eBook 1: Chapter 10
Introduction
A fundamental requirement of Business Continuity Management (BCM) is determining which organisational activities must be prioritised when normal operations are disrupted. For the Malaysian Communications and Multimedia Commission (MCMC), this requires identifying those business functions whose prolonged disruption could result in unacceptable regulatory, operational, stakeholder, financial, reputational or societal consequences.
Identifying Critical Business Functions (CBFs) is therefore not simply an exercise in listing important departments. It requires MCMC to understand how its regulatory mandate is delivered, assess the consequences of disruption over time, establish recovery priorities and identify the resources and dependencies required to maintain or restore priority activities.
This is particularly important because MCMC operates within Malaysia's highly interconnected communications and multimedia environment. Its responsibilities include regulatory activities involving licensing, competition and access, spectrum, numbering and electronic addressing, consumer protection and postal regulation.
MCMC also maintains technology-enabled services and registers. For example, its Register of Certified Proficient Persons provides information concerning certified radio operators and cabling providers, while the Communications Infrastructure Permit Management (CIPM) system is a centralised web application accessed by MCMC and external stakeholders.
Consequently, disruption to an MCMC function may have implications extending beyond the organisation itself. Regulated entities, consumers, government stakeholders and other parties may depend upon the continued availability of particular MCMC activities.
This chapter explains how MCMC can identify and prioritise its CBFs as part of an ISO 22301-aligned Business Continuity Management System (BCMS). It also proposes an initial catalogue of CBFs that can be validated through MCMC's formal Business Impact Analysis (BIA).
What Is a Critical Business Function?
A Critical Business Function is an organisational function or activity that must be maintained or recovered within an acceptable timeframe following disruption because failure to do so could result in unacceptable consequences.
For MCMC, a business function should therefore not be classified as critical merely because it is important during normal operations.
The distinction is significant.
Many MCMC functions will be important. However, BCM requires the organisation to determine how quickly each function must be recovered and which functions must receive priority when resources are constrained during a major disruption.
For example, an administrative activity that can be suspended for several weeks without serious consequences may be important but would not necessarily receive the same recovery priority as an activity where a prolonged interruption could significantly affect MCMC's regulatory responsibilities or ability to respond to a serious communications-sector incident.
Criticality is therefore time-dependent.
The central question is:
At what point would the disruption of this function cause consequences that MCMC considers unacceptable?
ISO 22301 Context for Identifying CBFs
ISO 22301 requires organisations to establish and maintain processes for analysing business impacts and assessing risks of disruption.
For MCMC, the BIA should provide the evidence necessary to:
- identify prioritised activities;
- understand the consequences of disruption;
- determine how impacts increase over time;
- establish recovery priorities;
- determine acceptable recovery timeframes;
- identify minimum acceptable operating levels;
- understand dependencies;
- identify required resources; and
- provide a basis for selecting business continuity strategies and solutions.
The identification of CBFs should therefore be an outcome of the BIA rather than an assumption made before the BIA.
A sound implementation sequence is:
Understand MCMC's Mandate and Operations
↓
Identify Business Functions and Activities
↓
Assess the Impact of Their Disruption
↓
Determine How Impact Changes Over Time
↓
Establish Maximum Tolerable Periods of Disruption
↓
Determine Recovery Time Objectives
↓
Identify Resource and Dependency Requirements
↓
Prioritise the Functions
↓
Confirm Critical Business Functions
↓
Obtain Management Approval
This creates an evidence-based basis for BCM prioritisation.
MCMC's Regulatory Context and BCM Priorities
The nature of MCMC's responsibilities should be considered when determining criticality.
MCMC's regulatory environment includes communications networks, telecommunications services, applications services and content applications services. Its licensing framework recognises Network Facilities Providers, Network Service Providers, Applications Service Providers and Content Applications Service Providers.
This means that MCMC's BCM considerations should extend beyond conventional internal impacts such as lost productivity.
When determining whether an activity is critical, MCMC should consider consequences affecting:
Regulatory Obligations
Could disruption prevent MCMC from performing a statutory or regulatory responsibility?
Communications and Multimedia Sector
Could prolonged disruption adversely affect MCMC's ability to oversee or support an important part of Malaysia's communications and multimedia environment?
Consumers
Could disruption impair MCMC's ability to protect consumers or handle serious communications and multimedia issues?
MCMC has historically maintained consumer complaint arrangements covering areas including telecommunications, broadcasting, internet, postal and digital certification services.
Government and National Stakeholders
Could disruption prevent MCMC from providing information, coordination or regulatory support required by government or other relevant authorities?
Regulated Entities
Could disruption prevent licensees or other regulated parties from completing time-sensitive regulatory activities?
Information
Could disruption result in loss, corruption, unavailability or unauthorised disclosure of critical regulatory information?
Reputation and Confidence
Could prolonged disruption significantly reduce stakeholder confidence in MCMC's ability to perform its responsibilities?
These considerations make MCMC's BIA different from that of a purely commercial organisation.
Criteria for Determining Criticality
MCMC should establish consistent criteria for assessing all business functions.
An illustrative impact framework could include the following.
|
Impact Dimension |
Key Question for MCMC |
|
Statutory / Regulatory |
Would disruption prevent MCMC from fulfilling a material statutory or regulatory obligation? |
|
Sector Impact |
Could disruption materially affect MCMC's oversight of Malaysia's communications and multimedia sector? |
|
Consumer Impact |
Could consumers experience significant or escalating harm because the function is unavailable? |
|
Government / National Interest |
Could disruption affect government priorities, national communications interests or coordination requirements? |
|
Stakeholder Impact |
Would regulated entities or other stakeholders be unable to perform time-sensitive activities? |
|
Operational Impact |
Would disruption prevent other important MCMC functions from operating? |
|
Technology / Information |
Would critical systems, information or digital services become unavailable or unreliable? |
|
Financial Impact |
Could disruption create material financial consequences? |
|
Legal / Compliance |
Could MCMC fail to satisfy legal, contractual or compliance requirements? |
|
Reputational Impact |
Could prolonged disruption significantly damage stakeholder confidence in MCMC? |
MCMC should define thresholds for each category so that business functions can be evaluated consistently.
Assessing the Impact of Disruption Over Time
A function does not become critical solely because disruption has consequences. The speed at which those consequences become unacceptable is equally important.
MCMC should therefore evaluate impact over defined periods.
For example:
|
Duration of Disruption |
Illustrative Assessment |
|
0–4 hours |
Immediate operational consequences |
|
4–12 hours |
Short-term degradation |
|
12–24 hours |
Increasing operational and stakeholder impact |
|
1–3 days |
Significant regulatory or stakeholder consequences may develop |
|
3–7 days |
Serious accumulated impact |
|
More than 7 days |
Potentially unacceptable strategic, regulatory or reputational consequences |
The appropriate intervals should ultimately be determined by MCMC.
Consider two functions.
A routine internal administrative process might tolerate disruption for several days.
By contrast, an MCMC function supporting coordination during a major nationwide telecommunications disruption may need to operate almost immediately.
Both functions may be organisationally important, but their BCM recovery priorities are fundamentally different.
Proposed Critical Business Functions for MCMC
Based on MCMC's publicly described responsibilities and the nature of its regulatory role, the following catalogue provides a proposed starting point for MCMC's BIA.
These functions should not be regarded as MCMC's formally approved CBFs. Their criticality, recovery requirements and ownership should be validated by MCMC through its internal BIA and management approval process.
|
Code |
Proposed Critical Business Function |
BCM Rationale |
|
CBF-1 |
Communications and Multimedia Regulatory Oversight |
Maintains MCMC's ability to perform priority regulatory oversight and address significant regulatory matters during disruption. |
|
CBF-2 |
Spectrum Management and Radiofrequency Coordination |
Supports management and regulatory oversight of spectrum-related activities and potentially time-sensitive interference or allocation matters. |
|
CBF-3 |
Licensing and Regulatory Authorisation Services |
Supports licensing and regulatory authorisation processes affecting communications and multimedia service providers. |
|
CBF-4 |
Consumer Complaint and Protection Services |
Maintains channels and processes for receiving, prioritising and addressing significant consumer complaints and issues. |
|
CBF-5 |
Communications Sector Incident Monitoring and Coordination |
Supports MCMC's ability to obtain situational information, coordinate appropriate regulatory actions and communicate during major sector disruptions. |
|
CBF-6 |
Regulatory Compliance Monitoring and Enforcement |
Maintains priority compliance and enforcement activities where delay could create unacceptable regulatory consequences. |
|
CBF-7 |
Critical Regulatory Information and Data Services |
Maintains availability, integrity and accessibility of information required to support priority regulatory functions and decisions. |
|
CBF-8 |
Critical Digital Regulatory Platforms and Online Services |
Supports priority digital platforms required by MCMC personnel, regulated entities and other authorised stakeholders. |
|
CBF-9 |
Stakeholder, Government and Crisis Communications |
Maintains MCMC's ability to communicate essential regulatory and incident information to government, industry, consumers, employees and other stakeholders. |
|
CBF-10 |
Critical ICT and Cybersecurity Services |
Provides the technology, connectivity, security and recovery capabilities upon which other MCMC CBFs depend. |
|
CBF-11 |
Communications Infrastructure Regulatory Coordination |
Supports priority regulatory coordination associated with communications infrastructure and relevant external stakeholders. |
|
CBF-12 |
Postal and Courier Regulatory Oversight |
Maintains priority regulatory responsibilities associated with postal and related regulated services where disruption could create unacceptable consequences. |
MCMC's licensing framework demonstrates the breadth of the regulatory environment, including network facilities, network services, application services and content application services. MCMC also operates stakeholder-facing technology such as CIPM, which involves MCMC, local authorities, Network Facilities Providers and State Economic Planning Units.
The proposed CBF catalogue therefore deliberately covers both external regulatory responsibilities and internal enabling capabilities.
Distinguishing CBFs from Supporting Resources
One common BCM problem is confusing a business function with the resource supporting the function.
For example:
Business function: Consumer Complaint and Protection Services
Supporting resources: Personnel, complaint-management applications, databases, telephones, internet connectivity, office facilities and third-party services.
Similarly:
Business function: Spectrum Management and Radiofrequency Coordination
Supporting resources: Specialist personnel, spectrum-management systems, monitoring equipment, databases, communications facilities and technical information.
This distinction is essential.
The objective of BCM is not simply to recover technology or facilities. It is to maintain or recover the business function.
The BIA must therefore begin with the activity that MCMC needs to perform and subsequently determine the resources required to perform it.
Identifying Dependencies for Each CBF
After confirming its CBFs, MCMC should map their dependencies.
A useful dependency model is:
People
↓
Processes
↓
Technology
↓
Information
↓
Facilities
↓
Suppliers and Third Parties
↓
Internal Dependencies
↓
External Dependencies
For example, the proposed CBF-4 Consumer Complaint and Protection Services might depend upon:
- trained complaint-handling personnel;
- complaint-management processes;
- complaint portals and applications;
- telecommunications and internet services;
- consumer and case information;
- escalation arrangements;
- regulated service providers;
- relevant internal technical or regulatory specialists; and
- communication channels.
MCMC's historical consumer-protection arrangements have included multiple complaint channels and complaint-management processes, illustrating how a stakeholder-facing function can depend upon multiple channels, personnel and systems.
The loss of any one dependency could reduce the function's operating capability even if the function itself has not completely failed.
Establishing Recovery Requirements
For each confirmed CBF, MCMC should establish appropriate recovery requirements.
These may include:
Maximum Tolerable Period of Disruption
The maximum duration after which continued disruption would result in unacceptable consequences.
Recovery Time Objective
The target timeframe for resuming the function following disruption.
Recovery Point Objective
Where data is involved, the point to which information must be recovered following loss or corruption.
Minimum Business Continuity Objective
The minimum acceptable capacity or level at which the function must operate during disruption.
For example, MCMC may determine that a stakeholder-facing function does not initially need to operate at 100% of normal capacity.
During the first phase of recovery, it may be sufficient to:
- accept urgent submissions;
- prioritise high-impact cases;
- provide essential stakeholder information;
- defer non-critical processing; and
- progressively restore normal service.
This is an important BCM principle:
Continuity does not necessarily mean restoring everything immediately. It means restoring the right activities, at the right capacity, within the required timeframe.
Example: Consumer Complaint and Protection Services
Consider the proposed:
CBF-4 – Consumer Complaint and Protection Services
MCMC has historically maintained consumer complaint arrangements addressing telecommunications and multimedia matters, including complaints associated with telecommunications, broadcasting, internet, postal and digital certification services.
Assume that the primary complaint-management platform becomes unavailable following a cyber incident.
The BIA should establish:
- how long complaint intake can be disrupted;
- which complaint categories require immediate attention;
- whether alternative intake channels can be activated;
- which personnel must remain available;
- what minimum information is required;
- how complaints can be recorded while the primary system is unavailable;
- how duplicate or lost cases will be prevented;
- how consumers will be informed;
- how regulated service providers will be contacted; and
- how manually captured information will subsequently be reconciled.
The continuity strategy might therefore provide:
Normal State
Online complaint services → case management → assessment → referral/escalation → resolution monitoring.
Disrupted State
Alternative intake channels → manual/alternate case recording → priority classification → urgent escalation → stakeholder communication → backlog reconciliation following system restoration.
The purpose is not merely to recover the application. It is to continue the priority outcome of the business function while the application is unavailable.
Example: Spectrum Management and Radiofrequency Coordination
Consider:
CBF-2 – Spectrum Management and Radiofrequency Coordination
A major disruption could affect access to systems, specialist personnel, monitoring capabilities or information supporting spectrum-related activities.
MCMC should determine:
- which spectrum activities are time-sensitive;
- which incidents require immediate regulatory attention;
- which technical specialists are essential;
- what information must remain accessible;
- which systems and monitoring capabilities are required;
- whether alternative technical procedures exist;
- which external stakeholders must be contacted; and
- what activities can temporarily be deferred.
This demonstrates why CBFs should subsequently be decomposed into critical activities and sub-processes.
Not every activity within a critical function necessarily requires the same recovery priority.
Example: Critical Digital Regulatory Platforms
MCMC's operations include digital systems supporting interactions between the Commission and external stakeholders.
For example, CIPM is described as a centralised web application involving users including local authorities, Network Facilities Providers, State Economic Planning Units and MCMC. (MCMC) MCMC also maintains the ReCPro register for certified proficient persons.
The existence of such systems demonstrates the need for the BIA to examine digital-service dependencies.
However, MCMC should avoid automatically declaring every system critical.
Instead, it should ask:
Which CBF does the system support?
What happens to that CBF when the system is unavailable?
How long can the business activity continue without it?
Is a workaround available?
What information must be recovered?
This approach ensures that technology recovery priorities are determined by business requirements, rather than technology teams independently determining system criticality.
Proposed CBF Prioritisation Model
Following the BIA, MCMC could assign recovery tiers.
|
Recovery Tier |
Description |
Illustrative BCM Treatment |
|
Tier 1 – Immediate / Mission Critical |
Disruption rapidly produces unacceptable consequences |
Highest recovery priority and strongest continuity arrangements |
|
Tier 2 – Critical |
Significant consequences develop within a short timeframe |
Rapid recovery required |
|
Tier 3 – Essential |
Function can tolerate a moderate period of disruption |
Recovery after Tier 1 and Tier 2 activities |
|
Tier 4 – Deferrable |
Function can be suspended temporarily without unacceptable consequences |
Restored after higher-priority activities |
The classification should be based on BIA results rather than management perception alone.
For example, seniority of the function owner should have no bearing on recovery priority.
A relatively small operational activity could receive Tier 1 status if its failure creates immediate unacceptable consequences, while a large administrative function might be classified Tier 3 or Tier 4 if it can tolerate a longer disruption.
Management Validation of Critical Business Functions
The BCM team should facilitate the identification process, but it should not independently make the final determination of organisational criticality.
CBF results should be reviewed by:
Business Function Owners
↓
BCM Coordinator / BCM Team
↓
Relevant Technology and Dependency Owners
↓
Risk / Governance Functions
↓
Senior Management
↓
Appropriate Management Authority
Management validation is important because CBF classification determines where MCMC will subsequently allocate continuity resources and recovery investment.
Approval should therefore confirm:
- the CBF;
- accountable function owner;
- maximum tolerable disruption;
- recovery priority;
- minimum operating requirement;
- critical dependencies;
- significant assumptions; and
- required continuity strategy.
Maintaining the CBF Catalogue
Criticality is not permanent.
MCMC's regulatory responsibilities, technologies, stakeholder expectations, operating arrangements and dependencies will continue to evolve.
The CBF catalogue should therefore be reviewed when there are significant changes involving:
- legislation or regulatory responsibilities;
- organisational restructuring;
- new or changed digital platforms;
- new regulatory services;
- technology transformation;
- outsourcing;
- new suppliers;
- office relocation;
- major incidents;
- significant cybersecurity developments;
- changes to government requirements; or
- lessons from exercises and actual disruptions.
A formal review should also occur at planned intervals as part of maintaining the BCMS.
This turns the CBF catalogue from a one-time project deliverable into a living BCM management tool.
From Critical Business Functions to BCM Strategies
Identification of CBFs is not the end of the BCM process.
It establishes the basis for the next question:
How will MCMC maintain these functions when their normal resources are unavailable?
For each CBF, MCMC should subsequently consider continuity strategies addressing:
Loss of People
Alternative personnel → cross-training → succession → remote working → workload prioritisation.
Loss of Premises
Remote working → alternate sites → relocation → distributed operations.
Loss of Technology
ICT disaster recovery → alternate systems → manual workaround → alternative communication channels.
Loss of Information
Backup → replication → protected records → alternative information sources.
Loss of Supplier
Alternative supplier → contractual continuity arrangements → insourcing → contingency inventory or capacity.
Loss of Communications
Alternative networks → mobile communications → emergency communications arrangements.
The connection is therefore:
CBF → Impact → Recovery Requirement → Dependencies → Vulnerabilities → Continuity Strategy → BC Plan → Exercise → Improvement
This chain ensures that MCMC's BCM arrangements are driven by what the organisation actually needs to continue.
Practical Output for MCMC
After this stage, MCMC should have an approved Critical Business Function Register.
An illustrative structure is:
|
Field |
Required Information |
|
CBF Code |
Unique reference |
|
CBF Name |
Name of critical function |
|
Function Owner |
Accountable owner |
|
Purpose |
Why the function is performed |
|
Stakeholders |
Parties dependent upon the function |
|
Impact of Disruption |
Consequences if unavailable |
|
MTPD |
Maximum tolerable period of disruption |
|
RTO |
Target recovery timeframe |
|
RPO |
Required data recovery point, where applicable |
|
Minimum Capacity |
Minimum acceptable operating level |
|
Critical People |
Personnel and competencies |
|
Critical Technology |
Applications and infrastructure |
|
Critical Information |
Data and records |
|
Critical Facilities |
Required locations/resources |
|
Critical Suppliers |
External dependencies |
|
Internal Dependencies |
Other MCMC functions required |
|
External Dependencies |
External organisations/services required |
|
Workaround |
Alternative method of operation |
|
Recovery Tier |
Prioritisation classification |
|
Approval |
Management validation |
|
Last Review |
Most recent validation date |
This register should become a key reference point for MCMC's BCM programme.
Identifying Critical Business Functions is one of the most important steps in establishing an effective Business Continuity Management System for the Malaysian Communications and Multimedia Commission.
The purpose is not to classify every important MCMC activity as critical. Rather, it is to determine which functions must be maintained or recovered within defined timeframes to prevent unacceptable consequences.
For MCMC, this assessment must reflect the organisation's distinctive role within Malaysia's communications and multimedia environment. Regulatory obligations, consumers, regulated entities, government stakeholders, digital services, telecommunications infrastructure and sector-wide dependencies should therefore form part of the criticality assessment.
This chapter has proposed an initial catalogue of twelve potential CBFs covering regulatory oversight, spectrum management, licensing, consumer protection, sector incident coordination, compliance and enforcement, regulatory information, digital platforms, stakeholder communications, ICT and cybersecurity, communications infrastructure coordination, and postal regulatory oversight.
These proposed functions should serve as inputs to MCMC's BIA rather than predetermined conclusions. Through the BIA, MCMC should validate each function, determine the consequences of disruption over time, establish maximum tolerable periods of disruption and recovery objectives, identify minimum operating requirements, map dependencies and obtain management approval.
The resulting CBF catalogue establishes the bridge between understanding the organisation and implementing BCM.
Once MCMC knows what must be protected and recovered first, it can make informed decisions concerning people, workplaces, technology, information, suppliers, alternative operating arrangements and recovery investment.
The fundamental principle for MCMC is therefore:
Do not start by asking which systems or departments should be recovered first. Start by identifying which organisational outcomes cannot be allowed to fail, determine the business functions that deliver those outcomes, and then establish what those functions require to continue.
This provides the evidence-based foundation for practical, defensible and ISO 22301-aligned business continuity planning across MCMC.
This chapter also creates a useful transition into eBook 2, Implementing Business Continuity Management for the Malaysian Communications and Multimedia Commission, because the proposed CBF catalogue can become the basis for detailed BIA, recovery requirements, continuity strategies and BC plan development.
| eBook 1: Understanding Your Organisation | |||||
| C1 | C2 [x] | C3 [x] | C4 [x] | C5 [x] | C6 [x] |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
| C7 [x] | C8 [x] | C9 [x] | C10 | C11 [x] | C12 [x] |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5].


![[BCM] [GEN] [Full Banner] Implementing Business Continuity Management](https://no-cache.hubspot.com/cta/default/3893111/7653b707-8a37-4e81-af7a-9982a8d67a64.png)

![[BCM] [GEN] Legal Disclaimer Banner](https://no-cache.hubspot.com/cta/default/3893111/d633fe26-3ef8-41e5-99ae-667e110827df.png)

![Banner [Summary] [BCM] [E1] [C10] Identifying Critical Business Functions](https://no-cache.hubspot.com/cta/default/3893111/0e59113c-d17a-48a8-8c28-bb1bcf487857.png)

![[BCM] [GEN] [3/4 Banner] Implementing Business Continuity Management](https://no-cache.hubspot.com/cta/default/3893111/3d7191cc-07cc-478a-9ca1-6f9c85593394.png)













![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





