A fundamental requirement of Business Continuity Management (BCM) is determining which organisational activities must be prioritised when normal operations are disrupted. For the Malaysian Communications and Multimedia Commission (MCMC), this requires identifying those business functions whose prolonged disruption could result in unacceptable regulatory, operational, stakeholder, financial, reputational or societal consequences.
Identifying Critical Business Functions (CBFs) is therefore not simply an exercise in listing important departments. It requires MCMC to understand how its regulatory mandate is delivered, assess the consequences of disruption over time, establish recovery priorities and identify the resources and dependencies required to maintain or restore priority activities.
This is particularly important because MCMC operates within Malaysia's highly interconnected communications and multimedia environment. Its responsibilities include regulatory activities involving licensing, competition and access, spectrum, numbering and electronic addressing, consumer protection and postal regulation.
MCMC also maintains technology-enabled services and registers. For example, its Register of Certified Proficient Persons provides information concerning certified radio operators and cabling providers, while the Communications Infrastructure Permit Management (CIPM) system is a centralised web application accessed by MCMC and external stakeholders.
Consequently, disruption to an MCMC function may have implications extending beyond the organisation itself. Regulated entities, consumers, government stakeholders and other parties may depend upon the continued availability of particular MCMC activities.
This chapter explains how MCMC can identify and prioritise its CBFs as part of an ISO 22301-aligned Business Continuity Management System (BCMS). It also proposes an initial catalogue of CBFs that can be validated through MCMC's formal Business Impact Analysis (BIA).
A Critical Business Function is an organisational function or activity that must be maintained or recovered within an acceptable timeframe following disruption because failure to do so could result in unacceptable consequences.
For MCMC, a business function should therefore not be classified as critical merely because it is important during normal operations.
The distinction is significant.
Many MCMC functions will be important. However, BCM requires the organisation to determine how quickly each function must be recovered and which functions must receive priority when resources are constrained during a major disruption.
For example, an administrative activity that can be suspended for several weeks without serious consequences may be important but would not necessarily receive the same recovery priority as an activity where a prolonged interruption could significantly affect MCMC's regulatory responsibilities or ability to respond to a serious communications-sector incident.
Criticality is therefore time-dependent.
The central question is:
At what point would the disruption of this function cause consequences that MCMC considers unacceptable?
ISO 22301 requires organisations to establish and maintain processes for analysing business impacts and assessing risks of disruption.
For MCMC, the BIA should provide the evidence necessary to:
The identification of CBFs should therefore be an outcome of the BIA rather than an assumption made before the BIA.
A sound implementation sequence is:
Understand MCMC's Mandate and Operations
↓
Identify Business Functions and Activities
↓
Assess the Impact of Their Disruption
↓
Determine How Impact Changes Over Time
↓
Establish Maximum Tolerable Periods of Disruption
↓
Determine Recovery Time Objectives
↓
Identify Resource and Dependency Requirements
↓
Prioritise the Functions
↓
Confirm Critical Business Functions
↓
Obtain Management Approval
This creates an evidence-based basis for BCM prioritisation.
The nature of MCMC's responsibilities should be considered when determining criticality.
MCMC's regulatory environment includes communications networks, telecommunications services, applications services and content applications services. Its licensing framework recognises Network Facilities Providers, Network Service Providers, Applications Service Providers and Content Applications Service Providers.
This means that MCMC's BCM considerations should extend beyond conventional internal impacts such as lost productivity.
When determining whether an activity is critical, MCMC should consider consequences affecting:
Could disruption prevent MCMC from performing a statutory or regulatory responsibility?
Could prolonged disruption adversely affect MCMC's ability to oversee or support an important part of Malaysia's communications and multimedia environment?
Could disruption impair MCMC's ability to protect consumers or handle serious communications and multimedia issues?
MCMC has historically maintained consumer complaint arrangements covering areas including telecommunications, broadcasting, internet, postal and digital certification services.
Could disruption prevent MCMC from providing information, coordination or regulatory support required by government or other relevant authorities?
Could disruption prevent licensees or other regulated parties from completing time-sensitive regulatory activities?
Could disruption result in loss, corruption, unavailability or unauthorised disclosure of critical regulatory information?
Could prolonged disruption significantly reduce stakeholder confidence in MCMC's ability to perform its responsibilities?
These considerations make MCMC's BIA different from that of a purely commercial organisation.
MCMC should establish consistent criteria for assessing all business functions.
An illustrative impact framework could include the following.
|
Impact Dimension |
Key Question for MCMC |
|
Statutory / Regulatory |
Would disruption prevent MCMC from fulfilling a material statutory or regulatory obligation? |
|
Sector Impact |
Could disruption materially affect MCMC's oversight of Malaysia's communications and multimedia sector? |
|
Consumer Impact |
Could consumers experience significant or escalating harm because the function is unavailable? |
|
Government / National Interest |
Could disruption affect government priorities, national communications interests or coordination requirements? |
|
Stakeholder Impact |
Would regulated entities or other stakeholders be unable to perform time-sensitive activities? |
|
Operational Impact |
Would disruption prevent other important MCMC functions from operating? |
|
Technology / Information |
Would critical systems, information or digital services become unavailable or unreliable? |
|
Financial Impact |
Could disruption create material financial consequences? |
|
Legal / Compliance |
Could MCMC fail to satisfy legal, contractual or compliance requirements? |
|
Reputational Impact |
Could prolonged disruption significantly damage stakeholder confidence in MCMC? |
MCMC should define thresholds for each category so that business functions can be evaluated consistently.
A function does not become critical solely because disruption has consequences. The speed at which those consequences become unacceptable is equally important.
MCMC should therefore evaluate impact over defined periods.
For example:
|
Duration of Disruption |
Illustrative Assessment |
|
0–4 hours |
Immediate operational consequences |
|
4–12 hours |
Short-term degradation |
|
12–24 hours |
Increasing operational and stakeholder impact |
|
1–3 days |
Significant regulatory or stakeholder consequences may develop |
|
3–7 days |
Serious accumulated impact |
|
More than 7 days |
Potentially unacceptable strategic, regulatory or reputational consequences |
The appropriate intervals should ultimately be determined by MCMC.
Consider two functions.
A routine internal administrative process might tolerate disruption for several days.
By contrast, an MCMC function supporting coordination during a major nationwide telecommunications disruption may need to operate almost immediately.
Both functions may be organisationally important, but their BCM recovery priorities are fundamentally different.
Based on MCMC's publicly described responsibilities and the nature of its regulatory role, the following catalogue provides a proposed starting point for MCMC's BIA.
These functions should not be regarded as MCMC's formally approved CBFs. Their criticality, recovery requirements and ownership should be validated by MCMC through its internal BIA and management approval process.
|
Code |
Proposed Critical Business Function |
BCM Rationale |
|
CBF-1 |
Communications and Multimedia Regulatory Oversight |
Maintains MCMC's ability to perform priority regulatory oversight and address significant regulatory matters during disruption. |
|
CBF-2 |
Spectrum Management and Radiofrequency Coordination |
Supports management and regulatory oversight of spectrum-related activities and potentially time-sensitive interference or allocation matters. |
|
CBF-3 |
Licensing and Regulatory Authorisation Services |
Supports licensing and regulatory authorisation processes affecting communications and multimedia service providers. |
|
CBF-4 |
Consumer Complaint and Protection Services |
Maintains channels and processes for receiving, prioritising and addressing significant consumer complaints and issues. |
|
CBF-5 |
Communications Sector Incident Monitoring and Coordination |
Supports MCMC's ability to obtain situational information, coordinate appropriate regulatory actions and communicate during major sector disruptions. |
|
CBF-6 |
Regulatory Compliance Monitoring and Enforcement |
Maintains priority compliance and enforcement activities where delay could create unacceptable regulatory consequences. |
|
CBF-7 |
Critical Regulatory Information and Data Services |
Maintains availability, integrity and accessibility of information required to support priority regulatory functions and decisions. |
|
CBF-8 |
Critical Digital Regulatory Platforms and Online Services |
Supports priority digital platforms required by MCMC personnel, regulated entities and other authorised stakeholders. |
|
CBF-9 |
Stakeholder, Government and Crisis Communications |
Maintains MCMC's ability to communicate essential regulatory and incident information to government, industry, consumers, employees and other stakeholders. |
|
CBF-10 |
Critical ICT and Cybersecurity Services |
Provides the technology, connectivity, security and recovery capabilities upon which other MCMC CBFs depend. |
|
CBF-11 |
Communications Infrastructure Regulatory Coordination |
Supports priority regulatory coordination associated with communications infrastructure and relevant external stakeholders. |
|
CBF-12 |
Postal and Courier Regulatory Oversight |
Maintains priority regulatory responsibilities associated with postal and related regulated services where disruption could create unacceptable consequences. |
MCMC's licensing framework demonstrates the breadth of the regulatory environment, including network facilities, network services, application services and content application services. MCMC also operates stakeholder-facing technology such as CIPM, which involves MCMC, local authorities, Network Facilities Providers and State Economic Planning Units.
The proposed CBF catalogue therefore deliberately covers both external regulatory responsibilities and internal enabling capabilities.
One common BCM problem is confusing a business function with the resource supporting the function.
For example:
Business function: Consumer Complaint and Protection Services
Supporting resources: Personnel, complaint-management applications, databases, telephones, internet connectivity, office facilities and third-party services.
Similarly:
Business function: Spectrum Management and Radiofrequency Coordination
Supporting resources: Specialist personnel, spectrum-management systems, monitoring equipment, databases, communications facilities and technical information.
This distinction is essential.
The objective of BCM is not simply to recover technology or facilities. It is to maintain or recover the business function.
The BIA must therefore begin with the activity that MCMC needs to perform and subsequently determine the resources required to perform it.
After confirming its CBFs, MCMC should map their dependencies.
A useful dependency model is:
People
↓
Processes
↓
Technology
↓
Information
↓
Facilities
↓
Suppliers and Third Parties
↓
Internal Dependencies
↓
External Dependencies
For example, the proposed CBF-4 Consumer Complaint and Protection Services might depend upon:
MCMC's historical consumer-protection arrangements have included multiple complaint channels and complaint-management processes, illustrating how a stakeholder-facing function can depend upon multiple channels, personnel and systems.
The loss of any one dependency could reduce the function's operating capability even if the function itself has not completely failed.
For each confirmed CBF, MCMC should establish appropriate recovery requirements.
These may include:
The maximum duration after which continued disruption would result in unacceptable consequences.
The target timeframe for resuming the function following disruption.
Where data is involved, the point to which information must be recovered following loss or corruption.
The minimum acceptable capacity or level at which the function must operate during disruption.
For example, MCMC may determine that a stakeholder-facing function does not initially need to operate at 100% of normal capacity.
During the first phase of recovery, it may be sufficient to:
This is an important BCM principle:
Continuity does not necessarily mean restoring everything immediately. It means restoring the right activities, at the right capacity, within the required timeframe.
Consider the proposed:
CBF-4 – Consumer Complaint and Protection Services
MCMC has historically maintained consumer complaint arrangements addressing telecommunications and multimedia matters, including complaints associated with telecommunications, broadcasting, internet, postal and digital certification services.
Assume that the primary complaint-management platform becomes unavailable following a cyber incident.
The BIA should establish:
The continuity strategy might therefore provide:
Online complaint services → case management → assessment → referral/escalation → resolution monitoring.
Alternative intake channels → manual/alternate case recording → priority classification → urgent escalation → stakeholder communication → backlog reconciliation following system restoration.
The purpose is not merely to recover the application. It is to continue the priority outcome of the business function while the application is unavailable.
Consider:
CBF-2 – Spectrum Management and Radiofrequency Coordination
A major disruption could affect access to systems, specialist personnel, monitoring capabilities or information supporting spectrum-related activities.
MCMC should determine:
This demonstrates why CBFs should subsequently be decomposed into critical activities and sub-processes.
Not every activity within a critical function necessarily requires the same recovery priority.
MCMC's operations include digital systems supporting interactions between the Commission and external stakeholders.
For example, CIPM is described as a centralised web application involving users including local authorities, Network Facilities Providers, State Economic Planning Units and MCMC. (MCMC) MCMC also maintains the ReCPro register for certified proficient persons.
The existence of such systems demonstrates the need for the BIA to examine digital-service dependencies.
However, MCMC should avoid automatically declaring every system critical.
Instead, it should ask:
Which CBF does the system support?
What happens to that CBF when the system is unavailable?
How long can the business activity continue without it?
Is a workaround available?
What information must be recovered?
This approach ensures that technology recovery priorities are determined by business requirements, rather than technology teams independently determining system criticality.
Following the BIA, MCMC could assign recovery tiers.
|
Recovery Tier |
Description |
Illustrative BCM Treatment |
|
Tier 1 – Immediate / Mission Critical |
Disruption rapidly produces unacceptable consequences |
Highest recovery priority and strongest continuity arrangements |
|
Tier 2 – Critical |
Significant consequences develop within a short timeframe |
Rapid recovery required |
|
Tier 3 – Essential |
Function can tolerate a moderate period of disruption |
Recovery after Tier 1 and Tier 2 activities |
|
Tier 4 – Deferrable |
Function can be suspended temporarily without unacceptable consequences |
Restored after higher-priority activities |
The classification should be based on BIA results rather than management perception alone.
For example, seniority of the function owner should have no bearing on recovery priority.
A relatively small operational activity could receive Tier 1 status if its failure creates immediate unacceptable consequences, while a large administrative function might be classified Tier 3 or Tier 4 if it can tolerate a longer disruption.
The BCM team should facilitate the identification process, but it should not independently make the final determination of organisational criticality.
CBF results should be reviewed by:
Business Function Owners
↓
BCM Coordinator / BCM Team
↓
Relevant Technology and Dependency Owners
↓
Risk / Governance Functions
↓
Senior Management
↓
Appropriate Management Authority
Management validation is important because CBF classification determines where MCMC will subsequently allocate continuity resources and recovery investment.
Approval should therefore confirm:
Criticality is not permanent.
MCMC's regulatory responsibilities, technologies, stakeholder expectations, operating arrangements and dependencies will continue to evolve.
The CBF catalogue should therefore be reviewed when there are significant changes involving:
A formal review should also occur at planned intervals as part of maintaining the BCMS.
This turns the CBF catalogue from a one-time project deliverable into a living BCM management tool.
Identification of CBFs is not the end of the BCM process.
It establishes the basis for the next question:
How will MCMC maintain these functions when their normal resources are unavailable?
For each CBF, MCMC should subsequently consider continuity strategies addressing:
Alternative personnel → cross-training → succession → remote working → workload prioritisation.
Remote working → alternate sites → relocation → distributed operations.
ICT disaster recovery → alternate systems → manual workaround → alternative communication channels.
Backup → replication → protected records → alternative information sources.
Alternative supplier → contractual continuity arrangements → insourcing → contingency inventory or capacity.
Alternative networks → mobile communications → emergency communications arrangements.
The connection is therefore:
CBF → Impact → Recovery Requirement → Dependencies → Vulnerabilities → Continuity Strategy → BC Plan → Exercise → Improvement
This chain ensures that MCMC's BCM arrangements are driven by what the organisation actually needs to continue.
After this stage, MCMC should have an approved Critical Business Function Register.
An illustrative structure is:
|
Field |
Required Information |
|
CBF Code |
Unique reference |
|
CBF Name |
Name of critical function |
|
Function Owner |
Accountable owner |
|
Purpose |
Why the function is performed |
|
Stakeholders |
Parties dependent upon the function |
|
Impact of Disruption |
Consequences if unavailable |
|
MTPD |
Maximum tolerable period of disruption |
|
RTO |
Target recovery timeframe |
|
RPO |
Required data recovery point, where applicable |
|
Minimum Capacity |
Minimum acceptable operating level |
|
Critical People |
Personnel and competencies |
|
Critical Technology |
Applications and infrastructure |
|
Critical Information |
Data and records |
|
Critical Facilities |
Required locations/resources |
|
Critical Suppliers |
External dependencies |
|
Internal Dependencies |
Other MCMC functions required |
|
External Dependencies |
External organisations/services required |
|
Workaround |
Alternative method of operation |
|
Recovery Tier |
Prioritisation classification |
|
Approval |
Management validation |
|
Last Review |
Most recent validation date |
This register should become a key reference point for MCMC's BCM programme.
Identifying Critical Business Functions is one of the most important steps in establishing an effective Business Continuity Management System for the Malaysian Communications and Multimedia Commission.
The purpose is not to classify every important MCMC activity as critical. Rather, it is to determine which functions must be maintained or recovered within defined timeframes to prevent unacceptable consequences.
For MCMC, this assessment must reflect the organisation's distinctive role within Malaysia's communications and multimedia environment. Regulatory obligations, consumers, regulated entities, government stakeholders, digital services, telecommunications infrastructure and sector-wide dependencies should therefore form part of the criticality assessment.
This chapter has proposed an initial catalogue of twelve potential CBFs covering regulatory oversight, spectrum management, licensing, consumer protection, sector incident coordination, compliance and enforcement, regulatory information, digital platforms, stakeholder communications, ICT and cybersecurity, communications infrastructure coordination, and postal regulatory oversight.
These proposed functions should serve as inputs to MCMC's BIA rather than predetermined conclusions. Through the BIA, MCMC should validate each function, determine the consequences of disruption over time, establish maximum tolerable periods of disruption and recovery objectives, identify minimum operating requirements, map dependencies and obtain management approval.
The resulting CBF catalogue establishes the bridge between understanding the organisation and implementing BCM.
Once MCMC knows what must be protected and recovered first, it can make informed decisions concerning people, workplaces, technology, information, suppliers, alternative operating arrangements and recovery investment.
The fundamental principle for MCMC is therefore:
Do not start by asking which systems or departments should be recovered first. Start by identifying which organisational outcomes cannot be allowed to fail, determine the business functions that deliver those outcomes, and then establish what those functions require to continue.
This provides the evidence-based foundation for practical, defensible and ISO 22301-aligned business continuity planning across MCMC.
This chapter also creates a useful transition into eBook 2, Implementing Business Continuity Management for the Malaysian Communications and Multimedia Commission, because the proposed CBF catalogue can become the basis for detailed BIA, recovery requirements, continuity strategies and BC plan development.
| eBook 1: Understanding Your Organisation | |||||
| C1 | C2 [x] | C3 [x] | C4 [x] | C5 [x] | C6 [x] |
| C7 [x] | C8 [x] | C9 [x] | C10 | C11 [x] | C12 [x] |
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||