RETAIL AUDIT FORUM - AUDITING BUSINESS CONTINUITY

Size: px
Start display at page:

Download "RETAIL AUDIT FORUM - AUDITING BUSINESS CONTINUITY"

Transcription

1 RETAIL AUDIT FORUM - AUDITING BUSINESS CONTINUITY Alan Hodgson MSc CMIIA MBCI

2 2 My Background 15 years within Internal Audit CMIIA MSc Audit Management and Consultancy 10 years in Retail 10 years in Business Continuity Management MBCI Established Continuous Solutions Ltd. seven years ago Set-up and managed the Retail Business Continuity Association for four years Approved by BSI to advise and audit to BS25999 Business Continuity Management Systems

3 3 Positioning Who has recently conducted a business continuity audit? What was the scope of the audit? How was the scope determined? What benchmark did you base your audit on / what did you audit to? How many audit days are committed to BCM / year? What is the experience of the auditors in the subject?

4 4 THE BIG QUESTION? Have you ever wondered if auditing business continuity plans was worthwhile, and whether they addressed the real continuity and disaster recovery risks that your organisation faces?

5 5 Initial Thoughts! Why are we doing Business Continuity in Retail? What should we be looking to include in the audit plan? How should we be auditing Business Continuity?

6 6 WHY ARE WE DOING BUSINESS CONTINUITY IN RETAIL?

7 7 A Few Good Reasons? Retailers continue to develop leaner structures to drive efficiencies but this in turn can also create vulnerabilities Corporate governance requirements continue to expand Stakeholders expect a reasonable degree of protection of there investment Insurers continue to put pressure on retailers to limit there own exposure There are sizeable risks inherent in some retail activities (e.g. distribution/call centres) There are risks inherent in Global sourcing and Supply Chains We have to do it because other Retailers are doing it? Numerous retail related major incidents experienced over recent years. It s flavour of the month with the Board..we just experienced a major incident? We have worked to hard to get the business to where it is, and we aren t prepared to lose it!!

8 8 WHAT SHOULD WE BE LOOKING TO INCLUDE IN THE AUDIT PLAN?

9 9 Systems / Risk Based Auditing The Basics Identify the risk Evaluate the controls Assess their effectiveness Make recommendations Offer an opinion of assurance

10 10 Business Continuity It should be Structured as any system of management Its purpose is to protect against risk It is designed to support controls which should include: Preventative measures Detective alerts Corrective actions and capabilities

11 11 The Business Continuity Management System (BCMS) Like any system the BCMS is auditable There are benefits to having such a system in place: It underpins the application, management, and commitment to maintaining effective business continuity arrangements It establishes common principles for managing the risk and supports consistency of approach It ensures a continual review and re-alignment in the application of controls It can result in ISO certification

12 12 What Do We Want From The Audit? What does the Risk Owner want from the Audit? What does the Business need from the audit? What does the Audit Committee need from the audit?

13 13 Defining the Audit Plan What is the stage of evolution of the subject in the business? How complex is the organisation? What are the real risks and how have they been identified? What do we already know about the controls in place?

14 14 Evolution of BCM Why audit to best practice? What is right for your organisation? Just Considered Some Activity Significant Focus Fully Embeded

15 15 A Typical Retail Model 100 s of Stores 1000 s of Products Employees Customers Retail Ops Distribution Multiple Warehouses / DC s Regional Hubs Suppliers 3 rd party logistics Employees Employees Customers 3 rd party logistics Web hosting ICT infrastructure E-comm. s Head Office Main Office Buildings ICT People SO WHERE DO YOU START TO AUDIT?

16 16 The Business Continuity Project Life Cycle (BCI 2006)

17 The Business Continuity Programme 17

18 18 Auditing Vertically (By Life Cycle) Embedding Review Implement Strategy Understanding Prog. Mang. Head Office Warehousing Call Centres Suppliers

19 19 Auditing Horizontally (By Life Cycle) Embedding Distribution Centres Review Implementing Strategy Understanding Prog. Mang. DC1 DC2 DC3 DC4 DC5

20 20 Business Continuity Controls STRATEGIC TACTICAL OPERATIONAL Corporate Risk Register Risk Management Policy Audit Committee Business Continuity Management Policy ICT Infrastructure Resilience ICT Disaster Recovery Arrangements Work Area Recovery Arrangements (Office, DC, Call Ctr.) ICT Security Site Risk / Control Assessments Work Area Recovery Testing Site ERP s Site Security Audit Review Divisional IMP s Site Health and Safety Allocation of ownership IMT Training and Exercising ERT Training and Exercising Business Continuity Steering group Business Change Management Protocols Contractor Management Project Risk Management Site / Operation BIA s Supplier Business Continuity Assessment Crisis Management Plan Supply Chain Management Fire Prevention Activities

21 21 HOW SHOULD WE BE AUDITING BUSINESS CONTINUITY?

22 22 It s Simple Then...or is it? Do you have business continuity plans in place? Do you have ICT disaster recovery arrangements in place? Have these arrangements been tested? Alignment with Retail Best Practice Benchmark ISO Certification IS IT ANY GOOD???

23 23 The Risks Manchester City Centre bombing 1996 M&S House of Fraser Buncefield Fuel Depot explosion 2006 Dixon s Retail Group Warehouse Fires B&Q (Branstone) Primark (Lutterworth) 2005 Central Milton Keynes Crane Collapse 2006 Co-Op Leicester 2008 Army Careers Office Bomb, - St. Marys Butt Reading 11 Feb 2014

24 24 The Risk Register What is Captured? A Single Business Continuity Risk? Multiple Business Continuity Risks? Are they captured by Division / Brands? Do we know who owns the risk? How do we show how well is it managed?

25 25 Who Owns The Risk? Managing Director Distribution Director Property Director ICT Director Distribution Centre Managers Head Office Facilities Manager Head of ICT Infrastructure

26 26 The Challenges in Scoping The BCM Audits The entire or just single elements of the BCMS? To what breadth: a Single Site or Facility; a Division or Brand; or the Group as a whole? To what depth: Head Offices; ICT infrastructure; Call Centres; Supply Chain (Warehousing, Distribution, logistics); Stores; Suppliers? Controls: Strategic Tactical Operational How should it interlink with other Audits: Security (logical or physical); Health and Safety; Project Management: Fire Prevention; Supplier; Contractor Management; etc.

27 27 The Fundamentals Understanding Business Exposure? Has a Business Impact Analysis (BIA) been conducted? What are the risks? Is the Executive aware of the size of the risk? What are the control structures in place e.g. the BCM: Policy; Strategy; Scope; Programme (time line); Responsibilities? Are these appropriate for our business.today?

28 28 The Auditors Assigned What is their level of knowledge of the business? How well do they understand the subject of BCM? What specific training have they been given? Remember. The Devil can often be in the detail. Do they have the skills to find it.. A lot may be riding on it!!!

29 29 Challenge 1 Lets assume that we have a single Distribution Centre, stocking a key range of internationally sourced products. Can its recovery capability really be assured and tested? Audit Considerations: How comprehensive is the BIA and who was involved in its analysis? What site controls are deployed: security; fire prevention; location; nature of product? Who has been involved in determining the recovery strategy? Are they in a position to know if it is achievable? Who signed it off? Is the Supply Chain efficient enough to support the anticipated recovery demands? Has the business engaged with the 3 rd parties likely to play a critical role in the recovery process, what evidence supports this? What level of detail is in the recovery plan? Does it include clear actions, owners, timelines? Can components of the recovery strategy be tested independently?

30 30 Challenge 2 If the ICT Director says that there is an adequate recovery capability for the businesses critical ICT infrastructure, then how can we be certain of this? Audit Considerations: Has a comprehensive BIA been conducted across whole business mapping the impact over time on each critical business process (retail, supply chain, e-comm. s, head office etc.), following the loss of supporting systems? Has the gap of this, against the stated systems recovery capability, been determined? ICT: How comprehensive is the ICT recovery testing programme? Who has been involved in the testing? What are the results from ICT recovery testing? How do these results compare with the stated recovery capability? What is the level of resilience deployed over the ICT infrastructure? Has the residual exposure escalated to Board? What improvement action plans are in place?

31 31 What the Audit Should Challenge? You should Challenge: The comprehensiveness of the risk and impact assessment The communication and visibility of the exposure to risk at Board level The ownership of the risks The process by which the recovery strategy, procedures, arrangements have been determined The skills and knowledge of those involved in this process The assessment of the control environment from which you operate from The extent, frequency, and scope of testing and exercising The process and management of implementing improvement actions Don t. question the level of recovery testing and exercising unless you have confidence that the risks and impacts have been fully assessed Be Positive. about what has been achieved, where good practice has clearly been adopted, and where a commitment to address business continuity risks has been made

32 32 Remember There s no quick fix in Business Continuity Management you either do it right. or don t bother! Its not about how big the plans are its about the approach, commitment, and effort that goes into developing a solid capability. To cover a large retail organisation committed to BCM then the BCM audit programme should be planned over several years. Consider using discrete specialist support where suitably skilled internal resources are lacking. As an auditor, don t just ask questions, role your sleeves up and have a look.you may be surprised at what you find!!

33 THANK YOU 33

Proposal for Business Continuity Plan and Management Review 6 August 2008

Proposal for Business Continuity Plan and Management Review 6 August 2008 Proposal for Business Continuity Plan and Management Review 6 August 2008 2008/8/6 Contents About Newton IT / Quality of our services. BCM & BS25999 Overview 2. BCM Development in line with BS25999 3.

More information

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015 Business Continuity Management Governance Frank Higgins Abu Dhabi March 2015 Different Names Same Concept BCM (Business Continuity Management) BSI 25999 IPOCM (Incident Preparedness & Operational Continuity

More information

Business Continuity Management Framework 2014 2017

Business Continuity Management Framework 2014 2017 Business Continuity Management Framework 2014 2017 Blackpool Council Business Continuity Framework V3.0 Page 1 of 13 CONTENTS 1.0 Forward 03 2.0 Administration 04 3.0 Policy 05 4.0 Business Continuity

More information

The PNC Financial Services Group, Inc. Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program The PNC Financial Services Group, Inc. Business Continuity Program subsidiaries) 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis

More information

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd BS 25999 Business Continuity Management By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd 1 Contents slide BSI British Standards 2006 BS 25999(Business Continuity) 2002 BS 15000

More information

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO 22301 AUDITS, CERTIFICATION AND TRAINING

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO 22301 AUDITS, CERTIFICATION AND TRAINING HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO 22301 AUDITS, CERTIFICATION AND TRAINING ISO 22301 BUSINESS CONTINUITY MANAGEMENT SYSTEMS Most organisations will, at some point, be faced with having to respond

More information

BS 25999 BUSINESS CONTINUITY MANAGEMENT

BS 25999 BUSINESS CONTINUITY MANAGEMENT BS 25999 BUSINESS CONTINUITY MANAGEMENT AUDIT, CERTIFICATION & training services HOW CAN YOU ENSURE BUSINESS CONTINUITY? BS 25999 AUDITS & CERTIFICATION FROM SGS Most organisations will, at some point,

More information

The PNC Financial Services Group, Inc. Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page

More information

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK BUSINESS CONTINUITY MANAGEMENT FRAMEWORK Document Author: Civil Contingencies Service - Authorised by the CCS Joint Management Board - Version 1.0. Issued December 2012 Page 1 FRAMEWORK STATEMENT Business

More information

Business Continuity for the New Professional. Britt Corra Enterprise BCM Erika Voss Senior BCM

Business Continuity for the New Professional. Britt Corra Enterprise BCM Erika Voss Senior BCM Business Continuity for the New Professional Britt Corra Enterprise BCM Erika Voss Senior BCM New to Business Continuity? Agenda & Experience 3-5 years experience? Seasoned veteran? What is BCM Tool Kit?

More information

Business Continuity Management Group Policy

Business Continuity Management Group Policy THE WAREHOUSE GROUP LIMITED ( the Company ) 1. Purpose of Policy This policy is to communicate The Warehouse Group Limited ( TWG ) governance requirements and arrangements for developing and sustaining

More information

Company Management System. Business Continuity in SIA

Company Management System. Business Continuity in SIA Company Management System Business Continuity in SIA Document code: Classification: Company Project/Service Year Document No. Version Public INDEX 1. INTRODUCTION... 3 2. SIA S BUSINESS CONTINUITY MANAGEMENT

More information

Business Continuity Planning

Business Continuity Planning Business Continuity Planning Public Entities Risk Management Forum 5 th July 2012 Presented by Mark Penberthy FBCI Overcoming Practical Challenges Business Continuity Management (BCM) AGENDA 1. What is

More information

BCP and DR. P K Patel AGM, MoF

BCP and DR. P K Patel AGM, MoF BCP and DR P K Patel AGM, MoF Key difference between BS 25999 and ISO 22301 ISO 22301 puts a much greater emphasis on setting the objectives, monitoring performance and metrics aligning BC to top management

More information

Risk Management & Business Continuity Manual 2011-2014

Risk Management & Business Continuity Manual 2011-2014 ANNEX C Risk Management & Business Continuity Manual 2011-2014 Produced by the Risk Produced and by the Business Risk and Business Continuity Continuity Team Team February 2011 April 2011 Draft V.10 Page

More information

Principles for BCM requirements for the Dutch financial sector and its providers.

Principles for BCM requirements for the Dutch financial sector and its providers. Principles for BCM requirements for the Dutch financial sector and its providers. Platform Business Continuity Vitale Infrastructuur Financiële sector (BC VIF) Werkgroep BCM requirements 21 September 2011

More information

Reputation. Further excellence. business continuity. risk management. Data security

Reputation. Further excellence. business continuity. risk management. Data security Reputation competitive advantage speed to market safety Further excellence trust Data security risk management business continuity HOW CAN YOU CREATE AND SECURE SUSTAINABLE BUSINESS? SOLUTIONS FOR MANAGING

More information

Merrycon s Approach to Business Continuity Management

Merrycon s Approach to Business Continuity Management Merrycon s Approach to Business Continuity Management Business Continuity is a management discipline that provides a framework for an organisation to build resilience, providing the capability for an effective

More information

Business Continuity Management and BS 25999 by Steve Chan, Head of Training - HK, BSI Management Systems

Business Continuity Management and BS 25999 by Steve Chan, Head of Training - HK, BSI Management Systems Business Continuity Management and BS 25999 by Steve Chan, Head of Training - HK, BSI Management Systems 9 April, 2008 2 Presentation content Drivers for Business Continuity Standards and definitions.

More information

Introduction to Business Continuity Planning

Introduction to Business Continuity Planning Introduction to Business Continuity Planning Business Continuity and Disaster Resilience Forum May 10, 2012 Rizal Ballroom A, Makati Shangri-la Manila, Philippines Dr Goh Moh Heng President BCM Institute

More information

Business Continuity Standards A Primer

Business Continuity Standards A Primer INTELLIGENT NOTIFICATION Alphabet Soup: Making Sense of BC/DR Standards Part 1: Business Continuity Standards A Primer Why all the attention now? One of the hottest topics in BC/DR these days is standards.

More information

Business Continuity Management Policy

Business Continuity Management Policy Business Continuity Management Policy Business Continuity Policy Version 1.0 1 Version control Version Date Changes Author 0.1 April 13 1 st draft PH 0.2 June 13 Amendments in line with guidance PH 0.3

More information

Business Continuity Policy and Business Continuity Management System

Business Continuity Policy and Business Continuity Management System Business Continuity Policy and Business Continuity Management System Summary: This policy sets out the structure for ensuring that the PCT has effective Business Continuity Plans in place in order to maintain

More information

Business Continuity - The Theory

Business Continuity - The Theory Business Continuity - The Theory Mark Redding Account Manager MSIG Cambridge 2011 Mitsui Sumitomo at Lloyd s Excellence in all we do Why plan? Mitsui Sumitomo at Lloyd s Excellence in all we do What is

More information

BUSINESS CONTINUITY MANAGEMENT SINGAPORE SS540 BCM STANDARDS. LSA Consultants Pte Ltd

BUSINESS CONTINUITY MANAGEMENT SINGAPORE SS540 BCM STANDARDS. LSA Consultants Pte Ltd BUSINESS CONTINUITY MANAGEMENT SINGAPORE SS540 BCM STANDARDS LSA Consultants Pte Ltd BCM SINGAPORE LSA Consultants Who are we? Business Continuity Management (BCM) What is it? Singapore Standard SS540

More information

BUSINESS CONTINUITY POLICY

BUSINESS CONTINUITY POLICY BUSINESS CONTINUITY POLICY Document Type Corporate Policy Unique Identifier CO-038 Document Purpose To provide a structure through which: i. A comprehensive business continuity management system (BCMS)

More information

Business Continuity Management Framework

Business Continuity Management Framework Business Continuity Management Framework Date of Issue: November 2013 Review Date: November 2014 Written by: Jackie Orchard Risk & Business Continuity Manager Authorised by: Signed off by: DCC Francis

More information

IIA South West Event. A look at key supply chain risks and why contracting is a key step 14 January 2015

IIA South West Event. A look at key supply chain risks and why contracting is a key step 14 January 2015 IIA South West Event A look at key supply chain risks and why contracting is a key step 14 January 2015 Objectives and agenda Page The contact at KPMG with respect to this presentation is: Iain Prince

More information

Il nuovo standard ISO 22301 sulla Business Continuity Scenari ed opportunità

Il nuovo standard ISO 22301 sulla Business Continuity Scenari ed opportunità Il nuovo standard ISO 22301 sulla Business Continuity Scenari ed opportunità Massimo Cacciotti Business Services Manager BSI Group Italia Agenda BSI: Introduction 1. Why we need BCM? 2. Benefits of BCM

More information

Business Continuity Management

Business Continuity Management Business Continuity Management Standard Operating Procedure Notice: This document has been made available through the Police Service of Scotland Freedom of Information Publication Scheme. It should not

More information

NHS Commissioning Board Business Continuity Management Framework (service resilience)

NHS Commissioning Board Business Continuity Management Framework (service resilience) NHS Commissioning Board Business Continuity Management Framework (service resilience) 1 P a g e NHS Commissioning Board Business Continuity Management Framework Date 7 January 2013 Audience NHS Commissioning

More information

Business Continuity Management Policy

Business Continuity Management Policy Business Continuity Management Policy Policy Holder: Authoriser: Caroline Gover, Head of Business Continuity Caroline Thomson, Chief Operating Officer Reviewed on: Feb 08 Reviewed on: Feb 08 Next Review

More information

Coping with a major business disruption. Some practical advice

Coping with a major business disruption. Some practical advice Coping with a major business disruption Some practical advice Coping with a major business disruption What is business continuity? Business continuity planning (BCP) is a management process that helps

More information

Tips and techniques a typical audit programme

Tips and techniques a typical audit programme Auditing Business Continuity Planning Tips and techniques a typical audit programme Karen Wills, Senior Internal Auditor St James s Place Wealth Management February 2014 Contents Background Roles and Responsibilities

More information

Business Continuity. Is your Business Prepared for the worse? What is Business Continuity? Why use a Business Continuity Plan?

Business Continuity. Is your Business Prepared for the worse? What is Business Continuity? Why use a Business Continuity Plan? Business Continuity Is your Business Prepared for the worse? Major emergencies can develop suddenly without warning. Situations can threaten and disrupt your business and impact upon you and your staff.

More information

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 Agenda Key Definitions Risks Business Continuity Management Program BCM Capability Assessment Process BCM Value Proposition

More information

Business Continuity Management Systems. Protecting for tomorrow by building resilience today

Business Continuity Management Systems. Protecting for tomorrow by building resilience today Business Continuity Management Systems Protecting for tomorrow by building resilience today Vital statistics 31% 40% of UK businesses have been affected by bad weather related transport problems, power

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy 1 NHS England INFORMATION READER BOX Directorate Medical Commissioning Operations Patients and Information Nursing Trans. & Corp. Ops. Commissioning Strategy Finance Publications

More information

Business Continuity Plan Toolkit

Business Continuity Plan Toolkit Business Continuity Plan Toolkit March 2015 1 Contents The Template instructions for use... 2 Introduction... 3 What is the purpose of this toolkit?... 3 Why do you need a Business Continuity Plan?...

More information

Business Continuity Planning. A guide to loss prevention

Business Continuity Planning. A guide to loss prevention Business Continuity Planning A guide to loss prevention There are many statistics quoted about the effect that a lack of planning for a disaster has on a business. What s certain is that any unplanned

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy Summary: This policy sets out the structure for ensuring that the PCT has effective Business Continuity Plans in place in order to maintain its essential business functions during

More information

" # $% "%&$& Lesley Fayers Exercising the BCP workbook.doc Page 1 of 12

 # $% %&$& Lesley Fayers Exercising the BCP workbook.doc Page 1 of 12 ! " # $% "%&$& Lesley Fayers Exercising the BCP workbook.doc Page 1 of 12 Objectives...3 1. Why run an exercise?...3 2. What sort of exercises are there?...3 Call Tree:...4 Walk Through:...4 Table Top:...4

More information

CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM

CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM A WHITE PAPER CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM AUTHORS: Neil A. Smith, MBCP [email protected] Sandra Riddell, MBCI [email protected] CSC Papers 2013 ABSTRACT The auditors said

More information

Business Continuity Management

Business Continuity Management Business Continuity Management The Concept and Context of BCM Planning and Study Notes THE CONCEPT AND CONTEXT OF BUSINESS CONTINUITY Introduction Whilst it is important to recognise that there is a holistic

More information

WEST YORKSHIRE FIRE & RESCUE SERVICE. Business Continuity Management Strategy

WEST YORKSHIRE FIRE & RESCUE SERVICE. Business Continuity Management Strategy WEST YORKSHIRE FIRE & RESCUE SERVICE Business Continuity Management Strategy Date Issued: 12 November 2012 Review Date: 12 November 2015 Version Control Version Number Date Author Comment 0.1 June 2011

More information

www.td.com.au Business Continuity - IT Disaster Recovery Discussion Paper - - Commercial in Confidence Version V2.0R Wednesday, 5 September 2012

www.td.com.au Business Continuity - IT Disaster Recovery Discussion Paper - - Commercial in Confidence Version V2.0R Wednesday, 5 September 2012 Business Continuity - IT Disaster Recovery Discussion Paper - - Version V2.0R Wednesday, 5 September 2012 Commercial in Confidence Melbourne Sydney 79-81 Coppin St Level 2 Richmond VIC 3121 414 Kent St

More information

Moving from BS 25999-2 to ISO 22301. The new international standard for business continuity management systems. Transition Guide

Moving from BS 25999-2 to ISO 22301. The new international standard for business continuity management systems. Transition Guide Transition Guide Moving from BS 25999-2 to ISO 22301 The new international standard for business continuity management systems Extract from The Route Map to Business Continuity Management: Meeting the

More information

BCM and DRP - RFP Template

BCM and DRP - RFP Template BCM and DRP - The Supreme Council of Information & Communication Technology ictqatar PUBLICATION DATE Document Reference This document should be used as an example of the contents of an RFP for business

More information

Business Continuity Management

Business Continuity Management Business Continuity Management Version 1 approved by SMG December 2013 Business Continuity Policy Version 1 1 of 9 Business Continuity Management Summary description: This document provides the rationale

More information

NHS Central Manchester Clinical Commissioning Group (CCG) Business Continuity Management (BCM) Policy. Version 1.0

NHS Central Manchester Clinical Commissioning Group (CCG) Business Continuity Management (BCM) Policy. Version 1.0 NHS Central Manchester Clinical Commissioning Group (CCG) Business Continuity Management (BCM) Policy Version 1.0 Document Control Title: Status: Version: 1.0 Issue date: May 2014 Document owner: (Name,

More information

EMBEDDING BCM IN THE ORGANIZATION S CULTURE

EMBEDDING BCM IN THE ORGANIZATION S CULTURE EMBEDDING BCM IN THE ORGANIZATION S CULTURE Page 6 AUTHOR: Andy Mason, BSc, MBCS, CITP, MBCI, Head of Business Continuity, PricewaterhouseCoopers LLP ABSTRACT: The concept of embedding business continuity

More information

PRACTICAL APPLICATIONS FOR BUSINESS CONTINUITY MANAGEMENT

PRACTICAL APPLICATIONS FOR BUSINESS CONTINUITY MANAGEMENT Karl D Bryant, MBCP, MBCI, CBCLA, PMP Senior Vice President PRACTICAL APPLICATIONS FOR BUSINESS CONTINUITY MANAGEMENT WWW.CHICAGOLANDRISKFORUM.ORG BUSINESS CONTINUITY MANAGEMENT PROGRAM OVERVIEW BUSINESS

More information

Business Intelligence & Business Continuity

Business Intelligence & Business Continuity Business Intelligence & Business Continuity BCM Maturity Curve April 22, 2013 COOP Systems Briefing 2 Chris Alvord, CEO, COOP Systems CBCP, MBCI, Former DRII Certified Trainer OCEG GRC, ISO 22301 Lead

More information

University of Glasgow. Policy for. Business Continuity Management

University of Glasgow. Policy for. Business Continuity Management University of Glasgow Policy for Business Continuity Management 1 Policy Statement The University of Glasgow is committed to delivering the highest possible quality of service to our students, and the

More information

Business Continuity Management Policy

Business Continuity Management Policy Governance: Business Committee Policy Owner: Chief Superintendent, Corporate Services Department: Corporate Services Policy Number: 002 Version: 3.0 Policy Writer: Business Continuity Co-ordinator Effective

More information

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14

More information

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745 ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan

More information

1.0 Policy Statement / Intentions (FOIA - Open)

1.0 Policy Statement / Intentions (FOIA - Open) Force Policy & Procedure Reference Number Business Continuity Management D269 Policy Version Date 23 July 2015 Review Date 23 July 2016 Policy Ownership Portfolio Holder Links or overlaps with other policies

More information

A GUIDE TO BUSINESS CONTINUITY PLANNING

A GUIDE TO BUSINESS CONTINUITY PLANNING A GUIDE TO BUSINESS CONTINUITY PLANNING Introduction The Civil Contingencies Act 2004 places a duty on Local Authorities to ensure that local businesses and voluntary sector organisations in their area

More information

EPRR: Toolkit Facilitator Guide

EPRR: Toolkit Facilitator Guide NHS England Business Continuity Management EPRR: Toolkit Facilitator Guide APPENDIX 1 1 [Intentionally Blank] INTRODUCTION The document has been designed to assist you to deliver the outcomes of the workshop

More information

Overview TECHIS60851. Manage information security business resilience activities

Overview TECHIS60851. Manage information security business resilience activities Overview Information security business resilience encompasses business continuity and disaster recovery from information security threats. As well as addressing the consequences of a major security incident,

More information

How To Plan A Crisis Management Program

How To Plan A Crisis Management Program Building a Security Conscious Business Continuity Management (BCM) Program Sam Stahl, CBCP, MBCI EMC Global Professional Services Program Manager [email protected] ASIS Singapore, 2014 Agenda Overview

More information

NOT PROTECTIVELY MARKED BUSINESS CONTINUITY. Specialist Operations Contingency Planning Business Continuity Manager 17.09.12

NOT PROTECTIVELY MARKED BUSINESS CONTINUITY. Specialist Operations Contingency Planning Business Continuity Manager 17.09.12 POLICY BUSINESS CONTINUITY Policy owners Policy holder Author Head of Services Specialist Operations Contingency Planning Business Continuity Manager Policy No. 132 Approved by Legal Services 17.09.12

More information

Staying In Business. A Business Continuity White Paper by. Paul O Brien and Gerard Joyce. LinkResQ Limited

Staying In Business. A Business Continuity White Paper by. Paul O Brien and Gerard Joyce. LinkResQ Limited Staying In Business A Business Continuity White Paper by Paul O Brien and Gerard Joyce LinkResQ Limited Contents: Introduction. 2 What is Business Continuity? 2 Loss Events = Opportunities for Disaster..

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning 4 Business Continuity Planning and Disaster Recovery Planning Basic Concepts 1. Business Continuity Management: Business Continuity means maintaining the uninterrupted availability of all key business

More information

Domain 1 The Process of Auditing Information Systems

Domain 1 The Process of Auditing Information Systems Certified Information Systems Auditor (CISA ) Certification Course Description Our 5-day ISACA Certified Information Systems Auditor (CISA) training course equips information professionals with the knowledge

More information

Effective risk management

Effective risk management Effective risk management Our holistic and disciplined risk management program is designed to mitigate risks at all levels of our business in order to protect our clients interests. 2 Vanguard > Effective

More information

Emergency Response and Business Continuity Management Policy

Emergency Response and Business Continuity Management Policy Emergency Response and Business Continuity Management Policy Owner: John Duffy, Registrar & Secretary Last updated: September 2012 Version: 04 Document control Date Version Author Changes To be populated

More information

Need to protect your business from potential disruption? Prepare for the unexpected with ISO 22301.

Need to protect your business from potential disruption? Prepare for the unexpected with ISO 22301. Need to protect your business from potential disruption? Prepare for the unexpected with. Why BSI? Keep your business running with and BSI. Our knowledge can transform your organization. For more than

More information

Business Continuity Management Planning Methodology

Business Continuity Management Planning Methodology , pp.9-16 http://dx.doi.org/10.14257/ijdrbc.2015.6.02 Business Continuity Management Planning Methodology Dr. Goh Moh Heng, Ph.D., BCCLA, BCCE, CMCE, CCCE, DRCE President, BCM Institute [email protected]

More information

BUILDING A SECURITY CONSCIOUS BUSINESS CONTINUITY MANAGEMENT (BCM) PROGRAM

BUILDING A SECURITY CONSCIOUS BUSINESS CONTINUITY MANAGEMENT (BCM) PROGRAM BUILDING A SECURITY CONSCIOUS BUSINESS CONTINUITY MANAGEMENT (BCM) PROGRAM SAM STAHL, CBCP, MBCI EMC GLOBAL PROFESSIONAL SERVICES PROGRAM MANAGER [email protected] ASIS SHANGHAI, 2015 1 AGENDA Overview

More information

Business Continuity and Risk Management. Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited

Business Continuity and Risk Management. Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited Business Continuity and Risk Management Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited What does Business Continuity mean? Business Continuity Management- Definition Business Continuity

More information

Business Continuity Management Policy

Business Continuity Management Policy Governance 1 Purpose The purpose of this policy is to communicate Business Continuity Management (BCM) framework, responsibilities and guiding principles for Victoria to effectively prepare for and achieve

More information

ISO 22301: Societal Security Terminology ISO 22313: BCMS Guidance ISO 22398: Exercises and Testing - Guidance

ISO 22301: Societal Security Terminology ISO 22313: BCMS Guidance ISO 22398: Exercises and Testing - Guidance The Impact of ISO 22301 Moving Your BCM Program to a Management System Implementing the Newly Approved International Business Continuity Management System Standard & Guidance Documents ISO 22301: Societal

More information

Global Statement of Business Continuity

Global Statement of Business Continuity Business Continuity Management Version 1.0-2014 Date October 18, 2014 Status Author Business Continuity Management (BCM) Page 1 of 8 Table of Contents 1. Credit Suisse Business Continuity Statement 3 2.

More information

Appendix 2 - Leicester City Council s Business Continuity Management Policy Statement and Strategy 2015. Business Continuity Policy Statement 2015

Appendix 2 - Leicester City Council s Business Continuity Management Policy Statement and Strategy 2015. Business Continuity Policy Statement 2015 Appendix 2 - Leicester City Council s Business Continuity Management Policy Statement and Strategy 2015 Business Continuity Policy Statement 2015 This Policy sets the direction for Business Continuity

More information

APICS INSIGHTS AND INNOVATIONS SUPPLY CHAIN RISK CHALLENGES AND PRACTICES

APICS INSIGHTS AND INNOVATIONS SUPPLY CHAIN RISK CHALLENGES AND PRACTICES APICS INSIGHTS AND INNOVATIONS SUPPLY CHAIN RISK CHALLENGES AND PRACTICES APICS INSIGHTS AND INNOVATIONS ABOUT THIS REPORT This report examines the role that supply chain risk management plays in organizations

More information

Risk Management Guidelines

Risk Management Guidelines Business Continuity Management Understanding Risk We live in an unpredictable world. No matter how effectively a business protects itself through insurance, there are some risks that cannot be anticipated,

More information

Using the GPGs to Solve Business Continuity Problems

Using the GPGs to Solve Business Continuity Problems Using the GPGs to Solve Business Continuity Problems Presented by: Brian Zawada FBCI US Chapter Board President www.thebci.org 1 What is the BCI? Founded in 1994, a Member-Owned, Not-for-Profit Professional

More information

Business Continuity Planning for Water Utilities: Guidance Document [Project #4319]

Business Continuity Planning for Water Utilities: Guidance Document [Project #4319] Business Continuity Planning for Water Utilities: Guidance Document [Project #4319] ORDER NUMBER: 4319 DATE AVAILABLE: June 2013 PRINCIPAL INVESTIGATORS: Jack Moyer, Rhiannon Kincaid, Kory Wilmot, Kate

More information

Business Continuity Management. Policy Statement and Strategy

Business Continuity Management. Policy Statement and Strategy Business Continuity Management Policy Statement and Strategy November 2011 Title Business Continuity Management Policy & Strategy Date of Publication: Cabinet Council Published by Borough Council of King

More information

Business Continuity Management

Business Continuity Management GENERALLY ACCESSIBLE Business Continuity Management Field Report from an Audit Point of View ISACA Swiss Chapter - After Hour Seminar 28 August 2006 - Urs Voigt - Group Internal Audit Disasters Happen

More information

Business Continuity Guidance for Suppliers & Contractors. Blackburn with Darwen Borough Council

Business Continuity Guidance for Suppliers & Contractors. Blackburn with Darwen Borough Council Business Continuity Guidance for Suppliers & Contractors For further information please contact: Rachel Hutchinson Civil Contingencies Manager Blackburn with Darwen Borough Council Contents 1. Introduction...

More information

TalentLink Disaster Recovery & Service Continuity

TalentLink Disaster Recovery & Service Continuity Technical Services Briefing Document TalentLink Disaster Recovery & Service Continuity Version 1.2 (January 2012) Contents Overview Planning for Service Continuity Disaster Recovery Process Business Continuity

More information

NHS 24 - Business Continuity Strategy

NHS 24 - Business Continuity Strategy NHS 24 - Strategy Version: 0.3 Issue Date: 20/09/2005 Status: Issued for Board Approval Status: draft Page 1 of 13 Table of Contents 1 INTRODUCTION...3 2 PURPOSE...3 3 SCOPE...3 4 ASSUMPTIONS...4 5 BUSINESS

More information

Appendix 1 - Leicester City Council s Business Continuity Management Strategy and Policy Statement - 2016

Appendix 1 - Leicester City Council s Business Continuity Management Strategy and Policy Statement - 2016 Appendix 1 - Leicester City Council s Business Continuity Management Strategy and Policy Statement - 2016 Policy Statement - 2016 This Policy sets the direction for Business Continuity Management at Leicester

More information

London Borough of Bromley. Executive & Resources PDS Committee. Disaster Recovery Plans for London Borough of Bromley

London Borough of Bromley. Executive & Resources PDS Committee. Disaster Recovery Plans for London Borough of Bromley Report No. DRR12/041 London Borough of Bromley PART 1 - PUBLIC Decision Maker: Executive & Resources PDS Committee Date: 4 th April 2012 Decision Type: Non-Urgent Non-Executive Non-Key Title: Disaster

More information

Update from the Business Continuity Working Group

Update from the Business Continuity Working Group 23 June 2014 Performance and Resources Board 19 To note Update from the Business Continuity Working Group Issue 1 The Business Continuity Working Group oversees the development, maintenance and improvement

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy St Mary Magdalene Academy V1.0 / September 2014 Document Control Document Details Document Title Document Type Business Continuity Policy Policy Version 2.0 Effective From 1st

More information

Birmingham CrossCity Clinical Commissioning Group. Business Continuity Management Policy

Birmingham CrossCity Clinical Commissioning Group. Business Continuity Management Policy Birmingham CrossCity Clinical Commissioning Group Business Continuity Management Policy Version V1.0 Ratified by Operational Development Group Date ratified 6 th November 2014 Name of originator / author

More information

ISO20000: What it is and how it relates to ITIL v3

ISO20000: What it is and how it relates to ITIL v3 ISO20000: What it is and how it relates to ITIL v3 John DiMaria; Certified Six Sigma BB, HISP BSI Product Manager; ICT (ISMS,ITSM,BCM) Objectives and Agenda To raise awareness, to inform and to enthuse

More information

The Resilient IT Infrastructure

The Resilient IT Infrastructure The Resilient IT Infrastructure Jeremy Wong Senior Vice President BCM Institute Republic Polytechnic, Block W4, Level 1, LR-W4B 25 November 2013 Jeremy Wong Senior Vice President Business Continuity Management

More information

Business Continuity & Crisis Management

Business Continuity & Crisis Management Group Standard Business Continuity & Crisis Management The need to plan and respond effectively is critical to the successful management of any crisis situation. Business Continuity Management is the holistic

More information