An integrated framework for business continuity management of critical infrastructures

Business continuity of critical infrastructures (CIs) is exposed to various hazards including random failures, malicious threats, natural disasters and human errors, which could generate accidents with serious consequences (fatality, injury, environmental damage, business interruption and company reputation loss). We conceptualize the business continuity management (BCM) process as the integration of four active stages: prevention, mitigation, emergency and recovery. Integrated assessment and management is needed on all stages. On the contrary, the current approaches of BCM have not considered all phases in an integrated man-ner. We propose a new framework, which stands on an extension of the Bow-Tie model, to efficiently and effectively prevent and mitigate the potential consequences of an accident by properly designing and strengthening safety barriers for preventing and mitigating accidents, and making safety decisions for emer-gency and recovery. The proposed framework allows considering safety barriers and decisions in an integrated way. For operationalization, we explore the use of two complementary quantitative methods, Bayesian Network (BN) and Constraint Goal Method. BN takes the “negative” viewpoint of failure to determine the causes which lead to the final damage. CGM employs the positive perspective of the goal achievement process. An oil pipeline system is considered to show the application of the proposed approaches.