. .

Managing Business Continuity Management for the
Malaysian Communications and Multimedia Commission (MCMC): A Practical Guide to
Organisational Resilience, Service Continuity, and Regulatory Excellence
BCM Ai Gen_with Cert Logo_6

[BCM] [MCMC] [E1] [C10] Identifying Critical Business Functions

[BCM] [GEN] [Full Banner] Implementing Business Continuity Management

A fundamental requirement of Business Continuity Management (BCM) is determining which organisational activities must be prioritised when normal operations are disrupted. For the Malaysian Communications and Multimedia Commission (MCMC), this requires identifying those business functions whose prolonged disruption could result in unacceptable regulatory, operational, stakeholder, financial, reputational or societal consequences.

Identifying Critical Business Functions (CBFs) is therefore not simply an exercise in listing important departments. It requires MCMC to understand how its regulatory mandate is delivered, assess the consequences of disruption over time, establish recovery priorities and identify the resources and dependencies required to maintain or restore priority activities.

This is particularly important because MCMC operates within Malaysia's highly interconnected communications and multimedia environment. Its responsibilities include regulatory activities involving licensing, competition and access, spectrum, numbering and electronic addressing, consumer protection and postal regulation.

MCMC also maintains technology-enabled services and registers. For example, its Register of Certified Proficient Persons provides information concerning certified radio operators and cabling providers, while the Communications Infrastructure Permit Management (CIPM) system is a centralised web application accessed by MCMC and external stakeholders.

New call-to-action

Moh Heng Goh
Business Continuity Management Certified Planner-Specialist-Expert
[BCM] [GEN] Legal Disclaimer Banner

eBook 1: Chapter 10

New call-to-action

Identifying Critical Business Functions


Introduction

New call-to-action

A fundamental requirement of Business Continuity Management (BCM) is determining which organisational activities must be prioritised when normal operations are disrupted. For the Malaysian Communications and Multimedia Commission (MCMC), this requires identifying those business functions whose prolonged disruption could result in unacceptable regulatory, operational, stakeholder, financial, reputational or societal consequences.

Identifying Critical Business Functions (CBFs) is therefore not simply an exercise in listing important departments. It requires MCMC to understand how its regulatory mandate is delivered, assess the consequences of disruption over time, establish recovery priorities and identify the resources and dependencies required to maintain or restore priority activities.

This is particularly important because MCMC operates within Malaysia's highly interconnected communications and multimedia environment. Its responsibilities include regulatory activities involving licensing, competition and access, spectrum, numbering and electronic addressing, consumer protection and postal regulation.

MCMC also maintains technology-enabled services and registers. For example, its Register of Certified Proficient Persons provides information concerning certified radio operators and cabling providers, while the Communications Infrastructure Permit Management (CIPM) system is a centralised web application accessed by MCMC and external stakeholders.

Consequently, disruption to an MCMC function may have implications extending beyond the organisation itself. Regulated entities, consumers, government stakeholders and other parties may depend upon the continued availability of particular MCMC activities.

This chapter explains how MCMC can identify and prioritise its CBFs as part of an ISO 22301-aligned Business Continuity Management System (BCMS). It also proposes an initial catalogue of CBFs that can be validated through MCMC's formal Business Impact Analysis (BIA).

What Is a Critical Business Function?

A Critical Business Function is an organisational function or activity that must be maintained or recovered within an acceptable timeframe following disruption because failure to do so could result in unacceptable consequences.

For MCMC, a business function should therefore not be classified as critical merely because it is important during normal operations.

The distinction is significant.

Many MCMC functions will be important. However, BCM requires the organisation to determine how quickly each function must be recovered and which functions must receive priority when resources are constrained during a major disruption.

For example, an administrative activity that can be suspended for several weeks without serious consequences may be important but would not necessarily receive the same recovery priority as an activity where a prolonged interruption could significantly affect MCMC's regulatory responsibilities or ability to respond to a serious communications-sector incident.

Criticality is therefore time-dependent.

The central question is:

At what point would the disruption of this function cause consequences that MCMC considers unacceptable?

ISO 22301 Context for Identifying CBFs

ISO 22301 requires organisations to establish and maintain processes for analysing business impacts and assessing risks of disruption.

For MCMC, the BIA should provide the evidence necessary to:

  • identify prioritised activities;
  • understand the consequences of disruption;
  • determine how impacts increase over time;
  • establish recovery priorities;
  • determine acceptable recovery timeframes;
  • identify minimum acceptable operating levels;
  • understand dependencies;
  • identify required resources; and
  • provide a basis for selecting business continuity strategies and solutions.

The identification of CBFs should therefore be an outcome of the BIA rather than an assumption made before the BIA.

A sound implementation sequence is:

 

Understand MCMC's Mandate and Operations

Identify Business Functions and Activities

Assess the Impact of Their Disruption

Determine How Impact Changes Over Time

Establish Maximum Tolerable Periods of Disruption

Determine Recovery Time Objectives

Identify Resource and Dependency Requirements

Prioritise the Functions

Confirm Critical Business Functions

Obtain Management Approval

 

This creates an evidence-based basis for BCM prioritisation.

MCMC's Regulatory Context and BCM Priorities

The nature of MCMC's responsibilities should be considered when determining criticality.

MCMC's regulatory environment includes communications networks, telecommunications services, applications services and content applications services. Its licensing framework recognises Network Facilities Providers, Network Service Providers, Applications Service Providers and Content Applications Service Providers. 

This means that MCMC's BCM considerations should extend beyond conventional internal impacts such as lost productivity.

When determining whether an activity is critical, MCMC should consider consequences affecting:

Regulatory Obligations

Could disruption prevent MCMC from performing a statutory or regulatory responsibility?

Communications and Multimedia Sector

Could prolonged disruption adversely affect MCMC's ability to oversee or support an important part of Malaysia's communications and multimedia environment?

Consumers

Could disruption impair MCMC's ability to protect consumers or handle serious communications and multimedia issues?

MCMC has historically maintained consumer complaint arrangements covering areas including telecommunications, broadcasting, internet, postal and digital certification services. 

Government and National Stakeholders

Could disruption prevent MCMC from providing information, coordination or regulatory support required by government or other relevant authorities?

Regulated Entities

Could disruption prevent licensees or other regulated parties from completing time-sensitive regulatory activities?

Information

Could disruption result in loss, corruption, unavailability or unauthorised disclosure of critical regulatory information?

Reputation and Confidence

Could prolonged disruption significantly reduce stakeholder confidence in MCMC's ability to perform its responsibilities?

These considerations make MCMC's BIA different from that of a purely commercial organisation.

Criteria for Determining Criticality

MCMC should establish consistent criteria for assessing all business functions.

An illustrative impact framework could include the following.

Impact Dimension

Key Question for MCMC

Statutory / Regulatory

Would disruption prevent MCMC from fulfilling a material statutory or regulatory obligation?

Sector Impact

Could disruption materially affect MCMC's oversight of Malaysia's communications and multimedia sector?

Consumer Impact

Could consumers experience significant or escalating harm because the function is unavailable?

Government / National Interest

Could disruption affect government priorities, national communications interests or coordination requirements?

Stakeholder Impact

Would regulated entities or other stakeholders be unable to perform time-sensitive activities?

Operational Impact

Would disruption prevent other important MCMC functions from operating?

Technology / Information

Would critical systems, information or digital services become unavailable or unreliable?

Financial Impact

Could disruption create material financial consequences?

Legal / Compliance

Could MCMC fail to satisfy legal, contractual or compliance requirements?

Reputational Impact

Could prolonged disruption significantly damage stakeholder confidence in MCMC?

MCMC should define thresholds for each category so that business functions can be evaluated consistently.

Assessing the Impact of Disruption Over Time

A function does not become critical solely because disruption has consequences. The speed at which those consequences become unacceptable is equally important.

MCMC should therefore evaluate impact over defined periods.

For example:

Duration of Disruption

Illustrative Assessment

0–4 hours

Immediate operational consequences

4–12 hours

Short-term degradation

12–24 hours

Increasing operational and stakeholder impact

1–3 days

Significant regulatory or stakeholder consequences may develop

3–7 days

Serious accumulated impact

More than 7 days

Potentially unacceptable strategic, regulatory or reputational consequences

The appropriate intervals should ultimately be determined by MCMC.

Consider two functions.

A routine internal administrative process might tolerate disruption for several days.

By contrast, an MCMC function supporting coordination during a major nationwide telecommunications disruption may need to operate almost immediately.

Both functions may be organisationally important, but their BCM recovery priorities are fundamentally different.

Proposed Critical Business Functions for MCMC

Based on MCMC's publicly described responsibilities and the nature of its regulatory role, the following catalogue provides a proposed starting point for MCMC's BIA.

These functions should not be regarded as MCMC's formally approved CBFs. Their criticality, recovery requirements and ownership should be validated by MCMC through its internal BIA and management approval process.

 

Code

Proposed Critical Business Function

BCM Rationale

CBF-1

Communications and Multimedia Regulatory Oversight

Maintains MCMC's ability to perform priority regulatory oversight and address significant regulatory matters during disruption.

CBF-2

Spectrum Management and Radiofrequency Coordination

Supports management and regulatory oversight of spectrum-related activities and potentially time-sensitive interference or allocation matters.

CBF-3

Licensing and Regulatory Authorisation Services

Supports licensing and regulatory authorisation processes affecting communications and multimedia service providers.

CBF-4

Consumer Complaint and Protection Services

Maintains channels and processes for receiving, prioritising and addressing significant consumer complaints and issues.

CBF-5

Communications Sector Incident Monitoring and Coordination

Supports MCMC's ability to obtain situational information, coordinate appropriate regulatory actions and communicate during major sector disruptions.

CBF-6

Regulatory Compliance Monitoring and Enforcement

Maintains priority compliance and enforcement activities where delay could create unacceptable regulatory consequences.

CBF-7

Critical Regulatory Information and Data Services

Maintains availability, integrity and accessibility of information required to support priority regulatory functions and decisions.

CBF-8

Critical Digital Regulatory Platforms and Online Services

Supports priority digital platforms required by MCMC personnel, regulated entities and other authorised stakeholders.

CBF-9

Stakeholder, Government and Crisis Communications

Maintains MCMC's ability to communicate essential regulatory and incident information to government, industry, consumers, employees and other stakeholders.

CBF-10

Critical ICT and Cybersecurity Services

Provides the technology, connectivity, security and recovery capabilities upon which other MCMC CBFs depend.

CBF-11

Communications Infrastructure Regulatory Coordination

Supports priority regulatory coordination associated with communications infrastructure and relevant external stakeholders.

CBF-12

Postal and Courier Regulatory Oversight

Maintains priority regulatory responsibilities associated with postal and related regulated services where disruption could create unacceptable consequences.

MCMC's licensing framework demonstrates the breadth of the regulatory environment, including network facilities, network services, application services and content application services. MCMC also operates stakeholder-facing technology such as CIPM, which involves MCMC, local authorities, Network Facilities Providers and State Economic Planning Units. 

The proposed CBF catalogue therefore deliberately covers both external regulatory responsibilities and internal enabling capabilities.

Distinguishing CBFs from Supporting Resources

One common BCM problem is confusing a business function with the resource supporting the function.

For example:

Business function: Consumer Complaint and Protection Services

Supporting resources: Personnel, complaint-management applications, databases, telephones, internet connectivity, office facilities and third-party services.

Similarly:

Business function: Spectrum Management and Radiofrequency Coordination

Supporting resources: Specialist personnel, spectrum-management systems, monitoring equipment, databases, communications facilities and technical information.

This distinction is essential.

The objective of BCM is not simply to recover technology or facilities. It is to maintain or recover the business function.

The BIA must therefore begin with the activity that MCMC needs to perform and subsequently determine the resources required to perform it.

Identifying Dependencies for Each CBF

After confirming its CBFs, MCMC should map their dependencies.

A useful dependency model is:

People

Processes

Technology

Information

Facilities

Suppliers and Third Parties

Internal Dependencies

External Dependencies

For example, the proposed CBF-4 Consumer Complaint and Protection Services might depend upon:

  • trained complaint-handling personnel;
  • complaint-management processes;
  • complaint portals and applications;
  • telecommunications and internet services;
  • consumer and case information;
  • escalation arrangements;
  • regulated service providers;
  • relevant internal technical or regulatory specialists; and
  • communication channels.

MCMC's historical consumer-protection arrangements have included multiple complaint channels and complaint-management processes, illustrating how a stakeholder-facing function can depend upon multiple channels, personnel and systems. 

The loss of any one dependency could reduce the function's operating capability even if the function itself has not completely failed.

Establishing Recovery Requirements

For each confirmed CBF, MCMC should establish appropriate recovery requirements.

These may include:

Maximum Tolerable Period of Disruption

The maximum duration after which continued disruption would result in unacceptable consequences.

Recovery Time Objective

The target timeframe for resuming the function following disruption.

Recovery Point Objective

Where data is involved, the point to which information must be recovered following loss or corruption.

Minimum Business Continuity Objective

The minimum acceptable capacity or level at which the function must operate during disruption.

For example, MCMC may determine that a stakeholder-facing function does not initially need to operate at 100% of normal capacity.

During the first phase of recovery, it may be sufficient to:

  • accept urgent submissions;
  • prioritise high-impact cases;
  • provide essential stakeholder information;
  • defer non-critical processing; and
  • progressively restore normal service.

This is an important BCM principle:

Continuity does not necessarily mean restoring everything immediately. It means restoring the right activities, at the right capacity, within the required timeframe.

Example: Consumer Complaint and Protection Services

Consider the proposed:

CBF-4 – Consumer Complaint and Protection Services

MCMC has historically maintained consumer complaint arrangements addressing telecommunications and multimedia matters, including complaints associated with telecommunications, broadcasting, internet, postal and digital certification services. 

Assume that the primary complaint-management platform becomes unavailable following a cyber incident.

The BIA should establish:

  • how long complaint intake can be disrupted;
  • which complaint categories require immediate attention;
  • whether alternative intake channels can be activated;
  • which personnel must remain available;
  • what minimum information is required;
  • how complaints can be recorded while the primary system is unavailable;
  • how duplicate or lost cases will be prevented;
  • how consumers will be informed;
  • how regulated service providers will be contacted; and
  • how manually captured information will subsequently be reconciled.

The continuity strategy might therefore provide:

Normal State

Online complaint services → case management → assessment → referral/escalation → resolution monitoring.

Disrupted State

Alternative intake channels → manual/alternate case recording → priority classification → urgent escalation → stakeholder communication → backlog reconciliation following system restoration.

The purpose is not merely to recover the application. It is to continue the priority outcome of the business function while the application is unavailable.

Example: Spectrum Management and Radiofrequency Coordination

Consider:

CBF-2 – Spectrum Management and Radiofrequency Coordination

A major disruption could affect access to systems, specialist personnel, monitoring capabilities or information supporting spectrum-related activities.

MCMC should determine:

  • which spectrum activities are time-sensitive;
  • which incidents require immediate regulatory attention;
  • which technical specialists are essential;
  • what information must remain accessible;
  • which systems and monitoring capabilities are required;
  • whether alternative technical procedures exist;
  • which external stakeholders must be contacted; and
  • what activities can temporarily be deferred.

This demonstrates why CBFs should subsequently be decomposed into critical activities and sub-processes.

Not every activity within a critical function necessarily requires the same recovery priority.

Example: Critical Digital Regulatory Platforms

MCMC's operations include digital systems supporting interactions between the Commission and external stakeholders.

For example, CIPM is described as a centralised web application involving users including local authorities, Network Facilities Providers, State Economic Planning Units and MCMC. (MCMC) MCMC also maintains the ReCPro register for certified proficient persons.

The existence of such systems demonstrates the need for the BIA to examine digital-service dependencies.

However, MCMC should avoid automatically declaring every system critical.

Instead, it should ask:

Which CBF does the system support?

What happens to that CBF when the system is unavailable?

How long can the business activity continue without it?

Is a workaround available?

What information must be recovered?

This approach ensures that technology recovery priorities are determined by business requirements, rather than technology teams independently determining system criticality.

Proposed CBF Prioritisation Model

Following the BIA, MCMC could assign recovery tiers.

 

Recovery Tier

Description

Illustrative BCM Treatment

Tier 1 – Immediate / Mission Critical

Disruption rapidly produces unacceptable consequences

Highest recovery priority and strongest continuity arrangements

Tier 2 – Critical

Significant consequences develop within a short timeframe

Rapid recovery required

Tier 3 – Essential

Function can tolerate a moderate period of disruption

Recovery after Tier 1 and Tier 2 activities

Tier 4 – Deferrable

Function can be suspended temporarily without unacceptable consequences

Restored after higher-priority activities

The classification should be based on BIA results rather than management perception alone.

For example, seniority of the function owner should have no bearing on recovery priority.

A relatively small operational activity could receive Tier 1 status if its failure creates immediate unacceptable consequences, while a large administrative function might be classified Tier 3 or Tier 4 if it can tolerate a longer disruption.

Management Validation of Critical Business Functions

The BCM team should facilitate the identification process, but it should not independently make the final determination of organisational criticality.

CBF results should be reviewed by:

Business Function Owners

BCM Coordinator / BCM Team

Relevant Technology and Dependency Owners

Risk / Governance Functions

Senior Management

Appropriate Management Authority

Management validation is important because CBF classification determines where MCMC will subsequently allocate continuity resources and recovery investment.

Approval should therefore confirm:

  • the CBF;
  • accountable function owner;
  • maximum tolerable disruption;
  • recovery priority;
  • minimum operating requirement;
  • critical dependencies;
  • significant assumptions; and
  • required continuity strategy.

Maintaining the CBF Catalogue

Criticality is not permanent.

MCMC's regulatory responsibilities, technologies, stakeholder expectations, operating arrangements and dependencies will continue to evolve.

The CBF catalogue should therefore be reviewed when there are significant changes involving:

  • legislation or regulatory responsibilities;
  • organisational restructuring;
  • new or changed digital platforms;
  • new regulatory services;
  • technology transformation;
  • outsourcing;
  • new suppliers;
  • office relocation;
  • major incidents;
  • significant cybersecurity developments;
  • changes to government requirements; or
  • lessons from exercises and actual disruptions.

A formal review should also occur at planned intervals as part of maintaining the BCMS.

This turns the CBF catalogue from a one-time project deliverable into a living BCM management tool.

From Critical Business Functions to BCM Strategies

Identification of CBFs is not the end of the BCM process.

It establishes the basis for the next question:

How will MCMC maintain these functions when their normal resources are unavailable?

For each CBF, MCMC should subsequently consider continuity strategies addressing:

Loss of People

Alternative personnel → cross-training → succession → remote working → workload prioritisation.

Loss of Premises

Remote working → alternate sites → relocation → distributed operations.

Loss of Technology

ICT disaster recovery → alternate systems → manual workaround → alternative communication channels.

Loss of Information

Backup → replication → protected records → alternative information sources.

Loss of Supplier

Alternative supplier → contractual continuity arrangements → insourcing → contingency inventory or capacity.

Loss of Communications

Alternative networks → mobile communications → emergency communications arrangements.

The connection is therefore:

CBF → Impact → Recovery Requirement → Dependencies → Vulnerabilities → Continuity Strategy → BC Plan → Exercise → Improvement

This chain ensures that MCMC's BCM arrangements are driven by what the organisation actually needs to continue.

Practical Output for MCMC

After this stage, MCMC should have an approved Critical Business Function Register.

An illustrative structure is:

 

Field

Required Information

CBF Code

Unique reference

CBF Name

Name of critical function

Function Owner

Accountable owner

Purpose

Why the function is performed

Stakeholders

Parties dependent upon the function

Impact of Disruption

Consequences if unavailable

MTPD

Maximum tolerable period of disruption

RTO

Target recovery timeframe

RPO

Required data recovery point, where applicable

Minimum Capacity

Minimum acceptable operating level

Critical People

Personnel and competencies

Critical Technology

Applications and infrastructure

Critical Information

Data and records

Critical Facilities

Required locations/resources

Critical Suppliers

External dependencies

Internal Dependencies

Other MCMC functions required

External Dependencies

External organisations/services required

Workaround

Alternative method of operation

Recovery Tier

Prioritisation classification

Approval

Management validation

Last Review

Most recent validation date

This register should become a key reference point for MCMC's BCM programme.

Banner [Summary] [BCM] [E1] [C10] Identifying Critical Business Functions

Identifying Critical Business Functions is one of the most important steps in establishing an effective Business Continuity Management System for the Malaysian Communications and Multimedia Commission.

The purpose is not to classify every important MCMC activity as critical. Rather, it is to determine which functions must be maintained or recovered within defined timeframes to prevent unacceptable consequences.

For MCMC, this assessment must reflect the organisation's distinctive role within Malaysia's communications and multimedia environment. Regulatory obligations, consumers, regulated entities, government stakeholders, digital services, telecommunications infrastructure and sector-wide dependencies should therefore form part of the criticality assessment.

This chapter has proposed an initial catalogue of twelve potential CBFs covering regulatory oversight, spectrum management, licensing, consumer protection, sector incident coordination, compliance and enforcement, regulatory information, digital platforms, stakeholder communications, ICT and cybersecurity, communications infrastructure coordination, and postal regulatory oversight.

These proposed functions should serve as inputs to MCMC's BIA rather than predetermined conclusions. Through the BIA, MCMC should validate each function, determine the consequences of disruption over time, establish maximum tolerable periods of disruption and recovery objectives, identify minimum operating requirements, map dependencies and obtain management approval.

The resulting CBF catalogue establishes the bridge between understanding the organisation and implementing BCM.

Once MCMC knows what must be protected and recovered first, it can make informed decisions concerning people, workplaces, technology, information, suppliers, alternative operating arrangements and recovery investment.

The fundamental principle for MCMC is therefore:

Do not start by asking which systems or departments should be recovered first. Start by identifying which organisational outcomes cannot be allowed to fail, determine the business functions that deliver those outcomes, and then establish what those functions require to continue.

This provides the evidence-based foundation for practical, defensible and ISO 22301-aligned business continuity planning across MCMC.

This chapter also creates a useful transition into eBook 2, Implementing Business Continuity Management for the Malaysian Communications and Multimedia Commission, because the proposed CBF catalogue can become the basis for detailed BIA, recovery requirements, continuity strategies and BC plan development.

 

BL-OR-3-5 Blog Under Construction

[BCM] [GEN] [3/4 Banner] Implementing Business Continuity Management

eBook 1: Understanding Your Organisation
C1 C2 [x] C3 [x] C4 [x] C5 [x] C6 [x]
New call-to-action New call-to-action New call-to-action New call-to-action New call-to-action New call-to-action
C7 [x] C8 [x] C9 [x] C10 C11 [x] C12 [x]
New call-to-action New call-to-action New call-to-action New call-to-action New call-to-action New call-to-action
 

 

More Information About Business Continuity Management Courses

To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5].

New call-to-action New call-to-action Register [BL-B-3]*
New call-to-action New call-to-action New call-to-action
FAQ [BL-B-3]

Please feel free to send us a note if you have any questions.

Email to Sales Team [BCM Institute]

 FAQ BL-B-5 BCM-5000
New call-to-action New call-to-action New call-to-action
 
 

Comments:

 

More Posts

New Call-to-action