This phase transforms the recovery strategies identified during earlier phases into documented procedures that can be executed during a disruption.
The objective of plan development is to ensure that all critical business functions within Damanat have clear, practical, and actionable recovery procedures that enable personnel to respond effectively during incidents.
A well-developed BC Plan provides a structured framework for managing disruptions, protecting regulatory responsibilities, and restoring normal operations within agreed recovery timeframes.
This chapter explains the key activities involved in developing Business Continuity Plans for Damanat and outlines how business units can create, validate, and maintain effective recovery plans.
The Business Continuity Plan Development process consists of three major stages:
Each stage ensures that the resulting plans are comprehensive, practical, and aligned with Damanat's business continuity objectives.
Plan Development (PD) translates approved Business Continuity Strategies into practical procedures that can be activated and executed during disruption.
The relationship is straightforward:
A Business Continuity Plan should therefore not be developed independently of the preceding analytical and strategy phases.
Its procedures should reflect approved recovery requirements, available resources, defined responsibilities and actual recovery arrangements.
The plan should be designed for use under pressure.
It should be concise enough to navigate quickly yet sufficiently detailed to support personnel operating under unfamiliar and degraded conditions.
Although plan structures may vary according to organisational requirements, Damanat's plans should generally address three operational periods:
Activities undertaken before disruption to ensure that the plan can be activated effectively.
Actions required following a disruption: assess the situation, activate the plan, mobilise resources, and resume priority activities.
Actions required to move from temporary continuity arrangements toward normal operations.
This structure creates continuity between preparedness, disruption management, recovery and normalisation.
Pre-crisis arrangements should ensure that required capabilities are ready before an incident occurs.
These should include:
Plan owners and recovery team members should understand:
Plans should contain or provide controlled access to current contact information for relevant:
Contact information should be maintained and tested.
Where alternate workspace forms part of the approved strategy, readiness should include:
Required continuity resources should be identified and, where appropriate, pre-positioned or made rapidly available.
Personnel expected to perform recovery activities should possess the necessary:
Information required during disruption should remain available, accessible and appropriately protected.
Where recovery depends upon external providers, contractual and operational activation arrangements should be documented.
Personnel with plan responsibilities should receive sufficient training before they are expected to perform those responsibilities during an actual disruption.
Once a disruptive event occurs, the Business Continuity Plan should provide a clear sequence of actions.
The organisation should define how potentially disruptive events are identified and reported.
The plan should define criteria for escalating an operational incident to the appropriate management, crisis management or business continuity level.
Activation procedures should identify:
Once activated, required teams, facilities, systems and suppliers should be mobilised.
The organisation should determine:
Where the primary workplace is unavailable, approved workplace recovery arrangements should be activated.
ICT Disaster Recovery should be initiated in accordance with business recovery priorities and coordinated with business recovery teams.
Relevant internal and external stakeholders should receive timely, controlled information appropriate to the situation.
CBFs should be restored according to approved recovery priorities, RTOs and MBCOs.
Recovery teams should record:
Recovery does not end when minimum operations resume.
The organisation must eventually restore deferred activities and transition from temporary arrangements to a sustainable normal operating environment.
Activities may include:
Particular attention should be given to data reconciliation following manual or alternative processing.
The objective is to prevent continuity arrangements themselves from creating subsequent operational, financial or information-integrity problems.
PD should generate:
|
PD Component |
Objective |
Main Procedure |
Responsible Role |
Required Supporting Information |
|
Activation |
Formally initiate continuity arrangements |
Assess criteria, authorise activation and notify teams |
Plan Owner/ Authorised Management |
Activation criteria and authority matrix |
|
Escalation |
Ensure disruption receives appropriate management attention |
Escalate based on impact and severity |
Incident/Business Management |
Escalation thresholds |
|
Team mobilisation |
Assemble required recovery personnel |
Notify and mobilise recovery teams |
Team Leader |
Contact lists and call tree |
|
Damage assessment |
Establish operational consequences |
Assess affected people, premises, technology and activities |
Recovery Team |
CBF and dependency information |
|
Workplace recovery |
Provide alternate operating capability |
Activate remote or alternate workspace |
Facilities/ICT/Business Team |
Approved workplace strategy |
|
ICT recovery |
Restore technology supporting CBFs |
Activate Disaster Recovery procedures |
ICT |
RTO, RPO and application priorities |
|
Business recovery |
Resume priority activities |
Execute approved recovery procedures |
CBF Owner/Recovery Team |
RTO, MBCO and strategy |
|
Communications |
Maintain controlled stakeholder information |
Prepare, approve and distribute communications |
Communications/Management |
Stakeholder and contact information |
|
Resource management |
Provide minimum recovery resources |
Allocate personnel, equipment and services |
Recovery Team |
Resource checklist |
|
Return to normal |
Restore normal operating arrangements |
Reconcile, migrate, restore and stand down |
CBF Owner |
Restoration criteria and reconciliation requirements |
|
Post-incident review |
Capture improvement opportunities |
Review performance and identify corrective actions |
BCM Programme Manager |
Incident logs and recovery records |
Damanat's continuity procedures should incorporate, where applicable:
Temporary continuity arrangements should not unintentionally bypass essential governance, financial, legal, information-security or approval controls.
The objective is controlled degradation, not uncontrolled relaxation of organisational safeguards.
The Business Continuity Plan Development Phase is the process by which Damanat's continuity strategies are translated into practical, executable recovery procedures.
By establishing a standardised BC Plan structure, defining a recovery organisation, conducting plan-writing workshops, and validating completed plans, Damanat can ensure that each critical business function has clear guidance for responding to disruptions.
Well-developed BC Plans enable Damanat to continue essential regulatory activities, protect critical information assets, maintain stakeholder confidence, and fulfil its statutory obligations during adverse events.
As required by ISO 22301, these plans should be regularly reviewed, updated, and tested to ensure they remain effective and aligned with the evolving operational and regulatory environment.
The completion of this phase provides the foundation for the next stage of the BCM Planning Methodology—Testing and Exercising—where the effectiveness of the plans will be validated through structured exercises and simulations.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
| C6 | C7 | C8 | C9 | C10 |
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5]
|
Please feel free to send us a note if you have any questions. |
||