Agenda. Creating a Robust Testing Program. Notification Tests. Overview of Testing. Beverly Schulz, CBCP

Size: px
Start display at page:

Download "Agenda. Creating a Robust Testing Program. Notification Tests. Overview of Testing. Beverly Schulz, CBCP"

Transcription

1 Agenda Overview of Testing Notification Tests Tabletop or Walk-through Tests Simulations Technology Outage Tests Third Party Outage Tests Workplace Outage Tests Workforce Outage Tests Reporting Creating a Robust Testing Program Beverly Schulz, CBCP Notification Tests Preparation, Execution, and Follow-up: Alert team to upcoming exercise* Develop script for notification calls*; set up in automated notification tool Conduct exercise and record Follow up on any incorrect contact information Set goals / objectives (i.e. 75% respond within a certain number of hours) and increase those over time Include just area recovery team contacts, or expand to cover all employees in the area Group by geography, contacting all employees in a city/state/region Group by area to allow ease in reporting Decrease the time allowed for response if multiple modalities are used % of participants responding Overview of Testing Purpose of Testing is to: Answer the question: Can the recover? Reinforce training of recovery team members Test the performance of the recovered systems, people, etc. Expose issues which may prevent recovery Get participants excited about fixing issues Demonstrate improvement year after year Test Types: Notification - A test of the phone numbers within a continuity plan Tabletop or Walk-through Exercises - A test of the continuity plan where participants discuss their response to a simulated disaster scenario Simulation Exercises - A test of IT,, and/or vendor recovery strategies, where participants perform recovery activities * - see Appendix

2 Simulation Tests Types of Simulation Tests: Loss of technology or telephony Loss of critical vendor Loss of workplace Loss of workforce or key resource Test the workplace unavailable scenario for all areas within a building at the same time Ensure the duration allows problems to surface Test a variety of scenarios, not just workplace outage Measure success based on the percentage of functions or applications recovered within their Recovery Time Objective Tabletop Tests Preparation, Execution, and Follow-up: Read the plan! Write a scenario that will test weaknesses within the plan Use scenario injects (i.e. monkey wrenches)* Include multiple, inter-dependent groups with differing RTOs Conduct executive level exercises Conduct surprise exercises Measure success based on percentage of answers known Measure success based on improvement opportunities identified * - see Appendix Disaster Recovery Tests, continued Business function / process validation Customer Purchase #1 #3 #2 #4 #5 Customer Statement Simulation Loss of Technology a.k.a. Disaster Recovery Tests Business function / process validation performance statistics Crisis Management involvement Third Party participation Measurements of success Schedule notification and tabletop exercises right before the Disaster Recovery exercise Conduct tests for each major data center Gradually increase scope so that more than most critical applications tested

3 Disaster Recovery Tests, continued Setting Success Rate Targets Use exercise sponsor or BC Committee to set target success rates Revisit targets on a regular basis (raise the bar) Example Measurements of Success for IT % of s meeting Recovery Time Objectives % of s recovered before end of exercise (even if late) % of s meeting Recovery Point Objectives Measurements of Success for the Business % of Functions meeting Recovery Time Objectives Impact Rating* - Allow to rate their own success using a pre-defined impact scale Disaster Recovery Tests, continued Volume/ Utilization Metric performance statistics (T) Production (T) Test Comparison No impact to better than expected Low impact to Moderate impact to High impact to Very high impact to * - see Appendix Simulation Loss of Workplace Allow real events to count as test credit Scope should align to plans, i.e. if plans are built by building, then tests should be by building Measure success based on the percentage of the area s people testing the strategy Measure success based on the percentage of the functions recovered within Recovery Time Objectives Simulation Loss of Third Party Test the ability of the to respond to the loss of the third party, OR test the third party s ability to recover from their own disaster, OR both! Start with a simple ping test or a tabletop test Expand over time involve login to vendor systems during their DR tests, file exchanges, etc. Measure success based on the percentage of Third Party applications meeting Recovery Time and Recovery Point objectives Measure success based on the percentage of Third Party functions meeting Recovery Time Objective Give extra credit for participation in third party s test

4 Reporting Identify issues resulting from test, assignments for resolutions, and target completion dates Include the following within the post test report: Scenario summary Objectives Results Lessons learned and recommendations for future tests Issues tracking and summary Simulation Loss of Workforce Allow real events to count as test credit Ensure the scope of the test allows problems to surface (ex. require a minimum of 25% workforce loss) Measure success based on the percentage of the area s people testing the strategy Measure success based on the percentage of the functions recovered within Recovery Time Objectives Develop a process to track actions to confirm closure Include of testing in Business Continuity metrics Questions? Reporting, cont d Consider developing metrics for Executive Management to show their ability to recover, based on testing : BC Issues from Testing and Events All issues documented appropriately including level of risk and actively remediated and updated Reflects mixed between 1 and a 3 Issues not registered or not being actively remediated Reflects mixed between 3 and a 5 Issues not registered and not being actively remediated Notification Testing % response rate 94-85% response rate 84-75% response rate 74-50% response rate <50% response rate Workforce Strategy Testing 100% of Mission Critical plans and >75% of remaining plans scored 2 or % of plans scored 2 or % of plans scored 2 or 1 or insufficient testing has occurred (i.e. risk is unknown) 50-25% of plans scored 2 or 1 <25% of plans scored 2 or 1 Workplace Strategy Testing 100% of Mission Critical plans and >75% of remaining plans scored 2 or % of plans scored 2 or % of plans scored 2 or 1 or insufficient testing has occurred (i.e. risk is unknown) 50-25% of plans scored 2 or 1 <25% of plans scored 2 or 1 Third Party Strategy Testing 100% of Mission Critical Third Parties met recovery time and recovery point and >75% of remaining third parties met recovery time and recovery point 99-75% of Third Parties met recovery time and recovery point 74-51% of plans scored 2 or higher or insufficient testing has occurred (i.e. risk is unknown) 50-25% of Third Parties met recovery time and recovery point <25% of Third Parties met recovery time and recovery point Disaster Recovery Testing 100% of plans with needs 99-90% of plans with met by app DR exercise needs met by app DR exercise 89-80% of plans with 79-70% of plans with needs met by app DR exercise needs met by app DR exercise <69% of plans with needs met by app DR exercise

5 Appendix 1 Notification Alert Sample text to use when alerting a group about an upcoming notification exercise: Subject: Notification Exercise Required Annually Per Business Continuity Standards, we are required to perform a Notification Exercise annually. This is performed without advance notice to test the accuracy of contact information, as well as the accessibility of the Recovery Team Members. We will be conducting this exercise before [month/day]. The attached Business Continuity Plan has all of the required information for a successful exercise. During which, you will be contacted via phone and . The automated system will call all phone numbers you have currently listed in the HR system (main, work, work cell, personal cell, home, etc.) in an effort to reach you. Note: when responding to the phone notification, please wait to hear that your response has been accepted before hanging up otherwise your response will not be registered. These contacts will continue several times within a 2 hour timeframe until contact is made and response has been received by the participant. For more information beverly.schulz@capitalone.com Various internet sites: Please let me know if you have any questions or if you would like additional information about the Notification Exercise. Appendix 3 - Tabletop Tests Scenarios and Injects Natural Disasters and Accidents: Main Scenario Inject Earthquake, Roof collapse hurricane, flood, Area roads blocked and local / state travel restrictions are being enforced blizzard, or IT is wondering how many computers you will need and what applications tornado you will need loaded on them. They are also inquiring as to any other equipment (fax, printer, copier, phones) you will need. Please respond. Fire Determined to be arson Mold grows due to water used in fire suppression, causing health issues for half of the employees so far. Which functions can be delayed and which can be transferred? Sink hole or Area roads blocked and local / state travel restrictions are being enforced impassable facility access Plane crash or mass transit accident Multiple executives on board The designated area decision maker was injured. Who is next in command? Appendix 2 Notification Template Sample text to use when conducting a notification exercise: This is the Business Continuity Management team, conducting your annual Notification Exercise in partnership with your [insert name] area. This mandatory exercise is required for all areas per Business Continuity Policy. In order for this exercise to be successful, please acknowledge receipt of this notification by entering 1 on your phone or in the body of the . Thank You.

6 Appendix 4 Impact Rating Samples What was the impact to CUSTOMERS? No impact = we do not work with customers Low Impact = minimal inconvenience to customers Moderate impact = inconvenienced and irate customers High impact = dissatisfied customers, escalating high % of complaints to managers Very high impact = customers are closing accounts at an unacceptable rate What REGULATORY impacts may have been caused? No impact Low impact = minor, isolated compliance issues Moderate impact = Regulators require issue resolution High impact = Regulators publicly warn company Very high impact = Regulators take action against company Appendix 3 - Tabletop Tests, cont d Infrastructure: Main Scenario Generator failure Heating / air conditioning failure Network or telecommunications failure Facility access disruption Inject Fuel supply vendor can t deliver Associates report health issues Determined to be malicious code All doors failed open Natural Disasters and Accidents: Main Scenario Loss of personnel due to illness Third party bankruptcy / hostile takeover Internet or cyber incident Protests block building access Inject Determined to be food poisoning from on-site cafeteria Choose a singlesource vendor Business critical data being released on Internet Time-released cyber attack Police blockade, tear gas, or injury to customer/employee Appendix 4 Impact Rating Samples, cont d What amount of REVENUE* would have been permanently lost due to the missed or failed recovery? None = we do not generate revenue Low = Zero to 50 thousand US dollars Moderate = 50 to 500 thousand US dollars High = 500 thousand to 1 million US dollars Very High = over 5 million US dollars * - Numbers for illustrative purposes only

Business Continuity Plan

Business Continuity Plan Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions

More information

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 AGENDA: Emergency Management Business Continuity Planning Q & A MONTH DAY, YEAR TITLE OF THE PRESENTATION 2 CANADIAN RED CROSS Disaster

More information

NCUA LETTER TO CREDIT UNIONS

NCUA LETTER TO CREDIT UNIONS NCUA LETTER TO CREDIT UNIONS NATIONAL CREDIT UNION ADMINISTRATION 1775 Duke Street, Alexandria, VA 22314 DATE: December 2001 LETTER NO.: 01-CU-21 TO: SUBJ: ENCL: All Federally Insured Credit Unions Disaster

More information

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015 Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level June 9, 2015 By: Tracy Hall MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company,

More information

What is an Exercise? Agenda. Types of Exercises. Tabletop Exercises for Executives. Defining the Tabletop Exercise. Types of Tabletop Exercises

What is an Exercise? Agenda. Types of Exercises. Tabletop Exercises for Executives. Defining the Tabletop Exercise. Types of Tabletop Exercises Tabletop Exercises for Executives Kathy Lee Patterson, CBCP, PMP Independence Blue Cross Defining the Tabletop Exercise Types of Tabletop Exercises Advantages to conducting Exercises Agenda 12 Step Approach

More information

Business Continuity and Disaster Recovery Planning

Business Continuity and Disaster Recovery Planning Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services

More information

CISM Certified Information Security Manager

CISM Certified Information Security Manager CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective

More information

for Human Service Providers Scott Ellis Scott Elliott Erin Sember-Chase 1

for Human Service Providers Scott Ellis Scott Elliott Erin Sember-Chase 1 for Human Service Providers Scott Ellis Scott Elliott Erin Sember-Chase 1 Goal The purpose of this webinar is to increase awareness and knowledge about the need for disaster/emergency continuity planning

More information

Business Continuity Planning Preparing Your Organization

Business Continuity Planning Preparing Your Organization Business Continuity Planning Preparing Your Organization Nicholas De Laurentis, CRM, IGP nick.delaurentis.gmkj@statefarm.com 1 Objectives Understand the importance of Business Continuity Planning Know

More information

Why Should Companies Take a Closer Look at Business Continuity Planning?

Why Should Companies Take a Closer Look at Business Continuity Planning? whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters

More information

How to Design and Implement a Successful Disaster Recovery Plan

How to Design and Implement a Successful Disaster Recovery Plan How to Design and Implement a Successful Disaster Recovery Plan Feb. 21 ASA Office-Administrative Section is Sponsored by Today s ASAPro Webinar is Brought to You by the How to Ask a Question Questions

More information

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic

More information

EXECUTIVE CRISIS MANAGEMENT TRAINING. Presented by Roseanne Rostron, CBCP Raido Response

EXECUTIVE CRISIS MANAGEMENT TRAINING. Presented by Roseanne Rostron, CBCP Raido Response EXECUTIVE CRISIS MANAGEMENT TRAINING Presented by Roseanne Rostron, CBCP Raido Response 1 Introduction Roseanne Rostron President Raido Response Over 12 years Crisis Management, Business Continuity, Disaster

More information

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK Federal Financial Institutions Examination Council FFIEC Business Continuity Planning BCP FEBRUARY 2015 IT EXAMINATION H ANDBOOK Table of Contents Introduction 1 Board and Senior Management Responsibilities

More information

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain 1. What is the most common planned performance duration for a continuity of operations plan (COOP)? A. 30 days B. 60 days C. 90 days D. It depends on the severity of a disaster. 2. What is the business

More information

Disaster Recovery Plan Checklist

Disaster Recovery Plan Checklist Disaster Recovery Plan Checklist Your guide for setting up or updating a Disaster Recovery Plan for your business. ArcSource Disaster Recovery Plan Checklist 1. Compile Your Internal Contacts Information

More information

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning The world has experienced a great deal of natural and man-made upheaval and destruction in the past few years, including tornadoes,

More information

The University of Iowa. Enterprise Information Technology Disaster Plan. Version 3.1

The University of Iowa. Enterprise Information Technology Disaster Plan. Version 3.1 Version 3.1 November 22, 2004 TABLE OF CONTENTS PART 1: DISASTER RECOVERY EXPECTATIONS... 3 OVERVIEW...3 EXPECTATIONS PRIOR TO AN INCIDENT OCCURRENCE...3 EXPECTATIONS PRIOR TO A DISASTER OCCURRENCE...4

More information

Business Continuity Overview

Business Continuity Overview Business Continuity Overview Beverley A. Retjos Senior Manager WW SWG Security & Controls 03/12/07 Business Continuity Management (BCM) Process of ensuring that a business is prepared to survive any disruption

More information

Business Continuity Planning for Schools, Departments & Support Units

Business Continuity Planning for Schools, Departments & Support Units Business Continuity Planning for Schools, Departments & Support Units 1 What is Business Continuity Planning? Examples Planning for an adverse, major or catastrophic event that would cause a disruption

More information

Statewide Disaster Recovery Coordinator Meeting. October 31, 2012

Statewide Disaster Recovery Coordinator Meeting. October 31, 2012 Statewide Disaster Recovery Coordinator Meeting October 31, 2012 Meeting Agenda ----- Topics ----- Opening Remarks and Introductions 10 minutes Short Subjects: Program Update 15 minutes Disaster Recovery

More information

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 Agenda Key Definitions Risks Business Continuity Management Program BCM Capability Assessment Process BCM Value Proposition

More information

Disaster Recovery Planning

Disaster Recovery Planning Disaster Recovery Planning This is a brief guide, with a suggested table of contents, to help you get started with putting together your Disaster Recovery Plan (DRP) Pensar can assist you in completing

More information

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP 2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level Tracy L. Hall, MBCP MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company, P.C.

More information

This presentation will introduce you to the concepts and terminology related to disaster recovery planning for businesses.

This presentation will introduce you to the concepts and terminology related to disaster recovery planning for businesses. 1. An Introduction This presentation will introduce you to the concepts and terminology related to disaster recovery planning for businesses. This presentation was prepared by the South Central Economic

More information

Building a strong business continuity plan

Building a strong business continuity plan Building a strong business continuity plan Protect your clients and firm with a well-planned business continuity plan A solid business continuity plan (BCP) is about more than simply staying in compliance.

More information

Business Continuity Template

Business Continuity Template Emergency Management Business Continuity Template The Regional Municipality of Wood Buffalo would like to give credit to the Calgary Emergency Management Agency (CEMA) and the Calgary Chamber of Commerce

More information

Ohio Conference for Payroll Professionals Disaster Recovery

Ohio Conference for Payroll Professionals Disaster Recovery Ohio Conference for Payroll Professionals Disaster Recovery Speaker Bruce E. Phipps CPP 2011 APA Payroll Man of the Year Principal Product Manager US Legislative Analyst ORACLE Corporation bruce.phipps@oracle.com

More information

Overview. Emergency Response. Crisis Management

Overview. Emergency Response. Crisis Management Prudential Financial s Preparedness Strategy Overview Emergency Response, Crisis Management, Business Continuation, Technology Disaster Recovery & Health Crisis Preparedness Prudential is committed to

More information

Ohio Supercomputer Center

Ohio Supercomputer Center Ohio Supercomputer Center IT Business Continuity Planning No: Effective: OSC-13 06/02/2009 Issued By: Kevin Wohlever Director of Supercomputer Operations Published By: Ohio Supercomputer Center Original

More information

Fundamentals of Business Continuity Planning Have a Plan!

Fundamentals of Business Continuity Planning Have a Plan! Fundamentals of Business Continuity Planning Have a Plan! Michael Kadar, MBCP, CISSP 2008 MK Continuity & Availability LLC kadarsro@talkamerica.net InfraGard Meeting Walsh College, Novi March 25, 2008

More information

EMERGENCY MANAGEMENT PLANNING CRITERIA FOR AMBULATORY SURGICAL CENTERS

EMERGENCY MANAGEMENT PLANNING CRITERIA FOR AMBULATORY SURGICAL CENTERS EMERGENCY MANAGEMENT PLANNING CRITERIA FOR AMBULATORY SURGICAL CENTERS The following criteria are to be used when developing Comprehensive Emergency Management Plans (CEMP) for all ambulatory surgical

More information

Fire Department Guide. Creating and Maintaining Business Continuity Plans (BCP)

Fire Department Guide. Creating and Maintaining Business Continuity Plans (BCP) Fire Department Guide Creating and Maintaining Business Continuity Plans (BCP) Business Continuity Planning Components Index: Introduction Getting Started Section 1 1. Assign departmental business continuity

More information

NAIT Guidelines. Implementation Date: February 15, 2011 Replaces: July 1, 2008. Table of Contents. Section Description Page

NAIT Guidelines. Implementation Date: February 15, 2011 Replaces: July 1, 2008. Table of Contents. Section Description Page Recommended by Emergency Preparedness Committee: January 26, 2011 Recommended by President s Council: February 11, 2011 Approved by Executive Committee: February 14, 2011 NAIT Guidelines CS1.1 Emergency

More information

Building Economic Resilience to Disasters: Developing a Business Continuity Plan

Building Economic Resilience to Disasters: Developing a Business Continuity Plan Building Economic Resilience to Disasters: Developing a Business Continuity Plan Buffalo Niagara Region February 26, 2014 Gail Moraton, CBCP Business Resiliency Manager Business Resiliency one important

More information

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP IT Disaster Recovery Plan Template By Paul Kirvan, CISA, CISSP, FBCI, CBCP Revision History REVISION DATE NAME DESCRIPTION Original 1.0 2 Table of Contents Information Technology Statement

More information

Command Center Handbook

Command Center Handbook Command Center Handbook P r o a c t i v IT e Monitoring Protecting Business Value Through Operational Excellence Abdul A Jaludi Copyright 2014 Abdul A Jaludi abby@tag-mc.net www.tag-mc.net All rights reserved.

More information

DISASTER RECOVERY PLANNING GUIDE

DISASTER RECOVERY PLANNING GUIDE DISASTER RECOVERY PLANNING GUIDE AN INTRODUCTION TO BUSINESS CONTINUITY PLANNING FOR JD EDWARDS SOFTWARE CUSTOMERS www.wts.com WTS Disaster Recovery Planning Guide Page 1 Introduction This guide will provide

More information

Business Continuity Planning Guide

Business Continuity Planning Guide Business Continuity Planning Guide For Small Businesses Prepared by the City of Vaughan Emergency Planning Department 1 Business Continuity Planning Business Continuity Planning (BCP) is a planning process

More information

IT Contingency Planning: IT Disaster Recovery Planning

IT Contingency Planning: IT Disaster Recovery Planning IT Contingency : IT Disaster Recovery Introduction CONTINGENCY PLANNING GUIDELINES FOR TABLE-TOP EXERCISE A tabletop exercise is a focused practice activity that places the participants in a simulated

More information

Availability Digest. www.availabilitydigest.com. @availabilitydig. Everbridge Emergency Notification July 2014

Availability Digest. www.availabilitydigest.com. @availabilitydig. Everbridge Emergency Notification July 2014 the Availability Digest @availabilitydig Everbridge Emergency Notification July 2014 Everbridge (www.everbridge.com) focuses on providing emergency/mass notification services (EMNS) via a simplified semi-automated

More information

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION Federal Financial Institutions Examination Council FFIEC Business Continuity Planning MARCH 2003 MARCH 2008 BCP IT EXAMINATION H ANDBOOK TABLE OF CONTENTS INTRODUCTION... 1 BOARD AND SENIOR MANAGEMENT

More information

Title: DISASTER RECOVERY/ MAJOR OUTAGE COMMUNICATION PLAN

Title: DISASTER RECOVERY/ MAJOR OUTAGE COMMUNICATION PLAN POLICY: This policy is intended to address organizational wide communication executed during a or major IS service outage. When a disaster occurs or when any critical system/infrastructure component is

More information

How to Plan for Disaster Recovery and Business Continuity

How to Plan for Disaster Recovery and Business Continuity A TAMP Systems White Paper TAMP Systems 1-516-623-2038 www.drsbytamp.com How to Plan for Disaster Recovery and Business Continuity By Tom Abruzzo, President and CEO Contents Introduction 1 Definitions

More information

National Fire Protection Association s Contribution to Business Continuity Strategies

National Fire Protection Association s Contribution to Business Continuity Strategies National Fire Protection Association s Contribution to Business Continuity Strategies about me 1. Retired AVP Senior Business Risk Consultant 2. FM Global Trained: 1. 35 Years Service 2. Founder Member

More information

Business Continuity Planning for Risk Reduction

Business Continuity Planning for Risk Reduction Business Continuity Planning for Risk Reduction Ion PLUMB ionplumb@yahoo.com Andreea ZAMFIR zamfir_andreea_ileana@yahoo.com Delia TUDOR tudordelia@yahoo.com Faculty of Management Academy of Economic Studies

More information

UNIVERSITY OF CALIFORNIA, MERCED EMERGENCY NOTIFICATION SYSTEM (UCMAlert)

UNIVERSITY OF CALIFORNIA, MERCED EMERGENCY NOTIFICATION SYSTEM (UCMAlert) UNIVERSITY OF CALIFORNIA, MERCED EMERGENCY NOTIFICATION SYSTEM (UCMAlert) RESPONSIBLE OFFICER : Vice Chancellor - Administration EFFECTIVE DATE : REVISION NUMBER : Original NUMBER OF PAGES : 8 I. REFERENCES

More information

DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS

DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS Appendix L DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS I. GETTING READY A. Obtain written commitment from top management of support for contingency planning objectives. B. Assemble

More information

Business Unit CONTINGENCY PLAN

Business Unit CONTINGENCY PLAN Contingency Plan Template Business Unit CONTINGENCY PLAN Version 1.0 (Date submitted) Submitted By: Business Unit Date Version 1.0 Page 1 1 Plan Review and Updates... 3 2 Introduction... 3 2.1 Purpose...

More information

Business Continuity Training and Testing: Narrowing the Gaps

Business Continuity Training and Testing: Narrowing the Gaps Business Continuity Training and Testing: Narrowing the Gaps Betty A. Kildow, CBCP, FBCI, Emergency Management Consultant Kildow Consulting 765/483-9365; BettyKildow@insightbb.com 93 nd Annual International

More information

2014 NABRICO Conference

2014 NABRICO Conference Business Continuity Planning 2014 NABRICO Conference September 19, 2014 6 CityPlace Drive, Suite 900 St. Louis, Missouri 63141 314.983.1200 1520 S. Fifth Street, Suite 309 St. Charles, Missouri 63303 636.255.3000

More information

This document contains the text of Secretary of the State regulations concerning

This document contains the text of Secretary of the State regulations concerning 1 This document contains the text of Secretary of the State regulations concerning Emergency Contingency Model Plan for Elections (Sections 9-174a-1 to 9-174a-34) This document was created by the Office

More information

Emergency Management Planning Criteria for Ambulatory Surgical Centers (State Criteria Form)

Emergency Management Planning Criteria for Ambulatory Surgical Centers (State Criteria Form) Emergency Management Planning Criteria for Ambulatory Surgical Centers (State Criteria Form) FACILITY INFORMATION: FACILITY NAME: FIELD (Company) FAC. TYPE: ASC STATE RULE: 59A-5, F.A.C CONTACT PERSON:

More information

(Provider s Name) Business Continuity Plan. CY 2010 Forward

(Provider s Name) Business Continuity Plan. CY 2010 Forward (Provider s Name) Business Continuity Plan CY 2010 Forward How to Use This Plan Disasters take many forms and require response at multiple levels. For disasters that threaten employee well-being, Company

More information

How To Plan A Crisis Management Program

How To Plan A Crisis Management Program Building a Security Conscious Business Continuity Management (BCM) Program Sam Stahl, CBCP, MBCI EMC Global Professional Services Program Manager stahl_samuel@emc.com ASIS Singapore, 2014 Agenda Overview

More information

Help! My phone lines are broken! A small businesses guide to telecoms disaster recovery

Help! My phone lines are broken! A small businesses guide to telecoms disaster recovery Help! My phone lines are broken! A small businesses guide to telecoms disaster recovery Packet Media Enterprise House, Block F4, Trentham Business Quarter, Bellringer Road, Trentham Lakes South, Stoke-on-Trent,

More information

Business Resilience Communications. Planning and executing communication flows that support business continuity and operational effectiveness

Business Resilience Communications. Planning and executing communication flows that support business continuity and operational effectiveness Business Resilience Communications Planning and executing communication flows that support business continuity and operational effectiveness Introduction Whispir have spent the last 14 years helping organisations

More information

EMERGENCY MANAGEMENT PLANNING CRITERIA FOR HOSPITALS

EMERGENCY MANAGEMENT PLANNING CRITERIA FOR HOSPITALS EMERGENCY MANAGEMENT PLANNING CRITERIA FOR HOSPITALS The following minimum criteria are to be used when developing Comprehensive Emergency Management Plans (CEMP) for all hospitals. These criteria will

More information

Principles for BCM requirements for the Dutch financial sector and its providers.

Principles for BCM requirements for the Dutch financial sector and its providers. Principles for BCM requirements for the Dutch financial sector and its providers. Platform Business Continuity Vitale Infrastructuur Financiële sector (BC VIF) Werkgroep BCM requirements 21 September 2011

More information

IT Service Continuity Management PinkVERIFY

IT Service Continuity Management PinkVERIFY -11-G-001 General Criteria Does the tool use ITIL 2011 Edition process terms and align to ITIL 2011 Edition workflows and process integrations? -11-G-002 Does the tool have security controls in place to

More information

Best-in-Class Crisis Preparation:

Best-in-Class Crisis Preparation: Best-in-Class Crisis Preparation: Maximize Readiness with the Four T s Robert Edson Vice President, Global Sales and Marketing Business Continuity Readiness Overview Business Continuity Management (BCM)

More information

CRISIS MANAGEMENT PLAN

CRISIS MANAGEMENT PLAN CRISIS MANAGEMENT PLAN Table of Contents Introduction... 3 Purpose... 3 Objectives... 3 Types & Levels of a Crisis... 4 Plan Activation... 6 Crisis Management Team (CMT) Structure... 6 CMT Responsibilities...

More information

AMBULATORY SURGICAL CENTERS (Based upon AHCA Form # 3130-2003 JUL 94)

AMBULATORY SURGICAL CENTERS (Based upon AHCA Form # 3130-2003 JUL 94) (Based upon AHCA Form # 3130-2003 JUL 94) The document below is the cross-reference used by Palm Beach County Division of Emergency Management for the annual review and re-certification of your CEMP. Review

More information

BUSINESS CONTINUITY PLANNING GUIDELINES

BUSINESS CONTINUITY PLANNING GUIDELINES BUSINESS CONTINUITY PLANNING GUIDELINES Washington University in St. Louis The purpose of this guide is to serve as a tool to all departments, divisions, and labs across the University in building a Business

More information

How To Prepare For A Disaster

How To Prepare For A Disaster Building an effective Tabletop Exercise Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 3/26/2013 #1 Continuity Plan Testing Flowchart 3/26/2013 #2 1 Ongoing Multi-Year

More information

Effectiveness of BCM through Exercising

Effectiveness of BCM through Exercising Effectiveness of BCM through Exercising By Wan Asriah Wan Adnan Head Business Continuity & Disaster Recovery Bursa Malaysia Berhad wan_asriah@bursamalaysia.com 31 October 2007 Bursa Malaysia and its Group

More information

Business Continuity Planning Toolkit. (For Deployment of BCP to Campus Departments in Phase 2)

Business Continuity Planning Toolkit. (For Deployment of BCP to Campus Departments in Phase 2) Business Continuity Planning Toolkit (For Deployment of BCP to Campus Departments in Phase 2) August 2010 CONTENTS: Background Assumptions Business Impact Analysis Risk (Vulnerabilities) Assessment Backup

More information

AMBULATORY SURGICAL CENTERS

AMBULATORY SURGICAL CENTERS AMBULATORY SURGICAL CENTERS STATUTE RULE CRITERIA Current until changed by State Legislature or AHCA Hospitals and Ambulatory Surgical Centers Statutory Reference 3 395.1055 (1)(c), Florida Statutes Rules

More information

State of South Carolina Policy Guidance and Training

State of South Carolina Policy Guidance and Training State of South Carolina Policy Guidance and Training Policy Workshop All Agencies Business Continuity Management Policy June 2014 Agenda Questions & Follow-Up Policy Workshop Overview & Timeline Policy

More information

IT Disaster Recovery Plan Template

IT Disaster Recovery Plan Template HOPONE INTERNET CORP IT Disaster Recovery Plan Template Compliments of: Tim Sexton 1/1/2015 An information technology (IT) disaster recovery (DR) plan provides a structured approach for responding to unplanned

More information

Prepared by Rod Davis, ABCP, MCSA November, 2011

Prepared by Rod Davis, ABCP, MCSA November, 2011 Prepared by Rod Davis, ABCP, MCSA November, 2011 Disaster an event, which causes the loss of an essential service, or part of it, for a length of time which imperils mission achievement. (Andrew Hiles,

More information

Business Continuity and Disaster Recovery Policy

Business Continuity and Disaster Recovery Policy Maine State Government Dept. of Administrative & Financial Services Office of Information Technology (OIT) Business Continuity and Disaster Recovery Policy I. Statement The Office of Information Technology

More information

Continuity of Operations Planning. A step by step guide for business

Continuity of Operations Planning. A step by step guide for business What is a COOP? Continuity of Operations Planning A step by step guide for business A Continuity Of Operations Plan (COOP) is a MANAGEMENT APPROVED set of agreed-to preparations and sufficient procedures

More information

11 Common Disaster Planning Mistakes

11 Common Disaster Planning Mistakes 11 Common Disaster Planning Mistakes The world is full of risk. Floods, fires, hurricanes, thefts, IT system failures and blackouts are just a few of the incredibly damaging disasters that can and do strike

More information

BUSINESS CONTINUITY PLAN

BUSINESS CONTINUITY PLAN How to Develop a BUSINESS CONTINUITY PLAN To print to A4, print at 75%. TABLE OF CONTENTS SUMMARY SUMMARY WHAT IS A BUSINESS CONTINUITY PLAN? CHAPTER PREPARING TO WRITE YOUR BUSINESS CONTINUITY PLAN CHAPTER

More information

NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00)

NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00) NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00) Subject and version number of document: Serial Number: Business Continuity Management Policy

More information

EMERGENCY PREPAREDNESS TEMPLATE

EMERGENCY PREPAREDNESS TEMPLATE EMERGENCY PREPAREDNESS TEMPLATE *This template is designed to help facilities keep track of emergency preparedness information. The fields can be typed in online or the form can be printed out and done

More information

DISASTER RESPONSE: MANAGING THE ENVIRONMENTAL RISKS. By Frank Westfall and Robert Winterburn

DISASTER RESPONSE: MANAGING THE ENVIRONMENTAL RISKS. By Frank Westfall and Robert Winterburn DISASTER RESPONSE: MANAGING THE ENVIRONMENTAL RISKS By Frank Westfall and Robert Winterburn DISASTER RESPONSE: MANAGING THE ENVIRONMENTAL RISKS Frank Westfall and Robert Winterburn April 2015 Whether it

More information

Disaster Recovery Plan Documentation for Agencies Instructions

Disaster Recovery Plan Documentation for Agencies Instructions California Office of Information Security Disaster Recovery Plan Documentation for Agencies Instructions () November 2009 SCOPE AND PURPOSE The requirements included in this document are applicable to

More information

GUIDE TO DEVELOPING AND CONDUCTING BUSINESS CONTINUITY EXERCISES

GUIDE TO DEVELOPING AND CONDUCTING BUSINESS CONTINUITY EXERCISES GUIDE TO DEVELOPING AND CONDUCTING BUSINESS CONTINUITY EXERCISES ATLANTA, GEORGIA FEBRUARY 12, 2011 Table of Contents FOREWORD... ii 1.0 Introduction... 1 1.1. Purpose... 1 1.2 Organization... 1 2.0 Rehearsal,

More information

Table of Contents... 1

Table of Contents... 1 ... 1 Chapter 1 Introduction... 4 1.1 Executive Summary... 4 1.2 Goals and Objectives... 5 1.3 Senior Management and Board of Directors Responsibilities... 5 1.4 Business Continuity Planning Processes...

More information

Building and Maintaining a Business Continuity Program

Building and Maintaining a Business Continuity Program Building and Maintaining a Business Continuity Program Successful strategies for financial institutions for effective preparation and recovery Table of Contents Introduction...3 This white paper was written

More information

Technology Recovery Plan Instructions

Technology Recovery Plan Instructions State of California California Information Security Office Technology Recovery Plan Instructions SIMM 5325-A (Formerly SIMM 65A) September 2013 REVISION HISTORY REVISION DATE OF RELEASE OWNER SUMMARY OF

More information

Boston College. Departmental Business Continuity Planning

Boston College. Departmental Business Continuity Planning Boston College Departmental Business Continuity Planning Spring 2013 1 BUSINESS CONTINUITY PROGRAM GOAL The goal of the Boston College Business Continuity Program is to ensure that all departments and

More information

The Joint Commission Approach to Evaluation of Emergency Management New Standards

The Joint Commission Approach to Evaluation of Emergency Management New Standards The Joint Commission Approach to Evaluation of Emergency Management New Standards (Effective January 1, 2008) EC. 4.11 through EC. 4.18 Revised EC. 4.20 Emergency Management Drill Standard Lewis Soloff

More information

Offsite Disaster Recovery Plan

Offsite Disaster Recovery Plan 1 Offsite Disaster Recovery Plan Offsite Disaster Recovery Plan Presented By: Natan Verkhovsky President Disty Portal Inc. 2 Offsite Disaster Recovery Plan Introduction This document is a comprehensive

More information

IT Disaster Recovery and Business Resumption Planning Standards

IT Disaster Recovery and Business Resumption Planning Standards Information Technology Disaster Recovery and Business IT Disaster Recovery and Business Adopted by the Information Services Board (ISB) on May 28, 1992 Policy No: Also see: 500-P1, 502-G1 Supersedes No:

More information

University of Prince Edward Island. Emergency Management Plan

University of Prince Edward Island. Emergency Management Plan Emergency Management Plan March 2012 ON CAMPUS Emergency Dial Security Assistance Dial 566-0384 OFF CAMPUS SUPPORT AGENCIES Fire & Ambulance... 9-1-1 Charlottetown Fire Department... 566-5548 Fire Marshal...

More information

Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).

Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP). Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP). Ed Fortin President Fortin Consulting Paul Godden Consultant & Quotation Author Friday 24 th February 2012 Business Continuity Planning

More information

How To Plan For An Event Like Ebola

How To Plan For An Event Like Ebola DOES YOUR BUSINESS CONTINUITY PLAN ADDRESS AN EVENT LIKE EBOLA? The degree of spread of Ebola in the months ahead is uncertain. In the unlikely event of a worst- case scenario, can your organization meet

More information

TSM ASSESSMENT PROTOCOL

TSM ASSESSMENT PROTOCOL TSM ASSESSMENT PROTOCOL A Tool for Assessing Crisis Management and Communications Planning Performance Purpose The purpose of the assessment protocol is to provide guidance to the member companies in completing

More information

Creating a Business Continuity Plan for your Health Center

Creating a Business Continuity Plan for your Health Center Creating a Business Continuity Plan for your Health Center 1 Page Left Intentionally Blank 2 About This Manual This tool is the result of collaboration between the Primary Care Development Corporation

More information

SALVE REGINA UNIVERSITY. Emergency. Office of Safety & Security

SALVE REGINA UNIVERSITY. Emergency. Office of Safety & Security SALVE REGINA UNIVERSITY Emergency Response Plan Office of Safety & Security Original: October 2000 Updated & Revised: February 2006 Updated & Revised: March 2010 Table of Contents Section I: Overview

More information

The Commonwealth of Massachusetts. 1 Ferncroft Road, P.O. Box 3340, Danvers, MA 01923-0840

The Commonwealth of Massachusetts. 1 Ferncroft Road, P.O. Box 3340, Danvers, MA 01923-0840 The Commonwealth of Massachusetts 1 Ferncroft Road, P.O. Box 3340, Danvers, MA 01923-0840 Emergency Response Plan 2013 Executive Approved February 18, 2014 I. Mission Statement An emergency can arise at

More information

Overview of how to test a. Business Continuity Plan

Overview of how to test a. Business Continuity Plan Overview of how to test a Business Continuity Plan Prepared by: Thomas Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com BRP/DRP Test Plan Creation and Exercise Page: 1 Table of Contents BCP/DRP Test

More information

Unit Guide to Business Continuity/Resumption Planning

Unit Guide to Business Continuity/Resumption Planning Unit Guide to Business Continuity/Resumption Planning (February 2009) Revised June 2011 Executive Summary... 3 Purpose and Scope for a Unit Business Continuity Plan(BCP)... 3 Resumption Planning... 4 Assumptions

More information

The Importance of Performance Metrics in Business Continuity Paul Kirvan, FBCI, CISA

The Importance of Performance Metrics in Business Continuity Paul Kirvan, FBCI, CISA The Importance of Performance Metrics in Business Continuity Paul Kirvan, FBCI, CISA BCM Advisory Services Board Member and Secretary The Business Continuity Institute USA Chapter Agenda Introduction Key

More information

Disaster Planning & Recovery: SHRM Resources. Shelly Trent, SPHR; SHRM Field Services Director

Disaster Planning & Recovery: SHRM Resources. Shelly Trent, SPHR; SHRM Field Services Director Disaster Planning & Recovery: SHRM Resources Shelly Trent, SPHR; SHRM Field Services Director 2012 Disaster News Millions without power in India Wildfires in Colorado Springs Mass shootings in movie theater

More information

Disaster Preparedness & Response

Disaster Preparedness & Response 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 A B C E INTRODUCTION AND PURPOSE REVIEW ELEMENTS ABBREVIATIONS NCUA REFERENCES EXTERNAL REFERENCES Planning - Ensuring

More information

TSM ASSESSMENT PROTOCOL

TSM ASSESSMENT PROTOCOL TSM ASSESSMENT PROTOCOL A Tool for Assessing Crisis Management Planning Performance Introduction Launched in 2004, Towards Sustainable Mining (TSM) is an initiative of The Mining Association of Canada

More information