Information Security Management for SMEs: Implementating and Operating a Business Continuity Management System (BCMS) Using PDCA Cycle
Gergely Krisztián Horváth, Cisa Cism · RePEc: Research Papers in Economics · 2013
Recent information security incidents and regulatory changes makes highlight the need of solid information security management. From a business perspective one way to be secure is to be able to operate continua hespecially for companies operating critical infrastructure elements. Business continuity management is the discipline that helps organizations to keep on operating in case of disruption or crisis. SMEs oftentimes lack the experience to establish such management systems, Therefore assistance to SMEs to implement and operate a business continuity management system (BCMS) aligned with the information security management system (ISMS) is highly appreciated. The article summarize the background to this topic and related Hungarian regulations, then major BCMS implementation and audit methodologies are discussed. Finally checklists and guidance is given to SMEs, based on professional literature and author’s experience, in order to successfully implement a BCMS system and operate it according to business needs and regulatory requirements.