The organisation should create a communication plan as part of its overall resilience planning. The plan should describe how staff are kept informed about matters affecting security and resilience and how relevant information is communicated to external parties in extraordinary situations.
External parties can include, for example:
- Emergency response units
- Critical infrastructure entities
- Providers of essential services
- The public
- Media
- Customers
The plan should communicate how daily operations and essential functions will be restored rapidly at the managerial, operational and security levels. The channels, responsibilities, and content for various types of communication should be defined. This can include incident alerts, risk updates, and changes to security procedures. The communication plan should be regularly exercised and evaluated.