To get the best help for your situation, first answer the questions on the guide's start page.
- Guide's start page
- Introduction to digital security risk management
- Risk management
- Safety and security management
- Continuity management and preparedness
- Information security
- Data protection
- Checklist
Decide on the continuity and preparedness processes
Find out what are the critical targets and functions
Your organisation must identify the operations that are critical for the operation of itself and its stakeholders, as developing their processes of preparedness and continuity management is a priority for your organisation.
For example, you can use support material published by the Digital and Population Data Services Agency to categorise critical targets:
Ensure roles and responsibilities
Necessary for responsibilities and roles:
- identification of critical resources and
- ensuring competent substitutes
- ensuring that relevant persons know what is expected of them.
Communicate the roles and responsibilities
In risk management related to preparedness and continuity management, it is important to communicate and implement the roles and responsibilities of the entire organisation. All employees must also know to whom or where they should submit the deviation report if they detect something abnormal.
Monitor the situation picture
The organisation must monitor the situation picture in both normal conditions and exception conditions. The situation picture should take into account the entire operating environment of the organisation, which also includes the operating environment that is essential for the key stakeholders.
The building of a situation picture should be planned so it maintains the critical functions of the organisation in all situations. The situation picture of normal conditions must be monitored regularly and continuously, similar to the annual clock.
Ensure that instructions for the staff are up to date
All employees of the organisation are responsible for the success of preparedness and continuity management. Ensure that the employees have sufficient competence in preparedness
- processes
- functions
- roles
- responsibilities.
Establish clear and regular reporting processes
You should create regular reporting processes for preparedness and continuity management, both in normal and unusual conditions. The processes must also be documented.
In order for reporting to improve the risk management related to precautionary measures and continuity management, the reporting processes must be clear, regular and continuous.