Auditing the Unthinkable: Business Continuity and Disaster Recovery. Agenda

Size: px
Start display at page:

Download "Auditing the Unthinkable: Business Continuity and Disaster Recovery. Agenda"

Transcription

1 Auditing the Unthinkable: Business Continuity and Disaster Recovery The Institute of Internal Auditors Moderator: Paul J. Sobel, CIA, CPA Vice President, Internal Audit Mirant Corporation Agenda Introduction and Overview Preparing an Effective Business Continuity Program Molly Latham Internal Audit Drivers in Business Continuity Michael Keating Auditing the Business Continuity Plan Matthew Gagnon First Hand Experience: Internal Audit s Role In a Disaster Kevin Piccoli Break Question & Answer Summary of Main Points

2 CPE Requirements Two CPE credits. Interactive polling and knowledge check questions. 75 percent response required to receive credit. Be sure to scroll down and read all of the possible answers, and then click the submit button for your answer to count. Must view the entire webcast, including the Q&A. Only registered participants will be eligible to receive credit. If viewing this webcast as a recording, an additional final exam must be passed; please ensure pop-up blocking software is disabled. Please Note: The corresponding slides may not be in exact sync with the panelist presentations because of system refresh delays; slides and resources are available for download/print from the webcast lobby page.

3 Key Questions for Today 1. What are some of the key items to a meaningful business continuity plan? 2. What are the benefits of using a business continuity model and how can it be used to improve the business continuity maturity level of an organization? Key Questions (cont.) 3. What are the drivers of internal audit s growing involvement in the business continuity management lifecycle? What is the significance of business continuity risk relative to risks covered in other audits? 4. Are there business continuity standards that internal auditors should be aware of, and if so, is compliance mandatory? 5. How can internal auditors get involved in business continuity management and what are some specific roles that chief audit executives, audit managers, and IT auditors should take?

4 Questions for Today (cont.) 6. Why are business continuity exercises important and what are some common testing exercises to assess the effectiveness of a business continuity program? 7. What are some key areas that internal auditors should review when performing a business continuity and disaster recovery audit? 8. What are the opportunities for internal auditors to add value during and after a disaster to help ensure successful recovery? Preparing an Effective Business Continuity Program Molly Latham, CIA, CCSA Manager, Business Continuity Planning Southern California Edison Co. Rosemead, Calif.

5 Agenda The importance of an effective business continuity plan (BCP) Keys to a meaningful business continuity program BCP scope Existing BCP models The Importance of an Effective Business Continuity plan Recent catastrophes (9-11, Katrina, Asian tsunami) demonstrate that events can and do happen Effective business continuity is a key internal control, with or without regulatory mandates What could be more important than surviving? If the program is sub-par, management needs to take corrective action before the next disaster

6 Keys to a Meaningful BCP Ensure the business continuity program (BCP) scope is broad An effective BCP must be holistic Reviewing just one piece of the program will not produce assurance that the overall program is sound Plans need to be tested to assure the quality of the business continuity program Ensure that management, the audit committee, and audit staff have a clear understanding of key business continuity concepts BCP Scope 1 Organizational issues Leadership Employee awareness Program structure and pervasiveness Performance issues Metrics Staffing Coordination with internal and external resources Incident management and communications Technology recovery Business recovery 1 Adapted from the Complete Public Domain Business Continuity Maturity Model sm, Virtual Corporation 2007

7 S. Calif. Edison s BC Model Business Continuity Maturity Model -Virtual Corporate Straight forward assessment tool Establishes six maturity levels Self-governed Supported self-governed Centrally governed Enterprise awakening Planned growth Synergistic Allows for online assessment Existing Models National Fire Protection Association Standard on Disaster/Emergency and Business Continuity Programs A nonmandatory national standard Focuses more heavily on emergency management rather than business recovery processes

8 BC Models Business Continuity Guideline ASIS International A five-phase model that includes Readiness Prevention Response Recovery / Resumption Testing and training Provides basic examples of business continuity work products BC Models (cont.) British Standard Recently adopted by the British Standards Institute Provides for a benchmark by which British companies may assess key suppliers and partners Establishes the business continuity process, principles and terminology Reflects the maturity of the British business continuity community

9 In Closing More than ever, there are enormous resources available to anyone who wants to learn more about this field Business continuity planning is here to stay; it is worthwhile to invest in BC certification for some audit staff Disaster Recovery Institute International Business Continuity Institute Knowledge Check # 1 Organizations should consider using a business continuity model to develop their business continuity program because: a. It is a mandatory regulatory requirement b. Many business continuity models provide processes for varying maturity levels c. Most models guarantee minimal business interruption

10 Knowledge Check # 2 When developing a business continuity plan, which of the following would be considered a performance issue, versus an organizational issue? a. Leadership b. Employee awareness c. Program structure d. Technology recovery Knowledge Check # 3 An evaluation of an organization's business continuity plan is sufficient to attest to the program's adequacy. a. True b. False

11 Internal Audit Drivers in Business Continuity Michael Keating, CBCP Associate Director Protiviti Atlanta, GA Agenda The growing role of internal auditing in business continuity management (BCM) Drivers of internal audit s growing involvement in BCM How internal auditing can be involved throughout the BCM lifecycle

12 Growing Standards U.S. National Preparedness Standard and British Standard More than 71% of respondents knew about the U.S. National Preparedness Standard More than 30% were already changing their BCM programs as a result (2007 KPMG/Continuity Insights Magazine Survey) Most other standards addressing BCM have become more rigid since 2004 Riskier World Despite a down year in 2006, most climatologists expect bad hurricane seasons for more years. Terrorism, especially smaller scale events, are a continuing threat. New threats such as pandemic influenza and single/sole source supplier failures are growing exposures.

13 Continuity Risks Growing in Consequence Continuity risks are appearing in more enterprise risk assessments. Consolidation, outsourcing, and offshoring creates risk concentrations that must be monitored and mitigated. Continuity-related risks are appearing in SEC 10-Ks and other investor disclosures. Implications of the Risk Environment: Greater Expectation of Preparedness Greater director and officer exposure is driving audit committees to increase their attention More external auditors are inquiring about continuity issues Customer mandates are rapidly becoming the norm in some industry segments Push toward more consensus in reasonable level of preparedness All of these issue require an periodic, objective assessment of the BCM program

14 What Should IA do in BCM? (in addition to BCM audits) Assist in the development and compliance monitoring of a BCM policy Incorporate continuity issues in existing risk assessment projects Sponsor and perform business impact analyses Assist with cost benefit analyses of BCM strategy options Develop BCM program maturity goals with management and the board IA and BCM Exercises Exercises are the key to demonstrating BCM capability Exercise formats vary and are equally valid depending on purpose Desk review Tabletop Component Simulation IA can observe exercises, and also assist in performance metrics and monitoring

15 Internal Audit Impact Almost 22% of respondents expected IA to measure the performance of their BCM programs Almost 50% of respondents cited some specific third party requirement for their BCM program Almost 2% of respondents indicated BCM actually reported to IA (2007 KPMG/Continuity Insights Magazine Survey) In Closing Business continuity continues to be driven by high profile issues In many cases, IA can add value by simply expanding areas they already audit As continuity becomes more of a strategic issue, IA s role in its maturity and compliance will only grow

16 Knowledge Check # 4 Which of the following creates the greatest concentration of business continuity risk? a. Consolidations and outsourcing b. Subsidiary and multiple branch operations c. Regional retail and manufacturing operations d. Application service providers Knowledge Check # 5 Which of the following is NOT a role that internal auditors should take in the business continuity process? a. Assist in compliance monitoring of the business continuity policy b. Incorporate continuity issues in existing risk assessment projects c. Perform business impact analysis d. Set business continuity maturity goals for the organization

17 Knowledge Check # 6 Internal auditors are increasingly including business continuity risk into their risk assessments and audit plans because it is: a. A regulatory requirement b. An integral part of the enterprise risk management process. c. A fairly easy fix that takes few audit resources Auditing the Business Continuity Plan Matthew Gagnon, CPA, CISA VP, Director of Internal Audit Fieldstone Investment Corp. Columbia, Md.

18 Agenda Auditing the business continuity plan How mature is your company s BCP Get BCP on your internal audit plan Update/document your understanding Finalize the audit scope Testing Communicate results to stakeholders BCP Maturity BCP maturity is a key factor in planning the nature and extent of audit testing. Has a Business Impact Assessment (BIA) been performed? Is it up-to-date? Does a formal BCP exist? Has a comprehensive set of disaster scenarios been documented? Have BCP roles been defined? Is crisis management included in the BCP? Disaster recovery planning? Business resumption planning? Is regular/periodic testing performed?

19 Get BCP on your Internal Audit Plan Identify business risks/quantify exposure Evaluate the significance of these risks relative to risks covered in other possible audit projects Determine the amount of audit resources you should allocate to complete this review IIA Standards: Due Professional Care / 1220.A Planning Obtain AC approval to audit BCP 2020 Communication and Approval 2600 Management s Acceptance of Risks Document Your Understanding Corporate BCP objectives Owners/participants Current state Business Impact Assessment Covered entities/business units Inter-relationships/dependencies defined Process prioritization/sequencing Recovery Time Objectives (RTOs) Risk management techniques for scenarios Extent of BCP testing executed Management evaluation of effectiveness

20 Finalize Scope Objectives may include: BIA: complete and accurate BCP design: includes comprehensive set of disaster scenarios; covers all business critical processes; plus those performed by 3 rd parties Risk management techniques: defined, approved, and implemented for all relevant risks RTOs: recovery sequences are consistent with BCP objectives and reduce impact to a level consistent with management s risk appetite Test plans: provide a reasonable basis for a conclusion regarding BCP effectiveness Test results:accurate, reported, timely addressed Testing Business Impact Assessment (BIA) Business Continuity Plan (BCP) Disaster Recovery Plan (DRP) Business Resumption Plan (BRP) Crisis Management (CM) BCP Test Results

21 BIA Testing Completeness Impact assessment calculations Financial Operational Change management Plan completeness BCP Testing Business/time critical processes Personnel roles & responsibilities Recovery manuals/procedures Offsite data/records storage and retrieval Recovery facilities Testing/disaster scenarios Change management

22 Plan completeness DRP Testing Personnel roles & responsibilities Recovery manuals/procedures Applications Data Hardware Networking Recovery facilities Change management Testing scenarios Plan completeness BRP Testing Personnel roles & responsibilities Recovery manuals/procedures Recovery facilities Telecommunications Change management Testing scenarios

23 Crisis Management Testing Plan completeness Personnel roles & responsibilities Recovery manuals/procedures Communications plan Recovery team members Employees Customers Shareholders Business partners Press Change management Testing scenarios Evaluating BCP Test & Results Is testing properly planned? Scenario selected/defined Goals established/communicated Appropriate personnel involved Interdependent entities tested simultaneously Business units; IT; 3 rd parties Results documented Appropriate actions planned/taken? - Conclusions accurate - Conclusions support assumptions - Action plans appropriate

24 Communicating Results Clearly describe observed BCP deficiencies and management s plan to address Executive summary; observation Criteria for concluding the observation constitutes a deficiency Likelihood and potential impact Action plan; person responsible; expected resolution date Distribute report to all stakeholders Audit committee Senior management; process owners Communicating/Disseminating Results In Closing Know the state of your company s BCP. Evaluate the significance of BCP risks relative to risks covered in other audits. Review the accuracy and completeness of the company s business impact analysis. Ensure the BCP considers a comprehensive set of disaster conditions. Determine that tests provide a reasonable basis for concluding on BCP effectiveness.

25 Knowledge Check # 7 Which of the following is generally NOT part of a business continuity plan (BCP)? a. Comprehensive set of disaster scenarios are documented b. Management roles are defined c. Ongoing testing is performed d. Documented approval of the BCP by the audit committee Knowledge Check # 8 A legitimate ERM role that internal auditors may undertake, with safeguards, includes: a. Coordinating ERM activities b. Imposing risk management processes c. Implementing risk management responses on management s behalf d. Owning and being accountable for the company s risk management process

26 First Hand Experience: Internal Audit s Role In a Disaster Kevin C. Piccoli, CPA Executive Vice President The Bank of New York New York, NY Agenda Bank of New York s experience in the 9-11 disaster How internal auditing added value to the disaster recovery efforts Opportunities Keys to a successful recovery

27 Impact on The Bank of New York 8,300 employees displaced Four buildings evacuated World Headquarters Operations Center Trading Center Three primary data centers abandoned Data/telecommunications infrastructure in lower Manhattan destroyed Evaluate the Team Capitalize on the strength of the team Knowledge of the business Cradle to grave approach Intuitive Resourceful Problem solving Focus of the audit team Chief audit executive: Advisor to CEO Audit managers: Advisors to business heads Audit staff: Part of business team IT audit: Data security, change control

28 Chief Audit Executive Role Advisor to CEO Control issues Status of recovery progress Trouble shooting Communication link Flexibility Policy decisions Risk assessment Observer; look for areas to assist Report to the board of directors Audit Managers Role Business advisor Assess the control environment Establish compensating controls Develop tools Software; reports; logs Assess business resources Coordinate with other business units Observe; identify areas for focus Develop the plan Part of the management team, NOT an auditor

29 Audit Staff Role Consider them the business employees Use their skills to: Research issues Develop reports Design reconciliation process Free up day-to-day personnel IT Audit Role Understand the recovery process What happened Strategy and priority of the fix Data security Change control Develop research tools Provide support to recovery efforts

30 Opportunities Be open and alert Reconciliation assistance Develop recovery plan for each business Foster communication Develop customer communications Be available for consultation Facilities coordinator Opportunities (cont.) Prepare for insurance claim Review press releases Communicate with customers Develop telephone lists Cheerleader Develop employee communications Develop policy Corporate governance & committees

31 Keys to a Successful Recovery Stick to the plan Cream rises to the top Communication Prioritize Systems Telecommunication Customers; Wall Street Fluid, constant redesigning of the process & plan Think of the people Other Exposures Avian Flu Approach is similar to other disasters but prolonged (3 months) Theft/loss of confidential information Assess situation Determine nature of data compromised Escalate immediately to bring all parties together Determine legal requirements Evaluate reputation exposure

32 In Closing Because of our business knowledge, internal auditing is invaluable to disaster recovery efforts. Serve as part of the management team, NOT as an auditor. Be flexible when assisting with policy decisions and risk assessment. Look for opportunities to help. Think of the people. Knowledge Check # 9 In the event of a disaster, internal auditors should: a. Continue to execute the approved annual audit plan b. Assess the control environment c. Immediately perform a disaster recovery audit d. Stay out of the way and wait for further instructions

33 Knowledge Check # 10 Audit managers should serve as part of the management team in a disaster recovery mode, rather than in an internal audit role. a. True b. False Panelist Q&A Click the Ask Question link below this slide image. Type your question in the text box. If your question is to a specific panelist please state the panelist in your question. Click the Submit button

34 In Summary 1. As business continuity becomes more of a strategic issue, internal auditors role in its maturity and compliance will only grow. 2. During the risk assessment process, internal auditors should document the organization s current state of business continuity preparedness and incorporate business continuity planning objectives into their audits. In many cases, internal auditors can add value by simply expanding areas they already audit. Summary (cont.) 3. A formal business continuity plan should document business critical processes, personnel roles and responsibilities, recovery procedures, offsite records storage and retrieval, and recovery facilities. 4. Internal auditors can add value by helping to ensure the business continuity program scope is broad enough and that management has a clear understanding of business continuity concepts.

35 Summary (cont. 2) 5. During a business continuity audit, internal auditors should review the accuracy and completeness of the company s business impact analysis and determine that the business continuity plan considers a comprehensive set of disaster scenarios. 6. During a disaster, internal auditors should be flexible when assisting with policy decisions and risk assessment and look for opportunities to help. Summary (final) 7. There are enormous resources available to learn more about business continuity preparedness and disaster recovery planning. It is worthwhile to invest in business continuity training for audit staff.

36 Thank you for participating! Please complete the webcast evaluation Live webcast when you close your browser the evaluation will open in a new window. On-demand viewers when you close this window your quiz will appear in a new window; upon completion of the quiz you will be presented an evaluation to complete.

The Business Continuity Maturity Continuum

The Business Continuity Maturity Continuum The Business Continuity Maturity Continuum Nick Benvenuto & Brian Zawada Protiviti Inc. 2004 Protiviti Inc. EOE Agenda Terminology Risk Management Infrastructure Discussion A Proposed Continuity Maturity

More information

Business Continuity and Disaster Recovery Planning

Business Continuity and Disaster Recovery Planning Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services

More information

MHA Consulting. Business Continuity Management 101

MHA Consulting. Business Continuity Management 101 0 MHA Consulting Business Continuity Management 101 Presented by: Michael Herrera Brandon Magestro MHA Consulting Agenda MHA Consulting Introduction Business Continuity Management (BCM) Defined 2013 Trends

More information

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 Agenda Key Definitions Risks Business Continuity Management Program BCM Capability Assessment Process BCM Value Proposition

More information

INFOSEC.MY KNOWLEDGE SHARING SESSION

INFOSEC.MY KNOWLEDGE SHARING SESSION INFOSEC.MY KNOWLEDGE SHARING SESSION Integration BCM into your Organization: Challenges & Opportunities 31 st October 2007 1 Prabha Ramanathan ( CBCP, MBCI, MBCS, MSCS) Certified Business Continuity Professional.have

More information

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745 ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan

More information

The Role of Internal Audit In Business Continuity Planning

The Role of Internal Audit In Business Continuity Planning The Role of Internal Audit In Business Continuity Planning Dan Bailey, MBCP Page 0 Introduction Dan Bailey, MBCP Senior Manager Protiviti Inc. dan.bailey@protiviti.com Actively involved in the Information

More information

The PNC Financial Services Group, Inc. Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program The PNC Financial Services Group, Inc. Business Continuity Program subsidiaries) 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis

More information

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015 Business Continuity Management Governance Frank Higgins Abu Dhabi March 2015 Different Names Same Concept BCM (Business Continuity Management) BSI 25999 IPOCM (Incident Preparedness & Operational Continuity

More information

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD. Business Continuity Management & Disaster Recovery Planning Presented by: Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD. 1 What is Business Continuity Management? Is a holistic management

More information

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd BS 25999 Business Continuity Management By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd 1 Contents slide BSI British Standards 2006 BS 25999(Business Continuity) 2002 BS 15000

More information

CISM Certified Information Security Manager

CISM Certified Information Security Manager CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective

More information

Using the Business Continuity Maturity Model To Gain Executive Approval. June 20, 2006

Using the Business Continuity Maturity Model To Gain Executive Approval. June 20, 2006 Using the Business Continuity Maturity Model To Gain Executive Approval Margaret Langsett, Executive Vice President, Virtual Corporation Manfred Heinzlreiter, CBCP, Managing Partner, BR- i.com June 20,

More information

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity INFORMATION RISK MANAGEMENT KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity ADVISORY Contents Agenda: Global trends and BCM

More information

Temple university. Auditing a business continuity management BCM. November, 2015

Temple university. Auditing a business continuity management BCM. November, 2015 Temple university Auditing a business continuity management BCM November, 2015 Auditing BCM Agenda 1. Introduction 2. Definitions 3. Standards 4. BCM key elements IT Governance class - IT audit program

More information

Business Continuity Management 101. Patrick Potter, CBCP MHA Consulting ISACA November 19, 2009

Business Continuity Management 101. Patrick Potter, CBCP MHA Consulting ISACA November 19, 2009 Business Continuity Management 101 Patrick Potter, CBCP MHA Consulting ISACA November 19, 2009 1 Who is MHA Consulting Who We Are What We Do Leading boutique consulting firm since 1998 Provider of consulting

More information

BCP and DR. P K Patel AGM, MoF

BCP and DR. P K Patel AGM, MoF BCP and DR P K Patel AGM, MoF Key difference between BS 25999 and ISO 22301 ISO 22301 puts a much greater emphasis on setting the objectives, monitoring performance and metrics aligning BC to top management

More information

Evaluating and Improving Your Business Continuity Plan

Evaluating and Improving Your Business Continuity Plan Evaluating and Improving Your Business Continuity Plan As presented to the Northeast Florida IIA Chapter January 23, 2015 Contact Information Karen Weir, MAC, CISA, CBCP Manager kweir@accretivesolutions.com

More information

Why Should Companies Take a Closer Look at Business Continuity Planning?

Why Should Companies Take a Closer Look at Business Continuity Planning? whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters

More information

Business Continuity Planning

Business Continuity Planning Business Continuity Planning Presenter Carolyn Bell-Wisdom, CIA, FCCA, FCA, CISA, CFE, Director, Internal Audit Outsourcing, Risk & Business Continuity Services at Jamaica AGENDA Welcome and introduction

More information

2014 NABRICO Conference

2014 NABRICO Conference Business Continuity Planning 2014 NABRICO Conference September 19, 2014 6 CityPlace Drive, Suite 900 St. Louis, Missouri 63141 314.983.1200 1520 S. Fifth Street, Suite 309 St. Charles, Missouri 63303 636.255.3000

More information

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015 Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level June 9, 2015 By: Tracy Hall MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company,

More information

The PNC Financial Services Group, Inc. Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page

More information

PAPER-6 PART-5 OF 5 CA A.RAFEQ, FCA

PAPER-6 PART-5 OF 5 CA A.RAFEQ, FCA Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-5 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand

More information

Table of Contents... 1

Table of Contents... 1 ... 1 Chapter 1 Introduction... 4 1.1 Executive Summary... 4 1.2 Goals and Objectives... 5 1.3 Senior Management and Board of Directors Responsibilities... 5 1.4 Business Continuity Planning Processes...

More information

Company Management System. Business Continuity in SIA

Company Management System. Business Continuity in SIA Company Management System Business Continuity in SIA Document code: Classification: Company Project/Service Year Document No. Version Public INDEX 1. INTRODUCTION... 3 2. SIA S BUSINESS CONTINUITY MANAGEMENT

More information

Meeting FFIEC Requirements: Enterprise-Wide Testing of Your. Business Continuity Plan

Meeting FFIEC Requirements: Enterprise-Wide Testing of Your. Business Continuity Plan Meeting FFIEC Requirements: Enterprise-Wide Testing of Your Business Continuity Plan April 25, 2012 Robin Remines, CBCP, AMBCI Certified Business Continuity Professional The OGO Difference Focus on making

More information

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA 1 Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand

More information

Business Continuity Plan

Business Continuity Plan Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions

More information

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES APPENDIX 1 DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES March 2008 Auditor General s Office Jeffrey Griffiths, C.A., C.F.E. Auditor General City of Toronto TABLE OF CONTENTS EXECUTIVE SUMMARY...1

More information

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK BUSINESS CONTINUITY MANAGEMENT FRAMEWORK Document Author: Civil Contingencies Service - Authorised by the CCS Joint Management Board - Version 1.0. Issued December 2012 Page 1 FRAMEWORK STATEMENT Business

More information

Business Continuity in Healthcare

Business Continuity in Healthcare Business Continuity in Healthcare Cynthia Simeone, CBCP, PMP Director Business Resilience Catholic Health Initiatives Scott Ream President Virtual Corporation 1 Session Speakers Cynthia Simeone, CBCP,

More information

Business Continuity Management Planning Methodology

Business Continuity Management Planning Methodology , pp.9-16 http://dx.doi.org/10.14257/ijdrbc.2015.6.02 Business Continuity Management Planning Methodology Dr. Goh Moh Heng, Ph.D., BCCLA, BCCE, CMCE, CCCE, DRCE President, BCM Institute moh_heng@bcm-institute.org

More information

State of South Carolina Policy Guidance and Training

State of South Carolina Policy Guidance and Training State of South Carolina Policy Guidance and Training Policy Workshop All Agencies Business Continuity Management Policy June 2014 Agenda Questions & Follow-Up Policy Workshop Overview & Timeline Policy

More information

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION Federal Financial Institutions Examination Council FFIEC Business Continuity Planning MARCH 2003 MARCH 2008 BCP IT EXAMINATION H ANDBOOK TABLE OF CONTENTS INTRODUCTION... 1 BOARD AND SENIOR MANAGEMENT

More information

SUPERVISORY AND REGULATORY GUIDELINES: PU19-0406 BUSINESS CONTINUITY GUIDELINES

SUPERVISORY AND REGULATORY GUIDELINES: PU19-0406 BUSINESS CONTINUITY GUIDELINES SUPERVISORY AND REGULATORY GUIDELINES: PU19-0406 Business Continuity Issued: 1 st May, 2007 Revised: 14 th October 2008 BUSINESS CONTINUITY GUIDELINES I. INTRODUCTION The Central Bank of The Bahamas (

More information

Business Continuity Planning:

Business Continuity Planning: Business Continuity Planning: How prepared must a CFO & other Executives be for a potential interruption to the business Presenter: Bruce L Scott, Partner Risk & Business Continuity Services June 2005

More information

Disaster Preparedness & Response

Disaster Preparedness & Response 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 A B C E INTRODUCTION AND PURPOSE REVIEW ELEMENTS ABBREVIATIONS NCUA REFERENCES EXTERNAL REFERENCES Planning - Ensuring

More information

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning 4 Business Continuity Planning and Disaster Recovery Planning Basic Concepts 1. Business Continuity Management: Business Continuity means maintaining the uninterrupted availability of all key business

More information

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14

More information

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC Assessing Your Disaster Recovery Plans Gregory H. Soule, CPA, CISA, CISSP, CFE Andrews Hooper Pavlik PLC Andrews Hooper Pavlik PLC Agenda Business Continuity Concepts Impact Analysis Risk Assessment Risk

More information

How To Prepare For A Disaster

How To Prepare For A Disaster Building an effective Tabletop Exercise Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 3/26/2013 #1 Continuity Plan Testing Flowchart 3/26/2013 #2 1 Ongoing Multi-Year

More information

Business Continuity Trends, Requirements and Expectations in 2009. Brian Zawada (MBCP) Director of Consulting Services Avalution Consulting

Business Continuity Trends, Requirements and Expectations in 2009. Brian Zawada (MBCP) Director of Consulting Services Avalution Consulting Business Continuity Trends, Requirements and Expectations in 2009 Brian Zawada (MBCP) Director of Consulting Services Avalution Consulting Overview What Is Business Continuity? The Value Proposition What

More information

Internal Auditing Guidelines

Internal Auditing Guidelines Internal Auditing Guidelines Recommendations on Internal Auditing for Lottery Operators Issued by the WLA Security and Risk Management Committee V1.0, March 2007 The WLA Internal Auditing Guidelines may

More information

THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST. Business Continuity Plan

THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST. Business Continuity Plan THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST Business Continuity Plan June 2012 Purpose The purpose of this Business Continuity Plan ( BCP ) is to define the strategies and the plans which

More information

Business Continuity Management

Business Continuity Management Prudential Standard CPS 232 Business Continuity Management Objective and key requirements of this Prudential Standard This Prudential Standard requires each APRA-regulated institution to implement a whole-of-business

More information

Disaster Recovery. Hendry Taylor Tayori Limited

Disaster Recovery. Hendry Taylor Tayori Limited Disaster Recovery Hendry Taylor Tayori Limited Agenda What is Business Continuity planning (BCP) What is Disaster Recovery (DR) and Disaster Recovery Planning (DRP) Overview Lifecycle Analysis Plan design

More information

BC / DR Implementation Tying Disaster Recovery Investment to Measurable Business Value

BC / DR Implementation Tying Disaster Recovery Investment to Measurable Business Value BC / DR Implementation Tying Disaster Investment to Measurable Business Value Continuity Insights Conference May 16-18, 2005 Agenda Purpose Discuss best practice process and tools that might be leveraged

More information

Principles for BCM requirements for the Dutch financial sector and its providers.

Principles for BCM requirements for the Dutch financial sector and its providers. Principles for BCM requirements for the Dutch financial sector and its providers. Platform Business Continuity Vitale Infrastructuur Financiële sector (BC VIF) Werkgroep BCM requirements 21 September 2011

More information

CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM

CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM A WHITE PAPER CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM AUTHORS: Neil A. Smith, MBCP nsmith24@csc.com Sandra Riddell, MBCI sriddel4@csc.com CSC Papers 2013 ABSTRACT The auditors said

More information

How To Manage A Disruption Event

How To Manage A Disruption Event BUSINESS CONTINUITY FRAMEWORK DOCUMENT INFORMATION DOCUMENT TYPE: DOCUMENT STATUS: POLICY OWNER POSITION: INTERNAL COMMITTEE ENDORSEMENT: APPROVED BY: Strategic document Approved Manager Organisational

More information

An Overview of Professional Directors and Officers Liability in Disaster Preparedness and Recovery Planning

An Overview of Professional Directors and Officers Liability in Disaster Preparedness and Recovery Planning An Overview of Professional Directors and Officers Liability in Disaster Preparedness and Recovery Planning Eric Martin Scott Southern University Law Center Preparation for disasters involves a variety

More information

A GUIDE TO BUSINESS CONTINUITY PLANNING

A GUIDE TO BUSINESS CONTINUITY PLANNING A GUIDE TO BUSINESS CONTINUITY PLANNING Introduction The Civil Contingencies Act 2004 places a duty on Local Authorities to ensure that local businesses and voluntary sector organisations in their area

More information

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP 2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level Tracy L. Hall, MBCP MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company, P.C.

More information

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS DIRECTORATE OF BANKING SUPERVISION AUGUST 2009 TABLE OF CONTENTS PAGE 1.0 INTRODUCTION..3 1.1 Background...3 1.2 Citation...3

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy Summary: This policy sets out the structure for ensuring that the PCT has effective Business Continuity Plans in place in order to maintain its essential business functions during

More information

Business Continuity Policy and Business Continuity Management System

Business Continuity Policy and Business Continuity Management System Business Continuity Policy and Business Continuity Management System Summary: This policy sets out the structure for ensuring that the PCT has effective Business Continuity Plans in place in order to maintain

More information

How to Design and Implement a Successful Disaster Recovery Plan

How to Design and Implement a Successful Disaster Recovery Plan How to Design and Implement a Successful Disaster Recovery Plan Feb. 21 ASA Office-Administrative Section is Sponsored by Today s ASAPro Webinar is Brought to You by the How to Ask a Question Questions

More information

Overview of how to test a. Business Continuity Plan

Overview of how to test a. Business Continuity Plan Overview of how to test a Business Continuity Plan Prepared by: Thomas Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com BRP/DRP Test Plan Creation and Exercise Page: 1 Table of Contents BCP/DRP Test

More information

How To Understand The State Of Business Continuity Preparedness

How To Understand The State Of Business Continuity Preparedness M ARKET STUDY The State of Business Continuity Preparedness Photo by Sergey Nivens Fotolia.com By STEPHANIE BALAOURAS Forrester Research and the Disaster Recovery Journal have partnered to field a number

More information

CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR. Follow-up Audit of Information Technology Services Department. IT Contingency Planning

CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR. Follow-up Audit of Information Technology Services Department. IT Contingency Planning Follow-up Audit of Information Technology Services Department CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR Follow-up Audit of Information Technology Services Department Project No. AU13-F05 October 25,

More information

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK Federal Financial Institutions Examination Council FFIEC Business Continuity Planning BCP FEBRUARY 2015 IT EXAMINATION H ANDBOOK Table of Contents Introduction 1 Board and Senior Management Responsibilities

More information

Coping with a major business disruption. Some practical advice

Coping with a major business disruption. Some practical advice Coping with a major business disruption Some practical advice Coping with a major business disruption What is business continuity? Business continuity planning (BCP) is a management process that helps

More information

BUSINESS CONTINUITY POLICY

BUSINESS CONTINUITY POLICY BUSINESS CONTINUITY POLICY Last Review Date Approving Body n/a Audit Committee Date of Approval 9 th January 2014 Date of Implementation 1 st February 2014 Next Review Date February 2017 Review Responsibility

More information

How To Plan A Crisis Management Program

How To Plan A Crisis Management Program Building a Security Conscious Business Continuity Management (BCM) Program Sam Stahl, CBCP, MBCI EMC Global Professional Services Program Manager stahl_samuel@emc.com ASIS Singapore, 2014 Agenda Overview

More information

EXECUTIVE CRISIS MANAGEMENT TRAINING. Presented by Roseanne Rostron, CBCP Raido Response

EXECUTIVE CRISIS MANAGEMENT TRAINING. Presented by Roseanne Rostron, CBCP Raido Response EXECUTIVE CRISIS MANAGEMENT TRAINING Presented by Roseanne Rostron, CBCP Raido Response 1 Introduction Roseanne Rostron President Raido Response Over 12 years Crisis Management, Business Continuity, Disaster

More information

Audit of the Disaster Recovery Plan

Audit of the Disaster Recovery Plan Audit of the Disaster Recovery Plan Report # 11-05 Prepared by Office of Inspector General J. Timothy Beirnes, CPA, Inspector General Kit Robbins, CISA, CISM, CRISC, Lead Information Systems Auditor TABLE

More information

Risk & Audit Committee California Public Employees Retirement System

Risk & Audit Committee California Public Employees Retirement System California Public Employees Retirement System Consent Agenda Item 5d ITEM NAME: Enterprise Risk Management Division Status Report PROGRAM: Risk Management ITEM TYPE: Information Consent EXECUTIVE SUMMARY

More information

Business Continuity and Crisis Management

Business Continuity and Crisis Management Business Continuity and Crisis Management Crisis Management, Business Continuity and The Incident Command System Understanding Differences and Putting it all together? by Max Ckonjevic FBCI, CBCP 1 Objectives

More information

Business Continuity Management Policy

Business Continuity Management Policy Business Continuity Management Policy Business Continuity Policy Version 1.0 1 Version control Version Date Changes Author 0.1 April 13 1 st draft PH 0.2 June 13 Amendments in line with guidance PH 0.3

More information

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard PUBLIC Version: 1.0 CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard (Approved by the Information Strategy and Governance Committee in December 2013; revision 1.1 approved by Chief

More information

Emergency Response and Business Continuity Management Policy

Emergency Response and Business Continuity Management Policy Emergency Response and Business Continuity Management Policy Owner: John Duffy, Registrar & Secretary Last updated: September 2012 Version: 04 Document control Date Version Author Changes To be populated

More information

How To Understand The Role Of An Internal Audit

How To Understand The Role Of An Internal Audit Top Ten Issues facing Internal Auditing in the Future The IIA Dallas Chapter April 6, 2006 Presented by: David A. Richards, CIA, CPA President The Institute of Internal Auditors drichards@theiia.org 1

More information

www.pwc.com Third Party Risk Management 12 April 2012

www.pwc.com Third Party Risk Management 12 April 2012 www.pwc.com Third Party Risk Management 12 April 2012 Agenda 1. Introductions 2. Drivers of Increased Focus on Third Parties 3. Governance 4. Third Party Risks and Scope 5. Third Party Risk Profiling 6.

More information

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP IT Disaster Recovery Plan Template By Paul Kirvan, CISA, CISSP, FBCI, CBCP Revision History REVISION DATE NAME DESCRIPTION Original 1.0 2 Table of Contents Information Technology Statement

More information

Guidance Note XGN XXX.1

Guidance Note XGN XXX.1 Guidance Note XGN XXX.1 Risk Assessment and Business Continuity Planning 1. This Guidance Note provides further detail on matters institutions should consider in assessing disruption scenarios and certain

More information

De Nederlandsche Bank N.V. May 2011. Assessment Framework for Financial Core Infrastructure Business Continuity Management

De Nederlandsche Bank N.V. May 2011. Assessment Framework for Financial Core Infrastructure Business Continuity Management De Nederlandsche Bank N.V. May 2011 Assessment Framework for Financial Core Infrastructure Business Continuity Management Contents INTRODUCTION... 3 BUSINESS CONTINUITY MANAGEMENT STANDARDS... 5 1. STRATEGY

More information

Proposal for Business Continuity Plan and Management Review 6 August 2008

Proposal for Business Continuity Plan and Management Review 6 August 2008 Proposal for Business Continuity Plan and Management Review 6 August 2008 2008/8/6 Contents About Newton IT / Quality of our services. BCM & BS25999 Overview 2. BCM Development in line with BS25999 3.

More information

Business Continuity / Disaster Recovery Context

Business Continuity / Disaster Recovery Context Capability Business Continuity / Disaster Recovery Context What is Business Continuity? The Business Continuity Program Life Cycle Copyright: Virtual Corporation, 1994 2006 Modified U.S. DoD Graphic Normal

More information

BUSINESS CONTINUITY PLANNING GUIDELINES

BUSINESS CONTINUITY PLANNING GUIDELINES BUSINESS CONTINUITY PLANNING GUIDELINES Washington University in St. Louis The purpose of this guide is to serve as a tool to all departments, divisions, and labs across the University in building a Business

More information

Business Continuity Management and BS 25999 by Steve Chan, Head of Training - HK, BSI Management Systems

Business Continuity Management and BS 25999 by Steve Chan, Head of Training - HK, BSI Management Systems Business Continuity Management and BS 25999 by Steve Chan, Head of Training - HK, BSI Management Systems 9 April, 2008 2 Presentation content Drivers for Business Continuity Standards and definitions.

More information

Audit of Business Continuity Planning

Audit of Business Continuity Planning INDIAN AFFAIRS AND NORTHERN DEVELOPMENT CANADA Audit of Business Continuity Planning Prepared by: Audit and Assurance Services Branch Project #10-12 June 2011 Table of Contents INITIALISMS AND ABBREVIATIONS...

More information

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION Emergency Preparedness at Internal Revenue Service Facilities Needs to Be Improved September 17, 2008 Reference Number: 2008-10-148 This report has cleared

More information

Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services

Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 1 Today s Agenda Structure of Today s Discussion Set Objectives General overview of DR/BCP Exercise Assumptions Scenarios

More information

Prudential Practice Guide

Prudential Practice Guide Prudential Practice Guide LPG 232 Business Continuity Management March 2007 www.apra.gov.au Australian Prudential Regulation Authority Disclaimer and copyright This prudential practice guide is not legal

More information

External Supplier Control Requirements BCM

External Supplier Control Requirements BCM External Supplier Control Requirements BCM BCM Requirement Description BCM Tiers Recovery Time Objective Why this is important 1. Business Continuity Policy Supplier will have a documented Business Continuity

More information

Business Continuity Management

Business Continuity Management Business Continuity Management Policy Statement & Strategy July 2009 Basildon District Council Business Continuity Management Policy Statement The Council is committed to ensuring robust and effective

More information

Exercising Your Enterprise Cyber Response Crisis Management Capabilities

Exercising Your Enterprise Cyber Response Crisis Management Capabilities Exercising Your Enterprise Cyber Response Crisis Management Capabilities Ray Abide, PricewaterhouseCoopers, LLP 2015 PricewaterhouseCoopers LLP, a Delaware limited liability partnership. All rights reserved.

More information

London Borough of Bromley. Executive & Resources PDS Committee. Disaster Recovery Plans for London Borough of Bromley

London Borough of Bromley. Executive & Resources PDS Committee. Disaster Recovery Plans for London Borough of Bromley Report No. DRR12/041 London Borough of Bromley PART 1 - PUBLIC Decision Maker: Executive & Resources PDS Committee Date: 4 th April 2012 Decision Type: Non-Urgent Non-Executive Non-Key Title: Disaster

More information

Mazzone & Associates, Inc.

Mazzone & Associates, Inc. Mazzone & Associates, Inc. Business Continuity Plan (BCP) Introduction. As a result of our ever-changing and evolving world, it has become necessary for firms in the financial services industry to take

More information

APPLICATION OF KING III CORPORATE GOVERNANCE PRINCIPLES 2014

APPLICATION OF KING III CORPORATE GOVERNANCE PRINCIPLES 2014 WOOLWORTHS HOLDINGS LIMITED CORPORATE GOVERNANCE PRINCIPLES 2014 CORPORATE GOVERNANCE PRINCIPLES 2014 CORPORATE GOVERNANCE PRINCIPLES 2014 This table is a useful reference to each of the King III principles

More information

Practice Guide BUSINESS CONTINUITY MANAGEMENT

Practice Guide BUSINESS CONTINUITY MANAGEMENT Practice Guide BUSINESS CONTINUITY MANAGEMENT AUGUST 2014 Table of Contents Executive Summary... 1 Introduction... 2 Internal Audit Roles and Engagements... 4 Internal Audit s Evaluation of Key BCM Elements...

More information

Version Date Comments / Changes 1.0 February 2008 Initial Policy Released 2.0 April 2013 Revised

Version Date Comments / Changes 1.0 February 2008 Initial Policy Released 2.0 April 2013 Revised Page 1 of 6 APPROVED (S) REVISED / REVIEWED SUMMARY Version Date Comments / Changes 1.0 Initial Policy Released 2.0 Revised POLICY Fraser Health is committed to providing a safe and secure environment.

More information

Cybersecurity The role of Internal Audit

Cybersecurity The role of Internal Audit Cybersecurity The role of Internal Audit Cyber risk High on the agenda Audit committees and board members are seeing cybersecurity as a top risk, underscored by recent headlines and increased government

More information

Global Statement of Business Continuity

Global Statement of Business Continuity Business Continuity Management Version 1.0-2014 Date October 18, 2014 Status Author Business Continuity Management (BCM) Page 1 of 8 Table of Contents 1. Credit Suisse Business Continuity Statement 3 2.

More information

Implementing and Auditing a Successful Business Continuity Plan

Implementing and Auditing a Successful Business Continuity Plan IIA Chicago Chapter 53 rd Annual Seminar April 15, 2013, Donald E. Stephens Convention Center @IIAChicago #IIACHI ing and Auditing a Successful Plan Agenda Introductions Training Overview and Objectives

More information

Crime Statistics Data Security Standards. Office of the Commissioner for Privacy and Data Protection

Crime Statistics Data Security Standards. Office of the Commissioner for Privacy and Data Protection Crime Statistics Data Security Standards Office of the Commissioner for Privacy and Data Protection 2015 Document details Security Classification Dissemination Limiting Marker Dissemination Instructions

More information

Subject: Internal Audit of Information Technology Disaster Recovery Plan

Subject: Internal Audit of Information Technology Disaster Recovery Plan RIVERSIDE: AUDIT & ADVISORY SERVICES June 30, 2009 To: Charles Rowley, Associate Vice Chancellor Computing & Communications Subject: Internal Audit of Information Technology Disaster Recovery Plan Ref:

More information

Integrating Pandemic Readiness into Your Organization's Resiliency Model.

Integrating Pandemic Readiness into Your Organization's Resiliency Model. Integrating Pandemic Readiness into Your Organization's Resiliency Model. David M. Sarabacha Senior Manager MBCP, MBCI, CISSP, CISA, CISM Deloitte & Touche LLP Agenda TOPIC SCHEDULE Session Overview Introduction

More information