Business Continuity Management (BCM) provides an organisation with a structured capability to prepare for disruptive incidents, maintain its priority activities at acceptable levels, and recover disrupted operations within appropriate timeframes.
For the Malaysian Communications and Multimedia Commission (MCMC), BCM has particular significance because the organisation performs regulatory, administrative, technical, consumer-protection, and industry-facing responsibilities within Malaysia's communications and multimedia environment.
MCMC's regulatory responsibilities cover areas including competition, access and licensing, spectrum assignment, numbering and electronic addressing, consumer protection, and social and postal regulation.
These responsibilities mean that a significant disruption affecting MCMC could have consequences extending beyond its internal operations to regulated entities, consumers, government stakeholders, and potentially the wider communications and digital ecosystem.
Accordingly, BCM for MCMC should not be regarded merely as a collection of recovery plans. It should be established as an organisation-wide management capability that connects MCMC's mandate, operating environment, critical business functions, people, facilities, technology, information, suppliers, dependencies, and management arrangements.
This approach is consistent with the principles of ISO 22301 – Security and resilience — Business continuity management systems — Requirements, which requires an organisation to understand its context, determine the scope of its Business Continuity Management System (BCMS), establish business continuity objectives, assess risks and impacts, implement appropriate continuity arrangements, exercise those arrangements, evaluate performance, and continually improve the BCMS.
This first eBook, Understanding Your Organisation for the Malaysian Communications and Multimedia Commission, therefore establishes the foundation for subsequent BCM implementation. Before MCMC determines recovery strategies or develops detailed business continuity plans, it must first understand what must be protected, why it is important, what could disrupt it, and what organisational capabilities are required to maintain continuity.
BCM is a management process for developing organisational resilience and establishing the capability to continue delivering prioritised products, services and activities following disruption.
For MCMC, this means preparing the organisation to continue or recover priority regulatory and organisational activities when normal operating arrangements are unavailable or significantly degraded.
Potential disruptive events could include:
BCM should therefore enable MCMC to answer several fundamental questions:
What activities must continue?
How quickly must they be recovered?
What resources and dependencies are required?
What level of disruption can MCMC tolerate?
What alternative arrangements are available?
Who has authority to make continuity decisions?
How will MCMC coordinate its response and recovery?
These questions form the foundation of an effective BCMS.
An effective BCM programme begins with understanding the organisation.
MCMC operates within a complex communications and multimedia ecosystem involving telecommunications providers, network operators, digital service providers, postal service providers, broadcasters, consumers, government agencies, technology providers, contractors and other stakeholders.
Its regulatory responsibilities encompass both economic and technical dimensions. MCMC's established functions include areas such as licensing, competition and access regulation, spectrum management, numbering and electronic addressing, consumer protection and postal regulation.
The organisation also operates technology-dependent regulatory and administrative systems. For example, MCMC describes its Communications Infrastructure Permit Management system as a centralised web application hosted at MCMC headquarters and accessed by stakeholders including local authorities, Network Facilities Providers and State Economic Planning Units.
From a BCM perspective, understanding MCMC's operations therefore requires more than producing an organisational chart. The BCM team should understand the end-to-end delivery of important activities and the resources supporting them.
This should include identifying:
|
Area |
BCM Consideration for MCMC |
|
Regulatory functions |
Activities that must remain available during disruption |
|
Stakeholders |
Government, regulated entities, consumers and other parties dependent upon MCMC |
|
People |
Specialist personnel, decision-makers and operational teams |
|
Technology |
Applications, infrastructure, databases and communication systems |
|
Information |
Regulatory, operational, licensing, technical and stakeholder information |
|
Facilities |
Headquarters, offices and other operational locations |
|
Third parties |
Vendors, service providers and outsourced arrangements |
|
Communications |
Internal, external, regulatory and crisis communications |
|
Dependencies |
Telecommunications, electricity, cloud, internet, government systems and other services |
The objective is to establish an operational picture showing how MCMC delivers its responsibilities and where disruption could affect that delivery.
The BCM goals should express what MCMC intends to achieve through its continuity capability.
Possible BCM goals for MCMC include:
These goals should ultimately connect BCM to MCMC's organisational responsibilities rather than treating continuity as an isolated administrative programme.
The BCM goals establish strategic direction. Business continuity objectives translate that direction into measurable outcomes.
In accordance with ISO 22301 principles, objectives should be consistent with the business continuity policy, measurable where practicable, monitored, communicated and updated when appropriate.
Examples for MCMC could include:
|
Proposed BC Objective |
Illustrative Measurement |
|
Identify all critical business functions |
100% of organisational functions assessed through BIA |
|
Establish recovery requirements |
Recovery objectives documented for all critical functions |
|
Maintain current BC plans |
Plans reviewed at least annually and following significant change |
|
Validate continuity arrangements |
Critical functions exercised according to an approved exercise programme |
|
Maintain BCM competence |
Relevant BCM and response personnel complete required training |
|
Address exercise findings |
Significant findings tracked through formal corrective actions |
|
Maintain supplier resilience |
Critical third-party dependencies included in BCM assessment |
|
Maintain management oversight |
BCMS performance periodically reviewed by appropriate management |
Actual objectives and targets should be approved by MCMC management after considering organisational priorities, statutory responsibilities, resources and risk appetite.
Business continuity plans inevitably operate on assumptions. These assumptions should be explicitly identified because an invalid assumption can undermine a recovery strategy.
Illustrative assumptions for MCMC might include:
Assumptions should subsequently be tested through exercises and scenario testing.
For example, if a BC plan assumes that employees can immediately work remotely following loss of the primary office, MCMC should verify whether remote-access capacity, endpoint availability, authentication systems, network connectivity, security controls and staff preparedness can actually support the required workload.
BCM requires participation across the organisation because no single department possesses all the knowledge necessary to understand operational dependencies and recovery requirements.
An illustrative BCM governance structure for MCMC could include:
Provides strategic direction, approves the BCM policy and resources, establishes accountability, and reviews the effectiveness of the BCMS.
Provides cross-functional oversight and resolves BCM issues requiring coordination between organisational units.
Coordinates implementation and maintenance of the BCMS, facilitates BIA and risk assessment activities, maintains BCM documentation, coordinates exercises and reports BCM performance.
Represent their respective organisational functions, identify critical activities, determine resource dependencies and develop function-level continuity arrangements.
Address continuity and recovery of applications, infrastructure, networks, information, cybersecurity services and digital dependencies.
Address alternate workplaces, building access, utilities, physical resources and workplace recovery.
Address workforce availability, staff welfare, succession, communication and alternative workforce arrangements.
Identify critical external providers and incorporate continuity requirements into relevant third-party arrangements.
Coordinate internal and external communications during significant disruptions.
Provide advice concerning statutory, contractual, governance and compliance implications associated with disruption.
The precise structure should reflect MCMC's actual organisational arrangements and authority framework.
ISO 22301 requires the organisation to understand internal and external issues relevant to its purpose and its ability to achieve the intended outcomes of the BCMS.
For MCMC, this should involve analysis of both its internal operating environment and the wider Malaysian communications and multimedia ecosystem.
External considerations may include:
Internal considerations may include:
The analysis should not simply describe the environment. It should identify how changes or disruptions within that environment could affect MCMC's ability to fulfil its priority responsibilities.
MCMC should implement BCM through a structured methodology rather than developing individual continuity plans independently.
An appropriate implementation sequence would be:
Understand the Organisation
↓
Establish BCM Governance, Policy and Objectives
↓
Assess Risks and Threats
↓
Conduct Business Impact Analysis
↓
Identify Critical Business Functions
↓
Determine Recovery Requirements
↓
Develop Business Continuity Strategies and Solutions
↓
Develop Business Continuity Plans and Procedures
↓
Train and Build Awareness
↓
Exercise and Validate
↓
Review, Maintain and Continually Improve
This lifecycle approach ensures that plans are based upon documented organisational requirements rather than assumptions about what should be recovered.
For MCMC, the methodology should also integrate with related organisational disciplines including risk management, information security, cybersecurity, ICT disaster recovery, emergency management, crisis management, facilities management and third-party management.
BCM does not replace these capabilities. Instead, it provides the framework for coordinating them around the objective of maintaining priority activities during disruption.
Risk assessment supports BCM by identifying disruptive events and vulnerabilities that could affect MCMC's operations.
Illustrative risk scenarios could include:
|
Threat / Scenario |
Potential BCM Impact |
|
Cyberattack |
Loss or restriction of access to regulatory systems and information |
|
Data-centre or ICT outage |
Unavailability of applications supporting critical functions |
|
Telecommunications outage |
Loss of connectivity with staff and external stakeholders |
|
Power failure |
Loss of workplace or technology availability |
|
Flood or severe weather |
Office inaccessibility and workforce disruption |
|
Building incident |
Loss of access to a key facility |
|
Critical supplier failure |
Unavailability of externally provided technology or services |
|
Workforce disruption |
Insufficient specialist staff to perform priority functions |
|
Data corruption |
Loss of reliable regulatory or operational information |
|
Sector-wide communications incident |
Increased regulatory workload while supporting infrastructure may itself be degraded |
|
Multiple concurrent failures |
Compounding effects across people, premises, technology and suppliers |
A particularly important BCM principle is that MCMC should avoid developing continuity arrangements exclusively around individual threats.
The organisation should also assess the consequences of losing required resources.
For example:
What happens if the workplace is unavailable?
What happens if critical applications are unavailable?
What happens if telecommunications connectivity is lost?
What happens if 40% of required personnel are unavailable?
What happens if a critical supplier cannot deliver its service?
This consequence-based approach improves the usability of continuity arrangements across multiple disruptive scenarios.
One of the most important outcomes of the BCM implementation process is the identification of MCMC's Critical Business Functions (CBFs).
A function should not be classified as critical merely because it is important under normal operating conditions. Criticality should be established through a structured Business Impact Analysis that considers the consequences of disruption over time.
The assessment could consider impacts relating to:
Potential functions requiring assessment could include regulatory and licensing activities, spectrum-related functions, consumer-facing services, regulatory monitoring, critical ICT services, stakeholder communications and incident coordination.
These examples should not automatically be treated as confirmed MCMC CBFs. Their actual criticality should be established through MCMC's BIA process.
For each confirmed CBF, the BIA should establish information such as:
|
Requirement |
Question |
|
Function |
What activity must be maintained or recovered? |
|
Impact |
What happens if it stops? |
|
Time |
How does the impact increase as disruption continues? |
|
MTPD |
What is the maximum tolerable period of disruption? |
|
RTO |
By when must the function be recovered? |
|
Minimum capacity |
What minimum level of service must be restored? |
|
People |
Which personnel and competencies are required? |
|
Technology |
Which systems and applications are essential? |
|
Information |
What records and data are required? |
|
Facilities |
What locations or physical resources are necessary? |
|
Suppliers |
Which external providers support the function? |
|
Interdependencies |
Which internal and external activities must operate for the function to continue? |
This analysis provides the evidence needed to prioritise BCM investment and develop appropriate continuity and recovery strategies.
Consider an illustrative MCMC function that depends on an online regulatory application.
Under normal conditions, personnel use the application to process information, communicate with relevant parties, and maintain regulatory records.
A disruption occurs following a major cyber incident. Access to the application is suspended while cybersecurity personnel investigate the incident.
The BCM question is not simply:
"How quickly can IT restore the application?"
MCMC should instead determine:
What regulatory activities depend upon the application?
How long can each activity remain unavailable?
Which stakeholders will be affected?
Can urgent cases be prioritised?
Can selected activities be performed manually?
What information is required to implement the workaround?
How will staff communicate with affected stakeholders?
Who has authority to invoke alternative procedures?
What happens if system recovery takes substantially longer than expected?
This illustrates the distinction between ICT disaster recovery and business continuity.
ICT disaster recovery restores technology.
Business continuity enables MCMC to maintain priority organisational activities while technology, facilities, personnel or other resources are disrupted.
Both capabilities must therefore work together.
The activities introduced in this chapter collectively establish the foundation of MCMC's BCMS.
Understanding organisational operations and the operating environment supports the ISO 22301 requirement to understand the organisation and its context.
Establishing BCM goals and objectives provides direction for the BCMS.
Defining assumptions and governance establishes the organisational framework necessary for implementation.
Assessing risks identifies circumstances that could disrupt operations.
Conducting the BIA and identifying critical business functions determines what must be protected and recovered.
Developing a BCM planning methodology provides the structured process through which MCMC can translate these requirements into strategies, plans, exercises and continual improvement.
The important principle is that BCM planning should begin with understanding the organisation rather than writing the plan.
Business Continuity Management for the Malaysian Communications and Multimedia Commission should be developed as an integrated organisational capability supporting MCMC's ability to maintain its priority responsibilities through disruption.
MCMC's position within Malaysia's communications and multimedia environment creates a distinctive continuity challenge. The organisation is dependent upon people, technology, telecommunications infrastructure, information, facilities, government interfaces and external service providers while simultaneously performing functions relevant to the regulation and oversight of a highly interconnected sector. Its BCM arrangements therefore need to address both internal organisational continuity and the broader consequences of disruption to its regulatory responsibilities.
This chapter has established the initial BCM framework by introducing BCM in the MCMC context, examining the organisation's operations, identifying BCM goals, establishing business continuity objectives, defining planning assumptions, considering the composition of the BCM team, analysing the operating environment, introducing the BCM planning methodology, assessing disruptive risks and identifying Critical Business Functions.
These activities provide the foundation for the remaining chapters of Understanding Your Organisation for the Malaysian Communications and Multimedia Commission.
The next stage is to move from a high-level understanding of BCM towards a more detailed understanding of MCMC as an organisation—its mandate, operating model, stakeholders, dependencies, services and organisational characteristics. This organisational understanding will subsequently provide the basis for identifying what is truly critical, determining appropriate recovery requirements and developing practical continuity strategies.
Ultimately, the effectiveness of MCMC's BCM programme will not be measured by the number of business continuity plans it produces. It will be demonstrated by whether MCMC can continue its priority responsibilities at an acceptable level when significant disruption actually occurs.
The chapter deliberately treats the suggested MCMC critical functions as candidates for BIA assessment rather than confirmed CBFs, which is important for maintaining ISO 22301 methodological integrity. It also creates a natural foundation for the subsequent chapters on understanding MCMC, its operating environment, BCM team composition, and identification of Critical Business Functions.
| eBook 1: Understanding Your Organisation | |||||
| C1 | C2 [x] | C3 [x] | C4 [x] | C5 [x] | C6 [x] |
| C7 [x] | C8 [x] | C9 [x] | C10 | C11 [x] | C12 [x] |
|
If you have any questions, click to contact us.
|
||