This eBook, Starting Your BCM Implementation for the Malaysian Communications and Multimedia Commission, is the third publication in the three-part eBook series:
Managing Business Continuity Management for the Malaysian Communications and Multimedia Commission (MCMC): A Practical Guide to Organisational Resilience, Service Continuity, and Regulatory Excellence
The three eBooks are designed to work together:
eBook 1 and eBook 2 provide the pre-reading, contextual understanding, methodology, and implementation guidance needed before the organisation begins completing the detailed BCM templates. This third eBook moves from understanding and preparation into hands-on implementation.
Its purpose is to help MCMC prepare, update, or strengthen the working documentation required for a Business Continuity Management project using a structured BCM planning methodology aligned, where applicable, with the principles of ISO 22301.
The emphasis in this eBook is practical. It is not intended merely to explain BCM concepts. Instead, it provides a structured implementation pathway through the major analytical and planning phases of a BCM project and shows how the outputs from each phase connect to the next.
The implementation sequence is:
Risk Analysis and Review
→ Business Impact Analysis
→ Business Continuity Strategy
→ Business Continuity Plan Development
Each phase produces specific outputs that should be reviewed, validated, and approved by the appropriate business, technical, and management stakeholders.
The primary purpose of this eBook is to provide MCMC with a practical implementation reference for preparing or updating the documentation required during a BCM project.
It is intended to support organisations that are either:
Unlike an introductory BCM publication, this eBook drills down into the specific worksheets, templates, analyses, and planning outputs required during implementation.
The central implementation logic is:
Understand the Organisation
→ Identify Threats
→ Determine What Is Critical
→ Assess Impact Over Time
→ Establish Recovery Requirements
→ Select Recovery Strategies
→ Determine Minimum Resources
→ Develop Business Continuity Procedures
→ Exercise and Improve
The result should be a set of traceable BCM documents in which the rationale for each recovery requirement can be linked back to an identified business need.
This eBook should be read together with the first two publications in the series.
The first eBook establishes the organisational context required before detailed BCM analysis begins.
It helps establish an understanding of:
This context is essential because BCM should not begin with systems or recovery facilities. It should begin with an understanding of what the organisation must continue to achieve during disruption.
The second eBook establishes the BCM implementation approach and explains how the programme should be organised, governed, and executed.
It provides the methodology needed to move from organisational understanding into structured BCM analysis and planning.
This third eBook is the working implementation guide.
It takes the organisation into the detailed completion of:
RAR → BIA → BCS → PD
The first two eBooks, therefore, answer:
What should MCMC understand, and how should the BCM project be organised?
The third eBook answers:
What must MCMC now analyse, document, decide, and develop?
The BCM implementation covered in this eBook follows four principal phases:
The Risk Analysis and Review phase examines threats capable of disrupting MCMC and the controls available to manage those threats.
It provides an understanding of the organisation's disruption exposure before recovery requirements and continuity strategies are finalised.
The BIA determines which activities are critical, the consequences of their disruption, how quickly they must be recovered, and the resources and dependencies needed to support them.
This phase establishes the business requirements that should subsequently drive continuity and technology recovery decisions.
The BCS phase converts the BIA requirements and risk findings into practical solutions for reducing disruption exposure and recovering affected activities.
It determines how MCMC intends to continue priority regulatory activities when normal resources are unavailable.
Plan Development translates approved recovery strategies into actionable procedures.
It answers:
Who does what, when, where, using which resources, and through which escalation and communication arrangements when disruption actually occurs?
The Risk Analysis and Review phase begins by identifying credible threats and evaluating the organisation's exposure to them.
Three principal templates are completed.
The first template identifies the specific threats capable of disrupting MCMC.
Threats may arise from areas such as:
The objective is to establish a sufficiently comprehensive threat register before attempting to determine which risks warrant further treatment.
The second template examines how the identified threats are presently managed.
It considers:
A control should not be regarded as effective merely because it exists. Its ownership, reliability, maintenance, testing, and actual effectiveness should also be considered.
The third template evaluates the consequences and likelihood of each threat after considering existing controls.
The assessment normally considers impacts across several dimensions, including:
The relationship can be represented as:
Threat
→ Existing Controls
→ Current Exposure
→ Impact
→ Likelihood
→ Risk Rating
→ Mitigation Priority
The output helps determine where additional mitigation, recovery planning or management attention is required.
The Business Impact Analysis is the central analytical phase of BCM.
The BIA should not begin by asking which systems should be recovered first. Instead, it should determine:
Which business functions must continue or recover first, and what do those functions require to operate?
For each Critical Business Function, MCMC should complete the following seven components.
This establishes the broader organisational continuity requirement.
The Corporate Minimum Business Continuity Objective (MBCO) defines the minimum level of products, services, or organisational capability that should be maintained during significant disruption.
It provides top-down direction before business units determine their individual recovery requirements.
Each Critical Business Function is decomposed into the business activities or Sub-Critical Business Functions that support it.
For each activity, the analysis should establish the minimum level that must be maintained during disruption.
This creates the connection:
Corporate MBCO
→ Critical Business Function
→ Sub-Critical Business Function
→ BU MBCO
This component assesses the consequences of disruption to each business activity across relevant impact dimensions.
It establishes why the activity matters and what consequences arise when it cannot be performed.
This component assesses how disruption consequences escalate with time.
It supports the determination of:
The principle is:
Longer Disruption → Increasing Consequences → Unacceptable Impact
The RTO should normally fall before the MTPD.
Once the Business RTO has been established, the organisation can determine which systems and applications are required to support recovery.
The correct sequence is:
Business Requirement
→ Business RTO
→ Required Application
→ System RTO
→ Data Requirement
→ RPO
This ensures technology recovery priorities are driven by business need rather than by technical preference.
This identifies the internal and external relationships upon which recovery depends.
Examples include:
The key question is:
What else must be available before this business function can recover successfully?
The final BIA component identifies the minimum information and records required to continue the business activity and demonstrate regulatory accountability.
Vital records may include:
The objective is not to classify every organisational document as vital. It is to identify the information without which the Critical Business Function cannot operate or demonstrate accountability.
The proposed Critical Business Functions represent the principal regulatory and supporting outcomes that should be subjected to a detailed BIA.
The list marks the beginning of the BIA phase and should be inserted into the working BCM report for management validation.
|
CBF Code |
Critical Business Function |
|
CBF-1 |
Communications and Multimedia Regulatory Oversight |
|
CBF-2 |
Spectrum Management and Radiofrequency Coordination |
|
CBF-3 |
Licensing and Regulatory Authorisation Services |
|
CBF-4 |
Consumer Complaint and Protection Services |
|
CBF-5 |
Communications Sector Incident Monitoring and Coordination |
|
CBF-6 |
Regulatory Compliance Monitoring and Enforcement |
|
CBF-7 |
Critical Regulatory Information and Data Services |
|
CBF-8 |
Critical Digital Regulatory Platforms and Online Services |
|
CBF-9 |
Stakeholder, Government, and Crisis Communications |
|
CBF-10 |
Critical ICT and Cybersecurity Services |
|
CBF-11 |
Communications Infrastructure Regulatory Coordination |
|
CBF-12 |
Postal and Courier Regulatory Oversight |
The term Critical Business Function should not be interpreted as meaning that every component of the function requires an identical recovery priority.
Each CBF should subsequently be decomposed into its Sub-Critical Business Functions and assessed individually.
The correct progression is:
Organisational Mandate
→ Products and Services
→ Critical Business Functions
→ Sub-Critical Business Functions
→ Impact Analysis
→ Recovery Requirements
This prevents recovery priorities from being assigned only at the department or system level.
The list above should also be regarded as subject to organisational validation. MCMC's management and relevant business owners should confirm that the proposed CBFs accurately represent those functions whose disruption could materially affect statutory, regulatory, public-interest, or operational outcomes.
Once the Risk Assessment and BIA have established what threatens the organisation and what must be recovered, the Business Continuity Strategy phase determines how continuity will be achieved.
Three principal templates are developed.
Mitigation addresses risks and control weaknesses identified through the RAR.
Typical strategies may include:
The purpose is to reduce the probability or consequences of disruption before it becomes necessary to invoke full recovery arrangements.
Recovery strategies determine how each critical activity will resume within its required RTO.
Potential strategies include:
The strategy selected should be justified according to the BIA requirement.
The decision logic is:
Business RTO
= Selected Recovery Strategy
A recovery strategy is incomplete unless the resources required to implement it are identified.
For each Sub-Critical Business Function, the organisation should determine the minimum resources needed during disruption, including:
The important distinction is between:
Normal Operating Resources
and
Minimum Resources Required to Achieve the BU MBCO
The continuity requirement is not necessarily to recreate the full normal operating environment immediately.
Once the Business Continuity Strategies have been selected, they must be converted into executable procedures.
This is the purpose of the Plan Development phase.
Detailed Business Continuity Plan procedures should be developed around the specific business processes supporting each Critical Business Function.
The plans should provide sufficient instruction to enable designated personnel to respond when normal operating arrangements are unavailable.
Typical procedural areas include:
Activation
→ Initial Assessment
→ Escalation
→ Staff Notification
→ Recovery Team Mobilisation
→ Alternate Working
→ Manual Workaround
→ Technology Recovery
→ Stakeholder Communications
→ Priority Processing
→ Backlog Management
→ Return to Normal Operations
→ Post-Incident Review
The procedures should be sufficiently specific to support action but flexible enough to accommodate different disruption scenarios.
A Business Continuity Plan should not become a lengthy description of BCM theory. Its primary value is operational:
Can the designated team use the plan to restore the required business capability within the approved RTO?
One of the most important objectives of this eBook is to maintain traceability across the entire BCM planning process.
For example:
Risk Assessment identifies:
Telecommunications Failure.
BIA identifies:
Regulatory Incident Situation Monitoring requires recovery within one hour.
BIA dependency analysis identifies:
Telecommunications and secure communications are essential resources.
BCS determines:
Diverse communications and alternative channels are required.
Plan Development defines:
How personnel activate the alternate communication method when the primary service fails.
The full traceability chain is therefore:
Threat
→ Critical Business Function
→ Business Impact
→ MTPD
→ RTO
→ BU MBCO
→ Dependencies
→ Recovery Strategy
→ Minimum Resources
→ BCP Procedure
→ Exercise
→ Improvement
This traceability is fundamental because it allows management, auditors and BCM practitioners to understand why each continuity strategy and recovery requirement exists.
This third eBook is intended to operate not only as guidance but also as a structured compilation of BCM project submissions.
During implementation, the organisation progressively completes and validates the templates associated with:
The result is a working implementation record showing how the BCM programme has progressed from analysis into recovery planning.
It may therefore be used to support:
The document should remain a living implementation guide. Outputs should be revised when the organisation changes, new systems are introduced, suppliers change, Critical Business Functions are redefined, incidents occur, or exercises identify weaknesses.
This eBook is also provided as part of a value-added and complementary implementation service for organisations seeking to implement or upgrade their BCM programmes while participating in BCM Institute certification or competency-based training.
The training-led implementation approach is intended to bridge the gap between learning BCM concepts and actually applying them within the organisation.
A conventional training approach may end with participants understanding terminology and methodology.
The training-led implementation approach continues further:
Learn the Methodology
→ Understand the Organisation
→ Apply the Templates
→ Develop Organisational Outputs
→ Review with Facilitators
→ Validate with Business Owners
→ Implement Improvements
→ Exercise
→ Maintain
Participants are therefore encouraged to use the concepts covered during training to prepare actual or draft BCM project outputs for their organisation.
This provides several benefits.
First, participants can immediately contextualise the methodology rather than attempting to interpret it months after training.
Second, the organisation receives a structured set of draft outputs that can accelerate implementation.
Third, business owners can review tangible BCM requirements rather than abstract concepts.
Fourth, areas of uncertainty or disagreement become visible early and can be resolved through workshops and management review.
Finally, the approach strengthens internal capability because organisational personnel participate directly in developing the BCM programme rather than relying entirely on an external consultant.
The eBook should nevertheless not be treated as replacing management validation, professional judgement, or organisation-specific governance. Illustrative assumptions must ultimately be confirmed by MCMC.
The most effective approach is to work through the BCM phases sequentially while allowing feedback between them.
Review the material established in eBooks 1 and 2.
Confirm:
Identify relevant threats, review controls, and determine current risk.
For each CBF:
Decompose → Assess Impact → Determine RTO → Identify Systems → Map Dependencies → Identify Vital Records
Use the BIA and RAR outputs to determine:
Mitigation → Recovery Method → Recovery Location → Minimum Resources
Convert approved strategies into clear procedures for each relevant business team.
Validate assumptions through:
Lessons should flow back into the earlier analysis.
Exercise Finding
→ BIA Assumption Review
→ Strategy Adjustment
→ Plan Revision
→ Control Improvement
This creates the continuous improvement cycle expected of a mature BCM programme.
Completing templates is necessary, but it should not become the objective of the BCM project.
The objective is organisational capability.
A completed BIA does not create resilience unless its RTOs influence recovery decisions.
A documented recovery strategy does not create resilience unless the required people, facilities, technology, and suppliers can actually be mobilised.
A Business Continuity Plan does not create resilience unless personnel understand it and can execute it.
The progression should therefore be:
Documented
→ Approved
→ Resourced
→ Implemented
→ Exercised
→ Demonstrated
→ Maintained
This distinction is particularly important in an ISO 22301-aligned BCM programme because evidence of documentation alone provides limited assurance that the organisation can actually continue its priority activities during disruption.
This third eBook marks the transition from understanding BCM and organising the BCM programme to performing the detailed analytical and planning work required for implementation.
The first two eBooks provide the foundation. This eBook turns that foundation into an implementation pathway covering:
Risk Analysis and Review
→ Business Impact Analysis
→ Business Continuity Strategy
→ Business Continuity Plan Development
Within the RAR phase, MCMC identifies credible threats, evaluates controls, and determines current risk.
Within the BIA phase, the organisation identifies its Critical Business Functions, decomposes them into Sub-Critical Business Functions, evaluates impact over time, establishes recovery requirements, and identifies supporting technology, dependencies, and vital records.
Within the BCS phase, those requirements are converted into mitigation strategies, recovery strategies, and minimum resource requirements.
Within the Plan Development phase, the approved strategies become practical procedures that personnel can use during an actual disruption.
The proposed Critical Business Functions provide the starting point for this implementation work:
CBF-1 Communications and Multimedia Regulatory Oversight
through
CBF-12 Postal and Courier Regulatory Oversight.
Each should ultimately be analysed at the Sub-CBF level rather than treated as a single indivisible activity.
The implementation logic for the remainder of the eBook is therefore:
Understand What Matters
→ Identify What Can Disrupt It
→ Determine How Quickly It Must Recover
→ Identify What It Depends Upon
→ Select How It Will Recover
→ Determine What Resources Are Required
→ Document What Personnel Must Do
→ Exercise the Arrangements
→ Improve
As a training-led implementation resource, this eBook is intended to help organisations convert the learning gained through BCM Institute's certification and competency-based training into structured organisational outputs. It provides a practical bridge between BCM education and BCM implementation, while leaving final validation, approval, and ownership with the organisation itself.
The purpose of starting BCM implementation is therefore not merely to complete a series of templates. It is to establish a credible and demonstrable capability for MCMC to continue its priority regulatory responsibilities, recover affected business functions within approved timeframes, protect stakeholders, and restore normal operations following disruption.
| eBook 3: Starting Your BCM Implementation |
||||||
| MBCO | P&S | RAR T1 | RAR T2 | RAR T3 | BCS T1 | eBook 1 |
| CBF 1: Communications and Multimedia Regulatory Oversight | ||||||
| DP | BIAQ P1 | BIAQ P2 | BIAQ P3 | BIAQ P4 | BIAQ P5 | eBook 2 |
| BIAQ P6 | BCS T2 | BCS T3 | PD | CBF | eBook 3 | |
|
If you have any questions, click to contact us.
|
||