> ## Content Index
> Fetch the complete content index at: https://paulobrien.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# PP5: Enabling Solutions
- URL: https://paulobrien.com/pp5-enabling-solutions/
- Published: 2026-08-25T16:34:59.000Z
- Updated: 2026-08-25T17:47:02.000Z
- Description: Part 5 of 6 in my CBCI study series. A practical breakdown of BCI GPG 7.0 PP5: Enabling Solutions—moving from abstract plans to operational response structures, developing concise playbooks, and managing the journey back to BAU.
- Author: Paul O'Brien
- Tags: CBCI Study Series, PP5: Enabling Solutions

## CBCI Study Series · Professional Practice 5 of 6

BCI Good Practice Guidelines (GPG 7.0)

### Operationalising the Strategy: A Study Guide to BCI PP5 (Enabling Solutions)

Introduction: My Journey from 'Drawing Board' to 'Active Duty'

In my previous post, [PP4: Solutions Design](https://paulobrien.com/tag/pp4-solutions-design/) (where we explored strategies and solutions for physical and technical resources), we designed some truly beautiful architectures on paper. But as I moved into my study preparation for PP5: Enabling Solutions, I came across a massive reality check. A strategy on paper is like a blueprint for an airplane—it is mathematically perfect, but it won't fly until you assemble the fuselage, train the crew, and write the emergency checklist.

This is the precise bridge where we move from PP4 (Design) to PP5 (Enabling Solutions). This technical practice is about operationalising our strategic designs. It is the raw mechanics of business continuity: building the team hierarchies, drafting the actual emergency playbooks, securing the crisis communications channels, and—crucially—mapping out the road back to normal. In my own study journey, grasping how a single incident can cascade through operational, tactical, and strategic levels was a major lightbulb moment.

Here are my core, exam-focused study notes to help you master how we operationalise recovery to ace your CBCI exam.

#### 1\. The Three Core Pillars of Enabling Solutions

To successfully translate solutions into operational capabilities, BCI candidates must understand that PP5 consists of three distinct, interrelated activities:

**• Implementing BC Solutions:** The process of operationalising and setting up the physical/digital resources, contracts, or redundant architectures agreed upon in PP4 (Design) so that they are fully ready for activation.

**• Designing the Response Structure:** Designating and training the specific, hierarchical response teams required to command, control, and communicate during an incident.

**• Developing and Managing BC Plans:** Creating actionable, direct, and concise guidance documents that detail the precise response steps and procedures those response teams must follow.

Crucially, the GPG reminds us that the BC Professional is ultimately accountable for ensuring that these solutions are implemented, but they do not do it alone. They must collaborate closely with procurement, legal, risk, and IT disaster recovery teams, ensuring that every implementation undergoes rigorous validation to verify that it meets the approved requirements.

#### 2\. Designing the Response Structure: Command, Control, and Communication

The purpose of the response structure is to establish a clear, documented hierarchy of teams to manage an incident, regardless of its cause. An effective response structure is typically built around three familiar levels of activity—Strategic, Tactical, and Operational. For the CBCI exam, you must understand exactly how these teams differ in their focus, authority, and plan ownership:

| Response Level | Strategic & Operational Focus                                                                                                                                | Primary Plan Owned                                       | Typical Leader                                       |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------- | ---------------------------------------------------- |
| Strategic      | Focuses on threats to viability, reputation, brand, and long-term objectives. Manages high-level communication with stakeholders and regulators.             | Crisis Management Plan / Crisis Comms Plan               | Top Management (e.g., CEO, Board Member)             |
| Tactical       | Coordinates the response across multiple business units. Directs resource acquisition, manages team coordination, and bridges Strategic/Operational actions. | Alternate Work Area / Transportation / Procurement Plans | Head of Facilities, HR, or Procurement               |
| Operational    | Protects life, safety, and physical premises. Executes localized manual workarounds, recovers systems, and continues prioritised business tasks.             | Emergency Response, Business Unit, & Tech Recovery Plans | Business Unit Managers, ICT Manager, Facilities Lead |

🚨

****EXAM TRAP ALERT:** These teams do not always activate simultaneously. A localised IT or server crash might only trigger an operational Technology Recovery Plan. If the outage persists for several days, threatening statutory or regulatory targets, it escalates to a tactical level to coordinate alternate workarounds, and finally to a strategic level if a public reputation crisis unfolds.

#### 3\. Documented Communications and Warning Plans: Buying Time Under Pressure

GPG 7.0 places massive emphasis on warning and communication capability during an incident. When a disruption strikes, clear and fast messaging can literally be a matter of life or death (e.g., building evacuations) or reputational survival (e.g., data breach notifications). To build a compliant communication structure, focus on these two components:

**• Warning Plans:** These plans detail exactly how to alert recipients so they can take protective action. They must identify recipients (on-site staff, remote workers, suppliers, and third parties), consider timing (in-hours vs. out-of-hours), and utilize multiple communication channels (call lists, call trees, public address systems, or automated notification software).

**• Crisis Communications:** To protect the organisation's reputation and provide a 'central source of truth', a designated spokesperson must manage media relations. The GPG highly recommends drafting pre-written, pre-approved holding statements in advance to buy the incident teams time to investigate the facts before making public announcements.

🚨

****EXAM TRAP ALERT: The 'No Duff' Code Word in Exercises**  
When exercising your warning and communication procedures under pressure, there is a risk of a simulated warning being mistaken for a real incident. To prevent this, the GPG notes that all communications must clearly state 'Exercise Only.' Furthermore, organisations use a distinctive military-derived code word like 'No Duff' to signal an immediate suspension of the exercise. If a participant shouts 'No Duff', it means a real-world emergency has occurred, and all teams must instantly halt the exercise and respond to the live event.

#### 4\. Developing and Managing Plans: The Anatomy of a GPG-Compliant Playbook

A Business Continuity Plan is not a theoretical essay or a dense compliance report. It is a concise, action-oriented guidance document designed to be read under extreme pressure. To ensure plans are highly usable, the GPG outlines the 'Six Qualities' that every plan must possess:

**• Direct:** Provide clear, action-oriented instructions and direct steps.

**• Unambiguous:** Avoid jargon, abbreviations, and complex language that could be open to multiple interpretations.

**• Verifiable:** Include checkpoints to prove that instructions have been carried out successfully.

**• Adaptable:** Remain flexible enough to handle unexpected variations of an incident.

**• Concise:** Strip out unnecessary fluff, leaving only what is useful during a crisis.

**• Ordered / Relevant:** Organised logically so that the user does not have to waste precious minutes searching for critical contacts or procedures.

Every single plan, whether Strategic, Tactical, or Operational, must contain standard structural components. When writing your plans, always ensure the following elements are clearly documented: (1) Purpose, Scope, and Objectives; (2) The designated response team and their alternates; (3) Clear activation criteria and triggers; (4) Specific individuals authorised to activate the plan; (5) Resource mobilisation and meeting locations (physical or virtual); (6) Prompts for immediate action and checklists; (7) Internal and external escalation guidelines; and (8) Formal procedures to stand down once the incident is resolved.

#### 5\. The Road Back: Returning to Business-As-Usual (BAU)

A very common gap in corporate business continuity planning is focusing entirely on the initial response while completely ignoring how the organisation will safely deactivate its temporary workarounds and transition back to normal operations. Under ISO 22301 and BCI PP5, having a documented process to return to BAU is a mandatory requirement.

GPG Figure 2 highlights that returning to BAU requires a dedicated plan because the organisation is often highly vulnerable when transitioning. This transition typically involves one of three scenarios:

**• Returning from alternate resources to primary resources:** Moving personnel and data back to the original physical office or primary database once they are repaired and verified.

**• Transitioning to a 'new normal':** Establishing entirely new primary resources (such as a new office building or a completely rebuilt server infrastructure) if the original assets were permanently destroyed.

**• Resumption of lower-priority activities:** Carefully bringing back non-prioritised processes (which had longer RTOs and were suspended during the crisis) without overwhelming the newly recovered systems.

Because the exact impact and duration of an incident cannot be predicted in advance, the GPG notes that a detailed, step-by-step return to BAU plan can only be written during the active disruption itself. However, the BC Professional must ensure that a high-level framework—outlining possible options, responsibilities, data reconciliation steps, and verification procedures—is drafted and approved before any incident occurs.

#### Test Your Knowledge: BCI Exam Prep PP5 Quiz

**Question 1**

According to the BCI Good Practice Guidelines, which level of the response structure is responsible for focusing on issues threatening the organisation's reputation and viability, and must always be led by top management?

A) Operational Response Team

B) Tactical Coordination Team

C) Strategic (Crisis Management) Team

D) ICT Disaster Recovery Team

#### Answer

****Correct Answer: C**

****Explanation**: The Strategic Team (Crisis Management Team) focuses on high-level strategic issues that threaten the organisation's viability, reputation, brand, or long-term objectives, and it must always be led by a member of Top Management. Operational teams focus on localised resumption, and tactical teams coordinate across units.

**Question 2**

During a simulated crisis exercise, an actual real-world emergency occurs. Which of the following should be used immediately to halt the exercise and notify participants to transition to a live response?

A) Issue a pre-approved digital holding statement to the media.

B) Activate the dark site immediately.

C) Shout the distinctive, military-derived code word 'No Duff'.

D) Wait for the next scheduled inject in the storyboard.

#### Answer

****Correct Answer: C**

****Explanation**: The GPG notes that to avoid confusing simulated instructions with a real-world emergency, organizations use a distinctive, pre-agreed code word such as 'No Duff' (derived from the military). When called, it prompts an immediate suspension of the exercise so teams can respond to the actual real-world event.

**Question 3**

An organisation is writing its Business Continuity plans. According to BCI PP5, why is a detailed, step-by-step 'Return to BAU' plan typically NOT fully specified prior to an incident occurring?

A) Returning to BAU is entirely voluntary and is not required by ISO 22301.

B) The state of the primary resources and the exact impact of the disruption cannot be predicted in advance.

C) The BC Professional is not responsible for deactivating workarounds.

D) Return to BAU plans must only be designed by external third-party suppliers.

#### Answer

****Correct Answer: B**

****Explanation**: While a high-level framework and possible options for returning to BAU must be developed before an incident, the GPG recognises that detailed, specific steps can only be written when the actual impact, timeline, and physical state of the primary resources are clear during the disruption itself.

**Question 4**

To ensure that Business Continuity plans can be easily read and executed by team members under extreme cognitive pressure, which of the following is an essential 'Quality of a Plan' defined by the BCI?

A) It must be highly detailed and contain at least 100 pages of context.

B) It must be written in a technical academic style to demonstrate compliance.

C) It must be concise, unambiguous, and ordered logically to avoid a search for information.

D) It must rely entirely on the memory of the department's hero employees.

#### Answer

****Correct Answer: C**

****Explanation**: According to the GPG, plans must be direct, concise, unambiguous (avoiding jargon), ordered logically to prevent a search for information, and relevant to the team using them, ensuring they are highly usable under high-pressure conditions.

**Question 5**

Under GPG Table 9, which of the following pairings correctly matches a specific plan type to its typical organizational owner?

A) Crisis Communications Plan — ICT Manager

B) Technology Recovery Plan — Public Relations / Communications Manager

C) Emergency Response Plan — Facilities Manager

D) Crisis Management Plan — Individual Business Unit Managers

#### Answer

****Correct Answer: C**

****Explanation**: According to GPG Table 9 (or equivalent plan ownership structures), the Emergency Response Plan (focusing on life safety and securing the physical facility) is typically owned by the Facilities Manager. The Crisis Communications Plan is owned by the Public Relations/Communications Manager, and the Technology Recovery Plan is owned by the ICT Manager.

  
**What's Next? Moving into Technical Validation**

Now that we have established our BCMS (PP1), embraced it culturally (PP2), analysed our critical requirements (PP3), designed cost-effective strategies (PP4), and operationalised them into high-pressure response plans (PP5), we have built a complete business continuity capability. But how do we prove that it actually works before a real crisis hits? To find out, we enter the final and most dynamic chapter of the BCI syllabus: Professional Practice 6 (PP6): Validation. In my next post, we will explore how to design realistic tabletop, walkthrough, and simulation exercises, write high-impact injects, run 'no duff' safety nets, and leverage post-incident reviews to drive continuous improvement. Stay tuned, and keep building resilience!

**Next in the series:**[(PP6): Validation](https://paulobrien.com/tag/pp6-validation/)

📚

New to the series?  
Start from the beginning or jump to any chapter by visiting the [CBCI Study Series Index](https://paulobrien.com/journey-to-cbci-business-continuity-gpg-7-0/) and don’t forget to grab your copy of the companion [GPG 7.0 Glossary Study Guide](https://paulobrien.com/bci-gpg-edition-7-0-complete-glossary/)!

## 📬 Never Miss a Deep Dive

I’m breaking down the entire BCI Good Practice Guidelines (GPG 7.0) step-by-step as I prepare for the CBCI exam. If you want practical resilience breakdowns and study notes delivered straight to your inbox as they publish, subscribe below—100% free, zero spam.

Subscribe 

Email sent! Check your inbox to complete your signup. 

No spam. Unsubscribe anytime.

---

*Disclaimer: These are independent study notes compiled to assist candidates preparing for the Certificate of the Business Continuity Institute (CBCI) examination. This content is not officially endorsed, sponsored, or affiliated with the Business Continuity Institute (BCI). The official body of knowledge is the BCI Good Practice Guidelines (GPG) Edition 7.0, which can be sourced directly from the BCI.*