BC / DR Implementation Tying Disaster Recovery Investment to Measurable Business Value

Size: px
Start display at page:

Download "BC / DR Implementation Tying Disaster Recovery Investment to Measurable Business Value"

Transcription

1 BC / DR Implementation Tying Disaster Investment to Measurable Business Value Continuity Insights Conference May 16-18, 2005 Agenda Purpose Discuss best practice process and tools that might be leveraged to accelerate IT Disaster program Agenda Introductions Level-set Business Continuity terminology and concepts Best practice BC / DR program implementation considerations BC / DR Integration Issues 2 Implementation Considerations The Business Continuity Program Life Cycle modified U.S. DoD graphic Normal Operations Incident Occurs Return to Normal Operations Capability Minimum Acceptable Level of Capability Emergency Response Risk Avoidance Risk Mitigation Restoration Contingency Planning and Crisis Management Proactive BCM Activities Prevention and Preparedness Risk Avoidance Proactive BCM Activities Reactive BCM Activities Prevention and Preparedness Response, & Restoration 3 1

2 What is Business Continuity? The four central disciplines Incident Management All aspects of emergency response, crisis management, and any other activities involved in command, control, and communications during a disastrous event Security Management Physical security, information security, and any other activities associated with protecting the integrity of targeted information and Technology Ensuring that all critical assets including information systems hardware, software, networks and applications are recoverable within defined recovery time objectives Business Ensuring that critical business functions and are recoverable within defined recovery time objectives 4 The Business Continuity Plans 6 BC Plans Working Together Incident Occurs Normal Operations Mitigation Action Plan may allow organization to avoid disruption Crisis Management Plan Activated Emergency Response Preparing for and of Damage Assessment Critical Operations Normal Operations Minimal Acceptable Level of Capability Hour 0 Begins Operating in Implement mode Restoration Plan Disaster Plan Activated Restoration Back to in place Begins Normal Emergency Response Plan Save lives and protect assets Conduct damage assessment Site Emergency Operations Center (EOC) Crisis Management Plan Executive Command Center (ECC) Regional and/or higher ECC(s) activated Command, Control, and Communications Mitigation Action Plan Tasks to initiate mitigation action(s) Avoid or minimize disruption Business Plan Ensure that critical functions continue to be performed Departmental Plans Requires EOC communications and authorizations Disaster Plan Ensure critical technical infrastructure is available Hot site recovery Restoration Plan A plan to return to normal operations 5 BC / DR Program Launch Strategy 7-Step approach to a sustainable BC / DR program Steps 1 6: BC / DR Project 1-time project Initiate BC / DR at sites in scope Integrate all BC disciplines Develop initial BC / DR plans Conduct first BC / DR plan tests Step 7: BC / DR Program Institutionalize BC / DR Annually repeat Steps 1 6 Link to Change Management Evolve BC / DR competency Utilize Business Continuity Maturity Model SM Improve state-of-preparedness 6 2

3 DR Methodology Summary Current status of your Company s DR Initiative Step 1- Scope DR Project Assemble Project Leadership Team Assemble Local Implementation Team Assemble Technology Teams incl. solution engineering / implementation Determine systems "in scope" and "out-of-scope Step 2 - Conduct DR Data Collection Business Impact Data Application and Systems Impact Data Step 3 - Complete DR Impact Analysis RTO determination RPO cost/benefit analysis System Dependency Analysis incl. infrastructure systems Physical / cyber / business risk assessment 7 DR Methodology Summary Current status of your Company s DR Initiative Step 4 - Formulate DR Strategies Systems Scalability Sequence DR Strategy Workbook Solution Engineering Authorization to proceed Step 5 - Implement Solutions and Document DR Plans Solution implementation Assemble DR Organization Document DR Plans Desk Check DR Plans 8 DR Methodology Summary Current status of your Company s DR Initiative Step 6 Test DR Plans Develop DR Test Strategy Schedule DR Test Conduct and Monitor DR Test Post-mortem DR Test Step 7 Maintain DR Plans Update DR Plans Link DR Plans to ISM Change Management Baseline DR Competency Establish Competency Goals and Annual Program 9 3

4 PAGE 1 Step GLOBAL BUSINESS CONTINUITY & DISASTER RECOVERY - LEVEL 0 PROCESS FLOW REVISION: DATE FEB 3, 2004 Step Step Step Step BC / DR Best Practices Implementing Sustainable BC / DR Programs Aventis BC/DR Implementation Governance and program support Board of Management Finance and Audit Committee Aventis Risk Council Collection, cross-functional evaluation, and prioritization of risks Review and monitor implementation timelines of plans to manage risks Recommend key business processes to be reviewed; Collaborate on processes and communications to build risk anticipation & proactivity and foster a culture of courage in risk reporting Aventis Operations Management Committee (OMC) Linked / Integrated with: Crisis Management SOX, Internal audit CFR Part 11 HIPAA Info Solution (ISM) policy Global Implementation Team (GIT) Program Management Daily BC program coordination / direction Project planning, control, and reporting Program communications BC / DR Center of Excellence BC / DR experts, program framework, toolkit, implementation support, and training of global BC/DR Business Continuity Council (BCC) Program Strategy Support Support the GIT in their strategic and operational planning; Review and provide feedback on program-wide goals, processes, and tools Business Function Liaison Serve as liaison to assure business needs are met, always keeping in mind that responsibility for implementing BC/DR lies within the Business In-country BC / DR Program Implementation Teams Global Processes and Systems DIA, IO, Comm Opes, F&A, Pasteur Regional Processes and Systems Europe, N.A., Asia, S.A., C.A., Africa Support Processes & Systems IS, Legal, QC, HR, Logistics, etc. 11 BC / DR Implementation Methodology 5-Step Process to Build & Test 1 st BC / DR Plans Step 1 Scope BC/DR Program Assemble team Define Scope Communicate project plan Global Business Continuity, Disaster - Level 0 Process Flow Process Number: 18 Step 2 Conduct BIA & Risk Assessment Conduct BIA survey Identify material process RTOs Identify material system RTOs Assess material process & systems risk Process Initiators Business change Systems change Periodic review Scope BC / DR Program 1 2 Understand Business Impact Complete Risk Assessment 3 Step 3 Formulate BC/DR Strategy Define & cost justify BC strategies Define & cost justify DR strategies Identify capex / opex requirements and timing Step 4 Build Process / Systems, Assemble Teams, and Document Plans Engineer & implement approved processes and systems Assemble & train recovery teams Document BC / DR Plans Step 5 Test and Update Plans Schedule and conduct DR / BC tests Update BC / DR plans, as required Identify & train site BC / DR Committee 5 Test and Update BC / DR Plans Exception Handling Build Approved Process / Systems Assemble Teams & Document Plans 12 4 Develop BC / DR Strategy 4

5 In Parallel with BC Program Launch Disaster Program Deliverables DR PROGRAM DR Program Charter Program (project) Plan, Milestones, Responsibilities DR Information Repository Periodic Status Reports DR STRATEGIES, FRAMEWORK, SERVICE LEVELS Preliminary DR Framework and Strategies Document Preliminary DR Service Level Catalogue Final DR Framework and Strategies Document Final DR Service Level Catalogue DR BASELINE PHASE 1 (Regulatory Compliance Applications) Project Plan Affected Applications List Baseline SOPs/Guidelines/Standards Back Up /Restore Validation Current Operating Gap analysis Validation / Testing Recommendation Implementation plan BUSINESS CONTINUITY FOR IS BIA s Risk Assessment Dependency analysis IS Process Strategy plans for Material Application and Infrastructure Services IMPLEMENT VERY HIGH DR SERVICES Material VH Application Inventory VH Applications DR requirements VH DR SOP/Guidelines/Standards Very High DR Service Infrastructure Recommendations Detailed Implementation schedules and project plans CREATE ENTERPRISE DATA CENTER DRP S DRP Standards, Guidelines Document Create self-directed Data Center DRP toolkit Major Data Center DRP Review & assessment. Implementation plan CREATE A SUSTAINABLE DR CAPABILITY ISM Update DR Roles and Responsibilities Document DR Change Management plan Implementation plan 13 BC / DR Methodology Summary A best practice approach to a sustainable program Step 1- Scope DR Program Assemble IT Disaster Program Resources Program Leadership Team Local Implementation Team Technology Teams incl. solution engineering / implementation Engage the Business Quantify executive risk appetite Get it right up front BC vs. DR-driven program and minimize Define and Document DR Vision confusion and redundant work effort Connect to BC/DR Program Design throughout Disaster Service Catalog implementation and Disaster Framework support efforts Disaster Strategies Bounding the DR Program ( Changing tires on a moving taxi ) Determine Systems In Scope" and Out-of-Scope Determine breadth of BC / DR data collection Initial Engineering of Infrastructure and Enterprise Application DR Solutions 14 IT Disaster Program Resources Implementation team for enterprise DR Implementations Enterprise DR Leadership Team (IT-SLT) Oversight and governance for Global DR program Provider of DR implementation Approver of DR policies, strategies, standards, and tools Final escalation point for resolving DR-related conflicts Business owners for their areas relative to BC for IS project (function as LIT) Speak for the business when defining DR business requirements for IS Shared Systems Preference: direct engagement with the business Enterprise Disaster Working Team Creator of methods and tools Manager of DR infrastructure projects Coordinate AG participation, as required Primary resource pool Initial escalation point for resolving conflict Site DR Working Teams To be formed as needed Enterprise DR Working Team Membership Sponsor: Chairperson: DR Strategy Lead: Data Center Consolidation Rep: Business Rep: Consulting Team Rep: GIS Functional Leads: Service Delivery Storage Platform Architecture Data Base Server Operations Network Operations Solutions Team Member Other Stakeholders: AGs, AIS, Business contacts 15 5

6 Engage the Business How much DR investment is appropriate? Materiality (protecting shareholder value) Quantify risk appetite for financial impact Establish implementation standards BIA Survey data provides details to determine process materiality Our Experience: System RTOs derived from business RTOs >60% of previously committed IS DR investments exceeded business requirements Significant reduction in DR CAPEX / OPEX Impact Categories determine level of BC/DR protection required 16 BC / DR Integration Issues Alternative Methods to Engage the Business Option #1 DR-driven project Assemble IT who can intuitively quantify business impact of disrupted applications Workshop to quantify impact Financial Legal Other preset measures Business executive signs-off on established RTOs Proceed with Disaster Steps 3 thru 7 Option # 2 Business-driven project Engage business at Step 1 Define Materiality criteria Conduct true Business Impact Analysis incl. application impacts System RTOs driven from BIA findings Proceed with BC / DR Steps 3 through 7 17 Define and Document Program Vision Connecting to Business Continuity Program Design Deliverables Relationship Chart Goal: Design an appropriately scaled and sustainable BC / DR Program High-Level Enterprise BIA Foundation Materials BIA Interview Results BIA Analysis Findings BC Program Design Roles & Work List Responsibilities Tools Document Grid BC Program Implementation Plan Business Continuity Function Plan Budget Staffing Plan Documents AIA to BIA Bridge Document Senior Management Authorization to Proceed BIA Findings Document BC Glossary BC Program Orientation Materials BC 1-Page Handout 18 6

7 Enterprise Business Impact Analysis Summary Build the Business Case for implementing a sustainable BC program (start building sr. mgmt support and commitment) Identify organization exposures, threats and risks and the adverse business impacts that might occur Prioritize launch sequence for all departments / business functions included in BC program launch High-Level Enterprise BIA Foundation Materials BIA Interview Results BIA Analysis Findings AIA to BIA Bridge Document BIA Findings Document 19 BC Program Design Summary Define BC delivery organization required to achieve conceived vision Work List BC Program Design Roles & Responsibilities Grid Tools Document Develop implementation plan based on thorough understanding of work to be done and how it can be achieved within your organization Business Continuity Function Plan BC Program Implementation Plan Budget Staffing Plan Documents Gain senior management commitment to and participation in your BC program launch Senior Management Authorization to Proceed BC Program BC 1-Page BC Glossary Orientation Handout Materials 20 Define and Document Program Vision Disaster Service Level Catalog Business Requirements for Service Level Categories BASE MED HIGH VERY HIGH IS will deliver 4 DR Service Levels Based upon Business Requirements Point Restoration These requirements will be identified through the Business Continuity project/s. Determinants of a DR Service Level Category Character istics of a DR Service Level Category time time time time is based on within 1 to 6 weeks within -7 1 days within 24 hours best effort (to minimum service level) Restoration restored based restored within 2 restored within 2 restored within on best effort months weeks 1 week (to full production capacity) to to latest to of latest full full weekly and latest full weekly latest 2 hours Point weekly and incremental daily and incremental of data incremental backup. All tapes daily backup. All collected daily backup. are stored off site. tapes are stored All tapes are off site. stored off site. Infrastructure No dedicated Limited physical Required physical Required facilities or physical facilities & are identified identified and plan made available are exists to acquire within recovery made available additional within the time. Plan exists within recovery Required timeframe. to acquire time. additional within the Required timeframe. DR plan DR plan is DR plan is DR plan available DR plan and stored both available and not mandatory not mandatory on and off site. stored both on DR plan tested and off site. once a year. DR plan tested twice a year. 21 7

8 (to minimum service level) (to full production capacity) time is based on best effort restored based on best effort to latest full weekly and incremental daily backup. All tapes are stored off site. No dedicated facilities or identified DR plan available and stored both on and off site. DR plan test is not mandatory time within 4 days to 1 week restored within 1 month to latest full weekly and incremental daily backup. All tapes are stored off site. Required physical identified and plan exists to acquire them within the Required timeframe. DR plan available and stored both on and off site. DR plan tested once a year. time within 1-3 days restored within 2 weeks to latest full weekly and incremental daily backup. All tapes are stored off site. time within 24 hours restored within 1 week of latest 2 hours of data collected Limited physical Required physical are made available are within recovery made available time. Plan exists within recovery to acquire time. additional within the Required timeframe. DR plan available and stored both on and off site. DR plan tested once a year. DR plan available and stored both on and off site. DR plan tested twice a year. DR Framework DR Services are described via the adoption of a consistent Framework which is used Globally to define the components that make up the DR services BASE MED HIGH VERY HIGH Data Backup Storage Disaster Services Infrastructure Facilities Computing Network Shared Services End User 22 Business Requirements Determine Service Levels Service Levels and Framework Combine to define Standardized Strategies Business Requirements for Service Level Categories Service levels Determine DR strategies / solutions BASE MED HIGH VERY HIGH Determinants of a DR Service Level Category Restoration BASE MED HIGH VERY HIGH Character istics of a DR Service Level Category Point Infrastructure facilities & DR plan Disaster Services Data Backup Storage Infrastructure Facilities Computing Network Shared Services End User 23 Standardized Strategies leveraged across the enterprise Standardized Strategies were selected for each Service level based upon best practices and Program objectives. Then as specific solutions were engineered, these Strategies were validated against the real applications business requirements. Data BASE MED HIGH VERY HIGH Backup Tape Tape Tape evault Storage Offsite Offsite Offsite Infrastructure Facilities Best Efforts Intra company Computing Best Efforts w/ Leverage Existing Bias Network Redundant Replaceme nt Shared Services Substitution Unlike Leverage Existing nonmaterial H/W Split Coml. Mobile Coml Vendor Intra Company Leverage Existing nonmaterial H/W Co Location Coml Vendor Coml Vendor evault Asynch Disk to Disk Redundant Hot Site Redundant Best Efforts Pre Wired Pre Wired Pre Wired Collaboration Services Systems Management Software Distribution Routing Redundancy BU & Servers InfoSec Remote Access Support Desk 24 8

9 Bounding the BC / DR Program Changing tires on a moving taxi Determine functions, sites, and systems that are In Scope" and Out-of-Scope Intuitive scoping exercises Establish local buy-in Determine breadth of BC / DR data collection What and how much data to be gathered from whom Finalize data collection / validation process Initial Engineering of Infrastructure and Enterprise Application DR Solutions Leveraging capital infrastructure and improvements 25 DR Methodology Summary A best practice approach to sustainable program Step 2 - Conduct BC / DR Data Collection Business Functions / Processes Work Inflows / Outflows (functional dependencies) Vital Records Requirements Business Impacts Known Mitigation, Safeguard, and Contingency Strategies Resource Requirements IT Applications, Network, and Other Infrastructure Systems Impacts Step 3 - Complete DR Impact Analysis RTO determination RPO cost/benefit analysis System Dependency Analysis incl. infrastructure systems Physical / cyber / business risk assessment 26 DR Methodology Summary A best practice approach to sustainable program Step 4 - Formulate DR Strategies Systems Scalability Sequence DR Strategy Workbook Solution Engineering Authorization to proceed Step 5 - Implement Solutions and Document DR Plans Solution implementation Assemble DR Organization Document DR Plans Desk Check DR Plans 27 9

10 DR Methodology Summary A best practice approach to sustainable program Step 6 Test DR Plans Develop DR Test Strategy Schedule DR Test Conduct and Monitor DR Test Post-mortem DR Test Step 7 Maintain DR Plans Update DR Plans Link DR Plans to ISM Change Management Baseline DR Competency Establish Competency Goals and Annual Program 28 Contact Information Scott W. Ream President Virtual Corporation (973) sream@virtual-corp.net Brian Bobich Chief Technology Officer Core Systems Group (732) brian@coresystemsgroup.com

Business Continuity / Disaster Recovery Context

Business Continuity / Disaster Recovery Context Capability Business Continuity / Disaster Recovery Context What is Business Continuity? The Business Continuity Program Life Cycle Copyright: Virtual Corporation, 1994 2006 Modified U.S. DoD Graphic Normal

More information

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS) Information Technology Disaster Recovery Policy Policy Statement This policy defines acceptable methods for disaster recovery planning, preparedness, management and mitigation of IT systems and services

More information

Business Continuity in Healthcare

Business Continuity in Healthcare Business Continuity in Healthcare Cynthia Simeone, CBCP, PMP Director Business Resilience Catholic Health Initiatives Scott Ream President Virtual Corporation 1 Session Speakers Cynthia Simeone, CBCP,

More information

Using the Business Continuity Maturity Model To Gain Executive Approval. June 20, 2006

Using the Business Continuity Maturity Model To Gain Executive Approval. June 20, 2006 Using the Business Continuity Maturity Model To Gain Executive Approval Margaret Langsett, Executive Vice President, Virtual Corporation Manfred Heinzlreiter, CBCP, Managing Partner, BR- i.com June 20,

More information

Building a Disaster Recovery Program By: Stieven Weidner, Senior Manager

Building a Disaster Recovery Program By: Stieven Weidner, Senior Manager Building a Disaster Recovery Program By: Stieven Weidner, Senior Manager Part two of a two-part series. If you read my first article in this series, Building a Business Continuity Program, you know that

More information

Business Continuity Plan

Business Continuity Plan Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions

More information

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 Agenda Key Definitions Risks Business Continuity Management Program BCM Capability Assessment Process BCM Value Proposition

More information

Business Continuity and Disaster Recovery Planning

Business Continuity and Disaster Recovery Planning Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services

More information

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14

More information

Tips and techniques a typical audit programme

Tips and techniques a typical audit programme Auditing Business Continuity Planning Tips and techniques a typical audit programme Karen Wills, Senior Internal Auditor St James s Place Wealth Management February 2014 Contents Background Roles and Responsibilities

More information

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com Fax: (718) 380-7322

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com Fax: (718) 380-7322 Business Continuity and Disaster Recovery Job Descriptions Table of Contents Business Continuity Services Organization Chart... 2 Director Business Continuity Services Group... 3 Manager of Business Recovery

More information

Business Continuity Program. EPC Quarterly Meeting November 5 th 2009 New York Presbyterian Cornell Campus

Business Continuity Program. EPC Quarterly Meeting November 5 th 2009 New York Presbyterian Cornell Campus Business Continuity Program EPC Quarterly Meeting November 5 th 2009 New York Presbyterian Cornell Campus A new era 2 GBeyond Emergency Management if 30%+ of MSK workforce is unavailable for work if IT

More information

William Rider Manager Disaster Recovery & Data Security The Johns Hopkins Health System & University

William Rider Manager Disaster Recovery & Data Security The Johns Hopkins Health System & University William Rider Manager Disaster Recovery & Data Security The Johns Hopkins Health System & University Competitive Leadership- Twelve Principles For Success Brian Billick Chapter 3 Be Be Prepared The time

More information

The Business Continuity Maturity Continuum

The Business Continuity Maturity Continuum The Business Continuity Maturity Continuum Nick Benvenuto & Brian Zawada Protiviti Inc. 2004 Protiviti Inc. EOE Agenda Terminology Risk Management Infrastructure Discussion A Proposed Continuity Maturity

More information

2014 NABRICO Conference

2014 NABRICO Conference Business Continuity Planning 2014 NABRICO Conference September 19, 2014 6 CityPlace Drive, Suite 900 St. Louis, Missouri 63141 314.983.1200 1520 S. Fifth Street, Suite 309 St. Charles, Missouri 63303 636.255.3000

More information

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD. Business Continuity Management & Disaster Recovery Planning Presented by: Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD. 1 What is Business Continuity Management? Is a holistic management

More information

SCADA Business Continuity and Disaster Recovery. Presented By: William Biehl, P.E. 913-601-0104 (mobile) Bill.Biehl@we-inc.com

SCADA Business Continuity and Disaster Recovery. Presented By: William Biehl, P.E. 913-601-0104 (mobile) Bill.Biehl@we-inc.com SCADA Business Continuity and Disaster Recovery Presented By: William Biehl, P.E. 913-601-0104 (mobile) Bill.Biehl@we-inc.com Business Continuity Planning, a Sound Process A Business Continuity Plan: "A

More information

Integrated Healthcare, Hospital and Medical Contingency Planning

Integrated Healthcare, Hospital and Medical Contingency Planning Integrated Healthcare, Hospital and Medical Contingency Planning James Paturas, CEM, EMTP, CBCP, FACCP Deputy Director, Clinical Services, Yale New Haven Center for Emergency Preparedness and Disaster

More information

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic

More information

9/3/2009. Information Systems Disaster Recovery. Learning Objectives. Why have a plan? unexpected? APPA-Institute for Facilities Management

9/3/2009. Information Systems Disaster Recovery. Learning Objectives. Why have a plan? unexpected? APPA-Institute for Facilities Management Information Systems Disaster Recovery APPA-Institute for Facilities Management J. Craig Klimczak, D.V.M., M.S. Vice-Chancellor for Technology St. Louis Community College 300 South Broadway St. Louis, MO

More information

CISM Certified Information Security Manager

CISM Certified Information Security Manager CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective

More information

Overview of how to test a. Business Continuity Plan

Overview of how to test a. Business Continuity Plan Overview of how to test a Business Continuity Plan Prepared by: Thomas Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com BRP/DRP Test Plan Creation and Exercise Page: 1 Table of Contents BCP/DRP Test

More information

Appendix 3 Disaster Recovery Plan

Appendix 3 Disaster Recovery Plan Appendix 3 Disaster Recovery Plan December 13, 2006 Revision XXQwest Government Services, Inc. 4250 North Fairfax DriveArlington, VA 22203(Delete this page)revision history Revision Number Revision Date

More information

NEEDS BASED PLANNING FOR IT DISASTER RECOVERY

NEEDS BASED PLANNING FOR IT DISASTER RECOVERY The Define/Align/Approve Reference Series NEEDS BASED PLANNING FOR IT DISASTER RECOVERY Disaster recovery planning is essential it s also expensive. That s why every step taken and dollar spent must be

More information

CERTIFIED DISASTER RECOVERY ENGINEER

CERTIFIED DISASTER RECOVERY ENGINEER CERTIFIED DISASTER RECOVERY ENGINEER KEY DATA COURSE OVERVIEW ACCREDITATION Course Title: C)DRE Duration: 4 days CPE Credits: 32 Class Format Options: Instructor-led classroom Live Online Training Computer

More information

CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM

CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM A WHITE PAPER CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM AUTHORS: Neil A. Smith, MBCP nsmith24@csc.com Sandra Riddell, MBCI sriddel4@csc.com CSC Papers 2013 ABSTRACT The auditors said

More information

DISASTER RECOVERY PLANNING GUIDE

DISASTER RECOVERY PLANNING GUIDE DISASTER RECOVERY PLANNING GUIDE AN INTRODUCTION TO BUSINESS CONTINUITY PLANNING FOR JD EDWARDS SOFTWARE CUSTOMERS www.wts.com WTS Disaster Recovery Planning Guide Page 1 Introduction This guide will provide

More information

Certified Disaster Recovery Engineer

Certified Disaster Recovery Engineer Cyber Security Training & Consulting Certified Disaster COURSE OVERVIEW 4 Days 32 CPE Credits $2,500 When a business is hit by a natural disaster, cyber crime or any other disruptive tragedy, how should

More information

Business Continuity Planning: Bridging the Gap Between IT and Business

Business Continuity Planning: Bridging the Gap Between IT and Business Business Continuity Planning: Bridging the Gap Between IT and Business Steve Burns, President EverGreen Data Continuity, Inc. sburns@evergreen-data.com 1 The Hard Facts One-third of businesses don t include

More information

Introduction UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT

Introduction UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT INFORMATION SECURITY: UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT FACTSHEET This factsheet will introduce you to Business Continuity Management (BCM), which is a process developed to counteract systems

More information

Protecting Your Business

Protecting Your Business Protecting Your Business Business Continuity/Disaster Recovery Planning Robert Haberman Senior Product Manager BCP/DRP TELUS BUSINESS SOLUTIONS Business Continuity/Disaster Recovery Planning 1 Agenda:

More information

Business Continuity. Port environment

Business Continuity. Port environment Business Continuity Port environment DEFINE BUSINESS CONTINUITY WHAT IT IS NOT RECOVERY FOCUS: PEOPLE PROCESSES TECHNOLOGY DELIVERABLES INFRAGARD DEFINITION MANAGEMENT PROCESS DEVELOPING ADVANCE PROCEDURES

More information

Business Continuity Planning:

Business Continuity Planning: Business Continuity Planning: How prepared must a CFO & other Executives be for a potential interruption to the business Presenter: Bruce L Scott, Partner Risk & Business Continuity Services June 2005

More information

Wilhelmenia Ravenell IT Manager Eli Lilly and Company

Wilhelmenia Ravenell IT Manager Eli Lilly and Company Wilhelmenia Ravenell IT Manager Eli Lilly and Company Agenda Introductions The Service Management Framework Keys of a successful Service management transformation Why transform? ROI and the customer experience

More information

How to measure your business resiliency

How to measure your business resiliency How to measure your business resiliency Define the KPI s/kri s and scorecards to control your security and business continuity capabilities Krzysztof Pulkiewicz BCMLogic krzysztof.pulkiewicz@bcmlogic.com

More information

Disaster recovery strategic planning: How achievable will it be?

Disaster recovery strategic planning: How achievable will it be? Disaster recovery strategic planning: How achievable will it be? Amr Ahmed Ernst & Young Advisory Services, Executive Director amr.ahmed@ey.com Christopher Rivera Ernst & Young Advisory Services, Manager

More information

Attachment to Data Center Services Multisourcing Service Integrator Master Services Agreement

Attachment to Data Center Services Multisourcing Service Integrator Master Services Agreement Attachment to Data Center Services Multisourcing Service Integrator Master Services Agreement DIR Contract No. DIR-DCS-MSI-MSA-001 Between The State of Texas, acting by and through the Texas Department

More information

Information Security Management: Business Continuity Planning. Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt.

Information Security Management: Business Continuity Planning. Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt. Information Security Management: Business Continuity Planning Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt. Overview BCP: Definition BCP: Need for (Why?) BCP: When BCP: Who

More information

CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT

CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT April 16, 2014 INTRODUCTION Purpose The purpose of the audit is to give assurance that the development of the Metropolitan Council s Continuity

More information

Business Continuity Planning 101. +1 610 768-4120 (800) 634-2016 www.strohlsystems.com info@strohlsystems.com

Business Continuity Planning 101. +1 610 768-4120 (800) 634-2016 www.strohlsystems.com info@strohlsystems.com Business Continuity Planning 101 Presentation Overview What is business continuity planning Plan Development Plan Testing Plan Maintenance Future advancements in BCP Question & Answer What is a Disaster?

More information

Temple university. Auditing a business continuity management BCM. November, 2015

Temple university. Auditing a business continuity management BCM. November, 2015 Temple university Auditing a business continuity management BCM November, 2015 Auditing BCM Agenda 1. Introduction 2. Definitions 3. Standards 4. BCM key elements IT Governance class - IT audit program

More information

How Kaiser Permanente Prepares for Emergencies

How Kaiser Permanente Prepares for Emergencies How Kaiser Permanente Prepares for Emergencies Skip Skivington Interim Vice President of Supply Chain Kaiser Permanente Oakland, CA Emergency Management Summit New Orleans, LA March 5, 2007 Kaiser Permanente

More information

NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems

NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems Marianne Swanson NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY 1 Table Of Contents Introduction to NIST SP 800-34

More information

Q uick Guide to Disaster Recovery Planning An ITtoolkit.com White Paper

Q uick Guide to Disaster Recovery Planning An ITtoolkit.com White Paper This quick reference guide provides an introductory overview of the key principles and issues involved in IT related disaster recovery planning, including needs evaluation, goals, objectives and related

More information

Continuity of Business

Continuity of Business White Paper Continuity of Business SAS Continuity of Business initiative reflects our commitment to our employees, to our customers, and to all of the stakeholders in our global business community to be

More information

IT Disaster Recovery Plan Template

IT Disaster Recovery Plan Template HOPONE INTERNET CORP IT Disaster Recovery Plan Template Compliments of: Tim Sexton 1/1/2015 An information technology (IT) disaster recovery (DR) plan provides a structured approach for responding to unplanned

More information

Virtualization for Consolidated Disaster Recovery with Agile360

Virtualization for Consolidated Disaster Recovery with Agile360 Virtualization for Consolidated Disaster Recovery with Agile360 Agenda 11:00am Overview by Brian Capoccia 11:05am Part I: Agile360 s Presentation by Kevin Burton 11:20am Part II: PlateSpin s Presentation

More information

Why Should Companies Take a Closer Look at Business Continuity Planning?

Why Should Companies Take a Closer Look at Business Continuity Planning? whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters

More information

State of South Carolina Policy Guidance and Training

State of South Carolina Policy Guidance and Training State of South Carolina Policy Guidance and Training Policy Workshop All Agencies Business Continuity Management Policy June 2014 Agenda Questions & Follow-Up Policy Workshop Overview & Timeline Policy

More information

Business Continuity Part 2 Converting Risk Assessments to Risk Mitigation Activities to Business Recovery Plans

Business Continuity Part 2 Converting Risk Assessments to Risk Mitigation Activities to Business Recovery Plans Business Continuity Part 2 Converting Risk Assessments to Risk Mitigation Activities to Business Recovery Plans Howard Pierpont Intel Corporation Hillsboro, OR Jan 2005 Corporate Business Principles Intel

More information

Business Continuity Position Description

Business Continuity Position Description Position Description February 9, 2015 Position Description February 9, 2015 Page i Table of Contents General Characteristics... 2 Career Path... 3 Explanation of Proficiency Level Definitions... 8 Summary

More information

JOB ANNOUNCEMENT. Chief Security Officer, Cheniere Energy, Inc.

JOB ANNOUNCEMENT. Chief Security Officer, Cheniere Energy, Inc. JOB ANNOUNCEMENT Chief Security Officer, Cheniere Energy, Inc. Position Overview The Vice President and Chief Security Risk Officer (CSRO) reports to the Chairman, Chief Executive Officer and President

More information

EMA Service Catalog Assessment Service

EMA Service Catalog Assessment Service MORE INFORMATION: To learn more about the EMA Service Catalog, please contact the EMA Business Development team at +1.303.543.9500 or enterpriseit@enterprisemanagement.com The IT Service Catalog Aligning

More information

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA 1 Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand

More information

OE PROJECT CHARTER TEMPLATE

OE PROJECT CHARTER TEMPLATE PROJECT : PREPARED BY: DATE (MM/DD/YYYY): Project Name Typically the Project Manager Project Charter Last Modified Date PROJECT CHARTER VERSION HISTORY VERSION DATE (MM/DD/YYYY) COMMENTS (DRAFT, SIGNED,

More information

July 30, 2009. Internal Audit Report 2009-08 Information Technology Business Continuity Plan Information Technology Department

July 30, 2009. Internal Audit Report 2009-08 Information Technology Business Continuity Plan Information Technology Department Internal Audit Report 2009-08 Introduction. The Municipality depends heavily on technology and automated information systems, and their disruption for even a few days could have a severe impact on critical

More information

Measuring Continuity Planning Program. Performance

Measuring Continuity Planning Program. Performance Measuring Continuity Planning Program Performance Carl B Jackson Director Crisis Management & Continuity Planning Resource Center (CMCPRC) Measuring Continuity Planning Program Performance Session Agenda

More information

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP IT Disaster Recovery Plan Template By Paul Kirvan, CISA, CISSP, FBCI, CBCP Revision History REVISION DATE NAME DESCRIPTION Original 1.0 2 Table of Contents Information Technology Statement

More information

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC Assessing Your Disaster Recovery Plans Gregory H. Soule, CPA, CISA, CISSP, CFE Andrews Hooper Pavlik PLC Andrews Hooper Pavlik PLC Agenda Business Continuity Concepts Impact Analysis Risk Assessment Risk

More information

COMMUNIQUE. Information Technology (IT) Governance Guidance

COMMUNIQUE. Information Technology (IT) Governance Guidance COMMUNIQUE 14-COM-002 July 14, 2014 Information Technology (IT) Governance Guidance The Credit Union Prudential Supervisors Association (CUPSA) has established an IT Risk Working Group to focus on IT governance

More information

Business Continuity Management Charter

Business Continuity Management Charter Province of Nova Scotia Business Continuity Management Charter Department, Agency or Commission Name Business Continuity Coordinator Name 3/14/2014 Program Charter for Business Continuity Management Program

More information

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745 ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan

More information

Best Practices in Healthcare IT Disaster Recovery Planning

Best Practices in Healthcare IT Disaster Recovery Planning BUSINESS WHITE PAPER Best Practices in Healthcare IT Disaster Recovery Planning Assessing your options for leveraging the cloud to enhance compliance, improve recovery objectives, and reduce capital expenditures

More information

Business Continuity Maturity Model

Business Continuity Maturity Model Business Continuity Maturity Model Version 1.4 Last Updated: April 4, 2007 Contact Virtual Corporation for latest revision Prepared by Virtual Corporation, Inc. Village Green Annex 98 Route, Suite 12 Budd

More information

Business Continuity & Recovery Plan Summary

Business Continuity & Recovery Plan Summary Introduction An organization s ability to survive a significant business interruption is determined by the company s ability to develop, implement, and maintain viable recovery and business continuity

More information

Best Practices in Disaster Recovery Planning and Testing

Best Practices in Disaster Recovery Planning and Testing Best Practices in Disaster Recovery Planning and Testing axcient.com 2015. Axcient, Inc. All Rights Reserved. 1 Best Practices in Disaster Recovery Planning and Testing Disaster Recovery plans are widely

More information

Application / Hardware - Business Impact Analysis Template. MARC Configuration Requirements. Business Impact Analysis

Application / Hardware - Business Impact Analysis Template. MARC Configuration Requirements. Business Impact Analysis Application / Hardware - Business Impact Analysis Template The single most important thing we can do is help you understand the criticality of each application, supporting hardware/server/pc and the required

More information

Virtualizácia Dátového centra v Slovak Telekom

Virtualizácia Dátového centra v Slovak Telekom Virtualizácia Dátového centra v Slovak Telekom e FOCUS konferencia TRENDY, STRATEGIE A IT TECHNOLOGIE pre 2008 až 2010 Doc. Ing. Oto Malý, PhD Vrchný riaditeľ Divízie IT Bratislava, 5.3.2008 February,

More information

Business Continuity Management

Business Continuity Management Business Continuity Management Policy Statement & Strategy July 2009 Basildon District Council Business Continuity Management Policy Statement The Council is committed to ensuring robust and effective

More information

Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June 12 2013

Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June 12 2013 Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June 12 2013 Chitra Gopalakrishnan Director KPMG LLP Agenda Introduction Business Continuity / Disaster

More information

BCP and DR. P K Patel AGM, MoF

BCP and DR. P K Patel AGM, MoF BCP and DR P K Patel AGM, MoF Key difference between BS 25999 and ISO 22301 ISO 22301 puts a much greater emphasis on setting the objectives, monitoring performance and metrics aligning BC to top management

More information

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK Federal Financial Institutions Examination Council FFIEC Business Continuity Planning BCP FEBRUARY 2015 IT EXAMINATION H ANDBOOK Table of Contents Introduction 1 Board and Senior Management Responsibilities

More information

Disaster Recovery 101. Sudarshan Ranganath & Matthew Phillips Ellucian

Disaster Recovery 101. Sudarshan Ranganath & Matthew Phillips Ellucian Disaster Recovery 101 Sudarshan Ranganath & Matthew Phillips Ellucian SESSION OBJECTIVES Business continuity is critical to every institution and its IT organization. How do you set up your ERP and other

More information

DRAFT Disaster Recovery Policy Template

DRAFT Disaster Recovery Policy Template DRAFT Disaster Recovery Policy Template NOTE: This is a boiler plate template much information is needed from to finalizeconsider this document pre-draft FOREWARD... 3 Policy Overview...

More information

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1 University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems. 1 Michigan Administrative Information Services (MAIS) MAIS is responsible for the production support of

More information

How to prepare your organization for an OCR HIPAA audit

How to prepare your organization for an OCR HIPAA audit How to prepare your organization for an OCR HIPAA audit Presented By: Mac McMillan, FHIMSS, CISM CEO, CynergisTek, Inc. Technical Assistance: 978-674-8121 or Amanda.Howell@iatric.com Audio Options: Telephone

More information

Chapter I: Fundamentals of Business Continuity Management

Chapter I: Fundamentals of Business Continuity Management Chapter I: Fundamentals of Business Continuity Management Objectives Define Business Continuity Management (BCM) Define the relationship between BCM and risk management Review BCM responsibilities Identify

More information

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION Federal Financial Institutions Examination Council FFIEC Business Continuity Planning MARCH 2003 MARCH 2008 BCP IT EXAMINATION H ANDBOOK TABLE OF CONTENTS INTRODUCTION... 1 BOARD AND SENIOR MANAGEMENT

More information

A BCP Tale: From Theory to Practice

A BCP Tale: From Theory to Practice A BCP Tale: From Theory to Practice Presenter: Gord Novoselnik Problem & Configuration Manager, Enterprise Solutions Division, MTS Allstream Gord.Novoselnik@mtsallstream.com 1 10 Commandments of BCM I.

More information

Val-EdTM. Valiant Technologies Education & Training Services. 2-day Workshop on Business Continuity & Disaster Recovery Planning

Val-EdTM. Valiant Technologies Education & Training Services. 2-day Workshop on Business Continuity & Disaster Recovery Planning Val-EdTM Valiant Technologies Education & Training Services 2-day Workshop on Business Continuity & Disaster Recovery Planning All Trademarks and Copyrights recognized Page 1 of 8 Welcome to Valiant Technologies.

More information

fs viewpoint www.pwc.com/fsi

fs viewpoint www.pwc.com/fsi fs viewpoint www.pwc.com/fsi June 2013 02 11 16 21 24 Point of view Competitive intelligence A framework for response How PwC can help Appendix It takes two to tango: Managing technology risk is now a

More information

Disaster Recovery Policy

Disaster Recovery Policy Disaster Recovery Policy INTRODUCTION This policy provides a framework for the ongoing process of planning, developing and implementing disaster recovery management for IT Services at UCD. A disaster is

More information

Exhibit to Data Center Services Multisourcing Service Integrator Master Services Agreement

Exhibit to Data Center Services Multisourcing Service Integrator Master Services Agreement Exhibit to Data Center Services Multisourcing Service Integrator Master Services Agreement DIR Contract No. DIR-DCS-MSI-MSA-001 Between The State of Texas, acting by and through the Texas Department of

More information

Business Continuity and the Cloud. Aaron Shaver US Signal, Solution Architect

Business Continuity and the Cloud. Aaron Shaver US Signal, Solution Architect Business Continuity and the Cloud Aaron Shaver US Signal, Solution Architect Overview What is BC/DR? Why should businesses have a strategy? Why do many business choose not to? How does the cloud change

More information

Disaster Recovery Plan (Business Continuity) Template - Version 8.2

Disaster Recovery Plan (Business Continuity) Template - Version 8.2 Brochure More information from http://www.researchandmarkets.com/reports/3630899/ Disaster Recovery Plan (Business Continuity) Template - Version 8.2 Description: ISO 27000, SOX, PCI-DSS & HIPAA Compliant

More information

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY This document outlines a set of policies and procedures for formalising a Business Continuity programme, and provides guidelines for developing, maintaining

More information

The Disaster Recovery Self-Assessment Guide and Validation Model. Jim Kates Cognizant Technology Solutions Jim.Kates@cognizant.com

The Disaster Recovery Self-Assessment Guide and Validation Model. Jim Kates Cognizant Technology Solutions Jim.Kates@cognizant.com The Disaster Recovery Self-Assessment Guide and Validation Model Jim Kates Cognizant Technology Solutions Jim.Kates@cognizant.com How Would You Evaluate Your DRP? (Is it a Disaster Recovery Plan or a Dilbert

More information

Business Continuity Management Software

Business Continuity Management Software Business Continuity Management (BCM) Software 1 Business Continuity Management Software All In One Continuity Management Solution A Single Platform Approach Manage entire lifecycle with comprehensive BC

More information

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015 Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level June 9, 2015 By: Tracy Hall MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company,

More information

COMCARE BUSINESS CONTINUITY MANAGEMENT

COMCARE BUSINESS CONTINUITY MANAGEMENT COMCARE BUSINESS CONTINUITY MANAGEMENT Title Business Continuity Management Version 2.1 Authorised by Executive Committee Effective date Authorisation date 10/7/2012 10/7/2012 COMCARE BUSINESS CONTINUITY

More information

BT Conferencing Business Continuity Management. Planning to stay in business

BT Conferencing Business Continuity Management. Planning to stay in business BT Conferencing Business Continuity Management Planning to stay in business Planning for the unexpected In today s connected world, businesses are increasingly dependent on their communications and networked

More information

Stepping Through the Info Security Program. Jennifer Bayuk, CISA, CISM

Stepping Through the Info Security Program. Jennifer Bayuk, CISA, CISM Stepping Through the Info Security Program Jennifer Bayuk, CISA, CISM Infosec Program How to: compose an InfoSec Program cement a relationship between InfoSec program and IT Governance design roles and

More information

Planning for Disaster Disaster

Planning for Disaster Disaster Planning for Disaster Ramesh Ramani CISM CGEIT Ramesh Ramani CISM CGEIT Paramount-Dubai Agenda Disaster Management-Introduction Examples BCP and IT Continuity Process of Disaster Management-PDCA Disaster

More information

White Paper: ISO 22301 Business Continuity Management An Overview. ISO 22301 Business Continuity Management An Overview

White Paper: ISO 22301 Business Continuity Management An Overview. ISO 22301 Business Continuity Management An Overview White Paper: ISO 22301 Business Continuity Management An Overview ISO 22301 Business Continuity Management An Overview Introduction As incidents such as malicious activism, terrorist attacks and environmental

More information

The Role of Internal Audit In Business Continuity Planning

The Role of Internal Audit In Business Continuity Planning The Role of Internal Audit In Business Continuity Planning Dan Bailey, MBCP Page 0 Introduction Dan Bailey, MBCP Senior Manager Protiviti Inc. dan.bailey@protiviti.com Actively involved in the Information

More information

eet Business continuity and disaster recovery Enhancing enterprise resiliency for the power and utilities industry Power and Utilities Fact Sheet

eet Business continuity and disaster recovery Enhancing enterprise resiliency for the power and utilities industry Power and Utilities Fact Sheet Power and Utilities Fact Sh Business continuity and disaster recovery Enhancing enterprise resiliency for the power and utilities industry A holistic approach to business resiliency and disaster recovery

More information

ACTUALLY TEST YOUR PLAN. Disaster Recovery using Shadow Protect. March Madness Lunch & Learn. www.martinandassoc.com 1 AGENDA

ACTUALLY TEST YOUR PLAN. Disaster Recovery using Shadow Protect. March Madness Lunch & Learn. www.martinandassoc.com 1 AGENDA AGENDA BEYOND BACKUP ENSURING RECOVER-ABILITY Identify and Quantify Exposure Risk Evolution of Recovery Technologies Build a Recover-Ability Solution Joe Gast Martin & Associates Maintenance Testing &

More information

Flinders University IT Disaster Recovery Framework

Flinders University IT Disaster Recovery Framework Flinders University IT Disaster Recovery Framework Establishment: Flinders University, 1 August 2013 Last Amended: Manager, ITS Security Services, 4 October 2013 Nature of Amendment: Initial release Date

More information

Enterprise Risk Management & Information Technology

Enterprise Risk Management & Information Technology Enterprise Risk Management & Information Technology Presented by Scott Perry and Gary Ross Slalom Consulting, San Francisco Agenda Introductions Session Objectives Overview of Enterprise Risk Management

More information

How to Design and Implement a Successful Disaster Recovery Plan

How to Design and Implement a Successful Disaster Recovery Plan How to Design and Implement a Successful Disaster Recovery Plan Feb. 21 ASA Office-Administrative Section is Sponsored by Today s ASAPro Webinar is Brought to You by the How to Ask a Question Questions

More information