BCI GPG Edition 7.0: Complete Glossary

Companion resource to my CBCI study series. A complete, compiled glossary of all 49 essential BCI GPG 7.0 terms, standard ISO definitions, and exam-critical metrics in one easy-to-read reference guide.

Paul O'Brien
5 min read
Dark blue banner titled "Complete Glossary: Essential Terms and Definitions for BCI GPG 7.0" by Paul O'Brien Insights.
Companion resource header for the BCI GPG 7.0 Complete Glossary by Paul O'Brien Insights.

CBCI Study Series · Companion Resource

A foundational component of passing the Certificate of the Business Continuity Institute (CBCI) examination is mastering the terminology. The BCI Good Practice Guidelines (GPG) Edition 7.0 glossary is fully aligned with ISO standards (such as ISO 22301:2019, ISO 22300:2021, and ISO 22316:2017) while featuring key practitioner-led terms. Below is the complete, compiled glossary of terms, definitions, and official sources to serve as a companion study guide for your exam prep.

Term Official BCI/ISO Definition Official Source
Activity One or more tasks with defined output. ISO 22301:2019
Audit Systematic, independent, and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled. ISO 22301:2019
Business continuity (BC) The capability of an organisation to continue the delivery of products and services within acceptable time frames at a predefined capacity during a disruption. ISO 22301:2019
Business continuity champions Persons tasked with supporting the BCMS from the perspective of their area of expertise, by inputting and maintaining the system and periodically updating documentation. GPG Edition 7.0
Business continuity management (BCM) The elements of BCM are as follows: a) Operational planning and control. b) BIA and risk assessment. c) BC strategies and solutions. d) BC plans and procedures. e) Exercise programme. f) Evaluation of BC documentation and capability. ISO 22313:2020
Business continuity plan (BCP) Documented information that guides an organisation to respond to disruption and resume, recover and restore the delivery of products and services consistent with its BC objectives. ISO 22301:2019
Business continuity requirements The time frames, resources, and capabilities necessary to continue to deliver the prioritised products, services, processes, and activities following a disruption. GPG 2018
Business impact analysis (BIA) A process of analysing the impact over time of a disruption on the organisation. ISO 22301:2019
Competence The ability to apply knowledge and skills to achieve the intended result. ISO 22301:2019
Controls Measure that maintains or modifies risk. Controls include but are not limited to any process, policy, device, practice, or other conditions or actions which maintain or modify risk. ISO 22300:2021
Crisis An unstable condition involving an impending abrupt or significant change that requires urgent attention and action to protect life, assets, property, or the environment. ISO 22300:2021
Crisis management Coordinated activities to lead, direct and control an organisation with regard to crisis. ISO 22361:2022
Disruption Incident whether anticipated or unanticipated, that causes an unplanned, negative deviation from the expected delivery of products and services according to an organisation’s objectives. ISO 22300:2021
Incident An event that can be, or could lead to, a disruption, loss, emergency, or crisis. ISO 22301:2019
Injects Individual timeline events that are part of an exercise. They may include simulated media news clips, website articles, social media feeds, telephone calls, emails, and text messages. GPG Edition 7.0
Interested parties A person or organisation that can affect, be affected by, or perceive itself to be affected by a decision or activity. Note: this is the preferred term – stakeholder is permitted. ISO 22300:2021
Invocation The act of declaring that an organisation’s BC arrangements need to be put into effect in order to continue the delivery of key products or services. ISO 22300:2021
Management system Set of interrelated or interacting elements of an organisation to establish policies and objectives and processes to achieve those objectives. ISO 22301:2019
Maximum tolerable period of disruption (MTPD) Time frame within which the impacts of not resuming activities would become unacceptable to the organisation. ISO 22301:2019
Minimum business continuity objective (MBCO) The minimum capacity or level of services or products that is acceptable to an organisation to achieve its business objectives during a disruption. ISO 22300:2021
Organisation The person or group of people that has its own functions with responsibilities, authorities, and relationships to achieve its objectives. ISO 22301:2019
Organisational culture The values, attitudes and behaviour of an organisation that contribute to the unique social and psychological environment in which it operates. ISO 22316:2017
Organisational resilience The ability of an organisation to absorb and adapt to a changing environment. ISO 22316:2017
Outsource Acquisition of services (with or without products) in support of a business function for performing activities using suppliers’ resources rather than the acquirer’s. ISO/TS 27036-1:2021
Personnel People working for and under the control of the organisation. ISO 22301:2019
Policy Intentions and direction of an organisation as formally expressed by its top management. ISO 22301:2019
Prioritised activities Activity to which urgency is given in order to avoid unacceptable impacts to the business during a disruption. ISO 22301:2019
Priority suppliers Priority suppliers are those who support prioritised activities and are identified as having the greatest impact if they fail to deliver resources, thereby impacting the organisation’s ability to deliver its own products or services. GPG Edition 7.0
Process Set of interrelated or interacting activities which transform inputs into outputs. ISO 22301:2019
Product and service The output or outcome provided by an organisation to interested parties. ISO 22301:2019
Programme Group of programme components managed in a coordinated way to realise benefits. ISO 21503:2022
Recovery point objective (RPO) The point to which information used by an activity is restored to enable the activity to operate on resumption to predefined levels. ISO 22300:2021
Recovery time objective (RTO) The time frame within the MTPD for resuming disrupted activities at a specified minimum acceptable capacity. ISO 22301:2019
Resources All assets (including plant and equipment), people, skills, technology, premises, and supplies and information (whether electronic or not) that an organisation must have available to use, when needed, in order to operate and meet its objectives. ISO 22301:2019
Risk Risk is defined as the effect of uncertainty on objectives. An effect is a deviation from the expected. It can be positive, negative or both and can address, create, or result in opportunities and threats. ISO 31000:2018
Risk assessment Overall process of risk identification, risk analysis, and risk evaluation. ISO 31000:2018
Risk management Coordinated activities to direct and control an organisation with regard to risk. ISO 31000:2018
Risk source Element which alone or in combination has the potential to give rise to risk. ISO 22300:2021
Risk treatment The process of modifying risk. ISO 22300:2021
Scenario A scenario is a pre-planned storyline that drives an exercise, as well as the stimuli used to achieve exercise project performance objectives. ISO 22300:2021
Service level agreement (SLA) A commitment between a product or service provider and a client organisation, aspects of which would include quality, availability, responsibilities, and continuity capabilities, which are agreed upon between the two parties. GPG Edition 7.0 / ISO 22318:2021
Simulation A simulation is the imitative representation of the functioning of one system or process by means of the functioning of another. ISO 22300:2021
Stakeholder This is a person or organisation that can affect, be affected by, or perceive itself to be affected by a decision or activity. Note: stakeholder is permitted, interested party is preferred. ISO 22301:2019
Supply chain continuity management (SCCM) Management process that identifies potential impacts to an organisation from disruption to its supply chain and provides an approach to manage and protect the organisation’s business activities from supply chain disruption. ISO 22318:2021
Test A unique and particular type of exercise which incorporates an expectation of a pass or fail element within the aim or objectives of the exercise being planned. ISO 22300:2021
Threat A potential cause of an unwanted incident that may result in harm to individuals, assets, a system or organisation, the environment, or the community. ISO 22301:2019
Top management A person or group of people who directs and controls an organisation at the highest level. ISO 22301:2012
Workforce People/workers who provide a service or input to contribute to the business or organisational outcomes. This can include employees, contractors, and volunteers. GPG Edition 7.0
Workplace A workplace is any location where people conduct business for their employer or themselves. GPG Edition 7.0