A family of plans, not a single document
Six plans, six uses
NIST SP 800-34 offers the clearest taxonomy. It avoids the permanent confusion between BCP, DRP and crisis plan.
| Plan | Trigger | Audience | Horizon |
|---|---|---|---|
| Emergency / evacuation plan | Alarm, immediate danger | All site occupants | Minutes |
| Crisis management plan | Activation decision | Crisis team | Hours to days |
| Business continuity plan | Resource unavailability | Affected business lines | Days to weeks |
| IT disaster recovery plan | Technical unavailability | Technical teams | Hours to days |
| Cyber incident response plan | Detection of compromise | SOC, CSIRT | Hours |
| Crisis communication plan | Team activation | Communications, executives | Hours to weeks |
These plans often trigger together, but never in the same order or at the same tempo. Merging them into a single document guarantees nobody will find what they are looking for.
The no-redundancy rule
Each piece of information lives in exactly one place. The crisis directory in particular must exist in one copy only, referenced by every plan.
The reason is practical: information duplicated across five plans gets updated in two of them. The other three become traps — and it is precisely the stale phone number that will be dialled on the day.
The three-depth rule
An effective plan reads at three levels, depending on how much time the reader has.
Level 1 — the action card. One double-sided page, ten actions maximum, usable in the first five minutes without reading anything else.
Level 2 — the procedure. Three to six pages, detailed actions, decision criteria, interfaces. Usable within the first hour.
Level 3 — the reference material. Annexes, maps, contracts, contacts, history. Consulted by those who prepare, not by those who act.
What must not be in a plan
- The rationale for choices: it belongs in the decision file, not the action plan.
- Regulatory recaps: they add weight without use. A reference is enough.
- Full org charts: only crisis roles and their deputies are useful.
- Detailed scenarios: a plan must work for scenarios nobody anticipated.
An operational continuity plan for one activity rarely runs beyond twelve pages, annexes excluded.
Key takeaways
- Each plan has its own trigger, audience and lifespan
- The single 300-page plan is never opened
- A piece of information lives in exactly one plan