All compliance pages

Business Continuity Policy

Last reviewed: Updated 2025

Plans and strategies to ensure operational resilience and key services survival during unforeseen crises.

BUSINESS CONTINUITY POLICY

Policy Overview

FieldDetails
Reference No.DJTMPL/IT/POL/BCP
Document NameBusiness Continuity Policy
Policy OwnerChief Operation Officer
Policy Approving AuthorityBoard Of Directors
Version No.1.0
Document StatusDefinitive
Issue Date01-04-2026
Compliance StatusMandatory
Next Review PeriodOne year from the date of release or earlier if required
Security ClassificationInternal Use Only
DistributionDJTMPL

Document Revision History

VersionRelease DateChange Description
1.001-04-2026First version

TABLE OF CONTENT

S. NoParticulars
1.Overview
2.Policy Statement
3.Purpose
4.Scope
5.Definition
6.Process
7.Responsibility

1. Overview

The aim of business continuity system is to prevent, identify and eliminate the risks of business interruption, as well as to create conditions for business recovery if such interruption occurs. Business continuity system is one of the most important components of the DJTMPL, which makes it possible to avoid and prevent the risks of business interruptions, maintain and enhance DJTMPL image among its consumers, Business Partners, and public officials (“Parties Concerned”), strengthen confidence in DJTMPL and improve loyalty.

2. Policy Statement

To meet the enterprise business objectives and ensure continuity of its operations, DJTMPL shall adopt and follow well-defined and time-tested plans and procedures, build redundancy in teams and infrastructure and manage a quick and efficient transition to the backup arrangement for business systems and services. Business Continuity Management (BCM) Policy reiterates the commitment of DJTMPL towards delivering the fastest transition and the highest quality of services through backup arrangements ensuring that the customers, business activities, and services do not suffer in any way. The Business Continuity Management Procedure, Backup Policy, and Backup Procedure shall be referred. The plan shall be available to the CISO and BCM team members of DJTMPL.

3. Purpose

The main objective of Business Continuity Management is to minimize/eliminate the loss to DJTMPL’s business in terms of revenue loss, loss of reputation, loss of productivity, and customer satisfaction. The Business Continuity Policy intends to:

a. establish a systematic approach for business continuity;

b. create awareness amongst the concerned employees, about the business continuity aspects of ISMS and its importance; and

c. test and review the business continuity plan for the organization.

4. Scope

This Policy is applied to all employees and officers hired under the fixed-term employment contracts, top managers and members of DJTMPL Board of Directors (“Employees”), as well as to all contractors, consultants, distributors, resellers and other representatives acting on behalf of DJTMPL (“Business Partners”). The policy complies with international and national documents regulating business continuity.

5. Definition

The components of business continuity are:

Strategy: Objects that are related to the strategies used by the business to complete day-to-day activities while ensuring continuous operations

Organization: Objects that are related to the structure, skills, communications and responsibilities of its employees

Applications and data: Objects that are related to the software necessary to enable business operations, as well as the method to provide high availability that is used to implement that software

Processes: Objects that are related to the critical business process necessary to run the business, as well as the IT processes used to ensure smooth operations

Technology: Objects that are related to the systems, network and industry-specific technology necessary to enable continuous operations and backups for applications and data

Facilities: Objects that are related to providing a disaster recovery site if the primary site is destroyed

The business continuity plan becomes a source reference at the time of a business continuity event or crisis and the blueprint for strategy and tactics to deal with the event or crisis.

6. Process

“Plan-Do-Check-Act” model is used to implement the business continuity processes. Key elements of this approach are as follows:

1. Business continuity policy is a document that regulates activities aimed at ensuring DJTMPL’s business continuity.

2. Risk assessment means identification, analysis and assessment of risk impact on DJTMPL’s business.

3. Analysis of incident impact on business is the analysis and assessment of possible impact of incidents on DJTMPL’s business processes.

4. Crisis management (planning) is a strategic planning to ensure DJTMPL’s business continuity, which includes the pre-developed principles of crisis management in case of the following scenarios: lack of personnel availability, lack of building/office availability, lack of infrastructure availability, lack of data availability and lack of suppliers availability.

5. Business continuity plan is a documented procedure or several procedures to be applied in the event of business interruption.

6. Recovery Plan is the process applied to recover and protect the infrastructure.

7. Incident management (planning) is a plan of actions to minimize impact of incidents on personnel and business processes.

8. Crisis communications (planning) is the pre-established and documented priorities in communications and ways to alert of the incidents.

9. Testing and training — DJTMPL carries out various trainings to get the employees prepared for the incidents; DJTMPL also performs regular tests based on various scenarios.

The following illustrates a business continuity planning process used by DJTMPL and its subsidiaries. It is a closed loop that supports continuing iteration and improvement as the objective. There are three major sections to the planning process:

Business prioritization: Identify various risks, threats and vulnerabilities, and establish priorities.

Integration into IT: Take the input from business prioritization and perform an overall business continuity program design.

Manage: Administer what has been assessed and designed.

Improvement of efficiency — DJTMPL regularly reviews its business continuity procedures.

7. Responsibility

All Employees bear responsibility for the compliance with this Policy and any other documents aimed at its implementation. Failure to comply with the requirements of this Policy shall be the ground for disciplinary action up to dismissal of Employees. DJTMPL top managers are entrusted with the control over compliance with this Policy.