GTAG10-coverGTAG 10 - Business Continuity Management
This GTAG focuses on how business continuity management (BCM) is designed to enable business leaders to manage the level of risk the organization could encounter in the case of a natural or man-made disruptive event that affects the extended operability of the organization.

The guide includes:

  • Disaster recovery planning for continuity of critical information technology infrastructure, and
  • Business application systems.

Chief audit executives CAEs have been challenged to educate corporate executives on the risks, controls, costs, and benefits of adopting a BCM program. Although it is true that recent disasters around the world have motivated some corporate leaders to give attention to BCM programs, the implementation of such programs is far from universal. The key challenge is engaging corporate executives to make BCM a priority.

Although most executives are likely to agree that BCM is a good idea, many will struggle to find the budget necessary to fund the program as well as an executive sponsor that has the time to ensure its success. Business Continuity Management will help the CAE communicate business continuity risk awareness and support management in its development and maintenance of a BCM program.

Table of Contents
1. Executive Summary
2. Introduction
spacer2.1 BCM Definition
spacer2.2 Crisis Management Planning
spacer2.3 Disaster Recovery of IT

3. Building a Business Case
4. Business Risks

spacer4.1 Common Disaster Scenarios
spacer4.2 Common Disaster Impacts

5. BCM Requirements
spacer5.1 Management Suppor
spacer5.2 Risk Assessment and Risk Mitigation.
spacer5.3 Business Impact Analysis
spacer5.4 Business Recovery and Continuity Strategy
spacer5.5 Disaster Recovery for IT
spacer5.6 Awareness and Training
spacer5.7 Maintenance of the BCM Program
spacer5.8 Exercise of the Business Continuity
spacer5.9 Crisis Communications
spacer5.10 Coordination with External Agencies
6. Emergency Response
7. Crisis Management
8. Conclusion/Summary
9. Appendix

spacer9.1 Sample BCP Audit Guide
spacer9.2 BCM Standards and Guidelines
spacer9.3 BCM Capability Maturity Model

Authors:
David Everest, Key Bank : : Roy E. Garber, Safe Auto Insurance Company
Michael Keating, Navigant Consulting : : Brian Peterson, Chevron Corporation

Download this guide (PDF, 1MB).
Purchase a printed version.
Download form for permission to translate to another language (PDF, 20KB).

The Institute of Internal Auditors • 247 Maitland Avenue • Altamonte Springs, Florida 32701-4201 USA
+1-407-937-1100 • Fax +1-407-937-1101 • www.theiia.org • Copyright 2008