Ebook

[BCM] [MCMC] [E1] [C1] Overview of BCM Case Study

Written by Moh Heng Goh | Sep 3, 2026, 4:59:58 AM

eBook 1: Chapter 1

Overview of Business Continuity Management for the Malaysian Communications and Multimedia Commission

Introduction


Business Continuity Management (BCM) provides an organisation with a structured capability to prepare for disruptive incidents, maintain its priority activities at acceptable levels, and recover disrupted operations within appropriate timeframes.

For the Malaysian Communications and Multimedia Commission (MCMC), BCM has particular significance because the organisation performs regulatory, administrative, technical, consumer-protection, and industry-facing responsibilities within Malaysia's communications and multimedia environment.

MCMC's regulatory responsibilities cover areas including competition, access and licensing, spectrum assignment, numbering and electronic addressing, consumer protection, and social and postal regulation.

These responsibilities mean that a significant disruption affecting MCMC could have consequences extending beyond its internal operations to regulated entities, consumers, government stakeholders, and potentially the wider communications and digital ecosystem.

Accordingly, BCM for MCMC should not be regarded merely as a collection of recovery plans. It should be established as an organisation-wide management capability that connects MCMC's mandate, operating environment, critical business functions, people, facilities, technology, information, suppliers, dependencies, and management arrangements.

This approach is consistent with the principles of ISO 22301 – Security and resilience — Business continuity management systems — Requirements, which requires an organisation to understand its context, determine the scope of its Business Continuity Management System (BCMS), establish business continuity objectives, assess risks and impacts, implement appropriate continuity arrangements, exercise those arrangements, evaluate performance, and continually improve the BCMS.

This first eBook, Understanding Your Organisation for the Malaysian Communications and Multimedia Commission, therefore establishes the foundation for subsequent BCM implementation. Before MCMC determines recovery strategies or develops detailed business continuity plans, it must first understand what must be protected, why it is important, what could disrupt it, and what organisational capabilities are required to maintain continuity.

Introducing BCM for MCMC

BCM is a management process for developing organisational resilience and establishing the capability to continue delivering prioritised products, services and activities following disruption.

For MCMC, this means preparing the organisation to continue or recover priority regulatory and organisational activities when normal operating arrangements are unavailable or significantly degraded.

Potential disruptive events could include:

  • major ICT or application outages;
  • cyber incidents affecting MCMC systems or information;
  • telecommunications or connectivity failures;
  • prolonged power disruption;
  • loss of access to a key office or operating location;
  • failure of critical suppliers or outsourced service providers;
  • severe weather, flooding or other natural hazards;
  • widespread workforce unavailability;
  • major public-health events;
  • disruption to critical government or shared services;
  • physical security incidents;
  • loss or corruption of important information; and
  • simultaneous or cascading disruptions involving several dependencies.

BCM should therefore enable MCMC to answer several fundamental questions:

What activities must continue?

How quickly must they be recovered?

What resources and dependencies are required?

What level of disruption can MCMC tolerate?

What alternative arrangements are available?

Who has authority to make continuity decisions?

How will MCMC coordinate its response and recovery?

These questions form the foundation of an effective BCMS.

Understanding MCMC's Operations

An effective BCM programme begins with understanding the organisation.

MCMC operates within a complex communications and multimedia ecosystem involving telecommunications providers, network operators, digital service providers, postal service providers, broadcasters, consumers, government agencies, technology providers, contractors and other stakeholders.

Its regulatory responsibilities encompass both economic and technical dimensions. MCMC's established functions include areas such as licensing, competition and access regulation, spectrum management, numbering and electronic addressing, consumer protection and postal regulation.

The organisation also operates technology-dependent regulatory and administrative systems. For example, MCMC describes its Communications Infrastructure Permit Management system as a centralised web application hosted at MCMC headquarters and accessed by stakeholders including local authorities, Network Facilities Providers and State Economic Planning Units.

From a BCM perspective, understanding MCMC's operations therefore requires more than producing an organisational chart. The BCM team should understand the end-to-end delivery of important activities and the resources supporting them.

This should include identifying:

 

Area

BCM Consideration for MCMC

Regulatory functions

Activities that must remain available during disruption

Stakeholders

Government, regulated entities, consumers and other parties dependent upon MCMC

People

Specialist personnel, decision-makers and operational teams

Technology

Applications, infrastructure, databases and communication systems

Information

Regulatory, operational, licensing, technical and stakeholder information

Facilities

Headquarters, offices and other operational locations

Third parties

Vendors, service providers and outsourced arrangements

Communications

Internal, external, regulatory and crisis communications

Dependencies

Telecommunications, electricity, cloud, internet, government systems and other services

The objective is to establish an operational picture showing how MCMC delivers its responsibilities and where disruption could affect that delivery.

Identifying BCM Goals for MCMC

The BCM goals should express what MCMC intends to achieve through its continuity capability.

Possible BCM goals for MCMC include:

  • Protect priority regulatory activities by ensuring that essential responsibilities can continue or be restored following disruption.
  • Reduce disruption to stakeholders by maintaining appropriate access to priority regulatory and stakeholder-facing services.
  • Protect people and organisational resources by incorporating personnel safety and resource availability into continuity arrangements.
  • Maintain effective regulatory coordination during incidents affecting MCMC or the wider communications and multimedia environment.
  • Protect information and technology dependencies required to perform critical functions.
  • Strengthen organisational resilience by reducing vulnerabilities and establishing alternative ways of working.
  • Provide effective management and governance during disruptive incidents.
  • Support continual improvement through exercises, incident reviews, audits, performance monitoring and management review.

These goals should ultimately connect BCM to MCMC's organisational responsibilities rather than treating continuity as an isolated administrative programme.

Establishing Business Continuity Objectives for MCMC

The BCM goals establish strategic direction. Business continuity objectives translate that direction into measurable outcomes.

In accordance with ISO 22301 principles, objectives should be consistent with the business continuity policy, measurable where practicable, monitored, communicated and updated when appropriate.

Examples for MCMC could include:

 

Proposed BC Objective

Illustrative Measurement

Identify all critical business functions

100% of organisational functions assessed through BIA

Establish recovery requirements

Recovery objectives documented for all critical functions

Maintain current BC plans

Plans reviewed at least annually and following significant change

Validate continuity arrangements

Critical functions exercised according to an approved exercise programme

Maintain BCM competence

Relevant BCM and response personnel complete required training

Address exercise findings

Significant findings tracked through formal corrective actions

Maintain supplier resilience

Critical third-party dependencies included in BCM assessment

Maintain management oversight

BCMS performance periodically reviewed by appropriate management

Actual objectives and targets should be approved by MCMC management after considering organisational priorities, statutory responsibilities, resources and risk appetite.

Determining Business Continuity Assumptions for MCMC

Business continuity plans inevitably operate on assumptions. These assumptions should be explicitly identified because an invalid assumption can undermine a recovery strategy.

Illustrative assumptions for MCMC might include:

  • primary offices may become temporarily inaccessible;
  • normal ICT services may not always be available during a disruption;
  • selected staff may need to work remotely or from alternate locations;
  • some incidents may affect both MCMC and its external service providers;
  • telecommunications services may be degraded rather than completely unavailable;
  • critical vendors may themselves experience disruption;
  • normal staffing levels may not be available;
  • a cyber incident may require systems to remain offline while investigation and containment occur;
  • stakeholder demand for information may increase substantially during a major communications-sector incident; and
  • alternative procedures may initially require manual processing or prioritisation.

Assumptions should subsequently be tested through exercises and scenario testing.

For example, if a BC plan assumes that employees can immediately work remotely following loss of the primary office, MCMC should verify whether remote-access capacity, endpoint availability, authentication systems, network connectivity, security controls and staff preparedness can actually support the required workload.

Developing the BCM Team Composition for MCMC

BCM requires participation across the organisation because no single department possesses all the knowledge necessary to understand operational dependencies and recovery requirements.

An illustrative BCM governance structure for MCMC could include:

Senior Management

Provides strategic direction, approves the BCM policy and resources, establishes accountability, and reviews the effectiveness of the BCMS.

BCM Steering Committee

Provides cross-functional oversight and resolves BCM issues requiring coordination between organisational units.

BCM Programme Manager or Coordinator

Coordinates implementation and maintenance of the BCMS, facilitates BIA and risk assessment activities, maintains BCM documentation, coordinates exercises and reports BCM performance.

Business Function Representatives

Represent their respective organisational functions, identify critical activities, determine resource dependencies and develop function-level continuity arrangements.

Information Technology and Cybersecurity

Address continuity and recovery of applications, infrastructure, networks, information, cybersecurity services and digital dependencies.

Facilities and Administration

Address alternate workplaces, building access, utilities, physical resources and workplace recovery.

Human Resources

Address workforce availability, staff welfare, succession, communication and alternative workforce arrangements.

Procurement and Vendor Management

Identify critical external providers and incorporate continuity requirements into relevant third-party arrangements.

Corporate Communications

Coordinate internal and external communications during significant disruptions.

Legal, Governance and Compliance Functions

Provide advice concerning statutory, contractual, governance and compliance implications associated with disruption.

The precise structure should reflect MCMC's actual organisational arrangements and authority framework.

Analysing MCMC's Operating Environment

ISO 22301 requires the organisation to understand internal and external issues relevant to its purpose and its ability to achieve the intended outcomes of the BCMS.

For MCMC, this should involve analysis of both its internal operating environment and the wider Malaysian communications and multimedia ecosystem.

External considerations may include:

  • Malaysian legislation and government policy;
  • communications and multimedia industry developments;
  • cybersecurity threats;
  • rapid technological change;
  • dependency upon national telecommunications infrastructure;
  • cloud and digital-service dependencies;
  • extreme weather and natural hazards;
  • supply-chain vulnerabilities;
  • stakeholder and consumer expectations;
  • interdependencies with government agencies;
  • changes in regulated technologies and services; and
  • major national or sector-wide incidents.

Internal considerations may include:

  • organisational structure;
  • governance and decision-making arrangements;
  • staffing and specialist expertise;
  • technology architecture;
  • critical information;
  • office and facility dependencies;
  • internal policies and procedures;
  • existing emergency and incident-management arrangements;
  • vendor dependencies;
  • organisational culture; and
  • existing BCM capability and maturity.

The analysis should not simply describe the environment. It should identify how changes or disruptions within that environment could affect MCMC's ability to fulfil its priority responsibilities.

Implementing the BCM Planning Methodology

MCMC should implement BCM through a structured methodology rather than developing individual continuity plans independently.

An appropriate implementation sequence would be:

Understand the Organisation

Establish BCM Governance, Policy and Objectives

Assess Risks and Threats

Conduct Business Impact Analysis

Identify Critical Business Functions

Determine Recovery Requirements

Develop Business Continuity Strategies and Solutions

Develop Business Continuity Plans and Procedures

Train and Build Awareness

Exercise and Validate

Review, Maintain and Continually Improve

This lifecycle approach ensures that plans are based upon documented organisational requirements rather than assumptions about what should be recovered.

For MCMC, the methodology should also integrate with related organisational disciplines including risk management, information security, cybersecurity, ICT disaster recovery, emergency management, crisis management, facilities management and third-party management.

BCM does not replace these capabilities. Instead, it provides the framework for coordinating them around the objective of maintaining priority activities during disruption.

Assessing Risks and Threats for MCMC

Risk assessment supports BCM by identifying disruptive events and vulnerabilities that could affect MCMC's operations.

Illustrative risk scenarios could include:

 

Threat / Scenario

Potential BCM Impact

Cyberattack

Loss or restriction of access to regulatory systems and information

Data-centre or ICT outage

Unavailability of applications supporting critical functions

Telecommunications outage

Loss of connectivity with staff and external stakeholders

Power failure

Loss of workplace or technology availability

Flood or severe weather

Office inaccessibility and workforce disruption

Building incident

Loss of access to a key facility

Critical supplier failure

Unavailability of externally provided technology or services

Workforce disruption

Insufficient specialist staff to perform priority functions

Data corruption

Loss of reliable regulatory or operational information

Sector-wide communications incident

Increased regulatory workload while supporting infrastructure may itself be degraded

Multiple concurrent failures

Compounding effects across people, premises, technology and suppliers

A particularly important BCM principle is that MCMC should avoid developing continuity arrangements exclusively around individual threats.

The organisation should also assess the consequences of losing required resources.

For example:

What happens if the workplace is unavailable?

What happens if critical applications are unavailable?

What happens if telecommunications connectivity is lost?

What happens if 40% of required personnel are unavailable?

What happens if a critical supplier cannot deliver its service?

This consequence-based approach improves the usability of continuity arrangements across multiple disruptive scenarios.

Identifying Critical Business Functions for MCMC

One of the most important outcomes of the BCM implementation process is the identification of MCMC's Critical Business Functions (CBFs).

A function should not be classified as critical merely because it is important under normal operating conditions. Criticality should be established through a structured Business Impact Analysis that considers the consequences of disruption over time.

The assessment could consider impacts relating to:

  • statutory and regulatory obligations;
  • telecommunications and multimedia sector oversight;
  • government responsibilities;
  • consumers and regulated entities;
  • financial consequences;
  • operational consequences;
  • information security;
  • stakeholder confidence;
  • organisational reputation; and
  • health, safety or broader societal consequences where applicable.

Potential functions requiring assessment could include regulatory and licensing activities, spectrum-related functions, consumer-facing services, regulatory monitoring, critical ICT services, stakeholder communications and incident coordination.

These examples should not automatically be treated as confirmed MCMC CBFs. Their actual criticality should be established through MCMC's BIA process.

For each confirmed CBF, the BIA should establish information such as:

Requirement

Question

Function

What activity must be maintained or recovered?

Impact

What happens if it stops?

Time

How does the impact increase as disruption continues?

MTPD

What is the maximum tolerable period of disruption?

RTO

By when must the function be recovered?

Minimum capacity

What minimum level of service must be restored?

People

Which personnel and competencies are required?

Technology

Which systems and applications are essential?

Information

What records and data are required?

Facilities

What locations or physical resources are necessary?

Suppliers

Which external providers support the function?

Interdependencies

Which internal and external activities must operate for the function to continue?

This analysis provides the evidence needed to prioritise BCM investment and develop appropriate continuity and recovery strategies.

Example: Applying BCM to an MCMC Regulatory Function

Consider an illustrative MCMC function that depends on an online regulatory application.

Under normal conditions, personnel use the application to process information, communicate with relevant parties, and maintain regulatory records.

A disruption occurs following a major cyber incident. Access to the application is suspended while cybersecurity personnel investigate the incident.

The BCM question is not simply:

"How quickly can IT restore the application?"

MCMC should instead determine:

What regulatory activities depend upon the application?

How long can each activity remain unavailable?

Which stakeholders will be affected?

Can urgent cases be prioritised?

Can selected activities be performed manually?

What information is required to implement the workaround?

How will staff communicate with affected stakeholders?

Who has authority to invoke alternative procedures?

What happens if system recovery takes substantially longer than expected?

This illustrates the distinction between ICT disaster recovery and business continuity.

ICT disaster recovery restores technology.

Business continuity enables MCMC to maintain priority organisational activities while technology, facilities, personnel or other resources are disrupted.

Both capabilities must therefore work together.

Linking Chapter 1 to ISO 22301

The activities introduced in this chapter collectively establish the foundation of MCMC's BCMS.

Understanding organisational operations and the operating environment supports the ISO 22301 requirement to understand the organisation and its context.

Establishing BCM goals and objectives provides direction for the BCMS.

Defining assumptions and governance establishes the organisational framework necessary for implementation.

Assessing risks identifies circumstances that could disrupt operations.

Conducting the BIA and identifying critical business functions determines what must be protected and recovered.

Developing a BCM planning methodology provides the structured process through which MCMC can translate these requirements into strategies, plans, exercises and continual improvement.

The important principle is that BCM planning should begin with understanding the organisation rather than writing the plan.

Business Continuity Management for the Malaysian Communications and Multimedia Commission should be developed as an integrated organisational capability supporting MCMC's ability to maintain its priority responsibilities through disruption.

MCMC's position within Malaysia's communications and multimedia environment creates a distinctive continuity challenge. The organisation is dependent upon people, technology, telecommunications infrastructure, information, facilities, government interfaces and external service providers while simultaneously performing functions relevant to the regulation and oversight of a highly interconnected sector. Its BCM arrangements therefore need to address both internal organisational continuity and the broader consequences of disruption to its regulatory responsibilities.

This chapter has established the initial BCM framework by introducing BCM in the MCMC context, examining the organisation's operations, identifying BCM goals, establishing business continuity objectives, defining planning assumptions, considering the composition of the BCM team, analysing the operating environment, introducing the BCM planning methodology, assessing disruptive risks and identifying Critical Business Functions.

These activities provide the foundation for the remaining chapters of Understanding Your Organisation for the Malaysian Communications and Multimedia Commission.

The next stage is to move from a high-level understanding of BCM towards a more detailed understanding of MCMC as an organisation—its mandate, operating model, stakeholders, dependencies, services and organisational characteristics. This organisational understanding will subsequently provide the basis for identifying what is truly critical, determining appropriate recovery requirements and developing practical continuity strategies.

Ultimately, the effectiveness of MCMC's BCM programme will not be measured by the number of business continuity plans it produces. It will be demonstrated by whether MCMC can continue its priority responsibilities at an acceptable level when significant disruption actually occurs.

The chapter deliberately treats the suggested MCMC critical functions as candidates for BIA assessment rather than confirmed CBFs, which is important for maintaining ISO 22301 methodological integrity. It also creates a natural foundation for the subsequent chapters on understanding MCMC, its operating environment, BCM team composition, and identification of Critical Business Functions.

 

eBook 1: Understanding Your Organisation
C1 C2 [x] C3 [x] C4 [x] C5 [x] C6 [x]
C7 [x] C8 [x] C9 [x] C10 C11 [x] C12 [x]
 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [B-3] course and the BCM-5000 Business Continuity Management Expert Implementer [B-5].

If you have any questions, click to contact us.