Business Continuity Management (BCM)
Business continuity management is the management system that keeps critical business processes running through severe disruption — IT outages, building damage, loss of key staff. It starts with a business impact analysis, from which recovery times, contingency plans and fallback options are derived. The governing references are ISO 22301:2019 as the certifiable standard and BSI Standard 200-4, published on 14 June 2023, which supersedes the earlier Standard 100-4. Disaster recovery is the IT-technical part of BCM, not a substitute for it.
Business Continuity Management (BCM) in practice
BSI Standard 200-4 defines three cumulative maturity stages: a reactive BCMS as the minimum capability for handling acute emergencies, a build-up BCMS as the intermediate step, and a standard BCMS as the complete management system. The staging is deliberate, so smaller organisations can start at the bottom and grow; compatibility with ISO 22301:2019 is built in.
The sequence is the same in both references. First, the business impact analysis identifies time-critical business processes and the resources they depend on — IT systems, data, people, premises, suppliers. From that follow the maximum tolerable period of disruption per process and, derived from it, the RTO and RPO targets for the supporting technology. Only then are strategies chosen: redundancy, an alternate site, replacement procurement, or a controlled manual fallback.
Documentation lives in business continuity and recovery plans that must be readable without access to the failed environment — an emergency manual stored only on the encrypted file server is worthless when it is needed. Exercises escalate from plan review through tabletop tests to full simulations, usually at least annually. For regulated organisations BCM is not optional: NIS2 lists business continuity, backup management and crisis management in Article 21(2) among the minimum measures, mirrored in Germany in Section 30 BSIG.