Incidents, emergency plans, BCM and recovery

Incidents

Incidents records detection, impact, affected assets, responsibilities, timeline and reporting obligations. For NIS2 and GDPR, the application separates report type, actual submission date, channel, reference and evidence. Deadlines derive from the incident and the respective obligation.

Incident list with obligations and status

Close an incident only when assessment, measures and required reports are recorded. Record a submitted-report correction as a correction, not by overwriting original evidence.

Emergency plans

Emergency plans hold scenario, content, responsible persons, priority, visibility, test date and versions. Every change creates a new version. Plan and record tests against the plan version used. Archive plans with test evidence instead of deleting them.

Emergency plans with status, priority and test dates

BCM

BCM maintains business processes, BIA assessments, dependencies, objectives and exercises. A BC exercise contains scenario, team, checklist, findings, lessons learned and tasks. Transfer open items into measures so they appear in the dashboard.

BCM processes and exercises

Recovery plan and backup jobs

The Recovery plan assigns recovery steps, roles and dependencies to critical assets and processes. Review sequence and contacts after material infrastructure changes.

Backup jobs documents strategy, destination, interval, retention, encryption, key custody, restore access and RPO assessment. Add backup runs and restore tests as evidence. Derived RPO and 3-2-1 assessments are calculated from the recorded data.

Recovery plan with steps and dependencies

Backup jobs with RPO, runs and restore tests