Alqanoni

Business Continuity Management Framework

Para. 2.1
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

BCM Governance Principle The business continuity governance framework should be defined, approved, implemented and maintained, which should be monitored by senior management. The business continuity structure should be defined and communicated to all relevant employees and third parties. Objective To direct, control and evaluate the overall approach to business continuity within the Member Organization Control Consideration: 1. Board of directors or a delegated executive member should have the ultimate responsibility for the BCM program. 2. The board of member organization, or a delegated member of senior management should allocate sufficient budget to execute the required BCM activities, 3. A BCM Committee should be established and mandated by the board of directors. 4. Senior management, such as CRO, COO, CIO, CISO, BCM manager and other relevant departments should be represented in the business continuity committee. 5. A business continuity committee charter should be developed and should reflect: a. Committee objectives b. Roles and responsibilities c. Minimum number of meeting participants d. Meeting frequency (minimum on quarterly basis) 6. A BCM function should be established. 7. A BCM manager/head should: a. Be appointed b. Have appropriate authority to manage the BCM program c. Be qualified and have appropriate experience, skills and competencies to implement and maintain the BCM program within the member organization 8. The BCM function should be adequately staffed with qualified team members 9. Cross-functional teams, consisting of strategic, tactical and operations team members should contribute in implementation and maintenance of the business continuity and disaster recovery plans. 2.2 BCM Strategy Principle A business continuity strategy should be defined and aligned with the Member Organization's overall strategic business objectives. Objective To ensure that business continuity Initiatives are in alignment with the strategic business objectives and embeds BCM as part of the good management practice within the Member Organization, in order to continual improvement In maturity. Control Consideration 1. The business continuity strategy should be defined, approved, implemented and maintained. 2. The strategy should at minimum define: a. Long-term strategic objectives for implementing and maturing the BCM program b. Road map with timelines for achieving strategic objectives c. Requirements for continual review and validation of alignment of the BCM program with strategic objectives 2.3 Business Continuity Policy Principle A business continuity policy should be defined, approved and communicated to relevant stakeholders. Objective To document the Member Organization’s commitment and objective of the business continuity program, and to communicate this to the relevant stakeholders. Control considerations 1. A business continuity policy should be defined, approved, implemented and communicated 2. The business continuity policy should at the minimum identify: a. Objectives b. Scope c. Responsibilities 3. The compliance with the business continuity policy should be monitored . 4. The effectiveness of policy implementation should be measured and periodically evaluated. 5. Scope exclusions for the BCM should be documented and periodically evaluated. The justifications for scope exclusions should be documented and approved by BCM committee and senior management.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.