Business Continuity

Keep your business continuity management register in one place — what each critical activity can tolerate, the plans that respond when it is disrupted, and the exercises that show those plans work.

ISO 22301 (the international standard for business continuity management) expects an organisation to understand which activities matter most, to plan how it keeps or restores them, and to rehearse those plans — the operational part of the standard, clause 8. This page is the register for that work, a BCMS (business continuity management system) record set in three parts: impact analyses, continuity plans and exercises. Each record can be linked to the framework controls it evidences, so an auditor can follow a requirement straight to the analysis, plan or exercise behind it.

Four terms carry the analysis. A BIA (business impact analysis) looks at one activity and asks what a disruption would cost. RTO (recovery time objective) is how quickly the activity must be running again. RPO (recovery point objective) is how much data, measured as time, you can afford to lose. MTPD (maximum tolerable period of disruption) is the point beyond which the outage becomes unacceptable — so it can never be shorter than the RTO.

Who uses it

Role Read the register Add and edit records Delete records
Viewer Yes No — no Add or Edit buttons appear No
Contributor Yes Yes, including exercise corrective actions and the status field No — the Delete action is not shown
Manager Yes Yes Yes
Admin Yes Yes Yes
Part of the Compliance module

Business Continuity sits in the Governance menu and belongs to the Compliance module. When that module is not provisioned for your organisation, the menu entry is hidden. Linking a record to a framework control is done from the control itself and needs the right to edit compliance mappings, which Manager and Admin hold.

What's on this screen

The page is headed Business Continuity, with a one-line reminder of what the register holds. Below it, three tabs split the register; the one you choose is kept in the address (/continuity?tab=plans), so a link or a browser refresh reopens the same tab. Every tab has the same layout: a filter row, a table and, if your role allows, a button to add a record.

  1. The tabs — Impact analyses, Continuity plans and Exercises. Impact analyses opens first.
  2. Search impact analyses... narrows the table by name or description as you type. Each tab has its own search box.
  3. All statuses restricts the table to one status: Draft, In review, Approved or Retired.
  4. All tiers restricts it to one criticality tier, from Tier 1 — vital to Tier 4 — deferrable.
  5. Add impact analysis opens the create form. It appears only if your role can create records.
  6. The table lists each analysis with its Criticality tier, RTO, RPO, MTPD, Owner and Status. Select a name to open the detail drawer; Edit and Delete sit at the end of the row according to your role. The table pages with Previous and Next.
The Business Continuity register on the Impact analyses tab — /continuity.
The Business Continuity register on the Impact analyses tab — /continuity.

The detail drawer shows everything recorded for the record, and ends with Linked framework controls — the controls this record evidences, each a link to the control in Compliance Frameworks. When nothing is linked yet, the drawer says so.

Record an impact analysis

Record one analysis per activity or process — payroll, order intake, the customer help desk — rather than one for the whole organisation. The recovery targets are only useful when they describe something specific.

  1. On the Impact analyses tab, select Add impact analysis. A form of the same name opens.
  2. Enter a Name and, optionally, a Description. The search box looks in both.
  3. Pick an Owner — the person accountable for the activity. The form will not save without one.
  4. Choose the Criticality tier: Tier 1 — vital, Tier 2 — important, Tier 3 — standard or Tier 4 — deferrable.
  5. Enter RTO, RPO and MTPD in minutes. The hint under each field shows the value as hours or days as you type. If the MTPD is shorter than the RTO, the form stops you with MTPD must be greater than or equal to RTO.
  6. Add the Revenue impact per hour and rate the Reputation impact and Regulatory impact from None to Critical. Set the Status and select Save. The form closes, a confirmation appears and the new row is in the table.
Adding an impact analysis: owner, criticality tier and recovery targets — /continuity.
Adding an impact analysis: owner, criticality tier and recovery targets — /continuity.

The detail drawer can also list Impact categories — a level per type of impact — and Notes. These are shown when a record carries them, for example one created through the API; the form itself does not edit them.

Write a continuity plan

  1. Open the Continuity plans tab. Its filter row has Search continuity plans... and a status filter.
  2. The table shows each plan's Version, Status, Next review, the number of Covered processes and the number of Exercises run against it.
  3. Select Add continuity plan. Give the plan a Name and an Owner, describe its Scope, and set its Version, Status and Next review date.
  4. Under Covered processes, choose the impact analyses this plan protects. This is what ties the plan back to the recovery targets it must meet.
  5. Write the Activation criteria (what triggers the plan), the Recovery procedures (the steps to restore the activity) and the Communications plan (who is told what, and when). All three accept Markdown. Select Save.
The Continuity plans tab: status filter, versions, review dates and coverage — /continuity?tab=plans.
The Continuity plans tab: status filter, versions, review dates and coverage — /continuity?tab=plans.

A plan's detail drawer also shows Roles and responsibilities — who holds which role during an incident, and how to reach them — when the plan carries that list.

Plan and record an exercise

An exercise is a rehearsal of a plan. You schedule it first and fill in the result once it has taken place, so the same record covers both the plan and the proof.

  1. Open the Exercises tab. Filter by All types or All outcomes, or search by name.
  2. Select Schedule exercise. Enter a Name, choose the Exercise type — Tabletop, Simulation, Failover or Walkthrough — and the Continuity plan it tests, and set the Scheduled for date. The date is required.
  3. After the exercise, select Edit on its row. Fill in Conducted on, Duration (minutes), the Outcome — Passed, Partial or Failed — and the Findings, then save. Until then the outcome reads Not conducted yet.
  4. The Corrective actions column counts the follow-up actions still open and flags any that are overdue.
The Exercises tab: type and outcome filters, plans tested and open corrective actions — /continuity?tab=exercises.
The Exercises tab: type and outcome filters, plans tested and open corrective actions — /continuity?tab=exercises.

Follow up with corrective actions

An exercise that did not fully pass needs a documented response. Open the exercise from its name; the drawer shows its details, Participants where recorded, the Findings and a Corrective actions section.

  1. The Corrective actions table lists each action with its owner, due date (marked Overdue when it has passed), status and any linked non-conformity.
  2. Select Add action. Describe the Action, add optional Details, pick an Owner and a Due date, and select Add.
  3. Move the action through Open, In progress and Done. To mark it Verified, first fill in Effectiveness verification — the evidence that the action worked. The form will not accept Verified without it.
  4. The drawer ends with Linked framework controls.
An exercise's detail drawer with its findings and corrective actions — /continuity?tab=exercises.
An exercise's detail drawer with its findings and corrective actions — /continuity?tab=exercises.
A shortfall without follow-up is flagged

When an exercise ends Partial or Failed and has neither a corrective action nor a non-conformity, the drawer shows Corrective action required with a button to raise a non-conformity. You can also raise one from a single action; it is linked back to the action and appears in Non-Conformities.

Statuses

Impact analyses and continuity plans share four statuses. You set the status in the form; Aegis does not run an approval workflow for these records.

Status Meaning
Draft Being written. New records start here.
In review Complete and waiting for the owner or a reviewer to agree it.
Approved Agreed and in force.
Retired No longer in use, but kept in the register as history.

Exercises have no status of their own. Their lifecycle is the scheduled date, the conducted date and the outcome.

Link controls

Links are made from the control's side. In Compliance Frameworks, open a control — for example an ISO 22301 clause 8 control — and use its mapping panel. The Impact analyses, Continuity plans and Exercises tabs there let a Manager or Admin search the register and link a record. Once linked, the record appears under Linked framework controls in its drawer, and the control's own link opens this page on the right tab with that record selected.

Retire or delete a record

Tips and limits

Where this connects