Business Continuity Management (BCM) provides a structured framework for ensuring that an organisation can continue or recover its critical activities when disruptive incidents occur.
For the Malaysian Communications and Multimedia Commission (MCMC), BCM is particularly important because the organisation performs regulatory, supervisory, coordination, enforcement, consumer protection, spectrum management, licensing, digital regulatory and stakeholder communication functions that may become even more important during a national or sector-wide disruption.
A significant disruption affecting telecommunications, digital infrastructure, broadcasting, spectrum usage, regulatory platforms, MCMC facilities, key personnel, ICT systems or third-party services could impair MCMC's ability to maintain timely regulatory oversight. The organisation therefore requires a systematic BCM methodology that moves from programme initiation and risk understanding through impact analysis, strategy development, plan preparation, exercising and long-term programme governance.
This chapter presents a seven-phase BCM Planning Methodology for MCMC:
The methodology supports an ISO 22301-aligned Business Continuity Management System (BCMS) and should be implemented as an enterprise-wide management process rather than as a one-time documentation exercise.
For MCMC, the central implementation requirement is that BCM must preserve the organisation's capability to continue its priority regulatory and public-interest functions during disruptions affecting either MCMC itself or the broader Malaysian communications and multimedia sector.
The BCM Planning Methodology provides MCMC with a consistent process for determining:
The methodology should enable MCMC to move from simply identifying risks to establishing an operational capability for maintaining regulatory effectiveness during disruption.
A useful implementation sequence is:
Understand → Analyse → Prioritise → Prepare → Recover → Validate → Improve
A key BCM requirement for MCMC is that continuity arrangements must not focus only on internal organisational recovery.
MCMC should also be able to maintain regulatory oversight during a major disruption affecting the Malaysian communications and multimedia sector.
This creates a potentially challenging scenario:
Sector Disruption
Increased Regulatory Workload
Possible Disruption to MCMC's Own Resources
=
Need for Enhanced Regulatory Continuity Capability
For example, a major telecommunications outage, widespread cyber incident, digital platform failure, critical infrastructure disruption, or national emergency could result in simultaneous requirements for:
MCMC's BCM programme should therefore be designed for surge conditions, not merely for normal workloads operating from an alternative location.
This requirement should be embedded throughout all seven phases of the BCM Planning Methodology.
|
Phase |
BCM Planning Phase |
Primary Purpose |
Principal Output |
|
1 |
Project Management (PM) |
Establish BCM governance, scope, objectives, and implementation arrangements |
BCM project charter and implementation plan |
|
2 |
Risk Analysis and Review (RAR) |
Identify and assess threats that could disrupt MCMC |
Risk assessment and treatment priorities |
|
3 |
Business Impact Analysis (BIA) |
Determine critical functions, impacts, and recovery requirements |
Critical Business Function and recovery requirement catalogue |
|
4 |
Business Continuity Strategy (BCS) |
Determine how priority activities will continue and recover |
Approved continuity and recovery strategies |
|
5 |
Plan Development (PD) |
Convert strategies into executable procedures |
Business Continuity Plans and recovery procedures |
|
6 |
Testing and Exercising (TE) |
Validate plans, people and recovery capability |
Exercise results, findings and corrective actions |
|
7 |
Program Management (PgM) |
Maintain governance, readiness and continual improvement |
Sustained and improved BCMS |
The phases are sequential for initial implementation but should become cyclical once the programme is operational.
The Project Management phase establishes the foundation for BCM implementation.
The objective is to ensure that MCMC's BCM initiative has:
BCM implementation should not begin with individual departments independently drafting continuity plans.
The first requirement is to establish a coordinated enterprise framework.
MCMC should:
The project scope should include both frontline regulatory functions and enabling functions.
Potential areas may include:
BCM ownership should remain with the relevant business functions rather than being delegated entirely to ICT or corporate services.
The PM phase should produce:
Risk Analysis and Review identifies the threats that could disrupt MCMC's operations and evaluates whether existing controls are sufficient.
The focus should be on business interruption risk.
The principal question is:
What events or conditions could prevent MCMC from delivering its critical functions?
Threat Categories
MCMC should consider threats across multiple categories.
Denial of Access — Natural Events
Examples may include:
Denial of Access — Human-Caused Events
Examples may include:
Unavailability of People
Examples include:
Supply Chain Disruption
Potential examples include:
Equipment and ICT Disruption
Potential threats include:
Risk assessment should evaluate correlated disruption.
For example, a cyberattack affecting a major communications provider may simultaneously:
The assessment should therefore consider both the likelihood and consequences of MCMC being disrupted while sector demand increases.
RAR should produce:
The Business Impact Analysis determines which MCMC activities are critical and how quickly they must be recovered.
The BIA asks:
What happens if this function becomes unavailable, and how does the impact increase over time?
This phase provides the evidence for recovery prioritisation.
MCMC should:
Impact Areas for MCMC
The BIA should consider impacts including:
For regulatory functions, financial loss may not be the dominant criterion.
Loss of timely regulatory oversight may be more significant.
Example
For CBF-1 Communications and Multimedia Regulatory Oversight, disruption could impair:
The BIA should determine which of these activities must be available within hours and which could be deferred for longer periods.
The BIA should produce:
Once recovery requirements have been established, MCMC must determine how they will be achieved.
Business Continuity Strategy converts BIA requirements into practical continuity solutions.
The strategy phase should evaluate alternatives for:
People + Premises + Technology + Information + Suppliers + Communications + Governance
People Strategies
Potential strategies include:
Workplace Strategies
Possible arrangements include:
ICT Strategies
Potential solutions include:
Supplier Strategies
Options may include:
For critical regulatory functions, MCMC should establish continuity capability that does not depend exclusively on its normal digital workflow.
For example, where regulatory decision-making normally depends on electronic case management and approval systems, an approved controlled alternative should exist for:
Information Collection → Assessment → Decision Formulation → Approval → Formal Communication → Record Reconciliation
This allows regulatory action to continue during ICT disruption.
The BCS phase should produce:
The Plan Development phase translates approved strategies into practical procedures.
A Business Continuity Plan should tell personnel:
What happened? → Who needs to act? → What needs to be done? → In what order? → Using what resources? → Who must be informed?
Plans should therefore be operational rather than descriptive.
Plan Structure
MCMC's plans should generally include:
Recovery Procedures
For each CBF, recovery procedures should be divided into:
Pre-Crisis Preparedness
Actions undertaken before disruption.
During Disruption
Actions to stabilise and maintain minimum operations.
Recovery
Actions required to restore priority functions.
Restoration
Actions required to transition from temporary continuity arrangements back to normal or revised operations.
For CBF-1 Communications and Multimedia Regulatory Oversight, recovery procedures should establish how MCMC will maintain:
PD should produce:
Plans cannot be assumed to work merely because they are documented.
Testing and Exercising validates whether:
Exercise Programme
MCMC should develop a progressive programme including:
Discussion-Based Exercises
Used to validate understanding of roles and procedures.
Tabletop Exercises
Used to test decision-making and coordination.
Simulation Exercises
Used to reproduce realistic disruption conditions.
Technical Recovery Tests
Used to validate ICT recovery.
Alternate Site Tests
Used to confirm workspace arrangements.
Integrated Exercises
Used to test multiple teams, systems, and stakeholders simultaneously.
One important exercise should involve:
A major disruption affecting Malaysia's communications sector occurring simultaneously with degradation of MCMC's primary ICT and workplace capability.
The exercise should test whether MCMC can:
This would provide a realistic test of MCMC's dual role as both an organisation requiring continuity and a regulator required to operate during sector disruption.
TE should produce:
Program Management ensures that BCM remains effective after the initial implementation project is completed.
BCM should transition from:
Project → Capability → Management System
The PgM phase ensures continual readiness.
MCMC should:
BCM should be reviewed whenever significant changes occur, including:
The seven phases should not operate independently.
They are connected through a continuous information flow:
An effective implementation should include governance at several levels.
MCMC's BCM documentation should be structured hierarchically.
This structure provides traceability from policy through implementation and evidence of ongoing management.
MCMC should establish indicators that demonstrate whether the BCM programme is operationally effective.
Examples include:
However, compliance indicators alone are insufficient.
The ultimate question is:
Can MCMC continue its most important regulatory functions when normal operating arrangements fail?
That should remain the principal measure of BCM effectiveness.
The Business Continuity Management Planning Methodology provides MCMC with a structured approach for developing and maintaining an enterprise-wide continuity capability.
The seven phases:
Project Management → Risk Analysis and Review → Business Impact Analysis → Business Continuity Strategy → Plan Development → Testing and Exercising → Program Management
provide a complete implementation pathway from initial governance through continual improvement.
Each phase answers a different but interconnected question:
Project Management
How will MCMC organise and govern BCM implementation?
Risk Analysis and Review
What could disrupt MCMC?
Business Impact Analysis
What must recover, and how quickly?
Business Continuity Strategy
How will continuity and recovery requirements be achieved?
Plan Development
What should personnel actually do during disruption?
Testing and Exercising
Will the arrangements work when required?
Program Management
How will MCMC keep the capability current and effective?
For MCMC, the methodology has an additional strategic dimension. The organisation must be prepared not only for disruptions affecting its own premises, personnel, systems and suppliers, but also for events that simultaneously increase demand for regulatory oversight across Malaysia's communications and multimedia sector.
The BCM programme should therefore be built around the ability to maintain regulatory visibility, decision-making, stakeholder coordination, public-interest protection and operational control under degraded conditions.
The resulting BCM capability should enable MCMC to progress through a continuous resilience cycle:
By implementing the seven-phase methodology systematically and embedding it within organisational governance, MCMC can establish a practical and sustainable ISO 22301-aligned BCMS that supports service continuity, regulatory effectiveness and organisational resilience.
| eBook 2: Implementing Business Continuity Management | ||||
| C1 | C2 | C3 | C4 | C5 |
| C6 | C7 | C8 | C9 | C10 |
To learn more about the course and schedule, click the buttons below for BCM-300 Business Continuity Management Implementer [BCM-3] and BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||