Ebook

[BCM] [Damanat] [E2] [C5] Business Continuity Strategy

Written by Dr Goh Moh Heng | Jul 27, 2026, 11:17:51 AM

eBook 2: Chapter 5

 

Business Continuity Strategy Phase of the BCM Planning Methodology for 

The Saudi Mortgage Guarantees Services Company

 

Introduction


The Business Continuity Strategy (BCS) phase is the stage of the Business Continuity Management (BCM) Planning Methodology in which The Saudi Mortgage Guarantees Services Company (Damanat) determines how its Critical Business Functions (CBFs) will be protected, continued and recovered following a disruptive incident.

The preceding Risk Analysis and Review (RAR) phase identifies the threats, vulnerabilities and single points of failure that could disrupt Damanat.

The Business Impact Analysis (BIA) establishes which business functions and supporting activities require priority recovery, how quickly they must be restored and what minimum resources are required.

The Business Continuity Strategy phase translates these findings into practical solutions.

In simple terms:

  • RAR identifies what could cause disruption.

  • BIA identifies what must be recovered and by when.

  • BCS determines how continuity and recovery will be achieved.

For Damanat, business continuity strategies should address the combination of people, processes, technology, information, premises, suppliers and external interfaces required to support mortgage guarantee operations and other Critical Business Functions.

The selected strategies should incorporate three complementary forms of resilience:

Prevention – reducing the likelihood of disruption.

Mitigation – reducing the severity of the consequences when disruption occurs.

Recovery – restoring affected Critical Business Functions and resources within predetermined recovery objectives.

The objective is not to eliminate every possible disruption. That is neither realistic nor economically practical. Instead, Damanat should establish a balanced portfolio of preventive, mitigating and recovery capabilities that allows priority business activities to remain within acceptable levels of disruption.

 

Purpose of the BC Strategy Phase


The purpose of the BCS phase is to identify, evaluate, select and approve continuity solutions that enable Damanat to achieve the recovery requirements established during the BIA.

The phase should answer questions such as:

  • How will critical work continue if the primary office cannot be used?
  • How will Damanat operate if critical employees are unavailable?
  • How will technology services be restored following a major failure?
  • How will critical data be recovered?
  • How will Damanat continue operating if a key supplier becomes unavailable?
  • How will mortgage guarantee applications be processed if normal systems are unavailable?
  • How will participating financial institutions communicate with Damanat during a disruption?
  • What minimum level of service must be maintained?
  • What alternative arrangements must be established before an incident occurs?
  • How quickly must recovery resources become available?

The resulting strategy should provide the foundation for the next BCM phase: Plan Development (PD).

 

Principles for Selecting Business Continuity Strategies

Business Continuity Strategies should not be selected simply because they represent common industry practices.

Each strategy should be supported by the results of Damanat's RAR and BIA.

The selection process should consider:

Recovery Requirements

The strategy must be capable of meeting the approved Recovery Time Objective (RTO), Recovery Point Objective (RPO), Maximum Acceptable Outage (MAO) and Minimum Business Continuity Objective (MBCO), where applicable.

Risk Exposure

Higher-risk functions may require greater resilience or redundancy.

Operational Feasibility

The solution must work under realistic disruption conditions.

Resource Availability

The required people, facilities, technology, information, and suppliers must be available when the strategy is activated.

Cost

Implementation and maintenance costs should be proportionate to the potential consequences of disruption.

Regulatory Requirements

The strategy should meet applicable legal, regulatory and supervisory expectations.

Dependency Requirements

The strategy should take account of internal and external dependencies.

Scalability

The strategy should remain effective against disruptions of varying durations and severities.

Sustainability

Damanat should be able to operate under the continuity arrangement for the period required to restore normal operations.

 

Regulatory Alignment of Damanat's Continuity Strategy

The Saudi Central Bank's Business Continuity Management Framework requires a business continuity strategy to be formally defined, approved, implemented, maintained, and aligned with the organisation's strategic objectives.

The framework also requires BIA results to identify recovery objectives, interdependencies, and supporting resources, while continuity plans must support the continuation of critical activities within those recovery objectives.

The SAMA framework also addresses alternative business workspaces, technology disaster recovery, backup and recovery processes, critical service providers, and contractual arrangements supporting continuity.

It specifies that alternative workspaces should support the delivery of critical processes in accordance with BIA recovery objectives, and that IT Disaster Recovery Plans should align with the BIA and restore critical technology infrastructure, data, systems, networks, and applications.

For Damanat, this means strategy selection should be demonstrably linked to:

BIA Requirement → Selected Strategy → Required Capability → Recovery Evidence

For example:

RTO of four hours → Alternative processing capability → Remote access and standby technology → Recovery test evidence

This traceability demonstrates that continuity arrangements are based on established business requirements rather than arbitrary technical solutions.

 

Business Continuity Strategies for Damanat's Critical Business Functions

Business Continuity Strategies for Damanat's Critical Business Functions should establish the capabilities necessary to maintain an acceptable level of mortgage guarantee and supporting operations during disruption.

A Critical Business Function normally depends upon several resources simultaneously. A recovery strategy should therefore not focus only on a single dimension such as technology.

For example, recovering a mortgage guarantee application system will not restore Mortgage Guarantee Origination if:

  • employees cannot access the system;
  • authorised approvers are unavailable;
  • application data cannot be retrieved;
  • participating financial institutions cannot connect;
  • supporting risk information is unavailable; or
  • the operating premises cannot be accessed.

Damanat should therefore develop strategies across the following resource dimensions:

People

→ Processes

→ Technology

→ Information and Data

→ Premises

→ Suppliers and Third Parties

→ Communications

→ External Dependencies

Each Critical Business Function should have an appropriate combination of strategies covering these dimensions.

 

Prevention Strategies

Prevention strategies reduce the likelihood of disruption.

These arrangements generally operate before an incident and form part of normal business operations.

For Damanat, preventive measures may include:

  • infrastructure redundancy;
  • preventive system maintenance;
  • cybersecurity controls;
  • resilient telecommunications;
  • capacity monitoring;
  • access-control mechanisms;
  • change-management controls;
  • staff cross-training;
  • succession planning;
  • supplier due diligence;
  • preventive equipment maintenance;
  • backup power arrangements;
  • information-security controls;
  • segregation of critical infrastructure;
  • process quality controls; and
  • monitoring of key service providers.
Example: Mortgage Guarantee Origination

If Mortgage Guarantee Origination depends heavily on a central processing platform, preventive strategies might include:

  • resilient infrastructure;
  • redundant network paths;
  • high-availability application components;
  • database replication;
  • proactive monitoring; and
  • controlled system-change processes.

These measures reduce the probability that a single technical fault causes a complete processing outage.

 

Mitigation Strategies

Mitigation strategies reduce the consequences of a disruptive incident after it has occurred or when disruption cannot be completely prevented.

Examples for Damanat may include:

  • manual workarounds;
  • alternative communication channels;
  • workload prioritisation;
  • temporary suspension of lower-priority activities;
  • cross-trained backup personnel;
  • alternative approval authorities;
  • remote working;
  • emergency supplier arrangements;
  • alternative processing routes;
  • predefined escalation procedures; and
  • temporary reduced-service operating models.
Example

Suppose the normal guarantee application interface with a participating financial institution becomes unavailable.

A mitigation strategy might permit priority applications to be securely exchanged through an approved alternative channel until the primary interface is restored.

This does not prevent the outage. It reduces the operational consequences.

 

Recovery Strategies

Recovery strategies restore interrupted activities and supporting resources following disruption.

They normally include:

  • technology disaster recovery;
  • restoration from backup;
  • application failover;
  • alternative workplaces;
  • replacement equipment;
  • alternative suppliers;
  • restoration of communications;
  • recovery of critical data;
  • relocation of personnel;
  • return-to-office arrangements; and
  • staged recovery of business processes.

Recovery strategies should be designed to achieve the recovery objectives established during the BIA.

 

People Continuity Strategies

People are fundamental to Damanat's capability for continuity.

Critical activities may depend on employees possessing specialist knowledge, approval authority, system privileges or relationships with external stakeholders.

Potential strategies include:

Cross-Training

Train multiple employees to perform critical activities.

Succession Arrangements

Identify alternates for critical managerial and specialist roles.

Delegated Authority

Define alternative approval authorities for disruptions.

Remote Working

Enable employees to perform critical activities from approved remote locations.

Workforce Relocation

Transfer employees temporarily to alternative premises.

Split-Team Arrangements

Separate critical employees across locations or working arrangements to reduce concentration exposure.

Temporary Redeployment

Reassign suitably skilled employees from lower-priority functions.

Damanat Example

If only two employees can authorise high-priority guarantee decisions, their simultaneous unavailability could create a significant processing bottleneck.

A continuity strategy might therefore require:

  • nominated alternate approvers;
  • documented delegation authority;
  • cross-training;
  • secure remote approval capability; and
  • regular validation of system-access privileges.

 

Business Process Continuity Strategies

Some processes can continue even when normal operating arrangements become unavailable.

Strategies may include:

  • simplified emergency procedures;
  • manual processing;
  • alternative workflows;
  • deferred processing;
  • workload prioritisation;
  • reduced service levels;
  • temporary centralisation;
  • temporary decentralisation;
  • alternative approval sequences; and
  • backlog management.
Example: Mortgage Guarantee Application Processing

During a major systems disruption, Damanat might prioritise:

  1. transactions already close to guarantee issuance;
  2. time-sensitive approved applications;
  3. high-priority participating financial institution requests;
  4. other applications once normal capacity is restored.

The strategy should also determine how transactions processed through temporary arrangements will later be reconciled with the main system.

 

Technology Continuity Strategies

Technology resilience is particularly important for activities involving electronic application processing, decision support, record management, communications and interfaces with financial institutions.

Potential strategies include:

  • high-availability architecture;
  • infrastructure redundancy;
  • application clustering;
  • database replication;
  • alternate data-centre capability;
  • cloud resilience;
  • network redundancy;
  • backup telecommunications;
  • automated failover;
  • technology disaster recovery;
  • alternative authentication arrangements;
  • system restoration procedures; and
  • manual workarounds during extended outages.

SAMA's BCM Framework requires IT disaster recovery arrangements for critical technology infrastructure to be aligned with BIA requirements, including data, systems, networks, services and applications.

It also specifies backup and recovery arrangements, as well as an appropriately located alternative data centre for applicable member organisations.

Damanat Example

For a platform supporting Mortgage Guarantee Origination, the technology strategy may provide:

Primary Environment → Failure Detection → DR Activation → Alternate Processing Environment → Data Validation → Business Resumption

Technology recovery should then be tested against the recovery objectives established through the BIA.

 

Information and Data Recovery Strategies

Recovering an application is insufficient if critical business data is unavailable or unreliable.

Damanat should therefore establish strategies covering:

  • regular backups;
  • offsite backup;
  • data replication;
  • immutable backup where appropriate;
  • protected storage;
  • recovery-point requirements;
  • restoration procedures;
  • transaction reconciliation;
  • alternative access to critical records;
  • integrity verification; and
  • retention of essential documentation.
Example

Suppose Damanat's RPO for a critical guarantee-processing database is 30 minutes.

The selected backup and replication arrangement should demonstrate that data can ordinarily be recovered to within that approved tolerance.

If the technology can only restore data from a backup taken 24 hours earlier, the strategy would not meet the BIA requirement.

 

Premises Continuity Strategies

Loss of the primary workplace should not prevent priority activities from being performed beyond their allowable interruption period.

Possible strategies include:

  • remote working;
  • alternate business workspace;
  • another Damanat facility;
  • temporary leased workspace;
  • third-party recovery facility;
  • split-site operations;
  • work-from-home arrangements; and
  • hybrid recovery arrangements.

The SAMA BCM Framework states that applicable organisations should have sufficient alternative business workspace to relocate required resources and to deliver critical processes in accordance with BIA recovery objectives.

Damanat Example

Damanat could establish a strategy under which:

First Response: Priority employees switch to remote working.

If disruption continues: Designated teams operate from an alternate workplace.

If disruption becomes prolonged: Additional resources are transferred to the alternate operating environment.

This provides scalability according to incident duration.

 

Supplier and Third-Party Continuity Strategies

Damanat's recovery capability may depend on external organisations over which it does not have direct operational control.

Strategies may include:

  • dual suppliers;
  • alternative service providers;
  • contractual recovery obligations;
  • minimum service-level requirements during disruption;
  • supplier BCP requirements;
  • supplier participation in exercises;
  • alternative processing arrangements;
  • service substitution;
  • inventory or capacity reserves; and
  • insourcing procedures where practical.

The SAMA BCM Framework addresses the continuity capabilities of vendors, suppliers, and service providers and requires key providers supporting critical activities to maintain continuity arrangements and to be tested periodically.

Damanat Example

If a third-party provider supports an important technology interface, Damanat should determine:

  • the provider's recovery time;
  • whether it meets Damanat's required RTO;
  • whether alternate infrastructure exists;
  • how incidents will be escalated;
  • whether an alternative provider is available; and
  • what temporary arrangements Damanat can implement.

A supplier with an RTO of 48 hours cannot support a Damanat function that must recover within four hours unless another continuity arrangement exists.

 

Participating Financial Institution Continuity Strategies

Mortgage guarantee activities involve interactions with financial institutions.

Damanat should therefore consider continuity arrangements for external communication and the exchange of transactions.

Strategies may include:

  • multiple communication channels;
  • alternative secure submission methods;
  • predefined emergency contact points;
  • manual confirmation procedures;
  • secure alternative document exchange;
  • delayed batch synchronisation;
  • transaction reconciliation; and
  • agreed escalation arrangements.
Example

If the normal application interface is unavailable, Damanat may activate a predefined alternative method for receiving specifically prioritised applications.

The strategy would need to address:

  • authentication;
  • information security;
  • data integrity;
  • authorisation;
  • transaction tracking; and
  • later reconciliation.

 

Communication Strategies

Effective continuity operations require reliable communications.

Damanat should consider:

  • primary corporate communications;
  • mobile communications;
  • alternative email capability;
  • emergency notification systems;
  • collaboration platforms;
  • external stakeholder communication channels;
  • regulator communication;
  • supplier communication;
  • employee notification; and
  • emergency contact directories.

Multiple channels should be available where communication itself represents a critical dependency.

 

Cyber Disruption Strategies

A cyber incident may require different continuity approaches from a conventional technology outage.

Immediately restoring compromised infrastructure may not be appropriate if the security threat remains active.

Cyber continuity strategies may therefore include:

  • isolation of affected environments;
  • clean recovery environments;
  • immutable backups;
  • alternative communications;
  • manual business procedures;
  • privileged-access recovery;
  • cyber incident response coordination;
  • forensic preservation;
  • controlled restoration; and
  • validation before business resumption.

The continuity strategy should therefore integrate BCM, IT disaster recovery, cybersecurity, and incident management requirements.

 

Strategies for Prolonged Disruption

Damanat should distinguish between short-term workarounds and arrangements that can support prolonged disruption.

For example, employees may be able to use a manual spreadsheet for several hours, but this may not remain practical for several weeks.

Strategies should therefore consider different stages:

Immediate

Maintain essential operations during the first hours.

Interim

Operate priority functions for several days.

Extended

Sustain operations during prolonged disruption.

Recovery

Restore normal or replacement operating capability.

Return to Normal

Transfer from continuity arrangements to normal operations.

 

Minimum Business Continuity Objective

Where appropriate, Damanat should establish the Minimum Business Continuity Objective (MBCO) for Critical Business Functions.

The MBCO represents the minimum acceptable level of service or activity that must be achieved during continuity operations.

For example, normal Mortgage Guarantee Origination might process 100 per cent of applications.

During a severe disruption, the approved strategy might initially support:

  • 30 percent of normal transaction capacity;
  • priority applications only;
  • specified participating institutions;
  • limited operating hours; or
  • essential decisions and guarantee issuance only.

The strategy must therefore answer not only how quickly the activity recovers, but also at what minimum operating capacity.

 

Developing Strategy Options

Damanat should normally consider more than one strategy option before selecting the preferred solution.

For example, for loss of premises:

Option A — Dedicated Alternate Site

Higher cost but strong readiness.

Option B — Remote Working

Lower infrastructure cost but dependent on employee connectivity and remote-access capability.

Option C — Shared Recovery Workspace

Potentially cost-effective but may involve availability limitations.

Option D — Hybrid Approach

Remote working for most employees with reserved alternate-site capacity for essential roles.

Each option should be evaluated against the BIA requirement.

 

Strategy Evaluation Criteria

A structured evaluation may consider:

 

Criterion

Key Question

RTO Compliance

Can the strategy recover the activity within the required time?

RPO Compliance

Can acceptable data loss be maintained?

MBCO

Can minimum required service levels be achieved?

Operational Feasibility

Can the strategy actually be activated?

Resource Availability

Will people, technology and facilities be available?

Dependency Risk

Does the strategy introduce another critical dependency?

Sustainability

How long can the arrangement operate?

Security

Are information and physical security maintained?

Regulatory Alignment

Does the approach meet applicable requirements?

Cost

Is the solution financially proportionate?

Complexity

Can employees realistically execute it?

Testability

Can the arrangement be validated regularly?

 

Example Strategy Evaluation for Damanat

Consider the loss of Damanat's primary office.

Option 1 — Wait for Building Restoration

Advantage: Minimal additional cost.

Disadvantage: Recovery time is unpredictable.

Assessment: Unsuitable for functions requiring rapid recovery.

Option 2 — Remote Working

Advantage: Rapid activation for suitable roles.

Disadvantage: Depends on connectivity, equipment and remote system access.

Assessment: Suitable for many knowledge-based functions if capacity is validated.

Option 3 — Alternate Recovery Site

Advantage: Controlled environment and dedicated recovery resources.

Disadvantage: Higher cost.

Assessment: Suitable for functions requiring secure infrastructure or physical coordination.

Preferred Approach

Damanat could adopt a hybrid strategy, combining remote work with alternate-site capacity for functions that cannot be performed entirely remotely.

 

Business Continuity Strategies for Damanat's Critical Business Functions — Text Format

The following provides an illustrative strategy model for Damanat's Critical Business Functions.

Mortgage Guarantee Origination

Damanat should ensure that applications can continue to be received, assessed, approved and issued when normal operating arrangements are disrupted.

Strategies may include resilient processing systems, remote access, alternative application submission arrangements, cross-trained assessment personnel, alternate approval authorities, data recovery, technology disaster recovery and temporary manual processing procedures.

Guarantee Administration

Guarantee records and servicing activities should remain accessible through redundant systems, recoverable data repositories and alternative working arrangements.

Critical updates may be prioritised during reduced-capacity operations.

Claims Management

Damanat should maintain access to claim information, authorised decision-makers and supporting documents.

Temporary manual workflows and alternative communication channels may be required where normal claims-processing technology is unavailable.

Financial and Payment-Related Operations

Priority financial obligations should be identified and supported by alternate authorised personnel, secure remote banking capability, alternative processing arrangements and defined escalation procedures.

Regulatory Reporting

Critical regulatory deadlines should be identified in advance.

Strategies should provide alternative access to required data, backup personnel, documented report-production procedures and secure communication channels with regulators.

Customer and Financial Institution Support

Alternative telephone, email and digital channels should support priority communications where normal channels are unavailable.

Emergency contact and escalation arrangements should be established for participating financial institutions.

Technology Services

Critical applications, infrastructure, networks and data should be supported by disaster recovery, backup, redundancy, alternative connectivity and tested restoration arrangements.

Corporate Support Functions

Human Resources, facilities, procurement, legal, risk, compliance and other support functions should maintain continuity capabilities proportionate to their role in supporting critical operations.

 

Business Continuity Strategies for Damanat's Critical Business Functions

Table Format

 

Critical Business Function / Resource

Key Disruption

Prevention Strategy

Mitigation Strategy

Recovery Strategy

Mortgage Guarantee Origination

Processing platform failure

High availability, monitoring, controlled changes

Prioritise urgent applications; temporary workaround

DR platform and application recovery

Application Intake

External interface unavailable

Redundant interface and monitoring

Alternative secure submission channel

Restore interface and reconcile transactions

Eligibility and Risk Assessment

Specialist personnel unavailable

Cross-training and succession

Redistribute workload

Activate alternate trained assessors

Guarantee Approval

Authorised approvers unavailable

Multiple delegated approvers

Remote approval

Activate alternate approval authority

Guarantee Certificate Generation

Application/service failure

Redundant system components

Temporary confirmation procedures

Restore certificate-generation capability

Guarantee Administration

Core system unavailable

Resilient infrastructure

Priority servicing only

Recover application and database

Claims Management

Claims system or staff unavailable

Cross-training and system resilience

Manual priority claims handling

Restore claims platform and records

Financial Operations

Payment capability unavailable

Multiple authorised personnel and resilient banking channels

Prioritise critical obligations

Activate alternate payment arrangement

Regulatory Reporting

Reporting platform/data unavailable

Backup reporting data and cross-trained personnel

Manual data consolidation

Restore reporting environment

Customer / FI Support

Contact channel unavailable

Multiple communications channels

Redirect calls/email to alternatives

Restore normal communication services

Critical Data

Corruption or loss

Replication, backup, access controls

Use last validated dataset

Restore within approved RPO

Primary Workplace

Building inaccessible

Geographic and workspace planning

Remote working

Relocate priority teams to alternate site

Critical Personnel

Widespread unavailability

Cross-training and succession

Reduce activity to MBCO

Redeploy alternates

Telecommunications

Carrier outage

Diverse connectivity

Mobile or alternative communications

Restore primary telecommunications

Third-Party Technology

Provider failure

Supplier resilience assessment

Alternative manual/service route

Activate alternative provider or provider DR

Cyber Incident

Systems compromised

Cybersecurity controls and monitoring

Isolate affected systems; manual procedures

Clean-system recovery from validated backups

The specific strategy for each Critical Business Function should ultimately be determined from its approved BIA and RAR results rather than from generic assumptions.

 

Strategy Documentation

Damanat should document the selected strategy for each Critical Business Function.

A strategy record could contain:

 

Field

Description

CBF

Critical Business Function

BIA Recovery Requirement

RTO, RPO, MAO and MBCO

Key Dependencies

People, process, technology, premises and suppliers

Identified Threat

Relevant RAR finding

Existing Capability

Current continuity arrangement

Strategy Options

Alternatives evaluated

Selected Strategy

Approved solution

Required Resources

Resources required for activation

Implementation Actions

Capability gaps to close

Strategy Owner

Accountable owner

Target Date

Implementation deadline

Approval

Management/committee approval

Validation Method

How the strategy will be tested

 

Strategy Gap Analysis

Selecting a strategy does not mean the required capability already exists.

Damanat should compare:

Required Capability versus Current Capability

The difference becomes the strategy gap.

For example:

BIA Requirement

Mortgage Guarantee Origination must recover within four hours.

Current Capability

Technology recovery takes eight hours.

Gap

Four-hour recovery deficit.

Required Action

Improve infrastructure, automation or failover capability to achieve the four-hour requirement.

This gap analysis should produce an implementation plan.

 

Strategy Implementation Plan

For each identified gap, Damanat should document:

  • required improvement;
  • accountable owner;
  • budget requirement;
  • implementation activities;
  • target completion date;
  • dependencies;
  • interim arrangement;
  • risk if delayed; and
  • validation requirement.

Significant gaps should be reported to the BCM Committee or appropriate governance authority.

 

Strategy Approval

Business Continuity Strategies should receive formal approval because they frequently involve investment, operational changes and acceptance of residual risks.

Approval should confirm that management accepts:

  • the recovery objective;
  • the selected solution;
  • cost;
  • resource requirements;
  • residual limitations;
  • implementation timeline; and
  • remaining risk.

Where a strategy cannot achieve an approved BIA requirement, the shortfall should be clearly escalated rather than hidden within the BCP.

 

From Strategy to Business Continuity Plan

The BCS phase determines what continuity capabilities Damanat will use.

The next Plan Development phase determines how those capabilities will be activated and operated during an incident.

For example:

Strategy

Employees will work remotely following loss of the primary workplace.

Business Continuity Plan

The BCP specifies:

  1. who declares the office unavailable;
  2. who activates remote working;
  3. which employees are prioritised;
  4. how employees are notified;
  5. which systems they access;
  6. what minimum activities they perform;
  7. how problems are escalated; and
  8. how operations return to normal.

Similarly:

Strategy

Mortgage Guarantee Origination will fail over to the DR environment.

Business Continuity / DR Procedure

The plan specifies:

Incident Detection → Escalation → DR Decision → Failover → Validation → Business Access → Transaction Reconciliation → Recovery Confirmation

This demonstrates the distinction between strategy and plan.

 

Business Continuity Strategy Deliverables

At the conclusion of the BCS phase, Damanat should have developed at minimum:

Ref

Deliverable

Purpose

BCS-01

Business Continuity Strategy Methodology

Defines strategy-development approach

BCS-02

Strategy Requirements Register

Consolidates BIA recovery requirements

BCS-03

Strategy Options Analysis

Documents alternatives

BCS-04

CBF Continuity Strategies

Defines strategies for priority functions

BCS-05

People Strategy

Addresses workforce continuity

BCS-06

Premises Strategy

Addresses workplace loss

BCS-07

Technology Recovery Strategy

Addresses systems and infrastructure

BCS-08

Information Recovery Strategy

Addresses data and records

BCS-09

Supplier Continuity Strategy

Addresses third-party dependencies

BCS-10

Communication Strategy

Addresses disruption communications

BCS-11

Strategy Gap Register

Identifies capability deficiencies

BCS-12

Implementation Plan

Closes identified strategy gaps

BCS-13

Strategy Approval Record

Documents management acceptance

 

Completion Criteria for the BCS Phase

Damanat should consider the Business Continuity Strategy phase sufficiently complete when:

  • approved BIA recovery requirements have been reviewed;
  • relevant RAR findings have been incorporated;
  • strategies have been developed for all prioritised Critical Business Functions;
  • people strategies have been established;
  • premises arrangements have been defined;
  • technology recovery requirements have been addressed;
  • data recovery requirements have been addressed;
  • critical suppliers and external dependencies have been considered;
  • alternative communication arrangements have been established;
  • multiple strategy options have been evaluated where appropriate;
  • selected strategies can reasonably meet RTOs, RPOs, MAOs and MBCOs;
  • capability gaps have been identified;
  • implementation actions have owners and deadlines;
  • residual risks and limitations have been documented; and
  • strategies have received appropriate management approval.

 

Integrating Prevention, Mitigation and Recovery

A mature continuity strategy should not rely on one type of control.

Damanat should combine:

Prevention → Mitigation → Recovery

Consider a critical technology platform.

Prevention

Redundant infrastructure and cybersecurity controls reduce the likelihood of failure.

Mitigation

Manual or alternative procedures reduce the immediate business impact.

Recovery

The disaster recovery environment restores technology capability.

Similarly, for critical personnel:

Prevention

Succession planning and cross-training reduce concentration risk.

Mitigation

Workload prioritisation reduces immediate disruption.

Recovery

Alternative personnel assume the required roles.

This layered approach provides greater resilience than relying on recovery alone.

 

The Business Continuity Strategy phase transforms Damanat's understanding of risk and business impact into practical resilience capability.

Through the preceding Risk Analysis and Review, Damanat identifies the threats, vulnerabilities, and single points of failure that could disrupt operations.

Through the Business Impact Analysis, Damanat determines which Critical Business Functions must be prioritised, how quickly they must recover, the acceptable level of data loss, the minimum operating capacity required, and the resources on which those activities depend.

The Business Continuity Strategy phase answers the next essential question:

“What arrangements must Damanat put in place to meet those recovery requirements?”

For Damanat, the answer should not be limited to technology disaster recovery.

A complete strategy must consider:

People + Processes + Technology + Information + Premises + Suppliers + Communications + External Dependencies

The strategy should also incorporate three complementary layers of resilience:

Prevention reduces the likelihood of disruption.

Mitigation limits the immediate consequences of disruption.

Recovery restores the affected Critical Business Function within its approved recovery objectives.

For example:

Critical personnel unavailable

→ Cross-training

→ Alternative authority

→ Redeployment of trained personnel

Primary office unavailable

→ Distributed working capability

→ Remote working

→ Alternate workspace

Processing technology unavailable

→ High-availability infrastructure

→ Temporary workaround

→ Disaster recovery

Critical supplier unavailable

→ Supplier resilience controls

→ Temporary alternative arrangements

→ Alternative provider

Critical data unavailable

→ Replication and backup

→ Use of validated recovery data

→ Restoration within the approved RPO

The resulting strategies provide the bridge between analysis and action.

They transform the findings of the RAR and BIA into the capabilities that Damanat will depend upon during an actual disruption.

The strategy phase should therefore produce approved, funded, implementable and testable solutions for each Critical Business Function.

Where current capabilities cannot achieve the established recovery requirements, the resulting gaps should be visible to management and addressed through formal improvement plans.

Once these strategies have been selected and approved, Damanat can proceed to the next phase of its BCM Planning Methodology—Plan Development (PD).

The focus then changes from:

“What is our recovery strategy?”

to:

“Exactly who will do what, when, where and how when a disruption occurs?”

The next chapter will translate Damanat's approved Business Continuity Strategies into practical Business Continuity Plans, activation procedures, escalation arrangements, response actions, recovery procedures and return-to-normal activities.

 

 

eBook 2: Implementing Business Continuity Management
C1 C2 C3 C4 C5
C6 C7 C8 C9 C10
 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]

 

Please feel free to send us a note if you have any questions.