NOTICE: This publication is available at:
|
|
|
- Allan Newton
- 10 years ago
- Views:
Transcription
1 Department of Commerce National Oceanic & Atmospheric Administration National Weather Service NATIONAL WEATHER SERVICE INSTRUCTION May 17, 2013 Operations and Services Readiness CONTINUITY OF OPERATIONS (COOP) NOTICE: This publication is available at: OPR: W/OPS (A. Wissman) Type of Issuance: Routine Certified by: W/OPS (D. R. Jones) SUMMARY OF REVISIONS: This directive supersedes NWS Instruction (NWSI) , December 31, Major revisions are: (1) Section 1 has been rewritten to more clearly define responsibilities of offices and responsibilities with regard to Primary Essential Functions; (2) Section 2, Authorities are updated to reflect recent additions, deletions, and changes; superseded directives have been removed; (3) References to National Weather Service (NWS) National Essential Functions (NEFs) have been removed; (4) Definitions for COOP, Continuity of Government, and Enduring Constitutional Government were updated; (5) Operational guidance for plan development has been added, to include fly-away kit content; (6) Additional guidance for the conduct of Business Impact Analysis (BIAs) and development of Recovery Strategy Analysis (RSA) has been added; (7) Additional guidance regarding training and exercises has been added; (8) wording and formatting in all sections has been cleaned up; (9) Reporting requirements have been clarified; (10) Department of Commerce (DOC) telework policy reference is added; (11) COOP Declaration Authorities have been added; (12) Reporting requirements are reduced; (12) Removed requirement to conduct annual Alternate Operating Locations (AOLs) activation for eight hours. Signed May 3, 2013 Mark S. Paese Date Director, Office of Operational Systems
2 Continuity of Operations Table of Contents Page 1 Purpose Primary Mission Essential Functions COOP Implementation Considerations Authorities Procedures Business Impact Assessment (BIA) Recovery Strategy Analysis COOP Plan Development Continuity of Operations Plans Notice of Confidentiality Plan Requirements COOP Activation Authorities Planning Assumptions Assume Preparedness Is Required for All Hazards, Conditions and Functional Recovery Assume IT Infrastructure is Impacted Assume Need for Alternate Communications Assume Need for Personnel Replacement Assume Need for Support from the National Communications System (NCS) Assume Potential Loss of Facilities Assume Activation without Warning Assume Constrained Resources Assume NWS is a Target NIMS Implementation Emergency Response Group Incident Command System Emergency Response Group Incident Commander Command Staff Disaster Assessment and Reconstitution Team Operations Planning Logistics Finance/Administration Roles and Responsibilities FMC Directors Continuity of Operations Coordinators Government Emergency Telephone Service/Wireless Priority Service Fly-Away Kit Reporting COOP Implementation Report Submission
3 7.2 Situation Report (SITREP) Submission Damage Assessment Status Report Submission Spot Report (SPOTREP) Submission Message Log Submission After-Action Report Submission COOP Plan Maintenance, Test, Training, and Exercising Plan Maintenance Testing, Training, and Exercise Plan Maintenance APPENDIX A - Definitions... A-1 APPENDIX B - Acronyms... B-1 APPENDIX C - Continuity of Operations Sample Plan Contents... C-1 APPENDIX D - Report Templates... D-1 3
4 1 Purpose. NWSI May 17, 2013 This directive serves as the overarching Continuity of Operations (COOP) instruction for COOP planning and plan development guidance for National Weather Service (NWS) and its component organizations. This instruction provides direction to all NWS Headquarters Financial Management Centers, Regional Headquarters, the National Centers for Environmental Prediction Center, and their subordinate units for developing, implementing, and maintaining COOP Plans. This directive does not address facility-level information system planning (commonly referred to as a disaster recovery plan) or a wide variety of incidents that can affect information system operations (commonly referred to as contingency plans). 1 Effective continuity planning and programs facilitate the performance of essential functions during all hazards, emergencies, or other situations that may disrupt normal operations and are part of a larger suite of plans, including disaster recovery plans and contingency plans supporting organizational resilience. 2, 3 This directive defines roles and responsibilities, establishes guidance to ensure the continuity of NWS Primary Mission Essential Functions (PMEFs) and restoration of services based on national time-line requirements and priorities. COOP planning involves a coordinated effort throughout NWS to ensure a high level of readiness and a capability to implement, with or without warning, continuity of operations plans, and maintain NWS Primary Mission Essential Functions. The capability to recover PMEFs will be developed in the event normal operations are compromised regardless of the incident or threat of an incident. The only way to develop and maintain a viable COOP capability is to embrace planning guidance as an integral part of daily operations. 1.1 Primary Mission Essential Functions. Primary Mission Essential Functions (PMEFs) are a subset of Mission Essential Functions (MEFs) that directly support National Essential Functions (NEFs). 4 NWS PMEFs have been validated by the National Continuity Coordinator (NCC). PMEFs are continuous, or resumed within 12 hours after a disruption, and sustainable in a recovery mode for 30 days or until normal operations are resumed. NWS resources necessary to support PMEFs will be identified in an annex to each NWS component s COOP Plan. NWS components will specify personnel, facilities, processes, technologies, and other assets necessary to maintain PMEFs. Appendix B contains a list of the National Oceanic and Atmospheric Administration (NOAA) PMEFs. The NWS Primary Mission Essential Functions, which support the NOAA Primary Essential Functions, are: 1. Ingest, encode, collect, and distribute surface, upper air, space-based, and electro-magnetic observations; 1 NIST SP , Rev.1 2 ibid 3 Federal Continuity Directive 1 (FCD 1), February 2008, sec. 1 4 See Appendix A for a list of National Essential Functions 4
5 2. Generate forecasts; and, 3. Issue watches, warnings, and advisories of severe weather and other hydro-meteorological and electromagnetic events. 1.2 COOP Implementation Considerations. When contemplating COOP implementation, the first consideration is the impact of the incident on NWS operations. The criteria for COOP implementation is not the incident itself but rather the scope and duration of its impact, as defined by the Recovery Time Objective (RTO). (RTO is defined as length of time at which a loss or significant operational degradation becomes unacceptable ). Notwithstanding all other considerations, COOP objectives remain the same: Safe and effective protection of all personnel either through evacuation or Shelter-in-Place; Protect and preserve equipment, facilities, and lesser assets needed to sustain operations; Safe and effective staff, resource, and functional relocation to alternate facilities; and, Sustain NWS PMEFs. NWS personnel will be prepared to exercise great flexibility and initiative when addressing needs and challenges that will arise during an actual COOP activation. National Weather Service headquarters and offices will continue to perform Primary Mission Essential Functions under all conditions regardless of cause. While specific emergencies or subsequent impacts cannot be predicted, planning for operational recovery under such conditions can mitigate the impact of the event on the public, NWS employees, facilities, and mission. 2 Authorities. These references direct that NOAA NWS develop and maintain a COOP capability USC 101 et seq., 314(a)(15), Homeland Security Act of USC c. Authorized activities of the National Oceanic and Atmospheric Administration USC 3544(b)(8) Federal Information Security Management Act (FISMA), January CFR , Management of Vital Records, November 2, CFR et seq, Occupant Emergency Program 6. Executive Order (EO) 13618, Assignment of National Security and Emergency Preparedness Telecommunications Functions, July 6, EO 12656, Assignment of Emergency Preparedness Responsibilities, November 18, 1988 as amended 8. EO 13231, Critical Infrastructure in the Information Age, October 16, National Infrastructure Protection Plan, National Presidential Directive (NSPD 51)/Homeland Security Presidential Directive (HSPD) 20, National Continuity Policy, May 4, Presidential Decision Directive (PDD) 39, Counter-Terrorism, July 21, PDD - 62, Combating Terrorism, May 22, HSPD 3, Homeland Security Advisory System, March 11, HSPD 5, Management of Domestic Incidents, February 28, HSPD 7, Critical Infrastructure Identification, Prioritization, and Protection, December 17, HSPD 8, National Preparedness, December 17,
6 17. Federal Continuity Directive 1 (FCD 1), Federal Executive Branch Continuity Program and Requirements, February FCD 2, Federal Executive Branch Mission Essential Function and Primary Mission Essential Function Identification and Submission Process, February H.R (d)(2) Continuity of Operations Plans Supersede Telework Policy 20. Office of Management and Budget, Circular A-130, Appendix III (Revision 3), Security of Federal Automated Information Resources, National Communications System Directive (NCSD) 3-8, Telecommunications Operations Provisioning of Emergency Power in Support of NS/EP Telecommunications, April 2, NCSD 3-10, Minimum Requirements for Continuity Communication Capabilities, July 25, National Communications System Manual , Guidance for Implementing NCSD 3-10 (FOUO), February 26, Department of Commerce Administrative Order (DAO) 210-1, Emergency Readiness for Department Continuity, November 4, DAO 210-7, Commerce Responsibilities in Disasters, April 15, National Institute of Technology (NIST), Special Publication (SP) (Revision 1), Contingency Planning for Information Technology Systems, May Federal Information System Processing Standards Publication (FIPS) 199, Standards For Security Categorization Of Federal Information And Information Systems, February NOAA Administrative Order (NAO) 210-2, Vital Records Program, June 13, NAO 210-5, Order of Succession to Key NOAA Positions, November 19, NAO , All Hazards Incident Management, October 24, National Weather Service Instruction , Preparations in Advance of or During, Disasters or Major Weather Emergencies, May 23, Department of Commerce Telework Policy, July Procedures. This instruction applies to all National Weather Service Financial Management Centers, Regional Headquarters and their subordinate offices and facilities, and the National Centers for Environmental Prediction and their subordinate units (hereafter offices). All offices will implement the following procedures for the development, implementation, and maintenance of their COOP Plans. Given the wide difference in missions amongst NWS offices, these instructions are written to the highest level. Offices are expected to and may modify these instructions as necessary to fit office mission and size. If in doubt, defer to the next higher level. 3.1 Business Impact Assessment (BIA). A BIA will identify all business functions and characterize the consequences of their loss. The BIA can then be used to establish continuity requirements and prioritize their recovery based on their RTO. FCD 1 and NIST SP (Rev 1), establish requirements for mission essential 6
7 functions 5. FCD 2 prescribes the procedures and the approval process for identifying Primary Mission Essential Functions. A BIA will be conducted within 12 months of the date of this directive and reviewed and updated annually not later than December 31 of each year; and, when the person in charge of the organization is replaced. (The procedures outlined in FCD 2, Annex A, for determining MEFs may be substituted for a formal BIA procedure.) BIA Reports 6 (BIARs) will identify all functions and services performed, the RTO of each function, and their associated recovery requirements. RTOs consider when the loss of a function becomes unacceptable to the organization and users and is the prioritization metric. 3.2 Recovery Strategy Analysis. Once the BIA has been approved by the Financial Management Center (FMC), each office will develop a Recovery Strategy Analysis (RSA). An RSA will: 1. Identify all strategies meeting approved requirements, determine advantages and disadvantages of each recovery strategy, and implementation recommendations based on cost effectiveness and the ability to satisfy requirements; 2. Establish orders of succession and current roster(s) of fully trained COOP personnel with authority and skills to perform essential functions; 3. Identify AOLs and, as appropriate, virtual office options including telework 7 ; and, 4. Be approved by the FMC. A Continuity of Operations Plan is a critical part of an organization s emergency response planning and contributes significantly to organizational resilience. [Continuity Plans are frequently confused with Contingency Plans. A Contingency Plan refers to information systems and provides the plans for responding to and recovering operations of a designated information system from incident or disruption of service and based on the Federal Information Security Act of 2002 (FISMA). Continuity Plans are based on Federal Continuity Directive 1 (FCD 1).] Continuity Plans and Contingency Plans are part of a suite of plans that organizations develop for emergency response and organizational resilience. Other plans (not in any particular order) in the suite are: Business Continuity Plan, Crises Communications Plan, Critical Infrastructure Protection Plan, Cyber Incident Response Plan, Disaster Recovery Plan, Information System Contingency Plan, and Occupant Emergency Plan COOP Plan Development. The COOP Plan will be developed upon approval of the recovery strategy analysis by the FMC. The COOP Plan will provide the procedures and supporting policies necessary to implement the approved strategies based on the requirements identified and approved through the BIA process. The COOP plan will include BIA results; testing, training, and exercise (TT&E) requirements; 5 FCD 1 section 9a; FCD 2, Annex A 6 See NIST SP (Rev1), Chap 3, for a discussion of BIA and RSA 7 H.R (d)(2) Continuity of Operations Plans Supersede Telework Policy during any period that an executive agency is operating under a continuity of operations plan, that plan shall supersede any telework policy. 8 See NIST SP (Rev 1), Chapter 2, for definitions and discussion of the types of plans 7
8 essential administrative records; roles and responsibilities; devolution; orders of succession and delegation of authority; reconstitution; and, the aforementioned policies and procedures. In order to accommodate all requirements while sustaining an operationally viable/user friendly plan, all offices are encouraged to divide their COOP plans into two separate volumes, segregating the administrative requirements from operational guidance. Appendix B presents a suggested format. 4 Continuity of Operations Plans. 4.1 Notice of Confidentiality. All COOP Plans containing Personally Identifiable Information (PII) will be stored and communicated using accepted PII controls as directed by Department of Commerce, NOAA, and NWS policies, directives, and, orders. All COOP Plans will include the following Notice of Confidentiality, and afforded protections commensurate with For Official Use Only (FOUO) information: Information contained in this Continuity of Operations Plan (COOP) is FOR OFFICIAL USE ONLY. Portions of this plan may contain information raising privacy or other considerations, which may be exempt from mandatory disclosure under the Freedom of Information Act. The information contained herein is to be used by personnel with an official Need to Know based on their responsibilities relative to this COOP activities. Some of the information in this plan, if made public, could endanger the lives and privacy of associates. In addition, the disclosure of information in this plan could compromise the security of essential equipment, services, and systems of the National Weather Service, or otherwise impact NWS ability to perform its critical functions, as well as disclose protected Personally Identifiable Information (PII). Unauthorized use of this information may constitute an invasion of privacy and a violation of law. 4.2 Plan Requirements. Appendix B provides a sample format for use in developing COOP Plans. COOP Plans will: 1. Define MEFs, PMEFs, and services performed or supported; 2. Establish COOP plan activation criteria and activation procedures; 3. Contain a roster of fully trained personnel with the authority and skills to perform essential functions and activities; 4. Contain procedures for employee advisories, alerts, and implementation of COOP procedures with instructions for relocation to the alternate operating location. Procedures will support activation with and without warning, during duty and non-duty hours (Fan-out List, Emergency Alert Trees, telephone trees, etc.); 5. Support methods for maintaining operational logs and detailed records of financial activity during COOP operations (ref. NWSI ); 6. Provide for personnel accountability throughout the duration of the COOP event; 7. Provide for recovering PMEFs within appropriate RTOs; 8. Establish processes and procedures to acquire resources necessary to sustain operations for at least 30 days. 9. Contain a fully coordinated and approved plan for Orders of Succession and Delegations of Authority; 8
9 10. Contain a list of alternate operating locations (AOLs), that are prepared to accommodate migrating functions, services and staff, including directions, points of contact, and telephone numbers; 11. Provide AOL security policies and check-in procedures; 12. Include a list of essential services in the immediate vicinity of each identified AOL, e.g., hospitals and critical care facilities, eating establishments, hotels and motels, etc. 13. Contain a list of essential records, as well as their location and instructions for access and retrieval (ref. NWSI 1-806); 14. Contain a list of interoperable communications between all NWS AOLs and the AOLs of all higher authorities (e.g. telephone, facsimile, cell and/or satellite telephones) and, instructions for contacting each (this information is maintained within the NWS Vital Records located on the NOAA Vital Records Server). ( contact lists/ ) 15. Require and provide guidance for regular COOP training, testing, and exercising. 4.3 COOP Activation Authorities. A COOP Plan may be activated by: 1. The President; 2. Secretary of Homeland Security acting for the President in accordance with HSPD 5, Management of Domestic Incidents 3. The Secretary of Commerce; 4. Under-Secretary for Oceans and Atmospheres (NOAA Administrator); 5. Director, National Weather Service; or, 6. FMC Director. 4.4 Planning Assumptions. It is impossible to predict every eventuality that could require activation of NWS COOP plans. All NWS facilities are potentially vulnerable to a broad range of accidents, natural disasters, technology or environmental failures, or deliberate acts including war or terrorism. In order to establish baseline planning factors, the following assumptions provide initial planning standards. Additional planning assumptions may be necessary for specific facilities and/or locations beyond those articulated here. COOP plans should address at least each of the following: Assume Preparedness Is Required for All Hazards, Conditions and Functional Recovery. Activation of the COOP plan may result from localized conditions that have little broader impact, a regional situation, or a catastrophic event that severely taxes the ability of the Federal Government to maintain operations. NWS personnel are prepared to address any hazard, all conditions, and impacts for emergency response, and recovery of core critical functions based on predetermined and approved prioritizations. All hazards planning can be addressed if strategies for the following four impacts are adequately developed and implemented: 1. Loss of computing infrastructure (e.g. hardware failure, software failure, virus, etc.); 2. Loss of telecommunications (voice and/or data); 3. Loss of Personnel; and, 9
10 4. Denial of facility access Assume IT Infrastructure is Impacted. Loss of IT infrastructure is a broad category that takes into account hardware failure, software failure, data loss or corruption, successful intrusion attempts or other cyber-attacks such as virus infections or worms, logic bombs, etc. Computing infrastructure recovery strategies are many and varied. It is critical to embrace the maxim the shorter the RTO, the fewer and more expensive the strategies become Assume Need for Alternate Communications. COOP activation will most likely occur in the face of damage to communications infrastructure necessitating each component develop and maintain a COOP crises communications plan. 1. Multiple communications mechanisms will have to be implemented to assure NWS staff/contractors can remain in contact, rotate responsibilities, or otherwise support the NWS mission during COOP. 2. The COOP crises communications plan will address - accounting for personnel, maintaining contact with NWS employees, and ensuring communications with critical contractors/vendors throughout the period of COOP implementation. 3. The communications plan will address communications with personnel deployed to COOP sites, as well as those who are not deployed Assume Need for Personnel Replacement. Given the nature of the NWS mission, NWS field facilities may be more likely to be impacted by natural disasters or other emergencies. Planning for loss of personnel includes critical technical staff, subject matter experts (SMEs), as well as leadership. The only viable strategies for recovering lost critical skills are reassignments between components and cross-training within each component. Ensuring leadership continuity includes both delegations of authority and succession planning Assume Need for Support from the National Communications System (NCS). In any event larger than unexpected rain or snow, the existing telecommunications system, both terrestrial and wireless, is often overcome by calling volume and/or reduced bandwidth. To minimize unanticipated communications outages, assume: 1. Both wireless and terrestrial communications may be overwhelmed by call volume in any emergency requiring activation of COOP; 2. Support from all telecommunications carriers will probably have to be coordinated, prioritized, and authorized by NCS during a COOP deployment; 3. AOLs may experience damage to or loss of normal communications; and, 4. NCS coordination takes place through the NWS Homeland Security Activities Director and/or the NOAA Office of Homeland Security Assume Potential Loss of Facilities. Denial of access to the facility can be caused in a variety of ways. The following are examples of potential situations: 10
11 1. Fire, flood, or explosion that requires long-term evacuation; 2. Loss of plumbing or loss of power that impacts motion sensor flushing; 3. Other conditions that result in civil response units that precludes access for damage assessment operations. (If access is denied by civil authorities beyond your shortest RTO, you have a COOP situation regardless that your Disaster Assessment and Reconstitution Team (DART) cannot provide an actual damage assessment report); 4. Toxic waste spill that precludes access; 5. Civil disturbance/riots that precludes access; or, 6. Severe winter storms that shut down or severely limit traffic patterns Assume Activation without Warning. National guidance requires all executive departments and agencies to base continuity planning on the assumption that advance warning will not be received to implement COOP and shift operations to AOLs. 9 All components prepare for activation procedures during normal hours as well as non-duty hours Assume Constrained Resources. Assume that when functions are recovered under COOP/ emergency conditions, operations will be limited to core critical functions. Consequently, COOP operations will be conducted with limited staff and technological resources and reduced logistic support aimed at supporting only the most critical NWS functions Assume NWS is a Target. As a global leader in weather, water, climate, and space event forecasting, NWS is a key information source for the nation s leadership and its allies, and military, intelligence, and U.S. commercial decision-making. As a key information source, the following incorporate the following into COOP planning: 1. NWS may be a high-priority target for countries, groups, organizations, or individuals who wish to constrain national decision-making or inflict damage on the national economy; 2. Hostile acts could involve physical or logical interruption of the flow of NWS products and services or alteration of NWS data so that NWS products are unreliable; and 3. Attempts to undertake hostile acts could occur at any time but seem particularly likely in times of international unrest or conflict. 5 NIMS Implementation. NWS components will implement the Incident Command System (ICS) feature of the National Incident Management Systems (NIMS) when activating COOP Plans. NWS components will designate personnel to form the following teams as appropriate for their organization. Functionality and response are the primary considerations; therefore, it may be appropriate to combine functions at weather forecast offices while a more robust, diverse command and 9 HSPD-20 Supra, paragraph (4). 11
12 response structure, may be required at higher levels. Nevertheless, there should be sufficient personnel to support 24/7 operations for all groups and teams for at least 30 days. 5.1 Emergency Response Group. The COOP recovery organization is organized as the Emergency Response Group (ERG) (see Figure 5-1). The ERG is responsible for local COOP implementation and management. The ERG is composed of the Incident Commander (IC), the Command Staff, Damage Assessment and Reconstitution Team, and the General Staff. The local FMC Manager has overall responsibility for the ERG. 5.2 Incident Command System. The ICS was developed in the 1970s as a response to studies that found that problems during disaster responses were more likely to be as a result of response mismanagement than any other single reason. 10 ICS: Is a standardized management tool for meeting the demands of small or large emergency or nonemergency situations; Represents "best practices" and has become the standard for emergency management across the country; May be used for planned events, natural disasters, and acts of terrorism; and, Is a key feature of NIMS. A typical implementation of ICS is illustrated in Figure 5-1. Emergency Response Group Incident Commander Command Staff DART Operations Planning Logistics Finance/ Administration Fig. 5-1 Typical Implementation of Incident Command System 10 ICS Resource Material, May
13 5.2.1 Incident Commander. The FMC director will act as or appoint an Incident Commander to act as the overall incident commander. If no IC is appointed or is absent for any reason, the senior NWS person on scene will act as the Incident Commander until relieved. The Incident Commander will: 1. Determine incident objectives and strategy (ies) to be followed. 2. Establish the level of organization needed, and continuously monitor the operation and effectiveness of that organization. 3. Manage planning meetings as required. 4. Approve and implement the Incident Action Plan (IAP). 5. Coordinate the activities of the Command and General Staff. 6. Approve requests for additional resources or for the release of resources. 7. Approve the use of participants, volunteers, and auxiliary personnel. 8. Authorize the release of information to the news media. 9. Order demobilization of the incident when appropriate Command Staff. The Command Staff s responsibilities include: 1. Verify power availability at alternate operating location; 2. Verify safety and security at the alternate site; 3. Coordinate and facilitate alternate site access for relocating personnel; 4. Coordinate personnel in-processing and incoming equipment handling; 5. Ensure vital records, documentation, and backup data is available; 6. Ensure successful IT system failovers; 7. Ensure recovery status reporting as required; 8. Provide quality assurance assessment of all recovery efforts; and, 9. Conduct any other coordination activity, as necessary, to ensure alternate facility readiness and successful operational fail-over Disaster Assessment and Reconstitution Team. The DART is composed of senior technical staff and subject matter experts within the FMC who will: 1. Assess damage to facilities, infrastructure, and operations and recommend an appropriate response to senior leadership. a. If the maximum time to repair, as determined by the DART, exceeds the RTO, COOP will be declared. b. If the primary facility cannot support operations, the DART will work with NWS Leadership, NOAA, and General Services Administration (GSA) to procure other facilities. 2. Conduct salvage operations to refurbish organizational assets that are deemed repairable, and to properly dispose of assets that are not repairable. 3. Coordinate with NWS Leadership and NOAA to repair damaged facilities and infrastructure. 4. Will develop a migration plan to restore operations within the primary facility if available; or, replacement facilities if necessary. 13
14 5.2.4 Operations. The Operations staff will: 1. Manage tactical operations. 2. Develop the operations portion of the IAP. 3. Supervise execution of operations portions of the IAP. 4. Request additional resources to support tactical operations. 5. Approve release of resources from active operational assignments. 6. Make or approve expedient changes to the IAP. NWSI May 17, Planning. The Planning staff will: 1. Collect and manage all incident-relevant operational data. a. Supervise preparation of the IAP. 2. Provide input to the IC and Operations in preparing the IAP. 3. Incorporate Traffic, Medical, and Communications Plans and other supporting materials into the IAP. 4. Conduct and facilitate planning meetings. 5. Reassign personnel within the ICS organization. 6. Compile and display incident status information. 7. Establish information requirements and reporting schedules for units (e.g., Resources, Situation Units). 8. Determine need for specialized resources. 9. Assemble and disassemble Task Forces and Strike Teams not assigned to Operations. 10. Establish specialized data collection systems as necessary (e.g., weather). 11. Assemble information on alternative strategies. 12. Provide periodic predictions on incident potential. 13. Report significant changes in incident status. 14. Oversee preparation of the Demobilization Plan Logistics. The Logistics staff will: 1. Provide all facilities, transportation, communications, supplies, equipment maintenance and fueling, food and medical services for incident personnel, and all off-incident resources. 2. Manage all incident logistics. 3. Provide logistical input to the IAP. 4. Brief Logistics Staff as needed. 5. Identify anticipated and known incident service and support requirements Finance/Administration. The Finance/Administration staff will: 1. Manage all financial aspects of the incident. 2. Provide financial and cost analysis information as requested. 3. Ensure compensation and claims functions are being addressed relative to the incident. 14
15 4. Develop an operating plan for the Finance/Administration Section and fill Section supply and support needs. 5. Meet with assisting and cooperating agency representatives as needed. 6. Maintain daily contact with agency(s) headquarters on finance matters. 7. Ensure that personnel time records are completed accurately and transmitted to home agencies. 8. Ensure that all obligation documents initiated at the incident are properly prepared and completed. 9. Brief agency administrative personnel on all incident-related financial issues needing attention or follow-up. 10. Provide input to the IAP. 6 Roles and Responsibilities. This section identifies the key players responsible for implementing and supporting COOP. Designation of personnel to support COOP is dependent upon the situation and could drastically change from incident to incident. Personnel identified here will be considered the minimum necessary to maintain essential functions and comprise the COOP Team. 6.1 FMC Directors. NWS Headquarters Office Directors and FMC Directors will: 1. Develop and maintain continuity of operations plans for their offices/facilities; 2. Develop and maintain emergency contact lists for their offices; 3. Develop, implement, and maintain functional backup and personnel cross-training for all primary mission essential functions; 4. Develop and implement delegations of authority and orders of succession. 5. Develop, document, and maintain any interagency agreements unique to a particular office necessary to sustain critical infrastructure or an essential function; 6. Ensure adequate equipment, procedures, plans, publications, and other vital records as necessary to sustain essential functions are made available at designated alternate location and devolution facilities; and, 7. Prepare a multi-year program and strategy plan that includes a program budget to support a viable COOP capability that comports with the planning presumptions and objectives in this plan 6.2 Continuity of Operations Coordinators. The Continuity of Operations Coordinators will: 1. Develop, maintain, and revise COOP Plans as necessary; 2. Develop and conduct plan tests/exercises and personnel COOP training to support COOP Plan implementation; 3. Review IS Contingency Plans to ensure adequate coordination and compliance with data center Disaster Recovery Plans (DRPs) and COOP Plans; 4. Provide in-briefing, as required, for all personnel arriving at Alternate Operating Locations; 5. Provide COOP technical support to the IC during COOP Plan activations. 6. In addition, the NWS COOP Coordinator specifically will: a. Develop, for approval by the Homeland Security Activities Director, the NWS COOP Policy; 15
16 b. Assist Homeland Security Activities Director s coordination with NOAA Homeland Security Program Office (HSPO); c. Provide COOP technical guidance to all NWS Component COOP Coordinators; d. Assist all NWS Component COOP Coordinators with conducting Business Impact Analysis (BIAs) and other assessments as necessary; and, 7. Review and provide recommendations for NWS Component COOP recovery strategies to ensure optimum use of all primary and alternate operating locations. 6.3 Government Emergency Telephone Service/Wireless Priority Service. The Government Emergency Telephone Service (GETS) and Wireless Priority Service (WPS) provide emergency access to local and long line telephone service for identified emergency personnel. GETS and WPS are intended for use during emergency situations when normal telecommunications systems are congested or have been affected by the scale of the emergency. All personnel identified as COOP personnel will acquire and maintain GETS cards and have WPS access. NWS Office of Operation is the point of contact (POC) for acquiring the necessary GETS and WPS credentials. 6.4 Fly-Away Kit. Each member of a COOP Team will maintain a fly-away kit or Go-Bag. As a minimum, the kit will contain those items a member considers essential to supporting continuity operations at an alternate site for at least 30 days. Each kit will be somewhat unique but most should include such items as COOP checklists, key contact lists (names, phone numbers, addresses, etc.), computer media or files specific to the member s position that will be important to an effective response capability, any specialized tools or equipment routinely used by the member, and maps to the alternate site. Table 6-1, below, is a sample of a fly-away kit checklist. Item Yes No N/A Government ID card(s) Driver s License Health Insurance Card Personal Credit Card(s) PDA/Cell Phone PDA/Cell phone charger GETS card (if issued) COOP Plan/individual checklists Flashlight Extra batteries Surgical mask Contact information - personal contacts Contact information - professional contacts Toiletries 16
17 Item Yes No N/A Extra clothing (as necessary) List of allergies or other medical conditions Hearing aid and batteries (if needed) Extra eye glasses and contact lenses (if needed) Prescription drugs for several days Over-the-counter drugs for several days Other items as directed/required: 7 Reporting. Table 6-1 Fly-Away Kit Checklist Timely and complete reporting is essential for maintaining the government s ability to accomplish its National Essential Functions and the NWS ability to accomplish its Primary Mission Essential Functions. When possible, all reports will be prepared and submitted electronically. The Incident Commander will approve the release of all reports. Approval for release will be maintained on the official file copy. Reports may be legibly written, typed and faxed, or prepared electronically and sent as an attachment. Appendix C to this directive contains templates, which may be used to gather the necessary information, and formats for the reports. 7.1 COOP Implementation Report. The COOP Implementation Report will be used to report the implementation of COOP and the deployment of staff and operations to AOL to designated higher authority headquarters. All communications plans should be reviewed to ensure accurate contact information Submission. This report will be completed and submitted electronically when possible. If electronic means are not available, facsimile is acceptable. Submissions will be made as follows: 1. Initial submission no later than one (1) hour or as soon as possible after AOL activation; and, 2. Ad hoc submissions as requested/directed by higher authority. 7.2 Situation Report (SITREP). The SITREP is used to summarize the current situation, significant events, and operational information occurring since the submission of previous reports. Specifically: 1. Report new information and update information reported in previous reports, include previously reported information only when required for clarification. 2. Report should include updates, if applicable, to previously submitted Damage Assessment Status (DAS) Reports. 3. Initial report may be combined with COOP Status Report. 17
18 7.2.1 Submission. Initial submission will be made no later than one (1) hour or as soon as possible after AOL activation 1. Daily reports submitted to higher authority headquarters no later than 0700 EST (0800 EDT); 2. Ad hoc submissions as requested/directed by higher authority. 7.3 Damage Assessment Status Report. The DAS is used to report the damage assessment of an organization s primary or alternate location. The DAS report may also be used for COOP implementation justification, if required Submission. Initial submission will be within two (2) hours or as soon as possible of AOL activation 1. Daily submission to higher headquarters no later than 0700 EST (0800 EDT) until termination of event. 2. Ad hoc submissions as requested/directed by higher authority. 7.4 Spot Report (SPOTREP). The SPOTREP is used to report information concerning a significant, previously unreported condition, emergency, or situation Submission. A SPOTREP is a free form report, submitted as soon as anyone first becomes aware of a specific event or situation. 7.5 Message Log. The Message Log is used to track, document and log all conversations with senior officials and external organizations Submission. Forms are submitted at the end of each duty cycle to the Command Support Staff (CSS) administrative entity at the alternate facility responsible for documenting and tracking COOP operations. Forms will be maintained at the AOL and included as attachments to the After- Action Report (AAR). 7.6 After-Action Report. The AAR provides: 1. Detailed report of activities and actions during the COOP activation; 2. Detailed account of issues or problems experienced by response staff during a response or exercise; and, 3. Recommendations on how identified issues or problems can be resolved Submission. The final report is due to NWS Homeland Security Activities Director no later than five (5) business days after termination of the event or exercise. 18
19 8 COOP Plan Maintenance, Test, Training, and Exercising. 8.1 Plan Maintenance. NWSI May 17, 2013 COOP Plans will be reviewed at least annually, not later than December 31 of each year, and within 30 calendar days of a change of the person in charge of the office or FMC. The review will be documented with a Memorandum for the Record (MFR). Copies of the MFR will be filed with the COOP Plan and provided to next higher authority (e.g. for a Weather Forecast Office [WFO] or River Forecast Center [RFC], the Region Headquarters; National Centers for Environmental Prediction [NCEP] for a Specialized Center) not later than 30 calendar days following a review. 8.2 Testing, Training, and Exercise. A TT&E program is necessary to prepare, validate, and familiarize leadership and staff with an organization s COOP Plan. Training and exercises also provide leadership and staff with the skills to perform their assigned COOP-related duties. All FMCs will plan, conduct, and document periodic test, training, and exercises to prepare for all-hazards continuity emergencies and disasters. 11 All FMCs will conduct a full exercise of their COOP Plan at least annually. A report of the results of the exercise will be produced (e.g. scenario, functions activated, alternate site activation). One copy of the report will be filed with the COOP Plan and one copy will be forwarded to the next higher headquarters not later than January 30 of each year. Each Regional Headquarters and the National Centers for Environmental Prediction will provide a summary of their subordinate unit activities to the Homeland Security Activities Director not later than February Plan Maintenance. Each FMC will maintain a copy of all subordinate units COOP Plans. The NWS Homeland Security Activities Director will maintain the NWS Headquarters COOP Plan. 11 FCD 1 section 9h. 19
20 APPENDIX A - Definitions Alternate Operations Location (AOL): An alternate work site providing the capability to perform mission essential functions until normal operations can be resumed. Business Impact Analysis (BIA): The identification of all functions performed by an organization, the requirements to enabling those functions, and the recovery prioritizations of those functions and requirements. Continuity of Government (COG): A coordinated effort within each branch of Government (e.g. the Federal Government s Executive Branch) to ensure the continued performance of NEFs during a catastrophic emergency. COOP is an integral part of COG and Enduring Constitutional Government (ECG). Continuity of Operations (COOP): Internal efforts within individual organizations (i.e. components of the Executive, Legislative and Judicial branches of government) to ensure continuing performance of MEFs and PMEFs during a wide range of emergencies, including localized acts of nature, accidents, and technological or attack-related emergencies. Continuity of Operations (COOP) Plan: The documentation of a predetermined set of decisions, instructions and procedures for the recovery of an organization, which focuses on the recovery of Primary Mission Essential Functions (PMEFs), Mission Essential Functions (MEFs) and executive leadership. Disaster: An incident that has caused a formal declaration by a designated authority based on pre-designated criteria. Disruption: An unplanned event that causes a degradation or cessation of functions, services, or applications. A disruption is generally of a duration shorter than that which would be declared a disaster. Emergency: A sudden, usually unexpected event, that does or could do harm to people, resources, property, or the environment. Emergencies can range from localized events that affect a single office in a building, to human, natural, technological events that damage, or threaten to damage, local operations. The emergency could cause the temporary evacuation of personnel or the permanent displacement of personnel and equipment from the site to a new operating location environment. Essential Operations: Those operations stated or implied, that are required to be filled by statute or Executive Order, or other operations deemed essential by the heads of principal organizational elements. Essential Positions: Those positions stated or implied, that are required to be performed by statute, Executive Order or other positions deemed essential by the heads of principal organizational elements. Emergency Operating Records: Records vital to the essential functions of the Federal Government for the duration of an emergency. Such records include emergency plans and directives, orders of succession, delegations of authority, staffing assignments, selected program records needed to continue the most critical agency operations, and related policy or procedural records. These records assist the organization in conducting operations during emergency A-1
21 conditions and resuming normal operations after the emergency. They are available at relocation sites or readily accessible electronically. Enduring Constitutional Government (ECG): A cooperative effort among the legislative, executive, and judicial branches of the Federal Government, coordinated by the President, as a matter of comity with respect to the legislative and judicial branches and with proper respect for the constitutional separation of powers among the branches, to preserve the constitutional framework under which the Nation is governed and the capability of all three branches of government to execute their constitutional responsibilities and provide for orderly succession, appropriate transition of leadership, interoperability, and support of NEFs during a catastrophic emergency. COOP is an integral part of COG and ECG. Essential Records & Systems: Hard copy or electronic records necessary to maintain continuity of operations during an emergency, to recover full operations following an emergency, and to protect the legal rights and interests of citizens and the U.S. Government. The two basic categories of essential records are emergency operating records, and legal and financial records. Incident Response Plan: The documentation of a predetermined set of instructions or procedures to detect, respond, and limit consequences of a malicious cyber-attack. Interoperable Communications: Alternate communications that provide the capability to perform minimum essential department or agency functions, to include reporting to higher authority, in conjunction with other agencies, until normal operations can be resumed. Legal and Financial Records: Records required for the preservation of the legal rights and interests of individual citizens and the Federal Government. These records require protection but need not be placed at, or in the vicinity of, relocation sites since the records would not be needed immediately. Designated and approved alternate site locations and/or Federal Records Centers may be used for dispersal storage. Examples of these records are those containing proof of ownership, financial interest (e.g., payroll, leave, social security, and retirement, insurance), legal proceeding decisions, and research (e.g., data, programs). Mission Essential Function (MEF): The limited set of department and agency-level government functions that continue after a disruption of normal activities. National Essential Function (NEF): The eight functions the President and national leadership focus on the requirement to lead and sustain the Nation during a catastrophic emergency. The eight NEFs are: 1. Ensuring the continued functioning of our form of government under the Constitution, including the functioning of the three separate branches of government; 2. Providing leadership visible to the Nation and the world and maintaining the trust and confidence of the American people; 3. Defending the Constitution of the United States against all enemies, foreign and domestic, and preventing or interdicting attacks against the United States or its people, property, or interests; 4. Maintaining and fostering effective relationships with foreign nations; 5. Protecting against threats to the homeland and bringing to justice perpetrators of crimes or attacks against the United States or its people, property, or interests; 6. Providing rapid and effective response to and recovery from the domestic consequences of an attack or other incident; A-2
22 7. Protecting and stabilizing the Nation's economy and ensuring public confidence in its financial systems; and 8. Providing for critical Federal Government services that address the national health, safety, and welfare needs of the United States. Plan Maintenance: Steps taken to ensure a plan is reviewed annually and updated whenever major changes occur. Primary Facility: The site of normal, day-to-day operations or the location where an employee usually goes to work. Primary Mission Essential Function (PMEF): A subset of an agency s Mission Essential Functions (MEFs) that directly support the National Essential Functions (NEFs). PMEFs will be approved by the National Continuity Coordinator subsequent to a formal nomination submission. PMEFs are continuous or resumed within 12 hours after an event and maintained for up to 30 days or until normal operations can be resumed. Reciprocal Agreement: An agreement between two organizations to support each other in the event of a declared disaster by either hosting critical applications on their servers or providing alternate workspace or both. Recovery Capability: The capability of an organization to continue without interruption, or restore critical functions in the event of a disaster or other emergency. Recovery Time Objective (RTO): The point in time at which the loss of a function becomes unacceptable to the organization and is the prioritization metric. Test, Training, and Exercise (TT&E): This activity includes: 1) efforts to hone skills; educate/advise designated staff of COOP responsibilities and the existing plans; and, 2) tests to demonstrate the viability and interoperability of all plans supporting COOP requirement. A-3
23 APPENDIX B - Acronyms AAR After-Action Report AOL Alternate Operating Location BIA Business Impact Analysis COG Continuity of Government COGCON Continuity of Government Condition COOP Continuity of Operations Plan CSS Command Support Staff DART Disaster Assessment and Reconstitution Team DAS Damage Assessment Report ECG Enduring Constitutional Government EDT Eastern Daylight Time ERG Emergency Response Group EST Eastern Standard Time FCD Federal Continuity Directive FIPS Federal Information Processing Standard FISMA Federal Information Security Management Act of 2002 FMC Financial Management Center FOUO For Official Use Only GETS Government Emergency Telephone Service HSPD Homeland Security Presidential Directive HSPO [NOAA] Homeland Security Program Office IAP Incident Action Plan ICS Incident Command System LRG Leadership Response Group MEF Mission Essential Function MFR Memorandum for the Record NCC National Continuity Coordinator (Department of Homeland Security) NCEP National Centers for Environmental Prediction NCR National Capital Region NCS National Communication System B-1
24 NCSD National Communication System Directive NEF National Essential Function NIMS National Incident Management System NIST National Institute of Standards and Technology NOAA National Oceanic and Atmospheric Administration NSPD National Security Presidential Directive NWS National Weather Service PDD Presidential Decision Directive PII Personally Identifiable Information PMEF Primary Mission Essential Function RFC River Forecast Center RSA Recovery Strategy Analysis RTO Recovery Time Objective SITREP Situation Report SPOTREP Spot Report TT&E Testing, training, and exercise USC US Code WFO NWS Forecast Office WPS Wireless Priority Service B-2
25 APPENDIX C - Continuity of Operations Sample Plan Contents Vol. I Policies and Procedures. NOTICE OF CONFIDENTIALITY 1 Introduction 1.1 Purpose 1.2 Applicability and Scope 2 Plan Objectives 2.1 Planning Phases Readiness and Preparedness Phase Activation and Relocation Phase Continuity and Operations Phase Reconstitution Phase 3 Essential Functions 3.2 Primary Mission Essential Functions 3.3 Critical Infrastructure 3.4 Interdependencies 4 Roles and Responsibilities 4.1 COOP Teams Incident Command Structure (ICS) Incident Commander (IC) Command Support Staff (CSS) Damage Assessment and Reconstitution Team (DART) 4.2 Key Personnel 4.3 Fly-away Kits or Go-Bags 5 Planning Assumptions 5.1 COOP Planning Assumptions Assume Preparedness Is Required for All Hazards and Conditions Assume the Need for Functional Redundancies, Cross-Training, and Alternative Leadership Options Assume the Potential Loss of Essential Personnel, Facilities, and Equipment Assume the Need for Support from the National Communications System Assume Activation without Warning Assume Constrained Resources C-1
26 5.1.7 Assume the Need for Special Communications and Staffing Plans Assume That NWS is a Target Assume the Need for Planning, Tests, Training, and Exercises Assume Long-Term Need for Resource and Personnel Reallocation Assume the Need for a Standing Inventory of Operational Requirements 5.2 COOP Planning Assumptions 5.3 Planning Scenarios Planning Impact 1. Loss of IT Infrastructure Planning Scenario 2. Loss of Telecommunications Connectivity Planning Scenario 3. Loss of Critical Personnel Planning Scenario 4. Denial of access to the Facility Planning Scenario 5. National or NCR Emergency 6 COOP Activation 6.1 Continuity of Government Conditions (COGCON) 6.2 COOP Activation Authorities 6.3 Orders of Succession during COOP Implementation 6.4 COOP Declaration Criteria Recovery Time Objectives COOP Situation Levels Critical Functions and Recovery Time Objectives 6.5 COOP Activation COOP Activation during Normal Hours COOP Activation during Non-Duty Hours Notification of Non-COOP Team Members 6.6 COOP Activation Reporting Procedures 6.7 Relocation Alternate Operating Location Operations Alternate Operating Location Telecommuting 6.8 Reconstitution 7 Devolution 7.1 Purpose 7.2 Applicability and Scope 7.3 Devolution Authority 7.4 Devolution Implementation Active Triggers C-2
27 7.4.2 Passive Triggers 7.5 Devolution support 8 Orders of Succession 9 Delegation of Authority 9.1 Delegations of Authority Training 10 Human Resource Management 10.1 Emergency Contact Information 11 Communications 12 Essential Records 12.1 Essential Records Authorities 12.2 Essential Records Liaison 12.3 Essential Records Inventory 13 Testing, Training, Exercising and Evaluating 13.1 Exercising/Testing 13.2 Training 13.3 Evaluation 14 Multi-Year Strategy and Program Management Plan Headquarters (HQ), NCEP, and Regional HQ only) 14.1 Responsibility 15 Reports 15.1 COOP Implementation Report Use Submission 15.2 Situation Report (SITREP) Use Submission 15.3 Damage Assessment Status (DAS) Report Use Submission 15.4 SPOT Report (SPOTREP) 15.5 After-Action Report (AAR) Submission 15.7 Message Log (ML) Submission 16 Plan Maintenance C-3
28 Appendices APPENDIX A - Authorities APPENDIX B - Definitions APPENDIX C - Acronyms APPENDIX D - National Incident Management System Implementation APPENDIX E - Damage Assessment and Reconstitution Team (DART) APPENDIX F - Orders of Succession Form APPENDIX G - Delegation of Authority Form APPENDIX H - COOP Report Templates APPENDIX I - NWS Contact information APPENDIX J - External Contact Information APPENDIX K - Continuity of Government Condition Matrix 12 APPENDIX L - Flyaway Kits APPENDIX M Alternate Operating Location APPENDIX N - Driving Directions AOL APPENDIX O - Exercise Template APPENDIX P - Family Emergency Plan Checklist Vol. II Checklists Incident Commander s Checklist Command Staff Checklist Operations Group Checklist Planning Group Checklist Logistics Group Checklist Finance and Administration Checklist DART Team Checklist NWSI May 17, Applicable to National Capital Region locations only C-4
29 APPENDIX D - Report Templates NWSI May 17, 2013 COOP Implementation Report Date/Time: Page of 1. Submitting Organization/Official: a. Contact Information 1) AOL Location: 2) Point of Contact: 3) Incident Commander: 4) Telephone: 5) Fax: b. Operating hours and periods: c. Personnel operating from AOL: d. Alternate Communications available and contact information: e. Telework Implemented: f. Estimated time to operate from AOL: D-1
30 Situation Report (SITREP) Report Number: Date/Time: Page of 1. Submitting Organization/Official: 2. Contact Information: a. AOL Location: b. Point of Contact: c. Incident Commander: d. Telephone: e. Fax: 3. Operating period: 4. Activities/Taskers Completed: 5. Activities/Taskers Outstanding: 6. Problems/Issues: D-2
31 8. Deviations Implemented: 9. Alternate Communications Implemented: D-3
32 Damage Assessment Report (DAS) Date/Time: Page of 1. Submitting Organization/Official: 2. DART Team Lead: 3. DART Team Members/Areas of Responsibility: 4. Findings: a. Facilities b. Power D-4
33 c. IT d. Telecommunications e. Personnel 5. Estimated time to repair 6. Recommendation(s): 7. COOP Declaration Recommendation: Declare Don t Declare D-5
Federal Continuity Directive 1 (FCD 1)
Federal Continuity Directive 1 (FCD 1) November 6, 2007 Federal Continuity Directive 1 (FCD 1) 6, 2007 Federal Continuity Directive 1 Federal Executive Branch National Continuity Program and Requirements
Department of Defense INSTRUCTION. Reference: (a) DoD Directive 3020.26, Defense Continuity Programs (DCP), September 8, 2004January 9, 2009
Department of Defense INSTRUCTION SUBJECT: Defense Continuity Plan Development NUMBER 3020.42 February 17, 2006 Certified current as of April 27, 2011 Reference: (a) DoD Directive 3020.26, Defense Continuity
Federal Continuity Directive 1 (FCD 1) Federal Continuity Directive 1 (FCD 1)
Federal Continuity Directive 1 (FCD 1) November 6, 2007 Federal Continuity Directive 1 (FCD 1) 6, 2007 Federal Continuity Directive 1 (FCD 1) Federal Executive Branch National Continuity Program and Requirements
Continuity of Operations Plan Template and Instructions for Federal Departments and Agencies July 2011. [Department/Agency Name] [Month Day, Year]
Continuity of Operations Plan Template and Instructions for Federal Departments and Agencies July 2011 [Department/Agency Name] [Month Day, Year] [Department/Agency Name] [Street Address] [City, State
DEPARTMENT OF THE NAVY HEADQUARTERS UNITED STATES MARINE CORPS 3000 MARINE CORPS PENTAGON WASHINGTON, DC 20350 3000
DEPARTMENT OF THE NAVY HEADQUARTERS UNITED STATES MARINE CORPS 3000 MARINE CORPS PENTAGON WASHINGTON, DC 20350 3000 MCO 3030.1 POC MARINE CORPS ORDER 3030.1 From : To: Commandant of the Marine Corps Distribution
CONTINUITY OF OPERATIONS
Court Services and Offender Supervision Agency for the District of Columbia POLICY STATEMENT CONTINUITY OF OPERATIONS I. COVERAGE This Policy Statement applies to all Court Services and Offender Supervision
Devolution of Operations Plan Template
[D/A Graphic] Devolution of Operations Plan Template April 2013 [Organization Name] [Street Address] [City, State Zip Code] [Organization Symbol] This page intentionally blank. ii [Organization Name] Devolution
FEDERAL EMERGENCY MANAGEMENT AGENCY (FEMA) INDEPENDENT STUDY COURSE INTRO TO INCIDENT COMMAND SYSTEM FOR FEDERAL WORKERS (IS-100.
This Study Guide has been created to provide an overview of the course content presented in the Federal Emergency Management Agency (FEMA) Independent Study Course titled IS-100.FWA Intro to Incident Command
Emergency Response Plan
Emergency Response Plan Public Version Contents INTRODUCTION... 4 SCOPE... 5 DEFINITION OF AN EMERGENCY... 5 AUTHORITY... 6 ACTION PRIOR TO DECLARATION... 6 FREEDOM OF INFORMATION & PRIVACY PROTECTION...
RECONSTITUTION PLAN K-1
RECONSTITUTION PLAN Reconstitution is restoring NOAA's ability to carry out all aspects of normal operations, the restoration of the capabilities that existed prior to the emergency. Reconstitution may
NIMS ICS 100.HCb. Instructions
NIMS ICS 100.HCb Instructions This packet contains the NIMS 100 Study Guide and the Test Questions for the NIMS 100 final exam. Please review the Study Guide. Next, take the paper test - record your answers
Comprehensive Emergency Management Plan (CEMP) Annex V CONTINUITY OF OPERATIONS PLAN (COOP)
Annex V CONTINUITY OF OPERATIONS PLAN (COOP) Milwaukee County Office of the Sheriff (MCSO) Division of Emergency Management Milwaukee County, ANNEX V CONTINUITY OF OPERATIONS PLAN (COOP) TABLE OF CONTENTS
Continuity of Operations:
Continuity of Operations: By Robert Marinelli The past twelve months have provided many challenges due to severe weather events. Massachusetts has withstood a major tropical storm, tornados, and several
Continuity of Operations (COOP) Plan Template Instructions. Federal Emergency Management Agency 500 C ST, SW Washington, D.C.
Continuity of Operations (COOP) Plan Template Instructions Federal Emergency Management Agency 500 C ST, SW Washington, D.C. 20472 FEMA GUIDE INSTRUCTIONS This guide provides instructions for developing
CONTINUITY OF OPERATION PLAN (COOP) FOR NONPROFIT HUMAN SERVICES PROVIDERS
A L L I A N C E F O R H U M A N S E R V I C E S www.alliance4hs.org CONTINUITY OF OPERATION PLAN (COOP) FOR NONPROFIT HUMAN SERVICES PROVIDERS ALLIANCE FOR HUMAN SERVICES & MIAMI-DADE COUNTY OFFICE OF
Business Continuity Planning Toolkit. (For Deployment of BCP to Campus Departments in Phase 2)
Business Continuity Planning Toolkit (For Deployment of BCP to Campus Departments in Phase 2) August 2010 CONTENTS: Background Assumptions Business Impact Analysis Risk (Vulnerabilities) Assessment Backup
U.S. Department of Energy Washington, D.C.
U.S. Department of Energy Washington, D.C. ORDER DOE O 150.1A Approved: SUBJECT: CONTINUITY PROGRAMS 1. PURPOSE. The purpose of this Order is: a. to assign and describe continuity roles and responsibilities
Continuity Guidance Circular 2 (CGC 2)
Continuity Guidance Circular 2 (CGC 2) Continuity Guidance for Non-Federal Governments: Mission Essential Functions Identification Process (States, Territories, Tribes, and Local Government Jurisdictions)
Legislative Language
Legislative Language SEC. 1. COORDINATION OF FEDERAL INFORMATION SECURITY POLICY. (a) IN GENERAL. Chapter 35 of title 44, United States Code, is amended by striking subchapters II and III and inserting
FEDERAL PREPAREDNESS CIRCULAR Federal Emergency Management Agency Washington, D.C. 20472 FPC 67
FEDERAL PREPAREDNESS CIRCULAR Federal Emergency Management Agency Washington, D.C. 20472 FPC 67 April 30, 2001 TO: SUBJECT: HEADS OF FEDERAL DEPARTMENTS AND AGENCIES ACQUISITION OF ALTERNATE FACILITIES
Business Continuity Planning 101. +1 610 768-4120 (800) 634-2016 www.strohlsystems.com [email protected]
Business Continuity Planning 101 Presentation Overview What is business continuity planning Plan Development Plan Testing Plan Maintenance Future advancements in BCP Question & Answer What is a Disaster?
Continuity of Operations Plan Template
Continuity of Operations Plan Template Office of Water (4608-T) EPA 817-B-14-007 November 2014 Please note: The golden key sticky notes located throughout the template provide additional information and
ICS-400: Advanced ICS for Command and General Staff, Complex Incidents and MACS for Operational First Responders (H-467)
ICS-400: Advanced ICS for Command and General Staff, Complex Incidents and MACS for Operational First Responders (H-467) Student Manual August 2006 National Fire Academy U.S. Fire Administration Directorate
THE WHITE HOUSE. Office of the Press Secretary. For Immediate Release February 12, 2013. February 12, 2013
THE WHITE HOUSE Office of the Press Secretary For Immediate Release February 12, 2013 February 12, 2013 PRESIDENTIAL POLICY DIRECTIVE/PPD-21 SUBJECT: Critical Infrastructure Security and Resilience The
All-Hazard Continuity of Operations Plan. [Department/College Name] [Date]
d All-Hazard Continuity of Operations Plan [Department/College Name] [Date] TABLE OF CONTENTS SECTION I: INTRODUCTION... 3 Executive Summary... 3 Introduction... 3 Goal... 4 Purpose... 4 Objectives...
Legislative Language
Legislative Language SECTION 1. DEPARTMENT OF HOMELAND SECURITY CYBERSECURITY AUTHORITY. Title II of the Homeland Security Act of 2002 (6 U.S.C. 121 et seq.) is amended (a) in section 201(c) by striking
EMERGENCY PREPAREDNESS PLAN Business Continuity Plan
EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic
CITY OF RICHMOND CONTINUITY OF OPERATIONS (COOP) DEPARTMENT PLAN TEMPLATE
CITY OF RICHMOND CONTINUITY OF OPERATIONS (COOP) DEPARTMENT PLAN TEMPLATE Version 2 February 2010 This template is derived from the Virginia Department of Emergency Management (VDEM) Local Government COOP
Continuity Plan Template and Instructions for Non-Federal Governments
Continuity Plan Template and Instructions for Non-Federal Governments [Department/Agency/Organization Name] [Month Day, Year] [Department/Agency/Organization Name] [Street Address] [City, State Zip Code]
Business Continuity Plan
Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions
UNION COLLEGE INCIDENT RESPONSE PLAN
UNION COLLEGE INCIDENT RESPONSE PLAN The college is committed to supporting the safety and welfare of all its students, faculty, staff and visitors. It also consists of academic, research and other facilities,
Table of Contents ESF-3-1 034-00-13
Table of Contents Primary Coordinating Agency... 2 Local Supporting Agencies... 2 State, Regional, and Federal Agencies and Organizations... 3 Purpose... 3 Situations and Assumptions... 4 Direction and
Table of Contents ESF-12-1 034-00-13
Table of Contents Primary Coordinating Agency... 2 Local Supporting Agencies... 2 State, Regional, and Federal Agencies and Organizations... 2 Purpose... 3 Situations and Assumptions... 4 Direction and
Miami-Dade County, Florida Emergency Operations Center (EOC) (your Dept. name here instead of EOC) Continuity of Operations Plan (COOP) Template
- Miami-Dade County, Florida Emergency Operations Center (EOC) (your Dept. name here instead of EOC) Continuity of Operations Plan (COOP) Template (Insert your department info here..) Miami-Dade County
Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0
Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0 Unless otherwise stated, these Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies
Ohio Supercomputer Center
Ohio Supercomputer Center IT Business Continuity Planning No: Effective: OSC-13 06/02/2009 Issued By: Kevin Wohlever Director of Supercomputer Operations Published By: Ohio Supercomputer Center Original
This page intentionally left blank.
This page intentionally left blank. This page intentionally left blank. CONTENTS List of Tables...vii List of Figures...vii What Is the National Incident Management System?...1 PREFACE... 3 INTRODUCTION
SAMPLE IT CONTINGENCY PLAN FORMAT
SAMPLE IT CONTINGENCY PLAN FORMAT This sample format provides a template for preparing an information technology (IT) contingency plan. The template is intended to be used as a guide, and the Contingency
H. R. 5005 11 SEC. 201. DIRECTORATE FOR INFORMATION ANALYSIS AND INFRA STRUCTURE PROTECTION.
H. R. 5005 11 (d) OTHER OFFICERS. To assist the Secretary in the performance of the Secretary s functions, there are the following officers, appointed by the President: (1) A Director of the Secret Service.
LAWRENCE COUNTY, KENTUCKY EMERGENCY OPERATIONS PLAN ESF-13
LAWRENCE COUNTY, KENTUCKY EMERGENCY OPERATIONS PLAN LAW ENFORCEMENT AND SECURITY ESF-13 Coordinates and organizes law enforcement and security resources in preparing for, responding to and recovering from
Pandemic Influenza Continuity of Operations Annex Template
Pandemic Influenza Continuity of Operations Annex Template Federal Emergency Management Agency 500 C ST, SW Washington, D.C. 20472 FEMA This page intentionally left blank TEMPLATE INSTRUCTIONS This template
TITLE III INFORMATION SECURITY
H. R. 2458 48 (1) maximize the degree to which unclassified geographic information from various sources can be made electronically compatible and accessible; and (2) promote the development of interoperable
HIGH-RISK SECURITY VULNERABILITIES IDENTIFIED DURING REVIEWS OF INFORMATION TECHNOLOGY GENERAL CONTROLS
Department of Health and Human Services OFFICE OF INSPECTOR GENERAL HIGH-RISK SECURITY VULNERABILITIES IDENTIFIED DURING REVIEWS OF INFORMATION TECHNOLOGY GENERAL CONTROLS AT STATE MEDICAID AGENCIES Inquiries
NOTICE: This publication is available at: http://www.nws.noaa.gov/directives/.
Department of Commerce National Oceanic & Atmospheric Administration National Weather Service NATIONAL WEATHER SERVICE INSTRUCTION 30-1203 JANUARY 23, 2012 Maintenance, Logistics, and Facilities Configuration
CONTINUITY OF OPERATIONS PLAN (COOP)
CONTINUITY OF OPERATIONS PLAN (COOP) DEPARTMENT OF HUMAN SERVICES CHILD WELFARE SERVICES BRANCH JUNE 2012 CONTINUITY OF OPERATIONS PLAN Child Welfare Services Branch Prepared for: Child Welfare Services
CISM Certified Information Security Manager
CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective
Final Exam for: IS-700.a: National Incident Management System (NIMS) An Introduction
Final Exam for: IS-700.a: National Incident Management System (NIMS) An Introduction Each time that this test is taken online, questions and answers are scrambled to protect the integrity of the exam Completion
Subject: Critical Infrastructure Identification, Prioritization, and Protection
For Immediate Release Office of the Press Secretary The White House December 17, 2003 Homeland Security Presidential Directive / HSPD-7 Subject: Critical Infrastructure Identification, Prioritization,
CONTINUITY OF OPERATIONS PLAN (COOP) Planning Guide and Outline
Final CONTINUITY OF OPERATIONS PLAN (COOP) Planning Guide and Outline A Format For the State, Local,and Tribal Terrorities to Use in Continuity Preparedness Prepared By the New York State Office of Emergency
85-01-55 Overview of Business Continuity Planning Sally Meglathery Payoff
85-01-55 Overview of Business Continuity Planning Sally Meglathery Payoff Because a business continuity plan affects all functional units within the organization, each functional unit must participate
www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014
www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 Agenda Key Definitions Risks Business Continuity Management Program BCM Capability Assessment Process BCM Value Proposition
ICS for LAUSD EOC and DOC Operation
ICS for LAUSD EOC and DOC Operation Below is some background information on the Incident Command System (used at our schools and in other field operations) and how it applies in an EOC environment. From
Standards for Security Categorization of Federal Information and Information Systems
FIPS PUB 199 FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION Standards for Security Categorization of Federal Information and Information Systems Computer Security Division Information Technology
Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM
Business Continuity Planning and Disaster Recovery Planning Ed Crowley IAM/IEM 1 Goals Compare and contrast aspects of business continuity Execute disaster recovery plans and procedures 2 Topics Business
BUSINESS CONTINUITY PLAN OVERVIEW
BUSINESS CONTINUITY PLAN OVERVIEW INTRODUCTION The purpose of this document is to provide Loomis customers with an overview of the company s Business Continuity Plan (BCP). Because of the specific and
Information Security for Managers
Fiscal Year 2015 Information Security for Managers Introduction Information Security Overview Enterprise Performance Life Cycle Enterprise Performance Life Cycle and the Risk Management Framework Categorize
CONTINUITY OF OPERATIONS PLAN (COOP)
CONTINUITY OF OPERATIONS PLAN (COOP) GADSDEN COUNTY DIVISION OF EMERGENCY MANAGEMENT April 2010 FINAL FOR OFFICIAL USE ONLY NOTICE: This document contains information pertaining to the deployment, mobilization,
Business Continuity Planning and Disaster Recovery Planning
Business Continuity Planning and Disaster Recovery Planning Ed Crowley IAM/IEM 1 ISC 2 Key Areas of Knowledge Understand business continuity requirements 1. Develop and document project scope and plan
It also provides guidance for rapid alerting and warning to key officials and the general public of a potential or occurring emergency or disaster.
Emergency Support Function #2 Communications ESF Coordinator: Information Technology Department Support Agencies: Tucson Fire Department Parks and Recreation Department Tucson Police Department Tucson
University of San Francisco EMERGENCY OPERATIONS PLAN
University of San Francisco EMERGENCY OPERATIONS PLAN University of San Francisco Emergency Operations Plan Plan Contact Eric Giardini Director of Campus Resilience 415-422-4222 This plan complies with
OREGON STATE UNIVERSITY MASTER EMERGENCY MANAGEMENT PLAN
OREGON STATE UNIVERSITY MASTER EMERGENCY MANAGEMENT PLAN Last Edit 2/8/2011 OVERVIEW This document provides a management framework for responding to incidents that may threaten the health and safety of
HIPAA Security COMPLIANCE Checklist For Employers
Compliance HIPAA Security COMPLIANCE Checklist For Employers All of the following steps must be completed by April 20, 2006 (April 14, 2005 for Large Health Plans) Broadly speaking, there are three major
All. Presidential Directive (HSPD) 7, Critical Infrastructure Identification, Prioritization, and Protection, and as they relate to the NRF.
Coordinating Agency: Department of Homeland Security Cooperating Agencies: All INTRODUCTION Purpose Scope This annex describes the policies, responsibilities, and concept of operations for Federal incident
Lesson 1: What Is the National Incident Management System (NIMS)? Summary of Lesson Content
Lesson 1: What Is the National Incident Management System (NIMS)? Lesson Overview On February 28, 2003, President Bush issued Homeland Security Presidential Directive 5. HSPD 5 directed the Secretary of
Is a standardized management tool for meeting the demands of small or large emergency or nonemergency situations.
Incident Command System (ICS) ICS was developed in the 1970s following a series of catastrophic fires in California's urban interface. Property damage ran into the millions, and many people died or were
Technology Infrastructure Services
LOB #303: DISASTER RECOVERY Technology Infrastructure Services Purpose Disaster Recovery (DR) for IT is a capability to restore enterprise-wide technology infrastructure, applications and data that are
HIPAA Security. 2 Security Standards: Administrative Safeguards. Security Topics
HIPAA Security SERIES Security Topics 1. Security 101 for Covered Entities 5. 2. Security Standards - Organizational, Security Policies Standards & Procedures, - Administrative and Documentation Safeguards
March 2007 Report No. 07-009. FDIC s Contract Planning and Management for Business Continuity AUDIT REPORT
March 2007 Report No. 07-009 FDIC s Contract Planning and Management for Business Continuity AUDIT REPORT Report No. 07-009 March 2007 FDIC s Contract Planning and Management for Business Continuity Results
[Organization Name] Continuity Multi-Year Strategy and Program Management Plan (MYSPMP) Template February 2014
[Organization Name] Continuity Multi-Year Strategy and Program Management Plan (MYSPMP) Template February 2014 [Organization Logo] i This page intentionally left blank ii [Organization Name] [City, State
NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems
NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems Marianne Swanson NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY 1 Table Of Contents Introduction to NIST SP 800-34
Draft 8/1/05 SYSTEM First Rev. 8/9/05 2 nd Rev. 8/30/05 EMERGENCY OPERATIONS PLAN
Draft 8/1/05 SYSTEM First Rev. 8/9/05 2 nd Rev. 8/30/05 EMERGENCY OPERATIONS PLAN I. INTRODUCTION A. PURPOSE - The University of Hawaii System Emergency Operations Plan (EOP) provides procedures for managing
Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION
Federal Financial Institutions Examination Council FFIEC Business Continuity Planning MARCH 2003 MARCH 2008 BCP IT EXAMINATION H ANDBOOK TABLE OF CONTENTS INTRODUCTION... 1 BOARD AND SENIOR MANAGEMENT
December 17, 2003 Homeland Security Presidential Directive/Hspd-7
For Immediate Release Office of the Press Secretary December 17, 2003 December 17, 2003 Homeland Security Presidential Directive/Hspd-7 Subject: Critical Infrastructure Identification, Prioritization,
Contingency Planning Guide for Information Technology Systems
NIST Special Publication 800-34 Contingency Planning Guide for Information Technology Systems Recommendations of the National Institute of Standards and Technology Marianne Swanson, Amy Wohl, Lucinda Pope,
Office of Inspector General
DEPARTMENT OF HOMELAND SECURITY Office of Inspector General Security Weaknesses Increase Risks to Critical United States Secret Service Database (Redacted) Notice: The Department of Homeland Security,
ON-SITE INCIDENT MANAGEMENT
ON-SITE INCIDENT MANAGEMENT Capability Definition Onsite Incident is the capability to effectively direct and control incident activities by using the Incident Command System (ICS) consistent with the
IT Disaster Recovery and Business Resumption Planning Standards
Information Technology Disaster Recovery and Business IT Disaster Recovery and Business Adopted by the Information Services Board (ISB) on May 28, 1992 Policy No: Also see: 500-P1, 502-G1 Supersedes No:
Cornell University RECOVERY PLAN
Cornell University RECOVERY PLAN Table of Contents Table of Contents List of Tables Section 1 INTRODUCTION... 1-1 1.1 Purpose... 1-1 1.2 Applicability and Scope... 1-1 Section 2 RECOVERY PLAN ROLES AND
NEEDS BASED PLANNING FOR IT DISASTER RECOVERY
The Define/Align/Approve Reference Series NEEDS BASED PLANNING FOR IT DISASTER RECOVERY Disaster recovery planning is essential it s also expensive. That s why every step taken and dollar spent must be
[Insert Company Logo]
[Insert Company Logo] Business Continuity and Disaster Recovery Planning (BCDRP) Manual 1 Table of Contents Critical Business Information 4 Business Continuity and Disaster Recover Planning (BCDRP) Personnel
ESF 02 - Communications Annex, 2015
ESF 02 - Communications Annex, 2015 Table of contents I. Introduction... 3 A. Purpose... 3 B. Scope of Operations... 3 C. Specific Authorities and References... 4 II. Situation and Assumptions... 4 A.
BUSINESS CONTINUITY POLICY
BUSINESS CONTINUITY POLICY Last Review Date Approving Body n/a Audit Committee Date of Approval 9 th January 2014 Date of Implementation 1 st February 2014 Next Review Date February 2017 Review Responsibility
Success or Failure? Your Keys to Business Continuity Planning. An Ingenuity Whitepaper
Success or Failure? Your Keys to Business Continuity Planning An Ingenuity Whitepaper May 2006 Overview With the level of uncertainty in our world regarding events that can disrupt the operation of an
Public Law 113 283 113th Congress An Act
PUBLIC LAW 113 283 DEC. 18, 2014 128 STAT. 3073 Public Law 113 283 113th Congress An Act To amend chapter 35 of title 44, United States Code, to provide for reform to Federal information security. Be it
Unit Guide to Business Continuity/Resumption Planning
Unit Guide to Business Continuity/Resumption Planning (February 2009) Revised June 2011 Executive Summary... 3 Purpose and Scope for a Unit Business Continuity Plan(BCP)... 3 Resumption Planning... 4 Assumptions
NIST Special Publication 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems
NIST Special Publication 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems Marianne Swanson Pauline Bowen Amy Wohl Phillips Dean Gallup David Lynes NIST Special Publication 800-34
Colorado College. Emergency Management Plan
Colorado College Emergency Management Plan An Emergency Preparedness Message from the President of Colorado College Dear Colorado College Community: As we learned this past summer in the cases of the Waldo
Cornell University EMERGENCY MANAGEMENT PROGRAM
Cornell University EMERGENCY MANAGEMENT PROGRAM Table of Contents Table of Contents Section 1 INTRODUCTION... 2 Section 2 EMERGENCY MANAGEMENT COMPONENTS... 3 Prevention-Mitigation Plan... 3 Preparedness
Continuity of Operations Actions
Continuity of Operations Actions Executive Summary California must be prepared to continue operations during any type of threat or emergency, and must be able to quickly and effectively resume essential
No. 33 February 19, 2013. The President
Vol. 78 Tuesday, No. 33 February 19, 2013 Part III The President Executive Order 13636 Improving Critical Infrastructure Cybersecurity VerDate Mar2010 17:57 Feb 15, 2013 Jkt 229001 PO 00000 Frm 00001
Performs the Federal coordination role for supporting the energy requirements associated with National Special Security Events.
ESF Coordinator: Energy Primary Agency: Energy Support Agencies: Agriculture Commerce Defense Homeland Security the Interior Labor State Transportation Environmental Protection Agency Nuclear Regulatory
