Continuity management COPL
(unchanged)
Developing, implementing and testing a business continuity framework.
Guidance notes
(unchanged)
Activities may include, but are not limited to:
- identifying potential threats and assessing their business impact
- developing plans and procedures to respond to an incident
- ensuring critical business functions can continue with a planned level of disruption
- ensuring an acceptable level of service can be restored after a disruption
- developing organisational resilience
- assuring that continuity is being designed into systems, processes and ways of working
- implementing continuity management practices for cloud-based services
- enabling continuous delivery, deployment and integration of applications and infrastructure without adverse impact or disruption to service
- collaborating with external partners and suppliers to ensure continuity across the supply chain
- using technologies and tools for enhanced risk assessment, monitoring and decision-making
- regularly communicating and training staff on their roles and responsibilities during disruptive events.
Incidents have a variety of causes, including, but not limited to: cyber-attacks, data breaches, organised crime, fires, floods, natural disasters, pandemics, health emergencies and supply chain failure.
Understanding the responsibility levels of this skill
Where lower levels are not defined...
- Specific tasks and responsibilities are not defined because the skill requires a higher level of autonomy, influence, and complexity in decision-making than is typically expected at these levels. You can use the essence statements to understand the generic responsibilities associated with these levels.
Where higher levels are not defined...
- Responsibilities and accountabilities are not defined because these higher levels involve strategic leadership and broader organisational influence that goes beyond the scope of this specific skill. See the essence statements.
Developing skills and demonstrating responsibilities related to this skill
The defined levels show the incremental progression in skills and responsibilities.
Where lower levels are not defined...
You can develop your knowledge and support others who do have responsibility in this area by:
- Learning key concepts and principles related to this skill and its impact on your role
- Performing related skills (see the related SFIA skills)
- Supporting others who are performing higher level tasks and activities
Where higher levels are not defined...
- You can progress by developing related skills which are better suited to higher levels of organisational leadership.
Click to learn why SFIA skills are not defined at all 7 levels.
Show/hide extra descriptions and levels.
Level 1
Continuity management: Level 2
(modified)
Maintains records of continuity testing and training activities.
Checks that documentation is accessible and up to date.
Records the actions taken and consequences following incidents or live testing exercises for use in lessons-learned reports.
Continuity management: Level 3
(modified)
Applies a defined methodology to document the detailed content of continuity plans, working within established plan structures and formats.
Maintains business continuity and disaster recovery plan documentation, keeping records current and consistent.
Contributes to test planning and supports the implementation of continuity management exercises.
Continuity management: Level 4
(modified)
Develops continuity management plans for defined business areas or functions.
Identifies the information and communication systems supporting critical business processes.
Leads the business impact analysis and risk assessment processes, engaging relevant stakeholders.
Coordinates the planning, design and testing of contingency plans. Reviews test results and recommends improvements to plans and procedures.
Continuity management: Level 5
(unchanged)
Manages the development, implementation and testing of continuity management plans.
Manages the relationship with individuals and teams who have authority for critical business processes and supporting systems.
Evaluates the critical risks and identifies priority areas for improvement.
Tests continuity management plans and procedures to ensure they address exposure to risk and that agreed levels of continuity can be maintained.
Continuity management: Level 6
(unchanged)
Sets the strategy for continuity management across the organisation.
Secures organisational commitment, funding and resources for continuity management.
Leads continuity management exercises.
Communicates the policy, governance, scope and roles involved in continuity management. Has defined authority and accountability for the actions and decisions for continuity management