7.13 Business Continuity Planning & Exercises

CISSP Domain 7 ยท Security Operations

7.13 Business Continuity Planning & Exercises

Disaster Recovery asks: how do we restore disrupted technology?

Business Continuity asks a broader question:

How does the organisation continue delivering its most important products and services while disruption is happening?

The normal office may be inaccessible. A cloud provider may be unavailable. Half the workforce may be absent. A supplier may fail. Telecommunications may be disrupted. Ransomware may disable corporate IT.

Business Continuity prepares the organisation to continue its essential activities at an acceptable level until normal operations can be restored.

๐ŸŽฏ

Prioritise

Identify the products, services and processes that matter most.

WHAT MUST CONTINUE?
๐Ÿ”„

Continue

Establish alternative people, locations, technology, suppliers and procedures.

HOW DO WE KEEP OPERATING?
๐Ÿงช

Exercise

Practise continuity arrangements and improve them before a real disruption occurs.

DOES THE PLAN WORK?
Current CISSP 7.13 Scope

Participate in Business Continuity Planning and Exercises

ISC2 does not currently list separate sub-bullets under objective 7.13.

The lesson therefore focuses on the concepts needed to understand and participate effectively in organisational Business Continuity.

Critical Activities

Determine what the organisation must continue delivering.

Business Impact

Understand what happens when those activities are disrupted.

Dependencies

Identify the people, technology, premises, information and suppliers required.

Continuity Strategies

Establish alternative ways of continuing essential activities.

Plans

Document how continuity arrangements will be activated and operated.

Exercises

Practise the plan and discover weaknesses.

Cross-Domain Connection

Domain 1.7 vs Domain 7.13

Domain 1.7

Identify, analyse, assess, prioritise and implement Business Continuity requirements.

BIA External Dependencies Business Requirements

WHAT DOES THE BUSINESS NEED?

Domain 7.13

Participate in Business Continuity planning and exercises.

Plans People Strategies Exercises

HOW DO WE PREPARE AND PRACTISE IT?

Domain 1 identifies the continuity requirement. Domain 7 operationalises and exercises it.

The Business Continuity Lifecycle

Business โ†’ Identify Critical Activities
Critical Activities โ†’ Business Impact Analysis
BIA โ†’ Priorities + Recovery Requirements
Requirements โ†’ Identify Dependencies
Dependencies โ†’ Continuity Strategies
Strategies โ†’ Business Continuity Plan
Plan โ†’ Train & Exercise
Exercise โ†’ Find Gaps
Gaps โ†’ Improve

BC Lifecycle

IDENTIFY What matters?
ANALYSE What if it stops?
DEPEND What does it need?
CONTINUE What alternatives exist?
PLAN Document actions
EXERCISE Practise
IMPROVE Fix weaknesses
Core Concept

Business Continuity Is About the Business

A Business Continuity Plan describes how important business or mission processes will be sustained during and after significant disruption.

Technology is important, but it is only one dependency.

People

Can the necessary workforce perform the activity?

Premises

Do people have somewhere safe to work?

Technology

Are required systems and communications available?

Information

Can personnel access the data and records they need?

Suppliers

Are critical external products and services still available?

Processes

Can activities be performed another way?

Business Continuity protects the ability to deliver the business outcome - not merely the servers supporting it.
Critical CISSP Distinction

Business Continuity vs Disaster Recovery

Business Continuity - BC

Keeps important business activities operating during disruption.

People Processes Premises Suppliers Technology

KEEP THE BUSINESS GOING

Disaster Recovery - DR

Restores disrupted information systems and technology capability.

Servers Networks Applications Data Recovery Sites

RESTORE THE TECHNOLOGY

BC vs DR

BC Keep business operating
DR Restore technology
DR can be part of BC. BC is broader than DR.

BC vs DR vs Incident Response vs Emergency Management

DisciplineMain Question
Incident ResponseHow do we control and resolve the security incident?
Emergency ResponseHow do we protect people and manage the immediate emergency?
Disaster RecoveryHow do we restore disrupted technology?
Business ContinuityHow do we keep essential business activities operating?
A single event can activate several of these processes at the same time.
Integrated Scenario

Ransomware Across the Enterprise

Security Team โ†’ Incident Response
IT Recovery Team โ†’ Disaster Recovery
Business Teams โ†’ Continuity Workarounds
Leadership โ†’ Crisis Decisions & Communications
Incident Response controls the attack. DR restores technology. BC keeps critical services operating in the meantime.
Foundation of BC

Business Impact Analysis - BIA

The BIA examines business activities and determines how disruption affects the organisation over time.

Business Product / Service โ†’ Processes
Processes โ†’ Dependencies
Disruption โ†’ Impact Over Time
Impact โ†’ Priority
Priority โ†’ Continuity Requirements
BIA asks what must continue and what happens to the business if it does not.

Business Impact Is Broader Than Money

Financial

Lost revenue, penalties, additional operating costs.

Operational

Inability to deliver products or services.

Legal / Regulatory

Failure to satisfy legal or regulatory obligations.

Safety

Harm to employees, customers or the public.

Customer

Loss of service, trust or contractual performance.

Reputation

Damage to confidence in the organisation.

The most important process is not necessarily the one that generates the most immediate revenue.
โฑ๏ธ Impact Changes Over Time A disruption may be tolerable briefly but unacceptable later
Payment processing unavailable

After 5 minutes: minor customer inconvenience.

After 2 hours: large transaction backlog.

After 24 hours: major financial and regulatory impact.

BIA considers both the severity of impact and how that impact changes as disruption continues.
Continuity Requirements

MTD ยท RTO ยท RPO

MTD - Maximum Tolerable Downtime

How long can the business process be disrupted before significant harm occurs?

BUSINESS LIMIT

RTO - Recovery Time Objective

How quickly should the supporting capability be recovered?

RECOVERY TARGET

RPO - Recovery Point Objective

How far back can recovered information go without unacceptable data loss?

DATA TARGET

Time & Data

MTD Maximum disruption
RTO Recovery target
RPO Data-loss target
The recovery objective must support the business tolerance.

Continuity Does Not Always Mean 100% Normal Service

During disruption, the organisation may continue an important activity at a reduced but acceptable level.

Normal operation

Customer contact centre: 1,000 staff.

Continuity mode

Available workforce: 400 staff.

Organisation temporarily prioritises:

Fraud Lost Cards Critical Payments

Lower-priority enquiries: delayed.

Continuity can mean maintaining essential capability at an acceptable reduced level until normal operations return.
๐ŸŽฏ Not Everything Is Equally Critical Prioritisation is necessary when resources are limited

If every application, process and service is labelled: critical,

then the organisation has not meaningfully prioritised.

Continuity planning identifies what must be protected first when the organisation cannot maintain everything.
Critical Concept

Business Processes Depend on Resources

People

Employees, specialists, contractors, decision-makers.

Premises

Offices, factories, warehouses, data centres.

Technology

Applications, networks, devices, cloud services.

Information

Databases, records, documentation and contact details.

Utilities

Electricity, water, fuel, telecommunications.

Suppliers

External organisations providing critical goods or services.

Transport

Movement of personnel, products and materials.

Facilities & Equipment

Specialist machinery, workspaces and physical resources.

Dependency Scenario

The Application Is Healthy

Online retailer's website: fully operational.

Payment provider: available.

Warehouse: available.

Delivery partner: has ceased operations.

Technology availability does not guarantee business continuity when an external dependency has failed.
External Dependencies

Supplier Continuity

A critical supplier should be assessed as part of the continuity chain.

Criticality

What happens if the supplier becomes unavailable?

Concentration Risk

Are several critical services dependent on the same provider?

Geography

Does the supplier share the same regional disruption risk?

Alternatives

Can another supplier provide the product or service?

Recovery Capability

What continuity arrangements does the supplier have?

Contract

Do service and recovery commitments support business requirements?

Outsourcing the service does not outsource the business impact of its failure.
๐Ÿ”— Single-Supplier Dependency A highly resilient organisation can still depend on a fragile supplier
Organisation

Two data centres: available.

Remote workforce: available.

Applications: highly available.

But all customer authentication depends on: one external identity provider.

Continuity is limited by the weakest critical dependency in the end-to-end service.
Continuity Strategy

How Can the Business Continue?

Alternate Location

Move activity to another office, site or facility.

Remote Working

Allow personnel to operate without the normal workplace.

Alternate Supplier

Redirect critical supply to another provider.

Manual Workaround

Perform a normally automated business activity manually.

Workforce Redeployment

Move trained personnel to the highest-priority activities.

Reduced Service

Continue only essential products or features.

Technology Recovery

Invoke Disaster Recovery where technology is required.

Inventory / Reserve Capacity

Maintain spare resources required during disruption.

โœ๏ธ Manual Workarounds Continue the business process without its normal technology
Normal process

Supplier payments approved through: automated workflow system.

Continuity mode

Application unavailable.

Critical payments use: documented manual dual-approval procedure.

Security still matters

Manual workarounds should preserve appropriate authorisation, segregation of duties, auditability and reconciliation.

Manual Workarounds Have Limits

Capacity

A manual process may support only a fraction of normal workload.

Error

Removing automation can increase human mistakes.

Fraud

Normal automated controls may no longer operate.

Duration

A workaround suitable for four hours may be unsuitable for four weeks.

Continuity workaround โ‰  permanent replacement for normal operations.
People & Premises

Remote-Working Continuity

Scenario

Main office: inaccessible for three weeks.

Strategy: workforce operates remotely.

The continuity plan should consider:

Laptops Internet Access VPN / ZTNA Capacity MFA Telephony Collaboration Home Working Security Support
"Everyone will work from home" is not a continuity strategy unless the organisation has validated that the required capability exists.

Workforce Continuity

Buildings and systems may remain available while the workforce does not.

Cross-Training

More than one person can perform critical activities.

Succession

Alternate decision-makers can assume critical authority.

Role Prioritisation

Scarce personnel can be moved to the most important activities.

Remote Capability

Staff can operate away from affected premises.

Contractor Support

External resources may provide additional capacity.

Welfare

Continuity plans must recognise the safety and practical needs of personnel.

Workforce Scenario

Systems Available - People Unavailable

Data centres: healthy.

Applications: healthy.

Network: healthy.

45% of critical operations staff: unavailable.

Business Continuity covers workforce disruption even when no technology disaster has occurred.
Premises Continuity

What If the Building Is Unavailable?

Remote Work Alternate Office Split Teams Reciprocal Space Temporary Workspace Relocate Critical Functions
Office fire

Building itself: not structurally destroyed.

But authorities prohibit re-entry for: 10 days.

Continuity planning considers loss of access, not merely destruction.

Information Continuity

Personnel cannot continue a critical process if the required information is unavailable.

Customer Records Supplier Details Emergency Contacts Procedures Contracts Financial Records Authentication Information
Problem

Emergency supplier list stored: only inside unavailable corporate SharePoint.

Continuity information should remain available under the disruption scenarios in which it will be needed.
Communications

Business Continuity Requires Communication

Employees

Where should they work and what should they do?

Management

What is the business impact and what decisions are required?

Customers

Which services remain available?

Suppliers

Which continuity arrangements need activation?

Regulators

Are notifications or updates required?

Emergency Services

Is external emergency coordination required?

Business Continuity communication is about keeping people coordinated while normal operating arrangements are disrupted.
๐Ÿ“ž Alternate Communications Normal communication channels may be part of the disruption
Normal tools
Email Teams Corporate VoIP

Identity platform fails.

All three become: unavailable.

SMS Emergency Notification Service Mobile Phones External Conference Bridge Alternative Collaboration Platform
Do not make every continuity communication method depend on the same critical technology.
Plan Activation

When Do We Activate Business Continuity?

Trigger

What disruption conditions may require continuity arrangements?

Authority

Who can activate the plan?

Scope

Which processes or locations are affected?

Notification

Who must be informed?

Strategies

Which continuity arrangements should be activated?

Priorities

Which activities receive scarce resources first?

Activation criteria should be understood before the organisation is under crisis pressure.

What Should a Business Continuity Plan Tell You?

Purpose & Scope

What does the plan protect?

Activation

When and by whom is it invoked?

Critical Activities

What must continue?

Priorities

What receives resources first?

Roles

Who does what?

Alternates

Who takes over if key people are unavailable?

Continuity Procedures

How does each activity continue?

Dependencies

What people, technology and suppliers are required?

Communications

How are stakeholders coordinated?

Return to Normal

How are temporary arrangements withdrawn?

๐Ÿ“‹ The Plan Must Survive the Disruption Continuity documentation must remain accessible
BC plan

Stored: only on internal network drive.

Ransomware: encrypts network drive.

The only copy of the continuity plan should not depend entirely on the environment the plan is designed to survive.

Protect the Business Continuity Plan

Continuity documentation can contain sensitive information.

Personal Phone Numbers Supplier Contacts Alternate Locations System Dependencies Emergency Credentials Recovery Procedures
The plan must be available during disruption while still being protected from inappropriate access.
Normalisation

Returning to Business as Usual

Continuity mode is normally temporary.

Normal Capability โ†’ Restore
Normal Capability โ†’ Validate
Temporary Processes โ†’ Reconcile
Continuity Controls โ†’ Withdraw Carefully
Business โ†’ Return to Normal
Returning to normal operations should be controlled just like entering continuity mode.
๐Ÿ”„ Reconcile Temporary Transactions Manual continuity activity may need to be entered into normal systems later
During outage

600 customer requests processed using: manual continuity forms.

Normal system returns.

The organisation must now:

Enter Transactions Avoid Duplication Validate Approvals Maintain Audit Trail
Continuity activity must eventually be reconciled with the normal operating environment.
Exercises

Business Continuity Must Be Practised

Objective 7.13 explicitly requires participation in Business Continuity exercises.

Unlike objective 7.12, ISC2 does not prescribe a separate list of BC exercise types here.

In practice, organisations may use different levels of exercise depending on the objective.

Discussion / Tabletop

Participants discuss how business activities would continue under a scenario.

Walkthrough

Participants step through continuity arrangements and resources.

Simulation / Functional Exercise

Personnel perform or simulate continuity roles under realistic conditions.

Operational Exercise

Selected continuity capability is actually used where appropriately controlled.

CISSP nuance

These are practical exercise approaches. They should not be mistaken for additional official ISC2 7.13 sub-bullets.

7.12 vs 7.13

DR Test vs BC Exercise

DR Testing

Can technology recovery capability restore the affected systems?

Backup Restore Failover Recovery Site RTO / RPO
BC Exercise

Can the organisation continue its critical business activities?

People Processes Facilities Suppliers Technology

7.12 vs 7.13

DR TEST Can technology recover?
BC EXERCISE Can business continue?

Define an Exercise Objective

Weak

"Exercise Business Continuity."

Better
Operate Customer Service With 50% Workforce Validate Loss of Main Office Test Alternate Supplier Activation Operate Without Corporate Email Validate Manual Payment Process
Good exercises are designed to answer specific continuity questions.

BC Exercise Cycle

DEFINE Exercise objective
SCENARIO Create disruption
EXERCISE Use continuity arrangements
OBSERVE Record what happens
LEARN Identify weaknesses
IMPROVE Correct plan
RETEST Prove improvement
BC Tabletop

The Office Is Unavailable for 30 Days

Scenario:

Structural damage makes headquarters inaccessible for one month.

Technology remains operational.

Questions

Which Teams Must Continue? Who Can Work Remotely? Who Needs Specialist Equipment? Where Will Mail Be Delivered? How Are Customers Contacted? Which Suppliers Need Notification? Who Activates Alternate Premises?
A Business Continuity exercise can test major disruption without any IT failure at all.
Supplier Exercise

Critical Supplier Fails

Exercise inject:

sole logistics provider ceases operations immediately.

BIA โ†’ Distribution Critical
Continuity Plan โ†’ Alternate Provider
Exercise โ†’ Contact Alternate
Discovery โ†’ Contract Expired
An exercise has turned an assumed continuity capability into a confirmed gap.
Infrastructure Scenario

Regional Power Failure

Headquarters: without power.

Local mobile network: degraded.

Public transport: partially suspended.

Data centre: operational on backup power.

Business Continuity considers the combined effect of people, premises, transport, telecommunications and technology.
SaaS Scenario

Critical SaaS Platform Unavailable

Customer relationship platform: unavailable globally.

Employees: healthy.

Offices: open.

Can Staff Access Essential Customer Information? Is There a Manual Process? Can New Requests Be Recorded Safely? How Will Transactions Be Reconciled Later?
Business Continuity focuses on maintaining the business process while the supplier restores the technology.
Cyber Continuity Scenario

Corporate IT Is Offline

Security isolates: large parts of the corporate network.

This may be the correct incident-response action.

But it also means:

Email Unavailable Customer Records Unavailable Printing Unavailable Corporate Telephony Degraded
Business Continuity should be capable of supporting essential operations while Incident Response and Disaster Recovery proceed.
Exercises

Test the People, Not Just the Plan

Decision-Makers

Can alternates make required decisions?

Process Owners

Do they understand their continuity procedures?

Employees

Do they know where to work and how to communicate?

Suppliers

Can external continuity arrangements be activated?

Communications Teams

Can internal and external messages be coordinated?

Security

Are continuity workarounds maintaining an acceptable security posture?

๐Ÿ›ก๏ธ Continuity Mode Still Needs Security Disruption does not automatically justify abandoning controls
Normal process unavailable

Employees propose:

emailing customer records to personal accounts so they can continue working.

The continuity workaround should preserve acceptable confidentiality, integrity, authorisation and accountability.

Continuity Controls May Be Different - Not Absent

Normal process

Automated transaction approval with: workflow controls and electronic audit trail.

Continuity process

Temporary manual process uses:

Two-Person Approval Numbered Forms Transaction Log Post-Recovery Reconciliation
Different control mechanism can preserve the same security objective.
Continuous Improvement

Exercise Findings Must Lead to Action

Exercise โ†’ Observe
Observation โ†’ Finding
Finding โ†’ Root Cause
Root Cause โ†’ Corrective Action
Corrective Action โ†’ Owner
Improvement โ†’ Retest
Exercise completed โ‰  continuity improved. Improvement occurs when findings are corrected.

Business Continuity Plans Must Change With the Business

New Products New Offices Cloud Migration Supplier Change Organisational Restructure New Regulations Changed Workforce New Threats
Old plan

Continuity strategy: move call-centre staff to Office B.

Office B: sold two years ago.

A continuity plan can become obsolete even when nobody edits the document.
CISSP Mindset

Plan for Effects, Not Only Named Disasters

It can be useful to think about loss of capability rather than trying to predict every possible disaster.

Loss of People

Whatever caused it.

Loss of Premises

Whatever caused it.

Loss of Technology

Whatever caused it.

Loss of Supplier

Whatever caused it.

Loss of Information

Whatever caused it.

Loss of Utilities

Whatever caused it.

A plan for "loss of workplace" can support fire, flood, structural damage, security cordon and other causes.
๐Ÿ”— Cascading Disruption One failure can create several continuity problems
Regional Storm โ†’ Power Failure
Power Failure โ†’ Telecom Failure
Transport Disruption โ†’ Staff Shortage
Supplier Closure โ†’ Material Shortage
Continuity planning should consider combinations of disruption rather than assuming failures occur neatly one at a time.
Common-Mode Scenario

Two Suppliers - One Dependency

Organisation uses: Supplier A and Supplier B.

This appears diversified.

Exercise reveals both suppliers depend on: the same upstream manufacturer.

Multiple suppliers do not provide true resilience if they share the same critical dependency.
Exercise Design

Make Scenarios Plausible and Challenging

Plausible

Scenario should be meaningful for the organisation.

Relevant

Exercise should test important continuity requirements.

Challenging

Do not assume every backup resource works perfectly.

Controlled

Exercise risk should remain appropriately managed.

Exercise injects
Primary Decision-Maker Unavailable Alternate Supplier Also Degraded Corporate Email Unavailable Building Closure Extended Media Enquiry Received

Observe What Actually Happens

Decision Delays Communication Problems Missing Contacts Resource Shortages Unclear Roles Hidden Dependencies Successful Workarounds
The exercise should generate evidence that helps improve continuity capability.
CISSP Mindset

Finding Problems Is Useful

Exercise result

Alternate supplier: cannot provide capacity for seven days.

BIA requires: continuity within four hours.

That is an important finding.

The organisation now has an opportunity to: change its continuity strategy before a real disruption occurs.

An exercise that exposes a serious weakness can be more valuable than an exercise where everyone simply confirms the plan works.

Business Continuity Measures

Activation Time

How quickly were continuity arrangements invoked?

Critical Activity Availability

Did essential services remain available?

Minimum Capacity

Could the organisation deliver the required level of service?

Communication Success

Were required stakeholders reached?

Supplier Activation

Did alternate supply arrangements work?

Outstanding Findings

Are continuity weaknesses being corrected?

๐ŸŽ“ CISSP Scenarios Recognise the Business Continuity principle being tested
Scenario 1

Management asks what Business Continuity primarily protects.

Best answer?

The organisation's ability to continue critical business activities.

Scenario 2

Management asks what Disaster Recovery primarily restores.

Best answer?

Disrupted information systems and technology capability.

Scenario 3

Is Disaster Recovery broader than Business Continuity?

Answer?

No. Business Continuity is broader and can include DR.

Scenario 4

A business process must continue even while its application is unavailable.

Which concept?

Business Continuity.

Scenario 5

The organisation analyses what happens when payroll is unavailable for increasing periods.

Which activity?

Business Impact Analysis.

Scenario 6

The process can be disrupted for no more than eight hours without significant harm.

Which concept?

MTD.

Scenario 7

The supporting system should recover within four hours.

Which concept?

RTO.

Scenario 8

Recovered information can be no more than 30 minutes old.

Which concept?

RPO.

Scenario 9

The RTO exceeds the maximum period the business can tolerate.

Primary problem?

Recovery capability does not support business continuity requirements.

Scenario 10

Every business process is classified as critical.

Primary concern?

Meaningful prioritisation has not occurred.

Scenario 11

The organisation can deliver only its most important services during disruption.

Can this still represent continuity?

Yes, if the reduced capability satisfies established business requirements.

Scenario 12

The servers are available but 60% of required staff cannot work.

Which continuity dependency failed?

People / workforce.

Scenario 13

The building is safe but authorities prohibit entry for two weeks.

Which continuity problem?

Loss of premises / access.

Scenario 14

The application works but a critical external logistics provider has failed.

Which concept?

External dependency / supplier continuity.

Scenario 15

A company outsources payment processing.

Has it outsourced the business impact if payments stop?

No.

Scenario 16

Two alternate suppliers both depend on the same manufacturer.

Primary concern?

Common dependency / concentration risk.

Scenario 17

Employees relocate to another office after the normal location becomes inaccessible.

Which strategy?

Alternate workplace.

Scenario 18

Employees continue activities from home.

Which strategy?

Remote-working continuity.

Scenario 19

An automated approval system fails and a documented dual-person manual process is used.

Which strategy?

Manual workaround.

Scenario 20

A manual process removes normal security controls.

Best approach?

Use appropriate compensating controls during continuity operation.

Scenario 21

Continuity staff email sensitive customer information to personal accounts.

Primary concern?

Continuity activity is creating unacceptable security risk.

Scenario 22

The BC plan is stored only on a failed corporate file server.

Primary problem?

The continuity plan itself is unavailable.

Scenario 23

The plan contains personal contact details and sensitive recovery information.

What is required?

Appropriate protection while maintaining availability.

Scenario 24

The organisation uses corporate email as its only emergency communication method.

Primary weakness?

Single communication dependency.

Scenario 25

A facilitator asks teams how they would operate if headquarters were unavailable.

Which activity?

Business Continuity tabletop exercise.

Scenario 26

The exercise discovers that an alternate supplier contract expired.

Is this useful?

Yes. The exercise identified a continuity gap.

Scenario 27

The organisation successfully recovers IT but staff do not know where to work.

Which plan was insufficient?

Business Continuity arrangements.

Scenario 28

The business continues manually while DR restores the failed application.

Can BC and DR operate together?

Yes.

Scenario 29

Ransomware forces security to disconnect corporate systems.

What can BC provide?

Alternative ways to continue essential activities during technical recovery.

Scenario 30

A BC exercise uses no defined objective.

Primary weakness?

Results will be difficult to evaluate meaningfully.

Scenario 31

An exercise finds several gaps but no corrective actions are assigned.

Primary concern?

The exercise may not result in improved continuity.

Scenario 32

A continuity gap is corrected.

What should follow where appropriate?

Retesting / re-exercising the corrected capability.

Scenario 33

The business changes supplier after the last BC exercise.

What should be considered?

Reviewing affected continuity plans and exercises.

Scenario 34

The continuity plan lists an alternate office that has since been sold.

Primary problem?

Plan maintenance failure.

Scenario 35

A disruption lasts much longer than anticipated.

What should the continuity strategy consider?

Whether temporary arrangements remain sustainable over time.

Scenario 36

A manual process handles only 20% of normal transaction volume.

What should determine whether this is acceptable?

Business continuity requirements and required minimum capability.

Scenario 37

A continuity exercise tests people, premises and suppliers but no servers fail.

Is this a valid BC exercise?

Yes. BC is broader than IT recovery.

Scenario 38

After normal systems return, manual transactions are never reconciled.

Primary risk?

Incomplete, duplicated or inconsistent business records.

Scenario 39

Business Continuity procedures bypass segregation of duties indefinitely.

Primary concern?

Temporary continuity exceptions have become permanent control weaknesses.

Scenario 40

Two different offices depend on the same electrical substation.

What should BC planners recognise?

A shared failure dependency.

Scenario 41

A disruption to transport prevents key staff reaching the office while systems remain operational.

Which continuity dependency?

Transport / workforce accessibility.

Scenario 42

Why should BC exercises sometimes introduce additional unexpected problems?

Best answer?

To test decision-making and resilience when assumptions fail.

Scenario 43

The company has a backup supplier but has never contacted it during an exercise.

What remains?

An unvalidated continuity assumption.

Scenario 44

What is the primary distinction between 7.12 and 7.13?

Answer?

7.12 tests DR plans; 7.13 participates in broader Business Continuity planning and exercises.

Scenario 45

Management asks for the central purpose of Business Continuity.

Best answer?

Maintain the organisation's critical products, services and business activities at an acceptable level during disruption and support an orderly return to normal operations.

CISSP Exam Perspective

Recognise the Clue Words

Keep Business Operating

Broad resilience.

Business Continuity

Restore IT

Technology recovery.

Disaster Recovery

Impact of Disruption

Business analysis.

BIA

What Must Continue?

Prioritisation.

Critical Business Activity

Maximum Disruption

Business limit.

MTD

Recovery Target

Technology / service.

RTO

Acceptable Data Loss

Recovery point.

RPO

Supplier Stops

External dependency.

Supply Chain Continuity

Alternative Provider

Continuity option.

Supplier Diversification

Office Unavailable

Premises.

Alternate Workplace

Staff Work From Home

Workforce strategy.

Remote Continuity

System Offline ยท Process Continues

Alternative method.

Manual Workaround

Reduced Service

Essential capability.

Continuity Mode

Same Provider Behind Two Suppliers

Hidden dependency.

Concentration Risk

Discuss Continuity Scenario

Exercise.

Tabletop

Plan No Longer Matches Business

Lifecycle.

Plan Maintenance

Exercise Finds Weakness

Good outcome.

Corrective Action

Normal Systems Return

Exit continuity.

Reconciliation / Normalisation

BC Plan Stored on Failed System

Plan availability.

Alternate Copy

Critical Specialist Missing

People.

Cross-Training / Alternate Personnel
โš ๏ธ Common CISSP Mistakes Business Continuity is broader than IT recovery
BC โ‰  DR

BC maintains business capability. DR restores technology.

BC โ‰  Only Technology

People, premises, suppliers and processes matter too.

Application Available โ‰  Business Continuous

A critical supplier or workforce dependency may still have failed.

Everything โ‰  Critical

Continuity planning requires meaningful prioritisation.

BIA โ‰  Risk Assessment

BIA focuses on business impact from disruption and the requirements for continuity.

MTD โ‰  RTO

MTD is business tolerance. RTO is a recovery target.

RTO โ‰  RPO

RTO concerns time. RPO concerns recoverable data.

Continuity โ‰  100% Normal Capacity

Essential capability may continue at a predefined reduced level.

Outsourced โ‰  No Continuity Responsibility

Supplier failure can still create business impact.

Two Suppliers โ‰  True Diversity

They may share the same upstream dependency.

Remote Work โ‰  Automatic Continuity

Connectivity, devices, identity and security must support it.

Manual โ‰  Uncontrolled

Manual workarounds still require appropriate security and authorisation.

Temporary โ‰  Permanent

Continuity procedures should eventually return to normal controls.

Manual Transaction โ‰  Finished Forever

Reconciliation may be required when normal systems return.

Plan Written โ‰  Plan Usable

Exercise it.

Plan Stored โ‰  Plan Available

It must remain accessible during disruption.

Plan Accessible โ‰  Plan Public

Sensitive continuity information still requires protection.

Exercise Finds Problems โ‰  Exercise Failure

Discovering weaknesses is a major purpose of exercising.

Finding Recorded โ‰  Finding Corrected

Assign actions and owners.

Correction Made โ‰  Correction Proven

Retest where appropriate.

Last Year's Plan โ‰  Today's Business

Organisations, technologies and suppliers change.

7.12 โ‰  7.13

7.12 tests DR plans. 7.13 covers broader Business Continuity planning and exercises.

Quick Reference

If you see...Think...
Keep critical activity operatingBusiness Continuity
Restore technology after disasterDisaster Recovery
Impact of business disruptionBIA
Maximum tolerated disruptionMTD
Target recovery timeRTO
Target recovery pointRPO
Process relies on external companyExternal Dependency
Two suppliers use same upstream providerConcentration / Common Dependency
Normal office unavailableAlternate Workplace / Remote Work
Application unavailable but activity continuesManual Workaround
Operate only most important servicesPrioritised Continuity
Discuss disruption scenarioBC Tabletop
Plan does not match current organisationPlan Maintenance
Exercise identifies weaknessCorrective Action
Manual records entered after recoveryReconciliation
Only specialist unavailableCross-Training / Alternate Personnel
Corporate communications failAlternate Communications
Supplier recovery slower than business requirementContinuity Gap

BC Core Memory Aid

WHAT? Critical business activity
IMPACT? What happens if it stops?
WHEN? How long can we tolerate it?
DEPENDS? What resources are required?
ALTERNATIVE? How else can we operate?
EXERCISED? Does it work?

Continuity Resource Memory Aid

PEOPLE Who performs it?
PLACE Where?
PROCESS How?
PLATFORM What technology?
PROVIDER Which supplier?
PROTECTED INFO What data?

Critical Distinctions

BC Keep business going
DR Restore technology
IR Control security incident
BIA Understand business impact
MTD Business tolerance
RTO Recovery target
RPO Data target

7.13 Master Memory Aid

IDENTIFY Critical activities
ANALYSE Business impact
PRIORITISE What matters first?
DEPENDENCIES People ยท place ยท tech ยท supplier
STRATEGY How will activity continue?
PLAN Who does what?
EXERCISE Practise
IMPROVE Fix what fails

Identify โ†’ Analyse โ†’ Prioritise โ†’ Continue โ†’ Exercise โ†’ Improve

The Business Continuity Leader's Questions

WHAT? Which products and services are critical?
IMPACT? What happens when they stop?
HOW LONG? What disruption can we tolerate?
PEOPLE? Who is required?
PLACE? Where can they operate?
TECH? Which systems are required?
DATA? Which information is essential?
SUPPLIER? Which external dependencies matter?
ALTERNATIVE? How else can the process operate?
SECURE? Are continuity arrangements appropriately controlled?
COMMUNICATE? How will stakeholders coordinate?
EXERCISED? Do we know the strategy works?
IMPROVED? Were findings actually fixed?

Key Takeaways

CISSP 7.13 is: Participate in Business Continuity planning and exercises.

The current CISSP outline does not provide separate sub-bullets under objective 7.13.

Business Continuity focuses on maintaining important business activities during disruption.

Disaster Recovery focuses more specifically on recovering disrupted technology.

BC = keep the business operating. DR = restore the technology.

Disaster Recovery can therefore form part of a broader Business Continuity strategy.

Business Continuity also covers disruptions involving people, premises, suppliers, information, utilities and business processes.

A technology failure is not required before Business Continuity becomes relevant.

A pandemic, building closure, transport failure or supplier collapse can create major continuity problems while every server remains operational.

The BIA is a fundamental input to continuity planning.

It identifies important business activities and analyses how disruption affects the organisation.

Impact may include financial, operational, legal, regulatory, safety, customer and reputational consequences.

Impact usually changes as disruption continues.

Something that is tolerable for ten minutes may be unacceptable after ten hours.

Business Continuity therefore requires meaningful prioritisation.

If everything is critical, nothing has genuinely been prioritised.

MTD represents how long a business process can be disrupted before significant harm occurs.

RTO establishes the target for restoring the required capability.

RPO establishes the target for recoverable information.

MTD = business tolerance. RTO = recovery time target. RPO = recovery-data target.

Recovery capability must support the business tolerance identified by the BIA.

Continuity does not necessarily require 100% normal service.

During disruption, the organisation may deliberately provide only essential products or services at an acceptable reduced level.

Critical business processes depend on resources.

Important dependency categories include people, premises, technology, information, utilities, suppliers, facilities and transport.

Continuity planning should identify these dependencies before disruption occurs.

External dependencies are particularly important.

Outsourcing a business activity or technology service does not remove the impact if that service fails.

Outsourced service โ‰  outsourced business risk.

Supplier concentration should also be considered.

Two suppliers may appear independent while relying on the same cloud platform, manufacturer, data centre or telecommunications provider.

Continuity strategies provide alternative ways to maintain the business activity.

They can include alternate locations, remote work, alternate suppliers, manual procedures, workforce redeployment, reduced service and technology recovery.

Manual workarounds can be useful when normal technology is unavailable.

However:

manual โ‰  uncontrolled.

Appropriate authorisation, segregation of duties, records and reconciliation may still be required.

Manual processes may also have limited capacity and may become unsustainable during long disruptions.

Remote working can provide continuity when premises are unavailable.

It requires more than simply telling employees to work from home.

Devices, connectivity, identity, authentication, communications, capacity, support and security must all be considered.

Workforce continuity also requires cross-training and alternate personnel.

A critical process should not depend unnecessarily on one individual.

Premises continuity considers loss of access as well as physical destruction.

Authorities may make a perfectly intact building unavailable for days or weeks.

Information needed for continuity must also remain accessible.

Emergency contacts and continuity procedures stored only inside failed infrastructure may be unavailable when needed.

Continuity plans themselves can contain sensitive operational information.

They therefore need both: availability and appropriate protection.

Business Continuity communications should cover employees, management, suppliers, customers and other appropriate stakeholders.

Alternate communication mechanisms may be required when normal channels depend on affected infrastructure.

Continuity plans should identify activation criteria, authority, roles, priorities, procedures and communication arrangements.

Plans should also address how the organisation eventually returns to normal operations.

Manual or temporary transactions may need to be reconciled when normal systems return.

Temporary continuity exceptions should also be removed appropriately.

Business Continuity plans must be exercised.

Exercises can examine decisions, people, facilities, processes, suppliers and technology.

BC exercises can include discussion-based scenarios, walkthroughs, simulations and operational exercises depending on the organisation's objectives and risk.

These should not be confused with additional official ISC2 7.13 sub-bullets.

Objective 7.12 focuses specifically on testing Disaster Recovery plans.

Objective 7.13 is broader.

7.12 asks: can technology recover? 7.13 asks: can the business continue?

Exercises should have a defined objective.

Useful scenarios can test loss of premises, workforce, suppliers, communications or technology.

Exercise scenarios can also introduce unexpected complications to test decision-making.

For example, the primary decision-maker may be unavailable or an alternate supplier may also experience disruption.

Business Continuity exercises should evaluate people as well as procedures.

Teams should know what to do, where to operate and how to communicate.

Continuity mode does not create a security-free environment.

Temporary processes should preserve an acceptable security posture even when the normal control mechanism cannot operate.

Exercises should produce findings and corrective actions.

A continuity exercise that discovers a serious weakness has produced valuable information.

Finding a problem during an exercise is better than discovering it during the disruption.

Findings should be analysed, assigned to owners and corrected.

Important corrections should subsequently be exercised again.

Business Continuity plans must also be maintained as organisations change.

New technology, offices, suppliers, organisational structures and regulatory requirements can invalidate old continuity arrangements.

Planning around loss of capability can sometimes be more reusable than planning only around specific named disasters.

For example: loss of premises can occur because of fire, flooding, structural damage, security incidents or an external cordon.

Continuity planning should also recognise cascading disruption.

A regional event may simultaneously affect power, telecommunications, transport, suppliers and workforce availability.

The central CISSP principle is:

identify the business activities that must continue, understand the impact of their disruption and their critical dependencies, establish practical alternative ways to maintain those activities, document who will do what, exercise the arrangements and continuously improve them so that the organisation can continue delivering what matters when normal operations are unavailable.

๐Ÿ“š Sources & Further Reading Business Continuity, BIA and exercise references