---
title: [CM] [BDCB] [E3] [CRA] [P2] Treatment and Control
description: [CM] [BDCB] [E3] [CRA] [P2] Treatment and Control
---

[eBook CM](https://blog.bcm-institute.org/en/ebook-cm)

# [\[CM\] \[BDCB\] \[E3\] \[CRA\] \[P2\] Treatment and Control](https://blog.bcm-institute.org/en/ebook-cm/cm-bdcb-e3-cra-p2-treatment-and-control)

 Written by [Moh Heng Goh](https://blog.bcm-institute.org/en/ebook-cm/author/moh-heng-goh) | Oct 7, 2026, 8:20:43 AM

### **Part 2: CAR – Treatment and Control for the Brunei Darussalam Central Bank**

#### **Introduction**

Following **CRA Part 1-1 — List of Threats for Brunei Darussalam Central Bank (BDCB)**, the next stage of the Crisis Risk Assessment is to determine how each identified threat is currently treated, what controls are in place, and what additional controls to consider.

BCMpedia defines existing risk treatment as the mitigating measures already implemented to address recognised threats. Its RAR methodology identifies four treatment approaches: **Risk Avoidance, Risk Reduction, Risk Transference, and Risk Acceptance**.

 

It also distinguishes **Existing Controls**, measures already implemented, from Additional (Planned) Controls,  proposed improvements.

More than one treatment approach can apply to the same threat, and the appropriate treatment ultimately depends on the organisation's risk appetite.

For this chapter, the treatments and controls below are **illustrative recommendations for BDCB's CRA**, not assertions that BDCB currently operates every control listed.

BDCB should validate them with the relevant business, facilities, security, technology, cyber, procurement, BCM, and crisis-management owners. This distinction is particularly important for technology-related scenarios.

BDCB publishes technology-risk, cyber-intrusion, IT third-party, and payment-system requirements for regulated entities, demonstrating the relevance of resilience, recoverability, and third-party technology risk within Brunei's financial sector.

##### **Treatment notation used in the table**

**Applicable** means that the treatment approach can reasonably form part of BDCB's treatment strategy.

**Limited** means that it can be used only for part of the exposure.

**Residual** means that, after practical controls have been applied, some remaining risk must normally be accepted within the approved risk tolerance.

 

#### **Denial of Access — Natural Disaster**

 

| Type of Threats / Crisis Scenario | Existing Risk Treatment – Risk Avoidance | Existing Risk Treatment – Risk Reduction | Existing Risk Treatment – Risk Transference | Existing Risk Treatment – Risk Acceptance | Existing Controls | Additional (Planned) Controls |
| --- | --- | --- | --- | --- | --- | --- |
| Flood | Avoid locating critical equipment in flood-prone areas; avoid low-level storage of vital assets | Applicable — drainage, barriers, alternate sites, and remote working | Limited — insurance and contracted recovery services | Residual — extreme flooding cannot be eliminated | Emergency response; facility protection; alternate workplace; BCM arrangements; backups | Site-specific flood study; flood barriers; alternate command location; annual flood exercise |
| Flash Flood | Restrict use of exposed areas for critical operations | Applicable — monitoring, access controls, and rapid evacuation | Limited — insurance | Residual | Weather monitoring; emergency notification; evacuation; alternate working | Automated weather alerts; predetermined closure triggers; alternative staff access routes |
| Severe Rain / Thunderstorm | Avoid unnecessary travel during severe conditions | Applicable — remote working and infrastructure protection | Limited | Residual | Weather monitoring, UPS, building maintenance, and remote access | Formal weather escalation thresholds; enhanced water-ingress inspection; remote-work activation checklist |
| Lightning | Avoid exposed external operations during storms | Applicable — lightning and surge protection | Limited — equipment insurance | Residual | Surge protection; earthing; UPS; equipment redundancy | Periodic lightning-protection testing; enhanced protection for critical ICT and telecommunications |
| Strong Wind / Windstorm | Avoid use of unsafe areas | Applicable — structural maintenance and secured external assets | Limited — property insurance | Residual | Building maintenance; emergency response; staff notification | Structural vulnerability review; formal wind thresholds for site closure |
| Tropical Storm | Suspend non-essential on-site activities when required | Applicable — BCM, alternate sites, remote work, and emergency preparedness | Limited | Residual | Emergency response, weather monitoring, and alternate work arrangements | Severe-weather playbook; pre-event resource staging; cross-sector communications exercise |
| Haze / Poor Air Quality | Reduce or suspend outdoor activities | Applicable — remote working and indoor air management | Limited | Residual | HVAC; employee communication; work-from-home capability | Air-quality trigger levels; vulnerable-employee arrangements; protective equipment stock |
| Earthquake Tremors | Avoid occupancy of structurally unsafe areas | Applicable — structural assessment and evacuation | Limited — insurance | Residual | Evacuation procedures; emergency response; building inspection arrangements | Post-tremor structural inspection protocol; exercise loss-of-premises scenario |
| External Fire / Wildfire | Avoid operations in affected exclusion zones | Applicable — evacuation, alternate site, and air-quality controls | Limited — insurance | Residual | Fire monitoring; evacuation; alternate workplace | Smoke-impact assessment; alternate access routes; extended premises-loss exercise |

#### **Denial of Access — Man-made Disaster**

 

| Type of Threats / Crisis Scenario | Risk Avoidance | Risk Reduction | Risk Transference | Risk Acceptance | Existing Controls | Additional (Planned) Controls |
| --- | --- | --- | --- | --- | --- | --- |
| Building Fire | Control ignition sources and prohibit unsafe practices | Applicable — detection, suppression, and evacuation | Applicable — property/business insurance where appropriate | Residual | Fire alarms; extinguishers; fire wardens; evacuation plans; drills | Alternate assembly areas; recovery-site exercise; enhanced fire-compartment review |
| Bomb Threat | Restrict unauthorised access and suspicious deliveries | Applicable — security screening, evacuation, and liaison with authorities | Limited | Residual | Security controls; evacuation; incident escalation | Bomb-threat checklist; suspicious-package training; command-post exercise |
| Explosion | Control hazardous activities and access | Applicable — emergency response and building safety | Applicable — insurance where appropriate | Residual | Evacuation; security; emergency services coordination | Mass-casualty scenario exercise; structural recovery assessment procedure |
| Terrorism / Hostile Attack | Restrict access to sensitive areas | Applicable — layered physical security and intelligence awareness | Limited | Residual | Guards; CCTV; access control; lockdown/evacuation arrangements | Threat-level framework; hostile reconnaissance awareness; multi-agency exercise |
| Civil Disturbance / Public Disorder | Avoid unnecessary presence in affected areas | Applicable — remote work and alternative access | Limited | Residual | Security monitoring; access controls; employee alerts | Dynamic security assessment; alternative entrances; crisis communication templates |
| Suspicious Package / Security Threat | Controlled mail and delivery arrangements | Applicable — screening and isolation | Limited | Residual | Security personnel; access control; evacuation | Suspicious-item procedure; specialist training; exercise with authorities |
| Hazardous Material Incident | Avoid exposure and isolate hazardous zones | Applicable — evacuation/shelter-in-place | Applicable where insurance/contractual arrangements exist | Residual | Emergency procedures; HVAC controls; evacuation | Shelter-in-place capability; air-handling isolation procedure; PPE readiness |
| Major Transport Accident Near Premises | Avoid affected routes and areas | Applicable — alternative access and remote work | Limited | Residual | Employee alerts; alternate access; BCM arrangements | Traffic/access contingency map; rapid work-from-home activation |
| Prolonged Power Outage | Avoid single utility dependency where feasible | Applicable — UPS, generators, and alternate sites | Limited — service contracts | Residual | UPS; backup generators; DR/BC arrangements | Extended-runtime testing; fuel-resupply agreements; black-start exercise |

 

#### **Unavailability of People**

 

| Type of Threats / Crisis Scenario | Risk Avoidance | Risk Reduction | Risk Transference | Risk Acceptance | Existing Controls | Additional (Planned) Controls |
| --- | --- | --- | --- | --- | --- | --- |
| Infectious Disease / Pandemic | Avoid unnecessary physical contact/exposure | Applicable — remote work, split teams, and hygiene controls | Limited | Residual | Remote access; health guidance; staff communications; succession arrangements | Pandemic staffing thresholds; minimum staffing model; cross-training; periodic pandemic exercise |
| Localised Infectious Disease Outbreak | Temporarily avoid the affected workplace | Applicable — isolation and remote work | Limited | Residual | Workplace health measures; remote access | Team-segregation procedure; rapid cleaning arrangements |
| Loss of Key Appointment Holder | Avoid excessive dependency on one individual | Applicable — deputies, succession, and cross-training | Generally not applicable | Residual | Delegation of authority; deputies; succession arrangements | Named alternates for every critical role; knowledge-transfer programme |
| Multiple Critical Staff Unavailable | Avoid concentration of skills within one team/location | Applicable — cross-training and split teams | Limited — specialist external support | Residual | Cross-training, remote working, and staff redeployment | Minimum staffing matrices; multi-skilled reserve pool; cross-location exercises |
| Workplace Accident / Safety Incident | Avoid unsafe practices | Applicable — occupational safety controls | Applicable — insurance/medical services | Residual | Safety procedures; first aid; incident reporting | Enhanced safety reviews; casualty-response exercise |
| Workplace Violence | Avoid uncontrolled access and known high-risk situations | Applicable — security and employee-support measures | Limited | Residual | Security; access control; emergency response | Threat-management protocol; staff awareness; post-incident psychosocial support |
| Labour Dispute Affecting Essential Services | Avoid dependence on one service channel/provider | Applicable — alternate providers/work arrangements | Applicable — contracted alternatives | Residual | Supplier contracts; BCM arrangements | Alternate supplier agreements; essential-service dependency mapping |
| Transport Disruption Affecting Workforce | Avoid unnecessary commuting during severe disruption | Applicable — remote work and staggered attendance | Limited | Residual | Remote access; staff communications | Critical-staff accommodation/transport options; alternative staffing arrangements |
| Mass Casualty / National Emergency | Avoid deployment into unsafe areas | Applicable — distributed teams, succession, and remote work | Limited | Residual | Crisis management; emergency communication; BCM | Workforce-accountability system; family-assistance arrangements; national emergency exercise |

 

#### **Disruption to the Supply Chain**

 

| Type of Threats / Crisis Scenario | Risk Avoidance | Risk Reduction | Risk Transference | Risk Acceptance | Existing Controls | Additional (Planned) Controls |
| --- | --- | --- | --- | --- | --- | --- |
| Loss of Specialised Technology Vendor | Avoid unnecessary single-vendor dependency | Applicable — redundancy and internal capability | Applicable — contractual SLAs/support obligations | Residual | Vendor contracts; support agreements; supplier monitoring | Exit strategy; alternate supplier; source/configuration escrow where appropriate |
| Telecommunications Provider Failure | Avoid reliance on one carrier/path | Applicable — diverse links and backup communications | Applicable — SLA | Residual | Redundant connectivity; mobile communications | Carrier/path diversity validation; satellite/independent emergency communications |
| Utility Supplier Failure | Reduce reliance on utility supply for critical operations | Applicable — generators, storage and alternate sites | Limited | Residual | UPS; generator; facility BCM | Extended outage test; fuel and maintenance assurance |
| Critical ICT / Cloud Service Provider Outage | Avoid unsuitable concentration/cloud dependency | Applicable — resilience, backups and portability | Applicable — contracts, SLA and liability provisions | Residual | Vendor due diligence; service monitoring; backups | Cloud exit plan; portability test; concentration-risk assessment |
| Cyberattack on Critical Supplier | Avoid suppliers lacking adequate security | Applicable — due diligence, segmentation and monitoring | Applicable — contractual obligations/cyber insurance where appropriate | Residual | Third-party risk assessment; security requirements | Supplier cyber exercises; breach-notification testing; fourth-party mapping |
| Security Service Provider Failure | Avoid sole reliance on outsourced capability | Applicable — internal contingency and alternate staffing | Applicable — contractual replacement provisions | Residual | SLA; supplier monitoring | Backup security provider; emergency staffing protocol |
| Critical Equipment Supplier Failure | Avoid proprietary single-source dependency where feasible | Applicable — spare inventory and alternative equipment | Applicable — maintenance/support contracts | Residual | Maintenance contracts; spares | Critical-spares analysis; second-source qualification |
| Logistics / Transportation Disruption | Avoid just-in-time dependence for critical resources | Applicable — buffer stock and alternative routes | Applicable — multiple logistics providers | Residual | Supplier arrangements; stock holdings | Minimum stock thresholds; alternate delivery routes/providers |
| Supplier Financial Failure | Avoid financially weak critical suppliers | Applicable — financial monitoring and alternatives | Applicable — contractual protections | Residual | Vendor due diligence; procurement controls | Supplier financial early-warning indicators; exit/replacement plan |
| Regulatory / Legal Failure Affecting Supplier | Avoid non-compliant providers | Applicable — compliance due diligence | Applicable — contractual warranties/termination rights | Residual | Legal review; supplier due diligence | Periodic compliance certification; rapid supplier substitution plan |
| Concentration / Common Supplier Failure | Applicable — diversify where practical | Applicable — redundancy and contingency arrangements | Limited | Residual | Supplier inventory; dependency management | Sector-wide concentration mapping; alternative-provider strategy; scenario testing |

BDCB's published regulatory framework includes dedicated **IT third-party risk-management guidance**, reinforcing the importance of due diligence, risk-based controls, and management of external technology dependencies in the financial sector.

#### **Equipment and IT-Related Disruption**

 

| Type of Threats / Crisis Scenario | Risk Avoidance | Risk Reduction | Risk Transference | Risk Acceptance | Existing Controls | Additional (Planned) Controls |
| --- | --- | --- | --- | --- | --- | --- |
| Hardware Failure | Avoid unsupported/end-of-life equipment | Applicable — redundancy and preventive maintenance | Applicable — warranties/support contracts | Residual | Redundant hardware; monitoring; maintenance | Predictive monitoring; lifecycle replacement programme |
| Software / Application Failure | Avoid unsupported/unproven software | Applicable — testing, redundancy, and rollback | Applicable — vendor support | Residual | SDLC/change controls; backups; monitoring | Resilience testing; automated rollback; dependency mapping |
| Network Failure | Avoid single points of failure | Applicable — redundant equipment/routes | Applicable — carrier SLA | Residual | Network redundancy; monitoring | Independent route testing; regular failover exercises |
| Telecommunications Failure | Avoid single-carrier dependency | Applicable — multiple communication channels | Applicable — carrier SLA | Residual | Backup links; mobile communications | Out-of-band communications capability |
| Cyberattack | Avoid unnecessary exposure and insecure technology | Applicable — layered cybersecurity | Applicable — specialist response services/cyber insurance where appropriate | Residual | Access control; monitoring; patching; endpoint/network security; incident response | Threat-led penetration testing; cyber crisis exercise; zero-trust enhancements; privileged-access review |
| Ransomware | Avoid unsupported systems and unnecessary privilege | Applicable — segmentation, EDR, and immutable backups | Limited — response contracts/insurance | Residual | Backups; endpoint protection, email security, and incident response | Offline/immutable recovery validation; ransomware recovery exercise |
| Distributed Denial-of-Service (DDoS) | Minimise unnecessary public exposure | Applicable — filtering and scalable protection | Applicable — DDoS mitigation provider | Residual | Firewalls; monitoring; ISP controls | DDoS scrubbing capability; stress testing |
| IT Sabotage | Avoid excessive privileged access | Applicable — segregation of duties and monitoring | Limited | Residual | Access management, logging, and physical security | Privileged-user behavioural monitoring; insider-threat programme |
| Data Corruption / Loss of Data Integrity | Avoid uncontrolled changes/interfaces | Applicable — validation, reconciliation, and backups | Limited | Residual | Backups; reconciliation; database controls | Point-in-time recovery testing; integrity-validation procedures |
| Data Breach / Information Leakage | Avoid unnecessary collection/access to sensitive data | Applicable — encryption, DLP, and least privilege | Limited — cyber insurance/services | Residual | Access controls; encryption; monitoring | Enhanced DLP; data classification review; breach simulation |
| RTGS System Disruption | Avoid uncontrolled change and single points of failure | Applicable — high availability, DR, and operational contingency | Limited — vendor/support contracts | Residual | Monitoring; recovery arrangements; participant procedures | End-to-end RTGS failover exercise; prolonged-outage manual/alternative procedures |
| ACH System Disruption | Avoid single points of failure | Applicable — redundancy and recovery capability | Limited | Residual | Monitoring; DR; reconciliation | Cross-system dependency test with RTGS; extended outage exercise |
| CSD System Disruption | Avoid single processing/data dependencies | Applicable — redundancy, backups, and reconciliation | Limited | Residual | Backup/recovery; access control; reconciliation | Data-integrity recovery test; CSD/RTGS combined scenario exercise |
| Data Centre Failure | Avoid geographic/common-cause concentration | Applicable — alternate recovery facility | Applicable — specialist facility/service contracts | Residual | DR site; UPS/generator; environmental monitoring | Geographic dependency review; full production failover exercise |
| DR / Failover Failure | Avoid untested recovery designs | Applicable — regular testing and independent validation | Limited | Residual | DR plans; backups, and recovery testing | Unannounced failover exercises; dependency-based recovery testing |
| Failed Technology Change / Upgrade | Avoid high-risk changes during critical periods | Applicable — testing, approval, and rollback | Limited — vendor support | Residual | Change management; test environments; rollback plans | Enhanced pre-production simulation; automated rollback; crisis trigger for failed major changes |
| Database Failure | Avoid unsupported or single-instance databases | Applicable — replication and backups | Applicable — vendor support | Residual | Replication; monitoring; backup/recovery | Corruption scenario test; recovery-point validation |
| Authentication / Identity Service Failure | Avoid single identity-service dependency | Applicable — redundant identity infrastructure and emergency access | Limited | Residual | MFA; replicated services; privileged access controls | Emergency-access procedure; identity-system failover exercise |
| UPS / Backup Generator Failure | Avoid single backup-power dependency | Applicable — redundant equipment and maintenance | Applicable — maintenance contracts | Residual | UPS; generators; periodic tests | Full-load endurance testing; fuel-supply resilience review |
| HVAC / Cooling Failure | Avoid single cooling-system dependency | Applicable — redundant cooling and monitoring | Applicable — maintenance contracts | Residual | Environmental monitoring; backup cooling | Thermal shutdown thresholds; extended cooling-failure test |
| Capacity / Performance Failure | Avoid inadequate capacity design | Applicable — capacity planning, scaling, and load balancing | Applicable for scalable external services | Residual | Performance monitoring; capacity management | Extreme-volume stress testing; automated scaling where appropriate |

BDCB's technology-risk framework for the financial sector emphasises robust IT risk management, effective governance, system security, reliability, resilience, and recoverability.

Its regulatory catalogue also includes cyber-intrusion reporting, technology risk, and IT third-party requirements.

These provide useful contextual benchmarks when BDCB validates the proposed technology controls above, although the table should not be interpreted as claiming that every regulatory control imposed on supervised entities is necessarily an internal BDCB control.

#### **Applying the Four Risk Treatments**

The four treatment approaches should not be treated as mutually exclusive. BCMpedia expressly notes that more than one risk treatment may be selected for a threat.

For example, BDCB could address telecommunications failure by **avoiding** a single-carrier design, **reducing** exposure through redundant links, **transferring** defined service obligations through supplier contracts, and **accepting** the residual possibility that an exceptional national telecommunications event could disable several providers simultaneously.

**Use Risk Avoidance where BDCB can remove the source of unacceptable exposure—for example, by** discontinuing unsupported technology or avoiding concentration of critical infrastructure in a vulnerable location.

**Risk Reduction** is likely to be the dominant treatment for many BDCB threats because critical central-bank activities cannot simply be discontinued. Reduction measures include redundancy, cybersecurity controls, cross-training, alternate premises, disaster recovery, supplier diversification, and crisis preparedness.

**Risk Transference** transfers some financial, contractual, or operational consequences to another party through insurance, outsourcing, warranties, maintenance contracts, or service-level agreements. It does **not** transfer BDCB's ultimate accountability for managing crisis consequences.

**Risk Acceptance** applies to the residual exposure remaining after reasonable controls have been implemented. Acceptance should be explicit, authorised at the appropriate level, and consistent with BDCB's approved risk appetite rather than arising merely because no further action has been taken.

#### **Existing Versus Additional Controls**

BCMpedia distinguishes controls already implemented from controls proposed for future implementation. Existing controls are instruments or practices already operating to manage the identified risk, while additional controls are improvements identified during the assessment.

Accordingly, before this table becomes an approved BDCB CRA record, the organisation should verify every entry in the **Existing Controls** column. Where a listed measure does not currently exist, it should be moved to **Additional (Planned) Controls** rather than being recorded as an established control.

For every proposed additional control, BDCB should subsequently identify a **control owner, implementation priority, target completion date, required resources, and evidence of completion**.

Escalate material residual risks above the approved risk appetite for management treatment decisions.

 

CRA Part 2 converts the threat catalogue developed in CRA Part 1-1 into an actionable risk-treatment framework. The purpose is not to eliminate every conceivable threat.

For a central bank, many threats—such as severe weather, cyberattack, national infrastructure failure, or widespread disease—cannot be completely avoided.

The objective is to reduce the likelihood or consequences to an acceptable level while ensuring that BDCB can continue or recover its critical responsibilities.

Pay particular attention to **cascading and common-cause failures**. Flooding can simultaneously affect premises, people, utilities, and telecommunications.

A cyberattack can compromise technology availability, data integrity, and stakeholder confidence.

A common technology provider failure can affect BDCB and financial institutions at the same time. These scenarios require controls that operate across organisational boundaries rather than within individual risk silos.

The completed CRA Part 2 should therefore provide BDCB with a traceable relationship between each **threat, selected treatment, existing control, and planned improvement**.

This creates the foundation for assessing control effectiveness and residual exposure, prioritising remediation, and developing severe-but-plausible scenarios for crisis exercises and preparedness.

 

| **eBook 3: Starting Your CM Implementation** |  |  |  |
| --- | --- | --- | --- |
| \[RAR\] \[P1-1\] | \[RAR\] \[P1-2\] | \[RAR\] \[P1-3\] | \[RAR\] \[P2\] |
|  |  |  |  |
| \[RAR\] \[P3\] | \[CMS\] \[P1\] | \[CMS\] \[P2\] | eBook 3 |
|  |  |  |  |
|  |  |  |  |

 

 

 

#### More Information About Crisis Management Blended/ Hybrid Learning Courses

To learn more about the course and schedule, click the buttons below for the  CM-300 Crisis Management Implementer \[CM-3\] and the CM-5000 Crisis Management Expert Implementer \[CM-5\].

|  |  |  |
| --- | --- | --- |
|  |  |  |
|  | Please feel free to send us a note if you have any questions. |  |
|  |  |  |

[View full post](https://blog.bcm-institute.org/en/ebook-cm/cm-bdcb-e3-cra-p2-treatment-and-control)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Moh Heng Goh"
  },
  "dateModified" : "2026-10-09T08:14:52.413Z",
  "datePublished" : "2026-10-07T08:20:43Z",
  "headline" : "[CM] [BDCB] [E3] [CRA] [P2] Treatment and Control",
  "image" : {
    "@type" : "ImageObject",
    "height" : 400,
    "url" : "https://3893111.fs1.hubspotusercontent-na1.net/hubfs/3893111/BDCB%20Graphic%20Folder/BDCB%20CM%20Graphic%20Folder/BDCB%20CM%20E3%20Morepost/%5BCM%5D%20%5BBDCB%5D%20%5BE3%5D%20%5BRAR%5D%20%5BP2%5D%20Treatment%20and%20Control.jpg",
    "width" : 400
  },
  "mainEntityOfPage" : "https://blog.bcm-institute.org/en/ebook-cm/cm-bdcb-e3-cra-p2-treatment-and-control",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "eBook CM"
  }
}
```