PP2 Embedding Business Continuity Flashcards

1
Q

Embedding business continuity includes (4):

A
  1. Raising awareness about BC through
    communication.
  2. Encouraging buy-in from interested parties.
  3. Ensuring required competencies and skills in place.
  4. Ensuring appropriate training and learning opportunities.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Organisational culture can be defined as:

A

Organisational culture can be defined as the “values, attitudes and behaviour of an organisation that contribute to the unique social and psychological environment in which it operates.” (Source: ISO 22316:2017)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Following steps required when understanding

and influencing organizational culture to ensure successful embedding of BC (4):

A
  1. Identify interested parties within organisation
  2. Determine how best to engage with interested parties.
  3. Engage and communicate
  4. Use existing events and communication
    channels where possible.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Methods that can be considered for embedding BC programme (8)

A
  1. Changing attitudes and behaviour. Useful to identify consequences of action (or inaction).
  2. Ensuring BC considered by top management
    when organization’s strategic plan is developed or reviewed.
  3. Including BC on relevant meeting agendas.
  4. Incorporating BC plans into standard operating
    procedures.
  5. Including BC awareness as part of induction
    processes.
  6. Scheduling BC exercises to coincide with planned
    shutdowns or quieter times.
  7. Ensuring BC requirements are considered as part of
    supply chain management.
  8. Ensuring new products or services consider BC
    during planning stages.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Specific core competencies and general management skills required of BC professional (6)

Management skills required in all professional practices:

A
  1. Understanding of context of organization
  2. Ability to form an organization-wide view.
  3. Ability to understand and collaborate with personnel
  4. Effective communication and interpersonal skills.
  5. Negotiating and influencing skills
  6. Facilitation skills to guide and direct workshops, planning, sessions, meetings, training, and exercises to achieve productive outcomes.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Specific core competencies and general management skills required of BC professional:

Management Practice PP1 – Policy and
Programme Management

A

Project management skills and understanding of

importance of continual improvement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Specific core competencies and general management skills required of BC professional:

Management Practice PP2 – Embedding BC

A
  1. Understanding of organizational culture and how to
    influence it.
  2. Knowledge of BC competencies and skills required
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Specific core competencies and general management skills required of BC professional:

Technical Practice PP3 - Analysis

A
  1. Analytical skills relating to BIA

2. Understanding of risk assessment and mitigation measures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Specific core competencies and general management skills required of BC professional:

Technical Practice PP4 - Design

A

Ability to design and select appropriate continuity

solutions for organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Specific core competencies and general management skills required of BC professional:

Technical Practice PP5 - Implementation

A
  1. Understanding of incident and crisis management,
    including knowledge of emergency response.
  2. Ability to develop, implement and manage plans.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Specific core competencies and general management skills required of BC professional:

Technical Practice PP6 - Validation

A
  1. Ability to develop, manage, coordinate, and deliver an
    exercise programme.
  2. Evaluation skills to validate effectiveness of BC programme
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Additional skills that may be required in an organization that may be outside of core competencies and skills (7):

A
  1. Emergency evacuation direction.
  2. Security.
  3. Welfare and frst-aid.
  4. Crisis management and leadership.
  5. Information and communication technology (ICT) service continuity and disaster recovery.
  6. Damage management, asset salvage and equipment restoration.
  7. External and internal communications to include public relations, brand, and reputation management
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

To ensure appropriate level of awareness, education and training is established for successful embedding, the
following steps should be taken (4):

A
  1. Define competencies and skills
  2. Determine training and awareness needs
  3. Design and deliver appropriate level of training
  4. Evaluate and report effectiveness
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
Additional ways to determine training and
awareness needs (4):
A
  1. Reviewing documentation
  2. Getting feedback from personnel
  3. Observation, including reviews of current working practices.
  4. Internal and external audit reports
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Conclusions reached from gap analysis or alternate

methods may include the following (4):

A
  1. No training or awareness activities are required.
  2. Some training or awareness is needed.
  3. Extensive training and awareness is required.
  4. Recruitment of an experienced person is required.
  5. Specific skills are required for a short time only and can be provided by outsourced service provider.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Training and awareness activities should be arranged or
revised as appropriate based on the findings of gap
analysis. Types of activities may include (6):

A
  1. Internal training and awareness activities (including exercises where appropriate).
  2. Self-study options.
  3. External training or awareness sessions.
  4. Mentoring (offered to certified members of BCI).
  5. Conferences, workshops, and seminars.
  6. Academic courses
17
Q

Competence reviews following training and awareness

activities can be assessed using the following (8)

A
  1. Verbal or written tests.
  2. Self-evaluation.
  3. Observation of the individuals or teams.
  4. Assessment during continued coaching or mentoring.
  5. Participation in exercises designed to evaluate competence.
  6. Group coaching.
  7. Recognition of academic qualifications.
  8. Recognition of professional credentials
18
Q

Examples of competence records include (6):

A
  1. Personnel training records
  2. Education and academic qualifications.
  3. Previous relevant experience.
  4. Skills or competencies demonstrated during initial interview.
  5. Professional qualifications.
  6. Personnel appraisals.
19
Q

Training and awareness activities should consider (4):

A
  1. Changes to business processes that affect organizational priorities or operations.
  2. Legislation or regulation affecting BC programme.
  3. Change in actual or perceived threats and vulnerabilities.
  4. Requirements of interested parties.
20
Q

Examples of information resources for training and awareness campaigns include (5):

A
  1. BC and resilience related websites, blogs etc
  2. Books, journals, and other industry publications.
  3. Conferences, workshops, webinars, and seminars.
  4. Regional forums and working groups.
  5. Industry sector working groups
21
Q

Suitable topics for awareness raising communications include (4):

A
  1. Report based on recent exercise
  2. ICT recovery test at alternate facilities
  3. Commentary on recent incident which affected organization.
  4. Examples of real-life incidents that are relevant to BC
22
Q

Outcomes of embedding BC are (3):

A
  1. Improvement in level organizational resilience,
    measured by a reduction in impact and frequency of
    incidents or an overall improvement in response.
  2. Reduction in costs associated with incidents.
  3. Feedback from interested parties, indicating greater confidence in the organization’s ability to handle disruptions effectively.
23
Q

Examples of performance measures include (4):

A
  1. Percentage of annual review completion.
  2. Status of BIA review, by department.
  3. Status of scheduled BC plan updates.
  4. Completion of BC exercised within set time frames.
24
Q

PP2 Embedding Professional Practice Definition (6):

A
  1. Defines how to integrate BC into business as usual
  2. Organisational culture understood and influenced.
  3. Awareness raised
  4. Buy-in encouraged
  5. Competencies and skills in place.
  6. Training and learning opportunities provided.