Types of BCP Plans

Plan

Purpose

Scope

Plan Relationship

Business Continuity Plan

Provides procedures for sustaining mission/business operations while recovering from a significant disruption

Addresses mission / business processes at a lower or expanded level from COOP MEFs

Mission/business process focused plan that may be activated in coordination with a COOP plan to sustain non-MEFs.

Continuity of Operations (COOP) Plan  

Provides procedures and guidance to sustain an organization’s MEFs at an alternate site for up to 30 days; mandated by federal directives.

Addresses MEFs at a facility; information systems are addressed based only on their support of the mission essential functions.

MEF focused plan that may also activate several business unit-level BCPs, ISCPs, or DRPs, as appropriate.  

Crisis Communications Plan

Provides procedures for disseminating internal and external communications; means to provide critical status information and control rumors.

Addresses communications with personnel and the public; not information system- focused.

Incident-based plan often activated with a COOP or BCP, but may be used alone during a public exposure event.

Critical Infrastructure Protection (CIP) Plan

Provides policies and procedures for protection of national critical infrastructure components, as defined in the National Infrastructure Protection Plan. 

Addresses critical infrastructure components that are supported or operated by an agency or organization.

Risk management plan that supports COOP plans for organizations with critical infrastructure and key resource assets.  

Cyber Incident Response Plan

Provides procedures for mitigating and correcting a cyberattack, such as a virus, worm, or Trojan horse.

Addresses mitigation and isolation of affected systems, cleanup, and minimizing loss of information.  

Information system- focused plan that may activate an ISCP or DRP, depending on the extent of the attack.  

Disaster Recovery Plan (DRP)

Provides procedures for relocating information systems operations to an alternate location.

Activated after major system disruptions with long-term effects.

Information system- focused plan that activates one or more ISCPs for recovery of individual systems.

Information System Contingency Plan (ISCP)

Provides procedures and capabilities for recovering an information system.

Addresses single information system recovery at the current or, if appropriate alternate location.

Information system- focused plan that may be activated independent from other plans or as part of a larger recovery effort coordinated with a DRP, COOP, and/or BCP. 

Occupant Emergency Plan (OEP)

Provides coordinated procedures for minimizing loss of life or injury and protecting property damage in response to a physical threat. 

Focuses on personnel and property particular to the specific facility; not mission/business process or information system based. 

The incident-based plan that is initiated immediately after an event, preceding a COOP or DRP activation.

 
Additional Notes:
Identification of Downtime
Response v. Recovery
BIA Business Impact Analysis – Recovery Point Objective
Business impact analysis has to consider cost-effectiveness
Business functional priorities
Timeframe for recovery
Resource requirements
Look at the impact to an asset-based on a vulnerability to a threat
Vulnerability assessment is to build an appropriate recovery strategy for that environment
Maximum tolerable downtime MTD is the point of no return
MTD is used to define resource requirements in CIP
MTD and RTO - Time is Critical
MTD – Maximum Tolerable Downtime is how long the business will tolerate disruption of mission-critical functions
RTO – Recovery Time Objective is how long a system/process can be down before the mission is impacted
Types of testing
Main Menu