Business Continuity Management Framework
Para. 2.8Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Crisis Management Plan Principle The Member Organization should define, approve and implement a crisis management plan that would facilitate a well-managed response for major incidents, including rapid communication to ensure overall safety to both internal and external stakeholders. Objective To ensure the Member Organization has effective crisis management plan in place and up-to-date for critical member organization products, services, business functions and processes, in case of a disruptive incident. Control considerations 1. A crisis management plan should be defined, approved and implemented. 2. The compliance with the crisis management plan should be monitored. 3. The effectiveness of the business continuity program within the crisis management plan should be measured and periodically evaluated. 4. The Member Organization should document a crisis management plan(s) that define(s) how crisis resulting from a major incident(s) will be addressed and managed, and should include at least: a. Criteria for declaring a crisis. b. The member organization should establish a command center for centralized management and an emergency command center. c. Crisis-management team members. Considering representatives of the critical products, services, functions and processes of the Member Organization (including Communications department) d. Contact details of those who are part of the crisis management team (including third-parties) e. Definition of the steps to be taken during and after a crisis or disaster (including the mandates required) f. Communication plan including the media response plan, to address the communication with the internal and external stakeholders during crisis. g. The frequency of crisis management tests 2.9 Testing Principle The Member Organization should define, approve, implement, execute and monitor regular BCP and DRP tests to train their employees and third-parties and test the effectiveness of the BC and DR plans. Objective To ensure that the Member Organization's existing BCP and DRP do work as defined and employees and third- parties are trained to execute these plans. 2.9.1 BCP Testing Control considerations 1. The Member Organization should periodically conduct BCP simulation test exercises ("at least once a year") 2. The tests should consider appropriate scenarios that are well planned with clearly defined objectives (e.g., per function, per service, per process, per location, per worst cases scenarios). The Member Organization should take into consideration to Include cyber security scenarios. 3. Defined test scenarios should cover the activation and involvement for crisis management team. 4. After the completion of the above individual tests, each Member organization should consider conducting an integrated BCM test for all critical services, business processes and functions. 2.9.2 DRP Testing Control considerations The Member Organization should periodically execute a DR test combined with BCP ("at least once a year"). The Member Organization should conduct an evaluation of the executed DR test of IT DR infrastructure that supports the Member Organization's critical systems to ensure the readiness and capability of DR to resume critical business operations for a period of time in case of a major disaster. The DR test results should provide an evaluation and suggestions for improvements to manage disruptive events impacting the Member Organization's business continuity. It should cover the activation and involvement of the crisis management team.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded