BCM · BSI 200-4 · ISO 22301

Business continuity under BSI 200-4 – with a digital crisis team.

Ordivis Continuity

Business impact analysis on real CMDB dependencies, detection of time chains and single points of failure, recovery playbooks that can be ticked off in an audit-proof way, and an emergency manual that points to its source instead of copying it.

BSI 200-4 & ISO 22301 Crisis organisation fully covered Live state instead of a paper binder
# BIA: process Bürgerservice Meldewesen
Damage matrix  →  MTPD suggestion 24 h
 RTO required   8 h   inherited by subprocesses
 RTO achievable  31 h  from CI dependencies
 Gap             − 23 h  → risk into the ISMS

SPoF  CORE-SW-01  3 critical processes
MBCO  Fallback: paper intake, 40 %
Fundamentals

What is business continuity management?

BCM is the systematic preparation for resuming business-critical processes within a tolerable time after an outage – from the business impact analysis through recovery plans to a practised crisis organisation.

It is explicitly not about preventing disruptions – that is the job of information security – but about the ability to act afterwards. The central question is not „how do we prevent the outage?“ but „how long can we endure it, and what do we do in that time?“

MTPD, RTO, RPO, MBCO – the four measures

They turn „back as fast as possible“ into a verifiable requirement:

  • MTPD – maximum tolerable period of disruption, until the damage becomes unbearable
  • RTO – targeted recovery time; must be below the MTPD
  • RPO – maximum acceptable data loss, measured as a period of time
  • MBCO – minimum business continuity objective, the level at which fallback operation continues

Ordivis Platform suggests the MTPD from the damage matrix under BSI 200-4 and inherits the RTO down the process hierarchy – so that a subprocess is not accidentally rated more leniently than the process it carries.

BCM or disaster recovery?

Disaster recovery is the technical recovery of systems. BCM is the overarching view of the business process – including staff, premises, suppliers and communication. A perfectly restored server is of little use if nobody knows who authorises fallback operation and how the public is informed. Ordivis Platform keeps both: DR plans based on real CI dependencies, embedded in the BCM framework.

Why the CMDB is the prerequisite

The interesting figure in the BIA is not the required recovery time but the achievableone. That follows from the chain of technical dependencies – and only a maintained CMDBknows it. Ordivis Platform computes the target/actual gap on that basis and detects time chains and single points of failure in the dependency graph. Remaining gaps can be carried straight into the ISMS risk analysis as risks.

Feature scope

What the BCM module does

  • A BCM module of its own (BSI 200-4 & ISO 22301)
  • A dedicated BCM officer role with fine-grained permissions
  • Scope with a maturity level model (reactive / building / standard)
  • Business processes as CMDB objects (linked read-only)
  • A shared creation flow for processes (CMDB & BCM)
  • Criticality measures MTPD, RTO, RPO, MBCO + immediate measures
  • Damage matrix with an automatic MTPD suggestion
  • RTO inheritance down the process hierarchy
  • Business impact analysis with a rule-based pre-filter
  • Detection of time chains & single points of failure on the dependency graph
  • Target/actual gap: achievable vs. required recovery time
  • Carry continuity gaps into the ISMS as risks
  • Full response organisation: crisis team, emergency team, response teams
  • Deputy check (n+1) and a NIS2 reporting-duty role
  • Contact & alerting lists with escalation
  • Emergency document library with document control & approval workflow
  • Interactive recovery playbooks that can be ticked off in an audit-proof way
  • Exercise & test management (tabletop, alerting, staff-level, full test)
  • Lessons learned & CAPA measures with follow-up
  • Conformity evidence and management summary as PDF
  • IT emergency manual generator from the existing data
  • Disaster recovery plans with roles and documented steps
BIA
BCM software: business impact analysis with criticality measures
Business impact analysisDamage matrix, MTPD/RTO/RPO and the gap between required and achievable.
Crisis organisation
Digital crisis team: response organisation under BSI 200-4
Response organisationCrisis team, emergency team and response teams with deputy check and alerting.
A detail that counts when it matters

Why the emergency manual must not be a copy

The classic IT emergency manual is a document written once, printed and filed in a binder. Two years later half the emergency contacts have left the organisation and the alerting chain points at a department that no longer exists. It will be noticed in an emergency.

The generator in Ordivis Platform produces the manual under BSI 200-4 from the existing data – emergency organisation, alerting chain, immediate measures, communication plan, contacts and emergency documents. The decisive point: the chapters point to their source instead of copying it. Every retrieval shows the live state. No duplicated upkeep, no stale contacts.

Frequently asked questions about BCM

Answered briefly and honestly

What is business continuity management?

BCM is the systematic preparation for resuming business-critical processes within a tolerable time after an outage – from the business impact analysis through recovery plans to a practised crisis organisation. It is not about preventing disruptions but about the ability to act afterwards.

What do MTPD, RTO, RPO and MBCO mean?

MTPD is the maximum tolerable period of disruption, until the damage becomes unbearable. RTO is the targeted recovery time and must be below the MTPD. RPO describes the maximum acceptable data loss, measured as a period of time. MBCO is the minimum business continuity objective, the level at which fallback operation continues. Together the four measures turn „back as fast as possible“ into a verifiable requirement.

What is the difference between BCM and disaster recovery?

Disaster recovery is the technical recovery of systems. BCM is the overarching view of the business process – including staff, premises, suppliers and communication. A perfectly restored server is of no use if nobody knows who authorises fallback operation. Ordivis Platform keeps both: DR plans based on real CI dependencies within the BCM framework.

What does the pre-filter in the business impact analysis achieve?

It separates time-critical from non-time-critical processes by rule before the BIA itself begins. That spares the full analysis for processes where it evidently yields no insight – the usual reason BIA projects stall halfway.

How are single points of failure found?

Through the dependency graph of the CMDB. Ordivis Platform detects time chains and components on which several critical processes hang at once – and shows the target/actual gap between achievable and required recovery time. Without maintained dependencies it remains guesswork.

What is the digital administrative or crisis team?

The complete response organisation under BSI 200-4: crisis team, emergency team and response teams with roles, a deputy check on the n+1 principle and alerting lists with escalation. For entities within the scope of NIS2 there is additionally a dedicated reporting-duty role.

How is the IT emergency manual produced?

The generator produces it under BSI 200-4 from the existing data: emergency organisation, alerting chain, immediate measures, communication plan, contacts and emergency documents. The decisive point is that the chapters point to their source instead of copying it – every retrieval shows the live state. That means no duplicated upkeep and no stale emergency contacts in a printed binder.

Does this help with NIS2?

Indirectly, and we put that cautiously on purpose. NIS2 requires measures to keep operations running, reporting channels and the ability to produce evidence – exactly the building blocks that BCM and the ISMS supply. A tool does not, however, satisfy a directive; implementation remains an organisational task.

Related

Continuity needs dependencies

CMDB software

The dependency graph on which time chains and single points of failure are detected.

ISMS software

Continuity gaps are carried into the risk analysis as risks.

Municipal & critical infrastructure

A digital administrative team and budget predictability for towns and districts.

See the BIA on real processes.

From the damage matrix through SPoF detection to the emergency manual – in a demo by video conference.