Emergency Planning for Essential Staff

Size: px
Start display at page:

Download "Emergency Planning for Essential Staff"

Transcription

1 October 2013 Emergency Planning for Essential Staff Larry G. Wlosinski, CDP, CISSP, CISM, CAP, CRISC, CISA, ITIL v3, CBCP Prepare for Disaster: Recover Faster. 1

2 Larry G. Wlosinski CDP, CISSP, CISM, CAP, CRISC, CISA, ITIL v3, CBCP Federal Government Experience (24+ yrs) EPA, NIH, CMS, DOJ, DHS, DOE, DIA, NOAA Commercial Industry Experience (14 yrs) Insurance, International & Interstate Banking, Collections, Small Business Consulting Experience: Computer Sciences Corp. (CSC) Section Manager Lockheed Martin IT Security Manager Booz Allen Hamilton (BAH) Associate And others Sr. IT Security Engineer, Project Manager, etc. IT Security Expertise: Policy, Procedure, Guidance, Standards, Templates, Checklists IT Security Assessments (C&A/A&A, Risk, Audit) Continuity Planning (OEP, BIA, ISCP, COOP, DRP, Devolution, etc.) Cloud Security Incident Response & Planning 2

3 Belated Reminder: September was National Preparedness Month Update your Continuity Plans: Contingency, Devolution, Disaster Recovery, COOP, etc. Conduct a Fire Drill at each location Test your Backup and Recovery Devices and Media Verify Command Center readiness Test Emergency Communication capability Update Calling Trees 3

4 Objectives Provide a better understanding of federal government emergency planning Review some federal government requirements Provide an understanding of the different plans Present an idea of team responsibilities Pass along some lessons learned Show how the various plans differ 4

5 AGENDA Orientation - Threats Present Emergency Framework National Essential Functions (NEFs) Types of Plans Discuss COOP & Devolution Plan Federal Continuity Directives (FCD 1 & 2) Elements & Building Blocks Document Contents Response Teams Devolution Plan Contents & Comparison 5

6 AGENDA (2) Discuss IT/S Contingency Planning Implementation/Activation Criteria Contents Teams Exercises/Testing Reporting Lessons Learned, AAR Review Contents of Other Plans COG BCP DRP BRP IRP OEP Pandemic 6

7 Federal Mandates National Security Presidential Directive 51 / Homeland Security Presidential Directive 20 (NSPD-51/HSPD-20) 5/9/2007 National Continuity Policy Executive Order /18/1988 Assignment of Emergency Preparedness Responsibilities National Continuity Policy Implementation Plan 8/31/2007 Federal Continuity Directives (FCD) 1 and 2 Feb

8 Sample Threats Terrorist Attack Biological Bomb/Explosion Chemical Civil Disturbance Fire (direct or nearby) Water Damage or Stoppage High Winds (Hurricane/Tornado) Power Loss/Utility Failure Hostage Situation Radiological Structure Damage Building Deterioration (electrical, pipes, roof) Telecommunications Loss Community Disaster Metropolitan Commuting Failure Requests for Shelter Airborne Crash Health/Pandemic Work stopage 8

9 Hierarchy of Business Continuity Management in United States Civilian Agencies 9

10 National Essential Functions (NEFs) 1. Ensuring the continued functioning of our form of government under the Constitution, including the functioning of the three separate branches of government. 2. Providing leadership visible to the Nation and the world and maintaining the trust and confidence of the American people. 3. Defending the Constitution of the United States against all enemies, foreign and domestic, and preventing or interdicting attacks against the United States or its people, property, or interests. 4. Maintaining and fostering effective relationships with foreign nations. 5. Protecting against threats to the homeland and bringing to justice perpetrators of crimes or attacks against the United States or its people, property, or interests. 6. Providing rapid and effective response to and recovery from the domestic consequences of an attack or other incident. 7. Protecting and stabilizing the Nation s economy and ensuring public confidence in its financial systems. Providing for critical Federal Government services that address the national health, safety, and welfare needs of the United States. 10

11 PMEFs and MEFs Primary Mission Essential Functions (PMEF) are agency functions that support the performance of the NEFs Functions that need to be continuous or resumed within 12 hours after an event and maintained for up to 30 days or until normal operations can be resumed. Mission Essential Functions (MEF) are government functions that support PMEFs Functions that enable an organization to provide vital services, exercise civil authority, maintain the safety of the public, and sustain the industrial/economic base during disruption of normal operations. 11

12 Types of Emergency Plans Continuity of Government (COG) Continuity of Operations Plan (COOP) Devolution Plan Business Continuity Plan (BCP) Information Technology/System Contingency Plan (CP) Disaster Recovery Plan (DRP) Business Resumption Plan (BRP) Incident Response Plan (IRP) Occupant Emergency Plan (OEP) Pandemic Plan 12

13 Relationships of Emergency Plans NIST SP

14 14

15 Types of Emergency Plans USA Continuity of Government (COG) Many plans Continuity of Operations Plan (COOP) FPC 65 Viable, executable plans for leadership, succession, and key personnel to ensure that a department/agency s essential functions continue to function as needed. Information System Contingency Plan NIST SP Management policy and procedures designed to maintain or restore business operations, including computer operations, possibly at an alternate location, in the event of emergencies, system failures, or disaster. Disaster Recovery Plan (DRP) A written plan for processing critical applications in the event of a major hardware or software failure or destruction of facilities. The DRP defines management policy and procedures designed to maintain or restore computer operations, at an alternate location, in the event of emergencies, system failures, or disaster. FCD 1 = Federal Continuity Directive 1, October 2012; FCD 2: July 2013 FPC 65 = Federal Branch Continuity of Operations (COOP), June 2004 NIST SP = Contingency Planning Guide for Information Technology Systems 15

16 Types of Emergency Plans (2) Incident Response Plan (IRP) The IRP provides a roadmap for implementing its incident response program based on the organization s policy. The plan lays out the resources, management support, metrics, training, and reporting that is needed to effectively maintain and mature an incident response capability. Business Resumption Plan (BRP) Addresses the resumption of normal business after the contingency event is over. Business Continuity Plan (BCP) BCPs are written at the office/component level, and they focus on sustaining the essential Business Functions. These plans address the overall recovery strategy for the organization and the steps to be taken immediately after a contingency event is declared. The BCP includes the OEP, ITCPs, IRPs, DRP, and BRP. Pandemic Plan Pandemic Plan emphasizes that continuing operations in the face of a pandemic may not entail an official COOP declaration and that maintaining functionality may be accomplished through contact intervention (social distancing) strategies, telework and other means, and may not require the relocation of the personnel. The Pandemic Plan also recognizes that relocation may be necessary due to a separate or concurrent event. 16

17 Types of Emergency Plans (3) Crisis Communications Plan Establishes internal and external communications procedures Occupant Emergency Plan (OEP) Outlines an organization s emergency response: evacuation, calling emergency authorities, etc. Risk Management Trains planners in a risk-based approach to identify vulnerabilities or gaps to facilities, personnel, operations, and resources, and recommends mitigation actions Devolution Plan FCD 1 To ensure the continuation of an agency s essential functions in the event that the agency s leadership and staff are unavailable or incapable of performing its essential functions from either its primary or alternate facilities 17

18 Communications Emergency Notification System (ENS) Telework (e.g., Cloud ) Hoteling (e.g., FEMA, BAH) Virtualize Vital Records Resources/Tools (GotoMeeting, Skype) PDA, Cell Phone Texting SharePoint Voice Wireless 18

19 Continuity of Operations Plan (COOP) & Devolution Plan SEC_RITY is not complete without U! 19

20 Federal Continuity Directive 1 (FCD 1) Continuity Evaluation Tool (CET) Federal Executive Branch National Continuity Program and Requirements Program Plans and Procedures (21 questions) Budgeting and Acquisition of Resources (8) Essential Functions (13) Orders of Succession (10) Delegations of Authority (9) Continuity Facilities (22) Continuity Communications (10) Vital Records Management (20) Human Capital (15) Test, Training, and Exercise Program (34) Devolution of Control and Direction (10) Reconstitution Operations (16) Operational Phases and Implementation (47) 20

21 Federal Continuity Directive 2 (FCD 2) Business Process Analysis (BPA) Implements the requirements of FCD 1, ANNEX C. It provides guidance and direction to Federal executive branch departments and agencies for identification of their Mission Essential Functions (MEFs) and potential Primary Mission Essential Functions (PMEFs). It includes guidance and checklists (7 worksheets) to assist departments and agencies in assessing their essential functions through a risk management process and in identifying potential PMEFs that support the National Essential Functions (NEFs) the most critical functions necessary to lead and sustain the nation during a catastrophic emergency. The FCD provides direction on the formalized process for submission of a department s or agency s potential PMEFs that are supportive of the NEFs. Includes guidance on the processes for conducting a Business Process Analysis (BPA) and Business Impact Analysis (BIA) for each of the potential PMEFs that assist in identifying essential function relationships and interdependencies, time sensitivities, threat and vulnerability analyses, and mitigation strategies that impact and support the PMEFs. 21

22 COOP Elements Essential Functions Delegation of Authority Orders of Succession Vital Records, Databases & Systems Interoperable Communications Contingency Staff and Responsibilities Calling Tree Devolution Reconstitution Tests, Training, and Exercises 22

23 Continuity of Operations Plan (COOP) I. Introduction II. Purpose III. Application and Scope IV. Mission Essential Functions (MEFs) V. Authorities and References VI. Concept of Operations (next slide) VII. COOP Planning Responsibilities VIII. Logistics I. Alternate Location II. Interoperable Communications IX. Test, Training, and Exercises X. Multi-Year Strategy & Program Management Plan (MYSPMP) I. Budget II. Maintenance XI. COOP Maintenance 23

24 COOP - Concept of Operations PHASE I ACTIVATION AND RELOCATION Decision Process Alert, Notification, and Implementation Process Leadership Orders of Succession Delegations of Authority Devolution Personnel Accountability Acquisition of Resources Human Capital PHASE II ALTERNATE FACILITY OPERATIONS Mission Critical Systems Vital Files, Records, and Databases PHASE III - RECONSTITUTION 24

25 COOP - Sample Appendices A. Authorities and References B. Business Impact Analysis (BIA) C. Emergency Personnel Rosters D. Go-Kit Recommendations E. Emergency Operational Checklists (Code Orange & Red) F. Human Capital (OPM Guidance) G. Family Support & Preparedness H. Emergency Telephone Numbers I. Alternate Location/Facility Information J. Maps and Evacuation Routes K. Facility and Risk Assessments L. Emergency Communications Procedures M. Multi-Year Strategy and Program Management Plan (MYSPMP) N. Test, Training, and Exercises 25

26 Emergency Teams Management: Confirms and communicates site relocation decision; Receives the Initial Disaster Alert; Verifies Status of Personnel; Verifies and Assesses the Damage in Coordination with the Damage Assessment Team; Decides Course of Action (Short vs. Long Term; Alternate Site/Location Assessment); Coordinates Communication (Across Teams; Intra-Team); Activates the ITCP; Plans expenditures (funding requirements & allocation) Damage Assessment: Determines amount and type of damage; Prepares initial estimate of time to restoration (this estimate will be used by management to determine whether to invoke COOP and/or relocate personnel to alternate facility); Performs continuous communication with management and others responsible regarding status. Network Restoration: Performs restoration of Services; Responsible for ensuring that all backbone architecture is restored and stable (Voice, Video, Data); Vendor Coordination Application Restoration: Responsible for restoration of all organization s essential applications once notified by network restoration team that network is stable and ready for application restoration process to begin. Applications include: , Web services, Customer applications, etc. Physical Security: Responsible for physical and logical security; Ensures that only authorized personnel have access to either the main site or the alternate recovery site as required System/Network Security: Enforcement of all security plans, policies and procedures during and after the return to normal operations; Monitors environment and may advise on recovery efforts (e.g., malicious software or activity, network security controls/safeguards, reporting) Help/Service Desk: Invokes the crisis management procedure; Maintains list of points of contact; Receives problem/event information; Determines scope of problem; Prepares service desk standard response; Informs the team of situation and provide response verbiage; Answers problem/service calls; Completes Remedy tickets; Tracks problem and resolution activity; Adjusts call response according to events 26

27 Exercise & Lessons Learned Exercise Eagle Horizon annual Require involvement of Essential Staff Lessons Learned Plan, plan, plan Prepare scenarios Test Calling Tree Write an After Action Report (AAR) Implement enhancements 27

28 COOP to Devolution Plan Comparison Phase COOP Devolution Concept Planning Implementation (including tests, training, and exercises) Relocate selected personnel to alternate facility COOP personnel will perform essential functions at alternate facility COOP personnel deploy to alternate facility and perform essential functions Transfer COOP mission to devolution site Devolution site personnel will perform essential functions Devolution site personnel perform essential functions 28

29 COOP -vs- Devolution Normal Operations MISSION PERSONNEL FACILITY COOP Activation MISSION PERSONNEL FACILITY Loss of Facility COOP Execution MISSION PERSONNEL ERS FACILITY Devolution of Operations MISSION PERSONNEL FACILITY Loss of Facility & Personnel Devolution Execution MISSION New PERSONNEL New FACILITY Reconstitution Potomac Forum, Ltd. Takes Organization back to a state of Normalcy 29

30 Devolution Plan 2. CONCEPT OF OPERATIONS 2.1 Disruption of Operations 2.2 Operational Sites 2.3 Operations Activation Conditions 2.4 Devolution Scenarios 2.5 Relationship between Continuity & Devolution of Operations 2.6 Threat Conditions & Potential Responses 2.7 Assumption of Essential Functions and Mission 2.8 Orders of Succession 2.9 Delegations of Authority 2.10 Personnel Recall Roster 3. ORGANIZATION AND RESPONSIBILITIES 3.1 Responsibilities of Devolution Working Group 3.2 Responsibilities of Devolution Emergency Response Group (DERG) 3.3 Organization 30

31 Devolution Plan 4. DEVOLUTION OF OPERATIONS IMPLEMENTATION 4.1 Readiness & Preparedness 4.2 Activation & Transfer of Authority 4.3 Devolution Operations 4.4 Reconstitution 5. SUPPORT REQUIREMENTS 5.1 Personnel Coverage Procedures During DERG Activations 5.2 Vital Records Management 5.3 Pre-Positioned Information 5.4 Continuity Communications 5.5 Tests, Training, & Exercise Program 5.6 Security 5.7 Budgeting and Acquisition 5.8 Human Capital Appendices: MEFS Resource Requirements Devolution of Operations Sites Devolution Counterparts Acronyms Threat Scenarios 31

32 Information System Contingency Plan (ISCP) Prepare for Disaster: Recover Faster. 32

33 Criteria Needed to Implement ISCP Safety of personnel Service disruption that adversely affects the mission Extended power disruption Catastrophic network event Normal troubleshooting / restoration procedures are not sufficient to repair the outage in a timely period Unable to support the mission essential functions 33

34 Contingency Plan Outline 1. Introduction 2. Concept of Operations 3. Notification and Activation (next 3 slides) 4. Recovery Operations 5. Reconstitution (Return to Normal) 6. Testing Plans 7. Training Scenarios and Exercises 8. Lessons Learned 9. Plan Maintenance 10. Appendices 34

35 ISCP Concept of Operations PHASE I ACTIVATION AND RELOCATION Decision Process Alert, Notification, and Implementation Process Declaring a Disaster Determine Impact & Severity Activating the Recovery Data Center Leadership Orders of Succession Delegations of Authority Devolution 35

36 ISCP Concept of Operations PHASE II: ALTERNATE FACILITY OPERATIONS Systems Recovery Priority Vital Files, Records, and Databases Recovery Teams 36

37 ISCP Concept of Operations PHASE III: RECONSTITUTION Planning Responsibilities Logistics Alternate Location Backup Media Storage Interoperable Communications Test, Training, & Exercises Plan Maintenance 37

38 ISCP Appendices (Suggested) A. Personnel Contact List B. Vendor Contact List C. Detailed Recovery Procedures D. Alternate Location/Facility Information E. System Validation Test Plan F. Alternate Storage Site and Telecommunications G. Diagrams (System and Input / Output) H. System Inventory I. Interconnections Table J. Test and Maintenance Schedule K. Associated Plans and Procedures L. Business Impact Analysis (BIA) M. Document Change Page 38

39 ISCP Exercise Phases Damage Assessment Recovery Reconstitution 39

40 Recovery Teams Essential Recovery Personnel Primary, Secondary, Tertiary Teams Functions Leadership Team Leads Subject Matter Experts (SMEs) Actual teams are assigned as required to restore essential functions/systems for example: Management Team Damage Assessment Team Server Restoration Team Application Restoration Team Network/Architecture Restoration Team Database (DB) Restoration Team (when applicable) Security Team Help/Service Desk Team 40

41 ISCP Testing Objectives Keep personnel assignments and notification/call lists current Acquaint new employees with responsibilities Verify backup storage procedures Verify primary and backup site have same configurations Train staff Test recovery procedures and checklists Identify and correct vulnerabilities Identify and mitigate new threats 41

42 Sample ISCP Scenario Variables Power outage Loss of equipment or data Loss of connectivity Unavailability/loss of staff; staff turnover Level of testing (one sample, partial, full) Stale documentation Contractual support issues Conflicting priorities Problems with on/offsite work environment Issues with alternate location 42

43 Lessons Learned Report 1. Component 2. System(s) Covered 3. Exercise/Test Date 4. Personnel Present/Participants 5. Scenario/Exercise Description 6. Results a. Description b. Impact c. Team Issues 7. Lessons Learned a. What Went Right? b. What Went Wrong? c. What should have been done differently? d. Preventative measures and recommendations e. Follow-up actions needed f. Items for revised ISCP 43

44 CP After Action Report (AAR) Executive Summary Exercise Overview Goals and Objectives Synopsis Exercise Analysis Lessons Learned Exercise Concerns Exercise Response Analysis Action Items & Recommendations Appendices Exercise Scenarios 44

45 Sec-UR-rity - You are at the center. Other Plans: Continuity of Government (COG) Business Continuity Plan (BCP) Disaster Recovery Plan (DRP) Business Resumption Plan (BRP) Incident Response Plan (IRP) Occupant Emergency Plan (OEP) Pandemic Plan 45

46 Continuity of Government (COG) - Many plans by sector Agriculture & Food Banking & Finance Chemical Commercial Facilities Communications Critical Manufacturing Dams Defense Industrial Base Emergency Services Energy Government Facilities Healthcare & Public Health Information Technology National Monuments & Icons Nuclear Reactors, Materials & Waste Postal & Shipping Transportation Systems Water 46

47 Business Continuity Plan (BCP) Business continuity planning reestablishment of critical business operations so that operations can continue If a disaster has rendered the business unusable for continued operations, there must be a plan to allow the business to continue to function 47

48 Disaster Recovery Plan (DRP) 1. Purpose and Scope 2. Objectives [e.g., Scale up and manage alternate site] 3. Assumptions 4. Criteria for Invoking DRP 5. Team Responsibilities 6. Emergency Procedures (Recovery Team) 7. Recovery Scenarios (Minor, Major) 8. Recovery Tasks/Activities by Team (Immediate, 3 Hours, 24 hours, Ongoing) 9. Command Center (Primary & alternate locations; Requirements) 10. Standby Facility (Location; Activation POC & Procedures) 11. Data Storage (Location, POC Information) 48

49 DRP (2) 12. Critical Applications (Classification, Prioritized, Time Est., Requirements) 13. Supplies for Standby Facility (Immediate needs; Where to obtain) 14. POC Information (Management, Teams, Vendors & Suppliers, Users) 15. Inventories Hardware: mainframe, server, workstations/pcs, disk & tape drives, printers, network equipment, non-computer Software: operating systems, utilities, application, data/backup 16. Supporting Documentation (Production schedules, policies, site plans, network diagrams, backup and restore procedures, first aid, OEP) 17. Testing and Training 18. Plan Maintenance (Cycle, records, distribution) 49

50 Business Resumption Plan (BRP) Government: Largely used by the government for focusing on specific essential functions within the organization. Industry: The business resumption plan addresses restoration of your business after an emergency. Different from the disaster recovery plan and business contingency plan, the BRP does not contain continuity procedures used during an emergency; instead it focuses on preventative measures and after the dust settles. The BRP helps you get your business back into full running order. 50

51 Sample Incident Response Plan (IRP) Purpose Scope Applicability Definitions Requirements for Incident Response Objectives and Measures of Effectiveness Organization and Structure Roles and Responsibilities Policies and Procedures: Pre-Incident Actions, Incident Recognition, Incident Reporting, Investigating and Reporting Data Loss Incidents, Incident Response Procedures Vulnerability Management Information Dissemination Control Compliance Requirements Appendices: POCs, Reporting Form(s) 51

52 Occupant Emergency Plan (OEP) Emergency Alarms Emergency Instructions for All Employees Evacuation Procedures Personnel Assignments Duties of Emergency Response Participants Cellular Phone and Pager Usage Shelter-In-Plan Appendices: Emergency Services & Utility Services Homeland Security Advisory System Evacuation Plan 52

53 Pandemic Plan 1. OPM Human Capital Planning for Pandemic Influenza 2. COOP Annex Pandemic Influenza 3. Response Stages 0-6 & Checklists 4. Government Purchase Card 5. Support of the Federal Response to a Pandemic Emergency 6. External Stockholder Communications 7. Response Stage Sample Messages 8. Contractor Management: Contractor Guidance During a Pandemic; Notice to Contractors; Emergency Acquisitions 9. Main Office Phone Numbers 10. Interoperable Communications; POC Lists 11. Accountability: Accountability Policy; Authority to Grant Administrative Leave Letter; Staff Accountability Worksheet 12. Non-Traditional Roles 13. Awareness Tools: Posters, Brochures, Web Sites, etc. 14. Vaccination Prioritization 15. Telework Program & Policy (Request Form & Agreement) 53

54 Appendices to Pandemic Plan PMEFs and MEFs Emergency Procurement Procedures Pandemic Response Procedures Pandemic Evaluation Tool Communications Preventative Measures Human Capital Guidance References Glossary and Acronyms 54

55 55

56 Boy Scout Motto: Be Prepared! 56

How To Plan For A Disaster

How To Plan For A Disaster Continuity Planning: Components, Process, & Resources Larry G. Wlosinski, CDP, CISSP, CISM, CISA, CAP, CRISC, ITIL, CBCP, CCSK October 2014 1 Definition - BCP A business continuity plan (BCP) is a plan

More information

SAMPLE IT CONTINGENCY PLAN FORMAT

SAMPLE IT CONTINGENCY PLAN FORMAT SAMPLE IT CONTINGENCY PLAN FORMAT This sample format provides a template for preparing an information technology (IT) contingency plan. The template is intended to be used as a guide, and the Contingency

More information

DEPARTMENT OF THE NAVY HEADQUARTERS UNITED STATES MARINE CORPS 3000 MARINE CORPS PENTAGON WASHINGTON, DC 20350 3000

DEPARTMENT OF THE NAVY HEADQUARTERS UNITED STATES MARINE CORPS 3000 MARINE CORPS PENTAGON WASHINGTON, DC 20350 3000 DEPARTMENT OF THE NAVY HEADQUARTERS UNITED STATES MARINE CORPS 3000 MARINE CORPS PENTAGON WASHINGTON, DC 20350 3000 MCO 3030.1 POC MARINE CORPS ORDER 3030.1 From : To: Commandant of the Marine Corps Distribution

More information

NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems

NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems Marianne Swanson NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY 1 Table Of Contents Introduction to NIST SP 800-34

More information

Federal Continuity Directive 1 (FCD 1)

Federal Continuity Directive 1 (FCD 1) Federal Continuity Directive 1 (FCD 1) November 6, 2007 Federal Continuity Directive 1 (FCD 1) 6, 2007 Federal Continuity Directive 1 Federal Executive Branch National Continuity Program and Requirements

More information

Continuity of Operations (COOP) Plan Template Instructions. Federal Emergency Management Agency 500 C ST, SW Washington, D.C.

Continuity of Operations (COOP) Plan Template Instructions. Federal Emergency Management Agency 500 C ST, SW Washington, D.C. Continuity of Operations (COOP) Plan Template Instructions Federal Emergency Management Agency 500 C ST, SW Washington, D.C. 20472 FEMA GUIDE INSTRUCTIONS This guide provides instructions for developing

More information

Why Should Companies Take a Closer Look at Business Continuity Planning?

Why Should Companies Take a Closer Look at Business Continuity Planning? whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters

More information

How To Prepare For A Disaster

How To Prepare For A Disaster Building an effective Tabletop Exercise Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 3/26/2013 #1 Continuity Plan Testing Flowchart 3/26/2013 #2 1 Ongoing Multi-Year

More information

Continuity of Operations Plan Template

Continuity of Operations Plan Template Continuity of Operations Plan Template Office of Water (4608-T) EPA 817-B-14-007 November 2014 Please note: The golden key sticky notes located throughout the template provide additional information and

More information

CONTINUITY OF OPERATIONS PLAN (COOP) Planning Guide and Outline

CONTINUITY OF OPERATIONS PLAN (COOP) Planning Guide and Outline Final CONTINUITY OF OPERATIONS PLAN (COOP) Planning Guide and Outline A Format For the State, Local,and Tribal Terrorities to Use in Continuity Preparedness Prepared By the New York State Office of Emergency

More information

Business Unit CONTINGENCY PLAN

Business Unit CONTINGENCY PLAN Contingency Plan Template Business Unit CONTINGENCY PLAN Version 1.0 (Date submitted) Submitted By: Business Unit Date Version 1.0 Page 1 1 Plan Review and Updates... 3 2 Introduction... 3 2.1 Purpose...

More information

Federal Continuity Directive 1 (FCD 1) Federal Continuity Directive 1 (FCD 1)

Federal Continuity Directive 1 (FCD 1) Federal Continuity Directive 1 (FCD 1) Federal Continuity Directive 1 (FCD 1) November 6, 2007 Federal Continuity Directive 1 (FCD 1) 6, 2007 Federal Continuity Directive 1 (FCD 1) Federal Executive Branch National Continuity Program and Requirements

More information

Comprehensive Emergency Management Plan (CEMP) Annex V CONTINUITY OF OPERATIONS PLAN (COOP)

Comprehensive Emergency Management Plan (CEMP) Annex V CONTINUITY OF OPERATIONS PLAN (COOP) Annex V CONTINUITY OF OPERATIONS PLAN (COOP) Milwaukee County Office of the Sheriff (MCSO) Division of Emergency Management Milwaukee County, ANNEX V CONTINUITY OF OPERATIONS PLAN (COOP) TABLE OF CONTENTS

More information

Continuity of Operations Plan Template and Instructions for Federal Departments and Agencies July 2011. [Department/Agency Name] [Month Day, Year]

Continuity of Operations Plan Template and Instructions for Federal Departments and Agencies July 2011. [Department/Agency Name] [Month Day, Year] Continuity of Operations Plan Template and Instructions for Federal Departments and Agencies July 2011 [Department/Agency Name] [Month Day, Year] [Department/Agency Name] [Street Address] [City, State

More information

RECONSTITUTION PLAN K-1

RECONSTITUTION PLAN K-1 RECONSTITUTION PLAN Reconstitution is restoring NOAA's ability to carry out all aspects of normal operations, the restoration of the capabilities that existed prior to the emergency. Reconstitution may

More information

Devolution of Operations Plan Template

Devolution of Operations Plan Template [D/A Graphic] Devolution of Operations Plan Template April 2013 [Organization Name] [Street Address] [City, State Zip Code] [Organization Symbol] This page intentionally blank. ii [Organization Name] Devolution

More information

Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services

Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 1 Today s Agenda Structure of Today s Discussion Set Objectives General overview of DR/BCP Exercise Assumptions Scenarios

More information

State of South Carolina Policy Guidance and Training

State of South Carolina Policy Guidance and Training State of South Carolina Policy Guidance and Training Policy Workshop All Agencies Business Continuity Management Policy June 2014 Agenda Questions & Follow-Up Policy Workshop Overview & Timeline Policy

More information

CONTINUITY OF OPERATIONS

CONTINUITY OF OPERATIONS Court Services and Offender Supervision Agency for the District of Columbia POLICY STATEMENT CONTINUITY OF OPERATIONS I. COVERAGE This Policy Statement applies to all Court Services and Offender Supervision

More information

Overview of how to test a. Business Continuity Plan

Overview of how to test a. Business Continuity Plan Overview of how to test a Business Continuity Plan Prepared by: Thomas Bronack Phone: (718) 591-5553 Email: [email protected] BRP/DRP Test Plan Creation and Exercise Page: 1 Table of Contents BCP/DRP Test

More information

CISM Certified Information Security Manager

CISM Certified Information Security Manager CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning 4 Business Continuity Planning and Disaster Recovery Planning Basic Concepts 1. Business Continuity Management: Business Continuity means maintaining the uninterrupted availability of all key business

More information

CONTINUITY OF OPERATIONS PLAN (COOP)

CONTINUITY OF OPERATIONS PLAN (COOP) CONTINUITY OF OPERATIONS PLAN (COOP) DEPARTMENT OF HUMAN SERVICES CHILD WELFARE SERVICES BRANCH JUNE 2012 CONTINUITY OF OPERATIONS PLAN Child Welfare Services Branch Prepared for: Child Welfare Services

More information

University Information Technology Services. Information System Contingency Plan Instructions

University Information Technology Services. Information System Contingency Plan Instructions University Information Technology Services Information System Contingency Plan Instructions Prepared by Victor Font UITS Business Continuity / Disaster Recovery Coordinator January 2013 Table of Contents

More information

U.S. Department of Energy Washington, D.C.

U.S. Department of Energy Washington, D.C. U.S. Department of Energy Washington, D.C. ORDER DOE O 150.1A Approved: SUBJECT: CONTINUITY PROGRAMS 1. PURPOSE. The purpose of this Order is: a. to assign and describe continuity roles and responsibilities

More information

Security Architecture. Title Disaster Planning Procedures for Information Technology

Security Architecture. Title Disaster Planning Procedures for Information Technology Category Applicability Title Disaster Planning Procedures for Information Technology All Public Entities (See the Applicability section below.) Standard - A degree or level of requirement that all jurisdictions

More information

2014 NABRICO Conference

2014 NABRICO Conference Business Continuity Planning 2014 NABRICO Conference September 19, 2014 6 CityPlace Drive, Suite 900 St. Louis, Missouri 63141 314.983.1200 1520 S. Fifth Street, Suite 309 St. Charles, Missouri 63303 636.255.3000

More information

Miami-Dade County, Florida Emergency Operations Center (EOC) (your Dept. name here instead of EOC) Continuity of Operations Plan (COOP) Template

Miami-Dade County, Florida Emergency Operations Center (EOC) (your Dept. name here instead of EOC) Continuity of Operations Plan (COOP) Template - Miami-Dade County, Florida Emergency Operations Center (EOC) (your Dept. name here instead of EOC) Continuity of Operations Plan (COOP) Template (Insert your department info here..) Miami-Dade County

More information

Western Intergovernmental Audit Forum

Western Intergovernmental Audit Forum Western Intergovernmental Audit Forum Business Continuity & Disaster Recovery Planning September 12, 2013 Presented by: City of Phoenix City Auditor Department Aaron Cook, Sr Internal Auditor IT Audit

More information

CITY OF RICHMOND CONTINUITY OF OPERATIONS (COOP) DEPARTMENT PLAN TEMPLATE

CITY OF RICHMOND CONTINUITY OF OPERATIONS (COOP) DEPARTMENT PLAN TEMPLATE CITY OF RICHMOND CONTINUITY OF OPERATIONS (COOP) DEPARTMENT PLAN TEMPLATE Version 2 February 2010 This template is derived from the Virginia Department of Emergency Management (VDEM) Local Government COOP

More information

PPSADOPTED: OCT. 2012 BACKGROUND POLICY STATEMENT PHYSICAL FACILITIES. PROFESSIONAL PRACTICE STATEMENT Developing a Business Continuity Plan

PPSADOPTED: OCT. 2012 BACKGROUND POLICY STATEMENT PHYSICAL FACILITIES. PROFESSIONAL PRACTICE STATEMENT Developing a Business Continuity Plan PROFESSIONAL PRACTICE STATEMENT Developing a Business Continuity Plan OCT. 2012 PPSADOPTED: What is a professional practice statement? Professional Practice developed by the Association Forum of Chicagoland

More information

Subject: Internal Audit of Information Technology Disaster Recovery Plan

Subject: Internal Audit of Information Technology Disaster Recovery Plan RIVERSIDE: AUDIT & ADVISORY SERVICES June 30, 2009 To: Charles Rowley, Associate Vice Chancellor Computing & Communications Subject: Internal Audit of Information Technology Disaster Recovery Plan Ref:

More information

Continuity of Operations Planning. A step by step guide for business

Continuity of Operations Planning. A step by step guide for business What is a COOP? Continuity of Operations Planning A step by step guide for business A Continuity Of Operations Plan (COOP) is a MANAGEMENT APPROVED set of agreed-to preparations and sufficient procedures

More information

Department of Defense INSTRUCTION. Reference: (a) DoD Directive 3020.26, Defense Continuity Programs (DCP), September 8, 2004January 9, 2009

Department of Defense INSTRUCTION. Reference: (a) DoD Directive 3020.26, Defense Continuity Programs (DCP), September 8, 2004January 9, 2009 Department of Defense INSTRUCTION SUBJECT: Defense Continuity Plan Development NUMBER 3020.42 February 17, 2006 Certified current as of April 27, 2011 Reference: (a) DoD Directive 3020.26, Defense Continuity

More information

Continuity of Operations Actions

Continuity of Operations Actions Continuity of Operations Actions Executive Summary California must be prepared to continue operations during any type of threat or emergency, and must be able to quickly and effectively resume essential

More information

Disaster Recovery and Business Continuity Plan

Disaster Recovery and Business Continuity Plan Disaster Recovery and Business Continuity Plan Table of Contents 1. Introduction... 3 2. Objectives... 3 3. Risks... 3 4. Steps of Disaster Recovery Plan formulation... 3 5. Audit Procedure.... 5 Appendix

More information

Why COOP? 6 Goals of COOP. 6 Goals of COOP. General Guidelines for COOP Capability. COOP Program Model 7 Phases. Phase 1: Initiate COOP program

Why COOP? 6 Goals of COOP. 6 Goals of COOP. General Guidelines for COOP Capability. COOP Program Model 7 Phases. Phase 1: Initiate COOP program Overview What is continuity of operations (COOP) planning? Business continuity planning the all hazard approach 466 Brian Butler Columbus Public Health, Office of Emergency Preparedness 6 goals of COOP

More information

Contingency Planning Guide for Information Technology Systems

Contingency Planning Guide for Information Technology Systems NIST Special Publication 800-34 Contingency Planning Guide for Information Technology Systems Recommendations of the National Institute of Standards and Technology Marianne Swanson, Amy Wohl, Lucinda Pope,

More information

Continuity Plan Template for Non-Federal Governments

Continuity Plan Template for Non-Federal Governments Continuity Plan Template for Non-Federal Governments [Department/Agency/Organization Name] [Month Day, Year] [Department/Agency/Organization Name] [Street Address] [City, State Zip Code] [Department/Agency/Organization

More information

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14

More information

Certified Disaster Recovery Engineer

Certified Disaster Recovery Engineer Cyber Security Training & Consulting Certified Disaster COURSE OVERVIEW 4 Days 32 CPE Credits $2,500 When a business is hit by a natural disaster, cyber crime or any other disruptive tragedy, how should

More information

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION Federal Financial Institutions Examination Council FFIEC Business Continuity Planning MARCH 2003 MARCH 2008 BCP IT EXAMINATION H ANDBOOK TABLE OF CONTENTS INTRODUCTION... 1 BOARD AND SENIOR MANAGEMENT

More information

Business Continuity Planning for Risk Reduction

Business Continuity Planning for Risk Reduction Business Continuity Planning for Risk Reduction Ion PLUMB [email protected] Andreea ZAMFIR [email protected] Delia TUDOR [email protected] Faculty of Management Academy of Economic Studies

More information

Table of Contents ESF-12-1 034-00-13

Table of Contents ESF-12-1 034-00-13 Table of Contents Primary Coordinating Agency... 2 Local Supporting Agencies... 2 State, Regional, and Federal Agencies and Organizations... 2 Purpose... 3 Situations and Assumptions... 4 Direction and

More information

Continuity Guidance Circular 2 (CGC 2)

Continuity Guidance Circular 2 (CGC 2) Continuity Guidance Circular 2 (CGC 2) Continuity Guidance for Non-Federal Governments: Mission Essential Functions Identification Process (States, Territories, Tribes, and Local Government Jurisdictions)

More information

Domain 3 Business Continuity and Disaster Recovery Planning

Domain 3 Business Continuity and Disaster Recovery Planning Domain 3 Business Continuity and Disaster Recovery Planning Steps (ISC) 2 steps [Har10] Project initiation Business Impact Analysis (BIA) Recovery strategy Plan design and development Implementation Testing

More information

Business Continuity Planning Toolkit. (For Deployment of BCP to Campus Departments in Phase 2)

Business Continuity Planning Toolkit. (For Deployment of BCP to Campus Departments in Phase 2) Business Continuity Planning Toolkit (For Deployment of BCP to Campus Departments in Phase 2) August 2010 CONTENTS: Background Assumptions Business Impact Analysis Risk (Vulnerabilities) Assessment Backup

More information

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic

More information

March 2007 Report No. 07-009. FDIC s Contract Planning and Management for Business Continuity AUDIT REPORT

March 2007 Report No. 07-009. FDIC s Contract Planning and Management for Business Continuity AUDIT REPORT March 2007 Report No. 07-009 FDIC s Contract Planning and Management for Business Continuity AUDIT REPORT Report No. 07-009 March 2007 FDIC s Contract Planning and Management for Business Continuity Results

More information

Business Continuity Plan

Business Continuity Plan Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions

More information

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP IT Disaster Recovery Plan Template By Paul Kirvan, CISA, CISSP, FBCI, CBCP Revision History REVISION DATE NAME DESCRIPTION Original 1.0 2 Table of Contents Information Technology Statement

More information

Ohio Conference for Payroll Professionals Disaster Recovery

Ohio Conference for Payroll Professionals Disaster Recovery Ohio Conference for Payroll Professionals Disaster Recovery Speaker Bruce E. Phipps CPP 2011 APA Payroll Man of the Year Principal Product Manager US Legislative Analyst ORACLE Corporation [email protected]

More information

CONTINUITY OF OPERATIONS PLAN TEMPLATE

CONTINUITY OF OPERATIONS PLAN TEMPLATE CONTINUITY OF OPERATIONS PLAN TEMPLATE For Long-Term Care Facilities CALIFORNIA ASSOCIATION OF HEALTH FACILITIES DISASTER PREPAREDNESS PROGRAM TABLE OF CONTENTS TABLE OF CONTENTS...2 SECTION 1: INTRODUCTION...3

More information

Continuity of Operations Plan (COOP) Guidelines for Skilled Nursing & Assisted Living Facilities (Name of Facility)

Continuity of Operations Plan (COOP) Guidelines for Skilled Nursing & Assisted Living Facilities (Name of Facility) Continuity of Operations Plan (COOP) Guidelines for Skilled Nursing & Assisted Living Facilities (Name of Facility) Spring 2014 Prepared by Gayle Sherman 165 Piney Creek Road, Reno VN 89511 (415)254 7267

More information

7 Homeland. ty Grant Program HOMELAND SECURITY GRANT PROGRAM. Fiscal Year 2008

7 Homeland. ty Grant Program HOMELAND SECURITY GRANT PROGRAM. Fiscal Year 2008 U.S. D EPARTMENT OF H OMELAND S ECURITY 7 Homeland Fiscal Year 2008 HOMELAND SECURITY GRANT PROGRAM ty Grant Program SUPPLEMENTAL RESOURCE: CYBER SECURITY GUIDANCE uidelines and Application Kit (October

More information

Subject: Critical Infrastructure Identification, Prioritization, and Protection

Subject: Critical Infrastructure Identification, Prioritization, and Protection For Immediate Release Office of the Press Secretary The White House December 17, 2003 Homeland Security Presidential Directive / HSPD-7 Subject: Critical Infrastructure Identification, Prioritization,

More information

ANNEX B COMMUNICATIONS

ANNEX B COMMUNICATIONS ANNEX B COMMUNICATIONS APPROVAL & IMPLEMENTATION Annex B Communications This emergency management plan is hereby approved. This plan is effective immediately and supersedes all previous editions. Jeff

More information

Business Continuity and Disaster Recovery Planning

Business Continuity and Disaster Recovery Planning Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services

More information

Disaster Recovery Planning Procedures and Guidelines

Disaster Recovery Planning Procedures and Guidelines Disaster Recovery Planning Procedures and Guidelines A Mandatory Reference for ADS Chapter 545 New Reference: 06/01/2006 Responsible Office: M/DCIO File Name: 545mal_060106_cd44 Information System Security

More information

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: [email protected] Fax: (718) 380-7322

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com Fax: (718) 380-7322 Business Continuity and Disaster Recovery Job Descriptions Table of Contents Business Continuity Services Organization Chart... 2 Director Business Continuity Services Group... 3 Manager of Business Recovery

More information

December 17, 2003 Homeland Security Presidential Directive/Hspd-7

December 17, 2003 Homeland Security Presidential Directive/Hspd-7 For Immediate Release Office of the Press Secretary December 17, 2003 December 17, 2003 Homeland Security Presidential Directive/Hspd-7 Subject: Critical Infrastructure Identification, Prioritization,

More information

LAWRENCE COUNTY, KENTUCKY EMERGENCY OPERATIONS PLAN ESF-13

LAWRENCE COUNTY, KENTUCKY EMERGENCY OPERATIONS PLAN ESF-13 LAWRENCE COUNTY, KENTUCKY EMERGENCY OPERATIONS PLAN LAW ENFORCEMENT AND SECURITY ESF-13 Coordinates and organizes law enforcement and security resources in preparing for, responding to and recovering from

More information

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand

More information

CERTIFIED DISASTER RECOVERY ENGINEER

CERTIFIED DISASTER RECOVERY ENGINEER CERTIFIED DISASTER RECOVERY ENGINEER KEY DATA COURSE OVERVIEW ACCREDITATION Course Title: C)DRE Duration: 4 days CPE Credits: 32 Class Format Options: Instructor-led classroom Live Online Training Computer

More information

Continuity Plan Template and Instructions for Non-Federal Governments

Continuity Plan Template and Instructions for Non-Federal Governments Continuity Plan Template and Instructions for Non-Federal Governments [Department/Agency/Organization Name] [Month Day, Year] [Department/Agency/Organization Name] [Street Address] [City, State Zip Code]

More information

STATE SUPPORT FUNCTION ANNEX 2 COMMUNICATIONS

STATE SUPPORT FUNCTION ANNEX 2 COMMUNICATIONS STATE SUPPORT FUNCTION ANNEX 2 COMMUNICATIONS PRIMARY AGENCIES: Department of Information and Innovation Department of Public Safety, Radio Technology Services SUPPORT AGENCIES: Agency of Transportation

More information

Business Continuity Planning 101. +1 610 768-4120 (800) 634-2016 www.strohlsystems.com [email protected]

Business Continuity Planning 101. +1 610 768-4120 (800) 634-2016 www.strohlsystems.com info@strohlsystems.com Business Continuity Planning 101 Presentation Overview What is business continuity planning Plan Development Plan Testing Plan Maintenance Future advancements in BCP Question & Answer What is a Disaster?

More information

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 AGENDA: Emergency Management Business Continuity Planning Q & A MONTH DAY, YEAR TITLE OF THE PRESENTATION 2 CANADIAN RED CROSS Disaster

More information

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK Federal Financial Institutions Examination Council FFIEC Business Continuity Planning BCP FEBRUARY 2015 IT EXAMINATION H ANDBOOK Table of Contents Introduction 1 Board and Senior Management Responsibilities

More information

BUSINESS CONTINUITY PLAN OVERVIEW

BUSINESS CONTINUITY PLAN OVERVIEW BUSINESS CONTINUITY PLAN OVERVIEW INTRODUCTION The purpose of this document is to provide Loomis customers with an overview of the company s Business Continuity Plan (BCP). Because of the specific and

More information

Continuity of Operations:

Continuity of Operations: Continuity of Operations: By Robert Marinelli The past twelve months have provided many challenges due to severe weather events. Massachusetts has withstood a major tropical storm, tornados, and several

More information

Table of Contents ESF-3-1 034-00-13

Table of Contents ESF-3-1 034-00-13 Table of Contents Primary Coordinating Agency... 2 Local Supporting Agencies... 2 State, Regional, and Federal Agencies and Organizations... 3 Purpose... 3 Situations and Assumptions... 4 Direction and

More information

Technology Recovery Plan Instructions

Technology Recovery Plan Instructions State of California California Information Security Office Technology Recovery Plan Instructions SIMM 5325-A (Formerly SIMM 65A) September 2013 REVISION HISTORY REVISION DATE OF RELEASE OWNER SUMMARY OF

More information

Hospital Emergency Operations Plan

Hospital Emergency Operations Plan Hospital Emergency Operations Plan I-1 Emergency Management Plan I PURPOSE The mission of University Hospital of Brooklyn (UHB) is to improve the health of the people of Kings County by providing cost-effective,

More information

NIST Special Publication 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems

NIST Special Publication 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems NIST Special Publication 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems Marianne Swanson Pauline Bowen Amy Wohl Phillips Dean Gallup David Lynes NIST Special Publication 800-34

More information

Disaster Preparedness & Response

Disaster Preparedness & Response 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 A B C E INTRODUCTION AND PURPOSE REVIEW ELEMENTS ABBREVIATIONS NCUA REFERENCES EXTERNAL REFERENCES Planning - Ensuring

More information

Standard Operating Procedure Contingency Planning Guidance

Standard Operating Procedure Contingency Planning Guidance Standard Operating Procedure Contingency Planning Guidance Version Date: 20080702 Effective Date: 20080707 Expiration Date: 20110707 Responsible Office: Office of the Chief Information Officer 1 Document

More information

Evaluating and Improving Your Business Continuity Plan

Evaluating and Improving Your Business Continuity Plan Evaluating and Improving Your Business Continuity Plan As presented to the Northeast Florida IIA Chapter January 23, 2015 Contact Information Karen Weir, MAC, CISA, CBCP Manager [email protected]

More information

NIST Special Publication 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems

NIST Special Publication 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems NIST Special Publication 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems Marianne Swanson Pauline Bowen Amy Wohl Phillips Dean Gallup David Lynes NIST Special Publication 800-34

More information

Fire Department Guide. Creating and Maintaining Business Continuity Plans (BCP)

Fire Department Guide. Creating and Maintaining Business Continuity Plans (BCP) Fire Department Guide Creating and Maintaining Business Continuity Plans (BCP) Business Continuity Planning Components Index: Introduction Getting Started Section 1 1. Assign departmental business continuity

More information

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION Disaster Recovery Testing Is Being Adequately Performed, but Problem Reporting and Tracking Can Be Improved May 3, 2012 Reference Number: 2012-20-041 This

More information

BUSINESS CONTINUITY PLAN

BUSINESS CONTINUITY PLAN How to Develop a BUSINESS CONTINUITY PLAN To print to A4, print at 75%. TABLE OF CONTENTS SUMMARY SUMMARY WHAT IS A BUSINESS CONTINUITY PLAN? CHAPTER PREPARING TO WRITE YOUR BUSINESS CONTINUITY PLAN CHAPTER

More information

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS DIRECTORATE OF BANKING SUPERVISION AUGUST 2009 TABLE OF CONTENTS PAGE 1.0 INTRODUCTION..3 1.1 Background...3 1.2 Citation...3

More information

Massachusetts Institute of Technology. Functional Area Recovery Management Team Plan Development Template

Massachusetts Institute of Technology. Functional Area Recovery Management Team Plan Development Template Massachusetts Institute of Technology Functional Area Recovery Management Team Plan Development Template Public Distribution Version For further information, contact: Jerry Isaacson MIT Information Security

More information

ANNEX 3 ESF-3 - PUBLIC WORKS AND ENGINEERING. SC Budget and Control Board, Division of Procurement Services, Materials Management Office

ANNEX 3 ESF-3 - PUBLIC WORKS AND ENGINEERING. SC Budget and Control Board, Division of Procurement Services, Materials Management Office ANNEX 3 ESF-3 - PUBLIC WORKS AND ENGINEERING PRIMARY: SUPPORT: SC Budget and Control Board, Division of Procurement Services, Materials Management Office Clemson University Regulatory and Public Service

More information

THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST. Business Continuity Plan

THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST. Business Continuity Plan THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST Business Continuity Plan June 2012 Purpose The purpose of this Business Continuity Plan ( BCP ) is to define the strategies and the plans which

More information