
Subpractices
1. Establish governance over process activities.
Elaboration:
2. Develop and publish organizational policy for the process.
Elaboration:
The service continuity policy should address
• responsibility, authority, and ownership for performing process activities
• procedures, standards, and guidelines for
– plan ownership
– plan documentation
Governance over the service continuity process may be exhibited by
• sponsorship and oversight to ensure that the process is accepted by the organization
as a strategic function with documented commitments to the plan and the process
• developing and publicizing higher-level managers’ objectives and requirements
for the process
• sponsoring process policies, procedures, standards, and guidelines, including
those for testing service continuity plans
• regular reporting from organizational units to higher-level managers on service
continuity process activities and results
• implementing a service continuity steering committee with oversight for all service
continuity plans and test plans
• making higher-level managers aware of applicable compliance obligations related
to the process, and regularly reporting on the organization’s satisfaction of these
obligations to higher-level managers
• sponsoring and funding process activities, including the development, documen-
tation, and testing of service continuity plans
• aligning service continuity plans with identified resilience requirements and
objectives and stakeholder needs and requirements, including the process plan
• verifying that the process supports strategic resilience objectives and is focused
on the assets and services that are of the highest relative value in meeting strategic
objectives
• creating dedicated higher-level management feedback loops on decisions about
the process and recommendations for improving the process
• providing input on identifying, assessing, and managing operational risks to services
• conducting regular internal and external audits and related reporting to audit
committees on process effectiveness
• creating formal programs to measure the effectiveness of process activities, and
reporting these measurements to higher-level managers
854 PART THREE CERT-RMM PROCESS AREAS