CBCI Glossary of Terms & Exam Flashcards
One or more tasks undertaken by, or for an organization, that produces or supports the delivery of one or more products and services.
Procedure or procedures
Activity or activities
Process or processes
Activity or activities
The Professional Practice within the business continuity management lifecycle that reviews and assesses an organization to identify its objectives, how it functions and the constraints of its operating environment.
PP1
PP2
PP3
PP4
Analysis (PP3)
A systematic, independent and documented process for obtaining evidence and evaluating it objectively to determine the extent to which the criteria are fulfilled.
Exercise
Audit
BIA
Risk assessment
Audit
The capability of the organization to continue delivery of products or services at acceptable pre-defined levels following disruptive incident.
Risk assessment
Business continuity
Exercising
Threat assessment
Business Continuity (BC)
A holistic management process that identifies potential threats to an organization and the impacts to business operations those threats, if realized, might cause, and which provides a framework for building organizational resilience with the capability of an effective response that safeguards the interests of its key stakeholders, reputation, brand and value-creating activities.
Business continuity management
What is the ongoing cycle of activities of the business continuity programme, that build organizational resilience?
Business Continuity Management (BCM) Lifecycle
Part of the overall management system that establishes, implements, operates, monitors, reviews, maintains and improves business continuity.
Business Continuity Management System (BCMS)
Documented procedures that guide organizations to respond, recover, resume, and restore to a pre-defined level of operation following disruption.
Business continuity plan (BCP)
The ongoing management and governance process supported by top management and appropriately resourced to implement and maintain business continuity management.
Business continuity programme
The time frames and resources, and capabilities necessary to continue to deliver the prioritised products, services, processes, and activities following a disruption.
Business continuity requirements
The process of analysing activities and the effect that a business disruption might have upon them.
Business impact analysis (BIA)
The ability to apply knowledge and skills to achieve intended results.
Competence
A recurring activity to enhance performance.
Continual improvement
A situation with a high level of uncertainty that disrupts the core activities and/or credibility of an organization and requires urgent action.
Crisis
The Professional Practice within the business continuity management lifecycle that identifies and selects appropriate solutions to determine how continuity can be achieved in the event of an incident.
Design (PP4)
The Professional Practice that defines how to integrate business continuity awareness and practice into business as usual activities.
Embedding (PP2)
The process to train for, assess, practice, and improve performance in an organization.
Exercise
The Professional Practice within the business continuity management lifecycle that implements the solutions agreed in the Design stage. It also includes developing the business continuity plans and a response structure.
Implementation (PP5)
A situation that might be, or could lead to, a disruption, loss, emergency or crisis.
Incident
A person or organization that can affect, be affected by, or perceive themselves to be affected by a decision or activity.
Interested party
The act of declaring that an organization’s business continuity arrangements need to be put into effect in order to continue delivery of key products or services.
Invocation
The time it would take for adverse impacts, which might arise as a result of not providing a product/service or performing an activity, to become unacceptable.
Maximum acceptable outage (MAO)
The time it would take for adverse impacts, which might arise as a result of not providing a product/service or performing an activity, to become unacceptable.
Maximum tolerable period of disruption (MTPD)
The minimum level of services and/or products that is acceptable to the organization to achieve its business objectives during a disruption.
Minimum Business Continuity Objective (MBCO)
The person or group of people that has its own functions with responsibilities, authorities and relationships to achieve its objectives.
Organisation
The ability of an organization to absorb and adapt in a changing environment.
Organisational resilience
The values, attitudes and behaviour of an organization that contribute to the unique social and psychological environment in which it operates.
Organisational culture
People working for and under the control of the organization.
Personnel
The document that provides the intentions and direction of an organization as formally expressed by its top management.
Policy
The Professional Practice that establishes the organization’s stance relating to business continuity and defines how it should be implemented throughout the business continuity programme.
Policy and Programme management (PP1)
The activities to which priority must be given following an incident in order to mitigate impacts.
Prioritised activities
A set of interrelated or interacting activities which transforms inputs into outputs.
Process
Beneficial outcomes provided by an organization to its customers, recipients and interested parties.
Products and services
The point to which information used by an activity must be restored to enable the activity to operate on resumption.
Recovery point objective (RPO)
The period of time following an incident within which a product or service must be resumed, or activity must be resumed, or resources must be recovered.
Recovery time objective (RTO)
All assets, people, skills, information, technology (including plant and equipment), premises, and supplies and information (whether electronic or not) that an organization has to have available to use, when needed, in order to operate and meet its objective.
Resources
The effect of uncertainty on objectives.
Risk
The overall process of risk identification, risk analysis and risk evaluation.
Risk assessment
Coordinated activities to direct and control an organization with regard to risk.
Risk management
An exercise whose aim is to obtain an expected, measurable pass/fail outcome.
Test
A potential cause of an unwanted incident, which can result in harm to individuals, the environment or the community.
Threat
A person or group of people who directs and controls an organization at the highest level.
Top management
The Professional Practice within the business continuity management lifecycle that confirms that the business continuity programme meets the objectives set in the policy and that the plans and procedures in place are effective. It includes exercising, maintenance and review activities.
Validation (PP6)
To which level do the following activities belong?
- Provide oversight and support of the business continuity programme including provision of adequate resources and approval of budget
- Ensure the business continuity programme aligns with the organisations objectives
- Ensure the business continuity programme complied with the business continuity policy and any related legal and regulatory requirements
- Monitor and review the business continuity programme regularly to ensure the requirements are being met
- Support continual improvement
Governance
To which group do these commitments belong?
- Recognising and communicating the requirements for business continuity as a key management discipline when building organisational resilience
- Ensuring that the business continuity policy and programme is aligned to the objectives of the organisation
- Ensuring that the business continuity programme delivers its expected outcomes and meets the requirements stated in the policy
- Maintaining support for the business continuity policy and programme
- Ensuring individuals undertake activities so the business continuity programme is effective
- Providing the resources required to implement the policy through the ongoing cycle of activities in the business continuity programme
- Directing and supporting continual improvement of the business continuity programme through reviews and self assessments
- Providing direction and guidance to embed business continuity into the organisation business as usual routines
Leadership
Whose responsibilities are as follows?
Providing leadership, commitment and resources as part of governance
Top management
Which group oversees, advises and manages the business continuity programme making recommendations and reporting to top management?
Business continuity steering group
Who ensures the business continuity plan adequately reflects the organisation business continuity capabilities?
Business continuity plan owner
Develops and delivers an effective business continuity programme including the facilitation and coordination of plans throughout the organisation
Business continuity professional
They respond to an incident or crisis
Incident response personnel
- Communicate the implications of departmental changes that may impact the business continuity programme
- Collect information for the BIA
- Develop, implement and maintain departmental plans on behalf of the plan owner
- Conduct and participate in exercise
Departmental representatives
Who has the following responsibilities?
- Acknowledge roles and responsibilities during an incident to ensure effectiveness by understanding the business continuity programme
- Recognise an incident or crisis
- Alert incident or crisis
- Alert incident or crisis responders
- Escalate action to the incident or crisis management team
- Respond appropriately to specific threats
- Respond appropriately when evacuated from the site
- Understand relevant plans and associated roles and responsibilities
All personnel
Which group acts where relevant within the business continuity programme or in response to an incident?
Interested party responsibilities
- Business continuity policy
- Business continuity programme of activities
- Project management documentation
- Business continuity team meeting agendas minutes and action trackers
- Skills and competency requirements and records
- Training and awareness activities
- BIA Questionnaires and information
- Risk Assessments
- Papers supporting the choice of business continuity solutions
- Response structure
- Business continuity plans
- Crisis management plans
- Exercise programme
- Exercise Reports
- SLAs with customers and suppliers
- Contracts for outsourced service recovery services including workspace and salvage
- A maintenance review programme and report
Business continuity programme documentation
To which PP’s process do these belong?
- Identifying the interested parties within the organisation who require engagement
- Determining how best to engage with them and understanding their key interests and priorities
- Engage and communicate with them using the most appropriate channels
- Use existing events and communication channels where possible to communicate the benefits and return on investment for business continuity within the organisation
Embedding
A network of influential individuals in the organisation who understand the benefits of business continuity and building organisational resilience and advocate for it within the organisation
Business continuity champions
Project management skills and an understanding of the importance of continual improvement
Policy and programme management core competencies
- An understanding of organisational culture and how to influence it
- knowledge of the business continuity competencies and skills required and training and awareness raising capabilities
Embedding business continuity core competencies
- Analytical skills related to the BIA including the ability to analyse information, identify problems and develop workable solutions
- An understanding of risk assessment and mitigation measures
Analysis core competencies
The ability to design and select appropriate continuity solutions for the organisation
Design Core Competencies
- An understanding of incident and crisis management including knowledge of emergency response
- The ability to develop, implement and manage plans
Implementation Core Competencies
- The ability to develop, manage, coordinate and deliver an exercise programme
- Evaluation skills to validate the effectiveness of the business continuity programme
Validation Core Competencies
- An understanding of the context of the organisation and the environment in which it operates as well as its approach to risk
- The ability to form an organisational wide view
- An ability to understand and collaborate with personnel in related management disciplines
- Effective communication and interpersonal skills
- Negotiation and influencing skills to gain top management buy-in and commitment
- facilitation skills and guide and direct workshops,planning sessions, meetings and exercises to achieve productive outcomes
Business continuity management skills