0% found this document useful (0 votes)
23 views21 pages

CBCI Qualification Specifications

Cbci

Uploaded by

hpncxbfvfh
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
23 views21 pages

CBCI Qualification Specifications

Cbci

Uploaded by

hpncxbfvfh
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 21

Certificate of the Business

Continuity Institute (CBCI)


Qualification Specification
Contents
About the Business Continuity Institute (BCI) 3
Introduction to the CBCI qualification 3

Aims of the CBCI qualification 4


Entry requirements 4
Qualification structure 4
Assessment 5
Qualification learning time 5

Specification for the Certificate 6


of the Business Continuity Institute (CBCI)
Unit 1 – PP1: Establishing a business continuity management system 6
Unit 2 – PP2: Embracing business continuity 8
Unit 3 – PP3: Analysis 10
Unit 4 – PP4: Solutions design 13
Unit 5 – PP5: Enabling solutions 15
Unit 6 – PP6: Validation 18

2
About the Business
Continuity Institute (BCI)
The BCI is the world’s leading institute for business continuity and resilience
professionals.

Our vision is a world where all organizations, communities and societies become
more resilient. Through the professionalism of our communities, the strength of
our relationships, the quality of our education, the breadth of our knowledge and
the depth of our insight, together we will build a world where every organization is
resilient.

Through our membership services, qualifications, training and events, we promote


professional standards in business continuity management and help resilience
professionals reach their full potential.

Introduction to the CBCI qualification


The CBCI qualification covers the full range of practices used by business continuity
professionals to develop, implement and maintain an effective business continuity
management system (BCMS). The qualification is based on BCI’s Competency
Framework and uses the BCI Good Practice Guidelines (GPG) Edition 7.0 as the
core text. The GPG draws on the knowledge of practitioners from all over the world
and on information from ISO standards, including ISO 22031: 2019 Security and
resilience — Business continuity management systems — Requirements.

The qualification is designed to be at Level 4 of the European Qualifications


Framework.

The CBCI is for individuals who are:


• seeking to complement practical experience in BCM with an internationally
recognised qualification;
• moving into a career in BCM; or
• in a role with BCM--related responsibilities.

Achievement of the CBCI entitles holders to use the post-nominal CBCI and to 12
months complimentary BCI membership at the CBCI Level.

3
Aims of the CBCI qualification
The CBCI qualification is designed to:
• enable individuals to demonstrate a wide range of foundational knowledge and
understanding of BCM;
• support individuals in operational BCM workplace roles;
• prepare individuals for progression to a qualification at a higher level or with more
content; and
• support individuals’ applications for membership of the BCI.

Entry requirements
There are no formal entry requirements. However, candidates are expected to have
taken a course with a BCI Licensed Training Partner and studied the BCI GPG
Edition 7.0 to ensure thorough knowledge and understanding before taking the CBCI
assessment.

Qualification structure
The structure of the CBCI qualification is based on the GPG Edition 7.0 The qualification
consists of six mandatory units, one for each of the Professional Practices in the GPG.

Unit 1 PP1: Establishing a business continuity management system

Unit 2 PP2: Embracing

Unit 3 PP3: Analysis

Unit 4 PP4: Solutions design

Unit 5 PP5: Enabling solutions

Unit 6 PP6: Validation

The detailed qualification content is set out in the six tables presented below.

4
Assessment
All six units are assessed in a single ninety-minute examination. Each unit carries equal marks.

The examination is online, closed-book and supervised by a proctor. Further information on the
examination is available at www.thebci.org/training-qualifications/cbci-exam.html

The examination consists of multiple-choice questions designed to test candidates’


understanding of the qualification content, as set out in the six tables presented below.
Candidates are required to answer all the examination questions.

The examination questions cover all six units and can be based on any of the assessment
criteria in the six tables presented below. Candidates should therefore prepare for the
examination by studying all of the qualification content.

To pass the examination, candidates must answer at least 63 questions correctly. Candidates
who answer 77 or more questions correctly will pass with merit.

The BCI has arrangements for:


• making reasonable adjustments for disabled candidates, and
• giving special consideration to candidates who are affected by events beyond their control.

Please contact [email protected] for further details.

Qualification learning time


The length of time needed to complete this qualification will depend on the existing knowledge
and experience of each individual candidate.

The BCI expects most candidates to spend around 10 hours studying each unit. Some
candidates might choose to spend more or less time on individual units, depending on their
existing knowledge and experience.

The total qualification time is therefore 61.5 hours:


• 60 hours (over six units) of study. This might include attending the CBCI training course.
• ninety minutes of assessment.

The CBCI training course is a minimum of 21 hours of guided learning. For candidates that
attend the training course, this contributes to the total qualification time of 61.5 hours.

5
Specification for the Certificate
of the Business Continuity
Institute (CBCI)
Unit 1 – PP1: Establishing a business continuity
management system

Learning outcomes Assessment criteria


Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

1. Understand the activities 1.1. Describe the activities needed to establish and
needed to establish and maintain a business continuity management
maintain a business system.
continuity management
system. 1.2. Explain why it is necessary to co-ordinate the
activities needed to establish and maintain a
business continuity management system and
describe the factors to be considered.

1.3. Identify the main stakeholder groups that should


be involved in establishing a business continuity
management system and explain the purpose of
engaging with stakeholders.

1.4. Describe the process and methods that can be used


to establish a business continuity management
system.

2. Understand why and how 2.1. Explain why it is important to define the scope of a
the scope of a business business continuity management system.
continuity management
system should be defined. 2.2. Identify and explain the factors that may affect
the scope of a business continuity management
system.

2.3. Explain why and when the scope of a business


continuity management system should be reviewed.

6
Learning outcomes Assessment criteria
Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

3. Understand the purpose 3.1. Describe the purpose of a business continuity policy
of a business continuity and explain how a business continuity policy is
policy and know how used.
to develop an effective
policy. 3.2. Explain the factors that should be taken into
account when developing a business continuity
policy.

3.3. Describe the process and methods that can be


used to develop and maintain an effective business
continuity policy.

4. Understand the role 4.1. Explain why it is important to establish governance


and features of effective and support from top management in the early
business continuity stages of establishing a business continuity
governance and management system.
know how to establish
governance. 4.2. Describe the activities and processes that should be
put in place by top management to ensure that the
BCMS is developed, monitored and implemented in
line with organization requirements.

4.3. Explain the factors that affect the process of


establishing governance and ensuring that
governance continues to meet the needs of the
business continuity management system.

4.4. Identify and describe typical business continuity


roles and their responsibilities.

4.5. Describe the outcomes and features of effective


governance.

7
Unit 2 – PP2: Embracing business continuity

Learning outcomes Assessment criteria


Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

1. Understand the difference 1.1. Explain what is meant by the terms “embracing” and
between embracing “embedding” in the context of business continuity
and embedding and explain the difference between them.Explain
business continuity in an why it is necessary to co-ordinate the activities
organization. needed to establish and maintain a business
continuity management system and describe the
factors to be considered.

1.2. Describe the outcomes of a fit-for-purpose business


continuity management system.

1.3. Explain how embedding business continuity without


embracing it can affect the effectiveness of the
business continuity management system and
explain the value added by embracing business
continuity.

2. Understand the 2.1. Explain what is meant by organization culture and


importance of explain why the existing culture in an organization is
organizational culture relevant to business continuity management.
and know how to develop
understanding of an 2.2. Describe the processes and methods that can be
organization’s culture. used to aid understanding of organizational culture.

3. Understand the 3.1. Explain what is meant by “business continuity


importance and culture” and describe the features of this type of
characteristics of an culture.
organization’s business
continuity culture. 3.2. Describe the factors that indicate that top
management is embracing business continuity
and explain how the level of involvement by top
management can impact the effectiveness of the
BCMS.

8
Learning outcomes Assessment criteria
Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

4. Understand why it is 4.1. Explain why it is important to identify and monitor


important to improve an the gap between the existing level and the desired
organization’s business level of embracing business continuity and explain
continuity culture how this gap affects the approach to improving
and understand the business continuity culture.
approaches that can be
used to achieve this. 4.2. Identify and explain the factors that affect the
approaches that can be taken to improve a
business continuity culture.

4.3. Describe the methods that can be used to raise


commitment to business continuity and to improve
an organization’s business continuity culture.

4.4. Identify and describe the indicators of a business


continuity culture where business continuity is
embraced.

5. Understand why and how 5.1. Explain why it is important to measure business
business continuity culture continuity culture.
should be measured.
5.2. Identify and describe the factors that should be
considered when determining how to measure
business continuity culture.

5.3. Describe methods that may be used for measuring


business continuity culture.

6. Understand the benefits 6.1. Explain the benefits of maintaining the relationship
and outcomes of between the organization and its internal and
embracing business external stakeholders.
continuity management
and the importance of 6.2. Explain why it is important to proactively secure
ongoing monitoring and support for the business continuity on an ongoing
maintenance activities. basis and identify examples of opportunities to raise
awareness.

6.3. Describe the outcomes of embracing business


continuity management.

9
Unit 3 – PP3: Analysis

Learning outcomes Assessment criteria


Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

1. Understand the purpose 1.1. Describe the purpose, use and aims of the Business
and use of the primary Impact Analysis.
techniques of analysis,
Business Impact 1.2. Describe the purpose and use of the Risk
Analysis (BIA) and Risk Assessment.
Assessment (RA).

2. Understand the different 2.1. Describe the three types of business impact
types of business impact analysis and explain the purpose of each.
analysis and the generic
activities undertaken 2.2. Identify and explain the factors that affect the ways
to develop a business in which organizations select and combine the types
impact analysis. of business impact analysis.

2.3. Describe and explain the steps involved in the


process to carry out a business impact analysis.

2.4. Describe the responsibilities of top management,


business continuity professionals and activity
owners in relation to business impact analysis.

2.5. Describe the main methods and techniques used


to collect information for business impact analysis
and identify the advantages and disadvantages of
different approaches.

2.6. Identify and explain the factors to be considered


when preparing to conduct the business impact
analysis.

10
Learning outcomes Assessment criteria
Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

3. Understand the maximum 3.1. Explain the concepts of MTPD and RTO and the
tolerable period of relationship between them.
disruption (MTPD) and
recovery time objective 3.2. Identify different types of impact that could be
(RTO), and how these are considered when determining the MTPD and RTO.
determined.
3.3. Identify and explain the factors that affect the
timeframes for the MTPD and RTO in different
contexts.

3.4. Explain why the business impact analysis should


determine the minimum business continuity
objective and the factors to be considered when
doing this.

4. Understand the purpose 4.1. Explain the purpose and use of the product and
of the product and service service business impact analysis.
business impact analysis
and the process to carry 4.2. Describe the steps involved in the product and
out the analysis. service business impact analysis.

5. Understand the purpose 5.1. Explain the purpose of the process business impact
of the process business analysis and identify the factors that affect its use.
impact analysis and the
process to carry out the 5.2. Describe the steps to complete the process
analysis. business impact analysis and identify the outcomes.

6. Understand the purpose 6.1. Explain the purpose of the activity business impact
of the activity business analysis.
impact analysis and the
process to carry out the 6.2. Describe the process to develop the activity
analysis. business impact analysis and the outcomes of the
process.

6.3. Describe the main categories of resources and


dependencies that support prioritized activities and
the factors that affect these.

7. 7. Understand the 7.1. Describe the purpose and content of a consolidated


content, approval and business impact analysis and describe the approval
use of a consolidated process.
business impact analysis.

11
Learning outcomes Assessment criteria
Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

8. Understand risk 8.1. Explain the purpose and use of risk assessment in
assessment in the the context of the Business Continuity Management
context of the Business System.
Continuity Management
System. 8.2. Explain the factors to be taken into consideration
when developing and using risk assessments.

8.3. Describe the key steps in the risk assessment


process.

12
Unit 4 – PP4: Solutions design

Learning outcomes Assessment criteria


Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

1. Understand the purpose 1.1. Describe the purpose and use of business
of business continuity continuity strategies and solutions.
strategy and solutions
design. 1.2. Explain the factors to be taken into account when
developing and assessing business continuity
strategies and solutions.

1.3. Identify the outcomes of strategies and solutions


design.

2. Understand how recovery 2.1. Identify the three main steps in the process for
strategies and solutions developing recovery strategies and solutions.
are developed.
2.2. Describe the purpose and use of gap analysis and
describe the processes to be followed to complete
gap analysis.

2.3. Describe the outcomes that may arise from gap


analysis and explain the decisions and actions that
may be taken.

2.4. Describe the process of strategy determination.

2.5. Describe the process to be followed and the factors


to be considered when identifying possible solutions
and strategies.

2.6. Explain why different recovery strategies are


needed for different RTO categories.

13
Learning outcomes Assessment criteria
Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

3. Understand the strategies 3.1. Describe the possible strategies and solutions in
and solutions that can relation to people resources and explain the factors
be used in relation to for consideration.
different resources and
RTO categories. 3.2. Describe the possible strategies and solutions in
relation to information and data resources and
explain the factors for consideration.

3.3. Describe the possible strategies and solutions in


relation to physical infrastructure resources and
explain the factors for consideration.

3.4. Describe the possible strategies and solutions in


relation to IT systems and applications resources
and explain the factors for consideration.

3.5. Describe the possible strategies and solutions in


relation to transport and logistics resources and
explain the factors for consideration.

3.6. Describe the possible strategies and solutions in


relation to finance resources and explain the factors
for consideration.

3.7. Describe the possible strategies and solutions


in relation to supplier and outsourcing partner
resources and explain the factors for consideration.

3.8. Describe the factors that need to be considered


in order to maintain the safety and wellbeing of
personnel during an incident.

4. Understand how 4.1. Describe the factors that influence the identification
unacceptable risks and of risk mitigation solutions.
single points of failure are
mitigated. 4.2. Describe the process and methods for identifying
risk mitigation strategies and solutions.

4.3. Explain the outcomes and benefits of approved risk


mitigation strategies and solutions.

14
Unit 5 – PP5: Enabling solutions

Learning outcomes Assessment criteria


Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

1. Understand the purpose 1.1. Explain the purpose of Enabling solutions and
of Enabling solutions describe the three main activities.
and understand the main
activities.

2. Understand how to 2.1. Describe the factors and principles that underpin the
implement a solution. implementation of solutions.

2.2. Describe the processes and methods needed to


implement and maintain solutions.

3. Understand how a 3.1. Describe the purpose of establishing a response


response structure is structure and explain the factors that need to be
established. taken into account.

3.2. Describe the features of an effective response


structure.

3.3. Describe the process and methods to develop an


effective response structure.

3.4. Describe the focus, activities and attributes of


strategic, tactical and operational response teams.

15
Learning outcomes Assessment criteria
Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

4. Understand the factors 4.1. Explain why it is important for organizations to have
affecting communications communication plans and procedures for use when
when responding to responding to incidents.
incidents and understand
relevant procedures to be 4.2. Describe the principles and features that underpin
applied. effective communications when responding to
incidents.

4.3. Describe the procedures and supporting information


that are required for communications regarding an
incident.

4.4. Explain the factors to be considered when engaging


with media and social media and describe the
procedures to be followed.

4.5. Describe the purpose and use of warning plans.

4.6. Describe the role and responsibilities of spoke


persons

5. Understand how business 5.1. Describe the purpose of business continuity plans
continuity plans are and explain the factors affecting the structure of
developed and managed. plans.

5.2. Describe the key features that make a business


continuity plan fit for purpose.

5.3. Describe the essential information that should be


included in all business continuity plans.

5.4. Describe the activities required to develop and


manage business continuity plans.

5.5. Describe the meeting and resources that should be


in place to enable management of an incident.

16
Learning outcomes Assessment criteria
Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

6. Understand the purpose 6.1. Explain the purpose, content and considerations
and characteristics of relevant to strategic plans and identify examples of
strategic, tactical and strategic plans.
operational business
continuity plans. 6.2. Describe the purpose, content and considerations
relevant to crisis communications plans.

6.3. Explain the purpose, content and considerations


relevant to tactical plans and identify examples of
tactical plans.

6.4. Describe the purpose and content of people welfare


plans for use in emergency response plans.

6.5. Explain the purpose, content and considerations


relevant to operational plans and identify examples
of operational plans.

6.6. Describe the content of a plan for returning


to business as normal and the factors to be
considered.

6.7. Explain the purpose, content and considerations


relevant to plans for specific situations and identify
examples of scenario specific plans and their
content.

17
Unit 6 – PP6: Validation

Learning outcomes Assessment criteria


Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

1. Understand the purpose 1.1. Explain the purpose and benefits of validation.
and importance of
validation. 1.2. Describe the three activities covered by validation.

2. Understand why and how 2.1. Explain the purpose of exercise programmes and
exercise programmes describe the outcomes of an effective programme.
are developed and
understand the different 2.2. Describe the factors to be taken into consideration
types of exercise that can when developing an exercise programme.
be utilised.
2.3. Describe the elements that should be covered in an
exercise programme.

2.4. Explain how exercise programmes can be used in


supply chain continuity management.

2.5. Explain how to develop an exercise programme and


describe the options to be considered.

2.6. Describe the format, use and benefits of discussion-


based exercises.

2.7. Describe the format, use and benefits of scenario-


based exercises.

2.8. Describe the format, use and benefits of simulation-


based exercises.

2.9. Describe the format, use and benefits of live


exercises.

2.10. Describe the format, use and benefits of test


exercises.

18
Learning outcomes Assessment criteria
Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

3. Understand how a single 3.1. Explain the factors to be considered when planning
exercise should be an individual exercise
developed, conducted
and evaluated. 3.2. Describe the steps in the process to plan and
develop an exercise.

3.3. Describe how to prepare for, start, manage,


suspend and end an exercise.

3.4. Explain the purpose of debriefing following an


exercise and describe the main types of debrief.

3.5. Describe methods that can be used to gather


information for a debrief.

3.6. Explain the benefits of developing, conducting and


evaluating an exercise.

4. Understand how a 4.1. Explain the purpose of maintenance activities


business continuity in relation to a business continuity management
management system system and the outcomes of a successful
should be maintained. maintenance programme.

4.2. Describe the factors to be taken into consideration


when planning and undertaking maintenance
activities.

4.3. Describe the process of maintenance and the


methods that can be used.

19
Learning outcomes Assessment criteria
Candidates who complete Assessment of this learning outcome will require
this unit should: candidates to:

5. Understand why and how 5.1. Explain the purpose of reviewing the business
a business continuity continuity management system and describe the
management system factors to be taken into account when planning and
should be reviewed. undertaking a review.

5.2. Identify the types of review that can be utilised and


explain how the effectiveness of different types of
review should be measured.

5.3. Explain the purpose of a business continuity


management system audit and describe the factors
to be considered when carrying out this type of
review.

5.4. Explain the purpose of a self-assessment review


and describe the factors to be considered when
carrying out this type of review.

5.5. Explain the purpose of a quality assurance review


and describe the factors to be considered when
carrying out this type of review.

5.6. Explain the purpose of appraising individual


performance in relation to the business continuity
management system and describe the factors to be
considered when carrying out this type of review.

5.7. Explain the purpose of reviewing supplier


performance in relation to the business continuity
management system and describe the factors to be
considered when carrying out this type of review.

5.8. Explain the purpose of a post-incident review and


describe the factors and process to be considered
when carrying out this type of review.

5.9. Explain the purpose of management review in


relation to the business continuity management
system l and describe the factors to be considered
when carrying out this type of review.

20
21

You might also like