Mapping is identifying, documenting and understanding the activities involved in delivering important or critical business services.
An organisation should identify, document and map the necessary people, processes, information, technology, facilities, and third parties service providers required to deliver each of its important or critical business services. This exercise should be undertaken collaboratively across the business to ensure comprehensive mapping.
Why Do We Map Processes and Resources?
Organisations must capture the key resources and dependencies that contribute to providing each important or critical business service to understand the possible threats to operational resilience.
Mapping incorporates identifying interdependencies and interconnections, including people, processes, information, technology, facilities, and third parties service providers.
The mapping process enables an organisation to have sufficient details to:
- test against the scenario
- test vulnerabilities
- test remediation
When mapping the "Processes," the relationship with key resources should be considered:
How to Map Operational Resilience Dependencies and Connections Across the Organization?
Mapping operational resilience dependencies and connections is essential for understanding the interdependencies between business units, systems, processes, and external stakeholders. The following actions are involved:
Identify Key Stakeholders
Engage with business unit leaders, IT managers, risk management teams, and other relevant stakeholders to identify and involve the key departments and individuals responsible for critical business functions.
Conduct Dependency Analysis
- Analyze the dependencies between business units, systems, applications, processes, and external entities (suppliers, partners, regulatory bodies).
- This analysis helps identify the critical links and potential vulnerabilities.
Identify Internal Interdependencies
- identify the interdependencies between different systems, processes, and functions.
- Analyze how one area's failures or disruptions can impact others.
- Consider dependencies on IT infrastructure, data centres, communication networks, and personnel.
- Document these interdependencies to understand internal dependencies comprehensively.
Identify External Interdependencies
- Assess the external interdependencies with third-party vendors, service providers, and other external entities.
- Identify critical relationships and dependencies the institution relies on to deliver its services.
○ includes outsourced processes, cloud service providers, regulatory reporting systems, and other external dependencies.
- Evaluate the potential impact of disruptions in these relationships on the institution's operations.
Document Interconnectivity and Interdependencies
- Create a comprehensive inventory that documents the identified dependencies and connections.
- Include information such as criticality, dependencies, contact persons, and relevant documentation.
- Document the identified interconnectivity and interdependencies in a structured manner.
- Visual representations such as diagrams or flowcharts illustrate the relationships and dependencies.
- Includes information on the relationship's nature, data flows, communication channels, and any contractual or legal obligations.
- This documentation will serve as a reference for future analysis and planning.
Establish Communication Channels
Establish effective communication channels to facilitate ongoing collaboration and information sharing among stakeholders. This ensures a common understanding of dependencies and enables efficient coordination during disruptions.
Regularly Review and Update
Continuously review and update the dependency mapping to reflect the organisational structure, processes, or external relationship changes. This ensures the accuracy and relevance of the mapping information.
"Implement" Phase of the OR Planning Methodology
|Identify Important Business Services||Map Processes and Resources||
Set Impact Tolerance
|Conduct Scenario Testing||Improve Lesson Learnt|
More Information About Blended Learning OR-5000 [BL-OR-5] or OR-300 [BL-OR-3]
To learn more about the course and schedule, click the buttons below for the OR-3 Blended Learning OR-300 Operational Resilience Implementer course and the OR-5 Blended Learning OR-5000 Operational Resilience Expert Implementer course.