Appearance
Operational Resilience
Where to find it: Operational Resilience, then BCM & Resilience (/bcm). Assets & Inventory (/inventory) and Scope Registry (/scope-registry) sit under Regulatory Compliance.
This domain answers: if something important stops working, what happens, how quickly can we recover, and have we ever actually proved it?
The primary subject: the business service
The canonical business service is the primary resilience subject. Business impact analyses, continuity plans, exercises and resilience assessments all anchor to important business services rather than to systems.
The reason is that customers and regulators care about services, not servers. "Can customers make payments?" is the question; "is database cluster 4 up?" is a detail beneath it.
Articles
| Article | What it covers |
|---|---|
| Assets & Inventory | The technology inventory: what exists |
| Scope Registry | Declared scopes: where things apply, effective-dated |
| Business Impact Analysis | RTO, RPO, MTD, MBCO and impact tolerances |
| Continuity Plans | BCP and DR plans, versions, activation criteria |
| Exercises | Testing, target versus actual, and breach handling |
| Resilience Assessments | The six-dimension posture and critical-failure override |
The chain
The truthfulness chain
Each of these is a separate fact
Plan exists, is not plan approved, is not exercise scheduled, is not exercise completed, is not exercise passed, is not service resilient.
Evidence retained is not recovery objective achieved.
Action plan completed is not finding closed, is not exercise passed, is not service resilient.
Where a service or plan has not been exercised or assessed, its status is reported as not tested or not assessed. It is never assumed resilient. An exercise scheduled in the future is never treated as completed or passed.
This is the single most important thing to understand about the domain. Resilience is the area where optimistic reporting is most tempting and most consequential.
Recovery objectives are human determinations
| Objective | Meaning |
|---|---|
| RTO — Recovery Time Objective | Maximum acceptable duration of service downtime |
| RPO — Recovery Point Objective | Maximum acceptable data loss window |
| MTD / MTPD — Maximum Tolerable Disruption | Outage duration causing intolerable harm; at or beyond the RTO |
| MBCO — Minimum Business Continuity Objective | Minimum acceptable operational capability on resumption |
All four are explicit human executive determinations backed by business impact assessment. None is synthesised by a heuristic.
Target versus actual
When a tested recovery time or data loss exceeds the target, the target is preserved as the standard of record and the exercise is marked as failed or breached.
The target is never quietly moved to match what was achieved. Changing an objective is a governance decision requiring its own approval, not a side effect of a disappointing test.
Entitlement
Requires the bcm_resilience entitlement for BIA, plans, exercises and resilience assessment. The Scope Registry and Assets are core infrastructure and are not separately licensed.
BCM is fully functional with Continuous Assurance off.
Permissions
| Permission | Grants |
|---|---|
bcm.read | View BIAs, plans, exercises, strategies and resilience status |
bcm.bia_manage / bcm.bia_approve | Manage and approve BIAs |
bcm.plan_manage / bcm.plan_approve | Manage and approve continuity plans |
bcm.exercise_manage / bcm.exercise_signoff | Plan and execute exercises; sign off results |
bcm.resilience_assess | Assess service resilience and impact tolerances |
bcm.ai_assist | Generate advisory AI drafts |
scope.read / scope.manage | View and manage assets and declared scopes |
Related domains
- Third-Party Risk — providers as service dependencies
- Incidents & Loss — when disruption actually happens
- Risk & Remediation — resilience findings and actions