Let's face it, just as gaining ISO 27001 Certification became all but mandatory to win and retain contracts in a post-GDPR world, it is likely that ISO 22301 Certification will become similarly desirable in a post Covid-19 world.
If you are familiar with ISO 27001, you will know that business continuity is already an important part of compliance with that ISO Standard. It talks about protecting information assets and data in the event of a disruptive incident.
When the dust settles, business in the UK are going to know exactly when, why, how and for how long they suffered during the disruptive incident that was instigated by the Coronavirus, Covid-19. Beyond maintaining information security, actual business survivability became the key concern.
Broader business continuity management, which spans the entire spectrum of your critical business activities is going to be essential in a post Covid-19 world.
• How has each of your diverse business functions faced the Covid-19 crisis?
• What departments were the most resilient in the short term?
• When did business-as-usual become business during an emergency?
• What functions needed extra support from other departments as the crisis changed and extended?
• Did you deploy the right people, resources and technology in the right place and at the right time?
• How did you know how to prioritise where and when to spend money on recovery?
You may not have realised, but these are all questions to be considered as part of business continuity management.
Your approach to business continuity needs to be multi-faceted, taking into account how each critical activity has a different recovery point objective (RPO), recovery time objective (RTO) and maximum tolerable period of disruption (MTPD), which may place different challenges on effective resource distribution and use, at different times, during the next disruptive incident.
What might good business continuity management look like in a post Covid-19 world?
• Leaner business models - a laser focus on non-essential costs
• Increased virtualisation - 'virtual' offices and remote working
• Increased collaboration with key suppliers
• More support for bring your own device (BYOD) - as businesses struggled to source and distribute existing IT equipment
• Increased pressure from stakeholders to have third-party approval of their approach to BCM, such as ISO 22301 Certification
At Consultanci, we will assist you through the process of establishing, implementing and certifying a resilient approach to business continuity management (BCM), which fits your organisation and at the right pace for your compliance team.