Business Continuity Management System (BCMS) Policy
Aligned to ISO 22301:2012 – Societal Security: Business Continuity Management Systems – Requirements
1. Purpose
As an industry leader in providing security services including manned guarding, key holding, and alarm response, Delta Force Group Ltd (DFG) recognises its obligation to customers, employees, and all applicable legislative and regulatory requirements to ensure our services continue to operate as smoothly as possible in the event of a disruption—whether major or minor.
DFG has determined and maintains a range of Business Continuity Plans (BCPs) and procedures to be followed in such events. These are established in line with ISO 22301:2012 requirements.
2. Policy Goal
The goal of this policy is to protect DFG operational activities against any potential situation that could result in the invocation of business continuity procedures, and to ensure planned, controlled, and effective response and recovery.
3. Commitment from Top Management
Top management has approved this Business Continuity policy and is committed to:
- providing appropriate resources to implement and maintain the BCMS,
- ensuring the BCMS remains suitable, adequate, and effective, and
- striving to continually improve the Business Continuity Management System.
4. BCMS Objectives
This Business Continuity Policy and associated objectives ensure that:
4.1 Incident Management, Continuity and Recovery Arrangements
DFG ensures that Incident Management, Business Continuity, and Disaster Recovery processes are:
- determined,
- documented, and
- communicated to relevant employees and interested parties.
4.2 Minimal Operational Interruption
Operational activities will suffer no interruption, or as little interruption as possible, during and after the invocation of continuity plans. Priority is given to life safety, service continuity, and contractual obligations.
4.3 Compliance with Legal, Regulatory, and Customer Requirements
DFG will meet all applicable legislative and regulatory requirements, including customer-specific contractual requirements, throughout disruption and recovery.
4.4 Training and Awareness
Business Continuity awareness and training will be made available to all employees, and role-specific instruction will be provided to those with continuity and incident responsibilities.
5. Incident Detection, Reporting and Management
DFG maintains procedures to detect, report, and manage a business continuity incident using effective risk management. These procedures include:
- clear reporting routes and escalation,
- incident classification and decision-making controls,
- defined responsibilities during disruption, and
- appropriate communication to clients and internal stakeholders.
6. Information Systems Availability
DFG will ensure that business requirements for the availability of information systems are met. This includes:
- maintaining resilience measures appropriate to operational needs,
- ensuring continuity arrangements support service delivery and reporting,
- implementing workable contingency processes when systems are degraded or unavailable.
7. Roles and Responsibilities
7.1 Managing Director
The Managing Director is responsible for:
- maintaining this Business Continuity policy,
- ensuring the BCMS is implemented and supported,
- providing support and advice during BCMS implementation and during continuity events, and
- ensuring appropriate resources are available to achieve BCMS objectives.
7.2 Managers
All managers are directly responsible for implementing this policy and ensuring that:
- continuity procedures relevant to their areas are followed,
- their teams understand reporting and escalation processes,
- training and awareness requirements are met, and
- business continuity actions are carried out effectively during an incident.
7.3 Employees
All employees must:
- follow instructions and continuity procedures applicable to their role,
- report disruptions, near misses, or risks promptly, and
- participate in training and exercises when required.
8. Communication, Documentation, and Review
This policy will be:
- communicated to all relevant persons working for or on behalf of DFG,
- supported by documented plans and procedures, and
- reviewed at planned intervals and after significant changes or incidents to ensure it remains effective and aligned with ISO 22301:2012 and business needs.
Signed:
Position:
Managing Director
Review History
| Reviewed | 05/01/2022 | 14/11/2022 | 23/10/2023 | 09/01/2024 | 01/01/2025 |
|---|---|---|---|---|---|
| Amendments | None | None | None | None | None |