Your Guide to Developing a Disaster Recovery Plan

Size: px
Start display at page:

Download "Your Guide to Developing a Disaster Recovery Plan"

Transcription

1 Your Guide to Developing a Disaster Recovery Plan

2 Your guide to developing a Disaster Recovery strategy In a discussion of Disaster Recovery and Business Continuity there are five factors that should be addressed in sequence. Those five areas consist of: 1. How much does a disaster really cost? 2. Business continuity and your Bank 3. The Business Impact Analysis 4. The Information Technology Plan 5. The Business Continuity Plan Part 1 How Much Does a Disaster Really Cost? Most companies have not given much thought regarding how much a potential disaster would really cost them. FNTS has a tool to help you calculate what a disaster would cost you. The following is an illustration on how it works. Assume the following: 1. You have a $100 million dollar company. 2. Your net profit margin after tax is 5.77 percent. 3. You fixed costs represent % of your Gross. 4. You have variable costs but cannot just turn them off, they must be ramped down. 5. Therefore, the total cost to the company would be 70.09% of the gross revenue. The points to consider here are that while the cost comes on gross, restoration of the revenue comes from after tax dollars. The fact is that you would lose $269, dollars per day. Additionally, it would take all of your profits from days of revenue just to break even. Gross Revenue In Millions $ $ 384, $ 1,923, Profit Loss 5.77% $ 22, $ 110, Fixed Cost 36.44% $ 140, $ 700, Variable Cost To Shutdown Total Cost To Company 27.88% $ 107, $ 536, % $ 269, $ 1,347, Days to Recover Example represents daily loss of 0.270% of gross revenue Forrester National Survey shows average of 0.380% of gross revenue Ave DR/BC plans cost approximately % to % of gross revenue 2

3 The question to ask yourself is this: Does my company have significantly cash rich resources capable of sustaining this kind of loss? If you have that much cash on hand, you don t need a Disaster Recovery / Business Continuity Plan. However, if you don t carry that much cash on hand, or you intend to finance the loss, read Part 2 and see how the financial community views the situation. Part 2 Business Continuity and Your Bank In today s rough economic times, many companies have opted to either forego development of a comprehensive Disaster Recovery Plan, or at minimum delay updating their current plan due to the desire to conserve cash. While this is an operational conservation effort to conserve cash for credit ratings, it can in fact actually hurt the credit rating or line of credit for the company. Three major changes in Federal banking enforcement can significantly affect your business. 1. FDIC Enforcement of the Individual Business Bank Credit Index Effective February 1 st, FDIC has announced that all banking institutions must comply with the guidelines that require the collective Bank Credit Index to be less than 100. Many banks have exceeded this number and it will take a stiffening of their loan portfolio to get back in line. The credit index is a business credit rating for each loan or line of credit customer based on the current financial condition. The bank index is the cumulative index of their portfolio. This effects you by a possible increase in your interest rate based on your risk. The two risks you face are a significant increase in your rating by your inability to show a plan to continue to generate revenue to pay your loan even if you did have a disaster. If a comprehensive plan is in place the bank is not required to penalize your rate. Secondly, if a plan is in place that shows how you would generate revenue, the bank can calculate your rating differently and you are not penalized by the group that does not have a plan in place unless of course you are one of the group that does not have a plan. 2. The Bank s Commercial Credit Index In order for the bank to comply, they have three alternatives to improve their own index. First, they can increase the interest rate on loans or lines of credit. This could affect you by driving your cost of money up significantly. For example, an increase of only 1% on a $50 million loan or line of credit would cost you $500 thousand dollars annually. Compare this to a plan that cost you even $100 thousand to create. Second, the bank can deny any more funding. If you feel that you will need (or might need!) additional funding or line use, denial could seriously limit or even destroy your business potential in this economy. Business that maintains a current DR Plan is more likely to receive additional funding since the Bank can justify to FDIC auditors that a plan is in place to continue to generate revenue and make the necessary bank payments. Lastly, because some banks have indexes that are so far out of balance they may be required to call the note to reduce the risk and index. Having a DR Plan in place to generate revenue would reduce the likely hood that you would be called. 3. LIBER (London InterBank Exchange Rate) Effective April 1 st, banks are required to use the LIBOR numbers to establish loan rates for each of the credit risk categories the commercial clients fall under. LIBOR is the rate that Banks charge other banks for money and is defined daily. This means that interest rates can rise immediately on any given day rather than the quarterly rate changes governed by the Prime Interest Rate which is a uniquely United States Number. Clients can no longer time the access to funds available based on projections (or reductions) of the prime rate. The question here is: Are you positioned with your financial resources, and have you made provisions to be able to continue to generate revenue to satisfy them while you recover from any kind of disaster? 3

4 Part 3 The Business Impact Analysis It is important to note that the BIA is not a planning component; rather the BIA establishes the guidelines (or road map ) for the development of the Business Continuity Plan (BCP) and related plans. The BIA is a report subject to executive management review and approval. An important component of the BIA is an evaluation, both internal and external, of the natural and manmade risks that threaten the organization. This is referred to as a Risk and Vulnerability Analysis and this analysis is included as part of the BIA. The BIA report identifies risks & exposures, reviews safety & security issues, and identifies the level of planning necessary for the Business to continue. For most businesses, critical operations are either revenue-generating operations or activities that directly support revenue-generating operations. Once critical operations, process flows and interdependencies are identified, strategies can be developed to ensure their ongoing function or rapid restoration. The BIA also reviews the level of existing planning both in the Information Technology department and throughout the other business units. Recommendations regarding additional planning or improvements to existing procedures are identified. The BIA answers the question Does your business need a comprehensive Business Continuity Plan or not? Part 4 The Information Technology Plan The Information Technology Plan (ITP) is often the only portion of the Disaster Recovery Plan that is in place. While corporate data is the asset you are protecting, remember that data that cannot be utilized or accessed is of no value in generating revenue. The ITP includes the need for planning in the following areas: Critical Data Management This is a formal plan to secure, classify and retrieve electronic information and critical applications. Data Center Recovery This is a formal plan to reconstruct systems & communication centers. Alternate Site Plan Management determines the type of Alternate Site Plan that is needed based on the established recovery time objectives, levels of service degradation and the response that is cost justified. Information Security Plan The need for additional Information Security Planning is based upon management's objectives, audit requirements, costs, and the effectiveness of existing controls. The ITP answers the question How will I recover and restore all the critical data, applications, and records that my business needs to continue in operation? Part 5 The Business Continuity Plan Generating revenue in a disaster aftermath is the entire point of the plan. As stated earlier, the ITP restores the data and applications, but the people execute making the money. How do they access the systems? Who is available? 4

5 Where do they work? Who is responsible for recovery? Where does the money go? How do we acquire materials to keep going? These are the keys to maintain the ability to generate revenue. The Business Continuity Plan (BCP) will develop the details of the response to a disaster situation by the business. This is the overarching plan for the business and defines the overall actions of the organization during an emergency. The central focus of a good BCP is to identify and develop solutions to maintain or rapidly restore critical operations. The Business Continuity Plan (BCP) is intended to establish policies, procedures and organizational structure for response to emergencies that are of sufficient magnitude to cause a significant disruption of the functioning of all or portions of the business. The BCP is the official plan of the business and describes the roles and responsibilities of support departments, operational groups and personnel during emergency situations. The BCP answers the question What will my business do to survive a disaster until we can return to normal business operations? Develop your plan today Most companies that do not have a comprehensive plan don t because they are not sure where to start. Find a methodology that will make sure questions get asked, the plan is complete, and the plan is maintainable. Disaster Management Institute (DMI) methodology is very complete and can be instituted in phases. Phasing is important since each phase is contingent on the phase ahead of it. Any disaster will create inconvenience, but a plan will make it survivable. The federal government reports that 80% of the businesses that face a two or more day disaster are out of business within 24 months. Don t let this happen to you. For information regarding disaster recovery or to develop your own plan contact or info@fnts.com 5

Business Continuity Planning 101. +1 610 768-4120 (800) 634-2016 www.strohlsystems.com info@strohlsystems.com

Business Continuity Planning 101. +1 610 768-4120 (800) 634-2016 www.strohlsystems.com info@strohlsystems.com Business Continuity Planning 101 Presentation Overview What is business continuity planning Plan Development Plan Testing Plan Maintenance Future advancements in BCP Question & Answer What is a Disaster?

More information

Disaster Recovery and Business Continuity Plan

Disaster Recovery and Business Continuity Plan Disaster Recovery and Business Continuity Plan Table of Contents 1. Introduction... 3 2. Objectives... 3 3. Risks... 3 4. Steps of Disaster Recovery Plan formulation... 3 5. Audit Procedure.... 5 Appendix

More information

Risk-Based Assessment and Scoping of IV&V Work Related to Information Assurance Presented by Joelle Spagnuolo-Loretta, Richard Brockway, John C.

Risk-Based Assessment and Scoping of IV&V Work Related to Information Assurance Presented by Joelle Spagnuolo-Loretta, Richard Brockway, John C. Risk-Based Assessment and Scoping of IV&V Work Related to Information Assurance Presented by Joelle Spagnuolo-Loretta, Richard Brockway, John C. Burget September 14, 2014 1 Agenda Information Assurance

More information

POLICY. 1) Business Continuity Management 2) Disaster Recovery 3) Critical Incident Management 4) Risk Management

POLICY. 1) Business Continuity Management 2) Disaster Recovery 3) Critical Incident Management 4) Risk Management POLICY Policy Title: Management Descriptors: 1) Management 2) Disaster Recovery 3) Critical Incident Management 4) Risk Management Category: Risk Management Intent Organisational Scope Definitions Policy

More information

Unit Guide to Business Continuity/Resumption Planning

Unit Guide to Business Continuity/Resumption Planning Unit Guide to Business Continuity/Resumption Planning (February 2009) Revised June 2011 Executive Summary... 3 Purpose and Scope for a Unit Business Continuity Plan(BCP)... 3 Resumption Planning... 4 Assumptions

More information

SCADA Business Continuity and Disaster Recovery. Presented By: William Biehl, P.E. 913-601-0104 (mobile) Bill.Biehl@we-inc.com

SCADA Business Continuity and Disaster Recovery. Presented By: William Biehl, P.E. 913-601-0104 (mobile) Bill.Biehl@we-inc.com SCADA Business Continuity and Disaster Recovery Presented By: William Biehl, P.E. 913-601-0104 (mobile) Bill.Biehl@we-inc.com Business Continuity Planning, a Sound Process A Business Continuity Plan: "A

More information

Overview of how to test a. Business Continuity Plan

Overview of how to test a. Business Continuity Plan Overview of how to test a Business Continuity Plan Prepared by: Thomas Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com BRP/DRP Test Plan Creation and Exercise Page: 1 Table of Contents BCP/DRP Test

More information

Best Practices for Protecting Your IBM FileNet P8 Information

Best Practices for Protecting Your IBM FileNet P8 Information Best Practices for Protecting Your IBM FileNet P8 Information Introduction There are dozens of articles and white papers outlining the most critical steps organizations can take to minimize the risk of

More information

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA 1 Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand

More information

Prudential Practice Guide

Prudential Practice Guide Prudential Practice Guide SPG 232 Business Continuity Management July 2013 www.apra.gov.au Australian Prudential Regulation Authority Disclaimer and copyright This prudential practice guide is not legal

More information

Business Income Insurance Policy: End the Confusion

Business Income Insurance Policy: End the Confusion 1740H Dell Range Blvd., #300 I Cheyenne, Wyoming 82009 PHONE: 307.433.8180 I FAX: 307.634.9497 EMAIL: info@bisimplified.com www.bisimplified.com ARTICLES: THE 411 Business Income Insurance Policy: End

More information

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015 Business Continuity Management Governance Frank Higgins Abu Dhabi March 2015 Different Names Same Concept BCM (Business Continuity Management) BSI 25999 IPOCM (Incident Preparedness & Operational Continuity

More information

THE INSURANCE POLICY: SIMPLIFIED!

THE INSURANCE POLICY: SIMPLIFIED! THE INSURANCE POLICY: SIMPLIFIED! INSURANCE CONTRACT: COMMERCIAL PROPERTY AND BUSINESS INCOME The insurance policy is a contract and as such, is governed by its conditions, provisions, and exclusions.

More information

PAPER-6 PART-5 OF 5 CA A.RAFEQ, FCA

PAPER-6 PART-5 OF 5 CA A.RAFEQ, FCA Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-5 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand

More information

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO 22301 AUDITS, CERTIFICATION AND TRAINING

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO 22301 AUDITS, CERTIFICATION AND TRAINING HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO 22301 AUDITS, CERTIFICATION AND TRAINING ISO 22301 BUSINESS CONTINUITY MANAGEMENT SYSTEMS Most organisations will, at some point, be faced with having to respond

More information

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1 AUDITING A BCP PLAN Thomas Bronack Auditing a BCP Plan presentation Page: 1 What are the Objectives of a Good BCP Plan Protect employees Restore critical business processes or functions to minimize the

More information

Business Continuity & Disaster Recovery

Business Continuity & Disaster Recovery Business Continuity & Disaster Recovery Safety First Quality Every Time 1 Business Continuity & Disaster Recovery Planning Who here has a formal Business Continuity & Disaster Recovery plan? The purpose

More information

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD. Business Continuity Management & Disaster Recovery Planning Presented by: Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD. 1 What is Business Continuity Management? Is a holistic management

More information

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com Fax: (718) 380-7322

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com Fax: (718) 380-7322 Business Continuity and Disaster Recovery Job Descriptions Table of Contents Business Continuity Services Organization Chart... 2 Director Business Continuity Services Group... 3 Manager of Business Recovery

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning 4 Business Continuity Planning and Disaster Recovery Planning Basic Concepts 1. Business Continuity Management: Business Continuity means maintaining the uninterrupted availability of all key business

More information

OC Chapter. Vendor Risk Management. Cover the basics of a good VRM program, standards, frameworks, pitfall and best outcomes.

OC Chapter. Vendor Risk Management. Cover the basics of a good VRM program, standards, frameworks, pitfall and best outcomes. OC Chapter Vendor Risk Management. Cover the basics of a good VRM program, standards, frameworks, pitfall and best outcomes. 2 Why Assess a Vendor? You don t want to be a Target for hackers via your vendors

More information

Business Continuity Planning Instructions

Business Continuity Planning Instructions Business Continuity Planning Instructions Business continuity planning is a proactive planning process that ensures critical services or products are delivered during a disruption. In creating the plan,

More information

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning The world has experienced a great deal of natural and man-made upheaval and destruction in the past few years, including tornadoes,

More information

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1 University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems. 1 Michigan Administrative Information Services (MAIS) MAIS is responsible for the production support of

More information

Business Continuity Planning

Business Continuity Planning Business Continuity Planning We believe all organisations recognise the importance of having a Business Continuity Plan, however we understand that it can be difficult to know where to start. That s why

More information

Desktop Scenario Self Assessment Exercise Page 1

Desktop Scenario Self Assessment Exercise Page 1 Page 1 Neil Jarvis Head of IT Security & IT Risk DHL Page 2 From reputation to data loss - how important is business continuity? Neil Jarvis Head of IT Security (EMEA) DHL Logistics IT Security Taking

More information

GLASGOW LIFE Review of Business Continuity Planning. Final Report

GLASGOW LIFE Review of Business Continuity Planning. Final Report Final Report INTERNAL AUDIT September 2011 Glasgow City Council Internal Audit 1 Table of Contents Section No Section Title 1 Introduction and Background 2 Audit Remit 3 Audit Opinion 4 Conclusions 5 Recommendations

More information

PARKES SHIRE COUNCIL BUSINESS CONTINUITY POLICY

PARKES SHIRE COUNCIL BUSINESS CONTINUITY POLICY PARKES SHIRE COUNCIL BUSINESS CONTINUITY POLICY PARKES SHIRE COUNCIL BUSINESS CONTINUITY POLICY CONTENTS INTRODUCTION... 1 PURPOSE... 1 POLICY... 1 DEFINITIONS... 1 RESPONSIBILITY... 1 RELATED DOCUMENTATION...

More information

Introduction to Business Continuity Planning

Introduction to Business Continuity Planning Introduction to Business Continuity Planning Business Continuity Management Ensure continuity and survival of our organization in the event of an emergency event: Essential elements: Risk identification

More information

Prudential Practice Guide

Prudential Practice Guide Prudential Practice Guide LPG 232 Business Continuity Management March 2007 www.apra.gov.au Australian Prudential Regulation Authority Disclaimer and copyright This prudential practice guide is not legal

More information

CIS 523/423 Disaster Recovery Business Continuity

CIS 523/423 Disaster Recovery Business Continuity CIS 523/423 Disaster Recovery Business Continuity Course Description A study of disaster recovery and business continuity as related to the information technology function in organizations. Topics will

More information

Business Continuity Business Continuity Management Policy

Business Continuity Business Continuity Management Policy Business Continuity Business Continuity Management Policy : Date of Issue: 28 January 2009 Version no: 1.1 Review Date: January 2010 Document Owner: Patricia Hughes Document Authoriser: Tony Curtis 1 Version

More information

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006 Department of Information Technology Data Center Disaster Recovery Audit Report Final Report September 2006 promoting efficient & effective local government Executive Summary Our audit found that a comprehensive

More information

Contingency Planning and Disaster Recovery Internal Control Questionnaire

Contingency Planning and Disaster Recovery Internal Control Questionnaire Contingency Planning and Disaster Recovery Internal Control Questionnaire [Institution s name] [Departments under review] [Heads of departments under review] A. POLICY AND SUPERVISION REVIEW 1. Was the

More information

Business Continuity and Disaster Recovery Policy

Business Continuity and Disaster Recovery Policy Maine State Government Dept. of Administrative & Financial Services Office of Information Technology (OIT) Business Continuity and Disaster Recovery Policy I. Statement The Office of Information Technology

More information

Implementing and Auditing a Successful Business Continuity Plan

Implementing and Auditing a Successful Business Continuity Plan IIA Chicago Chapter 53 rd Annual Seminar April 15, 2013, Donald E. Stephens Convention Center @IIAChicago #IIACHI ing and Auditing a Successful Plan Agenda Introductions Training Overview and Objectives

More information

Preparing for the Worst: Disaster Recovery and Business Continuity Planning for Investment Firms An Eze Castle Integration ebook

Preparing for the Worst: Disaster Recovery and Business Continuity Planning for Investment Firms An Eze Castle Integration ebook Preparing for the Worst: Disaster Recovery and Business Continuity Planning for Investment Firms An Eze Castle Integration ebook Table of Contents 1. Introduction to Business Continuity Planning and Disaster

More information

Moving forward in a difficult time

Moving forward in a difficult time Moving forward in a difficult time Purpose The purpose of recovery planning is to anticipate, to the maximum extent possible, what will be needed to restore the community to full functioning as rapidly

More information

Developing a Business Continuity Plan... More Than Disaster

Developing a Business Continuity Plan... More Than Disaster Developing a Business Continuity Plan..... More Than Disaster Recovery! April 19, 2010 UHY / MMA Business Survival Series Webinar Focus.... Understanding the components of Business Continuity Planning

More information

Business Continuity Overview

Business Continuity Overview Business Continuity Overview Beverley A. Retjos Senior Manager WW SWG Security & Controls 03/12/07 Business Continuity Management (BCM) Process of ensuring that a business is prepared to survive any disruption

More information

Interest Rate Swap. Product Disclosure Statement

Interest Rate Swap. Product Disclosure Statement Interest Rate Swap Product Disclosure Statement A Product Disclosure Statement is an informative document. The purpose of a Product Disclosure Statement is to provide you with enough information to allow

More information

Chapter 4 Information Security Program Development

Chapter 4 Information Security Program Development Chapter 4 Information Security Program Development Introduction Formal adherence to detailed security standards for electronic information processing systems is necessary for industry and government survival.

More information

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic

More information

CRISC Glossary. Scope Note: Risk: Can also refer to the verification of the correctness of a piece of data

CRISC Glossary. Scope Note: Risk: Can also refer to the verification of the correctness of a piece of data CRISC Glossary Term Access control Access rights Application controls Asset Authentication The processes, rules and deployment mechanisms that control access to information systems, resources and physical

More information

MIAMI UNIVERSITY Internal Audit & Consulting Services Risk Discussion Questionnaire GENERAL INFORMATION

MIAMI UNIVERSITY Internal Audit & Consulting Services Risk Discussion Questionnaire GENERAL INFORMATION MIAMI UNIVERSITY Internal Audit & Consulting Services Risk Discussion Questionnaire Department or Process: Contact Person: Contact Phone: Date Completed: GENERAL INFORMATION 1. What is the Purpose/Mission/Objective

More information

Beyond Disaster Recovery: Why Your Backup Plan Won t Work

Beyond Disaster Recovery: Why Your Backup Plan Won t Work Beyond Disaster Recovery: Why Your Backup Plan Won t Work Contents Introduction... 3 The Data Backup Model - Upgraded for 2015... 4 Why Disaster Recovery Isn t Enough... 5 Business Consequences with DR-Only

More information

Version: 3.0. Effective From: 19/06/2014

Version: 3.0. Effective From: 19/06/2014 Policy No: RM66 Version: 3.0 Name of Policy: Business Continuity Planning Policy Effective From: 19/06/2014 Date Ratified 05/06/2014 Ratified Business Service Development Committee Review Date 01/06/2016

More information

Business Continuity Plan

Business Continuity Plan Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions

More information

Application / Hardware - Business Impact Analysis Template. MARC Configuration Requirements. Business Impact Analysis

Application / Hardware - Business Impact Analysis Template. MARC Configuration Requirements. Business Impact Analysis Application / Hardware - Business Impact Analysis Template The single most important thing we can do is help you understand the criticality of each application, supporting hardware/server/pc and the required

More information

Coping with a major business disruption. Some practical advice

Coping with a major business disruption. Some practical advice Coping with a major business disruption Some practical advice Coping with a major business disruption What is business continuity? Business continuity planning (BCP) is a management process that helps

More information

Information Services IT Security Policies B. Business continuity management and planning

Information Services IT Security Policies B. Business continuity management and planning Information Services IT Security Policies B. Business continuity management and planning Version 1 Date created: 28th May 2009 Approved by Directorate: 2nd July 2009 Review date: 1st July 2010 Primary

More information

This is the third and final presentation on HIPAA Security Administrative Safeguards. This presentation focuses on the last 2 standards under the

This is the third and final presentation on HIPAA Security Administrative Safeguards. This presentation focuses on the last 2 standards under the This is the third and final presentation on HIPAA Security Administrative Safeguards. This presentation focuses on the last 2 standards under the HIPAA Security rule: Contingency planning and evaluation.

More information

Documentation. Disclaimer

Documentation. Disclaimer HOME UTORprotect DOCUMENTATION AMS/ROSI SERVICES CONTACT Documentation Disaster Recovery Planning Disaster Recovery Planning Disclaimer The following project outline is provided solely as a guide. It is

More information

Checklist For Business Recovery

Checklist For Business Recovery Checklist For Business Recovery Completed By: Name: Company: Room: Street: City, State, Zip: Phone #: Business Recovery Plan for: Business Recovery Plan (BRP)--LEVEL 1 (Executive Awareness/Authority) 1.

More information

WHY DO I NEED DATA PROTECTION SERVICES?

WHY DO I NEED DATA PROTECTION SERVICES? WHY DO I NEED DATA PROTECTION SERVICES? Data processing operations have evolved with breathtaking speed over the past few years, expanding from very large mainframe operations to small business networks.

More information

Disaster Recovery Planning Process

Disaster Recovery Planning Process Disaster Recovery Planning Process By Geoffrey H. Wold Part I of III This is the first of a three-part series that describes the planning process related to disaster recovery. Based on the various considerations

More information

Business Continuity Planning. Presentation and. Direction

Business Continuity Planning. Presentation and. Direction Business Continuity Planning Presentation and Direction Thomas Bronack, president Data Center Assistance Group, Inc. 15180 20 th Avenue Whitestone, NY 11357 Phone: (718) 591-5553 Email: bronackt@dcag.com

More information

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES APPENDIX 1 DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES March 2008 Auditor General s Office Jeffrey Griffiths, C.A., C.F.E. Auditor General City of Toronto TABLE OF CONTENTS EXECUTIVE SUMMARY...1

More information

Business Continuity Planning in IT

Business Continuity Planning in IT Introduction: Business Continuity Planning in IT The more your business relies on its IT systems, the more you need to consider how unexpected disruptions might affect your business. These disruptions

More information

Why. Your business. Needs. a Disaster RecoveryPlan. www.iconz-webvisions.com

Why. Your business. Needs. a Disaster RecoveryPlan. www.iconz-webvisions.com Why Your business Needs a Disaster RecoveryPlan 1 Disaster recovery is something that every business must plan for, but not many think about. A Disaster Preparedness Survey among 900 SMEs in the Asia-Pacific

More information

ISACA North Dallas Chapter

ISACA North Dallas Chapter ISACA rth Dallas Chapter Business Continuity Planning Observations of Critical Infrastructure Environments Ron Blume, P.E. Ron.blume@dyonyx.com 214-280-8925 Focus of Discussion Business Impact Analysis

More information

Subject: Internal Audit of Information Technology Disaster Recovery Plan

Subject: Internal Audit of Information Technology Disaster Recovery Plan RIVERSIDE: AUDIT & ADVISORY SERVICES June 30, 2009 To: Charles Rowley, Associate Vice Chancellor Computing & Communications Subject: Internal Audit of Information Technology Disaster Recovery Plan Ref:

More information

The following Accounting Standards Interpretation (ASI) relates to AS 7. ASI 29 Turnover in case of Contractors

The following Accounting Standards Interpretation (ASI) relates to AS 7. ASI 29 Turnover in case of Contractors 108 Accounting Standard (AS) 7 (revised 2002) Construction Contracts Contents OBJECTIVE SCOPE Paragraph 1 DEFINITIONS 2-5 COMBINING AND SEGMENTING CONSTRUCTION CONTRACTS 6-9 CONTRACT REVENUE 10-14 CONTRACT

More information

Building a Continuity Culture

Building a Continuity Culture Building a Continuity Culture A survey of Canadian decision makers on Business Continuity Planning KPMG LLP Building a Continuity Culture 1 Building a Continuity Culture A survey of Canadian decision

More information

Aligning Disaster Recovery and Business Continuity to Business Objectives. Session E7 John Jackson Fusion Risk Management, Inc.

Aligning Disaster Recovery and Business Continuity to Business Objectives. Session E7 John Jackson Fusion Risk Management, Inc. Aligning Disaster Recovery and Business Continuity to Business Objectives Session E7 John Jackson Fusion Risk Management, Inc. Topics Business Drivers Resilience Defined Your RPO is zero (or close to it!)

More information

BUSINESS CONTINUITY STRATEGY 2014-2017

BUSINESS CONTINUITY STRATEGY 2014-2017 BUSINESS CONTINUITY STRATEGY 2014-2017 This strategy covers the period 01 April 2014 31 March 2017 and was approved by the Major Incident Working Group 19.03.2014 Caroline Rushmer Major Incident and Business

More information

Business Continuity and Disaster Recovery Planning

Business Continuity and Disaster Recovery Planning Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services

More information

Management of IT Risks

Management of IT Risks 10 number 39 // 2-2006 Management of IT Risks Esther Cerdeño Deputy Director of IT MAPFRE REASEGUROS (Spain) The market needs insurers to study the feasibility of insuring costs relating to loss of information;

More information

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14

More information

OUTSOURCING GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS, 2008

OUTSOURCING GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS, 2008 OUTSOURCING GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS, 2008 BANK OF TANZANIA PART I PRELIMINARY 1 These guidelines may be cited as the Outsourcing Guidelines for Banks and Financial Institutions,

More information

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four Data Handling in University Business Impact Analysis ( BIA ) Agenda Overview Terminologies Performing

More information

Prevent Denial of Service Attacks with Availability Consulting

Prevent Denial of Service Attacks with Availability Consulting A Guidance Consulting White Paper P.O. Box 3322 Suwanee GA, 30024 678-528-2681 http://www.guidance-consulting.com Prevent Denial of Service Attacks with Availability Consulting By Guidance Consulting,

More information

Vital Records. Mary Hilliard, CRM

Vital Records. Mary Hilliard, CRM Vital Records Mary Hilliard, CRM Background Vital records of an organization must be identified so they can be protected Protection of vital records is a joint effort of records management and disaster

More information

Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM

Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM Business Continuity Planning and Disaster Recovery Planning Ed Crowley IAM/IEM 1 Goals Compare and contrast aspects of business continuity Execute disaster recovery plans and procedures 2 Topics Business

More information

Disaster Recovery and Business Continuity with E-Commerce Businesses

Disaster Recovery and Business Continuity with E-Commerce Businesses Disaster Recovery and Business Continuity with E-Commerce Businesses Eric Palmer IS 8300 Disaster Recovery/Business Continuity Planning Summer 2012 Abstract: Disaster Recovery and Business Continuity Planning

More information

Business Continuity Planning

Business Continuity Planning Business Continuity Planning CSH5 Chapter 58 Business Continuity Planning Michael Miora Justifying Costs of BCP 1 Copyright 2014 M. E. Kabay. All rights reserved. 2 Copyright 2014 M. E. Kabay. All rights

More information

Business Continuity Planning FAQ

Business Continuity Planning FAQ Case Western Reserve University s mission is to improve and enrich people s lives through research that capitalizes on the power of collaboration, and education that dramatically engages our students.

More information

International Accounting Standard 11 Construction Contracts

International Accounting Standard 11 Construction Contracts International Accounting Standard 11 Construction Contracts Objective The objective of this Standard is to prescribe the accounting treatment of revenue and costs associated with construction contracts.

More information

Sri Lanka Accounting Standard -LKAS 11. Construction Contracts

Sri Lanka Accounting Standard -LKAS 11. Construction Contracts Sri Lanka Accounting Standard -LKAS 11 Construction Contracts -405- Sri Lanka Accounting Standard -LKAS 11 Construction Contracts Sri Lanka Accounting Standard LKAS 11 Construction Contracts is set out

More information

Yale University Business Continuity Planning (BCP) Quick Start Guide

Yale University Business Continuity Planning (BCP) Quick Start Guide Yale University Business Continuity Planning (BCP) Quick Start Guide Introduction Yale University s mission is to create, preserve and disseminate knowledge. Each college, division, and major administrative

More information

PART 10 COMPUTER SYSTEMS

PART 10 COMPUTER SYSTEMS PART 10 COMPUTER SYSTEMS 10-1 PART 10 COMPUTER SYSTEMS The following is a general outline of steps to follow when contemplating the purchase of data processing hardware and/or software. The State Board

More information

B U S I N E S S C O N T I N U I T Y P L A N

B U S I N E S S C O N T I N U I T Y P L A N B U S I N E S S C O N T I N U I T Y P L A N 1 Last Review / Update: December 9, 2015 Table of Contents Purpose...3 Background...3 Books and Records Back-up and Recovery...4 Mission Critical Systems...

More information

Guideline for the Measurement, Monitoring and Control of Impaired Assets

Guideline for the Measurement, Monitoring and Control of Impaired Assets Guideline for the Measurement, Monitoring and Control of Impaired Assets FINAL TABLE OF CONTENTS 1 INTRODUCTION... 1 2 PURPOSE... 1 3 INTERPRETATION... 2 4 IMPAIRMENT RECOGNITION AND MEASUREMENT POLICY...

More information

Corporate Emergency Access System: The essential tool in times of crisis and emergency.

Corporate Emergency Access System: The essential tool in times of crisis and emergency. City of Philadelphia Managing Director s Office of Emergency Management Corporate Emergency Access System: The essential tool in times of crisis and emergency. Table of Contents Putting the CEAS Program

More information

Report to the Audit Committee

Report to the Audit Committee Report to the Audit Committee Agenda of: JANUARY 14, 2014 From: Rahoof Wally Oyewole, Departmental Audit Manager ITEM: V SUBJECT: INTERNAL AUDIT WORKPLAN THROUGH FISCAL YEAR 2014-15 AND POSSIBLE COMMITTEE

More information

1. Computer Security: An Introduction. Definitions Security threats and analysis Types of security controls Security services

1. Computer Security: An Introduction. Definitions Security threats and analysis Types of security controls Security services 1. Computer Security: An Introduction Definitions Security threats and analysis Types of security controls Security services Mar 2012 ICS413 network security 1 1.1 Definitions A computer security system

More information

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 AGENDA: Emergency Management Business Continuity Planning Q & A MONTH DAY, YEAR TITLE OF THE PRESENTATION 2 CANADIAN RED CROSS Disaster

More information

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745 ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan

More information

NEPAL ACCOUNTING STANDARDS ON CONSTRUCTION CONTRACTS

NEPAL ACCOUNTING STANDARDS ON CONSTRUCTION CONTRACTS NAS 13 NEPAL ACCOUNTING STANDARDS ON CONSTRUCTION CONTRACTS CONTENTS Paragraphs OBJECTIVE SCOPE 1 2 DEFINITIONS 3 6 COMBINING AND SEGMENTING CONSTRUCTION CONTRACTS 7 10 CONTRACT REVENUE 11 15 CONTRACT

More information

Fundamentals of Business Continuity Planning Have a Plan!

Fundamentals of Business Continuity Planning Have a Plan! Fundamentals of Business Continuity Planning Have a Plan! Michael Kadar, MBCP, CISSP 2008 MK Continuity & Availability LLC kadarsro@talkamerica.net InfraGard Meeting Walsh College, Novi March 25, 2008

More information

BUSINESS CONTINUITY PLANNING GUIDELINES

BUSINESS CONTINUITY PLANNING GUIDELINES BUSINESS CONTINUITY PLANNING GUIDELINES Washington University in St. Louis The purpose of this guide is to serve as a tool to all departments, divisions, and labs across the University in building a Business

More information

William Rider Manager Disaster Recovery & Data Security The Johns Hopkins Health System & University

William Rider Manager Disaster Recovery & Data Security The Johns Hopkins Health System & University William Rider Manager Disaster Recovery & Data Security The Johns Hopkins Health System & University Competitive Leadership- Twelve Principles For Success Brian Billick Chapter 3 Be Be Prepared The time

More information

BUSINESS CONTINUITY PLANNING. Business Continuity Management Plan. Version 1.4

BUSINESS CONTINUITY PLANNING. Business Continuity Management Plan. Version 1.4 BUSINESS CONTINUITY PLANNING Business Continuity Management Plan Version 1.4 October 2015 Table of Contents 1 OVERVIEW... 5 2 STRUCTURE OF THE DOCUMENT... 5 3 OBJECTIVE... 6 4 SCOPE... 6 4.1 EXECUTIVE

More information

H.R. 1283 CONGRESSIONAL BUDGET OFFICE COST ESTIMATE. Asbestos Compensation Act of 2000. July 13, 2000

H.R. 1283 CONGRESSIONAL BUDGET OFFICE COST ESTIMATE. Asbestos Compensation Act of 2000. July 13, 2000 CONGRESSIONAL BUDGET OFFICE COST ESTIMATE July 13, 2000 H.R. 1283 Asbestos Compensation Act of 2000 As ordered reported by the House Committee on the Judiciary on March 16, 2000 SUMMARY H.R. 1283 would

More information

Louisiana Small Business Development Center

Louisiana Small Business Development Center Ready for Anything Plan to Stay in Business Louisiana Small Business Development Center Southeastern Louisiana University Ready for Anything Plan to Stay in Business How Long Can You Tread Water? Presented

More information

Business Continuity Business Impact Analysis arrangements

Business Continuity Business Impact Analysis arrangements Aberdeen City Council Internal Audit Report 2012/2013 for Aberdeen City Council May 2013 Business Continuity Business Impact Analysis arrangements Final Report Contents Section Page 1. Executive Summary

More information

Business continuity plan

Business continuity plan Business continuity plan CONTENTS INTRODUCTION 2 - Scope - Components BUSINESS IMPACT ANALYSIS 3 - Business Affairs - Information Technology RISK ASSESSMENT 5 - Broad Categories of Hazards - Hazard Table

More information

Guideline - Business Continuity Plan

Guideline - Business Continuity Plan Guideline - Business Continuity Plan 1. Introduction: The Business Continuity Plan is a component of the Risk and Business Management suite. This suite includes: Risk Management including risk registers

More information

CONSUMER ELECTRONIC FUNDS TRANSFER AND DEBIT CARD AGREEMENT

CONSUMER ELECTRONIC FUNDS TRANSFER AND DEBIT CARD AGREEMENT We, us and our refer to. CONSUMER ELECTRONIC FUNDS TRANSFER AND DEBIT CARD AGREEMENT You and your apply to any individual who has an Account with us and is authorized to initiate the applicable EFTs. Account

More information

BUSINESS CONTINUITY PLANNING AT THE NATIONAL GALLERY OF AUSTRALIA. Erica Persak

BUSINESS CONTINUITY PLANNING AT THE NATIONAL GALLERY OF AUSTRALIA. Erica Persak BUSINESS CONTINUITY PLANNING AT THE NATIONAL GALLERY OF AUSTRALIA Erica Persak Thank you for giving me the opportunity to speak on behalf of the National Gallery on the subject of business continuity planning

More information