBF |
Critical Business Function |
|
BIA Recovery Requirement |
RTO, RPO, MAO and MBCO |
|
Key Dependencies |
People, process, technology, premises and suppliers |
|
Identified Threat |
Relevant RAR finding |
|
Existing Capability |
Current continuity arrangement |
|
Strategy Options |
Alternatives evaluated |
|
Selected Strategy |
Approved solution |
|
Required Resources |
Resources required for activation |
|
Implementation Actions |
Capability gaps to close |
|
Strategy Owner |
Accountable owner |
|
Target Date |
Implementation deadline |
|
Approval |
Management/committee approval |
|
Validation Method |
How the strategy will be tested |
Strategy Gap Analysis
Selecting a strategy does not mean the required capability already exists.
Damanat should compare:
Required Capability versus Current Capability
The difference becomes the strategy gap.
For example:
BIA Requirement
Mortgage Guarantee Origination must recover within four hours.
Current Capability
Technology recovery takes eight hours.
Gap
Four-hour recovery deficit.
Required Action
Improve infrastructure, automation or failover capability to achieve the four-hour requirement.
This gap analysis should produce an implementation plan.
Strategy Implementation Plan
For each identified gap, Damanat should document:
- required improvement;
- accountable owner;
- budget requirement;
- implementation activities;
- target completion date;
- dependencies;
- interim arrangement;
- risk if delayed; and
- validation requirement.
Significant gaps should be reported to the BCM Committee or appropriate governance authority.
Strategy Approval
Business Continuity Strategies should receive formal approval because they frequently involve investment, operational changes and acceptance of residual risks.
Approval should confirm that management accepts:
- the recovery objective;
- the selected solution;
- cost;
- resource requirements;
- residual limitations;
- implementation timeline; and
- remaining risk.
Where a strategy cannot achieve an approved BIA requirement, the shortfall should be clearly escalated rather than hidden within the BCP.
From Strategy to Business Continuity Plan
The BCS phase determines what continuity capabilities Damanat will use.
The next Plan Development phase determines how those capabilities will be activated and operated during an incident.
For example:
Strategy
Employees will work remotely following loss of the primary workplace.
Business Continuity Plan
The BCP specifies:
- who declares the office unavailable;
- who activates remote working;
- which employees are prioritised;
- how employees are notified;
- which systems they access;
- what minimum activities they perform;
- how problems are escalated; and
- how operations return to normal.
Similarly:
Strategy
Mortgage Guarantee Origination will fail over to the DR environment.
Business Continuity / DR Procedure
The plan specifies:
Incident Detection → Escalation → DR Decision → Failover → Validation → Business Access → Transaction Reconciliation → Recovery Confirmation
This demonstrates the distinction between strategy and plan.
Business Continuity Strategy Deliverables
At the conclusion of the BCS phase, Damanat should have developed at minimum:
|
Ref |
Deliverable |
Purpose |
|
BCS-01 |
Business Continuity Strategy Methodology |
Defines strategy-development approach |
|
BCS-02 |
Strategy Requirements Register |
Consolidates BIA recovery requirements |
|
BCS-03 |
Strategy Options Analysis |
Documents alternatives |
|
BCS-04 |
CBF Continuity Strategies |
Defines strategies for priority functions |
|
BCS-05 |
People Strategy |
Addresses workforce continuity |
|
BCS-06 |
Premises Strategy |
Addresses workplace loss |
|
BCS-07 |
Technology Recovery Strategy |
Addresses systems and infrastructure |
|
BCS-08 |
Information Recovery Strategy |
Addresses data and records |
|
BCS-09 |
Supplier Continuity Strategy |
Addresses third-party dependencies |
|
BCS-10 |
Communication Strategy |
Addresses disruption communications |
|
BCS-11 |
Strategy Gap Register |
Identifies capability deficiencies |
|
BCS-12 |
Implementation Plan |
Closes identified strategy gaps |
|
BCS-13 |
Strategy Approval Record |
Documents management acceptance |
Completion Criteria for the BCS Phase
Damanat should consider the Business Continuity Strategy phase sufficiently complete when:
- approved BIA recovery requirements have been reviewed;
- relevant RAR findings have been incorporated;
- strategies have been developed for all prioritised Critical Business Functions;
- people strategies have been established;
- premises arrangements have been defined;
- technology recovery requirements have been addressed;
- data recovery requirements have been addressed;
- critical suppliers and external dependencies have been considered;
- alternative communication arrangements have been established;
- multiple strategy options have been evaluated where appropriate;
- selected strategies can reasonably meet RTOs, RPOs, MAOs and MBCOs;
- capability gaps have been identified;
- implementation actions have owners and deadlines;
- residual risks and limitations have been documented; and
- strategies have received appropriate management approval.
Integrating Prevention, Mitigation and Recovery
A mature continuity strategy should not rely on one type of control.
Damanat should combine:
Prevention → Mitigation → Recovery
Consider a critical technology platform.
Prevention
Redundant infrastructure and cybersecurity controls reduce the likelihood of failure.
Mitigation
Manual or alternative procedures reduce the immediate business impact.
Recovery
The disaster recovery environment restores technology capability.
Similarly, for critical personnel:
Prevention
Succession planning and cross-training reduce concentration risk.
Mitigation
Workload prioritisation reduces immediate disruption.
Recovery
Alternative personnel assume the required roles.
This layered approach provides greater resilience than relying on recovery alone.
The Business Continuity Strategy phase transforms Damanat's understanding of risk and business impact into practical resilience capability.
Through the preceding Risk Analysis and Review, Damanat identifies the threats, vulnerabilities, and single points of failure that could disrupt operations.
Through the Business Impact Analysis, Damanat determines which Critical Business Functions must be prioritised, how quickly they must recover, the acceptable level of data loss, the minimum operating capacity required, and the resources on which those activities depend.
The Business Continuity Strategy phase answers the next essential question:
“What arrangements must Damanat put in place to meet those recovery requirements?”
For Damanat, the answer should not be limited to technology disaster recovery.
A complete strategy must consider:
People + Processes + Technology + Information + Premises + Suppliers + Communications + External Dependencies
The strategy should also incorporate three complementary layers of resilience:
Prevention reduces the likelihood of disruption.
Mitigation limits the immediate consequences of disruption.
Recovery restores the affected Critical Business Function within its approved recovery objectives.
For example:
Critical personnel unavailable
→ Cross-training
→ Alternative authority
→ Redeployment of trained personnel
Primary office unavailable
→ Distributed working capability
→ Remote working
→ Alternate workspace
Processing technology unavailable
→ High-availability infrastructure
→ Temporary workaround
→ Disaster recovery
Critical supplier unavailable
→ Supplier resilience controls
→ Temporary alternative arrangements
→ Alternative provider
Critical data unavailable
→ Replication and backup
→ Use of validated recovery data
→ Restoration within the approved RPO
The resulting strategies provide the bridge between analysis and action.
They transform the findings of the RAR and BIA into the capabilities that Damanat will depend upon during an actual disruption.
The strategy phase should therefore produce approved, funded, implementable and testable solutions for each Critical Business Function.
Where current capabilities cannot achieve the established recovery requirements, the resulting gaps should be visible to management and addressed through formal improvement plans.
Once these strategies have been selected and approved, Damanat can proceed to the next phase of its BCM Planning Methodology—Plan Development (PD).
The focus then changes from:
“What is our recovery strategy?”
to:
“Exactly who will do what, when, where and how when a disruption occurs?”
The next chapter will translate Damanat's approved Business Continuity Strategies into practical Business Continuity Plans, activation procedures, escalation arrangements, response actions, recovery procedures and return-to-normal activities.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
![]() |
![]() |
![]() |
![]() |
![]() |
| C6 | C7 | C8 | C9 | C10 |
![]() |
![]() |
![]() |
![]() |
![]() |
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]


![[BCM] [Damanat] [Full Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/221734db-8c33-48bd-8147-fc740eecaf83.png)

![Banner [Summary] [BCM] [E2] [C5] Business Continuity Strategy](https://no-cache.hubspot.com/cta/default/3893111/ca7fd7d5-8923-46f4-b420-08a7eca83bdb.png)
![[BCM] [Damanat] [3/4 Banner] Implementing BCM for The Saudi Mortgage Guarantees Services Company](https://no-cache.hubspot.com/cta/default/3893111/0252380a-b2dc-4059-be10-b5566002b711.png)
![[BCM] [Damanat] [E2] [C1] Business Continuity Management Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/b17b614b-c36c-4437-95ca-5c1d44ac6ce3.png)
![[BCM] [Damanat] [E2] [C2] Project Management](https://no-cache.hubspot.com/cta/default/3893111/4663bc6b-2e85-4e17-b6af-b5c784413b28.png)
![[BCM] [Damanat] [E2] [C3] Risk Analysis and Review](https://no-cache.hubspot.com/cta/default/3893111/5423f27a-6048-40c1-b55c-238fafb59648.png)
![[BCM] [Damanat] [E2] [C4] Business Impact Analysis](https://no-cache.hubspot.com/cta/default/3893111/7a3c1a1f-d7f6-4d5d-8fef-deedc7d91f63.png)
![[BCM] [Damanat] [E2] [C6] BCM Plan Development](https://no-cache.hubspot.com/cta/default/3893111/ebff27c2-d3e9-4f2c-9a4c-0534e01fa535.png)
![[BCM] [Damanat] [E2] [C7] Testing and Exercising](https://no-cache.hubspot.com/cta/default/3893111/ed03c310-870a-482d-bac6-446897084091.png)
![[BCM] [Damanat] [E2] [C8] Program Management](https://no-cache.hubspot.com/cta/default/3893111/f52be888-834d-480c-9149-1167d38f1147.png)
![[BCM] [Damanat] [E2] [C9] Summary](https://no-cache.hubspot.com/cta/default/3893111/dab5bc8f-3d96-444b-880f-78cf037fc906.png)
![[BCM] [Damanat] [E2] [C10] Back Cover](https://no-cache.hubspot.com/cta/default/3893111/351b85f0-d850-4dee-a5c0-55c2b37c3075.png)


![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





