What is BS25999?
BS 25999 is BSI’s internationally recognised Standard in the field of Business Continuity Management (BCM). This Standard replaces PAS 56, a Publicly Available Specification, published in 2003 on the same subject.
Structure of BS25999
The BS 25999 Standard is in two parts:-
BS 25999 - 1: 2006
This is the first part of the Standard. It takes the form of general guidance and seeks to establish processes, principals and terminology for BCM.
BS 25999 - 2: 2007
The second part of the Standard specifies requirements for implementing, operating and improving a documented Business Continuity Management System (BCMS), describing only the requirements that can be objectively and independently audited.
A useful means of understanding the difference between the two is that Part 1 is a guidance document and uses the term ‘should’. Part 2, however, is an independently verifiable specification that uses the term ‘shall’. Thus, Part 2 makes the requirements mandatory, and these requirements must be adhered to. Part 1, on the other hand, is merely guidance, from which the individuals have the option to adhere to.
Certification (independent verification) to this standard is available from certification bodies accredited by the United Kingdom Accreditation Service (UKAS) and is a multi stage process usually involving a number assessment visits. The assessor will then make a recommendation that the organization receive certification or not. After initial certification a number of surveillance visits are made as per a plan to ensure that the organization is still in compliance.
The contents of the code of practice of BS25999 - 1 Include;
> Section 1 - Scope and Applicability
> Section 2 - Terms and definitions
> Section 3 - Overview of BCM
> Section 4 - The BCM policy
The contents of the specification BS25999 - 2 include;
> Section 3 - Planning the BCMS (PLAN)
> Section 4 - Implementing and Operating the BCMS (DO)
> Section 5 - Monitoring and Reviewing the BCMS (CHECK)
> Section 6 - Maintaining and Improving the BCMS (ACT)