---
title: [BCM] [JCUS] [E3] [RAR] [T2] Treatment and Control
description: [BCM] [JCUS] [E3] [RAR] [T2] Treatment and Control
image: https://blog.bcm-institute.org/hubfs/JCU%20Graphic%20Folder/JCU%20E3%20Morepost/%5BBCM%5D%20%5BJCU%5D%20%5BE3%5D%20%5BRAR%5D%20%5BT2%5D%20Treatment%20and%20Control.jpg
---

. .

[![BCMIWhiteLogo.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogo.png?width=556&name=BCMIWhiteLogo.png "BCMIWhiteLogo.png")](http://www.bcm-institute.org/)

- [Home](https://www.bcm-institute.org/)
- [About Us](https://www.bcm-institute.org/about-us-3/) 
    - [A President’s Perspective](https://www.bcm-institute.org/about-us/a-presidents-perspective/)
    - [Our History](https://www.bcm-institute.org/about-us/our-history/)
    - [Our Advisory Council](https://www.bcm-institute.org/about-us/our-advisory-council/)
    - [Customers’ Testimonials](https://www.bcm-institute.org/about-us/customers-testimonials/)
    - [Credential Verification](https://www.bcm-institute.org/about-us/credential-verification/)
- [Courses](https://blog.bcm-institute.org/blog/course-fees-for-blended-learning-courses-master-catalog) 
    - [ISO 22301 Business Continuity Management System Audit](https://blog.bcm-institute.org/audit/business-continuity-management-audit-courses)
    - [ISO 22301 Business Continuity Management](https://blog.bcm-institute.org/bcm/business-continuity-management-courses)
    - [Crisis Communication](https://blog.bcm-institute.org/crisis-communication/crisis-communication-courses)
    - [Crisis Management](https://blog.bcm-institute.org/en/crisis-management/courses)
    - [IT Disaster Recovery](https://blog.bcm-institute.org/it-disaster-recovery/courses)
    - [Operational Resilience](https://blog.bcm-institute.org/operational-resilience/courses)
    - [Operational Resilience Audit](https://blog.bcm-institute.org/operational-resilience-audit/courses)
- [Certification](https://blog.bcm-institute.org/certification/types-of-certifications-offered) 
    - [ISO 22301 BCMS Audit Certification](https://blog.bcm-institute.org/certification/business-continuity-management-audit-certification)
    - [ISO22301 Business Continuity Management Certification](https://blog.bcm-institute.org/bcm/business-continuity-management-certification)
    - [Crisis Communication Certification](https://blog.bcm-institute.org/crisis-communication/crisis-communication-certification)
    - [Crisis Management Certification](https://blog.bcm-institute.org/en/crisis-management/crisis-management-certification)
    - [IT Disaster Recovery Planning Certification](https://blog.bcm-institute.org/it-disaster-recovery/it-disaster-recovery-certification)
    - [Operational Resilience Certification](https://blog.bcm-institute.org/operational-resilience/operational-resilience-certification)
    - [Operational Resilience Audit Certification](https://blog.bcm-institute.org/operational-resilience-audit)
- [Seminars](https://blog.bcm-institute.org/meet-the-expert/mte-webinar-mainpage)
- [Store](https://www.bcm-institute.org/store-2/)
- [Contact Us](http://www.bcm-institute.org/about-us/contact-us/)

- <https://www.facebook.com/BCMInstitute/>
- <https://www.linkedin.com/company/business-continuity-management-institute-bcm-institute>

##### Institutional Resilience in Action: Business Continuity Management Implementation at JCU Singapore

![BB BCM 6](https://blog.bcm-institute.org/hs-fs/hubfs/BB%20BCM%20%5BAi%20Gen%20Blog%20Photo%5D/BB%20BCM%20Template/BB%20BCM%206.jpg?width=2000&height=1333&name=BB%20BCM%206.jpg "BB BCM 6")

# \[BCM\] \[JCUS\] \[E3\] \[RAR\] \[T2\] Treatment and Control

[![\[BCM\] \[JCU\] \[Full Banner\] Business Continuity Management Implementation at JCU Singapore](https://no-cache.hubspot.com/cta/default/3893111/c28ce2ee-dfaa-4e23-b28a-6ae8ca285f06.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c28ce2ee-dfaa-4e23-b28a-6ae8ca285f06)

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/56984c79-92aa-4f6a-9e8c-053832b46ec5.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/56984c79-92aa-4f6a-9e8c-053832b46ec5)

Risk identification alone does not provide sufficient information for effective Business Continuity Management.

Once JCUS has identified relevant threats, it needs to understand how it currently manages them, whether existing controls are reliable and effective, and whether additional measures are required.

RAR Part 2 therefore builds upon the Threat Register developed in Part 1.

Three concepts need to be distinguished:

- **Threat** – an event, condition or circumstance capable of causing disruption.
- **Risk Treatment** – the overall approach selected to modify, share, avoid or retain the risk associated with that threat.
- **Control** – a specific measure, process, technology, procedure or arrangement used to implement the treatment.

 

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/2a94d523-88cf-42a5-b3f3-b5cef0641a42.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/2a94d523-88cf-42a5-b3f3-b5cef0641a42)

[Dr Goh Moh Heng](https://blog.bcm-institute.org/ebook/author/dr-goh-moh-heng) Oct 3, 2026

###### Business Continuity Management Certified Planner-Specialist-Expert

### [![x \[BCM\] \[JCU\] Legal Disclaimer Banner](https://no-cache.hubspot.com/cta/default/3893111/e57030e6-3c63-46cc-988b-1eabb945de75.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/e57030e6-3c63-46cc-988b-1eabb945de75)

[![Part 2: RAR - Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/121caffe-2e46-49cd-9bc5-976ed1c4cca9.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/121caffe-2e46-49cd-9bc5-976ed1c4cca9)

#### Treatment and Control**[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/2a94d523-88cf-42a5-b3f3-b5cef0641a42.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/2a94d523-88cf-42a5-b3f3-b5cef0641a42)**

### **RAR Part 2: Treatment and Control for James Cook University Singapore**

#### Objective

  

[![\[BCM\] \[ALPS\] \[E3\] \[RAR\] \[T2\] Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/bf6da142-014d-4c47-83cf-f31e0c55b75e.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/bf6da142-014d-4c47-83cf-f31e0c55b75e)

The objective of **RAR Part 2: Treatment and Control** is to assess how the threats identified during the Risk Analysis and Review process are treated and controlled and to determine whether further measures are required to reduce the potential for disruption to James Cook University Singapore (JCUS).

This assessment provides a structured basis for evaluating the adequacy of existing arrangements and identifying additional controls to consider before assessing and accepting residual risks.

Because confirmed details of JCUS's internal control environment have not been provided for this assessment, controls described as existing are **reasonably assumed controls requiring validation** unless otherwise supported by approved JCUS documentation.

 

#### **Introduction**

Risk identification alone does not provide sufficient information for effective Business Continuity Management.

Once JCUS has identified relevant threats, it needs to understand how those threats are currently managed, whether existing controls are reliable and effective, and whether additional measures are required.

RAR Part 2 therefore builds upon the Threat Register developed in Part 1.

Three concepts need to be distinguished:

- **Threat** – an event, condition or circumstance capable of causing disruption.
- **Risk Treatment** – the overall approach selected to modify, share, avoid or retain the risk associated with that threat.
- **Control** – a specific measure, process, technology, procedure or arrangement used to implement the treatment.

![](https://blog.bcm-institute.org/hs-fs/hubfs/undefined-Oct-03-2026-09-10-16-5123-AM.png?width=1774&height=887&name=undefined-Oct-03-2026-09-10-16-5123-AM.png)

For example, a cyberattack is a threat.

Risk reduction may be the selected treatment.

Network segmentation, endpoint protection, security monitoring, and incident response procedures are controls that support that treatment.

An organisation may apply several treatment approaches simultaneously.

An organisation might reduce a technology risk through redundancy, partially transfer it through contractual cloud-service commitments and insurance, and formally accept a defined level of residual exposure.

The principal treatment approaches considered in this chapter are:

- **Risk Avoidance** – eliminating the activity or exposure that creates an unacceptable risk.
- **Risk Reduction** – reducing the likelihood or consequences of the threat or increasing the organisation's ability to withstand and recover from it.
- **Risk Transference** – sharing or transferring financial, contractual, operational or service-delivery consequences to another party.
- **Risk Acceptance** – knowingly retaining residual risk within authorised risk appetite and subject to appropriate monitoring and review.

The existence of a control does not automatically demonstrate that a risk is adequately managed. JCUS should consider whether each control is appropriately designed, implemented, owned, maintained, tested and capable of operating under actual disruption conditions.

Controls that have never been tested may provide less assurance than their documented design suggests.

Similarly, an alternate workplace provides limited continuity value if staff cannot access critical applications from it, and backups provide limited protection if restoration has not been successfully demonstrated.

Identified weaknesses should therefore be converted into specific improvement actions with accountable owners, implementation dates, verification requirements and appropriate management oversight.

Treatment and control analysis also informs other resilience activities. It helps determine appropriate Business Continuity Strategies, Crisis Management arrangements, ICT Disaster Recovery priorities, emergency response requirements and broader Operational Resilience capabilities.

Risk acceptance should be particularly controlled. Acceptance is an active governance decision, not inaction.

Document significant residual risks, approve them at the appropriate authority level, and monitor and reconsider them whenever exposure, the operating environment, or control effectiveness materially changes.

 

#### **Part 1: Treatment and Control Assessment**

##### **Working Threat Register Assumption**

Pending insertion of the approved JCUS RAR Part 1 register, the following specific threats are used to demonstrate the Part 2 assessment and provide coverage across all five required categories:

##### **Denial of Access – Natural Disaster**

- Flood
- Severe Storm
- Lightning and Severe Weather
- Haze or Environmental Hazard

##### **Denial of Access – Man-made Disaster**

- Fire
- Building Access Restriction
- Utility or Building Services Failure
- Security Incident Affecting Campus Access

##### **Unavailability of People**

- Pandemic or Infectious Disease Outbreak
- Loss of Key Personnel
- Widespread Staff Unavailability
- Industrial Action or Transport Disruption Affecting Workforce Availability

##### **Disruption to the Supply Chain**

- Critical Supplier Failure
- Telecommunications Service Provider Failure
- Critical Technology Service Provider Failure
- Failure of Essential Facilities or Maintenance Provider

##### **Equipment and IT-Related Disruption**

- Power Failure
- Telecommunications Failure
- Cyberattack
- Ransomware
- Application Failure
- Network Failure
- Data Centre or Hosting Environment Outage
- Critical Hardware Failure
- Data Loss or Corruption

**Assumption:** These threats are a working implementation set based only on the specific examples and mandatory categories supplied for this chapter.

They should be reconciled against the approved RAR Part 1 threat register before final publication.

Retain threat names exactly as approved unless an obvious duplication or error requires correction.

 

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/6a22ead5-8825-422c-bb6d-945b119a3fcb.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/6a22ead5-8825-422c-bb6d-945b119a3fcb)

##### **Table RAR Part 2: Treatment and Control for James Cook University Singapore**

| **Threat** | **Existing Risk Treatment – Risk Avoidance** | **Existing Risk Treatment – Risk Reduction** | **Existing Risk Treatment – Risk Transference** | **Existing Risk Treatment – Risk Acceptance** | **Existing Controls** | **Additional Planned Controls** |
| --- | --- | --- | --- | --- | --- | --- |
| Flood (Denial of Access – Natural Disaster) | Partially Applicable. Exposure may be reduced through appropriate siting and avoiding placement of critical equipment in vulnerable areas. The external flood threat cannot be completely avoided. | Dependent on validation. Facility protection, drainage, emergency procedures, remote working and alternate teaching arrangements may reduce operational consequences. | Property insurance, landlord responsibilities and recovery-service arrangements may share part of the financial or facility impact, subject to validation. | Accept residual exposure only within the approved risk appetite, after assessing facility vulnerability and continuity capability. | Assumed – validate: weather monitoring; emergency response; protection of critical equipment; remote teaching/working capability; alternate teaching arrangements; evacuation procedures; insurance. | Facilities owner to conduct flood-vulnerability assessment; identify vulnerable critical assets; confirm alternate teaching locations; test remote teaching following campus denial; verify insurance scope annually. Priority: High where material exposure exists. |
| Severe Storm (Denial of Access – Natural Disaster) | Not Applicable – severe weather cannot be fully avoided; reduction and preparedness measures are required. | Weather monitoring, safe-working arrangements, remote learning capability, facilities protection and communications can reduce consequences. Effectiveness requires validation. | Insurance and contractual building-maintenance arrangements may transfer limited consequences. | Management may accept temporary residual risk where controls reduce exposure to approved levels; management must review when severe-weather alerts arise. | Assumed – validate: weather alerts; campus emergency procedures; remote work/teaching capability; emergency communications; building maintenance; backup power for selected systems. | Establish defined weather escalation thresholds; document campus closure/remote-teaching decision criteria; conduct severe-weather tabletop exercises; verify emergency communications annually. |
| Lightning and Severe Weather (Denial of Access – Natural Disaster) | Not Applicable – environmental occurrence cannot be eliminated. | Lightning protection, surge protection, UPS, backup power and ICT recovery arrangements can reduce consequences. | Building service agreements, warranties and insurance may share financial consequences. | Residual exposure may be accepted after validating electrical protection and recovery capability. | Assumed – validate: electrical protection; UPS; surge protection; equipment shutdown procedures; backup; DR capability. | Facilities/ICT to verify protection for critical equipment; test UPS capacity; document controlled shutdown/restart procedures; include electrical-event scenarios in recovery exercises. |
| Haze or Environmental Hazard (Denial of Access – Natural Disaster) | Partially Applicable. Outdoor or on-campus activities may be suspended when environmental conditions exceed approved thresholds. | Remote teaching, indoor relocation, environmental monitoring, workforce arrangements and student communications can reduce exposure. | Limited transference may arise through facility-management or specialist-service arrangements. | Short-term residual exposure may be accepted within health and safety thresholds and with management approval. | Assumed – validate: environmental monitoring; health and safety procedures; remote learning; communications; alternative teaching arrangements. | Establish documented trigger levels for changing teaching modes; define decision authority; maintain communication templates; exercise transition from physical to remote delivery. |
| Fire (Denial of Access – Man-made Disaster) | Partially Applicable. Hazardous activities and unsafe practices can be restricted, but fire risk cannot be entirely removed. | Expected core treatment: fire prevention, detection, suppression, evacuation, compartmentation and continuity arrangements. Effectiveness requires inspection and testing. | Property insurance, landlord arrangements, maintenance contracts and specialist recovery services may share consequences. | Do not accept significant uncontrolled fire exposure. Residual risk following statutory and continuity controls may be accepted through established governance. | Assumed – validate: alarms; detection; extinguishers/suppression; evacuation plans; drills; emergency response; electrical inspection; alternate workplace/teaching arrangements; insurance. | Validate fire protection and inspection records; map critical teaching/ICT assets by fire zone; establish relocation procedures; conduct combined evacuation/BCP exercises; verify post-fire recovery arrangements. |
| Building Access Restriction (Denial of Access – Man-made Disaster) | Partially Applicable. Activities can be designed so essential services do not depend exclusively on a single physical location. | Remote work, online teaching, alternate facilities, access-control procedures and distributed information reduce impact. | Alternate premises agreements and external service arrangements may share operational consequences. | Residual short-term access risk may be accepted where remote or alternate operations meet recovery requirements. | Assumed – validate: remote access; online learning; alternate rooms/sites; emergency communications; access-control management; BCP procedures. | Identify minimum alternate teaching capacity; document building-denial procedures; pre-authorise remote teaching triggers; test full-day campus denial scenario. |
| Utility or Building Services Failure (Denial of Access – Man-made Disaster) | Partially Applicable. Critical activities may be relocated from buildings unable to provide essential utilities. | Preventive maintenance, UPS, backup power, alternate facilities and relocation reduce consequences. | Maintenance contracts, warranties and landlord/service-provider obligations may transfer part of the exposure. | Accept residual exposure only where the maximum outage duration remains compatible with recovery requirements. | Assumed – validate: facilities maintenance; emergency maintenance contacts; backup power for critical systems; alternate teaching arrangements; incident escalation. | Identify single points of failure in electricity, cooling and building services; establish recovery priorities with facilities providers; test relocation procedures; review backup-power duration. |
| Security Incident Affecting Campus Access (Denial of Access – Man-made Disaster) | Partially Applicable. Access to threatened locations or activities may be prohibited when security risk becomes unacceptable. | Physical security, access control, emergency notification, lockdown/evacuation procedures and remote delivery reduce consequences. | Specialist security services and insurance may transfer limited consequences. | Acceptance should depend on formal security assessment and authorised decision-making. | Assumed – validate: access control; security personnel; visitor controls; incident escalation; emergency communications; evacuation/lockdown arrangements. | Integrate security and BCM escalation; establish campus denial decision matrix; conduct joint security/BCM exercise; validate alternate teaching and communication capability. |
| Pandemic or Infectious Disease Outbreak (Unavailability of People) | Partially Applicable. High-risk activities or physical gatherings may be suspended, but the underlying threat cannot be eliminated. | Remote teaching/work, workforce separation, hygiene measures, cross-training, absence monitoring and alternative staffing reduce consequences. | Limited transfer through healthcare, outsourced services or insurance where applicable; accountability remains with JCUS. | Residual exposure may be accepted after implementing workforce and service-continuity measures, with senior management oversight during prolonged events. | Assumed – validate: remote learning; remote work; health guidance; absence reporting; communications; cross-training; alternative academic delivery. | Maintain pandemic staffing scenarios; identify minimum staffing by critical function; cross-train priority roles; exercise sustained staff absence; review remote-delivery capacity periodically. |
| Loss of Key Personnel (Unavailability of People) | Partially Applicable. Excessive dependency on individual personnel can be deliberately designed out. | Succession planning, deputies, cross-training, documented procedures and knowledge management reduce impact. | Specialist contractors or external professional support may share some operational consequences. | Temporary residual dependency may require formal acceptance where specialist capability cannot be duplicated economically. | Assumed – validate: deputies; delegation arrangements; documented processes; shared records; cross-training for selected functions. | Complete key-person dependency analysis; establish minimum two-deep coverage for priority roles where practicable; document succession authority; conduct unannounced deputy-role exercises. |
| Widespread Staff Unavailability (Unavailability of People) | Not Applicable – widespread workforce disruption cannot normally be fully avoided. | Cross-training, remote work, workload prioritisation, redeployment and minimum staffing plans reduce consequences. | Temporary staffing or outsourced support may transfer part of operational workload. | Accept residual staffing risk only where essential services can remain within agreed recovery requirements. | Assumed – validate: remote work; leave/absence management; role deputies; prioritisation; alternative academic staffing. | Develop staffing thresholds at 10%, 25%, 40% and higher absence levels; predefine services to defer; maintain redeployment matrix; exercise prolonged workforce shortage. |
| Industrial Action or Transport Disruption Affecting Workforce Availability (Unavailability of People) | Partially Applicable. Dependency on physical presence can be reduced, but external transport or industrial events cannot be eliminated. | Remote working, flexible scheduling, alternate delivery and staff redeployment reduce impact. | Limited external support may be available for selected activities. | Residual exposure may be accepted where alternative delivery maintains priority services. | Assumed – validate: remote access; online teaching; workforce communications; timetable flexibility; contingency staffing. | Define remote-operation triggers; identify roles requiring physical presence; prepare transport/access contingencies for essential personnel; exercise workforce-access disruption. |
| Critical Supplier Failure (Disruption to the Supply Chain) | Partially Applicable. Sole-source dependency can sometimes be avoided through supplier diversification or alternative sourcing. | Due diligence, continuity requirements, performance monitoring, alternate suppliers and contingency stock/services reduce impact. | Contracts, SLAs, warranties and indemnities may transfer some consequences, but not JCUS's accountability for continuity. | Formally accept residual supplier dependency only after assessing substitutability and recovery capability. | Assumed – validate: procurement due diligence; contracts; SLAs; supplier contacts; performance management; escalation arrangements. | Classify critical suppliers; obtain supplier BCM evidence; identify alternatives; strengthen continuity clauses; conduct joint exercises with highest-criticality suppliers; annually review concentration risk. |
| Telecommunications Service Provider Failure (Disruption to the Supply Chain) | Partially Applicable. Avoid exclusive dependence on one carrier where proportionate and technically feasible. | Diverse connectivity, alternate communications, mobile services and remote-working contingencies reduce impact. | Carrier SLAs and service credits transfer only limited financial consequences. | Short residual outages may be accepted if alternative communications satisfy recovery requirements. | Assumed – validate: telecom contracts; mobile communications; internet connectivity; service escalation; alternative communications. | Assess carrier/path diversity; provide independent backup connectivity for critical functions; document communications fallback hierarchy; conduct telecom-loss simulation. |
| Critical Technology Service Provider Failure (Disruption to the Supply Chain) | Partially Applicable. Avoid high-risk providers or unsupported services where viable alternatives exist. | Vendor due diligence, resilience requirements, data backup, service monitoring, and exit planning reduce consequences. | SLAs, cloud resilience commitments, warranties and managed recovery services may transfer defined consequences. | Residual provider risk requires governance approval based on service criticality and viable recovery alternatives. | Assumed – validate: vendor contracts; SLA monitoring; vendor support; backups; incident escalation; service management. | Perform technology-provider concentration assessment; validate vendor DR capability; document exit/transition plans; require evidence of recovery tests; exercise provider outage scenarios. |
| Failure of Essential Facilities or Maintenance Provider (Disruption to the Supply Chain) | Partially Applicable.  Dependency on a single maintenance source can sometimes be avoided. | Preventive maintenance, alternate contractors, spare parts and escalation arrangements reduce impact. | Maintenance agreements, warranties and emergency call-out commitments share operational consequences. | Residual risk may be accepted where alternate facilities or contractors can satisfy recovery requirements. | Assumed – validate: maintenance contracts; scheduled maintenance; emergency support; facilities escalation. | Identify alternate contractors for critical services; define maximum response times; maintain critical spare strategy; conduct supplier-response tests. |
| Power Failure (Equipment and IT-Related Disruption) | Not Applicable – external or internal power loss cannot be fully avoided. | UPS, backup power, equipment protection, orderly shutdown, alternate facilities and ICT recovery reduce consequences. | Utility agreements, equipment warranties and insurance may share limited consequences. | Accept residual outage exposure only where backup duration and recovery arrangements meet business requirements. | Assumed – validate: UPS; electrical protection; backup arrangements; emergency lighting; ICT shutdown procedures; alternate work/teaching capability. | Test UPS under realistic load; document runtime by critical system; identify extended-outage strategy; conduct power-loss recovery exercise; remove electrical single points of failure where justified. |
| Telecommunications Failure (Equipment and IT-Related Disruption) | Partially Applicable. Avoid single-carrier and single-path dependencies where feasible. | Network redundancy, mobile alternatives, collaboration tools and alternate connectivity reduce consequences. | Carrier SLAs and managed telecommunications services transfer limited operational/financial consequences. | Residual short-term outage may be accepted if alternative channels satisfy minimum continuity requirements. | Assumed – validate: multiple communications channels; network monitoring; service-provider escalation; mobile communications; remote-access capability. | Implement/validate diverse connectivity; define fallback communications sequence; test voice/data outage scenarios; establish recovery performance measures. |
| Cyberattack (Equipment and IT-Related Disruption) | Partially Applicable. Unsupported technology and unnecessarily exposed services can be eliminated, although cyberattack itself cannot be avoided. | Defence-in-depth cybersecurity, access control, monitoring, segmentation, patching, backup, incident response and awareness reduce likelihood and impact. | Cyber insurance and managed security/service-provider arrangements may share financial or operational consequences but do not transfer accountability. | Do not passively accept material unmitigated cyber exposure. Residual exposure requires documented approval within cyber-risk governance. | Assumed – validate: identity/access management; endpoint security; network controls; monitoring; vulnerability management; backups; incident response; awareness; escalation. | Validate controls through technical assurance; strengthen segmentation and privileged-access controls where required; conduct cyber-BCM exercises; map critical services to technical dependencies; test recovery from destructive attack. |
| Ransomware (Equipment and IT-Related Disruption) | Partially Applicable. Remove unsupported systems, unnecessary services, and insecure configurations where possible. | Endpoint protection, email/web controls, segmentation, MFA, patching, immutable/offline backups, monitoring and recovery testing reduce exposure. | Cyber insurance, specialist incident-response retainers and managed recovery arrangements may share consequences. | Acceptance is inappropriate where recoverability has not been demonstrated. Accept residual exposure only after validating recovery capability and control effectiveness. | Assumed – validate: endpoint protection; access control; backups; monitoring; incident response; security awareness; DR arrangements. | Implement/validate immutable backup; test clean-environment restoration; conduct ransomware simulation; define minimum viable service recovery sequence; verify privileged-account security and emergency communications. |
| Application Failure (Equipment and IT-Related Disruption) | Partially Applicable. Retire or replace unsupported or unreliable applications. | High availability, monitoring, preventive maintenance, backup, restoration, change control and manual workarounds reduce impact. | Vendor support, warranties, SaaS SLAs and managed application services may transfer defined consequences. | Residual application downtime may be accepted where it remains within approved recovery requirements and tested workarounds exist. | Assumed – validate: application support; monitoring; backups; incident management; change management; vendor escalation; DR arrangements. | Map critical applications to business functions; confirm RTO/RPO alignment; develop manual workarounds; perform restoration tests; eliminate unsupported applications; establish recovery evidence. |
| Network Failure (Equipment and IT-Related Disruption) | Partially Applicable. Avoid unnecessary single points of failure where technically and financially proportionate. | Redundant devices/links, monitoring, configuration backup, spare equipment and alternate connectivity reduce impact. | Managed network services, warranties and carrier contracts may transfer part of the response burden. | Residual exposure may be accepted after validating redundancy and recovery time. | Assumed – validate: network monitoring; redundant components; configuration management; vendor support; incident escalation. | Perform network single-point-of-failure assessment; test failover; maintain validated configuration backups; ensure critical spares; conduct campus network outage exercise. |
| Data Centre or Hosting Environment Outage (Equipment and IT-Related Disruption) | Partially Applicable. Concentration in a single hosting environment may be reduced or avoided for sufficiently critical services. | Redundant hosting, replication, backups, failover, DR arrangements, and cloud availability design reduce impact. | Hosting/cloud SLAs, managed recovery, and insurance may share consequences. | Residual hosting risk requires formal approval where service concentration remains unavoidable. | Assumed – validate: backup; replication; DR arrangements; vendor escalation; infrastructure monitoring; alternate hosting where applicable. | Validate recovery architecture; test failover/restoration end-to-end; assess geographic/concentration risk; obtain provider recovery evidence; align technical recovery with business RTO/RPO. |
| Critical Hardware Failure (Equipment and IT-Related Disruption) | Partially Applicable. Retire unsupported or obsolete equipment to reduce avoidable exposure. | Redundancy, preventive maintenance, monitoring, spare equipment and lifecycle replacement reduce impact. | Hardware warranties, maintenance agreements and managed infrastructure services may transfer repair/replacement responsibilities. | Residual exposure may be accepted for non-critical hardware; critical single points of failure require remediation or explicit approval. | Assumed – validate: maintenance; monitoring; warranties; spares; redundancy for selected infrastructure; lifecycle management. | Identify critical hardware single points; maintain appropriate spares; establish lifecycle replacement thresholds; test component failover; review warranty response against recovery requirements. |
| Data Loss or Corruption (Equipment and IT-Related Disruption) | Partially Applicable. Unsafe manual processes and unsupported data-storage methods can be eliminated. | Backup, replication, access control, integrity monitoring, versioning, change controls and restoration procedures reduce consequences. | Cloud/provider commitments and insurance may share limited consequences; responsibility for information recovery remains with JCUS. | Do not accept significant unrecoverable data exposure. Residual loss within approved RPO requires authorised acceptance. | Assumed – validate: scheduled backups; access control; audit logging; replication/versioning; restoration procedures; data retention. | Test restoration against defined RPO/RTO; implement protected/immutable backup where appropriate; validate backup coverage; establish data-integrity checks; conduct data-corruption recovery simulation. |

 

#### **Control Validation Requirements**

Because many controls in this assessment are assumed rather than confirmed, JCUS should undertake a structured control-validation exercise before treating the table as a final representation of its control environment.

For every existing control, validation should establish:

 

| Validation Area | Key Question |
| --- | --- |
| Existence | Is the control actually implemented? |
| Ownership | Is a named function accountable for it? |
| Design | Is the control capable of addressing the relevant threat? |
| Operation | Does the control operate consistently in practice? |
| Coverage | Does it protect all relevant locations, people, systems and services? |
| Currency | Is the control maintained and updated? |
| Testing | Has its effectiveness been demonstrated? |
| Recovery Capability | Will the control remain available during disruption? |
| Evidence | Can implementation and testing be demonstrated? |
| Effectiveness | Does the control reduce likelihood or impact to the expected degree? |

A control should not be classified as effective solely because a policy, contract, technology or procedure exists.

 

#### **Planned Control Implementation Register**

Transfer material improvements identified in the assessment into a formal implementation register.

 

| Field | Implementation Requirement |
| --- | --- |
| Threat | Threat addressed by the action |
| Control Gap | Specific weakness identified |
| Planned Control | Defined improvement action |
| Control Type | Preventive, Detective, Corrective, Recovery, Directive, Deterrent or Compensating |
| Risk Treatment | Avoidance, Reduction, Transference or Acceptance |
| Owner | Accountable function |
| Priority | Critical, High, Medium or Low |
| Target Date | Approved implementation date |
| Expected Risk Reduction | Intended improvement in likelihood, impact or recoverability |
| Testing Method | How effectiveness will be demonstrated |
| Evidence Required | Documentation demonstrating completion |
| Status | Planned, In Progress, Implemented, Validated or Closed |

This ensures that recommendations become measurable risk-treatment activities rather than remaining general observations.

 

#### **Risk Acceptance Governance**

Risk acceptance should only occur after the relevant existing and planned controls have been considered.

For significant residual risks, the acceptance record should identify:

- the specific threat and resulting exposure;
- existing controls;
- known control limitations;
- residual consequences;
- reason further treatment is not currently justified or practicable;
- approving authority;
- acceptance date;
- review date;
- monitoring requirements;
- escalation thresholds; and
- circumstances requiring reconsideration.

Acceptance should be reconsidered when:

![](https://blog.bcm-institute.org/hs-fs/hubfs/undefined-Oct-03-2026-09-10-17-6847-AM.png?width=1774&height=887&name=undefined-Oct-03-2026-09-10-17-6847-AM.png)

An expired, undocumented or unreviewed acceptance should not automatically be treated as continuing approval.

 

#### **Relationship with Business Continuity Strategy**

The RAR Part 2 assessment provides an important input into Business Continuity Strategy development.

Where preventive controls cannot sufficiently reduce disruption risk, JCUS should determine how essential activities will continue or recover.

For example:

![](https://blog.bcm-institute.org/hs-fs/hubfs/undefined-Oct-03-2026-09-10-18-8535-AM.png?width=1774&height=887&name=undefined-Oct-03-2026-09-10-18-8535-AM.png)

Similarly:

![](https://blog.bcm-institute.org/hs-fs/hubfs/undefined-Oct-03-2026-09-10-21-2550-AM.png?width=1774&height=887&name=undefined-Oct-03-2026-09-10-21-2550-AM.png)

Risk treatment and Business Continuity Strategy should therefore be complementary rather than treated as separate exercises.

 

#### **Relationship with Crisis Management**

Certain threats may escalate beyond operational recovery and require strategic Crisis Management.

Examples include:

- major fire;
- prolonged campus denial;
- widespread infectious disease;
- serious security incident;
- destructive cyberattack;
- ransomware affecting critical systems;
- major data loss;
- extended technology outage; or
- simultaneous failure of multiple critical dependencies.

The Risk Assessment should therefore inform crisis escalation criteria, Crisis Management Team exercises, stakeholder communication arrangements and strategic decision-making procedures.

 

#### **Relationship with Operational Resilience**

Treatment and control analysis also supports Operational Resilience by identifying where essential services depend upon vulnerable combinations of:

##### **People + Premises + Technology + Information + Third Parties**

Controls should therefore be evaluated not only individually but also for their combined ability to prevent a disruption from exceeding acceptable operational limits.

A well-controlled component can still contribute to failure where another critical dependency remains a single point of failure.

 

#### **Recommended Control Assurance Cycle**

JCUS should apply a continuous assurance cycle:

![](https://blog.bcm-institute.org/hs-fs/hubfs/undefined-Oct-03-2026-09-10-20-0781-AM.png?width=2172&height=724&name=undefined-Oct-03-2026-09-10-20-0781-AM.png)

Repeat this cycle when significant organisational, technological, regulatory, supplier, or threat-environment changes occur.

 

**[![Banner \[Table\] \[BCM\] \[E3\] \[RAR\] \[Summing Up\] \[T2\] Treatment and Control of Identified Threats](https://no-cache.hubspot.com/cta/default/3893111/6755d2e8-5050-4a5e-be0a-a1568a65e0ed.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/6755d2e8-5050-4a5e-be0a-a1568a65e0ed)**

RAR Part 2 converts the threat identification undertaken in Part 1 into a structured assessment of how disruption risks are managed.

For JCUS, effective treatment requires more than maintaining individual preventive measures.

The organisation should understand which risks it avoids, which it reduces, which it shares with third parties, and which residual exposures it deliberately accepts.

Place particular emphasis on validating assumed controls.

A documented control provides limited assurance unless you can demonstrate its ownership, availability, reliability, and effectiveness.

Convert control gaps into specific improvement actions with defined owners, priorities, implementation timeframes, testing methods, and evidence requirements.

The completed treatment and control assessment provides a foundation for subsequent risk analysis by establishing the control environment against which likelihood, impact and residual exposure can be evaluated.

It also informs Business Continuity Strategy, ICT Disaster Recovery, Crisis Management, supplier resilience and broader Operational Resilience planning.

**Effective risk treatment requires appropriate controls; effective controls require ownership and testing; and residual risk requires deliberate, documented and accountable management acceptance.**

 

[![BL-OR-3-5 Blog Under Construction](https://no-cache.hubspot.com/cta/default/3893111/3aefb2d2-3110-47c1-ad4f-d3e6e5381066.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3aefb2d2-3110-47c1-ad4f-d3e6e5381066)

 

[![\[BCM\] \[JCU\] \[3/4 Banner\] Business Continuity Management Implementation at JCU Singapore](https://no-cache.hubspot.com/cta/default/3893111/d81098d9-9f30-4c17-a897-2fc202440adc.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/d81098d9-9f30-4c17-a897-2fc202440adc)

| **eBook 3: Starting Your BCM Implementation** |  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- | --- |
| **MBCO** | **P&S** | **RAR T1** | **RAR T2** | **RAR T3** | **BCS T1** | **CBF** |
| [![\[BCM\] \[JCU\] \[E3\] \[BIA\] MBCO Corporate MBCO](https://no-cache.hubspot.com/cta/default/3893111/37db16b1-9a61-4815-adbb-527771b7bd35.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/37db16b1-9a61-4815-adbb-527771b7bd35) | [![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[PS\] Key Product and Services](https://no-cache.hubspot.com/cta/default/3893111/3117a3bf-33fd-4522-a373-4ce343e253a6.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3117a3bf-33fd-4522-a373-4ce343e253a6) | [![\[BCM\] \[JCU\] \[E3\] \[RAR\] \[T1\] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/de614923-e16d-4c4b-878e-60b97f56183f.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/de614923-e16d-4c4b-878e-60b97f56183f) | [![\[BCM\] \[JCU\] \[E3\] \[RAR\] \[T2\] Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/71606f66-523b-41e0-af99-19f5e4cc2f37.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/71606f66-523b-41e0-af99-19f5e4cc2f37) | [![\[BCM\] \[JCU\] \[E3\] \[RAR\] \[T3\] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/0192071d-0c49-4a20-a2a8-f0894418f873.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/0192071d-0c49-4a20-a2a8-f0894418f873) | [![\[BCM\] \[JCU\] \[E3\] \[BCS\] \[T1\] Mitigation Strategies and Justification](https://no-cache.hubspot.com/cta/default/3893111/12b9c723-7ba3-4523-a1c2-0e75dc09a4e3.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/12b9c723-7ba3-4523-a1c2-0e75dc09a4e3) | [![\[BCM\] \[JCU\] \[E1\] \[C10\] Identifying Critical Business Functions](https://no-cache.hubspot.com/cta/default/3893111/b7aaf4cf-e4f4-4e31-bb8f-6885a5f2203d.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/b7aaf4cf-e4f4-4e31-bb8f-6885a5f2203d) |
| **CBF-1 Teaching and Learning Delivery** |  |  |  |  |  |  |
| **DP** | **BIAQ P1** | **BIAQ P2** | **BIAQ P3** | **BIAQ P4** | **BIAQ P5** | **BIAQ P6** |
| [![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[DP\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/87dc20a3-b9ed-454a-90ee-2ca3e2419322.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/87dc20a3-b9ed-454a-90ee-2ca3e2419322) | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T1\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/c0d85e4b-2df7-44ee-9c25-4112e99a64f3.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c0d85e4b-2df7-44ee-9c25-4112e99a64f3)** | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T2\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/3d5d03b2-0465-4e70-8920-efbaf80a835c.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3d5d03b2-0465-4e70-8920-efbaf80a835c)** | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T3\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/4107cc4d-b5ca-486c-bca0-d2a049b8c752.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/4107cc4d-b5ca-486c-bca0-d2a049b8c752)** | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T4\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/e9bd80ac-aa4d-4da0-873e-92bb036ae9c9.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/e9bd80ac-aa4d-4da0-873e-92bb036ae9c9)** | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T5\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/7c619369-8c50-4876-a478-749b847adee0.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/7c619369-8c50-4876-a478-749b847adee0)** | **[![\[BCM\] \[JCU\] \[E3\] \[BIA\] \[T6\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/bdb520b6-bc53-40cf-bc72-5e4eb5c2d1ae.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/bdb520b6-bc53-40cf-bc72-5e4eb5c2d1ae)** |
|  |  | **BCS T2** | **BCS T3** | **PD** |  |  |
|  |  | [![\[BCM\] \[JCU\] \[E3\] \[BCS\] \[T2\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/10a04273-213c-4b93-a69a-966039c382bb.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/10a04273-213c-4b93-a69a-966039c382bb) | [![\[BCM\] \[JCU\] \[E3\] \[BCS\] \[T3\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/d2ec73f8-a65d-473f-9a70-afa20ac0b990.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/d2ec73f8-a65d-473f-9a70-afa20ac0b990) | [![\[BCM\] \[JCU\] \[E3\] \[PD\] \[CBF\] \[1\] Teaching and Learning Delivery](https://no-cache.hubspot.com/cta/default/3893111/41fe68b0-13dc-4690-bd61-369c6da03192.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/41fe68b0-13dc-4690-bd61-369c6da03192) |  |  |
|  |  |  |  |  |  |  |

 

#### More Information About Business Continuity Management Courses

 

[![BCCE Business Continuity Certified Expert Certification (Size 100)](https://no-cache.hubspot.com/cta/default/3893111/c010f0fd-7ba6-4f60-b63b-38efafac8ca5.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/c010f0fd-7ba6-4f60-b63b-38efafac8ca5)[![BCCS Business Continuity Certified Specialist Certification (Size 100)](https://no-cache.hubspot.com/cta/default/3893111/354ef907-cf2c-4148-aa47-577a930e76c5.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/354ef907-cf2c-4148-aa47-577a930e76c5)To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer \[B-3\] course and the BCM-5000 Business Continuity Management Expert Implementer \[B-5\].

| [![Register \[BL-B-3\]\*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/9ff8a3dc-e39a-465b-929f-72e232cdd5fb.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/9ff8a3dc-e39a-465b-929f-72e232cdd5fb) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/f3922b80-e96a-46d6-8993-dc150a5de2d5.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/f3922b80-e96a-46d6-8993-dc150a5de2d5) |
| --- | --- | --- |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/1cb17ac7-50b2-4f88-bc4b-c7444e4b57b5.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/1cb17ac7-50b2-4f88-bc4b-c7444e4b57b5) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/3ecb1171-819d-45a2-8686-6db917a20156.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3ecb1171-819d-45a2-8686-6db917a20156) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/21525c10-4003-4934-95fc-fe218174bc5b.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/21525c10-4003-4934-95fc-fe218174bc5b) |
| [![FAQ \[BL-B-3\]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae) | If you have any questions, click to contact us. [![Email to Sales Team \[BCM Institute\]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e) | [![ FAQ BL-B-5 BCM-5000](https://no-cache.hubspot.com/cta/default/3893111/9c199ae8-c470-4bb7-9612-73c7a084e94c.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/9c199ae8-c470-4bb7-9612-73c7a084e94c) |
| [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/8999211a-2c51-4be7-bf49-c393f6c67974.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/8999211a-2c51-4be7-bf49-c393f6c67974) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/5c1aa95d-f6dd-4067-a95c-5cc0c32d7ed8.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/5c1aa95d-f6dd-4067-a95c-5cc0c32d7ed8) | [![New call-to-action](https://no-cache.hubspot.com/cta/default/3893111/086ab3b9-4d66-4a95-b2f7-1148e9803a9c.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/086ab3b9-4d66-4a95-b2f7-1148e9803a9c) |

#### **Your Comments Here:**

 

### More Posts

[![New Call-to-action](https://no-cache.hubspot.com/cta/default/3893111/839787f4-a4fd-456f-accf-54c947026558.png)](https://cta-redirect.hubspot.com/cta/redirect/3893111/839787f4-a4fd-456f-accf-54c947026558)

![BCMIWhiteLogoSmall.png](https://blog.bcm-institute.org/hs-fs/hubfs/Blog%20Testing/BCMIWhiteLogoSmall.png?width=72&name=BCMIWhiteLogoSmall.png "BCMIWhiteLogoSmall.png")

All rights reserved. Copyright 2026

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Dr Goh Moh Heng",
    "url" : "https://blog.bcm-institute.org/ebook/author/dr-goh-moh-heng"
  },
  "dateModified" : "2026-10-03T12:45:51.344Z",
  "datePublished" : "2026-10-03T10:41:27.000Z",
  "headline" : "[BCM] [JCUS] [E3] [RAR] [T2] Treatment and Control",
  "mainEntityOfPage" : {
    "@id" : "https://blog.bcm-institute.org/ebook/bcm-jcus-e3-rar-t2-treatment-and-control",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.bcm-institute.org/hubfs/BCMI%20Logo.png"
    },
    "name" : "BCMI Pte Ltd"
  }
}
```