> ## Content Index
> Fetch the complete content index at: https://paulobrien.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# PP1: Establishing a BCMS
- URL: https://paulobrien.com/pp1-establishing-a-bcms/
- Published: 2026-08-22T19:19:49.000Z
- Updated: 2026-08-22T21:07:18.000Z
- Description: Part 1 of 6 in my CBCI study series. A practical breakdown of BCI GPG 7.0 PP1: Establishing a BCMS—moving from organisational "heroics" to system-dependent resilience, avoiding common exam traps, and defining governance.
- Author: Paul O'Brien
- Tags: CBCI Study Series, PP1 – Establishing a BCMS

## **CBCI Study Series · Professional Practice 1 of 6**

*BCI Good Practice Guidelines (GPG 7.0)*

### Introduction: Moving from "Heroics" to "Systems"

As I dig into the BCI Good Practice Guidelines (GPG 7.0) for my CBCI study series, **PP1: Establishing a BCMS** immediately stood out to me. Unlike some modules where concepts can feel strictly theoretical, PP1 is a section I’ve actively implemented in the real world. Setting up governance, defining clear scopes, and securing executive buy-in are the bedrock of any resilient organisation. Mapping out these core requirements brings a great sense of clarity to how a BCMS operates in practice rather than just on paper.

## Exam Overview & Core Mindset

If you are preparing for your Certificate of the Business Continuity Institute (CBCI) exam, Professional Practice 1 (PP1) is your logical launchpad. This practice outlines how a Business Continuity Management System (BCMS) is designed, implemented, and governed as a structured, repeatable programme rather than a series of ad-hoc, reactive tasks.

The absolute core mindset shift that you must master for PP1 is the transition from a person-dependent model of resilience (relying on a "lone wolf" or a specific "hero" to save the day during a crisis) to a **system-dependent model**. A fit-for-purpose BCMS is not a point-in-time document; it is an ongoing, iterative cycle of continual improvement backed by top management. When a disruption occurs, recovery should succeed because of pre-validated systems, not individual heroics.

## 🚨 EXAM TRAP ALERT: The Table 1 Mapping Pitfall

This is one of the most common areas where CBCI candidates lose easy marks. Table 1 in the GPG maps out the nine core activities required to establish a BCMS, but they do not all belong to PP1! The exam loves to test these boundaries.

For example, *“Determine the objectives of the BCMS”* is not mapped to PP1—it belongs to **PP3: Analysis** (because your analytical recovery requirements like MTPDs, RTOs, and RPOs serve as your system objectives).

Memorise the GPG Table 1 mapping below to secure these easy marks on exam day:

### GPG Table 1: Core Activities & Professional Practice Mapping

| Activity Needed to Establish a BCMS                                  | Mapped Professional Practice (GPG 7.0)           |
| -------------------------------------------------------------------- | ------------------------------------------------ |
| **1\. Define the scope of the BCMS**                                 | **PP1: Establishing a BCMS**                     |
| **2\. Establish a BC policy**                                        | **PP1: Establishing a BCMS**                     |
| **3\. Establish high-level governance of the BCMS**                  | **PP1: Establishing a BCMS**                     |
| **4\. Determine the objectives of the BCMS**                         | **PP3: Analysis** (derived via BIAs)             |
| **5\. Determine how the objectives of the BCMS will be met**         | **PP4: Solutions Design**                        |
| **6\. Develop detailed operational processes & response structures** | **PP5: Enabling Solutions**                      |
| **7\. Validate the BCMS (exercises, tests, audits)**                 | **PP6: Validation**                              |
| **8\. Ensure the organization has a culture that supports BC**       | **PP2: Embracing BC**                            |
| **9\. Establish how the BCMS will be monitored & reviewed**          | **PP1: Establishing a BCMS** (high-level policy) |

## 1\. Defining the Scope (ISO 22301 Clause 4.3)

Before writing a policy or conducting a workshop, you must define the boundaries and applicability of your BCMS. Under both GPG and ISO standards, scope is usually defined in relation to high-value products and services or specific geographical locations.

- **Focus the Footprint:** The initial scope may be limited to specific areas with high value. Keeping the initial footprint focused makes the program significantly easier and more cost-effective to manage regarding risk, complexity, and cost.
- **Documenting Exclusions:** Under ISO 22301, the scope must be available as documented information. If you exclude any part of your organisation, you must formally document and explain those exclusions. Crucially, these exclusions must never compromise your organisation's overall ability or responsibility to provide business continuity as mandated by legal or regulatory requirements.

## 2\. Establishing the BC Policy (ISO 22301 Clause 5.2)

The Business Continuity Policy is a high-level statement of the organisation's intentions and direction as formally expressed by its top management.

- **The Purpose:** The policy must explain the meaning and importance of BCM, demonstrate top management commitment to continual improvement, set expectations for all workers, and establish the framework for setting recovery objectives.
- **The "Keep It High-Level" Rule:** A massive pitfall is cluttering the policy with operational details. The GPG explicitly dictates that the BC Policy should be written at a high level and must **not** include specific recovery requirements, processes, or operational response roles.

> **Why?** If you write a specific "2-hour recovery time for our database" into the policy itself, any minor technical upgrade would require you to get the entire policy formally reviewed, re-signed, and re-approved by the Chief Executive or Board. Keep operational targets in your BIA reports, and keep the policy stable.

## 3\. Governing the Program (The Separation of Duties)

Governance establishes the roles, responsibilities, and authorities needed to develop, operate, and monitor the BCMS. BCI candidates must memorise the strict division of duties outlined in Table 2:

### GPG Table 2: Roles & Core Responsibilities

| Role (BCI GPG Table 2)                        | Core Responsibility                                                                                                               | Key Exam Focus 🧠                                                                                                   |
| --------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------- |
| **Top Management**                            | Holds ultimate accountability; establishes policy; assigns roles; and allocates resources (funding, time, technology, people).    | **The Decision-Maker:** They own the risk and provide the budget. They do *not* write the plans.                    |
| **BC Professional**                           | Develops, coordinates, and facilitates the BCMS (analysis, plans, templates, and exercises).                                      | **The Facilitator:** They coordinate across the business but do *not* own the risks or make final budget decisions. |
| **BC Plan Owner**                             | Ensures their specific plan adequately delivers the required recovery capabilities to meet BIA targets.                           | **The Plan Custodian:** Accountable for the plan's viability and readiness.                                         |
| **Departmental Representative** (BC Champion) | Collects BIA data; drafts departmental procedures; coordinates local exercises; and acts as the liaison with the BC Professional. | **The Operational Link:** The hands-on contact within individual business units.                                    |
| **Incident Response Team**                    | Mobilises during a crisis to execute recovery solutions and follow the pre-drafted BC plans.                                      | **The Responders:** The tactical and operational hands during a live disruption.                                    |

## 4\. The "Interim" Crisis Management Plan

When establishing a BCMS for the very first time, conducting thorough BIAs, designing strategies, and implementing technical recovery plans takes time. To protect the organisation during this developmental gap, the GPG recommends establishing an **interim crisis management plan**.

This interim plan is supported by subject matter experts with sufficient knowledge to manage a crisis effectively prior to the development of the full BCMS. It acts as a temporary "safety net" and is later reviewed and consolidated into your final, mature BCMS.

## 🧪 Test Your Knowledge: BCI Exam Prep PP1 Quiz

### Question 1

Table 1 in the GPG maps activities needed to establish a BCMS to their relevant Professional Practices. To which Professional Practice is the activity *"Determine the objectives of the BCMS"* mapped?

**A)** PP1: Establishing a BCMS  
**B)** PP2: Embracing Business Continuity  
**C)** PP3: Analysis  
**D)** PP4: Solutions Design

#### Answer

✅ Correct Answer: C) PP3: Analysis

****Explanation:** This is a classic exam trap! While establishing objectives sounds like an administrative, program-setup task for PP1, your business continuity requirements (specifically your MTPDs, RTOs, and RPOs derived during the BIA in PP3) actually serve as the concrete objectives of your BCMS. Therefore, the activity is mapped strictly to ****PP3: Analysis**.

### Question 2

According to BCI GPG Table 2, which role is ultimately accountable for the overall effectiveness of the BCMS and holds the specific authority to allocate resources such as funding, time, and competent people?

**A)** The Business Continuity Professional  
**B)** Top Management  
**C)** The BC Plan Owner  
**D)** The Departmental Representative

#### Answer

✅ Correct Answer: B) Top Management

****Explanation:** Under both BCI and ISO 22301 standards, Top Management is ultimately accountable for the BCMS. While the Business Continuity Professional coordinates and facilitates the day-to-day program, only Top Management has the organisational authority to allocate corporate budgets, dedicate staff time, and commit technological resources.

### Question 3

A newly appointed BC Lead is drafting a corporate Business Continuity Policy. They decide to write the specific 2-hour Recovery Time Objective (RTO) for the main digital database directly into the policy text. Is this an industry good practice?

**A)** Yes, because the policy is highly visible and should contain all key recovery targets.  
**B)** Yes, because the policy is where all technical metrics must be legally documented.  
**C)** No, because the policy should be written at a level that is independent of the scope and must not include specific, frequently changing operational metrics.  
**D)** No, because the BC Policy is restricted strictly to third-party suppliers.

#### Answer

✅ Correct Answer: C) No, because the policy should be written at a level that is independent of the scope and must not include specific, frequently changing operational metrics.

****Explanation:** The Business Continuity Policy must remain a high-level, stable statement of intent. The GPG explicitly states that the policy should not include specific information such as BCMS requirements (RTOs/RPOs), processes, or operational response roles. Including specific technical parameters means that any minor change in your IT infrastructure would force you to re-draft, re-approve, and re-sign the policy at the executive board level.

---

### Question 4

When an organization is establishing a BCMS for the very first time, what does the GPG recommend implementing as a temporary "safety net" while the mature BCMS is still being developed?

**A)** An external third-party audit  
**B)** A full-scale simulation exercise  
**C)** A temporary BIA waiver  
**D)** An interim crisis management plan supported by subject matter experts

#### Answer

✅ Correct Answer: D) An interim crisis management plan supported by subject matter experts

****Explanation:** Establishing a complete, standard-aligned BCMS takes time. To protect the organisation during this development phase, the GPG recommends establishing an interim crisis management plan supported by competent internal or external experts. This temporary plan provides a basic emergency response capability and is eventually reviewed and consolidated into the final, mature BCMS once it is operational.

---

### Question 5

Under ISO 22301 Clause 4.3, when determining the scope of the BCMS, which of the following is correct regarding the exclusion of certain departments or locations?

**A)** Exclusions are never permitted under the ISO 22301 standard.  
**B)** Exclusions can be made verbally and do not require formal documentation.  
**C)** Any exclusions must be formally documented and explained, and must not affect the organisation's ability to provide business continuity.  
**D)** Exclusions are only permitted for third-party IT hosting facilities.

#### Answer

✅ Correct Answer: C) Any exclusions must be formally documented and explained, and must not affect the organization's ability to provide business continuity.

****Explanation:** ISO 22301 Clause 4.3.2 explicitly permits organizations to limit their BCMS scope (for example, to high-value prioritized products or specific locations), but mandates that any exclusions must be documented and justified. Crucially, these exclusions are only acceptable if they do not compromise the organisation's overarching responsibility to maintain business continuity for its prioritised operations.

## 📬 Never Miss a Deep Dive

I’m breaking down the entire BCI Good Practice Guidelines (GPG 7.0) step-by-step as I prepare for the CBCI exam. If you want practical resilience breakdowns and study notes delivered straight to your inbox as they publish, subscribe below—100% free, zero spam.

Subscribe 

Email sent! Check your inbox to complete your signup. 

No spam. Unsubscribe anytime.

That wraps up the core breakdown for PP1! Laying down the structural framework is only half the battle, though—getting the wider business to actually care about it is where the real work begins.

Up next, I’ll be diving into **PP2: Embracing BC** to cover organisational culture, training, and awareness. Stay tuned—PP2 is on its way!

> **Next in the series:** PP2 — Embracing Business Continuity →

---

*Disclaimer: These are independent study notes compiled to assist candidates preparing for the Certificate of the Business Continuity Institute (CBCI) examination. This content is not officially endorsed, sponsored, or affiliated with the Business Continuity Institute (BCI). The official body of knowledge is the BCI Good Practice Guidelines (GPG) Edition 7.0, which can be sourced directly from the BCI.*