Business Continuity Planning: IT Security and Maturity Models
This paper examines Lindstrom, Samuelsson, and Hagerfors's (2010) research on business continuity planning methodology, focusing on how three organizations approach continuity planning from an IT security perspective. The paper highlights the finding that only 30% of senior and middle managers recognize IT security as a strategic weakness requiring ongoing improvement. It discusses the critical role of senior management commitment and education, the value of cyclical continuity strategies in smaller organizations, and the progression of organizational maturity in responding to IT security threats. A staircase maturity model illustrating organizational development in business continuity is also described.
- Overview of Business Continuity Planning Methodology: Introduction to IT security continuity planning research
- Continuity Planning as a Strategic Task: Senior management commitment to continuity strategy
- Cyclical Strategies in Smaller Organizations: Cyclical learning models in smaller organizations
- The Maturity Model and Organizational Culture: Staircase maturity model and cultural change
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- The paper grounds its analysis in peer-reviewed empirical research, citing multiple studies to build a coherent argument about the gaps in business continuity planning.
- It draws a clear connection between senior management commitment and the effectiveness of IT security strategies, making an organizational behavior argument supported by evidence.
- The inclusion and explanation of a maturity model ("staircase" methodology) gives the paper a concrete visual anchor that reinforces the theoretical discussion.
Key academic technique demonstrated
The paper demonstrates synthesis of multiple secondary sources to support a central claim. Rather than summarizing one article in isolation, it weaves together findings from Lindstrom et al. (2010) and Botha and Von Solms (2004) to show converging evidence for the importance of senior management involvement and ongoing education in business continuity planning.
Structure breakdown
The paper opens with an introduction to the primary source and its central finding about managerial awareness. It then moves into a focused discussion of continuity planning as a strategic, rather than purely technical, responsibility. Smaller organizations and their cyclical learning approaches are presented as a counterpoint model, before the paper closes with a discussion of the maturity model and its implications for organizational culture and funding.
Overview of Business Continuity Planning Methodology
In Business Continuity Planning Methodology, Lindstrom, Samuelsson, and Hagerfors (2010) provide insights into how three organizations have structured their continuity planning from an IT security perspective. The authors contend that only 30% of middle and senior management executives recognize that IT security is a strategic weakness in organizations — one that must be continually improved upon and kept current to protect information assets. The authors make this point to underscore the critical need for a continuity planning methodology that encompasses not just systems, but also processes and roles. One of the major outcomes of their research is the definition of a maturity model, described further below.
Continuity Planning as a Strategic Task
Citing results from studies conducted across three different organizations, the authors support the hypothesis that contingency planning is typically managed only at the IT level, rather than at the process or role-based level. They contend that much greater levels of education and commitment on the part of senior management are needed. Several studies cited by the authors demonstrate what a significant difference senior management support and commitment make to the development of an effective business continuity strategy. These studies are corroborated by the authors' own research, which reveals a persistent lack of commitment, ongoing education, and preventative strategies within organizations.
References
Botha, J., & Von Solms, R. (2004). A cyclic approach to business continuity planning. Information Management & Computer Security, 12(4), 328–337.
Lindstrom, J., Samuelsson, S., & Hagerfors, A. (2010). Business continuity planning methodology. Disaster Prevention and Management, 19(2), 243–255.
Always verify citation format against your institution’s current style guide requirements.