Lesson14 min

A family of plans, not a single document

Six plans, six uses

NIST SP 800-34 offers the clearest taxonomy. It avoids the permanent confusion between BCP, DRP and crisis plan.

PlanTriggerAudienceHorizon
Emergency / evacuation planAlarm, immediate dangerAll site occupantsMinutes
Crisis management planActivation decisionCrisis teamHours to days
Business continuity planResource unavailabilityAffected business linesDays to weeks
IT disaster recovery planTechnical unavailabilityTechnical teamsHours to days
Cyber incident response planDetection of compromiseSOC, CSIRTHours
Crisis communication planTeam activationCommunications, executivesHours to weeks

These plans often trigger together, but never in the same order or at the same tempo. Merging them into a single document guarantees nobody will find what they are looking for.

The no-redundancy rule

Each piece of information lives in exactly one place. The crisis directory in particular must exist in one copy only, referenced by every plan.

The reason is practical: information duplicated across five plans gets updated in two of them. The other three become traps — and it is precisely the stale phone number that will be dialled on the day.

The three-depth rule

An effective plan reads at three levels, depending on how much time the reader has.

Level 1 — the action card. One double-sided page, ten actions maximum, usable in the first five minutes without reading anything else.

Level 2 — the procedure. Three to six pages, detailed actions, decision criteria, interfaces. Usable within the first hour.

Level 3 — the reference material. Annexes, maps, contracts, contacts, history. Consulted by those who prepare, not by those who act.

What must not be in a plan

  • The rationale for choices: it belongs in the decision file, not the action plan.
  • Regulatory recaps: they add weight without use. A reference is enough.
  • Full org charts: only crisis roles and their deputies are useful.
  • Detailed scenarios: a plan must work for scenarios nobody anticipated.

An operational continuity plan for one activity rarely runs beyond twelve pages, annexes excluded.

Key takeaways

  • Each plan has its own trigger, audience and lifespan
  • The single 300-page plan is never opened
  • A piece of information lives in exactly one plan