This article is the second of a four-part series that discusses the key elements of NFPA 1660 (2024) Standard for Emergency, Continuity, and Crisis Management: Preparedness, Response, and Recovery.
The first article in the series introduced the significant consolidation of the NFPA’s Emergency Response and Responder Safety (ERRS) standards, emphasizing the importance of preparedness, response and recovery in today’s unpredictable and risk-prone environment. Highlighting the integration of past standards into a streamlined NFPA 1660, it discusses the enhanced usability and quality aimed at helping organizations effectively manage a variety of risks – from natural disasters to cybersecurity threats. This article will look more closely at Chapters 4 (Program Management), Chapter 5 (Planning) and Chapter 6 (Implementation), looking at how these consolidated guidelines provide a comprehensive planning and implementation to disaster preparedness, assisting organizations in enhancing resilience and ensuring operational continuity amid crises. The third article will follow on from these themes and look at the execution, training and education within the strategies within NFPA 1660. Within this article the reference to Entity means person, organization or group that is responsible for the implementation and/or fulfilment of the requirements and considerations of NFPA 1660.
The standard outlines the requirements for developing, implementing, maintaining and evaluating an emergency management and disaster response program. It is intended to help organizations prepare for and respond to emergencies effectively, ensuring that they can protect lives, property and the environment during incidents focusing on the key elements for success, such as:
- Program management: guidance on administration, finance and logistics necessary to support the program.
- Planning: details on preparing emergency operations plans, including the process for developing, approving and maintaining these plans.
- Implementation: focuses on the necessary steps for executing plans during an actual emergency, including procedures for emergency response, recovery and mitigation activities.
- Testing and evaluation: involves procedures for testing and evaluating emergency plans and capabilities through drills, exercises and other assessment tools.
- Revision: methods for updating plans based on lessons learned and changes in the environment or resources.

Planning and implementation strategies
The planning process details the steps involved in developing emergency operations plans, including stakeholder engagement and plan formulation. The implementation considerations explain how to effectively implement these plans in real-world scenarios, focusing on coordination, resource allocation and the roles of various stakeholders during an emergency.
A program coordinator shall be appointed by the entity’s leadership and authorized to develop, implement, administer, evaluate and maintain the program. Performance objectives shall be developed by the entity to address both short-term and long-term needs, which they should define as part of this process. In addition, a program committee shall be established by the entity in accordance with its policy. This committee shall provide input or assist in the coordination of the preparation, development, implementation, evaluation and maintenance of the program. The committee shall include the program coordinator and others who have the expertise, the knowledge of the entity and the capability to identify resources from all key functional areas within the entity. The program committee shall solicit applicable external representation.
Program management overview
A comprehensive program management framework is crucial for effective organizational operations, especially when addressing emergency preparedness and response. The documented program should encompass several core elements:
- Executive policy: This should clearly define the vision, mission statement, roles, responsibilities and enabling authority of the program, establishing a solid foundation for all subsequent activities.
- Program scope and objectives: It includes defining the scope, goals and performance objectives of the program, alongside metrics for evaluating these objectives to ensure they meet the strategic aims of the organization.
- Compliance and legislation: The program must adhere to applicable authorities, legislation, regulations and industry codes of practice, ensuring all activities are compliant with legal and regulatory frameworks.
- Budgeting and scheduling: Detailed planning regarding the program’s budget and schedule, including critical milestones, is essential. This section should cover anticipated costs, prioritization of activities and resources required.
- Operational plans and procedures: Development of detailed plans and procedures is necessary for the effective implementation of the program. These plans should address the logistics of resources, management of changes and records management practices.
- Financial and administrative framework: A robust financial and administrative strategy should be in place to support the program’s activities before, during and after incidents. This includes procedures for expediting fiscal decisions, managing program finances, procurement, payroll and tracking/documenting costs.
- Records management: Effective records management is critical. The program should ensure that vital records (both hard copy and electronic) are identified, backed up regularly, and can be retrieved and recovered as needed. Additionally, procedures should be established for the protection and access of these records.
This management framework is designed to enhance preparedness across various domains – prevention, mitigation, response, continuity and recovery – integrating an ‘all-hazards’ approach through a comprehensive risk assessment.
Risk assessment
A thorough risk assessment is pivotal for the development and implementation of effective strategic plans within an organization. This process involves identifying potential hazards and assessing their likelihood and potential impact on the entity’s operations. The planning process should integrate a Business Impact Analysis (BIA) to forecast the consequences of disruptions to business functions and processes, allowing for the creation of strategies focused on prevention, mitigation and quick recovery. Key components of the risk-assessment process include:
- Strategic planning: This foundational step involves defining the organization’s vision, mission and goals, which guide the subsequent risk-assessment and management strategies.
- Hazard identification: A comprehensive list of potential hazards should be identified, encompassing a wide range of factors:
- Natural hazards such as earthquakes, floods and hurricanes.
- Human-caused incidents including accidents like fires and explosions, as well as intentional acts such as cyber-attacks and terrorism.
- Technological and operational disruptions such as power outages, IT system failures and supply chain interruptions.
- Economic, financial and strategic risks including economic downturns, strategic failures and financial crises.
- Involvement of key stakeholders is crucial in the risk-assessment process to ensure a comprehensive understanding of risks and their potential impacts across all areas of the organization.
- Development of response and recovery plans: based on the identified risks and their analysis, the organization should develop detailed emergency operations/response plans, crisis communication strategies, and continuity and recovery plans.
By conducting a risk assessment that evaluates the full spectrum of potential risks and their impacts, organizations can create robust strategies that enhance their resilience, ensuring they are prepared to manage and recover from adverse events efficiently.

Implementation of emergency and crisis management plans
Effective implementation of emergency management plans involves thorough planning processes that consider various scenarios and their potential impacts. This includes making key assumptions, defining functional roles, establishing lines of authority and setting up processes for the delegation of authority and succession. Central to the plans are the health and safety of personnel. This entails identifying necessary logistics support and resource requirements to ensure safety during emergencies. The entity should develop strategies aimed at preventing incidents that threaten life and property and mitigating those that cannot be prevented. These strategies are based on comprehensive hazard identification and risk assessments, and they include both immediate and long-term actions to reduce vulnerabilities.
Establishing a robust crisis management capability is crucial. This includes engaging senior leadership, detecting early warning signs, conducting situation analyses, declaring crises and activating crisis management plans. It also involves developing strategies to mitigate potential impacts and coordinating crisis communication efforts. Effective communication strategies and plans must be developed to manage information dissemination to internal and external audiences before, during and after an incident. This includes setting up a central contact facility or communications hub and developing protocols for issuing warnings and managing crisis communications.
The entity must coordinate and implement detailed operational procedures to support the overarching program. These procedures should cover response and recovery from incidents, control access to affected areas, account for personnel and manage resources effectively. It’s also essential to maintain an incident management system to coordinate response, continuity and recovery operations. Effective resource management involves establishing processes for describing, inventorying, requesting and tracking resources, ensuring they are mobilized and demobilized efficiently according to the needs of the incident management system.
Continuity plans should include strategies to continue critical processes identified in the Business Impact Analysis (BIA). Recovery plans should focus on restoring processes and systems and include detailed roles and responsibilities for implementing recovery strategies. Through these comprehensive steps, the entity can ensure it is well-prepared to handle emergencies and crises effectively, minimizing impacts and facilitating a quicker return to normal operations.
As we delve into the operational intricacies of NFPA 1660 in this second article of our four-part series, we underscore the importance of strategic alignment and comprehensive planning in bolstering organizational resilience. The chapters discussed provide a blueprint for developing, implementing and maintaining robust emergency, continuity and crisis management programs. By integrating a thorough risk-assessment process that includes a Business Impact Analysis (BIA), the standard guides entities through a meticulous planning phase that anticipates various crisis scenarios and their potential impacts. This proactive approach is crucial for preparing organizations to not only face emergencies effectively but also recover from them swiftly and efficiently, thereby ensuring continuity of operations and the protection of critical assets.
The third article in this series will further explore the vital components of executing these strategies, focusing on training and education to ensure that plans are not only in place but also actionable when required. Through this series, NFPA 1660 is shown as an essential standard that equips organizations to navigate the complexities of modern-day risks and threats, enhancing their preparedness in an ever-evolving risk landscape.
About the Author
Branch President, GCC Branch – The Institution of Fire Engineers.
