AgentStack
SKILL verified MIT Self-run

Bcp Planner

skill-takusaotome-claude-skills-library-bcp-planner · by takusaotome

|

No reviews yet
0 installs
5 views
0.0% view→install

Install

$ agentstack add skill-takusaotome-claude-skills-library-bcp-planner

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Bcp Planner? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

BCP Planner(事業継続計画策定支援)

Overview

This skill transforms you into an expert business continuity planner capable of developing comprehensive BCPs and DRPs. By following ISO 22301 standards and industry best practices, you can help organizations prepare for, respond to, and recover from disruptions.

Primary language: Japanese (default), English supported Standards: ISO 22301 (Business Continuity Management) Output format: BCP/DRP documents, BIA reports, test plans, training materials

Use this skill when:

  • Developing business continuity plans for organizations
  • Conducting Business Impact Analysis (BIA)
  • Creating disaster recovery strategies for IT systems
  • Planning and conducting BCP/DRP tests and exercises
  • Achieving ISO 22301 certification
  • Improving organizational resilience

Core Concepts

BCP vs DRP

BCP (Business Continuity Plan):

  • Scope: Entire business operations
  • Focus: Maintaining critical business functions during disruption
  • Includes: People, processes, facilities, suppliers, communication
  • Objective: Minimize business impact, maintain revenue

DRP (Disaster Recovery Plan):

  • Scope: IT systems and technology
  • Focus: Restoring IT infrastructure and data
  • Includes: Servers, networks, applications, data backups
  • Objective: Restore technology operations within RTO/RPO

Relationship: DRP is a subset of BCP. A comprehensive BCP includes DRP as one component.

Key Metrics

RTO (Recovery Time Objective)
Disruption → [RTO] → Service Restored

RTO = Maximum acceptable downtime

Examples:
- Tier 1 (Critical): RTO = 1 hour
- Tier 2 (Important): RTO = 8 hours
- Tier 3 (Normal): RTO = 24 hours
RPO (Recovery Point Objective)
Last Backup ← [RPO] → Disruption

RPO = Maximum acceptable data loss

Examples:
- RPO = 0: No data loss (synchronous replication)
- RPO = 1 hour: Hourly backups
- RPO = 24 hours: Daily backups
MTPD (Maximum Tolerable Period of Disruption)
MTPD = Point at which disruption becomes catastrophic

Example:
- E-commerce site: MTPD = 4 hours (beyond this, significant revenue loss and customer churn)

Core Workflows

Workflow 1: Business Impact Analysis (BIA)

Purpose: Identify critical business functions and quantify impact of disruption.

Step 1: Identify Business Functions

List all business functions/processes:

  • Core Functions: Revenue-generating, mission-critical
  • Support Functions: HR, Finance, IT, Legal
  • Management Functions: Executive management, governance

Example List:

  • Order Processing
  • Customer Support
  • Manufacturing
  • Shipping/Logistics
  • IT Infrastructure
  • Payroll
  • Financial Reporting
Step 2: Assess Criticality

For each function, evaluate:

Criticality Criteria:

  1. Revenue Impact: How much revenue loss per hour/day?
  2. Customer Impact: Customer satisfaction, churn risk
  3. Regulatory Impact: Compliance violations, fines
  4. Reputational Impact: Brand damage, media attention
  5. Operational Impact: Dependency by other functions

Criticality Rating:

| Function | Revenue Impact | Customer Impact | Regulatory | Reputation | Overall Criticality |
|----------|----------------|-----------------|------------|------------|---------------------|
| Order Processing | Very High | High | Medium | High | **Critical** |
| Customer Support | Medium | Very High | Low | High | **High** |
| Payroll | Low | Low | High | Medium | **Medium** |
| Marketing | Low | Low | None | Low | **Low** |
Step 3: Determine Time Sensitivity

Time Sensitivity Analysis:

Impact = f(Time)

Hour 1-4: Minimal impact, workarounds possible
Hour 4-8: Moderate impact, customer frustration
Hour 8-24: Significant impact, revenue loss
Day 1-3: Severe impact, regulatory issues
Day 3+: Catastrophic, business survival threat

Example:

Function: Order Processing
- Hour 1: Minimal (orders queue)
- Hour 4: Moderate (customers call support)
- Hour 8: Significant ($50K revenue loss, customer complaints)
- Hour 24: Severe ($200K loss, media attention, customer churn)
- Day 3: Catastrophic (irreparable brand damage)

MTPD = 8 hours
RTO Target = 4 hours (before significant impact)
Step 4: Identify Dependencies

Dependency Mapping:

Business Function: Order Processing

Dependencies:
- People: Sales team, order fulfillment team
- Technology: E-commerce platform, payment gateway, inventory system
- Facilities: Warehouse, office space
- Suppliers: Payment processor, shipping carrier
- Data: Product catalog, customer database, inventory data

Single Points of Failure (SPOF):

  • Identify SPOFs that could disrupt critical functions
  • Examples: Single server, key person, single supplier
Step 5: Calculate Financial Impact

Financial Impact Formula:

Total Impact = Direct Costs + Indirect Costs + Opportunity Costs

Direct Costs:
- Lost revenue
- Extra expenses (overtime, expedited shipping)
- Fines and penalties

Indirect Costs:
- Customer compensation
- Productivity loss
- Recovery costs

Opportunity Costs:
- Lost future revenue (customer churn)
- Competitive disadvantage

Example:

Function: E-commerce Website
Downtime: 8 hours

Direct Costs:
- Lost sales: $100,000
- Staff overtime: $5,000

Indirect Costs:
- Customer service calls: $3,000
- Brand damage mitigation: $10,000

Opportunity Costs:
- Customer churn (estimated): $50,000

Total 8-hour Impact: $168,000
Hourly Impact: $21,000/hour
Step 6: Prioritize Recovery

Priority Matrix:

       High Impact
         │
 Tier 1 │  Tier 1
(RTO:1h)│ (RTO:4h)
         │
  ───────┼───────
         │
 Tier 2 │  Tier 3
(RTO:8h)│(RTO:24h)
         │
     Low Criticality

Workflow 2: Risk Assessment

Purpose: Identify threats and assess likelihood and impact.

Step 1: Identify Threats

Threat Categories:

  1. Natural Disasters
  • Earthquake, flood, typhoon, fire
  • Pandemic
  1. Technology Failures
  • Server failure, network outage
  • Data breach, ransomware
  1. Human-Caused
  • Cyber attack, sabotage
  • Human error, strikes
  1. Supply Chain
  • Supplier failure
  • Transportation disruption
  1. Facility-Related
  • Power outage
  • HVAC failure, water damage
Step 2: Assess Likelihood and Impact

Risk Assessment Matrix:

Likelihood:
- Rare: Once in 10+ years
- Unlikely: Once in 5-10 years
- Possible: Once in 2-5 years
- Likely: Once per year
- Almost Certain: Multiple times per year

Impact:
- Insignificant: $5M, >7 days

Risk Matrix:

Impact     │ Rare │Unlikely│Possible│ Likely │Almost Certain
───────────┼──────┼────────┼────────┼────────┼──────────────
Catastrophic│Medium│  High  │Extreme │Extreme │   Extreme
Major      │ Low  │ Medium │  High  │Extreme │   Extreme
Moderate   │ Low  │  Low   │ Medium │  High  │   High
Minor      │ Low  │  Low   │  Low   │ Medium │   Medium
Insignif.  │ Low  │  Low   │  Low   │  Low   │   Low

Example:

| Threat | Likelihood | Impact | Risk Level | Mitigation Priority |
|--------|------------|--------|------------|---------------------|
| Ransomware | Likely | Major | Extreme | **Immediate** |
| Earthquake | Unlikely | Catastrophic | High | **High** |
| Power Outage | Almost Certain | Moderate | High | **High** |
| Key Person Unavailable | Possible | Minor | Low | **Medium** |
Step 3: Develop Mitigation Strategies

Risk Treatment Options:

  1. Avoid: Eliminate the risk
  • Example: Move data center out of flood zone
  1. Reduce: Minimize likelihood or impact
  • Example: Implement cybersecurity measures, backup systems
  1. Transfer: Share risk with others
  • Example: Insurance, outsource to cloud provider
  1. Accept: Accept the risk
  • Example: Low-likelihood, low-impact risks

Mitigation Plan Example:

Risk: Ransomware Attack
Current Level: Extreme (Likely × Major)

Mitigation Actions:
1. Implement MFA (Multi-Factor Authentication)
2. Deploy EDR (Endpoint Detection and Response)
3. Conduct security awareness training
4. Implement immutable backups (air-gapped)
5. Develop incident response plan

Residual Risk: Medium (Unlikely × Moderate)
Cost: $150,000
Expected Benefit: Avoid $5M loss
ROI: 33:1

Workflow 3: Recovery Strategy Development

Purpose: Define how to recover critical functions within RTO/RPO.

Step 1: Recovery Strategy Options

For IT Systems:

  1. Hot Site (RTO: minutes to hours)
  • Fully operational duplicate site
  • Real-time replication
  • High cost, immediate failover
  1. Warm Site (RTO: hours to days)
  • Partially equipped site
  • Periodic data sync
  • Medium cost, moderate setup time
  1. Cold Site (RTO: days to weeks)
  • Empty facility with infrastructure
  • No equipment pre-installed
  • Low cost, long setup time
  1. Cloud-Based DR (RTO: hours)
  • Cloud infrastructure (AWS, Azure, GCP)
  • Pay-as-you-go
  • Scalable, cost-effective

For Business Functions:

  1. Alternate Work Location
  • Remote work (VPN, collaboration tools)
  • Alternate office space
  • Co-working spaces
  1. Manual Workarounds
  • Paper-based processes
  • Manual data entry
  • Temporary manual procedures
  1. Outsourcing
  • Temporary staffing
  • Third-party service providers
  1. Inventory/Stockpiling
  • Safety stock
  • Pre-positioned supplies
Step 2: Cost-Benefit Analysis

Recovery Strategy Comparison:

| Strategy | RTO | RPO | Setup Cost | Annual Cost | Pros | Cons |
|----------|-----|-----|------------|-------------|------|------|
| Hot Site | 1h | 0 | $500K | $200K/yr | Immediate recovery | Very expensive |
| Warm Site | 4-8h | 1h | $200K | $100K/yr | Balanced | Some downtime |
| Cold Site | 1-7d | 24h | $50K | $20K/yr | Cost-effective | Long recovery |
| Cloud DR | 2-4h | 1h | $100K | $50K/yr | Scalable, modern | Dependency on cloud |

Recommendation: For critical systems (Tier 1), use Cloud DR or Warm Site. For non-critical systems (Tier 3), use Cold Site or accept longer RTO.

Step 3: Define Recovery Procedures

Recovery Procedure Template:

## Recovery Procedure: [System/Function Name]

### Objective
Restore [System/Function] to operational state within [RTO].

### Scope
- Systems: [List of servers, applications, databases]
- Data: [List of datasets and backup sources]
- Dependencies: [Prerequisites for recovery]

### Roles and Responsibilities
- **Recovery Manager**: [Name]
- **Technical Lead**: [Name]
- **Communication Lead**: [Name]

### Pre-Requisites
- [ ] Disaster declared by [Authority]
- [ ] Recovery site accessible
- [ ] Recovery team mobilized

### Recovery Steps

#### Phase 1: Assessment (0-30 minutes)
1. Assess extent of damage
2. Determine recovery strategy (primary vs. alternate site)
3. Activate recovery team

#### Phase 2: Infrastructure Recovery (30min - 2 hours)
1. Provision cloud resources OR activate alternate site
2. Restore network connectivity
3. Restore storage systems

#### Phase 3: Data Recovery (2 - 4 hours)
1. Identify most recent viable backup
2. Restore database from backup
3. Validate data integrity

#### Phase 4: Application Recovery (4 - 6 hours)
1. Deploy application servers
2. Configure applications
3. Perform smoke tests

#### Phase 5: Validation (6 - 8 hours)
1. End-to-end testing
2. User acceptance testing
3. Performance validation

#### Phase 6: Cutover (8 hours)
1. Update DNS/routing
2. Notify users
3. Monitor closely

### Rollback Plan
If recovery fails, rollback to [previous state] by [procedure].

### Checklists
- [ ] All systems operational
- [ ] Data integrity confirmed
- [ ] Users can access
- [ ] Performance acceptable

Workflow 4: BCP/DRP Documentation

Purpose: Create comprehensive, actionable BCP/DRP documents.

BCP Document Structure
# Business Continuity Plan

## 1. Executive Summary
- Purpose and scope
- Key risks and mitigation strategies
- Recovery priorities

## 2. Plan Governance
- Plan owner and approval authority
- Review and update schedule
- Distribution list

## 3. Business Impact Analysis
- Critical functions and RTOs
- Financial impact analysis
- Dependencies

## 4. Risk Assessment
- Threat scenarios
- Risk ratings
- Mitigation strategies

## 5. Recovery Strategies
- Recovery options for each critical function
- Cost-benefit analysis
- Chosen strategies

## 6. Emergency Response Procedures
- Incident detection and notification
- Escalation procedures
- Initial response actions

## 7. Recovery Procedures
- Step-by-step recovery instructions
- Role assignments
- Resource requirements

## 8. Communication Plan
- Internal communication (employees)
- External communication (customers, suppliers, media, regulators)
- Communication templates

## 9. Contact Lists
- Emergency contacts (24/7)
- Vendors and suppliers
- Key stakeholders

## 10. Training and Testing
- Training program
- Test schedule (tabletop, simulation, full)
- Test results and lessons learned

## 11. Plan Maintenance
- Review triggers
- Update procedures
- Version control

## Appendices
- Detailed technical recovery procedures
- Vendor contracts and SLAs
- Floor plans and facility information
- Forms and templates
DRP Document Structure
# Disaster Recovery Plan

## 1. Introduction
- Purpose, scope, objectives
- Assumptions and constraints

## 2. Disaster Scenarios
- Natural disasters
- Technology failures
- Cyber attacks

## 3. Roles and Responsibilities
- DR Team structure
- RACI matrix

## 4. Disaster Declaration
- Criteria for declaring disaster
- Authority and approval process

## 5. Notification Procedures
- Call tree
- Notification templates
- 24/7 contact information

## 6. Recovery Priorities
- System tier classification (Tier 1, 2, 3)
- Recovery sequence

## 7. Recovery Procedures
- Infrastructure recovery
- Data recovery
- Application recovery
- Network recovery

## 8. Recovery Sites
- Primary data center
- Alternate site (Hot/Warm/Cold)
- Cloud DR environment

## 9. Data Backup and Restoration
- Backup schedule
- Backup verification
- Restoration procedures

## 10. Testing and Maintenance
- Test types and frequency
- Test scenarios
- Plan update procedures

## 11. Vendor Management
- Critical vendors and SLAs
- Escalation procedures

## Appendices
- System inventory
- Network diagrams
- Configuration details
- Backup schedules

Workflow 5: Testing and Training

Purpose: Validate BCP/DRP effectiveness and train personnel.

Test Types

1. Tabletop Exercise

  • Description: Discussion-based walkthrough
  • Participants: Key personnel in a conference room
  • Duration: 2-4 hours
  • Frequency: Quarterly
  • Benefit: Low cost, identifies gaps in plan
  • Limitation: No actual recovery

Example Scenario:

"At 2 AM, the primary data center experiences a fire in the server room.
Initial reports indicate all servers are offline. What do you do?"

Discussion points:
- Who declares the disaster?
- How do you notify the recovery team?
- What is the recovery sequence?
- What are the communication procedures?

2. Walkthrough Test

  • Description: Step-by-step review of procedures
  • Participants: DR team
  • Duration: Half day
  • Frequency: Semi-annually
  • Benefit: Validates procedures without disruption
  • Limitation: No hands-on execution

3. Simulation/Parallel Test

  • Description: Partial recovery in test environment
  • Participants: Technical team
  • Duration: 1-2 days
  • Frequency: Annually
  • Benefit: Hands-on validation without disrupting production
  • Limitation: May not reflect production complexity

4. Full Interruption Test

  • Description: Actual failover to DR site
  • Participants: All stakeholders
  • Duration: 1-3 days
  • Frequency: Every 2-3 years (high risk)
  • Benefit: Most realistic test
  • **Li

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.