DRI Business Continuity Planning and Documentation 1 — Questions and Answers
Question 1: What is the PRIMARY purpose of a Business Continuity Plan (BCP)?
- To prevent all possible disruptions to business operations
- To provide documented procedures and information enabling an organization to respond to and recover from a disruptive incident (Correct answer)
- To transfer financial risk to insurance providers during a disruption
- To fulfill regulatory requirements for documented emergency procedures
Correct answer: To provide documented procedures and information enabling an organization to respond to and recover from a disruptive incident
A BCP provides the documented procedures, information, roles, and resources enabling an organization to respond to and recover from disruptions—the primary purpose is enabling continuity and recovery, not prevention or risk transfer.
Business Continuity Plans are response and recovery documents, not prevention tools. Prevention and risk reduction are addressed through risk assessment, vulnerability mitigation, and preventive controls. The BCP assumes that disruptions will occur despite preventive efforts and provides the pre-planned procedures for responding effectively. A well-designed BCP includes activation criteria, notification procedures, alternate operating procedures, resource requirements, recovery site information, vendor contacts, and responsibilities for each phase of response. Plans should be concise, actionable, and written for the specific audience that will use them during a stressful incident. The DRI CBCP framework emphasizes that plans are only valuable if they are exercised, maintained, and can actually be executed by trained personnel under crisis conditions.
Question 2: Which document defines who is responsible for invoking the Business Continuity Plan and under what circumstances?
- The Business Impact Analysis report
- The IT Disaster Recovery Plan
- The BCP activation and escalation procedures (Correct answer)
- The employee emergency contact list
Correct answer: The BCP activation and escalation procedures
The BCP activation and escalation procedures define who has authority to declare an incident, under what conditions the plan is activated, and the escalation path if primary decision-makers are unavailable.
Activation authority and criteria are among the most critical elements of a BCP because the consequences of both under-activation (failing to invoke the plan when needed) and over-activation (triggering unnecessary disruption and cost) can be severe. Activation procedures document the specific triggers that should prompt BCP consideration (duration thresholds, impact thresholds, specific event types), the individual or group with authority to declare an incident and activate the plan, and the escalation path when primary decision-makers are unavailable. Without clear activation procedures, organizations may experience dangerous delays while people wait for someone else to make the decision, or junior employees may fail to activate plans because they lack clear authority. DRI practice requires unambiguous activation procedures tested in exercises to ensure smooth, rapid activation when needed.
Question 3: A BCP component that documents the alternate procedures for performing critical business functions manually or with limited technology is called:
- A disaster recovery plan
- A workaround procedure or manual fallback procedure (Correct answer)
- A business impact analysis update
- An emergency operations center runbook
Correct answer: A workaround procedure or manual fallback procedure
Workaround procedures (also called manual fallback procedures) document how critical business functions can be performed using manual or alternative methods when normal systems, tools, or processes are unavailable.
Workaround procedures are practical, step-by-step documents that allow business unit personnel to continue performing essential functions when normal systems, facilities, or resources are unavailable. For example, a workaround procedure for accounts receivable might describe how invoices can be generated manually using paper forms, how payments can be recorded in a spreadsheet, and how the backlog will be reconciled when systems are restored. These procedures are often overlooked in BCPs that focus exclusively on technology recovery, but they are essential for the period between incident occurrence and full system restoration. Effective workaround procedures are developed with input from the business units that will use them, tested through tabletop exercises, and kept simple enough to be executed under stress by staff who may not have used the procedures before.
Question 4: Which of the following is a characteristic of a GOOD Business Continuity Plan document?
- Comprehensive technical detail covering all possible scenarios
- Long explanatory sections providing the rationale for each decision
- Concise, actionable checklists with clear roles and contact information (Correct answer)
- Written primarily for senior management to demonstrate strategic alignment
Correct answer: Concise, actionable checklists with clear roles and contact information
Good BCPs are concise, actionable documents written for the personnel who will execute them during a crisis—checklists, clear role assignments, and readily accessible contact information are more valuable than comprehensive technical detail or strategic narrative.
BCP documentation quality is often inversely related to document length. Comprehensive, theoretical documents that attempt to address every possible scenario become unwieldy and unusable during actual incidents when stress and time pressure are high. Best-practice BCPs use clear, numbered checklists with action items, explicit role assignments (not just job titles, but named individuals with backups), current contact information, decision trees for common scenarios, and references to supporting documents for detail. The audience for most BCP sections is not senior management but the business unit managers, team leaders, and employees who must execute recovery procedures. Writing for this audience means prioritizing actionability over comprehensiveness. DRI CBCP methodology emphasizes that a BCP that can be executed effectively during a real incident is always preferable to a theoretically comprehensive document that freezes responders in information overload.
Question 5: How often should a Business Continuity Plan be reviewed and updated, according to DRI best practices?
- Only when a significant disruption has occurred
- Every five years to align with strategic planning cycles
- At least annually and after significant changes to the business, systems, or threat environment (Correct answer)
- Whenever a new senior executive joins the organization
Correct answer: At least annually and after significant changes to the business, systems, or threat environment
DRI best practices require BCP review at least annually and following significant organizational changes—new systems, reorganizations, facility changes, acquisitions, or changes in the threat environment—to keep plans current and effective.
Business Continuity Plans degrade rapidly without maintenance. Employees named in plans leave the organization, phone numbers change, vendors are replaced, systems are updated, facilities move, and the threat landscape evolves. A plan that was accurate when written may be dangerously outdated within a year. DRI standards require at minimum an annual review cycle that systematically validates all key elements: personnel and contact information, organizational structure, critical systems and applications, vendor and supplier lists, recovery site arrangements, and recovery procedures. Additional reviews are triggered by specific events: major system implementations, facility relocations, mergers or acquisitions, significant reorganizations, lessons learned from exercises or actual incidents, and material changes in the threat environment. Organizations should establish a formal change management process for BCPs to ensure updates are approved, version-controlled, and distributed to all plan holders.
Question 6: What is the purpose of version control in BCP documentation?
- To track how many times each employee has accessed the plan
- To ensure all plan holders are working from the current, authorized version and to maintain an audit trail of changes (Correct answer)
- To comply with ISO 27001 document control requirements only
- To prevent unauthorized personnel from reading the plan
Correct answer: To ensure all plan holders are working from the current, authorized version and to maintain an audit trail of changes
Version control ensures all plan holders are using the current authorized version and maintains an audit trail of what the plan said at any given time—critical for avoiding the scenario where responders use outdated procedures during an incident.
Version control is a fundamental document management practice for BCPs. Without it, organizations risk having multiple different versions of the plan in circulation—some plan holders may have an old version on their hard drive, others may be working from a printed copy made before the last update, while the 'current' version sits on the intranet. During an actual incident, this fragmentation can cause responders to follow contradictory procedures or use obsolete contact information. Effective version control includes: a unique version number and date on every document, a controlled distribution list, a process for distributing updates and confirming receipt, a requirement to destroy or archive superseded versions, and an audit trail recording what changed between versions and why. Electronic plan repositories with access controls can automate much of this process, but human processes for ensuring all plan holders acknowledge updates remain necessary.
What is the PRIMARY purpose of a Business Continuity Plan (BCP)?