Business Continuity Plan Assessment Tool v1.0

Size: px
Start display at page:

Download "Business Continuity Plan Assessment Tool v1.0"

Transcription

1 Appendix 5 Annex F To NSERP Business Continuity Plan Assessment Tool v1.0 Continuity Plan Assessment Tool v1.0.doc Page 1 of 17

2 Business Continuity Plan Assessment Tool v1.0 This tool is designed to assess an organization s business continuity plan. Assessment categories include 1) Plan Authority, 2) Plans, 3) Plan Resources, 4) Training, Exercising & Validation, and 5) Maintenance. The assessment process is focused at a non-detailed level and addresses what is considered to be key elements of the various categories. This tool was developed based upon: The EMO NS Business Continuity Management Guide v1.0 The Nova Scotia Draft Standard for Business Continuity Management The Business Continuity Institute 2007 Good Practice Guidelines How to Use This Document Key Issues / Questions Items which should be evident within the organization s business continuity plan. These may be considered a minimum standard to be compliant with what is expected of an organization s plan. Assessment Options (Y, P, N, NA). Y = The item exists. P = The item partially exists. N = The item does not exist. NA = The item is not applicable. Examples of evidence that would support a positive assessment - The examiner may use the examples listed in this column to support the selection of an appropriate assessment option and supporting comments if required. Comments Detailed explanation of findings identifying issues requiring attention. Recommendations Directions for plan improvement and compliance with established criteria. Continuity Plan Assessment Tool v1.0.doc Page 2 of 17

3 1.0 Plan Authority This section reviews plan authority. Any plan developed to support an effective response to a business continuity event requires the authority to do so. This authority must be provided from the most senior level of the organization and be evident within the process. Item Key Issues / Questions Y P N NA Examples of evidence that would support a positive assessment Has senior management provided the authority to support an effective response to a business continuity event? Senior management has provided authority by indicating the authorization to do so with a written statement and / or signature Has senior management assigned responsibility for a business continuity response to identified individuals in the organization? Is the authority for the business continuity plan and response clearly evident in the plan(s)? Individuals with various BCM response responsibilities have been identified within various response based documents where appropriate. Authority for the plan and response is written in each of the plan documents. Section 1.1 Comments: Section 1.1 Recommendations: Continuity Plan Assessment Tool v1.0.doc Page 3 of 17

4 2.0 Plans Providing for an effective response to an organization wide business continuity event may require the invoking of an organization s incident management plan, crisis communications plan and business continuity plan(s). This section reviews various aspects of the incident management plan, crisis communications plan and business continuity plan(s). The review for each section is at a non-detailed level and focuses on the major elements of the various plans The incident management plan defines how the strategic issues of a incident affecting the organization would be addressed and managed by the executive team. The crisis communications plan defines how communications with the key stakeholders will be managed. The business continuity plan addresses the business disruption, interruption or loss from the initial response to the point at which normal business operations are resumed. Continuity Plan Assessment Tool v1.0.doc Page 4 of 17

5 2.1 Incident Management Plan This section reviews aspects of the organization s incident management plan. Item Key Issues / Questions Y P N NA Examples of evidence that would support a positive assessment Does the organization have an incident management plan? The organization will show evidence of a written plan for use by senior management to respond to business continuity events Does the plan identify a senior management team member who has been appointed as the owner of the plan? A member of the senior management team has been identified within the plan as the owner. Typically this is the DM or some other senior official Have the scope and the objectives of the The scope and the objectives have been clearly identified. This will plan been identified? Are the people, roles and responsibilities of the incident management team identified within the plan? Are various all hazards and hazard specific plan options identified and addressed within the plan? Does the incident management plan identify contact lists for key employees, suppliers, service providers, etc.? Does the incident management plan have an operations centre identified? Does the incident management plan identify a reliable mechanism by which to communicate? Are the appropriate people aware of the incident management plan and are they identified? Does the incident management plan document the key personnel, resources, services and actions required to implement and manage a response? include what is covered by the plan and what is not. Each person who is on the IMT is identified in the plan along with their role and responsibilities. Plan is written from an all hazards approach. Addresses loss of facilities, IT, Data, staff, equipment, services, supplies, utilities. Addresses certain hazard specific options where required based on a TRVA. Contact lists for key employees, suppliers, service providers are included. Names, telephone numbers, cell numbers and fax numbers are listed. A place to setup and manage the emergency has been identified. A primary and alternate form of communications has been identified. A distribution list has been created. Each person on the list has been sent the most current version of the plan. Key personnel, resources, services and actions required to implement and manage a response have been clearly identified. Continuity Plan Assessment Tool v1.0.doc Page 5 of 17

6 Has the incident management plan been signed off by the senior management team? The senior management team has physically signed the document to indicate that they are aware of it and accept its contents. Section 2.1 Comments: Section 2.1 Recommendations: Continuity Plan Assessment Tool v1.0.doc Page 6 of 17

7 2.2 Crisis Communications Plan This section reviews aspects of the organization s crisis communications plan. The crisis communications plan defines how communications with the key stakeholders will be managed. The following assessment is based on a corporate crisis communications plan. Item Key Issues / Questions Y P N NA Examples of evidence that would support a positive assessment Does the organization have a crisis communications plan? A crisis communications plan has been written based upon the template created by Communications Nova Scotia Does the plan have stated goals / Goals and objectives of the plan are clearly stated. objectives? Are the crisis communications team members, roles and responsibilities identified and assigned? Crisis communications team members, roles and responsibilities have been identified and assigned. Names and contact information is found within the plan Are key spokespeople identified? Names of key spokes people, their contact info and subject matter expertise have been identified Does the plan identify/explain a situation A process to asses the situation has been identified in the plan. assessment procedure? Is a location for the team to operate identified within the plan? A physical space for the team to setup has been secured and identified in the plan Does the plan identify/explain a The plan describes a generic process to develop key messages for mechanism to develop key messages? Does the plan identify/explain procedures for informing internal and external audiences? Does the plan identify/explain the process for media monitoring? Does the plan identify/explain the process to deal with rumor control? Does the plan identify/explain a process to track activity? Does the plan identify/explain the process for follow-up and evaluation? an event. Internal and external audiences have been identified and procedure for getting key messages to each have been identified and documented in the plan. Media monitoring processes have been identified and documented in the plan. A process to deal with rumors has been identified and documented in the plan.?????have been identified and documented in the plan. A process for follow-up and evaluation has been identified and documented in the plan. Continuity Plan Assessment Tool v1.0.doc Page 7 of 17

8 Section 2.2 Comments: Section 2.2 Recommendations: Continuity Plan Assessment Tool v1.0.doc Page 8 of 17

9 2.3 Business Continuity Plan(s) This section reviews aspect of the organization s business continuity plan(s). It s assumed that most organizations will have multiple business continuity plans to support business resumption due to their size, complexity and geographic dispersion. A head office / regional office / satellite office structure may have independent plans at each location. Item Key Issues / Questions Y P N NA Examples of evidence that would support a positive assessment Does the organization have an all hazards business continuity plan(s) with an appropriate number of sub-plans to support the resumption of its most All hazards approach, specific hazards addressed, emergency management organizational structures, identified urgent programs/services. Addresses loss of staff, data, IT, services, utilities, equipment, supplies, major impacts to the organization. urgently required programs/services? Does the plan(s) identify urgently BCP lists urgently required programs/services, program/services required programs/services? Does the plan(s) identify action steps to resume urgently required programs/services? Does the plan identify the members and the roles responsibilities of the BCM Response Team? Does the plan(s) identify the owner/custodian of the plan(s)? Does the plan(s) identify its scope and objectives? Does the plan(s) identify/explain assumptions been documented? Does the plan(s) identify a document history? Does the plan(s) identify/explain a confidentiality notification? Does the plan(s) identify a distribution list? Does the plan(s) identify/explain a purpose statement? indicate resumption priority Discrete action steps to resume an interrupted service have been documented, easy to use, may be actionable by someone with appropriate knowledge/skills Each role and responsibility for the team is identified. Members of the team with contact info is identified, subject matter experts identified. Each plan has a named custodian with responsibility for the plan. Each plan has a clearly define scope which identifies the aspects of the organization covered by the plan. Plan assumptions are listed Document history including date, author, revision notes, other explanations of what has changed Underscores the importance of maintaining confidentiality of private information contained within BC plans List of who receives the documents and updates The purpose of the plan is stated and addresses the needs of the department in relation to it s overall BCP. Continuity Plan Assessment Tool v1.0.doc Page 9 of 17

10 Does the plan(s) identify a policy statement? Policy statement supporting the plan that provides for authority and direction on the plan Does the plan(s) identify/explain emergency response instructions? Instructions detailing who to call with regards to health, fire, policing or other situations requiring an emergency response from a first responding agency Does the plan(s) identify/explain an incident declaration process? Process to declare an incident as actionable under the scope of the BCP Does the plan(s) identify/explain a BCP Who is responsible for activating the BCP and what should they do activation procedure? Does the plan(s) identify/explain a notification procedure? Call tree identified, who should be notified of what when an event happens Does the plan(s) identify/explain reporting requirements? How internal reporting will happen, scheduled reports, who will receive what info Does the plan(s) identify/explain which programs / services which require an Identifies which programs/services require an alternate work place strategy due to their urgent status. alternate relocation strategy? Does the plan(s) identify/explain the alternate relocation strategy for those Detailed explanation of alternate work relocation strategy for those programs/services requiring one. programs / services that require one? Does the plan(s) identify/explain emergency services contact information? Contact numbers for emergency services providers and services they would be expected to supply Does the plan(s) identify/explain Employee contact lists are within the plan employee contact information? Does the plan(s) identify/explain supplier contact information? Supplier contact info is within the plan, names, telephone numbers, business names Does the plan(s) identify/explain how damage assessment will be handled? for damage assessment, overview of the process Does the plan(s) identify/explain occupational health and safety issues for OH&S issues, overview of the process may be addressed? Does the plan(s) identify/explain security issues may be addressed? for safety issues, overview of the security issues addressed Does the plan(s) identify/explain how IT issues may be addressed? for IT and disaster recovery, overview of the process Does the plan(s) identify/explain how Continuity Plan Assessment Tool v1.0.doc Page 10 of 17

11 telecommunications issues may be addressed? Does the plan(s) identify/explain how human resources issues may be addressed? Does the plan(s) identify/explain how finance issues may be addressed? Does the plan(s) identify/explain how legal / regulatory issues may be addressed? Does the plan(s) identify/explain how insurance issues may be addressed? Does the plan(s) identify/explain how salvage and restoration issues may be addressed? Does the plan(s) describe commonly used acronyms? Does the plan(s) identify/explain define key terminology? Have the plan(s) been signed off by the senior management team? for telecom issues, overview of the process, how phones will be redirected in case of emergency for HR issues, overview of the process, how HR issues will be addressed for financial issues, overview of the process, how financial issues will be addressed for legal/regulatory issues, overview of the process, how legal/regulatory issues will be addressed for insurance issues, overview of the process, how insurance issues will be addressed for salvage/issues, overview of the process, how HR issues will be addressed Commonly used acronyms are listed with their corresponding definition. Key terminology is listed and explained. Senior management has signed off on the plan. Section 2.3 Comments: Section 2.3 Recommendations: Continuity Plan Assessment Tool v1.0.doc Page 11 of 17

12 3.0 Plan Resources This section reviews aspects of the organization s business continuity plan resources. Resources need to be identified and must be accessible in support of the response to a business continuity event within the stated timeframes. A review of resources may be necessary in many areas. Some specialist resources may be required, both of equipment and personnel. Decisions are needed on competencies and skills required by staff and/or external specialists who may be used. Arrangements for mutual aid, for sharing specialist, knowledge, equipment, and for standardizing procedures and equipment between government organizations can increase cost effectiveness. Item Key Issues / Questions Y P N NA Examples of evidence that would support a positive assessment Are there clear procedures for authorizing business continuity event expenditures? Procedures for authorizing expenditures are documented. Names/positions of contact people are listed Do you have arrangements to ensure that contractors and/or other resources will, where relevant, support the organizations response to a BCM event, and be able to continue critical services in an business continuity event? Does the BCM plan identify the process for obtaining extra equipment/services in a major business continuity event? Are the resources required to respond to a business continuity event accessible within the stated timeframes? Is there a procedure for authorizing funds beyond a stated spending limit authority? Are mutual aid agreements/service level agreements in-place with partnering organizations? Is the authority to use specified resources stated? Are resource contact lists detailed in the plan? Procurement policy recognises the issue. Relevant contractors required to show adequate arrangements are in place. Advance arrangements made e.g. stand by contracts, other formal arrangements with suppliers, mutual aid. Regularly updated lists of suppliers and contact numbers, especially for after hours. RTOs are indicated Process identifies who is to be contacted and what must be documented to get access to additional funds MOUs / SLAs are included in document and signed by organization representatives. Statements form use of resources are explicit. Contact names and info for staff, suppliers, emergency response, etc. Continuity Plan Assessment Tool v1.0.doc Page 12 of 17

13 Section 3.1 Comments: Section 3.1 Recommendations: Continuity Plan Assessment Tool v1.0.doc Page 13 of 17

14 4.0 Training, Exercising and Validation This section reviews aspects of the organization s business continuity plan exercising and validation. Well designed exercises, plus reviews of how the business continuity event plan and procedures perform in actual incidents, are often the only way of testing plan outcomes. (Exercises are taken to include table top as well as live exercises). Exercises can act as a training activity as well as (but not always at the same time as) a method of plan validation, so it is important that the aims of any particular exercises are clear. External involvement in at least some exercise design, management and/or review is helpful. This gives an important external element of challenge. In addition the individual designing and running an exercise cannot effectively test their own reactions, which weakens the value of exercises if they are always run by a organization s own business continuity event management coordinator/planning team. There should always be a review/debrief after an exercise or incident, involving all players; and a organization/remo should be able to show that actions have been taken, if necessary, as a result of this. 4.1 Training Item Key Issues / Questions Y P N NA Examples of evidence that would support a positive assessment Do the plan(s) have a training strategy that covers all those who have responsibilities under business continuity management? Training needs analysis and records of trained staff. Training strategy. Structured annual training program. Program of continuous professional development for BCM coordinator and planning committee If individuals at your organization have a specialized skill/training in business continuity event management, with a regional application, do you have a process in place to ensure their training is current? Does your department training program align with provincial training program? Do you share training with partners and neighbouring organizations where appropriate? Are training opportunities promoted to individuals who may need the training and to their managers? Do you evaluate the quality and effectiveness of training provided? Training records. Formal arrangements with region. Shared personnel resources e.g. business continuity event site manager, business continuity event public information officer, EOC Manager etc. Discussed with provincial EMO training unit. Joint training timetables. Joint local training and exercises program. Program discussed with neighbouring departments. Shared training calendar. Appropriate advertising material (leaflets, posters, calendars etc). Aims set for training. Feedback sought from trainees and line managers on achievement of aims and on the quality of training. Continuity Plan Assessment Tool v1.0.doc Page 14 of 17

15 Section 4.1 Comments: Section 4.1 Recommendations: Continuity Plan Assessment Tool v1.0.doc Page 15 of 17

16 4.2 Exercising and Validation Item Key Issues / Questions Y P N NA Examples of evidence that would support a positive assessment Are all business continuity plans covered by a regular exercise program and subsequent debriefing? Rolling program of exercises for both all hazards plans as well as hazard specific plans. Notes from debriefing/review meeting held after every exercise Is there a system of quality control for exercises, including reviewing achievement against aims? Are the conclusions of exercises /incident debriefs used where relevant to improve plans? Feedback arrangements. Participant feedback covers aims and whether achieved and quality. Occasional external reviews. Notes of debriefing meeting after all exercises/incidents. Action plans. Section 4.2 Comments: Section 4.2 Recommendations: Continuity Plan Assessment Tool v1.0.doc Page 16 of 17

17 5.0 Maintenance This section reviews aspects of the organization s business continuity plan maintenance. Item Key Issues / Questions Y P N NA Examples of evidence that would support a positive assessment Does the plan(s) have a maintenance process? A plan maintenance process is identified within the plan documentation Does the plan identify/explain how it is Details on how the plan is to be maintained is evident. to be maintained? Does the plan(s) identify/explain who is the person/people to maintain it? The various individuals who are responsible for plan maintenance are identified Does the plan identify/explain the maintenance schedule and/or triggers? Plan updates are based upon a specific schedule and /or when certain trigger events occur such as staff change, technology update, etc. Section 5.1 Comments: Section 5.1 Recommendations: Continuity Plan Assessment Tool v1.0.doc Page 17 of 17

Business Continuity Management Program Development Guide

Business Continuity Management Program Development Guide Business Continuity Management Program Development Guide Prepared by The NS Emergency Management Office, Winter 2012 Version 1.1 Page 2 of 24 Document Revision History Date Author Revision Notes Fall 2011

More information

emergency response? 1.1e Has the municipality appointed an Emergency Planning Committee, in accordance with the Emergency Management Act?

emergency response? 1.1e Has the municipality appointed an Emergency Planning Committee, in accordance with the Emergency Management Act? 1. Overview: Municipal Responsibilities Aim: Responding to emergencies is recognized as a municipal responsibility. There is no single structure for delivering the services covered by the Emergency Management

More information

External Supplier Control Requirements BCM

External Supplier Control Requirements BCM External Supplier Control Requirements BCM BCM Requirement Description BCM Tiers Recovery Time Objective Why this is important 1. Business Continuity Policy Supplier will have a documented Business Continuity

More information

MUNICIPALITIES EMERGENCY MANAGEMENT PROGRAM EVALUATION

MUNICIPALITIES EMERGENCY MANAGEMENT PROGRAM EVALUATION MUNICIPALITIES EMERGENCY MANAGEMENT PROGRAM EVALUATION 1 PREAMBLE The Emergency Management Office s (EMO) mission is to ensure the safety and security of Nova Scotians and their property by providing for

More information

Business Unit CONTINGENCY PLAN

Business Unit CONTINGENCY PLAN Contingency Plan Template Business Unit CONTINGENCY PLAN Version 1.0 (Date submitted) Submitted By: Business Unit Date Version 1.0 Page 1 1 Plan Review and Updates... 3 2 Introduction... 3 2.1 Purpose...

More information

State of South Carolina Policy Guidance and Training

State of South Carolina Policy Guidance and Training State of South Carolina Policy Guidance and Training Policy Workshop All Agencies Business Continuity Management Policy June 2014 Agenda Questions & Follow-Up Policy Workshop Overview & Timeline Policy

More information

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY This document outlines a set of policies and procedures for formalising a Business Continuity programme, and provides guidelines for developing, maintaining

More information

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard PUBLIC Version: 1.0 CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard (Approved by the Information Strategy and Governance Committee in December 2013; revision 1.1 approved by Chief

More information

How To Manage A Disruption Event

How To Manage A Disruption Event BUSINESS CONTINUITY FRAMEWORK DOCUMENT INFORMATION DOCUMENT TYPE: DOCUMENT STATUS: POLICY OWNER POSITION: INTERNAL COMMITTEE ENDORSEMENT: APPROVED BY: Strategic document Approved Manager Organisational

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy Summary: This policy sets out the structure for ensuring that the PCT has effective Business Continuity Plans in place in order to maintain its essential business functions during

More information

Business Continuity Policy and Business Continuity Management System

Business Continuity Policy and Business Continuity Management System Business Continuity Policy and Business Continuity Management System Summary: This policy sets out the structure for ensuring that the PCT has effective Business Continuity Plans in place in order to maintain

More information

NAIT Guidelines. Implementation Date: February 15, 2011 Replaces: July 1, 2008. Table of Contents. Section Description Page

NAIT Guidelines. Implementation Date: February 15, 2011 Replaces: July 1, 2008. Table of Contents. Section Description Page Recommended by Emergency Preparedness Committee: January 26, 2011 Recommended by President s Council: February 11, 2011 Approved by Executive Committee: February 14, 2011 NAIT Guidelines CS1.1 Emergency

More information

Business Continuity Management Policy

Business Continuity Management Policy Business Continuity Management Policy Business Continuity Policy Version 1.0 1 Version control Version Date Changes Author 0.1 April 13 1 st draft PH 0.2 June 13 Amendments in line with guidance PH 0.3

More information

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand

More information

CISM Certified Information Security Manager

CISM Certified Information Security Manager CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective

More information

Business Continuity Management Charter

Business Continuity Management Charter Province of Nova Scotia Business Continuity Management Charter Department, Agency or Commission Name Business Continuity Coordinator Name 3/14/2014 Program Charter for Business Continuity Management Program

More information

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic

More information

Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services

Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 1 Today s Agenda Structure of Today s Discussion Set Objectives General overview of DR/BCP Exercise Assumptions Scenarios

More information

BCP and DR. P K Patel AGM, MoF

BCP and DR. P K Patel AGM, MoF BCP and DR P K Patel AGM, MoF Key difference between BS 25999 and ISO 22301 ISO 22301 puts a much greater emphasis on setting the objectives, monitoring performance and metrics aligning BC to top management

More information

Update from the Business Continuity Working Group

Update from the Business Continuity Working Group 23 June 2014 Performance and Resources Board 19 To note Update from the Business Continuity Working Group Issue 1 The Business Continuity Working Group oversees the development, maintenance and improvement

More information

VICTOR KHANYE LOCAL MUNICIPALITY PLAASLIKE MUNISIPALITEIT. ICT Business Continuity Plan. DRAFT v0.1 Page 1 of 9

VICTOR KHANYE LOCAL MUNICIPALITY PLAASLIKE MUNISIPALITEIT. ICT Business Continuity Plan. DRAFT v0.1 Page 1 of 9 VICTOR KHANYE LOCAL MUNICIPALITY PLAASLIKE MUNISIPALITEIT ICT Business Continuity Plan Policy Number: Approved by Council: Resolution No: Review Date: DRAFT v0.1 Page 1 of 9 Contents 1 Purpose, scope and

More information

Business Continuity Management For Small to Medium-Sized Businesses

Business Continuity Management For Small to Medium-Sized Businesses Business Continuity Management For Small to Medium-Sized Businesses Produced by NORMIT and Norfolk County Council Resilience Team For an electronic copy of this document visit www.normit.org Telephone

More information

Guidance Note XGN XXX.1

Guidance Note XGN XXX.1 Guidance Note XGN XXX.1 Risk Assessment and Business Continuity Planning 1. This Guidance Note provides further detail on matters institutions should consider in assessing disruption scenarios and certain

More information

BUSINESS CONTINUITY PLAN

BUSINESS CONTINUITY PLAN BUSINESS CONTINUITY PLAN [Name of Team/Service/Organisation] [Insert Building Name and Address] [Insert date] Detailing arrangements for: Incident Management Business Continuity Recovery and Resumption

More information

BCM and DRP - RFP Template

BCM and DRP - RFP Template BCM and DRP - The Supreme Council of Information & Communication Technology ictqatar PUBLICATION DATE Document Reference This document should be used as an example of the contents of an RFP for business

More information

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14

More information

1.0 Policy Statement / Intentions (FOIA - Open)

1.0 Policy Statement / Intentions (FOIA - Open) Force Policy & Procedure Reference Number Business Continuity Management D269 Policy Version Date 23 July 2015 Review Date 23 July 2016 Policy Ownership Portfolio Holder Links or overlaps with other policies

More information

Business Continuity (Policy & Procedure)

Business Continuity (Policy & Procedure) Business Continuity (Policy & Procedure) Publication Scheme Y/N Can be published on Force Website Department of Origin Force Operations Policy Holder Ch Supt Head of Force Ops Author Business Continuity

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy St Mary Magdalene Academy V1.0 / September 2014 Document Control Document Details Document Title Document Type Business Continuity Policy Policy Version 2.0 Effective From 1st

More information

Unit Guide to Business Continuity/Resumption Planning

Unit Guide to Business Continuity/Resumption Planning Unit Guide to Business Continuity/Resumption Planning (February 2009) Revised June 2011 Executive Summary... 3 Purpose and Scope for a Unit Business Continuity Plan(BCP)... 3 Resumption Planning... 4 Assumptions

More information

Business Continuity Management Policy and Framework

Business Continuity Management Policy and Framework Management Policy and Framework Version: Produced by: Date Produced: Approved by: Updated: 7 University Manager with the assistance of the Operational Group 11 th March 2010 Steering Group (14 December

More information

Business Continuity Planning advice for Businesses with 50-250 employees

Business Continuity Planning advice for Businesses with 50-250 employees Business Continuity Planning advice for Businesses with 50-250 employees Where to begin? A business continuity plan should consist of a business and contingencies analysis. It needs to be developed by

More information

Developing a Sustainable Emergency Management Program. David E. Oliver Ed.D, CSP, CEM

Developing a Sustainable Emergency Management Program. David E. Oliver Ed.D, CSP, CEM Developing a Sustainable Emergency Management Program David E. Oliver Ed.D, CSP, CEM Key Points: Reflections on Disasters and Demons So You re the New Emergency Manager? ICS, EOP, ICP, EOC, and Other Acronyms

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning 4 Business Continuity Planning and Disaster Recovery Planning Basic Concepts 1. Business Continuity Management: Business Continuity means maintaining the uninterrupted availability of all key business

More information

Council Policy Business Continuity Management

Council Policy Business Continuity Management Policy Name: Business Continuity Management Council Policy Business Continuity Management ADOPTED BY COUNCIL: 19 th April 2016 DATE OF NEXT REVIEW: 18 th April 2020 RESPONSIBLE OFFICER: REFERENCES: Chief

More information

Enterprise South Liverpool Academy

Enterprise South Liverpool Academy Enterprise South Liverpool Academy Emergency and Crisis Management The sponsors mission is that the Enterprise South Liverpool Academy (ESLA) equips all members of its learning community with the values,

More information

Business Continuity Plans

Business Continuity Plans Version Number Issue 2 Business Continuity Policy Date Revision Complete Policy Owner Author Reason for Revision Proof Read April 2016 Business Improvement Manager Emma Earle, Business Services Officer

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy 1 NHS England INFORMATION READER BOX Directorate Medical Commissioning Operations Patients and Information Nursing Trans. & Corp. Ops. Commissioning Strategy Finance Publications

More information

Business Continuity Management

Business Continuity Management Business Continuity Management Standard Operating Procedure Notice: This document has been made available through the Police Service of Scotland Freedom of Information Publication Scheme. It should not

More information

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd BS 25999 Business Continuity Management By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd 1 Contents slide BSI British Standards 2006 BS 25999(Business Continuity) 2002 BS 15000

More information

CONTINUITY OF OPERATIONS PLAN TEMPLATE

CONTINUITY OF OPERATIONS PLAN TEMPLATE CONTINUITY OF OPERATIONS PLAN TEMPLATE For Long-Term Care Facilities CALIFORNIA ASSOCIATION OF HEALTH FACILITIES DISASTER PREPAREDNESS PROGRAM TABLE OF CONTENTS TABLE OF CONTENTS...2 SECTION 1: INTRODUCTION...3

More information

A Practical Approach to Business Impact Analysis

A Practical Approach to Business Impact Analysis A Practical Approach to Business Impact Analysis A Practical Approach to Business Impact Analysis Understanding the Organization through Business Continuity Management Ian Charters First published in

More information

Emergency Operations California State University Los Angeles

Emergency Operations California State University Los Angeles Business Continuity Plan Emergency Operations California State University Los Angeles 1. Objective & Scope 2. Definition of Disaster 3. Risk and Business Impact Analysis Summary 4. Business Continuity

More information

IT Disaster Recovery and Business Resumption Planning Standards

IT Disaster Recovery and Business Resumption Planning Standards Information Technology Disaster Recovery and Business IT Disaster Recovery and Business Adopted by the Information Services Board (ISB) on May 28, 1992 Policy No: Also see: 500-P1, 502-G1 Supersedes No:

More information

PPSADOPTED: OCT. 2012 BACKGROUND POLICY STATEMENT PHYSICAL FACILITIES. PROFESSIONAL PRACTICE STATEMENT Developing a Business Continuity Plan

PPSADOPTED: OCT. 2012 BACKGROUND POLICY STATEMENT PHYSICAL FACILITIES. PROFESSIONAL PRACTICE STATEMENT Developing a Business Continuity Plan PROFESSIONAL PRACTICE STATEMENT Developing a Business Continuity Plan OCT. 2012 PPSADOPTED: What is a professional practice statement? Professional Practice developed by the Association Forum of Chicagoland

More information

BUSINESS CONTINUITY & STRATEGY POLICY

BUSINESS CONTINUITY & STRATEGY POLICY BUSINESS CONTINUITY & STRATEGY POLICY Authorship: Chris Wallace, Information Governance Manager Committee Approved: Quality and Clinical Governance Committee Approved date: 1 Feb 2014 Review Date: Jan

More information

Why Should Companies Take a Closer Look at Business Continuity Planning?

Why Should Companies Take a Closer Look at Business Continuity Planning? whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters

More information

NHS Lancashire North CCG Business Continuity Management Policy and Plan

NHS Lancashire North CCG Business Continuity Management Policy and Plan Agenda Item 12.0. NHS Lancashire North CCG Business Continuity Management Policy and Plan Version 2 Page 1 of 25 Version Control Version Reason for update 1.0 Draft for consideration by Executive Committee

More information

Principles for BCM requirements for the Dutch financial sector and its providers.

Principles for BCM requirements for the Dutch financial sector and its providers. Principles for BCM requirements for the Dutch financial sector and its providers. Platform Business Continuity Vitale Infrastructuur Financiële sector (BC VIF) Werkgroep BCM requirements 21 September 2011

More information

The PNC Financial Services Group, Inc. Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program The PNC Financial Services Group, Inc. Business Continuity Program subsidiaries) 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis

More information

November 2007 Recommendations for Business Continuity Management (BCM)

November 2007 Recommendations for Business Continuity Management (BCM) November 2007 Recommendations for Business Continuity Management (BCM) Recommendations for Business Continuity Management (BCM) Contents 1. Background and objectives...2 2. Link with the BCP Swiss Financial

More information

Business Continuity Planning for Risk Reduction

Business Continuity Planning for Risk Reduction Business Continuity Planning for Risk Reduction Ion PLUMB ionplumb@yahoo.com Andreea ZAMFIR zamfir_andreea_ileana@yahoo.com Delia TUDOR tudordelia@yahoo.com Faculty of Management Academy of Economic Studies

More information

SAMPLE IT CONTINGENCY PLAN FORMAT

SAMPLE IT CONTINGENCY PLAN FORMAT SAMPLE IT CONTINGENCY PLAN FORMAT This sample format provides a template for preparing an information technology (IT) contingency plan. The template is intended to be used as a guide, and the Contingency

More information

BUSINESS CONTINUITY POLICY

BUSINESS CONTINUITY POLICY BUSINESS CONTINUITY POLICY Last Review Date Approving Body n/a Audit Committee Date of Approval 9 th January 2014 Date of Implementation 1 st February 2014 Next Review Date February 2017 Review Responsibility

More information

Oadby and Wigston Borough Council. Information and Communications Technology (I.C.T.) Section

Oadby and Wigston Borough Council. Information and Communications Technology (I.C.T.) Section Appendix 1 Oadby and Wigston Borough Council Information and Communications Technology (I.C.T.) Section Information Communication Technology Contingency and Disaster Recovery Plan Version 0.1 10/04/09

More information

Disaster Recovery Plan

Disaster Recovery Plan Disaster Recovery Plan Date: Revision: 8.0 EXTERNAL BCP PLAN PAGE 1 OF 12 Federal regulation states, and internal corporate policies require, that Penson Financial Services, Inc. (Penson) develop Business

More information

An Introduction to. Business Continuity Planning

An Introduction to. Business Continuity Planning An Introduction to Business Continuity Planning Company Profile Practical Experience European Head Office Extensive Client Base Established 1998 Expert Consultants Global Network Why BCP? I am often asked

More information

Business Continuity Plan Toolkit

Business Continuity Plan Toolkit Business Continuity Plan Toolkit March 2015 1 Contents The Template instructions for use... 2 Introduction... 3 What is the purpose of this toolkit?... 3 Why do you need a Business Continuity Plan?...

More information

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA 1 Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand

More information

University of Glasgow. Policy for. Business Continuity Management

University of Glasgow. Policy for. Business Continuity Management University of Glasgow Policy for Business Continuity Management 1 Policy Statement The University of Glasgow is committed to delivering the highest possible quality of service to our students, and the

More information

How To Prepare For A Disaster

How To Prepare For A Disaster Building an effective Tabletop Exercise Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 3/26/2013 #1 Continuity Plan Testing Flowchart 3/26/2013 #2 1 Ongoing Multi-Year

More information

Disaster Recovery Plan Documentation for Agencies Instructions

Disaster Recovery Plan Documentation for Agencies Instructions California Office of Information Security Disaster Recovery Plan Documentation for Agencies Instructions () November 2009 SCOPE AND PURPOSE The requirements included in this document are applicable to

More information

A Guide for School Board Education Continuity Planning

A Guide for School Board Education Continuity Planning A Guide for School Board Planning by Dave Jackson This resource outlines considerations and guidelines to assist school boards in business continuity planning. Included in the report are: Information regarding

More information

COMCARE BUSINESS CONTINUITY MANAGEMENT

COMCARE BUSINESS CONTINUITY MANAGEMENT COMCARE BUSINESS CONTINUITY MANAGEMENT Title Business Continuity Management Version 2.1 Authorised by Executive Committee Effective date Authorisation date 10/7/2012 10/7/2012 COMCARE BUSINESS CONTINUITY

More information

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014

www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 Agenda Key Definitions Risks Business Continuity Management Program BCM Capability Assessment Process BCM Value Proposition

More information

BUSINESS CONTINUITY MANAGEMENT REQUIREMENTS FOR SGX MEMBERS NEW RULES FOR INCLUSION IN SGX-ST RULES

BUSINESS CONTINUITY MANAGEMENT REQUIREMENTS FOR SGX MEMBERS NEW RULES FOR INCLUSION IN SGX-ST RULES BUSINESS CONTINUITY MANAGEMENT REQUIREMENTS FOR SGX MEMBERS NEW RULES FOR INCLUSION IN SGX-ST RULES New rule Current Rule Proposed Rule 4.6.21 Business Continuity Requirements The following requirements

More information

Technology Recovery Plan Instructions

Technology Recovery Plan Instructions State of California California Information Security Office Technology Recovery Plan Instructions SIMM 5325-A (Formerly SIMM 65A) September 2013 REVISION HISTORY REVISION DATE OF RELEASE OWNER SUMMARY OF

More information

Proposal for Business Continuity Plan and Management Review 6 August 2008

Proposal for Business Continuity Plan and Management Review 6 August 2008 Proposal for Business Continuity Plan and Management Review 6 August 2008 2008/8/6 Contents About Newton IT / Quality of our services. BCM & BS25999 Overview 2. BCM Development in line with BS25999 3.

More information

Business Continuity Management

Business Continuity Management Business Continuity Management Version 1 approved by SMG December 2013 Business Continuity Policy Version 1 1 of 9 Business Continuity Management Summary description: This document provides the rationale

More information

A Business Continuity Plan for Government. George Bomar Dianne Casey Texas Department of Licensing and Regulation

A Business Continuity Plan for Government. George Bomar Dianne Casey Texas Department of Licensing and Regulation A Business Continuity Plan for Government George Bomar Dianne Casey Texas Department of Licensing and Regulation A practiced logistical plan for how an organization will recover and restore partially or

More information

BUSINESS CONTINUITY PLAN

BUSINESS CONTINUITY PLAN How to Develop a BUSINESS CONTINUITY PLAN To print to A4, print at 75%. TABLE OF CONTENTS SUMMARY SUMMARY WHAT IS A BUSINESS CONTINUITY PLAN? CHAPTER PREPARING TO WRITE YOUR BUSINESS CONTINUITY PLAN CHAPTER

More information

NHS Durham Dales, Easington and Sedgefield Clinical Commissioning Group. Business Continuity Plan

NHS Durham Dales, Easington and Sedgefield Clinical Commissioning Group. Business Continuity Plan NHS Durham Dales, Easington and Sedgefield Clinical Commissioning Group Business Continuity Plan Page 1 Review To be done annually Author Chief Operating Officer Reviewer Head of Corporate Services Version

More information

Community and Built Environment Localities and Safer Communities Business Continuity Management Policy Andrew Fyfe

Community and Built Environment Localities and Safer Communities Business Continuity Management Policy Andrew Fyfe Community and Built Environment Localities and Safer Communities Business Continuity Management Policy Andrew Fyfe 4 Aug 14 Draft v4.4 TBC Resilience Team BCM Policy draft v4.4 1 4 Aug 2014 Statement of

More information

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745 ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan

More information

University of Glasgow. Business Continuity Management. Guidance Notes

University of Glasgow. Business Continuity Management. Guidance Notes University of Glasgow Business Continuity Management Guidance Notes 1 Contents Page 1 Introduction to Business Continuity Management 3 2 Roles and Responsibilities 4 3 Business Impact Analysis 5 4 Developing

More information

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1 AUDITING A BCP PLAN Thomas Bronack Auditing a BCP Plan presentation Page: 1 What are the Objectives of a Good BCP Plan Protect employees Restore critical business processes or functions to minimize the

More information

Company Management System. Business Continuity in SIA

Company Management System. Business Continuity in SIA Company Management System Business Continuity in SIA Document code: Classification: Company Project/Service Year Document No. Version Public INDEX 1. INTRODUCTION... 3 2. SIA S BUSINESS CONTINUITY MANAGEMENT

More information

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK BUSINESS CONTINUITY MANAGEMENT FRAMEWORK Document Author: Civil Contingencies Service - Authorised by the CCS Joint Management Board - Version 1.0. Issued December 2012 Page 1 FRAMEWORK STATEMENT Business

More information

Creating a Business Continuity Plan. What We ll Cover... What is a BCP? Micky Hogue, CRM

Creating a Business Continuity Plan. What We ll Cover... What is a BCP? Micky Hogue, CRM Creating a Business Continuity Plan Micky Hogue, CRM Sandia National Laboratories Albuquerque, NM 505-844-6640 Mlhogue@sandia.gov What We ll Cover... What is a Business Continuity Plan Why create a BCP?

More information

Business Continuity Management Policy and Plan

Business Continuity Management Policy and Plan Business Continuity Management Policy and Plan 1 Page No: Contents 1.0 Introduction 3 2.0 Purpose 3 3.0 Definitions 4 4.0 Roles, Duties & Responsibilities 4 4.1 Legal And Statutory Duties, Responsibilities

More information

Guideline - Business Continuity Plan

Guideline - Business Continuity Plan Guideline - Business Continuity Plan 1. Introduction: The Business Continuity Plan is a component of the Risk and Business Management suite. This suite includes: Risk Management including risk registers

More information

Business Continuity Policy

Business Continuity Policy Business Continuity Policy Page 1 of 15 Business Continuity Policy First published: Amendment record Version Date Reviewer Comment 1.0 07/01/2014 Debbie Campbell 2.0 11/07/14 Vicky Ryan Updated to include

More information

NOT PROTECTIVELY MARKED BUSINESS CONTINUITY. Specialist Operations Contingency Planning Business Continuity Manager 17.09.12

NOT PROTECTIVELY MARKED BUSINESS CONTINUITY. Specialist Operations Contingency Planning Business Continuity Manager 17.09.12 POLICY BUSINESS CONTINUITY Policy owners Policy holder Author Head of Services Specialist Operations Contingency Planning Business Continuity Manager Policy No. 132 Approved by Legal Services 17.09.12

More information

IDA FAS Sub-Committee Guidelines for Testing 1 As of October 16, 2006

IDA FAS Sub-Committee Guidelines for Testing 1 As of October 16, 2006 Guidelines for Testing 1 The Contingency Planning Sub-Committee of the IDA compiled the following BCP testing guidelines for the benefit of IDA Members. These guidelines are not mandatory and should be

More information

business continuity plan for:

business continuity plan for: business continuity plan for: Insert your company name here Our statement of Business Continuity is: > To ensure all employees are competent to do their tasks, and to provide adequate training > To review

More information

Business Continuity Overview

Business Continuity Overview Business Continuity Overview Beverley A. Retjos Senior Manager WW SWG Security & Controls 03/12/07 Business Continuity Management (BCM) Process of ensuring that a business is prepared to survive any disruption

More information

Cornell University EMERGENCY MANAGEMENT PROGRAM

Cornell University EMERGENCY MANAGEMENT PROGRAM Cornell University EMERGENCY MANAGEMENT PROGRAM Table of Contents Table of Contents Section 1 INTRODUCTION... 2 Section 2 EMERGENCY MANAGEMENT COMPONENTS... 3 Prevention-Mitigation Plan... 3 Preparedness

More information

Appendix 3 Disaster Recovery Plan

Appendix 3 Disaster Recovery Plan Appendix 3 Disaster Recovery Plan December 13, 2006 Revision XXQwest Government Services, Inc. 4250 North Fairfax DriveArlington, VA 22203(Delete this page)revision history Revision Number Revision Date

More information

Business continuity management policy

Business continuity management policy Business continuity management policy health.wa.gov.au Effective: XXX Title: Business continuity management policy 1. Purpose All public sector bodies are required to establish, maintain and review business

More information

Prudential Practice Guide

Prudential Practice Guide Prudential Practice Guide LPG 232 Business Continuity Management March 2007 www.apra.gov.au Australian Prudential Regulation Authority Disclaimer and copyright This prudential practice guide is not legal

More information

White Paper. Lifecycle Disaster Recovery Costs

White Paper. Lifecycle Disaster Recovery Costs White Paper Lifecycle Disaster Recovery Costs Lifecycle Disaster Recovery Costs Do you really understand the costs to a financial institution for IT Disaster Recovery? Most professionals working in a

More information

D2-02_01 Disaster Recovery in the modern EPU

D2-02_01 Disaster Recovery in the modern EPU CONSEIL INTERNATIONAL DES GRANDS RESEAUX ELECTRIQUES INTERNATIONAL COUNCIL ON LARGE ELECTRIC SYSTEMS http:d2cigre.org STUDY COMMITTEE D2 INFORMATION SYSTEMS AND TELECOMMUNICATION 2015 Colloquium October

More information

Business Continuity Business Continuity Management Policy

Business Continuity Business Continuity Management Policy Business Continuity Business Continuity Management Policy : Date of Issue: 28 January 2009 Version no: 1.1 Review Date: January 2010 Document Owner: Patricia Hughes Document Authoriser: Tony Curtis 1 Version

More information

BUSINESS CONTINUITY PLAN

BUSINESS CONTINUITY PLAN Business Logo Here BUSINESS CONTINUITY PLAN FOR SMALL TO MEDIUM SIZED BUSINESSES DATE :??? VERSION:?? PRODUCED BY DURHAM CIVIL CONTINGENCIES UNIT BUSINESS CONTINUITY PLAN LIST OF CONTENTS 1. DISCLAIMER...4

More information

Business Continuity. Client Briefing

Business Continuity. Client Briefing Business Continuity Client Briefing About this document This document describes Mediaocean s disaster recovery and business continuity policy. Mediaocean LLC. Mediaocean Systems Limited 2015 This manual

More information

NHS Hardwick Clinical Commissioning Group. Business Continuity Policy

NHS Hardwick Clinical Commissioning Group. Business Continuity Policy NHS Hardwick Clinical Commissioning Group Business Continuity Policy Version Date: 26 January 2016 Version Number: 2.0 Status: Approved Next Revision Due: January 2017 Gordon Stevens MBCI Corporate Assurance

More information

THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST. Business Continuity Plan

THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST. Business Continuity Plan THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST Business Continuity Plan June 2012 Purpose The purpose of this Business Continuity Plan ( BCP ) is to define the strategies and the plans which

More information

Plan Development Getting from Principles to Paper

Plan Development Getting from Principles to Paper Plan Development Getting from Principles to Paper March 22, 2015 Table of Contents / Agenda Goals of the workshop Overview of relevant standards Industry standards Government regulations Company standards

More information

Creating a Business Continuity Plan for your Health Center

Creating a Business Continuity Plan for your Health Center Creating a Business Continuity Plan for your Health Center 1 Page Left Intentionally Blank 2 About This Manual This tool is the result of collaboration between the Primary Care Development Corporation

More information

Business continuity plan

Business continuity plan Business continuity plan CONTENTS INTRODUCTION 2 - Scope - Components BUSINESS IMPACT ANALYSIS 3 - Business Affairs - Information Technology RISK ASSESSMENT 5 - Broad Categories of Hazards - Hazard Table

More information