MANAGEMENT ADVISORY SERVICE REPORT

Size: px
Start display at page:

Download "MANAGEMENT ADVISORY SERVICE REPORT"

Transcription

1 MANAGEMENT ADVISORY SERVICE REPORT 2014 Disaster Recovery Exercise Date: September 8, 2014 Report Number: 2014-MAS-04 Report Number: 2014-MAS-04 Disaster Recovery Exercise

2 Table of Contents: Page Executive Summary Background 1 Objective and Scope 2 Results 2 Appendix Distribution 4 MAS Performed By 4 Report Number: 2014-MAS-04 Disaster Recovery Exercise

3 Executive Summary Background The Office of the Internal Auditor (OIA) recently partnered with the Information Technology function (IT) to observe the Disaster Recovery Exercise which was conducted on May 17, 2014, and to review the IT Disaster Recovery Plan (DRP) and supporting documentation. The exercise was limited in scope and only included the Citizens Insurance Suite (f/k/a CORE ), CDW, Cognos and supporting applications. Several significant changes have occurred in the IT environment over the past year which supported OIA assisting IT by performing this engagement: New Personnel - An IT staff member who was not previously involved with disaster recovery has been assigned responsibility for managing the exercises, as well as for maintaining the DRP and supporting documentation. New Applications - The exercise was focused on the Billing Center and Policy Center modules of Citizens Insurance Suite (CORE) which have gone live since the last exercise. New Technology - New hardware was installed in the DR Data Center in Tampa and new software was implemented to automate the transfer of IT operations from the Production Data Center in Jacksonville and back. The Enterprise Risk Management (ERM) Business Continuity group provides the framework and administers the Citizens Business Continuity Program (BCP) which is guided by the principles and standards of The Disaster Recovery Institute International (DRii), the Disaster Recovery Journal (DRJ), and the Business Continuity Institute (BCI). The BCP is a comprehensive and proactive program focused on maintaining time-sensitive business functions during an outage so that Citizens customers continue to receive quality products and services with minimal disruption. The BCP includes both the business unit(s) recovery capability (referred to as Business Continuity or BC) and the information technology (IT) recovery capability (referred to as Disaster Recovery or DR). Citizens BCP is based upon Business Impact Analyses (BIAs) which were performed in A BIA evaluates and prioritizes business processes by assessing the potential quantitative (financial) and qualitative (non-financial) impact that could occur if any business function was unable to operate for a period of time for any reason. The BIAs help to reveal business process and supporting IT system interdependencies, and to determine the Recovery Time Objectives (RTOs) for the processes and systems. Using the BIAs, IT maps systems and operations to business processes and develops recovery strategies to meet the required RTO s. The IT Operations Department is responsible for the DR program and associated test exercises. The Citizens IT infrastructure has been built so that in response to a pending disaster or in the event of the loss of the Production Data Center in Jacksonville, the delivery of critical business applications and supportive technology services can be transferred to the DR Data Center in Tampa. It is important to note that the IT DRP does not include all systems and services and is approved as such. Business Units will be required to continue processes without the support of technology in some cases. Determining an acceptable level of business continuance is the Report Number: 2014-MAS-04 Disaster Recovery Exercise 1

4 Executive Summary responsibility of the Executive Leadership Team (ELT) based on recommendations from the ERM BC team. Citizens has also developed a Catastrophe (CAT) Plan to provide scalability for handling the increased volume of claims in the event of one or more storms or other weather events affecting Florida. The CAT Plan and testing exercise are not directly related to the BCP or DRP. Objective and Scope The objective of the review was to evaluate the adequacy and effectiveness of the processes and controls that comprise disaster recovery planning, documentation and test execution. The focus of the review included: Observation of the disaster recovery exercise and determination if it is executed in accordance with the DRP. Determination if the DRP and disaster recovery exercise execution aligns with updated business impact analyses and recovery objectives and whether the DRP is adequate to successfully support the business in the event of a disaster. Evaluation of the DRP and supporting documentation with consideration of relevant standards, best practices and the ERM BCP Manual. Results We noted that the planning meetings and preparations leading up to the disaster recovery exercise were comprehensive and that there was excellent communication and teamwork during the exercise. We also observed that the execution of DR exercises, the annual testing of all applications and systems, and the content of the DRP and supporting documentation should be ameliorated. These observations include: Disaster Recovery Exercise - The Emergency Response Team (ERT) members responsible for overall Incident Management and Operations, and for Incident Management and Staff Coordination monitored the exercise and participated in issue resolution via the conference call bridge. It may be beneficial for one or both of them to be on-site during the exercise to provide a presence consistent with the importance of the exercise and to be able to observe activities first-hand. In light of recent and on-going staff departures, additional training, cross-training and knowledge transfer for remaining staff should be considered. To the greatest extent possible, disaster recovery exercises should be representative of circumstances that would exist during a real disaster with respect to availability of systems, means of communication, network resources and so forth. Annual Testing of All Systems and Applications - An annual exercise of all DR capable applications should be performed so that recovery personnel stay familiar with recovery procedures and that any changes in the IT environment over the past year are included. Report Number: 2014-MAS-04 Disaster Recovery Exercise 2

5 Executive Summary IT EDRP (Enterprise Disaster Recovery Plan) and EDRP Supplemental Information - It would be beneficial to ensure that the EDRP and ERRP Supplemental Information are reviewed and updated on a regular basis and after major changes to the IT environment. The externally hosted Sustainable Planner application which is used by ERM could be leveraged to store IT disaster recovery documentation in an external location which would be accessible from anywhere via the Internet in the event of a real disaster. In addition, we noted the following process improvement opportunities related to the storage of the DRP and supporting documentation, as well as a potential impact on the IT DR capability as a result of the upcoming relocation of IT personnel from Tallahassee to Jacksonville: Organization of Disaster Recovery Documentation on the Network Shared Drive - The EDRP and EDRP Supplemental Information which are stored on the network should be stored in a shared folder which is readily identifiable, well known, and not easily confused with any other network folder. Relocation of IT Personnel to Jacksonville - The potential impact on the disaster recovery capability resulting from the relocation of IT personnel from Tallahassee and Tampa to Jacksonville should be assessed. Consideration should be given to sending disaster recovery personnel to a distant location in advance of an approaching hurricane. Management has agreed with our observations and provided action plans. We would like to thank management and staff for their cooperation and professional courtesy throughout the course of this review. Report Number: 2014-MAS-04 Disaster Recovery Exercise 3

6 Appendix Distribution Addressees: Robert Sellers, V.P. - IT Infrastructure and Operations Copies: Juan Cocuy, Citizens Audit Committee Chairman Bette Brown, Citizens Audit Committee Member Jim Henderson, Citizens Audit Committee Member Barry Gilway, President/CEO/Executive Director Kelly Booten, Chief - Systems and Operations Curt Overpeck, Chief Information Officer Christine Turner Ashburn, V.P. - Communications, Legislative and External Affairs Debby Kearney, Ethics and Compliance Officer Bruce Meeks, Inspector General Carol Williams, Director, Enterprise Risk Management Johnson Lambert, LLP (External Auditors) Following Audit Committee Distribution The Honorable Rick Scott, Governor The Honorable Jeff Atwater, Chief Financial Officer The Honorable Pam Bondi, Attorney General The Honorable Adam Putnam, Commissioner of Agriculture The Honorable Don Gaetz, President of the Senate The Honorable Will Weatherford, Speaker of the House of Representatives MAS Performed By Auditor in Charge Audit Director Under the Direction of Gary Sharrock Karen Wittlinger Joe Martins Chief of Internal Audit Report Number: 2014-MAS-04 Disaster Recovery Exercise 4

AUDIT REPORT. Service Desk and Problem Management Audit Opinion: Satisfactory. November 14, 2014. Report Number: 2014-IT-04

AUDIT REPORT. Service Desk and Problem Management Audit Opinion: Satisfactory. November 14, 2014. Report Number: 2014-IT-04 AUDIT REPORT Service Desk and Problem Management Audit Opinion: Satisfactory November 14, 2014 Report Number: 2014-IT-04 Table of Contents: Page Executive Summary Background 1 Audit Objectives and Scope

More information

AUDIT REPORT. Citizens Insurance Suite Check Printing Audit Opinion: Needs Improvement. June 11, 2015

AUDIT REPORT. Citizens Insurance Suite Check Printing Audit Opinion: Needs Improvement. June 11, 2015 AUDIT REPORT Citizens Insurance Suite Check Printing Audit Opinion: Needs Improvement June 11, 2015 Citizens Insurance Suite Check Printing Table of Contents: Page Executive Summary Background 1 Objectives

More information

AUDIT REPORT. Corporate Access and Identity Management Project Audit Opinion: Satisfactory. July 31, 2015

AUDIT REPORT. Corporate Access and Identity Management Project Audit Opinion: Satisfactory. July 31, 2015 AUDIT REPORT Corporate Access and Identity Management Project Audit Opinion: Satisfactory July 31, 2015 Report Number: 2015-IT-02 Corporate Access and Identity Management Project Table of Contents: Page

More information

AUDIT REPORT. Cloud Software as a Service (SaaS) Procurement and Governance Audit. June 9, 2016

AUDIT REPORT. Cloud Software as a Service (SaaS) Procurement and Governance Audit. June 9, 2016 AUDIT REPORT Cloud Software as a Service (SaaS) Procurement and Governance Audit June 9, 2016 Table of Contents: Page Executive Summary Background 1 Audit Objectives and Scope 1 Management s Assessment

More information

INVESTIGATION REPORT. Secondary Employment Policy Violation. Date: May 23, 2014. Report Number: CPIC 14-03-0002. Report Number: CPIC 14-03-0002

INVESTIGATION REPORT. Secondary Employment Policy Violation. Date: May 23, 2014. Report Number: CPIC 14-03-0002. Report Number: CPIC 14-03-0002 INVESTIGATION REPORT Secondary Employment Policy Violation Date: May 23, 2014 Table of Contents: Page Report Background 1 Allegations 1 Procedures 1 Findings 2 Conclusion 2 Appendix Distribution 3 Audit

More information

AUDIT REPORT. Citizens Data Warehouse Audit Opinion: Needs Improvement. Date: June 9, 2014. Report Number: 2014-AUD-IT-01

AUDIT REPORT. Citizens Data Warehouse Audit Opinion: Needs Improvement. Date: June 9, 2014. Report Number: 2014-AUD-IT-01 AUDIT REPORT Citizens Data Warehouse Audit Opinion: Date: June 9, 2014 Report Number: 2014-AUD-IT-01 Report Number: 2014-AUD-IT-01 Citizens Data Warehouse Table of Contents: Page Executive Summary Background

More information

AUDIT REPORT. Legal Billing Compliance. July 29, 2015. Report Number: 2015-AUD-09 Legal Billing Compliance

AUDIT REPORT. Legal Billing Compliance. July 29, 2015. Report Number: 2015-AUD-09 Legal Billing Compliance AUDIT REPORT Legal Billing Compliance July 29, 2015 Executive Summary Background In order to thoroughly review and manage legal fee bills received from a large pool of legal firms providing legal services

More information

FORENSIC AUDIT REPORT. Legal Defense Billing Audit Opinion: Unsatisfactory. Date: May 31, 2014. Report Number: 2013-AUD-15

FORENSIC AUDIT REPORT. Legal Defense Billing Audit Opinion: Unsatisfactory. Date: May 31, 2014. Report Number: 2013-AUD-15 FORENSIC AUDIT REPORT Legal Defense Billing Audit Opinion: Unsatisfactory Date: May 31, 2014 Table of Contents: Page Executive Summary Background 2 Audit Objectives and Scope 3 Audit Procedures 3 Summary

More information

SUMMARY MINUTES OF THE INFORMATION SYSTEMS ADVISORY COMMITTEE MEETING Friday, September 12, 2014

SUMMARY MINUTES OF THE INFORMATION SYSTEMS ADVISORY COMMITTEE MEETING Friday, September 12, 2014 CITIZENS PROPERTY INSURANCE CORPORATION SUMMARY MINUTES OF THE INFORMATION SYSTEMS ADVISORY COMMITTEE MEETING Friday, The Information Systems Advisory Committee (ISAC) of Citizens Property Insurance Corporation

More information

THE OFFICE OF THE INTERNAL AUDITOR STATUS UPDATE MARCH 11, 2014

THE OFFICE OF THE INTERNAL AUDITOR STATUS UPDATE MARCH 11, 2014 THE OFFICE OF THE INTERNAL AUDITOR STATUS UPDATE MARCH 11, 2014 Since the last Audit Committee meeting, the OIA has focused on finalizing the execution of the 2013 Audit Plan and the development of the

More information

Western Intergovernmental Audit Forum

Western Intergovernmental Audit Forum Western Intergovernmental Audit Forum Business Continuity & Disaster Recovery Planning September 12, 2013 Presented by: City of Phoenix City Auditor Department Aaron Cook, Sr Internal Auditor IT Audit

More information

FLORIDA COMMISSION ON OFFENDER REVIEW (formerly Florida Parole Commission)

FLORIDA COMMISSION ON OFFENDER REVIEW (formerly Florida Parole Commission) FLORIDA COMMISSION ON OFFENDER REVIEW (formerly Florida Parole Commission) TENA M. PATE, Chair BERNARD R. COHEN, SR., Vice-Chair MELINDA N. COONROD, Secretary RICK SCOTT, Governor PAM BONDI, Attorney General

More information

CHAPTER 2016-138. Committee Substitute for Committee Substitute for Committee Substitute for House Bill No. 1033

CHAPTER 2016-138. Committee Substitute for Committee Substitute for Committee Substitute for House Bill No. 1033 CHAPTER 2016-138 Committee Substitute for Committee Substitute for Committee Substitute for House Bill No. 1033 An act relating to information technology security; amending s. 20.61, F.S.; revising the

More information

CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR. Follow-up Audit of Information Technology Services Department. IT Contingency Planning

CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR. Follow-up Audit of Information Technology Services Department. IT Contingency Planning Follow-up Audit of Information Technology Services Department CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR Follow-up Audit of Information Technology Services Department Project No. AU13-F05 October 25,

More information

5/25/2011. Citizens Property Insurance Corporation:

5/25/2011. Citizens Property Insurance Corporation: Citizens Property Insurance Corporation: CAS Spring Meeting May 2011 1 Citizens Overview Citizens is a Florida State created, not for profit, tax exempt government entity established principally to provide

More information

EMERGENCY MANAGEMENT PERFORMANCE AND STATE HOMELAND SECURITY PROGRAM FEDERAL GRANTS

EMERGENCY MANAGEMENT PERFORMANCE AND STATE HOMELAND SECURITY PROGRAM FEDERAL GRANTS EMERGENCY MANAGEMENT PERFORMANCE AND STATE HOMELAND SECURITY PROGRAM FEDERAL GRANTS REPORT ON AUDIT FOR THE YEAR ENDED JUNE 30, 2014 Auditor of Public Accounts Martha S. Mavredes, CPA www.apa.virginia.gov

More information

Subject: Internal Audit of Information Technology Disaster Recovery Plan

Subject: Internal Audit of Information Technology Disaster Recovery Plan RIVERSIDE: AUDIT & ADVISORY SERVICES June 30, 2009 To: Charles Rowley, Associate Vice Chancellor Computing & Communications Subject: Internal Audit of Information Technology Disaster Recovery Plan Ref:

More information

The PNC Financial Services Group, Inc. Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page

More information

January 12, 2016. Dr. Hobson Wildenthal, President ad interim Ms. Lisa Choate, Chair of the Institutional Audit Committee:

January 12, 2016. Dr. Hobson Wildenthal, President ad interim Ms. Lisa Choate, Chair of the Institutional Audit Committee: THE UNIVERSITY OF TEXAS SYSTEM AT THE UNIVERSITY OF TEXAS AT DALLAS OFFICE OF INTERNAL AUDIT 800 W. CAMPBELL RD. SPN 32 RICHARDSON, TX 75080 PHONE 972-883-4876 FAX 972-883-6846 January 12, 2016 Dr. Hobson

More information

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES APPENDIX 1 DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES March 2008 Auditor General s Office Jeffrey Griffiths, C.A., C.F.E. Auditor General City of Toronto TABLE OF CONTENTS EXECUTIVE SUMMARY...1

More information

Evaluating and Improving Your Business Continuity Plan

Evaluating and Improving Your Business Continuity Plan Evaluating and Improving Your Business Continuity Plan As presented to the Northeast Florida IIA Chapter January 23, 2015 Contact Information Karen Weir, MAC, CISA, CBCP Manager kweir@accretivesolutions.com

More information

This report is to provide Audit Committee with the terms of reference for an audit project included in the 2007 Audit Work Plan.

This report is to provide Audit Committee with the terms of reference for an audit project included in the 2007 Audit Work Plan. Terms of Reference - Audit Project Date: September 5, 2007 STAFF REPORT INFORMATION ONLY To: From: Wards: Audit Committee Jeff Griffiths, Auditor General All Reference Number: SUMMARY This report is to

More information

Business Continuity Planning Instructions

Business Continuity Planning Instructions Business Continuity Planning Instructions Business continuity planning is a proactive planning process that ensures critical services or products are delivered during a disruption. In creating the plan,

More information

FINAL AUDIT REPORT WITH RECOMENDATIONS Information Technology No. 11-001

FINAL AUDIT REPORT WITH RECOMENDATIONS Information Technology No. 11-001 FINAL AUDIT REPORT WITH RECOMENDATIONS Information Technology No. 11-001 SUBJECT: Review of Emergency Plans DATE: September 24, 2010 for Critical Information Technology Operations and Financial Systems

More information

A BCP Tale: From Theory to Practice

A BCP Tale: From Theory to Practice A BCP Tale: From Theory to Practice Presenter: Gord Novoselnik Problem & Configuration Manager, Enterprise Solutions Division, MTS Allstream Gord.Novoselnik@mtsallstream.com 1 10 Commandments of BCM I.

More information

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com Fax: (718) 380-7322

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com Fax: (718) 380-7322 Business Continuity and Disaster Recovery Job Descriptions Table of Contents Business Continuity Services Organization Chart... 2 Director Business Continuity Services Group... 3 Manager of Business Recovery

More information

Audit of. District s Information Technology Disaster Recovery Plan

Audit of. District s Information Technology Disaster Recovery Plan Audit of District s Information Technology Disaster Recovery Plan April 11, 2014 Report #2014-03 MISSION STATEMENT The School Board of Palm Beach County is committed to providing a world class education

More information

May 2012 Report No. 12-030

May 2012 Report No. 12-030 John Keel, CPA State Auditor Incentive Compensation at the Teacher Retirement System, the Employees Retirement System, and the Permanent School Fund Report No. 12-030 Incentive Compensation at the Teacher

More information

Introduction to Business Continuity Planning

Introduction to Business Continuity Planning Introduction to Business Continuity Planning Business Continuity Management Ensure continuity and survival of our organization in the event of an emergency event: Essential elements: Risk identification

More information

Citizens Property Insurance Corporation: PCS Catastrophe Conference May 2011

Citizens Property Insurance Corporation: PCS Catastrophe Conference May 2011 Citizens Property Insurance Corporation: PCS Catastrophe Conference May 2011 Citizens Overview Citizens is a Florida State-created, not-for-profit, tax-exempt government entity established principally

More information

Evaluation of the Railroad Retirement Board s Disaster Recovery Plan Report No. 06-08, August 14, 2006 INTRODUCTION

Evaluation of the Railroad Retirement Board s Disaster Recovery Plan Report No. 06-08, August 14, 2006 INTRODUCTION Evaluation of the Railroad Retirement Board s Disaster Recovery Plan Report No. 06-08, August 14, 2006 INTRODUCTION This report presents the results of the Office of Inspector General s evaluation of the

More information

Interagency Statement on Pandemic Planning

Interagency Statement on Pandemic Planning Interagency Statement on Pandemic Planning PURPOSE The FFIEC agencies 1 are jointly issuing guidance to remind financial institutions that business continuity plans should address the threat of a pandemic

More information

Fundamentals of Business Continuity Planning Have a Plan!

Fundamentals of Business Continuity Planning Have a Plan! Fundamentals of Business Continuity Planning Have a Plan! Michael Kadar, MBCP, CISSP 2008 MK Continuity & Availability LLC kadarsro@talkamerica.net InfraGard Meeting Walsh College, Novi March 25, 2008

More information

STATE OF NORTH CAROLINA

STATE OF NORTH CAROLINA STATE OF NORTH CAROLINA AUDIT OF THE INFORMATION SYSTEM GENERAL CONTROLS AT VANCE-GRANVILLE COMMUNITY COLLEGE HENDERSON, NORTH CAROLINA JUNE 2004 OFFICE OF THE STATE AUDITOR RALPH CAMPBELL, JR. STATE AUDITOR

More information

BUSINESS CONTINUITY PLANNING

BUSINESS CONTINUITY PLANNING Policy 8.3.2 Business Responsible Party: President s Office BUSINESS CONTINUITY PLANNING Overview The UT Health Science Center at San Antonio (Health Science Center) is committed to its employees, students,

More information

DRAFT Disaster Recovery Policy Template

DRAFT Disaster Recovery Policy Template DRAFT Disaster Recovery Policy Template NOTE: This is a boiler plate template much information is needed from to finalizeconsider this document pre-draft FOREWARD... 3 Policy Overview...

More information

Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June 12 2013

Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June 12 2013 Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June 12 2013 Chitra Gopalakrishnan Director KPMG LLP Agenda Introduction Business Continuity / Disaster

More information

POLICY. 1) Business Continuity Management 2) Disaster Recovery 3) Critical Incident Management 4) Risk Management

POLICY. 1) Business Continuity Management 2) Disaster Recovery 3) Critical Incident Management 4) Risk Management POLICY Policy Title: Management Descriptors: 1) Management 2) Disaster Recovery 3) Critical Incident Management 4) Risk Management Category: Risk Management Intent Organisational Scope Definitions Policy

More information

Beyond Disaster Recovery: Why Your Backup Plan Won t Work

Beyond Disaster Recovery: Why Your Backup Plan Won t Work Beyond Disaster Recovery: Why Your Backup Plan Won t Work Contents Introduction... 3 The Data Backup Model - Upgraded for 2015... 4 Why Disaster Recovery Isn t Enough... 5 Business Consequences with DR-Only

More information

Tips and techniques a typical audit programme

Tips and techniques a typical audit programme Auditing Business Continuity Planning Tips and techniques a typical audit programme Karen Wills, Senior Internal Auditor St James s Place Wealth Management February 2014 Contents Background Roles and Responsibilities

More information

RE: Proposals for New Universities and Colleges

RE: Proposals for New Universities and Colleges October 21, 2011 Ava L. Parker Chair, Florida Board of Governors State University System 325 West Gaines Street, Suite 1614 Tallahassee, Florida 32399-0400 Kathleen Shanahan Chair, State Board of Education

More information

Disaster Recovery Journal Spring World 2014

Disaster Recovery Journal Spring World 2014 Disaster Recovery Journal Spring World 2014 What works: Services and service supply chain business continuity risk management Don Hall, CBCP, Cisco Services Business Continuity Analyst Cisco Systems, Inc.

More information

Certification. Is it Right for You? 2013 Micron Technology, Inc. February 12, 2014

Certification. Is it Right for You? 2013 Micron Technology, Inc. February 12, 2014 Certification Is it Right for You? 2013 Micron Technology, Inc. All rights reserved. Products are warranted only to meet Micron s production data sheet specifications. Information, products, and/or specifications

More information

How To Check If Nasa Can Protect Itself From Hackers

How To Check If Nasa Can Protect Itself From Hackers SEPTEMBER 16, 2010 AUDIT REPORT OFFICE OF AUDITS REVIEW OF NASA S MANAGEMENT AND OVERSIGHT OF ITS INFORMATION TECHNOLOGY SECURITY PROGRAM OFFICE OF INSPECTOR GENERAL National Aeronautics and Space Administration

More information

NCUA LETTER TO CREDIT UNIONS

NCUA LETTER TO CREDIT UNIONS NCUA LETTER TO CREDIT UNIONS NATIONAL CREDIT UNION ADMINISTRATION 1775 Duke Street, Alexandria, VA 22314 DATE: December 2001 LETTER NO.: 01-CU-21 TO: SUBJ: ENCL: All Federally Insured Credit Unions Disaster

More information

Business Continuity Business Impact Analysis arrangements

Business Continuity Business Impact Analysis arrangements Aberdeen City Council Internal Audit Report 2012/2013 for Aberdeen City Council May 2013 Business Continuity Business Impact Analysis arrangements Final Report Contents Section Page 1. Executive Summary

More information

Disaster Recovery/Business Continuity

Disaster Recovery/Business Continuity CITY AUDITOR'S OFFICE Disaster Recovery/Business Continuity March 6, 2015 AUDIT REPORT NO. 1511 CITY COUNCIL Mayor W.J. Jim Lane Suzanne Klapp Virginia Korte Kathy Littlefield Vice Mayor Linda Milhaven

More information

Business Continuity and Disaster Recovery Planning

Business Continuity and Disaster Recovery Planning Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services

More information

Recommendation Current Position and Explanation for Slippage: Target Dates:

Recommendation Current Position and Explanation for Slippage: Target Dates: IT Disaster Recovery 2012/13 Recommendation R1: A Disaster Recovery Plan should be developed and approved. As a minimum, this should include; the identification and prioritisation of key IT systems the

More information

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS DIRECTORATE OF BANKING SUPERVISION AUGUST 2009 TABLE OF CONTENTS PAGE 1.0 INTRODUCTION..3 1.1 Background...3 1.2 Citation...3

More information

INFORMATION TECHNOLOGY CONTROLS OF SELECTED SYSTEMS UTILIZED BY THE CITIZENS PROPERTY INSURANCE CORPORATION. Information Technology Operational Audit

INFORMATION TECHNOLOGY CONTROLS OF SELECTED SYSTEMS UTILIZED BY THE CITIZENS PROPERTY INSURANCE CORPORATION. Information Technology Operational Audit REPORT NO. 2015-017 SEPTEMBER 2014 INFORMATION TECHNOLOGY CONTROLS OF SELECTED SYSTEMS UTILIZED BY THE CITIZENS PROPERTY INSURANCE CORPORATION Information Technology Operational Audit CITIZENS PROPERTY

More information

Proposal: Long Term Data Center Briefing Presentation. Information System Advisory Committee May 24, 2012

Proposal: Long Term Data Center Briefing Presentation. Information System Advisory Committee May 24, 2012 Proposal: Long Term Data Center Briefing Presentation Information System Advisory Committee May 24, 2012 Data Center Strategic Roadmap Goal Provide functional data center facilities for Citizens which

More information

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14

More information

Maryland Transportation Authority

Maryland Transportation Authority Audit Report Maryland Transportation Authority March 2014 OFFICE OF LEGISLATIVE AUDITS DEPARTMENT OF LEGISLATIVE SERVICES MARYLAND GENERAL ASSEMBLY This report and any related follow-up correspondence

More information

De Nederlandsche Bank N.V. May 2011. Assessment Framework for Financial Core Infrastructure Business Continuity Management

De Nederlandsche Bank N.V. May 2011. Assessment Framework for Financial Core Infrastructure Business Continuity Management De Nederlandsche Bank N.V. May 2011 Assessment Framework for Financial Core Infrastructure Business Continuity Management Contents INTRODUCTION... 3 BUSINESS CONTINUITY MANAGEMENT STANDARDS... 5 1. STRATEGY

More information

Business Unit CONTINGENCY PLAN

Business Unit CONTINGENCY PLAN Contingency Plan Template Business Unit CONTINGENCY PLAN Version 1.0 (Date submitted) Submitted By: Business Unit Date Version 1.0 Page 1 1 Plan Review and Updates... 3 2 Introduction... 3 2.1 Purpose...

More information

Serving As a Unified Voice for the Financial Planning Profession. September 17 and 18, 2012. FPA of Florida Makes 11th Trip to Tallahassee

Serving As a Unified Voice for the Financial Planning Profession. September 17 and 18, 2012. FPA of Florida Makes 11th Trip to Tallahassee Serving As a Unified Voice for the Financial Planning Profession September 17 and 18, 2012 FPA of Florida Makes 11th Trip to Tallahassee Representatives from the FPA of Florida in attendance: Paul Miller,

More information

Nelson R. Bregon, General Deputy Assistant Secretary for Community Planning and Development. James D. McKay Regional Inspector General for Audit, 4AGA

Nelson R. Bregon, General Deputy Assistant Secretary for Community Planning and Development. James D. McKay Regional Inspector General for Audit, 4AGA Issue Date July 26, 2006 Audit Report Number 2006-AT-1014 TO: Nelson R. Bregon, General Deputy Assistant Secretary for Community Planning and Development FROM: James D. McKay Regional Inspector General

More information

Hanh Do, Director, Information System Audit Division, GAA. SUBJECT: Review of HUD s Information Technology Contingency Planning and Preparedness

Hanh Do, Director, Information System Audit Division, GAA. SUBJECT: Review of HUD s Information Technology Contingency Planning and Preparedness Issue Date: August 31, 2006 Audit Report Number 2006-DP-0005 TO: Lisa Schlosser, Chief Information Officer, A FROM: Hanh Do, Director, Information System Audit Division, GAA SUBJECT: Review of HUD s Information

More information

MHA Consulting. Business Continuity Management 101

MHA Consulting. Business Continuity Management 101 0 MHA Consulting Business Continuity Management 101 Presented by: Michael Herrera Brandon Magestro MHA Consulting Agenda MHA Consulting Introduction Business Continuity Management (BCM) Defined 2013 Trends

More information

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY This document outlines a set of policies and procedures for formalising a Business Continuity programme, and provides guidelines for developing, maintaining

More information

Business Continuity Planning: Bridging the Gap Between IT and Business

Business Continuity Planning: Bridging the Gap Between IT and Business Business Continuity Planning: Bridging the Gap Between IT and Business Steve Burns, President EverGreen Data Continuity, Inc. sburns@evergreen-data.com 1 The Hard Facts One-third of businesses don t include

More information

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY AUTHOR/ APPROVAL DETAILS Document Author Written By: Human Resources Authorised Signature Authorised By: Helen Shields Date: 20

More information

Why Should Companies Take a Closer Look at Business Continuity Planning?

Why Should Companies Take a Closer Look at Business Continuity Planning? whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters

More information

The George Washington University

The George Washington University PMLC Project Management Life Cycle The George Washington University Expense Reporting (eexpense) System Implementation Project Project Transition Document Prepared By: Adam Donaldson Version: 1.2 Date:

More information

Attachment N CPIC Vendor Resiliency Business Continuity Planning Questionnaire

Attachment N CPIC Vendor Resiliency Business Continuity Planning Questionnaire Instructions: Citizens Property Insurance Corporation (CPIC) distributes this survey to vendors and business partners used by groups within the Firm, who are critical to the operational readiness of Citizens

More information

Department of Public Utilities Customer Information System (BANNER)

Department of Public Utilities Customer Information System (BANNER) REPORT # 2010-06 AUDIT of the Customer Information System (BANNER) January 2010 TABLE OF CONTENTS Executive Summary..... i Comprehensive List of Recommendations. iii Introduction, Objective, Methodology

More information

Audit of the Test of Design of Entity-Level Controls

Audit of the Test of Design of Entity-Level Controls Audit of the Test of Design of Entity-Level Controls Canadian Grain Commission Audit & Evaluation Services Final Report March 2012 Canadian Grain Commission 0 Entity Level Controls 2011 Table of Contents

More information

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010 Business Continuity and Emergency Preparedness Planning Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010 Overview Define key terms and list essential elements of business continuity

More information

The University of Texas at Tyler. Audit of Compliance with Texas Administrative Code 202

The University of Texas at Tyler. Audit of Compliance with Texas Administrative Code 202 Audit of Compliance with Texas Administrative Code 202 August 2015 OFFICE OF AUDIT AND CONSULTING SERVICES 3900 UNIVERSITY BOULEVARD TYLER, TEXAS 75799 BACKGROUND Texas Administrative Code (TAC) Title

More information

APPENDIX XII: EMERGENCY SUPPORT FUNCTION 12 - ENERGY

APPENDIX XII: EMERGENCY SUPPORT FUNCTION 12 - ENERGY APPENDIX XII: EMERGENCY SUPPORT FUNCTION 12 - ENERGY PRIMARY AGENCIES: Public Service Commission and the Florida Energy and Climate Commission SUPPORT AGENCIES: Nuclear Regulatory Commission, Florida Rural

More information

Audit Plan Update. Percentage of Total Budgeted Hours. Adjusted Budgeted Hours. Actual YTD. Audit & MAS 8,066 8,366 38% 7,085.0 46% 2012 Carry Over

Audit Plan Update. Percentage of Total Budgeted Hours. Adjusted Budgeted Hours. Actual YTD. Audit & MAS 8,066 8,366 38% 7,085.0 46% 2012 Carry Over AUDIT COMMITTEE UPDATE DECEMBER 13, 2013 EXECUTIVE SUMMARY Office of the Internal Auditor Update Since the last Audit Committee meeting, the OIA has focused on finalizing the execution of the 2013 Audit

More information

03/14/2013 Compensation Update Citizens Property Insurance Corporation Board of Governors Meeting March 22, 2013

03/14/2013 Compensation Update Citizens Property Insurance Corporation Board of Governors Meeting March 22, 2013 03/14/2013 Compensation Update Citizens Property Insurance Corporation Board of Governors Meeting March 22, 2013 Executive Summary As Florida s no profit provider of property insurance, Citizens is continuously

More information

External Supplier Control Requirements BCM

External Supplier Control Requirements BCM External Supplier Control Requirements BCM BCM Requirement Description BCM Tiers Recovery Time Objective Why this is important 1. Business Continuity Policy Supplier will have a documented Business Continuity

More information

Disaster Recovery Policy

Disaster Recovery Policy Disaster Recovery Policy Organizational Functional Area: Policy for: Executive Division Bank Disaster Recovery Program Board Reviewed: September 14, 2011 Department/Individual Responsible for Maintaining/Updating

More information

Audit, Finance and Legislative Committee Mayor Craig Lowe, Chair Mayor-Commissioner Pro Tem Thomas Hawkins, Member

Audit, Finance and Legislative Committee Mayor Craig Lowe, Chair Mayor-Commissioner Pro Tem Thomas Hawkins, Member City of Gainesville Inter-Office Communication April 3, 2012 TO: FROM: SUBJECT: Audit, Finance and Legislative Committee Mayor Craig Lowe, Chair Mayor-Commissioner Pro Tem Thomas Hawkins, Member Brent

More information

The Government Cloud Protection Program: Disaster Recovery Services Transformed for the Perfect Storm

The Government Cloud Protection Program: Disaster Recovery Services Transformed for the Perfect Storm 2010 NASCIO RECOGNITION AWARD NOMINATION The Government Cloud Protection Program: Disaster Recovery Services Transformed for the Perfect Storm Nomination Category: Risk Management Initiatives Name of State

More information

Office of Emergency Management: Rebuilding the Organization to Strengthen Oregon s Emergency Management

Office of Emergency Management: Rebuilding the Organization to Strengthen Oregon s Emergency Management Secretary of State Audit Report Kate Brown, Secretary of State Gary Blackmer, Director, Audits Division Office of Emergency Management: Rebuilding the Organization to Strengthen Oregon s Emergency Management

More information

2014 NABRICO Conference

2014 NABRICO Conference Business Continuity Planning 2014 NABRICO Conference September 19, 2014 6 CityPlace Drive, Suite 900 St. Louis, Missouri 63141 314.983.1200 1520 S. Fifth Street, Suite 309 St. Charles, Missouri 63303 636.255.3000

More information

Three Cost-Effective Ways to Improve Your Business Continuity Planning and Protect Your Firm

Three Cost-Effective Ways to Improve Your Business Continuity Planning and Protect Your Firm Three Cost-Effective Ways to Improve Your Business Continuity Planning and Protect Your Firm In the past few years, business disruptions have brought the financial industry under greater scrutiny. Superstorm

More information

IT DISASTER RECOVEry

IT DISASTER RECOVEry IT DISASTER RECOVEry COMPETENCY LEVEL COMPETENCY WHICH LEVEL SHOULD I BE STARTING MY BUSINESS CONTINUITY TRAINING? KNOW DO DRP-200 DRP-300 I am new to IT Disaster Recovery Planning (IT DRP) I just need

More information

About RecoveryPlanner.com Business Continuity Management

About RecoveryPlanner.com Business Continuity Management RecoveryPlanner Web-Based Planning Software About RecoveryPlanner.com Business Continuity Management Founded by experts in disaster recovery, business continuity and emergency response in 1999, RecoveryPlanner

More information

WILTSHIRE POLICE FORCE POLICY

WILTSHIRE POLICE FORCE POLICY Template v4 WILTSHIRE POLICE FORCE POLICY BUSINESS CONTINUITY MANAGEMENT SYSTEMS (BCMS) Effective from: July 2013 Version: 2.0 Next Review Date: July 2015 POLICY STATEMENT Wiltshire Police has a statutory

More information

Statement of Guidance

Statement of Guidance Statement of Guidance Business Continuity Management All Licensees 1. Statement of Objectives 1.1. To enhance the resilience of the financial sector and to minimise the potential impact of a major operational

More information

VIRGINIA WORKERS COMPENSATION COMMISSION REPORT ON AUDIT FOR THE YEARS ENDED JUNE 30, 2006 AND JUNE 30, 2007

VIRGINIA WORKERS COMPENSATION COMMISSION REPORT ON AUDIT FOR THE YEARS ENDED JUNE 30, 2006 AND JUNE 30, 2007 VIRGINIA WORKERS COMPENSATION COMMISSION REPORT ON AUDIT FOR THE YEARS ENDED JUNE 30, 2006 AND JUNE 30, 2007 AUDIT SUMMARY Our audit of the Virginia Workers Compensation Commission found: proper recording

More information

SCOPE; ENFORCEMENT; AUTHORITY; EXCEPTIONS

SCOPE; ENFORCEMENT; AUTHORITY; EXCEPTIONS Title: DRAFT USG Continuity of Operation Plan Policy Policy Number: 2009-Julian Date Topical Security Area: Document Type: Standard Pages: Words: Lines: 5 1,387 182 Issue Date: May-09 Effective Date: Immediately

More information

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745 ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan

More information

IT DISASTER RECOVERY SAN FRANCISCO STATE UNIVERSITY. Audit Report 11-32 August 25, 2011

IT DISASTER RECOVERY SAN FRANCISCO STATE UNIVERSITY. Audit Report 11-32 August 25, 2011 IT DISASTER RECOVERY SAN FRANCISCO STATE UNIVERSITY Audit Report 11-32 August 25, 2011 Members, Committee on Audit Henry Mendoza, Chair Melinda Guzman, Vice Chair Margaret Fortune Steven M. Glazer William

More information

RSA ARCHER BUSINESS CONTINUITY MANAGEMENT AND OPERATIONS Solution Brief

RSA ARCHER BUSINESS CONTINUITY MANAGEMENT AND OPERATIONS Solution Brief RSA ARCHER BUSINESS CONTINUITY MANAGEMENT AND OPERATIONS Solution Brief INTRODUCTION Now more than ever, organizations depend on services, business processes and technologies to generate revenue and meet

More information

SUPERVISORY AND REGULATORY GUIDELINES: PU19-0406 BUSINESS CONTINUITY GUIDELINES

SUPERVISORY AND REGULATORY GUIDELINES: PU19-0406 BUSINESS CONTINUITY GUIDELINES SUPERVISORY AND REGULATORY GUIDELINES: PU19-0406 Business Continuity Issued: 1 st May, 2007 Revised: 14 th October 2008 BUSINESS CONTINUITY GUIDELINES I. INTRODUCTION The Central Bank of The Bahamas (

More information

How Organizations Are Improving Business Resiliency With Continuous IT Availability

How Organizations Are Improving Business Resiliency With Continuous IT Availability A Custom Technology Adoption Profile Commissioned By EMC Corporation How Organizations Are Improving Business Resiliency With Continuous IT Availability February 2013 Introduction: Business Stakeholders

More information

Judiciary Administrative Office of the Courts Data Center

Judiciary Administrative Office of the Courts Data Center New Jersey State Legislature Office of Legislative Services Office of the State Auditor Judiciary Administrative Office of the Courts Data Center April 30, 2001 to January 15, 2002 Richard L. Fair State

More information

Choosing BCP Software: One Organization s Story. Brenda E. Brown-Paul

Choosing BCP Software: One Organization s Story. Brenda E. Brown-Paul Choosing BCP Software: One Organization s Story Brenda E. Brown-Paul Introduction Brenda Brown-Paul Sr. Analyst for a Professional Services Company 21 years of IT experience 6 years in business continuity

More information

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION Disaster Recovery Testing Is Being Adequately Performed, but Problem Reporting and Tracking Can Be Improved May 3, 2012 Reference Number: 2012-20-041 This

More information

Business Continuity Policy & Plans

Business Continuity Policy & Plans Agenda Item 8.3a SNCCG Governing Body 11.03.2014 Business Continuity Policy & Plans Ref Number: Version: 1 Status: Pending Approval Author: A Brown Approval body Governing Body Date Approved Date Issued

More information

Some companies never recover from a disaster related loss. A business that cannot operate will lose money, customers, credibility, and good will.

Some companies never recover from a disaster related loss. A business that cannot operate will lose money, customers, credibility, and good will. How Disaster Recovery Planning Can Be Leveraged For Electronic Discovery and Litigation Response Digital Discovery and e-evidence John Connell April 1. 2008 Hurricanes, floods, earthquakes, power outages,

More information

NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems

NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems Marianne Swanson NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY 1 Table Of Contents Introduction to NIST SP 800-34

More information

Change Management: The Greatest ROI of ITIL

Change Management: The Greatest ROI of ITIL Change Management: The Greatest ROI of ITIL Author: Vance F. Brown 2012 Cherwell Software, Inc. All Rights Reserved. Provided by: a Cherwell Value Added Reseller 1 As IT performance is increasingly measured

More information

Best Practices in Developing an IT Disaster Recovery Plan. Vijaykumar Kulkarni AGM Product Management

Best Practices in Developing an IT Disaster Recovery Plan. Vijaykumar Kulkarni AGM Product Management Best Practices in Developing an IT Disaster Recovery Plan Vijaykumar Kulkarni AGM Product Management PRESENTER PROFILE Vijaykumar Kulkarni Assistant General Manager - Product Management in Netmagic Solutions,

More information