1 BUSINESS RESUMPTION PLANNING: EXERCISING THE DISASTER MANAGEMENT TEAM By: Paul H. Rosenthal Information Systems Department School of Business & Economics California State University, Los Angeles 5151 State University Drive Los Angeles, California / Gene Sheniuk Abstract Disaster simulation exercises are used to test the staffing, management, and decision making of both the computer and non-computer related aspects of an organization's business continuity and life-safety plans. Special simulation methods must be used to exercise the Disaster Management Team and their Emergency Operations Center. A proven approach to designing and conducting this type of simulation is presented, including a full script from a recent simulation exercise. Keywords: Disaster simulation, contingency planning, business resumption planning, business continuity planning, life-safety, command center * * * * * INTRODUCTION During the 1980's, contingency planning evolved from data center backup planning, to business resumption planning (BRP). Business resumption planning involves arranging for emergency business and data center operations and recovery planning following a disaster. The growth of commercial backup data centers has made available inexpensive data center contingency resources for all but the largest organizations. The commercial hot/cold backup sites are available for testing of critical applications, so that most organizations had, by the late 1980's, fully tested data center contingency plans. However, the vast majority of data center users has only a vague idea of how they might operate during a disaster that destroys the data center or their operating locations. Data processing management has gradually persuaded their users that they need a business resumption plan that integrates with the data center plans. Data processing management also needs to persuade their users that there is a need for simultaneously testing the data center and the user's business resumption plans through disaster simulation exercises similar to those described in this paper and by Rosenthal and Himel . However, unless these BRPs are periodically tested, they are seldom usable operationally. Plans that were initially operationally viable become obsolete very quickly unless periodic tests force every department and work group to maintain
2 off-site: up-to-date contact lists; files and processing resources; communications resources; and current programs, procedures, and forms. Disaster simulation exercises are now widely used to exercise the staffing, procedures, and resources for both the computer and non-computer related aspects of an organization's business continuity and life-safety plans. The scenarios and simulation methods normally used for these exercises are designed to test the various functional teams charged with recovering business operations while assuring the safety of personnel and facilities. The disaster management team charged with coordinating the actions of the functional teams during notification, mobilization, activation, emergency operations, and recovery are normally involved in these simulations as observers. This lack of involvement results from the need to use highly structured scenarios that include the expected decisions of the management team. Separate simulation exercises are therefore normally required to test the preparation of the Disaster Management Team (DMT) and the configuration of their Emergency Operations Center (EOC). FUNCTIONS OF OPERATIONAL & SIMULATION TESTING There are two primary activities involved in testing a BRP: Operational Testing Performing critical computer and non-computer related tasks using backup resources and facilities. Simulation Testing Performing the notification, mobilization, activation, emergency operations, and recovery phases of a BRP based on a typical disaster. The methodologies for operational testing are well known. Organizations with available backup resources, normally adequately test their emergency operations capability. However, the use of simulation for testing the managerial aspects of their BRPs is rare, and the methods for planning and conducting such simulations are poorly understood. This paper, therefore, presents a proven methodology for BRP simulation that has been used in several simulations conducted in the Los Angeles basin. In addition to the methodology, a script from a recent exercise is included that was recently used by a major Los Angeles financial firm. BUSINESS RESUMPTION PLANNING (BRP) LIFE CYCLE Rothberg  defines a disaster as "...any event that causes significant disruption to operations, thereby threatening the business' survival." Business resumption planning (BRP), the newest term for disaster recovery planning, can be conceptually divided into three major phases: prevention, planning, and testing. Figure 1 lists the major life cycle tasks needed to protect against such disasters. Exercising the disaster management team (DMT), the subject of this paper, is the last step in the BRP life cycle. It is usually the least performed activity in the BRP life cycle.
3 FIGURE 1. Business Resumption Planning Life Cycle I. Prevention - Threat Analysis - Physical Security & Protection Program - Data Security & Protection Program II. III. Planning - Critical Function/Application Analysis - Design of Normal & Emergency Processing Architectures for:.. computer & telecommunications.. manual processing and record storage - Obtain Backup Resources for:.. off-site storage.. computer processing.. manual processing.. data and voice communications.. management control - Arrange Disaster Response Team Staffing for:.. damage assessment and recovery planning.. emergency operations.. disaster response management Testing - Desk Top Walk Through.. backup resource utilization.. team responsibilities.. emergency operations approaches - Operations Testing.. computer processing based applications.. manual processing based applications - Simulation Testing.. emergency response teams.. disaster management team An excellent example of a BRP for a university data center can be found in Rohde and Haskett . They, as do most other authors, stop short of the testing phase. Without both periodic operational testing (performing critical business functions using backup resources) and simulation testing (exercising the decision making portions of the plan), a plan quickly becomes unusable. Phase I- Prevention
4 The first steps in a the BRP program, is to determine the possible extent of exposure to a disaster, and then to minimize the probability of a disaster occurring. The initial step in any BRP program is that of obtaining the substantial funding normally required. This requires selling the Board of Directors on the reality of a possible disaster and the impact on the ability of the organization to survive. According to Yetter , an inadequate understanding of the potential threats and their possible impact is often the weak link in many disaster security and recovery programs. His paper is an excellent presentation of the quantitative approach to threat evaluation. The results of such a quantitative study is used to rate the potential severity of each hazard as a guide for prevention and recovery spending. The detailed quantitative approach to risk analysis is popular with government and large industrial firms with major consulting budgets. The board of directors of most firms however, respond better to a fiduciary responsibility analysis. A list of risks to which the firm's facilities and personnel is exposed is presented and a case study approach is used to demonstrate realistic risk exposure. Estimates are made of the financial impact on various business functions, computer related and non-computer related, of a loss in resource capability. When the impacts include financial or service level losses that can effect the firms survival, then the board members fiduciary responsibility requires a prudent level of protection and recovery capability. Funding for an adequate BRP is then made available, often as a priority project. Physical security planning primarily involves access controls, fire and water protection, earthquake and storm hardening, and critical records security. Most firms have a physical security program in place covering these areas prior to the implementation of a BRP program. The second step in the BRP is therefore simply an assessment of the program, and improvement if necessary. The authors experience indicates that the critical records area, particularly for non-computerized files, are frequently the major weak point. Data security and protection programs are not as wide spread as physical security programs. Few firms have high quality data oriented security programs, particularly in the personal computer area and for non-financial & personnel manual records involving off-site backup of critical records. This area frequently requires a major effort. Phase II- Planning The disaster planning process outlined in Figure 1 is often initiated by the data center, as it implements applications critical to the day-to-day operations of the organization. The data processing oriented disaster planning selling job to the board often alerts them to the risk presented by the non-computerized portions of the firms operations, and as discussed in Orr  a total recovery planning effort is initiated. A good overview of the BRP process can be found in Janulaitis . Phase III- Testing
5 Desk top walk through- Prior to any detailed testing, key stakeholders in the BRP are convened in a conference room, and a detailed review is performed of the plan. Many small events are described and the participants are asked to state how the plan would guide their reactions. The events should require utilization of: major backup resources, emergency operations approaches, and all emergency response teams. Following this step, operations and simulation tests are scheduled. Operational testing- Few organizations operationally test the complete disaster reaction cycle of: activation, life-safety, damage assessment, mobilization, emergency operations using off-site files and backup resources, and recovery planning. Only the data processing emergency operations area can be tested without involving a substantial number of persons during business hours. The scope of most operational tests therefore, includes: a semi-annual off-hour call to the manager of data center operations, assembly of the backup site operations team, acquisition of backup materials from an off-site location, travel to a backup hot/cold site, installation of systems and applications software, loading production data, and systems test of several critical applications. Simulation testing- Simulation is the most feasible approach for testing the decision making aspects of disaster reaction activities. The use of simulation exercises for BRP has been spreading slowly over the last decade. Unlike their counterpart military war games that use computer driven scenarios to perform very realistic exercises, BRP exercises are paper and pencil simulations. Teams are placed at tables representing their backup locations, and the description of an evolving disaster is presented. The teams communicate using backup communication resources or forms, make decisions, and everyone pretends that what is ordered actually happens. Debriefings and evaluation studies follow to correct any flaws in the BRP. Most simulation exercises are very successful in that they force personnel to learn the BRP while working together, and find flaws and inconsistencies in policies and plans. The remainder of this paper presents a detailed methodology and the disaster scenario used recently by a major Los Angeles firm for performing such a simulation exercise for their Disaster Management Team. Details of a similar approach for the simulation testing of Emergency Response Teams representing business functions or operational activities, can be found in Himel and Rosenthal . FUNCTIONS OF BRP TEAMS Most organizations with mature business resumption plans have a three tier BRP organization structure (for an example see Coleman ), including: Top tier- Second tier- Third tier- Policy Group Disaster Management Team (DMT) Emergency Response Teams (ERT) The top tier Policy Group consists of upper-level executives that are available for approving major DMT decisions involving customer service impact, major expenditures or major potential liabilities. For example, after the Bay Area earthquake a major bank opened their branches the
6 next day without power and full cleanup and repairs. The ability to provide much needed cash to customers was deemed more important than the potential for accidents or robberies. The middle tier DMT includes representatives of key departments and functions involved in lifesafety and business contingency planning. Figure 2 lists the functional organizations often represented on a DMT. Selecting the chairperson of the DMT is often a difficult and politically sensitive decision. The pressure to appoint a senior executive should be resisted. Senior executives belong in the Policy Group among their peers. The chair of the DMT, and therefore the coordinator of the EOC, should be an extremely knowledgeable peer of the other members of the DMT. The chair should not however, be associated with any ERT. The chair is frequently the supervisor of the Project Head, Business Continuity Planning. FIGURE 2 Typical Disaster Management Team (DMT) Membership Manager, Planning- DMT Chairperson Manager, Facility Operations Manager, Transportation/Logistics Manager, Security/Safety Manager, Human Relations Manager, Public Relations Manager, Marketing/Customer Service Manager, Manufacturing/Operations Manager, Data Processing Project Head- Business Continuity Planning, and DMT Secretary The third tier is made up of a large number of Emergency Response Teams (ERT). For example, the data processing area might have specialized logistics, backup data center operations, network operations, and user support ERTs. The safety area might include a dozen or more ERTs with first aid and evacuation responsibilities, each headed by a floor warden. PERIODIC TESTING OF YOUR BRP Every six months your plans should be operationally tested using your backup facilities and offsite storage resources. Every year the management aspects of your plan should be simulation tested. These two activities assure the currency of your plan and the readiness of your staff. The remainder of this paper discusses the planning of simulation tests for second tier- disaster management teams.
7 FUNCTIONS OF DISASTER MANAGEMENT TEAM (DMT) During a disaster the DMT has two primary functions: Life-Safety Management Coordinating the efforts of emergency response teams to assure the safety of personnel and to minimize the damage to their facilities following a disaster. A life-safety DMT is normally organized for every major facility or campus. Business Continuity Planning Planning and coordinating emergency operations and restoration of normal operations following a disaster. A business continuity DMT is normally responsible for a total business unit, frequently involving multiple and wide-spread facilities. A combined life-safety and business continuity simulation test is feasible for organizations with a single facility or campus. However, for organizations with multiple facilities, separate life-safety tests for each locations plus a separate integrated business resumption test are normally performed. THE EMERGENCY OPERATIONS CENTER (EOC) The EOCs observed by the author are of two basic structural types: the single conference room approach, and the dual room approach. Figure 3, the EOC of the firm that used the scenario presented in this paper, illustrates the most common and least expensive approach, the converted conference room. Large conference rooms at two or more widely separated locations are converted to EOCs. Furnishing and equipment required include:! Telephone consoles for each participant; including an EOC rotary line, a dedicated incoming line for each function, and a line for outgoing calls.! Tvs and radios to monitor news and public announcements.! White boards, tack boards, and flip charts.! Facility maps and area maps with medical and emergency service facilities identified.! Multiple radios with multiple channels for use in communicating with emergency response teams and the outside world. At least one of the EOCs will often house a portable satellite communication unit.! Room power connected to the building's emergency power system.! Food, water, and rest facilities for primary and alternate DMT members.
8 California firms often have Los Angeles and San Francisco EOCs and DMTs because of the possibility of an area wide disaster due to a major earthquake. Other areas of the world may not need this much separation between locations. Figure 4, the EOC of a major Los Angeles utility, illustrates the dual room EOC approach. It is normally used by organizations with frequent operational emergencies, such as utilities exposed to power outages or pipeline breaks. The EOC is used for both operational emergencies and for disasters affecting non-operational facilities and personnel. A second conference room type EOC is also normally available at a site remote from the primary EOC. EOC testing involves two functions: a periodic walk-through of all equipment by the Project Head- Business Continuity Planning, and periodically performing DMT simulations in the EOC. DESIGNING A DMT SIMULATION SCENARIO Proper planning of a scenario requires a detailed knowledge of the risk exposures and business continuity plans for all impacted facilities and organizations. As discussed in Rosenthal and Himel , a scenario should:! be solvable for most of the life safety and business functions participating, using existing plans and backup resources! represent the occurrence of realistic risk exposure! be capable of being partitioned into four to six time steps, each representing a unique but solvable set of problems. The simulation scenario which follows was derived from a State of California earthquake planning scenario . It is based on a major earthquake occurring at the southern edge of the Los Angeles basin. Scenario Period One Period One simulated time of 3:00 p.m., as described in Exhibit 1, was immediately after a major earthquake in the Los Angeles basin approximately 15 miles from the firms location. Exhibit 1 was read to the participants at the start of the time step, and a copy was given to them as reference material. This same process was repeated for each time-step. The EOC was considered to have been activated and the DMT had to assess the status of their facilities, handle life-safety activities, and plan for their employees safety and confort.
9 Scenario Period Two Period Two simulated time of 8:00 p.m., as described in Exhibit 2, was five hours after the earthquake. Travel throughout the Los Angeles Basin is extremely difficult, and a curfew is starting. The DMT must implement a sleep-over program and protect their facilities. Scenario Period Three Period Three simulated time of 11:00 p.m., as described in Exhibit 3, was immediately after a strong aftershock. Significant additional damage and employee hysteria require the DMT to revise their sleep-over and next-day life-safety and business resumption plans. Scenario Period Four Period Four simulated time, as described in exhibit 4, was 8:00 a.m. the next day. The curfew is over, and the DMT must plan to sent as many employees as possible home, while implementing short term business resumption plans. Scenario Period Five Period Five simulated time, as described in Exhibit 5, was 6:00 p.m. the next day. The DMT must create a business recovery and facility repair plan. Solution Work-sheets Exhibits 6, 7, 8, 9, and 10 present solution work-sheets for each time step that were prepared prior to the simulation by the test administration team. Above the lines are the information gathering activities expected of each participant. Below the lines are the DMT decisions and actions expected. The scenario and solution work-sheets have been edited to delete material relating to the firms specific facilities and business operations. The scenario and solutions therefore do not represent the full set of responses that were expected from the organization. ADMINISTERING A DMT SIMULATION EXERCISE As discussed in Rosenthal and Himel , operational simulation tests of emergency response teams are evaluated following the simulation. DMT simulations are of most value however, when an evaluation and redirection period occurs at the close of each scenario time period. This improves the learning experience and assures consistency between the following time periods scenarios and DMT planning. Simulation exercises of single emergency response teams can also be handled in the same manner.
10 Figure 5 shows personnel assignments during a typical DMT simulation exercise. As shown, the members of the test administration team were able to listen to the conversations of assigned DMT members and check off the actions completed on the Exhibit 6-10 control forms. External communications to the Policy Group and to the emergency response teams can be handled in two ways:! the chairperson of all emergency response teams can be briefed prior to the simulation exercise and are available to produced planned responses through the emergency radio or telephone network. The Policy Group responses are however handled by a member of the test administration team.! The test administration team can simulate all external responses and provide all input information. Most DMT members prefer the second alternative since it does not expose their mistakes to persons that work for them. The time allocated to the DMT to generate a solution to each scenario stage and then review the solution with the administration team normally takes minutes for the first time step, reducing to minutes for the final time step. EVALUATING THE SIMULATION Following the simulation exercise, the Test Administration Team with the Project Head- Business Continuity Planning, should plan to spend at least a half day evaluating the impacted BRP policies and procedures as well as each DMT members knowledge. Brief individual briefings should then be held with each DMT member and their alternates, and action plans to correct any deficiencies prepared. The Project Head- Business Continuity Planning must then monitor the implementation of the action plans in preparation for the following years DMT simulation exercise. CONCLUSIONS At the disaster management team exercises that I have observed, the participants indicated that the review of policies and procedures, and the lessons learned were extremely valuable. They were also surprised at the number of omissions and inconsistencies found in their life safety and business resumption plans. The primary value of a DMT simulation exercise is the realization by management, that the extensive testing conducted for the emergency response teams had little impact on the Disaster
11 Policy and Disaster Management Teams preparation. They realize how important it is that simulation exercises similar to the one described in this paper for the Disaster Management Team be conducted every few years. Additionally a Desk Top Walk Through for the Disaster Policy Team should also be conducted periodically. REFERENCES 1. Coleman, Paul. "The First Interstate Fire: Plan, Preparation And Activation." Contingency Journal. (1:2) April-June 1990, pp Rosenthal, Paul and Himel, Barry. "Business Resumption Planning: Exercising Your Emergency Response Teams." Computers & Security. (10:6) October 1991, pp Janulaitis, M. Victor. "Creating a Disaster Recovery Plan." Info Systems. (32:2) February 1985, pp Orr, Daniel. "Toronto Dominion Bank: Management Support and Expert Systems Tools Speed Contingency Planning." Contingency Journal. (1:2) April-June 1990, pp Rohde, Renete and Haskett, Jim. "Disaster Recovery Planning For Academic Computing Centers." Communications of the ACM. (33:6) June 1990, pp Rothberg, M. L. "Disaster Plans: Added Complexity." Computer Decisions. (21:2) February 1989, pp Toppozada, T. R., Bennett, J. H., Borchardt, G., Saul, R. and Davis, J. F. Planning Scenario For A Major Earthquake On The Newport-Inglewood Fault Zone. (Special Publication 99) Sacramento, California: California Department of Conservation, Division of Mines and Geology, Yetter, David L. "Hazard Analysis Techniques For Business And Industry." Contingency Journal. (1:2) April-June 1990, pp. 6. About the Authors Paul Rosenthal is a Professor of Information Systems at California State University, Los Angeles' School of Business & Economics. He has a B.S. in Ed. and an M.A. in Mathematics from Temple University, an M.B.A. from U.C.L.A., and a D.B.A. from U.S.C. His research interests include planning of information systems projects, sourcing methodologies, and business resumption planning for both information systems and user activities. He is a member of ACM and SIM International.
12 Simulated Time: 3:00 pm, Wednesday Exhibit 1A: Scenario 1 Announcement! Earthquake Magnitude , Major Quake- major destruction within 5-10 miles, significant destruction within miles, major damage within miles.! Epicenter Near Long Beach! Southbay Roads and Freeways Impassable and badly damaged. A mile of I-405 east of Long Beach Freeway destroyed.! Significant Damage to Roads and Freeways Throughout the LA Basin- Traffic at a Standstill. Concrete ruble surrounding interchanges and many bridges.! Streets and Walkways close to High-rise and Masonry Buildings impassable and unsafe due to Falling Glass and Debris. Vehicles can not move through streets adjacent to highrise buildings.! Utilities Unavailable, Telephone System Reserved for Emergency Agencies Uses Only. No dial-tone for outgoing calls.! Downtown Buildings have suffered Significant Damage to Contents, Walls, Ceiling, and Windows, Plus Extensive Water Damage From Leaking Pipes & Sprinklers. Furniture and computer components have traveled across rooms severing wires and cables.! High-Rise Buildings have Suffered Extensive Loss of Glass on Upper Floors. Widespread Cracking of Glass on Lower Floors. Floors above tenth are not occupiable.! The Emergency Operations Center (EOC) has been activated and occupied. What would you do? What are your plans?
13 Exhibit 1B: Report from Project Head, BRP The following information is based on initial radio reports, Simulated Time: 3:30 pm Wednesday! A Intensity earthquake has occurred on the Newport-Inglewood fault centered in the Long Beach area.! Damage from the quake in the Long Beach area is equivalent to Level XI Intensity Shaking: Bridges destroyed, Broad fissures in ground, underground pipelines completely out of service, earth slumps and land slips in soft ground. Few masonry structures standing, many well built wooden structures destroyed, great damage in specially designed (high rise) buildings.! Damage from the quake in the area surrounding Long Beach (within approximately miles) would be equivalent to Level X Intensity Shaking: Ground badly cracked, shifted sand & mud, landslides from steep slopes. Some well-built wooden structures destroyed, most masonry and frame structures destroyed, severe damage in specially designed (high rise) buildings.! Damage from the earthquake in the areas between miles (includes downtown Los Angeles) would be equivalent to Level IX Intensity Shaking: Damage considerable in specially designed buildings (high rise), damage great in substantial buildings with partial collapse, many buildings shifted off foundations. High rise Buildings will lose substantial glass above 10 stories and almost total loss of glass above 20 stories, with violent shifting of contents in upper floors.
14 Exhibit 1C: Report from the Damage Assessment Team! Epicenter of Quake Reported Just West of Long Beach Airport.! Severe Destruction in Long Beach and Surrounding Areas. Simulated Time: 4:00 pm Wednesday! Extensive Damage Throughout LA Basin, No Utilities, Traffic at a Standstill, Most Freeway Interchanges Closed. Utilities will require several days to restore outside the LB area, SFV and eastern areas may have services on thursday.! Telephone Systems Locked-out From Other Than Emergency Locations.! Dusk to Dawn Curfew Announced for LA County for all persons without Emergency Services Passes. Violators will be detained and heavily fined.! LAX and LB Airports Closed, Others Open for Incoming Emergency Personnel Only.! Mayor's Announcement- Don't Travel, Take Cover, Be Ready for Major After-Shocks! No Structural Damage to our Downtown Buildings.! Upper floors of all buildings reporting extensive damage, broken and missing windows, furniture has moved across rooms.! Computer Center is badly shaken. Many pieces of equipment have moved an broken their cables. All systems are being shut down as gracefully as possible, luckily our UPS worked.! Many minor injuries in all buildings. First Aid Teams are handling.! Many people are hysterical, everyone upset.
15 Simulated Time: 8:00 pm., Wednesday Exhibit 2 Scenario 2 Announcement! Curfew Going Into Effect. Streets almost empty of people.! First Aid Facilities Overloaded with injured.! Traffic Within 10 Miles of Long Beach at a Standstill, cars being abandoned.! LA Basin Freeways & Interchanges Closed Until Inspected, Due To Possible Bridge Damage. Caltrans hopes to open most northern LA Basin Freeways by late Thursday.! Many Surface Streets Blocked By Debris and Abandoned Cars. Major streets in area show light traffic.! Public & Private Contractor/Construction Personnel Are Being Mobilized to Clear Major Streets & Freeways.! Telephone System Operational But Overloaded. Everyone requested to use phones for medical emergency use only. Dial-tone after half-hour wait. Local calls getting fast busy. Long distance calls going through.! Military Personnel Deploying Throughout the LA Basin, Particularly in Business & Shopping Areas. National Guard being deployed, army expected during night.! Many Displaced and Homeless Persons Trying To Enter Our Buildings Seeking Shelter.! What are your plans for this evening and night?
16 Simulated Time: 11:00 pm., Wednesday Exhibit 3 Scenario 3 Announcement! Major After-Shock Near Culver City.! Major Damage In Areas South-West of Downtown.! Additional Significant Damage to All Our Buildings, including Structural Damage to Headquarters Building. Cracks and wall-to-support beam separation. Extensive glass cracking and some loss on lower floors, including ground floors.! Widespread Hysteria and Some Minor Injuries- Primarily in Headquarters Building.! Fires Visible In Night Sky West & South of Downtown.! What should you do and announce? Exhibit 4 Scenario 4 Announcement Simulated Time: 8:00 am, Thursday (Next Day)! Curfew Over, Military Everywhere.! Limited Open Travel Routes to be Announced at 10:00 am, Curfew To Continue for Several Nights.! Utility Services to be Restored by Neighborhood during Next Several Days (except for Long Beach Area). Utilities will be restored to downtown over weekend, residential areas are being given priority.! Access to Long Beach Area Open to Residents Only! Smoke from Fires Visible in Areas West & South of Downtown! What are your plans for today and Friday?
17 Exhibit 5 Scenario 5 Announcement Simulated Time 6:00 pm, Thursday (Next Day)! Except for some single personnel living in the Long Beach area and selected key security personnel, all of our employees have returned home.! Numerous members of our Emergency Response Teams, including approximately half of the team leaders, have called from home for instructions.! Utilities will start to be restored in much of the LA Basin tonight and tomorrow. Most main roads and some freeways outside the Long Beach and west side area are open and running reasonably well.! Damage assessment team estimates that approximately half our total LA Basin floor space will be available Monday. Headquarters Building space will probable not be available for several weeks.! What are your plans for the rest of this week?
18 Exhibit 6: Scenario 1 Solutions Checklist DMT Chair & BRP Head Security Logistics Human & Public Relations Customer Service Manufacturing/ Operations Facilities Data Processing -Announce BRP Activation -Open EOC Log -Establish Policy Group Contact -Assess Move to Shelter Areas vs Evacuation of Building -Activate EOC -Make Initial Buildings Announcements -Activate EOC & ERT's Communications -Verify Supplies Available to Area ERTs -Assess Potential For Personnel Returning Home -Initiate Collection of Injured as Feasible -Assess EOC/ External Communications -Assess EOC/ Employee Communications -Monitor Public Information -Initiate Building Announcements -Determine Status of Potential Repair & Supply Vendors -Activate Emergency Building Operations -Initiate Damage Assessment -Initiate Security Program for Building & Surrounding Area -Activate Backup Data Center -Activate EOC/ Data Center Communications -Assess Data Center Status -Assess Voice & Data Network Status Coordinate Notification & Shelter Planning Asses Status & Initial Response -Develop Policy for Admission of External People -Review Plans with Legal -Brief Policy Team on Status and Plans -Monitor Egress and Dispatch of Personnel -Initiate Sleepover Plan -Assign Groups to Shelters -Assign First- Aid Personnel to Injured Collection Areas -Assign Volunteers to Replace Telephone Handsets -Initiate Employee Status Reporting -Initiate Public Announcements as Feasible -Announce Shelter Plan & Initiate Movement of Personnel -Assign HR Support Staff to Shelter Areas -Produce Periodic Announcements -Inform Other Company Locations of Status & Plans as Possible -Attempt Contact with Out of Area Repair & Supply Vendors -Activate Building Login & Logout Procedures -Initiate Periodic Building & Area Status Reporting -Activate Contingency Plans Using Out of Area Personnel, Tapes and Supplies -Arrange for Dispatch, when Feasible, of Tapes and Teams to Backup Data Center
19 Exhibit 7: Scenario 2 Solutions Checklist DMT Chair & BRP Head Security Logistics Human & Public Relations Customer Service Manufacturing/ Operations Facilities Data Processing -Arrange for EOC Rotation -Monitor Status Reports from ERT Teams -Activate Overnight Area and Building Security Program -Report Onsite, Logout & Login Statistics -Analyze Staff Egress Potential -Initiate Route Maps Preparation -Distribute Backup Food and Supplies -Plan Public & Family Information Plan -Draft Overnight Shelter Plan Announcements -Draft Emotional Support Plan Announcement -Determine Status of Out of Area Support -Adjust Shelter Occupancy Patterns as Needed -Activate Fire watch Program -Activate Shelter Registration Program -Monitor Activation of Backup Data Center by Out of Area Personnel -Staff Family Response System Coordinate Finalization of Overnight Plans Brief Policy Team -Establish Rules for Confidential Information With Policy Team -Verify Security & Fire Watch Programs -Close Off Area Perimeters -Monitor Traffic Reports for Use in Route Maps -Announce the Shelter, Support, and Family Information Plan -Activate Family Call and Information Plan -Inform Out of Area Management of Status and Plans -Activate Out of Area Support for Next Day -Reserve Hotel Space for EOC & Other Watch Personnel -Plan Cleanup and Repair Projects -Initiate Data Center Close Down
20 Exhibit 8: Scenario 3 Solutions Checklist DMT Chair & BRP Head Security Logistics Human & Public Relations Customer Service Manufacturing/ Operations Facilities Data Processing -Assess Total Situation -Maintain EOC Rotation -Verify EOC/ Shelters Communications -Arrange Evacuation of any Newly Damaged Areas -Activate Plan for Collection of Injured -Draft Revised Announcements -Initiate Facility Inspections -Check All Communications Coordinate Employee Announcements Brief Policy Team -Verify Evacuations -Inspect Area, Building, and Shelter Security -Continue Route Map Preparation -Assign Volunteers to Replace Phone Handsets -Announce Status and Plans to Personnel
BUSINESS RESUMPTION PLANNING: EXERCISING YOUR EMERGENCY RESPONSE TEAMS Disaster simulation exercises are used to test the staffing, management, and decision making aspects of both the computer and non-computer
Sound Shake Facilitating Earthquake Preparedness: A Workplace Guide Introduction Thank you for taking the time to better prepare your business or organization for the potential impacts of an earthquake
The First Interstate Bank Fire By Paul Coleman At 10:30 p.m. the night of May 4, 1988, Los Angeles worst high-rise fire swept through the 62 story downtown headquarters of First Interstate Bank destroying
NCUA LETTER TO CREDIT UNIONS NATIONAL CREDIT UNION ADMINISTRATION 1775 Duke Street, Alexandria, VA 22314 DATE: December 2001 LETTER NO.: 01-CU-21 TO: SUBJ: ENCL: All Federally Insured Credit Unions Disaster
RPI Employee s Federal Credit Union Business Continuity/Disaster Recovery Plan January 23, 2012 Purpose and Objectives 2 Disaster Recovery Organizational Structure 3 Appendices: Disaster Recovery Emergency
Emergency Response Simulation Objective: A hands-on approach to teaching students how the emergency response process works by testing plans, making decisions, and facing unexpected events. LESSON For this
Are You Ready to ShakeOut? Major earthquakes can cause unprecedented catastrophes. With earthquakes as an inevitable part of our future, businesses should make plans and take actions to ensure that disasters
CITY OF HOUSTON Office of Emergency Management October 2004 Emergency Management is responsible for coordinating the City of Houston s preparation for and response to emergency situations. Houston is exposed
Local Government Cyber Security: Guidelines for Backing Up Information A Non-Technical Guide Essential for Elected Officials Administrative Officials Business Managers Multi-State Information Sharing and
HOPONE INTERNET CORP IT Disaster Recovery Plan Template Compliments of: Tim Sexton 1/1/2015 An information technology (IT) disaster recovery (DR) plan provides a structured approach for responding to unplanned
BRYN MAWR COLLEGE EMERGENCY RESPONSE PLAN Revised 3/17/08 (abridged) This document is a synopsis of the planning and preparation the College has undertaken to handle emergencies in a professional, efficient,
1 Offsite Disaster Recovery Plan Offsite Disaster Recovery Plan Presented By: Natan Verkhovsky President Disty Portal Inc. 2 Offsite Disaster Recovery Plan Introduction This document is a comprehensive
Template Policy on Healthcare Facility Patient Evacuation and Shelter-in Place Policy: It is the policy of the healthcare facility to have defined procedures to protect the life and safety of both patients1
Recommended by Emergency Preparedness Committee: January 26, 2011 Recommended by President s Council: February 11, 2011 Approved by Executive Committee: February 14, 2011 NAIT Guidelines CS1.1 Emergency
Massachusetts Institute of Technology Functional Area Recovery Management Team Plan Development Template Public Distribution Version For further information, contact: Jerry Isaacson MIT Information Security
Emergency Management Plan March 2012 ON CAMPUS Emergency Dial Security Assistance Dial 566-0384 OFF CAMPUS SUPPORT AGENCIES Fire & Ambulance... 9-1-1 Charlottetown Fire Department... 566-5548 Fire Marshal...
Disaster Recovery Planning This is a brief guide, with a suggested table of contents, to help you get started with putting together your Disaster Recovery Plan (DRP) Pensar can assist you in completing
Appendix L DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS I. GETTING READY A. Obtain written commitment from top management of support for contingency planning objectives. B. Assemble
Appendix A: Preparedness Checklists 1 Flood Preparedness Checklist The following checklist will help you prepare for how a flood could impact your business and your business continuity and disaster recovery
Ohio Supercomputer Center IT Business Continuity Planning No: Effective: OSC-13 06/02/2009 Issued By: Kevin Wohlever Director of Supercomputer Operations Published By: Ohio Supercomputer Center Original
Cyber Security: Guidelines for Backing Up Information A Non-Technical Guide Essential for Executives, Business Managers Administrative & Operations Managers This appendix is a supplement to the Cyber Security:
ENGINEERING-BASED EARTHQUAKE RISK MANAGEMENT MRP Engineering Newsletter February 2012 The world recently experienced several major earthquakes, which caused severe local impacts and major worldwide repercussions.
Are You Ready to ShakeOut? Major earthquakes can cause unprecedented catastrophes. With earthquakes as an inevitable part of our future, hospitals should make plans and take actions to ensure that disasters
1 of 12 DOCUMENT REVISION HISTORY Revision No. Date DESCRIPTION OF CHANGES Pages Affected By 00 01/07/2003 Draft Issued For Comment All HSEQ Dept. 01 01/09/2003 Total Change First Approved Issue All HSEQ
Fire Following Earthquake: Planning, Strategic, and Tactical Considerations Los Angeles County Fire Department Chief Deputy (Acting) David R. Richardson Jr. Fire Following Earthquake: An Overlooked Dilemma
EMERGENCY PROCEDURES In an Emergency Call 911 Using County Telephone System Call 9-911 Fresno County Sheriff 600-3111 Fresno County Security 600-6785 TABLE OF CONTENTS Introduction 3 Accidents 4 Serious
Disaster Recovery Plan Checklist Your guide for setting up or updating a Disaster Recovery Plan for your business. ArcSource Disaster Recovery Plan Checklist 1. Compile Your Internal Contacts Information
Emergency Operations Severe Weather Sarasota Manatee Airport Authority 2014 Important Information Needed INTERESTED PARTIES: Air Traffic Control Delta Air Lines JetBlue Airways United Airlines US Airways/American
Overview of how to test a Business Continuity Plan Prepared by: Thomas Bronack Phone: (718) 591-5553 Email: firstname.lastname@example.org BRP/DRP Test Plan Creation and Exercise Page: 1 Table of Contents BCP/DRP Test
California Institute of Technology EMERGENCY ACTION PLAN Emergency Plan For: DEPARTMENT/DIVISION BUILDING (S) FLOOR/ROOM Work Site Emergency Coordinator Name Email Evacuation Assembly Areas Building Assembly
Emergency Response Plan Public Version Contents INTRODUCTION... 4 SCOPE... 5 DEFINITION OF AN EMERGENCY... 5 AUTHORITY... 6 ACTION PRIOR TO DECLARATION... 6 FREEDOM OF INFORMATION & PRIVACY PROTECTION...
Business Continuity Planning (BCP) / Disaster Recovery (DR) Introduction Interruptions to business functions can result from major natural disasters such as earthquakes, floods, and fires, or from man-made
Disaster Recovery Planning Process By Geoffrey H. Wold Part I of III This is the first of a three-part series that describes the planning process related to disaster recovery. Based on the various considerations
Disaster Recovery Plan Starling Systems Deliverable #15 - Draft I Contract # 04-06 Accepted on: March 29, 2005 Starling Systems 711 S. Capitol Way, Suite 301 Olympia, WA 98501 DISASTER RECOVERY PLAN TABLE
Clovis Municipal School District Information Technology (IT) Disaster Recovery Plan Revision History REVISION DATE NAME DESCRIPTION Draft 1.0 Eric Wimbish IT Backup Disaster Table of Contents Information
Green Mountain College EMERGENCY RESPONSE AND RECOVERY PLAN INTRODUCTION Green Mountain College recognizes that one measure of an organization's strength is its ability to respond well in an emergency.
EXECUTIVE CRISIS MANAGEMENT TRAINING Presented by Roseanne Rostron, CBCP Raido Response 1 Introduction Roseanne Rostron President Raido Response Over 12 years Crisis Management, Business Continuity, Disaster
Table of Contents Primary Coordinating Agency... 2 Local Supporting Agencies... 2 State, Regional, and Federal Agencies and Organizations... 2 Purpose... 3 Situations and Assumptions... 4 Direction and
EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic
EMERGENCY PREPAREDNESS AND CRISIS MANAGEMENT PLAN MAY 2009 Public Web Version Getting Help Immediately Any situation requiring immediate response from police, fire, or emergency medical services to preserve
2014 Polk County ESF #3 Public Works and Engineering: Damage Assessment Section Public Version ESF#3 Damage Assessment Section 2014 Polk County Emergency Management Agency Page 1 of 14 Table of Contents
Business Continuity Planning at Financial Institutions July 2003 Bank of Japan Table of Contents Introduction...2 1 The Bank s View of Business Continuity Planning 1) Significance of business continuity
CONTINUITY OF OPERATIONS PLAN TEMPLATE For Long-Term Care Facilities CALIFORNIA ASSOCIATION OF HEALTH FACILITIES DISASTER PREPAREDNESS PROGRAM TABLE OF CONTENTS TABLE OF CONTENTS...2 SECTION 1: INTRODUCTION...3
UNITED CHURCH OF CHRIST LOCAL CHURCH DISASTER PREPAREDNESS AND RESPONSE PLANNING GUIDELINES The United Church of Christ local churches may use this plan as a guide when preparing their own disaster plans
Hurricane Checklist Although most hurricane warnings refer to the time a hurricane will make landfall, the impact from a hurricane can begin to be felt several hours prior to landfall. Landfall is defined
Availability and Disaster Recovery: Basic Principles by Chuck Petch, WVS Senior Technical Writer At first glance availability and recovery may seem like opposites. Availability involves designing computer
Domain 3 Business Continuity and Disaster Recovery Planning Steps (ISC) 2 steps [Har10] Project initiation Business Impact Analysis (BIA) Recovery strategy Plan design and development Implementation Testing
GEOTECHNICAL ISSUES OF LANDSLIDES CHARACTERISTICS MECHANISMS PREPARDNESS: BEFORE, DURING AND AFTER A LANDSLIDE QUESTIONS FOR DISCUSSIONS Huge landslide Leyte, Phillipines, 1998 2000 casulties Small debris
Recommended by Emergency Preparedness Committee: April 21, 2009 Recommended by President s Council: May 1, 2009 Approved by Executive Committee: May 5, 2009 NAIT Procedures CS1.2.6 Flood Implementation
1. What is the most common planned performance duration for a continuity of operations plan (COOP)? A. 30 days B. 60 days C. 90 days D. It depends on the severity of a disaster. 2. What is the business
University of Victoria EMERGENCY RESPONSE PLAN 2013 Table of Contents PLAN FUNDAMENTALS... 2 PURPOSE... 2 PRIORITIES... 2 PLAN SCOPE... 2 AUTHORITY... 2 RESPONSE LEVELS... 2 BEFORE AN EMERGENCY... 3 DURING
ANNEX K - UTILITIES RESTORATION ESF #3, #12 I. MNWALK REQUIREMENTS Item #: 1, 4, 46, 53, 54 II. PURPOSE The purpose of this annex is to describe the organization, operational concepts and responsibilities
EOC Assessment Checklist INTRODUCTION The following checklist will assist State and local governments in performing the initial assessment of the hazards, vulnerabilities, and resultant risk to their existing
Storm Ready Prep and Safety Power Restoration Your Service Connection Generator Safety Power Outage Map Stay Connected with Gulf Power Storm Ready 3 Gulf Power Ready for the storm 4 Be prepared, be safe
Nell Campbell-Drake Deborah Koller Jim Poteet Vice President Assistant Vice President Vice President Federal Reserve Bank Federal Reserve Bank Brink s, Inc. Please turn off all cell phones or mobile devices.
Mt. San Antonio College Campus Emergency Response and Evacuation Plan The Mt. SAC Board of Trustees is committed to providing a safe and secure campus work and learning environment for students, employees,
STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 AGENDA: Emergency Management Business Continuity Planning Q & A MONTH DAY, YEAR TITLE OF THE PRESENTATION 2 CANADIAN RED CROSS Disaster
Draft 8/1/05 SYSTEM First Rev. 8/9/05 2 nd Rev. 8/30/05 EMERGENCY OPERATIONS PLAN I. INTRODUCTION A. PURPOSE - The University of Hawaii System Emergency Operations Plan (EOP) provides procedures for managing
24 HOUR ANSWERING SERVICE The regular office hours at our firm are 9:00 am to 5:00 pm Monday to Friday. After these regular hours, the same telephone number is answered by a Telephone Answering Service,
The handouts and presentations attached are copyright and trademark protected and provided for individual use only. READINESS RESOURCES American Bar Association -- www.abanet.org Disaster Recovery: www.abanet.org/lpm/lpt/articles/slc02051.html
Cloud Computing Chapter 10 Disaster Recovery and Business Continuity and the Cloud Learning Objectives Define and describe business continuity. Define and describe disaster recovery. Describe the benefits
Hospital Emergency Operations Plan I-1 Emergency Management Plan I PURPOSE The mission of University Hospital of Brooklyn (UHB) is to improve the health of the people of Kings County by providing cost-effective,
What is a COOP? Continuity of Operations Planning A step by step guide for business A Continuity Of Operations Plan (COOP) is a MANAGEMENT APPROVED set of agreed-to preparations and sufficient procedures
Disaster Recovery Planning Presented by Micky Hogue, CRM Sandia National Laboratories Albuquerque, New Mexico Mlhogue@sandia.gov 1 2 3 If that happened to your business... Would your business be able to
DM-PH&SD-P7-TG6 رقم النموذج : I. Introduction This Guideline on supports the national platform for disaster risk reduction. It specifies requirements to enable both the public and private sector to develop
Business Continuity Planning 101 Presentation Overview What is business continuity planning Plan Development Plan Testing Plan Maintenance Future advancements in BCP Question & Answer What is a Disaster?
Disaster Recovery and Business Continuity Barbara Nollau Rupert King/Getty Images Computer Systems Quality and Compliance discusses practical aspects of computer systems and provides useful information
VI. EMERGENCY MANAGEMENT ORGANIZATION General 1. The overall responsibility for emergency preparedness rests with government on all levels, including all agencies of state, county and city in coordination
Earthquake Preparedness Tips & Strategies What to Do BEFORE an Earthquake What to Do DURING an Earthquake BE PREPARED! For more information, log onto: www.gema.ga.gov www.ready.ga.gov www.geophysics.eas.gatech.edu
Contents Yale Business Continuity Program Emergency Response Guide March 2016 Introduction Immediate Actions Assess the Damage Determining Business Disruption Determining Plan of Action Relocation Checklist
Page 1 of 7 The CPA Journal Online June 1994 Planning for disaster. by Smith, L. Murphy Search Software Personal Help Abstract- The string of natural and man-made disasters that had recently devastated
Disaster Recovery and Business Continuity What Every Executive Needs to Know Bruce Campbell & Sandra Evans Contents Why you need DR and BC What constitutes a Disaster? The difference between disaster recovery
5-04-25 Adding Communications Network Support to Existing Disaster Recovery Plans Leo A. Wrobel Payoff This article reviews the processes that must be documented in a recovery plan for a company's mission-critical
Last revised Feb. 2015 Festivals & Events Emergency Management Planning Guidelines The City of Burlington has partnered with the Halton Regional Police Service (HRPS) in the development of the Emergency
UNIVERSITY OF CALIFORNIA, MERCED EMERGENCY NOTIFICATION SYSTEM (UCMAlert) RESPONSIBLE OFFICER : Vice Chancellor - Administration EFFECTIVE DATE : REVISION NUMBER : Original NUMBER OF PAGES : 8 I. REFERENCES
Contingency Planning for Senior Management What you need to know about your business recovery Agenda Current Regulatory Environment Risk Management What is Contingency Planning Components of a solid recovery