BCI GPG Edition 7.0: Complete Glossary
Companion resource to my CBCI study series. A complete, compiled glossary of all 49 essential BCI GPG 7.0 terms, standard ISO definitions, and exam-critical metrics in one easy-to-read reference guide.
CBCI Study Series · Companion Resource
A foundational component of passing the Certificate of the Business Continuity Institute (CBCI) examination is mastering the terminology. The BCI Good Practice Guidelines (GPG) Edition 7.0 glossary is fully aligned with ISO standards (such as ISO 22301:2019, ISO 22300:2021, and ISO 22316:2017) while featuring key practitioner-led terms. Below is the complete, compiled glossary of terms, definitions, and official sources to serve as a companion study guide for your exam prep.
| Term | Official BCI/ISO Definition | Official Source |
|---|---|---|
| Activity | One or more tasks with defined output. | ISO 22301:2019 |
| Audit | Systematic, independent, and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled. | ISO 22301:2019 |
| Business continuity (BC) | The capability of an organisation to continue the delivery of products and services within acceptable time frames at a predefined capacity during a disruption. | ISO 22301:2019 |
| Business continuity champions | Persons tasked with supporting the BCMS from the perspective of their area of expertise, by inputting and maintaining the system and periodically updating documentation. | GPG Edition 7.0 |
| Business continuity management (BCM) | The elements of BCM are as follows: a) Operational planning and control. b) BIA and risk assessment. c) BC strategies and solutions. d) BC plans and procedures. e) Exercise programme. f) Evaluation of BC documentation and capability. | ISO 22313:2020 |
| Business continuity plan (BCP) | Documented information that guides an organisation to respond to disruption and resume, recover and restore the delivery of products and services consistent with its BC objectives. | ISO 22301:2019 |
| Business continuity requirements | The time frames, resources, and capabilities necessary to continue to deliver the prioritised products, services, processes, and activities following a disruption. | GPG 2018 |
| Business impact analysis (BIA) | A process of analysing the impact over time of a disruption on the organisation. | ISO 22301:2019 |
| Competence | The ability to apply knowledge and skills to achieve the intended result. | ISO 22301:2019 |
| Controls | Measure that maintains or modifies risk. Controls include but are not limited to any process, policy, device, practice, or other conditions or actions which maintain or modify risk. | ISO 22300:2021 |
| Crisis | An unstable condition involving an impending abrupt or significant change that requires urgent attention and action to protect life, assets, property, or the environment. | ISO 22300:2021 |
| Crisis management | Coordinated activities to lead, direct and control an organisation with regard to crisis. | ISO 22361:2022 |
| Disruption | Incident whether anticipated or unanticipated, that causes an unplanned, negative deviation from the expected delivery of products and services according to an organisation’s objectives. | ISO 22300:2021 |
| Incident | An event that can be, or could lead to, a disruption, loss, emergency, or crisis. | ISO 22301:2019 |
| Injects | Individual timeline events that are part of an exercise. They may include simulated media news clips, website articles, social media feeds, telephone calls, emails, and text messages. | GPG Edition 7.0 |
| Interested parties | A person or organisation that can affect, be affected by, or perceive itself to be affected by a decision or activity. Note: this is the preferred term – stakeholder is permitted. | ISO 22300:2021 |
| Invocation | The act of declaring that an organisation’s BC arrangements need to be put into effect in order to continue the delivery of key products or services. | ISO 22300:2021 |
| Management system | Set of interrelated or interacting elements of an organisation to establish policies and objectives and processes to achieve those objectives. | ISO 22301:2019 |
| Maximum tolerable period of disruption (MTPD) | Time frame within which the impacts of not resuming activities would become unacceptable to the organisation. | ISO 22301:2019 |
| Minimum business continuity objective (MBCO) | The minimum capacity or level of services or products that is acceptable to an organisation to achieve its business objectives during a disruption. | ISO 22300:2021 |
| Organisation | The person or group of people that has its own functions with responsibilities, authorities, and relationships to achieve its objectives. | ISO 22301:2019 |
| Organisational culture | The values, attitudes and behaviour of an organisation that contribute to the unique social and psychological environment in which it operates. | ISO 22316:2017 |
| Organisational resilience | The ability of an organisation to absorb and adapt to a changing environment. | ISO 22316:2017 |
| Outsource | Acquisition of services (with or without products) in support of a business function for performing activities using suppliers’ resources rather than the acquirer’s. | ISO/TS 27036-1:2021 |
| Personnel | People working for and under the control of the organisation. | ISO 22301:2019 |
| Policy | Intentions and direction of an organisation as formally expressed by its top management. | ISO 22301:2019 |
| Prioritised activities | Activity to which urgency is given in order to avoid unacceptable impacts to the business during a disruption. | ISO 22301:2019 |
| Priority suppliers | Priority suppliers are those who support prioritised activities and are identified as having the greatest impact if they fail to deliver resources, thereby impacting the organisation’s ability to deliver its own products or services. | GPG Edition 7.0 |
| Process | Set of interrelated or interacting activities which transform inputs into outputs. | ISO 22301:2019 |
| Product and service | The output or outcome provided by an organisation to interested parties. | ISO 22301:2019 |
| Programme | Group of programme components managed in a coordinated way to realise benefits. | ISO 21503:2022 |
| Recovery point objective (RPO) | The point to which information used by an activity is restored to enable the activity to operate on resumption to predefined levels. | ISO 22300:2021 |
| Recovery time objective (RTO) | The time frame within the MTPD for resuming disrupted activities at a specified minimum acceptable capacity. | ISO 22301:2019 |
| Resources | All assets (including plant and equipment), people, skills, technology, premises, and supplies and information (whether electronic or not) that an organisation must have available to use, when needed, in order to operate and meet its objectives. | ISO 22301:2019 |
| Risk | Risk is defined as the effect of uncertainty on objectives. An effect is a deviation from the expected. It can be positive, negative or both and can address, create, or result in opportunities and threats. | ISO 31000:2018 |
| Risk assessment | Overall process of risk identification, risk analysis, and risk evaluation. | ISO 31000:2018 |
| Risk management | Coordinated activities to direct and control an organisation with regard to risk. | ISO 31000:2018 |
| Risk source | Element which alone or in combination has the potential to give rise to risk. | ISO 22300:2021 |
| Risk treatment | The process of modifying risk. | ISO 22300:2021 |
| Scenario | A scenario is a pre-planned storyline that drives an exercise, as well as the stimuli used to achieve exercise project performance objectives. | ISO 22300:2021 |
| Service level agreement (SLA) | A commitment between a product or service provider and a client organisation, aspects of which would include quality, availability, responsibilities, and continuity capabilities, which are agreed upon between the two parties. | GPG Edition 7.0 / ISO 22318:2021 |
| Simulation | A simulation is the imitative representation of the functioning of one system or process by means of the functioning of another. | ISO 22300:2021 |
| Stakeholder | This is a person or organisation that can affect, be affected by, or perceive itself to be affected by a decision or activity. Note: stakeholder is permitted, interested party is preferred. | ISO 22301:2019 |
| Supply chain continuity management (SCCM) | Management process that identifies potential impacts to an organisation from disruption to its supply chain and provides an approach to manage and protect the organisation’s business activities from supply chain disruption. | ISO 22318:2021 |
| Test | A unique and particular type of exercise which incorporates an expectation of a pass or fail element within the aim or objectives of the exercise being planned. | ISO 22300:2021 |
| Threat | A potential cause of an unwanted incident that may result in harm to individuals, assets, a system or organisation, the environment, or the community. | ISO 22301:2019 |
| Top management | A person or group of people who directs and controls an organisation at the highest level. | ISO 22301:2012 |
| Workforce | People/workers who provide a service or input to contribute to the business or organisational outcomes. This can include employees, contractors, and volunteers. | GPG Edition 7.0 |
| Workplace | A workplace is any location where people conduct business for their employer or themselves. | GPG Edition 7.0 |
