Ordivis Continuity
Business impact analysis on real CMDB dependencies, detection of time chains and single points of failure, recovery playbooks that can be ticked off in an audit-proof way, and an emergency manual that points to its source instead of copying it.
# BIA: process Bürgerservice Meldewesen Damage matrix → MTPD suggestion 24 h RTO required 8 h inherited by subprocesses RTO achievable 31 h from CI dependencies Gap − 23 h → risk into the ISMS SPoF CORE-SW-01 3 critical processes MBCO Fallback: paper intake, 40 %
BCM is the systematic preparation for resuming business-critical processes within a tolerable time after an outage – from the business impact analysis through recovery plans to a practised crisis organisation.
It is explicitly not about preventing disruptions – that is the job of information security – but about the ability to act afterwards. The central question is not „how do we prevent the outage?“ but „how long can we endure it, and what do we do in that time?“
They turn „back as fast as possible“ into a verifiable requirement:
Ordivis Platform suggests the MTPD from the damage matrix under BSI 200-4 and inherits the RTO down the process hierarchy – so that a subprocess is not accidentally rated more leniently than the process it carries.
Disaster recovery is the technical recovery of systems. BCM is the overarching view of the business process – including staff, premises, suppliers and communication. A perfectly restored server is of little use if nobody knows who authorises fallback operation and how the public is informed. Ordivis Platform keeps both: DR plans based on real CI dependencies, embedded in the BCM framework.
The interesting figure in the BIA is not the required recovery time but the achievableone. That follows from the chain of technical dependencies – and only a maintained CMDBknows it. Ordivis Platform computes the target/actual gap on that basis and detects time chains and single points of failure in the dependency graph. Remaining gaps can be carried straight into the ISMS risk analysis as risks.
The classic IT emergency manual is a document written once, printed and filed in a binder. Two years later half the emergency contacts have left the organisation and the alerting chain points at a department that no longer exists. It will be noticed in an emergency.
The generator in Ordivis Platform produces the manual under BSI 200-4 from the existing data – emergency organisation, alerting chain, immediate measures, communication plan, contacts and emergency documents. The decisive point: the chapters point to their source instead of copying it. Every retrieval shows the live state. No duplicated upkeep, no stale contacts.
BCM is the systematic preparation for resuming business-critical processes within a tolerable time after an outage – from the business impact analysis through recovery plans to a practised crisis organisation. It is not about preventing disruptions but about the ability to act afterwards.
MTPD is the maximum tolerable period of disruption, until the damage becomes unbearable. RTO is the targeted recovery time and must be below the MTPD. RPO describes the maximum acceptable data loss, measured as a period of time. MBCO is the minimum business continuity objective, the level at which fallback operation continues. Together the four measures turn „back as fast as possible“ into a verifiable requirement.
Disaster recovery is the technical recovery of systems. BCM is the overarching view of the business process – including staff, premises, suppliers and communication. A perfectly restored server is of no use if nobody knows who authorises fallback operation. Ordivis Platform keeps both: DR plans based on real CI dependencies within the BCM framework.
It separates time-critical from non-time-critical processes by rule before the BIA itself begins. That spares the full analysis for processes where it evidently yields no insight – the usual reason BIA projects stall halfway.
Through the dependency graph of the CMDB. Ordivis Platform detects time chains and components on which several critical processes hang at once – and shows the target/actual gap between achievable and required recovery time. Without maintained dependencies it remains guesswork.
The complete response organisation under BSI 200-4: crisis team, emergency team and response teams with roles, a deputy check on the n+1 principle and alerting lists with escalation. For entities within the scope of NIS2 there is additionally a dedicated reporting-duty role.
The generator produces it under BSI 200-4 from the existing data: emergency organisation, alerting chain, immediate measures, communication plan, contacts and emergency documents. The decisive point is that the chapters point to their source instead of copying it – every retrieval shows the live state. That means no duplicated upkeep and no stale emergency contacts in a printed binder.
Indirectly, and we put that cautiously on purpose. NIS2 requires measures to keep operations running, reporting channels and the ability to produce evidence – exactly the building blocks that BCM and the ISMS supply. A tool does not, however, satisfy a directive; implementation remains an organisational task.
The dependency graph on which time chains and single points of failure are detected.
Continuity gaps are carried into the risk analysis as risks.
A digital administrative team and budget predictability for towns and districts.
From the damage matrix through SPoF detection to the emergency manual – in a demo by video conference.