1.1

Policy and Procedure

Is business continuity plan documented and implemented?

BCM New client test nodes

Medium

1.2

Policy and Procedure

Whether the scope and objectives of a BCP are clearly defined in the policy document? (Scope to cover all critical activities of business. Objectives should clearly spell out outcomes of the BCP)

BCM New client test nodes

Medium

1.3

Policy and Procedure

Whether there exist any exceptions to the scope of BCP i.e. in terms of location or any specific area, and whether the management has justifications for exclusion of the same.

BCM New client test nodes

Medium

1.4

Policy and Procedure

What is the time limit for such exclusion and what is the current strategy of covering such exclusions

BCM New client test nodes

Medium

1.5

Policy and Procedure

Are the policy and procedure documents approved by the Top Management? (Verify sign off on policy and procedure documents and budget allocations made by the management for a BCP)

BCM New client test nodes

Medium

1.6

Policy and Procedure

Does the business continuity plan ensure the resumption of IS operations during major information system failures? (Verify that the IS disaster recovery plan is in line with strategies, goals and objectives of corporate business continuity plan).

BCM New client test nodes

Medium