eBook 2: Chapter 1
Business Continuity Management Planning Methodology for Malaysian Communications and Multimedia Commission
Introduction
Business Continuity Management (BCM) provides a structured framework for ensuring that an organisation can continue or recover its critical activities when disruptive incidents occur.
For the Malaysian Communications and Multimedia Commission (MCMC), BCM is particularly important because the organisation performs regulatory, supervisory, coordination, enforcement, consumer protection, spectrum management, licensing, digital regulatory and stakeholder communication functions that may become even more important during a national or sector-wide disruption.
A significant disruption affecting telecommunications, digital infrastructure, broadcasting, spectrum usage, regulatory platforms, MCMC facilities, key personnel, ICT systems or third-party services could impair MCMC's ability to maintain timely regulatory oversight. The organisation therefore requires a systematic BCM methodology that moves from programme initiation and risk understanding through impact analysis, strategy development, plan preparation, exercising and long-term programme governance.
This chapter presents a seven-phase BCM Planning Methodology for MCMC:

The methodology supports an ISO 22301-aligned Business Continuity Management System (BCMS) and should be implemented as an enterprise-wide management process rather than as a one-time documentation exercise.
For MCMC, the central implementation requirement is that BCM must preserve the organisation's capability to continue its priority regulatory and public-interest functions during disruptions affecting either MCMC itself or the broader Malaysian communications and multimedia sector.
Purpose of the BCM Planning Methodology
The BCM Planning Methodology provides MCMC with a consistent process for determining:
- what must be protected;
- what could disrupt critical activities;
- which functions must recover first;
- how quickly those functions must resume;
- what minimum level of service must be maintained;
- which resources and dependencies are required;
- what continuity and recovery strategies are appropriate;
- how recovery procedures should be documented;
- how readiness should be tested; and
- how BCM capability should be maintained and continually improved.
The methodology should enable MCMC to move from simply identifying risks to establishing an operational capability for maintaining regulatory effectiveness during disruption.
A useful implementation sequence is:
Understand → Analyse → Prioritise → Prepare → Recover → Validate → Improve
BCM Requirement Specific to MCMC
A key BCM requirement for MCMC is that continuity arrangements must not focus only on internal organisational recovery.
MCMC should also be able to maintain regulatory oversight during a major disruption affecting the Malaysian communications and multimedia sector.
This creates a potentially challenging scenario:
Sector Disruption
Increased Regulatory Workload
Possible Disruption to MCMC's Own Resources
=
Need for Enhanced Regulatory Continuity Capability
For example, a major telecommunications outage, widespread cyber incident, digital platform failure, critical infrastructure disruption, or national emergency could result in simultaneous requirements for:
- regulatory incident monitoring;
- coordination with regulated entities;
- cross-agency coordination;
- consumer and public-interest assessment;
- management reporting;
- regulatory decision-making;
- stakeholder communications; and
- corrective action monitoring.
MCMC's BCM programme should therefore be designed for surge conditions, not merely for normal workloads operating from an alternative location.
This requirement should be embedded throughout all seven phases of the BCM Planning Methodology.
Overview of the Seven-Phase BCM Planning Methodology
|
Phase |
BCM Planning Phase |
Primary Purpose |
Principal Output |
|
1 |
Project Management (PM) |
Establish BCM governance, scope, objectives, and implementation arrangements |
BCM project charter and implementation plan |
|
2 |
Risk Analysis and Review (RAR) |
Identify and assess threats that could disrupt MCMC |
Risk assessment and treatment priorities |
|
3 |
Business Impact Analysis (BIA) |
Determine critical functions, impacts, and recovery requirements |
Critical Business Function and recovery requirement catalogue |
|
4 |
Business Continuity Strategy (BCS) |
Determine how priority activities will continue and recover |
Approved continuity and recovery strategies |
|
5 |
Plan Development (PD) |
Convert strategies into executable procedures |
Business Continuity Plans and recovery procedures |
|
6 |
Testing and Exercising (TE) |
Validate plans, people and recovery capability |
Exercise results, findings and corrective actions |
|
7 |
Program Management (PgM) |
Maintain governance, readiness and continual improvement |
Sustained and improved BCMS |
The phases are sequential for initial implementation but should become cyclical once the programme is operational.
The Seven-Phase BCM Planning Methodology
Phase 1: Project Management (PM)
Purpose
The Project Management phase establishes the foundation for BCM implementation.
The objective is to ensure that MCMC's BCM initiative has:
- defined scope;
- management sponsorship;
- clear objectives;
- appropriate governance;
- sufficient resources;
- designated roles and responsibilities;
- implementation milestones; and
- documented deliverables.
BCM implementation should not begin with individual departments independently drafting continuity plans.
The first requirement is to establish a coordinated enterprise framework.
Key Activities
MCMC should:
- obtain senior management sponsorship;
- appoint an appropriate BCM programme owner;
- establish a BCM Steering Committee or equivalent governance arrangement;
- define the organisational scope of the BCMS;
- identify business units and Critical Business Functions within scope;
- establish the implementation methodology;
- allocate roles and responsibilities;
- establish a project schedule;
- define documentation standards;
- determine training requirements; and
- establish management reporting arrangements.
MCMC-Specific Considerations
The project scope should include both frontline regulatory functions and enabling functions.
Potential areas may include:
- communications and multimedia regulatory oversight;
- spectrum management;
- licensing and regulatory authorisation;
- consumer complaint and protection services;
- regulatory compliance and enforcement;
- incident monitoring and coordination;
- digital regulatory platforms;
- ICT and cybersecurity;
- stakeholder communications;
- human resources;
- facilities;
- finance; and
- other enterprise support services.
BCM ownership should remain with the relevant business functions rather than being delegated entirely to ICT or corporate services.
Key Deliverables
The PM phase should produce:
- BCM policy;
- BCM programme charter;
- BCMS scope;
- BCM governance structure;
- roles and responsibilities;
- implementation schedule;
- stakeholder register;
- communication plan;
- training plan; and
- management reporting framework.
Phase 2: Risk Analysis and Review (RAR)
Purpose
Risk Analysis and Review identifies the threats that could disrupt MCMC's operations and evaluates whether existing controls are sufficient.
The focus should be on business interruption risk.
The principal question is:
What events or conditions could prevent MCMC from delivering its critical functions?
Threat Categories
MCMC should consider threats across multiple categories.
Denial of Access — Natural Events
Examples may include:
- severe flooding;
- extreme weather;
- environmental incidents;
- hazardous conditions affecting premises; and
- regional infrastructure disruption.
Denial of Access — Human-Caused Events
Examples may include:
- fire;
- security incidents;
- civil disturbance;
- building safety issues;
- malicious acts; and
- nearby incidents restricting access.
Unavailability of People
Examples include:
- infectious disease;
- mass absenteeism;
- transportation disruption;
- loss of key personnel;
- skill shortages; and
- simultaneous unavailability of specialised personnel.
Supply Chain Disruption
Potential examples include:
- telecommunications service failure;
- outsourced service disruption;
- cloud service outage;
- critical equipment supplier failure;
- specialist contractor unavailability; and
- dependency on third-party data or services.
Equipment and ICT Disruption
Potential threats include:
- cyberattack;
- ransomware;
- system outage;
- network failure;
- data corruption;
- cloud service interruption;
- power failure; and
- telecommunications disruption.
MCMC-Specific Requirement
Risk assessment should evaluate correlated disruption.
For example, a cyberattack affecting a major communications provider may simultaneously:
- generate significant regulatory workload;
- increase stakeholder communications;
- require regulatory incident monitoring;
- create consumer impact;
- require cross-government coordination; and
- affect MCMC's own communications or information systems.
The assessment should therefore consider both the likelihood and consequences of MCMC being disrupted while sector demand increases.
Key Deliverables
RAR should produce:
- threat register;
- vulnerability assessment;
- existing control assessment;
- risk ratings;
- treatment decisions;
- additional mitigation measures;
- residual risk assessment; and
- risk monitoring requirements.
Phase 3: Business Impact Analysis (BIA)
Purpose
The Business Impact Analysis determines which MCMC activities are critical and how quickly they must be recovered.
The BIA asks:
What happens if this function becomes unavailable, and how does the impact increase over time?
This phase provides the evidence for recovery prioritisation.
Key BIA Activities
MCMC should:
- identify business functions;
- decompose them into Sub-Critical Business Functions where appropriate;
- identify function owners;
- assess consequences of disruption;
- assess impact over time;
- determine criticality;
- establish Maximum Tolerable Period of Disruption;
- establish Minimum Business Continuity Objectives;
- determine Recovery Time Objectives;
- determine Recovery Point Objectives where information recovery is relevant;
- identify minimum resource requirements;
- identify internal and external dependencies;
- identify vital records;
- identify critical ICT systems and applications; and
- establish recovery priorities.
Impact Areas for MCMC
The BIA should consider impacts including:
- regulatory impact;
- consumer impact;
- public-interest impact;
- legal and statutory impact;
- operational impact;
- government and stakeholder impact;
- financial impact;
- reputational impact;
- data and information impact; and
- impact on regulated entities.
For regulatory functions, financial loss may not be the dominant criterion.
Loss of timely regulatory oversight may be more significant.
Example
For CBF-1 Communications and Multimedia Regulatory Oversight, disruption could impair:
- issue intake;
- severity assessment;
- regulatory prioritisation;
- decision-making;
- coordination with regulated entities;
- cross-agency coordination;
- regulatory situation monitoring; and
- management reporting.
The BIA should determine which of these activities must be available within hours and which could be deferred for longer periods.
Key Deliverables
The BIA should produce:
- Critical Business Function catalogue;
- Sub-Critical Business Function catalogue;
- impact assessment;
- impact-over-time assessment;
- MTPD;
- MBCO;
- RTO;
- RPO where applicable;
- minimum resource requirements;
- dependency matrix;
- vital records register; and
- prioritised recovery sequence.
Phase 4: Business Continuity Strategy (BCS)
Purpose
Once recovery requirements have been established, MCMC must determine how they will be achieved.
Business Continuity Strategy converts BIA requirements into practical continuity solutions.
The strategy phase should evaluate alternatives for:
People + Premises + Technology + Information + Suppliers + Communications + Governance
People Strategies
Potential strategies include:
- cross-training;
- succession planning;
- alternate personnel;
- split teams;
- remote working;
- mutual support between offices;
- redeployment;
- minimum staffing arrangements; and
- specialist backup.
Workplace Strategies
Possible arrangements include:
- alternate MCMC facilities;
- remote working;
- dedicated recovery locations;
- geographically separated operating teams;
- shared government facilities where appropriate; and
- temporary workspace arrangements.
ICT Strategies
Potential solutions include:
- resilient infrastructure;
- system redundancy;
- disaster recovery facilities;
- cloud resilience;
- backup connectivity;
- data replication;
- alternate communications channels;
- cyber recovery capability; and
- manual workarounds.
Supplier Strategies
Options may include:
- alternative suppliers;
- multiple-source arrangements;
- contractual continuity requirements;
- service-level agreements;
- inventory buffers;
- alternative logistics; and
- supplier continuity assurance.
MCMC-Specific Strategy Requirement
For critical regulatory functions, MCMC should establish continuity capability that does not depend exclusively on its normal digital workflow.
For example, where regulatory decision-making normally depends on electronic case management and approval systems, an approved controlled alternative should exist for:
Information Collection → Assessment → Decision Formulation → Approval → Formal Communication → Record Reconciliation
This allows regulatory action to continue during ICT disruption.
Key Deliverables
The BCS phase should produce:
- strategy option assessments;
- cost-benefit evaluation;
- selected strategies;
- management approvals;
- implementation plans;
- resource requirements; and
- strategy implementation schedules.
Phase 5: Plan Development (PD)
Purpose
The Plan Development phase translates approved strategies into practical procedures.
A Business Continuity Plan should tell personnel:
What happened? → Who needs to act? → What needs to be done? → In what order? → Using what resources? → Who must be informed?
Plans should therefore be operational rather than descriptive.
Plan Structure
MCMC's plans should generally include:
- purpose and scope;
- activation criteria;
- roles and responsibilities;
- notification procedures;
- escalation arrangements;
- immediate actions;
- recovery procedures;
- alternate workplace arrangements;
- manual workarounds;
- communications procedures;
- ICT dependencies;
- supplier coordination;
- regulatory stakeholder coordination;
- emergency contacts;
- vital records;
- recovery checklists;
- action logs; and
- return-to-normal procedures.
Recovery Procedures
For each CBF, recovery procedures should be divided into:
Pre-Crisis Preparedness
Actions undertaken before disruption.
During Disruption
Actions to stabilise and maintain minimum operations.
Recovery
Actions required to restore priority functions.
Restoration
Actions required to transition from temporary continuity arrangements back to normal or revised operations.
MCMC-Specific Example
For CBF-1 Communications and Multimedia Regulatory Oversight, recovery procedures should establish how MCMC will maintain:
- regulatory issue intake;
- severity assessment;
- regulatory prioritisation;
- decision approval;
- regulated entity coordination;
- cross-agency coordination;
- situation monitoring;
- management reporting; and
- regulatory recordkeeping.
Key Deliverables
PD should produce:
- enterprise BCP;
- CBF recovery procedures;
- Crisis Management interface procedures;
- ICT disaster recovery plans;
- communication procedures;
- manual workaround procedures;
- call trees and emergency contacts;
- recovery checklists; and
- restoration procedures.
Phase 6: Testing and Exercising (TE)
Purpose
Plans cannot be assumed to work merely because they are documented.
Testing and Exercising validates whether:
- people understand their responsibilities;
- recovery strategies work;
- systems can be recovered;
- communications operate;
- decisions can be made;
- suppliers respond;
- alternative arrangements are practical; and
- recovery requirements can be achieved.
Exercise Programme
MCMC should develop a progressive programme including:
Discussion-Based Exercises
Used to validate understanding of roles and procedures.
Tabletop Exercises
Used to test decision-making and coordination.
Simulation Exercises
Used to reproduce realistic disruption conditions.
Technical Recovery Tests
Used to validate ICT recovery.
Alternate Site Tests
Used to confirm workspace arrangements.
Integrated Exercises
Used to test multiple teams, systems, and stakeholders simultaneously.
MCMC-Specific Exercise Scenario
One important exercise should involve:
A major disruption affecting Malaysia's communications sector occurring simultaneously with degradation of MCMC's primary ICT and workplace capability.
The exercise should test whether MCMC can:
- detect and assess the sector event;
- activate continuity arrangements;
- prioritise regulatory matters;
- operate using alternate communications;
- coordinate with regulated entities;
- coordinate with government stakeholders;
- make regulatory decisions;
- communicate authorised directions;
- maintain situation monitoring; and
- sustain regulatory records.
This would provide a realistic test of MCMC's dual role as both an organisation requiring continuity and a regulator required to operate during sector disruption.
Key Deliverables
TE should produce:
- annual exercise programme;
- exercise objectives;
- exercise scenarios;
- evaluation criteria;
- exercise reports;
- lessons identified;
- corrective action plans;
- accountable action owners; and
- retest requirements.
Phase 7: Programme Management (PgM)
Purpose
Program Management ensures that BCM remains effective after the initial implementation project is completed.
BCM should transition from:
Project → Capability → Management System
The PgM phase ensures continual readiness.
Key Activities
MCMC should:
- maintain BCM governance;
- review the BCM policy;
- update BIA information;
- reassess risks;
- maintain continuity strategies;
- update plans;
- conduct exercises;
- maintain staff awareness;
- review supplier continuity;
- monitor corrective actions;
- perform internal reviews;
- support management review;
- integrate BCM with organisational change; and
- continually improve the BCMS.
Change Management
BCM should be reviewed whenever significant changes occur, including:
- organisational restructuring;
- new regulatory responsibilities;
- major technology implementation;
- office relocation;
- new suppliers;
- changes to telecommunications infrastructure dependencies;
- new digital regulatory platforms;
- significant incidents;
- legislative change; or
- changes to the Malaysian communications and multimedia environment.
Integration Across the Seven Phases
The seven phases should not operate independently.
They are connected through a continuous information flow:

BCM Governance for MCMC
An effective implementation should include governance at several levels.

Documentation Framework
MCMC's BCM documentation should be structured hierarchically.

This structure provides traceability from policy through implementation and evidence of ongoing management.
Measuring BCM Effectiveness
MCMC should establish indicators that demonstrate whether the BCM programme is operationally effective.
Examples include:

However, compliance indicators alone are insufficient.
The ultimate question is:
Can MCMC continue its most important regulatory functions when normal operating arrangements fail?
That should remain the principal measure of BCM effectiveness.
The Business Continuity Management Planning Methodology provides MCMC with a structured approach for developing and maintaining an enterprise-wide continuity capability.
The seven phases:
Project Management → Risk Analysis and Review → Business Impact Analysis → Business Continuity Strategy → Plan Development → Testing and Exercising → Program Management
provide a complete implementation pathway from initial governance through continual improvement.
Each phase answers a different but interconnected question:
Project Management
How will MCMC organise and govern BCM implementation?
Risk Analysis and Review
What could disrupt MCMC?
Business Impact Analysis
What must recover, and how quickly?
Business Continuity Strategy
How will continuity and recovery requirements be achieved?
Plan Development
What should personnel actually do during disruption?
Testing and Exercising
Will the arrangements work when required?
Program Management
How will MCMC keep the capability current and effective?
For MCMC, the methodology has an additional strategic dimension. The organisation must be prepared not only for disruptions affecting its own premises, personnel, systems and suppliers, but also for events that simultaneously increase demand for regulatory oversight across Malaysia's communications and multimedia sector.
The BCM programme should therefore be built around the ability to maintain regulatory visibility, decision-making, stakeholder coordination, public-interest protection and operational control under degraded conditions.
The resulting BCM capability should enable MCMC to progress through a continuous resilience cycle:

By implementing the seven-phase methodology systematically and embedding it within organisational governance, MCMC can establish a practical and sustainable ISO 22301-aligned BCMS that supports service continuity, regulatory effectiveness and organisational resilience.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
![]() |
![]() |
![]() |
![]() |
![]() |
| C6 | C7 | C8 | C9 | C10 |
![]() |
![]() |
![]() |
![]() |
![]() |
More Information About Business Continuity Management Courses
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5].


![[BCM] [MCMC] [Full Banner] Managing Business Continuity Management for the MCMC](https://no-cache.hubspot.com/cta/default/3893111/216f8c6a-2cf1-4905-b446-83def1e4b034.png)


![x eBook Cover [BCM] [GEN] [E2] [2D]](https://no-cache.hubspot.com/cta/default/3893111/ebd16725-1ea7-4e0e-b693-57fc9beac049.png)
![[BCM] [MCMC] [E2] [C1] Business Continuity Management Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/6da23000-7b52-4ed3-9c1f-1787ac503a13.png)






![x [Banner] [Summing] [OR] [E2] [C1] Overview of Operational Resilience Planning Methodology](https://no-cache.hubspot.com/cta/default/3893111/0c551e82-cf06-432c-8498-1d3c9bb2dece.png)

![[BCM] [MCMC] [3/4 Banner] Managing Business Continuity Management for the MCMC](https://no-cache.hubspot.com/cta/default/3893111/4b71120e-0476-483b-9fdf-94c0e229490f.png)












![Register [BL-B-3]*](https://no-cache.hubspot.com/cta/default/3893111/ac6cf073-4cdd-4541-91ed-889f731d5076.png)



![FAQ [BL-B-3]](https://no-cache.hubspot.com/cta/default/3893111/b3824ba1-7aa1-4eb6-bef8-94f57121c5ae.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)





