This chapter will cover:
Part 14: Minimum Personnel Requirements
Part 15: Supporting Technology Requirements
Part 16: Vital Records and Information Requirements
Part 17: Internal CBF Dependency Matrix
Part 18: External Dependency Assessment
Part 19: Facility and Recovery-Location Requirements
Part 20: Manual Workaround Assessment
People are the most critical resource in the successful recovery of any organisation.
Regardless of how resilient Damanat's facilities, technology and systems may be, business recovery cannot be achieved without competent personnel possessing the authority, skills and experience necessary to perform essential activities.
The Business Impact Analysis (BIA) should therefore determine not only the minimum number of staff required but also the competencies, delegated authorities and succession arrangements needed to sustain each Critical Business Function (CBF) during disruption.
When assessing personnel requirements, Damanat should consider:
The objective is to recover essential business capability rather than restore the full workforce immediately.
|
Critical Business Function |
Essential Roles |
Indicative Minimum Staff |
Alternate / Backup Roles |
Specialist Competencies |
Key Person Risk |
Required Improvement |
|---|---|---|---|---|---|---|
|
CBF-1 Mortgage Guarantee Origination |
Mortgage Guarantee Officers, Team Leader |
8 |
Cross-trained Operations Officers |
Mortgage underwriting |
Medium |
Increase cross-training |
|
CBF-2 Guarantee Risk Assessment |
Risk Analysts |
4 |
Senior Credit Officers |
Financial risk modelling |
High |
Develop additional certified analysts |
|
CBF-3 Guarantee Issuance & Administration |
Guarantee Administrators |
4 |
Operations Officers |
Documentation management |
Medium |
Improve succession planning |
|
CBF-4 Claims Assessment & Settlement |
Claims Specialists |
4 |
Senior Operations Officers |
Claims evaluation |
Medium |
Cross-functional training |
|
CBF-5 Financial & Treasury Management |
Finance Manager, Treasury Officers |
4 |
Senior Accountants |
Treasury operations |
Medium |
Dual-authority coverage |
|
CBF-6 Enterprise Risk Management |
Enterprise Risk Manager |
3 |
Compliance Officers |
Enterprise risk management |
High |
Increase backup capability |
|
CBF-7 Regulatory Compliance |
Compliance Manager |
3 |
Legal Officers |
Regulatory reporting |
Medium |
Knowledge transfer programme |
|
CBF-8 Information Technology Services |
Infrastructure Engineers |
5 |
Senior System Administrators |
Infrastructure recovery |
High |
Expand technical succession |
|
CBF-9 Information Security |
Cybersecurity Analysts |
4 |
ICT Security Engineers |
Incident response |
High |
Continuous cyber training |
|
CBF-10 Relationship Management |
Relationship Managers |
4 |
Customer Service Officers |
Stakeholder engagement |
Low |
Cross-training |
|
CBF-11 Legal & Corporate Governance |
Legal Counsel |
2 |
External Legal Adviser |
Regulatory law |
Medium |
Panel legal support |
|
CBF-12 Human Resource Management |
HR Manager |
2 |
HR Executives |
Workforce mobilisation |
Low |
Update succession plan |
|
CBF-13 Procurement & Vendor Management |
Procurement Officers |
2 |
Finance Officers |
Emergency procurement |
Low |
Supplier continuity training |
|
CBF-14 Corporate Communications |
Communications Manager |
2 |
Executive Assistant |
Crisis communications |
Medium |
Media training |
|
CBF-15 BCM & Crisis Management |
BCM Manager |
3 |
Deputy BCM Coordinator |
BCM and crisis management |
High |
Additional BCM training |
The BIA should recognise that recovery capability depends more on competence than on total staff numbers. A larger workforce without the appropriate knowledge, delegated authority or technical expertise may be less effective than a smaller, well-trained recovery team.
Accordingly, Damanat should ensure that:
Nearly every Critical Business Function performed by Damanat depends on technology.
Consequently, the Business Impact Analysis should identify the ICT systems, applications and infrastructure necessary to support business recovery. Technology recovery priorities should always be derived from business recovery requirements rather than determined independently by ICT.
Technology dependency analysis should consider:
|
Critical Business Function |
Supporting System / Technology |
Business Use |
Required Availability |
Business RTO |
Indicative System RTO |
Indicative RPO |
Manual Workaround |
System Owner |
|---|---|---|---|---|---|---|---|---|
|
CBF-1 |
Mortgage Guarantee Processing System |
Application processing |
Continuous |
12 hrs |
8 hrs |
15 min |
Limited |
ICT |
|
CBF-2 |
Risk Assessment Platform |
Credit risk analysis |
High |
12 hrs |
8 hrs |
30 min |
Partial |
ICT |
|
CBF-3 |
Document Management System |
Guarantee documentation |
High |
24 hrs |
12 hrs |
30 min |
Paper forms |
ICT |
|
CBF-4 |
Claims Management System |
Claims processing |
High |
24 hrs |
12 hrs |
1 hr |
Manual register |
ICT |
|
CBF-5 |
ERP & Financial System |
Finance operations |
High |
24 hrs |
12 hrs |
15 min |
Manual ledger |
Finance/ICT |
|
CBF-7 |
Regulatory Reporting System |
Compliance reporting |
High |
24 hrs |
12 hrs |
1 hr |
Spreadsheet reporting |
Compliance |
|
CBF-8 |
Network Infrastructure |
Enterprise ICT |
Critical |
8 hrs |
4 hrs |
Near Zero |
None |
ICT |
|
CBF-9 |
SIEM & SOC Platform |
Cyber monitoring |
Critical |
4 hrs |
2 hrs |
Near Zero |
Limited |
Cybersecurity |
|
CBF-10 |
CRM |
Customer management |
High |
24 hrs |
12 hrs |
1 hr |
Manual contact lists |
ICT |
|
CBF-15 |
Incident Management Platform |
Crisis coordination |
Critical |
2 hrs |
1 hr |
15 min |
Manual incident log |
BCM |
The supporting technology assessment should demonstrate that:
Information is a critical organisational asset. Without access to accurate, complete and reliable information, Damanat would be unable to process mortgage guarantees, demonstrate regulatory compliance or make informed management decisions. The BIA should therefore identify the vital records required to support each CBF and define how they will be protected and recovered during disruption.
Vital records should be assessed according to:
|
Critical Business Function |
Vital Record / Information |
Format |
Storage Location |
Required Recovery Time |
Minimum Version |
Alternate Access Method |
Record Owner |
|---|---|---|---|---|---|---|---|
|
CBF-1 |
Mortgage Guarantee Applications |
Electronic |
EDMS |
12 hrs |
Current |
Replicated storage |
Operations |
|
CBF-2 |
Risk Assessment Models |
Electronic |
Risk Repository |
12 hrs |
Current |
DR Repository |
Risk Management |
|
CBF-3 |
Guarantee Register |
Database |
Production Database |
24 hrs |
Current |
DR Database |
Operations |
|
CBF-4 |
Claims Files |
Electronic |
Claims Repository |
24 hrs |
Current |
Backup Repository |
Claims |
|
CBF-5 |
Financial Records |
Electronic |
ERP |
24 hrs |
Current |
Finance Backup |
Finance |
|
CBF-7 |
Regulatory Reports |
Electronic |
Compliance Repository |
24 hrs |
Current |
Secure Archive |
Compliance |
|
CBF-8 |
System Configuration Documentation |
Electronic |
ICT Repository |
8 hrs |
Latest Approved |
Offline Copy |
ICT |
|
CBF-9 |
Security Logs |
Electronic |
SIEM |
4 hrs |
Real-time |
Secure Backup |
Cybersecurity |
|
CBF-15 |
BCM Documentation |
Electronic |
BCM Repository |
2 hrs |
Latest Approved |
Printed Emergency Copy |
BCM Office |
Each vital record should have:
No Critical Business Function operates independently.
The BIA should identify how business functions rely upon one another to deliver Damanat's services.
Understanding these internal dependencies enables management to identify shared resources, single points of failure and enterprise-wide recovery priorities.
|
Dependent CBF |
Supporting CBF |
Nature of Dependency |
Dependency Criticality |
Required Availability |
Consequence of Failure |
Possible Workaround |
|---|---|---|---|---|---|---|
|
CBF-1 |
CBF-8 ICT Services |
Mortgage processing systems |
Critical |
Immediate |
Processing stops |
Limited manual intake |
|
CBF-1 |
CBF-9 Information Security |
Secure authentication |
Critical |
Immediate |
Cyber risk |
Temporary enhanced controls |
|
CBF-2 |
CBF-5 Finance |
Financial information |
High |
24 hrs |
Incomplete assessments |
Manual verification |
|
CBF-3 |
CBF-8 ICT |
Document management |
High |
12 hrs |
Guarantee issuance delayed |
Paper documentation |
|
CBF-4 |
CBF-5 Finance |
Payment processing |
High |
24 hrs |
Claims delayed |
Manual payment approval |
|
CBF-7 |
CBF-11 Legal |
Regulatory interpretation |
Medium |
48 hrs |
Compliance uncertainty |
External legal advice |
|
CBF-15 |
CBF-14 Communications |
Stakeholder communications |
High |
4 hrs |
Delayed crisis communications |
Alternative communication channels |
Dependency analysis should identify:
These shared dependencies often become enterprise-wide recovery priorities because disruptions affect multiple CBFs simultaneously.
The next instalment will cover:
| P0 | P1 | P2 | P3 | P4 | P5 | P6 | P7 |
|
|
To learn more about the course and schedule, click the buttons below for the BCM-300 Business Continuity Management Implementer [BCM-3] and the BCM-5000 Business Continuity Management Expert Implementer [BCM-5].
|
Please feel free to send us a note if you have any questions. |
||