The BCMMETRICS self assessment tool and its real time reporting revealed a number of common trends affecting the successful implementation of “low” to “moderately” compliant BCM programs:
1. MANAGEMENT ROADMAP/REPORTING INCONSISTENT OR LACKING – In many cases, BCM Offices simply lack documentation of a BCM Program roadmap and management status reporting. Without knowing where you are going and/or where you stand, leaves the future up in the air.
2. LACK OF DOCUMENTED STANDARDS – Majority of BCM programs have a policy but lack the documented standards (Recovery Plan Development, Alternate Work Area, Recovery Strategies, Plan Maintenance, etc.) needed to guide the execution of the other key dimensions (Crisis Management, Business Recovery, Disaster Recovery) of the program. Without documented standards, organizations do not have a clear roadmap of BCM expectations.
3. IT AND BUSINESS ALIGNMENT ABSENT – There is a clear lack of alignment between Information Technology and the business. Business Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) are not being regularly aligned with Information Technology and their current recovery capabilities. Often, actual recovery times (RTAs) and recovery points (RPAs) are not known or communicated.
4. INCONSISTENT APPLICATION OF RECOVERY STRATEGIES – Due to lack of strategy standards, BCM programs are often left to haphazardly identify recovery strategies/solutions across the business and Information Technology. Recommended recovery strategies/solutions need to be pre-defined and approved for each level of Recovery Time Objective (RTO) and Recovery Point Objective (RPO) to ensure consistency in application of strategies and solutions.
5. RECOVERY EXERCISE TYPES INCONSISTENT WITH LEVEL OF CRITICALITY – BCM Offices are not using increasingly complex recovery exercises (tabletop, functional, full relocation exercise, etc.) to validate the ability of businesses and Information Technology to recover the critical business processes and systems/applications of the organization.
6. TRAINING AND AWARENESS NOT IMPLEMENTED AT ALL LEVELS- BCM Offices have yet to implement training at all levels of the organization including senior management, recovery teams and general employees. It is critical that all levels of the organization are educated to ensure comprehensive knowledge and awareness.