TITOLO V - Capitolo 9 - LA CONTINUITÀ OPERATIVA Accountable: Board
|
|
|
- Clyde Cobb
- 10 years ago
- Views:
Transcription
1 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA GdR BI 263 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Mappatura COBIT 5 Elenco per Accountability 1
2 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Impegno per Ruolo... 4 Board... 5 EDM05 - Ensure Stakeholder Transparency... 5 Chief Operating Officer... 7 DSS04 - Manage Continuity... 7 Business Executives BAI06 - Manage Changes MEA01 - Monir, Evaluate and Assess Performance and Conformance Business Process Owners BAI04 - Manage Availability and Capacity Steering (Programmes/Projects) Committee BAI02 - Manage Requirements Definition BAI07 - Manage Change Acceptance and Transitioning Chief Risk Officer APO12 - Manage Risk Chief Information Security Officer DSS01 - Manage Operations Compliance MEA02 - Monir, Evaluate and Assess the System of Internal Control MEA03 - Monir, Evaluate and Assess Compliance with External Requirements Audit MEA02 - Monir, Evaluate and Assess the System of Internal Control MEA03 - Monir, Evaluate and Assess Compliance with External Requirements Chief Information Officer APO01 - Manage the IT Management Framework APO02 - Manage Strategy APO07 - Manage Human Resources APO10 - Manage Suppliers APO12 - Manage Risk MEA02 - Monir, Evaluate and Assess the System of Internal Control Head IT Operations BAI04 - Manage Availability and Capacity BAI09 - Manage Assets DSS02 - Manage Service Requests and Incidents
3 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA DSS04 - Manage Continuity Service Manager APO09 - Manage Service Agreements DSS02 - Manage Service Requests and Incidents Business Continuity Manager DSS04 - Manage Continuity
4 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Impegno per Ruolo Impegno Dominio / Accountability del Ruolo Rating Ruolo Audit Board EDM 2.3 Business Continuity Manager Business Executives Business Process Owners Chief Information Officer Chief Information Security Officer Chief Operating Officer Chief Risk Officer Compliance Head IT Operations APO Service Manager BAI DSS MEA Ruolo (Accountable) Steering (Programmes /Projects) Committee Piazzi,Natale Prampolini, Emanuele Romeo, Ugo Vignolo Lutati 4
5 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Board Board EDM05 - Ensure Stakeholder Transparency (Rating per ruolo :2.3) Ensure that enterprise IT performance and conformance measurement and reporting are transparent, with stakeholders approving the goals and metrics and the necessary remedial actions. Purpose Make sure that the communication stakeholders is effective and timely and the basis for reporting is established increase performance, identify areas for improvement, and confirm that IT-related objectives and strategies are in line with the enterprise s strategy. Process Outcomes (Goals) 1. Stakeholder reporting is in line with stakeholder requirements. 2. Reporting is complete, timely and accurate. 3. Communication is effective and stakeholders are satisfied. EDM Evaluate stakeholder reporting requirements. (Rating per ruolo :2.0) 9.A.III.3 tilo Comunicazioni alla Banca d'italia Input Actions improve value delivery Risk management issues for the board Feedback on allocation and effectiveness of resources and capabilities Refined scope from Board (EDM02.03) Board (EDM03.03) Board (EDM04.03) Audit (MEA02.08) Evaluation of enterprise reporting requirements Reporting and communication principles Chief Executive Officer (MEA01.01) Chief Executive Officer (MEA01.01) 5
6 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Board S.2. Identify requirements for reporting on information security stakeholders (e.g., what information is required, when it is required, how it is presented). 2.0 Chief Executive Officer, Chief Information Officer EDM Direct stakeholder communication and reporting. (Rating per ruolo :2.0) 9.A.III.3 tilo Comunicazioni alla Banca d'italia Input Risk analysis and risk profile reports for stakeholders from Chief Information Officer (APO12.04) Rules for validating and approving mandary reports Escalation guidelines Chief Executive Officer (MEA01.01), Audit (MEA03.04) Chief Information Officer (MEA01.05) S.3. Produce for stakeholders regular information security status reports that include information security activities, performance, achievements, risk profile, business benefits, hot pics (e.g., cloud, consumer products), outstanding risk (including compliance and audit) and capability gaps. 2.0 Chief Executive Officer, Chief Information Officer 6
7 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Operating Officer Chief Operating Officer DSS04 - Manage Continuity (Rating per ruolo :3.7) Establish and maintain a plan enable the business and IT respond incidents and disruptions in order continue operation of critical business processes and required IT services and maintain availability of information at a level acceptable the enterprise. Purpose Continue critical business operations and maintain availability of information at a level acceptable the enterprise in the event of a significant disruption. Process Outcomes (Goals) 1. Business-critical information is available the business in line with minimum required service levels. 2. Sufficient resilience is in place for critical services. 3. Service continuity tests have verified the effectiveness of the plan. 4. An up--date continuity plan reflects current business requirements. 5. Internal and external parties have been trained in the continuity plan. DSS Define the business continuity policy, objectives and scope. (Rating per ruolo :3.1) tilo 9.I.3 Banche soggette ai requisiti applicabili a tutti gli operari (Allega A, Sezione II) 9.I.4 Banche soggette ai requisiti particolari per i processi a rilevanza sistemica (Allega A, Sezione III) 9.A.I.1 Premessa 9.A.II.1 Ambi del piano di continuità operativa 9.A.II.3 Definizione del piano di continuità operativa e gestione delle crisi 9.A.III.2 Definizione del piano di continuità operativa e gestione delle crisi Input SLAs from Service Manager (APO09.03) 7
8 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Operating Officer Policy and objectives for business continuity Disruptive incident scenarios Assessments of current continuity capabilities and gaps Chief Executive Officer (APO01.04) B.1. Identify internal and outsourced business processes and service activities that are critical the 2.6 enterprise operations or necessary meet legal and/ or contractual obligations. B.2. Identify key stakeholders and roles and responsibilities for defining and agreeing on continuity 2.6 policy and scope. B.3. Define and document the agreed-on minimum policy objectives and scope for business continuity 2.4 and embed the need for continuity planning in the enterprise culture. B.4. Identify essential supporting business processes and related IT services. 2.5 Business Process Owners, Chief Information Officer, Head IT Operations, Service Manager, Business Continuity Manager DSS Maintain a continuity strategy. (Rating per ruolo :3.3) tilo 9.I.3 Banche soggette ai requisiti applicabili a tutti gli operari (Allega A, Sezione II) 9.I.4 Banche soggette ai requisiti particolari per i processi a rilevanza sistemica (Allega A, Sezione III) 9.A.I.1 Premessa 9.A.II.3 Definizione del piano di continuità operativa e gestione delle crisi 9.A.III.2 Definizione del piano di continuità operativa e gestione delle crisi 9.A.III.3 Comunicazioni alla Banca d'italia Input Risk-related root causes Risk impact communications from Chief Information Officer (APO12.06) 8
9 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Operating Officer Business impact analyses Continuity requirements Approved strategic options Chief Information Officer (APO12.02) Chief Information Officer (APO02.05) B.1. Identify potential scenarios likely give rise events that could cause significant disruptive 2.2 incidents. B.2. Conduct a business impact analysis evaluate the impact over time of a disruption critical 2.3 business functions and the effect that a disruption would have on them. B.3. Establish the minimum time required recover a business process and supporting IT based on an 2.7 acceptable length of business interruption and maximum lerable outage. B.4. Assess the likelihood of threats that could cause loss of business continuity and identify measures 2.4 that will reduce the likelihood and impact through improved prevention and increased resilience. B.5. Analyse continuity requirements identify the possible strategic business and technical options. 2.2 B.6. Identify potential scenarios likely give rise events that could cause significant disruptive 2.5 incidents. B.7. Determine the conditions and owners of key decisions that will cause the continuity plans be 2.6 invoked. B.8. Identify resource requirements and costs for each strategic technical option and make strategic 2.2 recommendations. B.9. Obtain executive business approval for selected strategic options. 2.0 Business Process Owners, Chief Information Officer, Head Architect, Head IT Operations, Business Continuity Manager DSS Review, maintain and improve the continuity plan. (Rating per ruolo :3.0) tilo 9.I.3 Banche soggette ai requisiti applicabili a tutti gli operari (Allega A, Sezione II) 9.I.4 Banche soggette ai requisiti particolari per i processi a rilevanza sistemica (Allega A, Sezione III) 9.A.II.3 Definizione del piano di continuità operativa e gestione delle crisi 9.A.III.2 Definizione del piano di continuità operativa e gestione delle crisi 9.A.III.3 Comunicazioni alla Banca d'italia 9
10 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Operating Officer Results of reviews of plans Recommended changes plans B.1. Review the continuity plan and capability on a regular basis against any assumptions made and current business operational and strategic objectives. B.2. Consider whether a revised business impact assessment may be required, depending on the nature of the change. B.3. Recommend and communicate changes in policy, plans, procedures, infrastructure, and roles and responsibilities for management approval and processing via the change management process. B.4. Review the continuity plan on a regular basis consider the impact of new or major changes : enterprise organisation, business processes, outsourcing arrangements, technologies, infrastructure, operating systems and application systems Business Process Owners, Chief Information Officer, Head IT Operations, Business Continuity Manager 10
11 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Executives Business Executives BAI06 - Manage Changes (Rating per ruolo :2.3) Manage all changes in a controlled manner, including standard changes and emergency maintenance relating business processes, applications and infrastructure. This includes change standards and procedures, impact assessment, prioritisation and authorisation, emergency changes, tracking, reporting, closure and documentation. Purpose Enable fast and reliable delivery of change the business and mitigation of the risk of negatively impacting the stability or integrity of the changed environment. Process Outcomes (Goals) 1. Authorised changes are made in a timely manner and with minimal errors. 2. Impact assessments reveal the effect of the change on all affected components. 3. All emergency changes are reviewed and authorised after the change. 4. Key stakeholders are kept informed of all aspects of the change. BAI Evaluate, prioritise and authorise change requests. (Rating per ruolo :1.9) 9.A.II.3 tilo Definizione del piano di continuità operativa e gestione delle crisi Input Integrated and configured solution components Approved service requests Proposed solutions known errors Identified sustainable solutions Approved changes the plans Root cause analyses and recommendations from Head Development (BAI03.05) Service Manager (DSS02.03) Head IT Operations (DSS03.03) Service Manager (DSS03.05) Business Continuity Manager (DSS04.08) Business Executives (DSS06.01) 11
12 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Executives Impact assessments Approved requests for change Change plan and schedule Steering (Programmes/Projects) Committee (BAI07.01) Steering (Programmes/Projects) Committee (BAI07.01) B.4. Plan and evaluate all requests in a structured fashion. Include an impact analysis on business process, infrastructure, systems and applications, business continuity plans (BCPs) and service providers ensure that all affected components have been identified. Assess the likelihood of adversely affecting the operational environment and the risk of implementing the change. Consider security, legal, contractual and compliance implications of the requested change. Consider also interdependencies amongst changes. Involve business process owners in the assessment process, as appropriate. 1.9 Business Process Owners, Chief Information Officer, Head Development, Head IT Operations, Service Manager BAI Close and document the changes. (Rating per ruolo :2.1) 9.A.II.3 tilo Definizione del piano di continuità operativa e gestione delle crisi Change documentation B.1. Include changes documentation (e.g., business and IT operational procedures, business continuity and disaster recovery documentation, configuration information, application documentation, help screens, and training materials) within the change management procedure as an integral part of the change
13 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Executives Business Process Owners, Project Management Office, Chief Information Officer, Head Development, Head IT Operations MEA01 - Monir, Evaluate and Assess Performance and Conformance (Rating per ruolo :2.4) Collect, validate and evaluate business, IT and process goals and metrics. Monir that processes are performing against agreed-on performance and conformance goals and metrics and provide reporting that is systematic and timely. Purpose Provide transparency of performance and conformance and drive achievement of goals. Process Outcomes (Goals) 1. Goals and metrics are approved by the stakeholders. 2. Processes are measured against agreed-on goals and metrics. 3. The enterprise moniring, assessing and informing approach is effective and operational. 4. Goals and metrics are integrated within enterprise moniring systems. 5. Process reporting on performance and conformance is useful and timely. MEA Analyse and report performance. (Rating per ruolo :2.4) 9.A.II.3 9.A.III.2 tilo Definizione del piano di continuità operativa e gestione delle crisi Definizione del piano di continuità operativa e gestione delle crisi Performance reports Board (EDM01.03), (All APO), (All BAI), (All DSS), (All MEA) 13
14 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Executives B.1. Design process performance reports that are concise, easy understand, and tailored various 1.6 management needs and audiences. Facilitate effective, timely decision making (e.g., scorecards, traffic light reports) and ensure that the cause and effect between goals and metrics are communicated in an understandable manner. B.2. Compare the performance values internal targets and benchmarks and, where possible, 1.6 external benchmarks (industry and key competirs). B.3. Recommend changes the goals and metrics, where appropriate. 1.6 B.4. Distribute reports the relevant stakeholders. 1.6 B.5. Analyse the cause of deviations against targets, initiate remedial actions, assign responsibilities 1.6 for remediation, and follow up. At appropriate times, review all deviations and search for root causes, where necessary. Document the issues for further guidance if the problem recurs. Document results. B.6. Where feasible, link achievement of performance targets the organisational reward 1.6 compensation system. Business Process Owners, Head Development, Head IT Operations, Service Manager 14
15 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Process Owners Business Process Owners BAI04 - Manage Availability and Capacity (Rating per ruolo :2.5) Balance current and future needs for availability, performance and capacity with cost-effective service provision. Include assessment of current capabilities, forecasting of future needs based on business requirements, analysis of business impacts, and assessment of risk plan and implement actions meet the identified requirements. Purpose Maintain service availability, efficient management of resources, and optimisation of system performance through prediction of future performance and capacity requirements. Process Outcomes (Goals) 1. The availability plan anticipates the business expectation of critical capacity requirements. 2. Capacity, performance and availability meet requirements. 3. Availability, performance and capacity issues are identified and routinely resolved. BAI Assess business impact. (Rating per ruolo :2.5) 9.A.II.2 tilo Analisi di impat Input Internal and external SLAs from Head Development (BAI03.02) Availability, performance and capacity scenarios Availability, performance and capacity business impact assessments 15
16 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Process Owners B.1. Identify only those solutions or services that are critical in the availability and capacity management process. B.2. Map the selected solutions or services application(s) and infrastructure (IT and facility) on which they depend enable a focus on critical resources for availability planning. B.3. Collect data on availability patterns from logs of past failures and performance moniring. Use modelling ols that help predict failures based on past usage trends and management expectations of new environment or user conditions. B.4. Create scenarios based on the collected data, describing future availability situations illustrate a variety of potential capacity levels needed achieve the availability performance objective. B.5. Determine the likelihood that the availability performance objective will not be achieved based on the scenarios. B.6. Determine the impact of the scenarios on the business performance measures (e.g., revenue, profit, cusmer services). Engage the business line, functional (especially finance) and regional leaders understand their evaluation of impact. B.7. Ensure that business process owners fully understand and agree the results of this analysis. From the business owners, obtain a list of unacceptable risk scenarios that require a response reduce risk acceptable levels Head IT Operations, Service Manager 16
17 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Steering (Programmes/Projects) Committee Steering (Programmes/Projects) Committee BAI02 - Manage Requirements Definition (Rating per ruolo :2.3) Identify solutions and analyse requirements before acquisition or creation ensure that they are in line with enterprise strategic requirements covering business processes, applications, information/data, infrastructure and services. Co-ordinate with affected stakeholders the review of feasible options including relative costs and benefits, risk analysis, and approval of requirements and proposed solutions. Purpose Create feasible optimal solutions that meet enterprise needs while minimising risk. Process Outcomes (Goals) 1. Business functional and technical requirements reflect enterprise needs and expectations. 2. The proposed solution satisfies business functional, technical and compliance requirements. 3. Risk associated with the requirements has been addressed in the proposed solution. 4. Requirements and proposed solutions meet business case objectives (value expected and likely costs). BAI Define and maintain business functional and technical requirements. (Rating per ruolo :2.3) 9.A.II.1 9.A.II.3 tilo Ambi del piano di continuità operativa Definizione del piano di continuità operativa e gestione delle crisi Input Data integrity procedures Data security and control guidelines Data classification guidelines Architecture principles Information architecture model Baseline domain descriptions and architecture definition Solution development guidance Supplier RFIs and RFPs Acceptance criteria from Business Executives (APO01.06) Chief Executive Officer (APO03.01) Architecture Board (APO03.02) Chief Executive Officer (APO03.05) Chief Information Officer (APO10.02) Business Executives (APO11.03) 17
18 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Steering (Programmes/Projects) Committee Requirements definition reposiry Confirmed acceptance criteria from stakeholders Record of requirement change requests Head Development (BAI03.01), Head Development (BAI03.02), Head IT Operations (BAI04.01), Chief Executive Officer (BAI05.01) Head Development (BAI03.01), Head Development (BAI03.02), Head IT Operations (BAI04.03), Chief Executive Officer (BAI05.01), Business Executives (BAI05.02) Steering (Programmes/Projects) Committee (BAI03.09) B.6. Confirm acceptance of key aspects of the requirements, including enterprise rules, information controls, business continuity, legal and regulary compliance, auditability, ergonomics, operability and usability, safety, and supporting documentation. 2.3 Business Process Owners, Project Management Office, Head Architect, Head Development BAI07 - Manage Change Acceptance and Transitioning (Rating per ruolo :1.5) Formally accept and make operational new solutions, including implementation planning, system and data conversion, acceptance testing, communication, release preparation, promotion production of new or changed business processes and IT services, early production support, and a post-implementation review. Purpose Implement solutions safely and in line with the agreed-on expectations and outcomes. Process Outcomes (Goals) 1. Acceptance testing meets stakeholder approval and takes in account all aspects of the implementation and conversion plans. 2. Releases are ready for promotion in production with stakeholder readiness and support. 3. Releases are promoted successfully, are stable and meet expectations. 4. Lessons learned contribute future releases. BAI Plan business process, system and data conversion. (Rating per ruolo :1.5) 18
19 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Steering (Programmes/Projects) Committee A.II.3 tilo Definizione del piano di continuità operativa e gestione delle crisi Migration plan Business Executives (DSS06.02) B.6. Consider the risk of conversion problems, business continuity planning, and fallback procedures in the business process, data and infrastructure migration plan where there are risk management, business needs or regulary/compliance requirements. 1.5 Business Process Owners, Chief Risk Officer, Chief Information Officer, Head Development, Service Manager, Information Security Manager, Business Continuity Manager 19
20 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Risk Officer Chief Risk Officer APO12 - Manage Risk (Rating per ruolo :2.0) Continually identify, assess and reduce IT-related risk within levels of lerance set by enterprise executive management. Purpose Integrate the management of IT-related enterprise risk with overall ERM, and balance the costs and benefits of managing IT-related enterprise risk. Process Outcomes (Goals) 1. IT-related risk is identified, analysed, managed and reported. 2. A current and complete risk profile exists. 3. All significant risk management actions are managed and under control. 4. Risk management actions are implemented effectively. APO Maintain a risk profile. (Rating per ruolo :2.0) 9.A.III.2 tilo Definizione del piano di continuità operativa e gestione delle crisi Input Approved risk lerance levels Risk appetite guidance Identified supplier delivery risk Evaluations of potential threats from Board (EDM03.01) Chief Information Officer (APO10.04) Chief Information Security Officer (DSS05.01) Documented risk scenarios by line of business and function Aggregated risk profile, including status of risk management actions Board (EDM03.02), Chief Information Officer (APO02.02) 20
21 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Risk Officer B.1. Invenry business processes, including supporting personnel, applications, infrastructure, 1.1 facilities, critical manual records, vendors, suppliers and outsourcers, and document the dependency on IT service management processes and IT infrastructure resources. B.2. Determine and agree on which IT services and IT infrastructure resources are essential sustain 1.1 the operation of business processes. Analyse dependencies and identify weak links. B.3. Aggregate current risk scenarios by category, business line and functional area. 1.1 B.4. On a regular basis, capture all risk profile information and consolidate it in an aggregated risk 1.1 profile. B.5. Based on all risk profile data, define a set of risk indicars that allow the quick identification and 1.1 moniring of current risk and risk trends. B.6. Capture information on IT risk events that have materialised, for inclusion in the IT risk profile of 1.1 the enterprise. B.7. Capture information on the status of the risk action plan, for inclusion in the IT risk profile of the 1.1 enterprise. Business Process Owners, Compliance, Audit, Chief Information Officer 21
22 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Security Officer Chief Information Security Officer DSS01 - Manage Operations (Rating per ruolo :2.9) Co-ordinate and execute the activities and operational procedures required deliver internal and outsourced IT services, including the execution of pre-defined standard operating procedures and the required moniring activities. Purpose Deliver IT operational service outcomes as planned. Process Outcomes (Goals) 1. Operational activities are performed as required and scheduled. 2. Operations are monired, measured, reported and remediated. DSS Manage the environment. (Rating per ruolo :2.4) 9.A.III.2 tilo Definizione del piano di continuità operativa e gestione delle crisi Environmental policies Insurance policy reports Chief Executive Officer (APO01.08) Compliance (MEA03.03) B.1. Identify natural and man-made disasters that might occur in the area within which the IT facilities are located. Assess the potential effect on the IT facilities. B.3. Situate and construct IT facilities minimise and mitigate susceptibility environmental threats Head IT Operations, Information Security Manager 22
23 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Security Officer DSS Manage facilities. (Rating per ruolo :2.7) 9.A.II.1 tilo Ambi del piano di continuità operativa Facilities assessment reports Health and safety awareness Chief Information Officer (MEA01.03) 23
24 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Security Officer B.1. Examine the IT facilities requirement for protection against power fluctuations and outages, in conjunction with other business continuity planning requirements. Procure suitable uninterruptible supply equipment (e.g., batteries, generars) support business continuity planning. B.2. Regularly test the uninterruptible power supply s mechanisms, and ensure that power can be switched the supply without any significant effect on business operations. B.3. Ensure that the facilities housing the IT systems have more than one source for dependent utilities (e.g., power, telecommunications, water, gas). Separate the physical entrance of each utility. B.4. Confirm that cabling external the IT site is located underground or has suitable alternative protection. Determine that cabling within the IT site is contained within secured conduits, and wiring cabinets have access restricted authorised personnel. Properly protect cabling against damage caused by fire, smoke, water, interception and interference. B.5. Ensure that cabling and physical patching (data and phone) are structured and organised. Cabling and conduit structures should be documented (e.g., blueprint building plan and wiring diagrams). B.6. Analyse the facilities housing s high-availability systems for redundancy and fail-over cabling requirements (external and internal). B.7. Ensure that IT sites and facilities are in ongoing compliance with relevant health and safety laws, regulations, guidelines, and vendor specifications. B.8. Educate personnel on a regular basis on health and safety laws, regulations, and relevant guidelines. Educate personnel on fire and rescue drills ensure knowledge and actions taken in case of fire or similar incidents. B.9. Record, monir, manage and resolve facilities incidents in line with the IT incident management process. Make available reports on facilities incidents where disclosure is required in terms of laws and regulations. B.10. Ensure that IT sites and equipment are maintained according the supplier s recommended service intervals and specifications. The maintenance must be carried out only by authorised personnel. B.11. Analyse physical alterations IT sites or premises reassess the environmental risk (e.g., fire or water damage). Report results of this analysis business continuity and facilities management Head IT Operations, Information Security Manager 24
25 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Compliance Compliance MEA02 - Monir, Evaluate and Assess the System of Internal Control (Rating per ruolo :1.5) Continuously monir and evaluate the control environment, including self-assessments and independent assurance reviews. Enable management identify control deficiencies and inefficiencies and initiate improvement actions. Plan, organise and maintain standards for internal control assessment and assurance activities. Purpose Obtain transparency for key stakeholders on the adequacy of the system of internal controls and thus provide trust in operations, confidence in the achievement of enterprise objectives and an adequate understanding of residual risk. Process Outcomes (Goals) 1. Processes, resources and information meet enterprise internal control system requirements. 2. All assurance initiatives are planned and executed effectively. 3. Independent assurance that the system of internal control is operational and effective is provided. 4. Internal control is established and deficiencies are identified and reported. MEA Ensure that assurance providers are independent and qualified. (Rating per ruolo :1.5) 9.A.III.2 tilo Definizione del piano di continuità operativa e gestione delle crisi B.1. Establish adherence applicable codes of ethics and standards (e.g., Code of Professional Ethics 1.0 of ISACA) and (industry- and geography-specific) assurance standards, e.g., IT Audit and Assurance Standards of ISACA and the International Auditing and Assurance Standards Board s (IAASB s) International Framework for Assurance Engagements (IAASB Assurance Framework). B.2. Establish independence of assurance providers. 1.0 B.3. Establish competency and qualification of assurance providers
26 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Compliance Business Process Owners, Chief Information Officer MEA03 - Monir, Evaluate and Assess Compliance with External Requirements (Rating per ruolo :2.0) Evaluate that IT processes and IT-supported business processes are compliant with laws, regulations and contractual requirements. Obtain assurance that the requirements have been identified and complied with, and integrate IT compliance with overall enterprise compliance. Purpose Ensure that the enterprise is compliant with all applicable external requirements. Process Outcomes (Goals) 1. All external compliance requirements are identified. 2. External compliance requirements are adequately addressed. MEA Confirm external compliance. (Rating per ruolo :2.0) 9.A.III.2 tilo Definizione del piano di continuità operativa e gestione delle crisi Input Compliance audit results Results of installed licence audits Licence deviations Insurance policy reports from Business Executives (BAI05.06) Chief Information Officer (BAI09.05) Head IT Operations (BAI10.05) Chief Information Security Officer (DSS01.04) Identified compliance gaps Compliance confirmations Audit (MEA02.08) Board (EDM01.03) 26
27 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Compliance B.1. Regularly evaluate organisational policies, standards, procedures and methodologies in all 1.4 functions of the enterprise ensure compliance with relevant legal and regulary requirements in relation the processing of information. B.2. Address compliance gaps in policies, standards and procedures on a timely basis. 1.4 B.3. Periodically evaluate business and IT processes and activities ensure adherence applicable 1.4 legal, regulary and contractual requirements. B.4. Regularly review for recurring patterns of compliance failures. Where necessary, improve 1.4 policies, standards, procedures, methodologies, and associated processes and activities. Chief Executive Officer, Chief Financial Officer, Chief Operating Officer, Business Executives, Business Process Owners, Chief Information Officer, Privacy Officer 27
28 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Audit Audit MEA02 - Monir, Evaluate and Assess the System of Internal Control (Rating per ruolo :2.2) Continuously monir and evaluate the control environment, including self-assessments and independent assurance reviews. Enable management identify control deficiencies and inefficiencies and initiate improvement actions. Plan, organise and maintain standards for internal control assessment and assurance activities. Purpose Obtain transparency for key stakeholders on the adequacy of the system of internal controls and thus provide trust in operations, confidence in the achievement of enterprise objectives and an adequate understanding of residual risk. Process Outcomes (Goals) 1. Processes, resources and information meet enterprise internal control system requirements. 2. All assurance initiatives are planned and executed effectively. 3. Independent assurance that the system of internal control is operational and effective is provided. 4. Internal control is established and deficiencies are identified and reported. MEA Ensure that assurance providers are independent and qualified. (Rating per ruolo :1.5) 9.A.III.2 tilo Definizione del piano di continuità operativa e gestione delle crisi B.1. Establish adherence applicable codes of ethics and standards (e.g., Code of Professional Ethics 1.0 of ISACA) and (industry- and geography-specific) assurance standards, e.g., IT Audit and Assurance Standards of ISACA and the International Auditing and Assurance Standards Board s (IAASB s) International Framework for Assurance Engagements (IAASB Assurance Framework). B.2. Establish independence of assurance providers. 1.0 B.3. Establish competency and qualification of assurance providers
29 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Audit Business Process Owners, Chief Information Officer MEA Execute assurance initiatives. (Rating per ruolo :2.0) 9.A.II.3 tilo Definizione del piano di continuità operativa e gestione delle crisi Input Root causes of quality delivery failures Risk analysis and risk profile reports for stakeholders Risk-related root causes Results of penetration tests Root cause analyses and recommendations Identified compliance gaps from Chief Information Officer (APO11.05) Chief Information Officer (APO12.04) Chief Information Officer (APO12.06) Chief Information Security Officer (DSS05.02) Business Executives (DSS06.01) Compliance (MEA03.03) Refined scope Assurance review results Assurance review report (All APO), (All BAI), (All DSS), (All MEA) Board (EDM05.01), Board (EDM05.03), (All APO), (All BAI), (All DSS), (All MEA) Board (EDM05.03), (All APO), (All BAI), (All DSS), (All MEA) B.3. Test the effectiveness of the control design of the key control objectives. 1.7 B.4. Alternatively/additionally test the outcome of the key control objectives. 1.7 Business Process Owners, Chief Information Officer MEA03 - Monir, Evaluate and Assess Compliance with External Requirements (Rating per ruolo :2.3) Evaluate that IT processes and IT-supported business processes are compliant with laws, regulations and contractual requirements. Obtain assurance that the requirements have been identified and complied with, and integrate IT compliance with overall enterprise compliance. 29
30 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Audit Purpose Ensure that the enterprise is compliant with all applicable external requirements. Process Outcomes (Goals) 1. All external compliance requirements are identified. 2. External compliance requirements are adequately addressed. MEA Obtain assurance of external compliance. (Rating per ruolo :2.3) 9.A.II.3 tilo Definizione del piano di continuità operativa e gestione delle crisi Input Rules for validating and approving mandary reports Assessment of reporting effectiveness from Board (EDM05.02) Board (EDM05.03) Compliance assurance reports Reports of non-compliance issues and root causes Board (EDM01.03) Board (EDM01.03), Audit (MEA02.07) B.1. Obtain regular confirmation of compliance with internal policies from business and IT process 1.6 owners and unit heads. B.2. Perform regular (and, where appropriate, independent) internal and external reviews assess 1.6 levels of compliance. B.3. If required, obtain assertions from third-party IT service providers on levels of their compliance 1.6 with applicable laws and regulations. B.4. If required, obtain assertions from business partners on levels of their compliance with applicable 1.6 laws and regulations as they relate intercompany electronic transactions. B.5. Monir and report on non-compliance issues and, where necessary, investigate the root cause. 1.6 B.6. Integrate reporting on legal, regulary and contractual requirements at an enterprisewide level, 1.6 involving all business units. Chief Information Officer 30
31 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Officer Chief Information Officer APO01 - Manage the IT Management Framework (Rating per ruolo :2.3) Clarify and maintain the governance of enterprise IT mission and vision. Implement and maintain mechanisms and authorities manage information and the use of IT in the enterprise in support of governance objectives in line with guiding principles and policies. Purpose Provide a consistent management approach enable the enterprise governance requirements be met, covering management processes, organisational structures, roles and responsibilities, reliable and repeatable activities, and skills and competencies. Process Outcomes (Goals) 1. An effective set of policies is defined and maintained. 2. Everyone is aware of the policies and how they should be implemented. APO Establish roles and responsibilities. (Rating per ruolo :2.3) tilo 9.I.3 Banche soggette ai requisiti applicabili a tutti gli operari (Allega A, Sezione II) 9.I.4 Banche soggette ai requisiti particolari per i processi a rilevanza sistemica (Allega A, Sezione III) Input Authority levels Assigned responsibilities for resource management Skill development plans Skills and competencies matrix Quality management system (QMS) roles, responsibilities and decision rights Information security management system (ISMS) scope statement Allocated levels of authority Allocated roles and responsibilities from Board (EDM01.01) Board (EDM04.02) Chief Information Officer (APO07.03) Chief Operating Officer (APO11.01) Chief Information Security Officer (APO13.01) Business Executives (DSS06.03) 31
32 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Officer Definition of IT-related roles and responsibilities Definition of supervisory practices Chief Information Security Officer (DSS05.04) Chief Information Officer (APO07.01) B.1. Establish, agree on and communicate IT-related roles and responsibilities for all personnel in the enterprise, in alignment with business needs and objectives. Clearly delineate responsibilities and accountabilities, especially for decision making and approvals. B.2. Consider requirements from enterprise and IT service continuity when defining roles, including staff back-up and cross-training requirements. B.3. Provide input the IT service continuity process by maintaining up--date contact information and role descriptions in the enterprise Head IT Administration APO02 - Manage Strategy (Rating per ruolo :1.8) Provide a holistic view of the current business and IT environment, the future direction, and the initiatives required migrate the desired future environment. Leverage enterprise architecture building blocks and components, including externally provided services and related capabilities enable nimble, reliable and efficient response strategic objectives. Purpose Align strategic IT plans with business objectives. Clearly communicate the objectives and associated accountabilities so they are undersod by all, with the IT strategic options identified, structured and integrated with the business plans. Process Outcomes (Goals) 1. All aspects of the IT strategy are aligned with the enterprise strategy. 2. The IT strategy is cost-effective, appropriate, realistic, achievable, enterprise-focussed and balanced. 3. Clear and concrete short-term goals can be derived from, and traced back, specific long-term initiatives, and can then be translated in operational plans. 4. IT is a value driver for the enterprise. 5. There is awareness of the IT strategy and a clear assignment of accountability for delivery. APO Assess the current environment, capabilities and performance. (Rating per ruolo :1.8) 32
33 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Officer A.III.3 tilo Comunicazioni alla Banca d'italia Input Cost optimisation opportunities Definition of potential improvement projects Identified gaps in IT services the business Improvement action plans and remediations Emerging risk issues and facrs Risk analysis results Aggregated risk profile, including status of risk management actions Project proposals for reducing risk Performance and capacity plans Prioritised improvements Corrective actions Results of fit-for-purpose reviews Opportunities reduce asset costs or increase value Results of cost optimisation reviews from Chief Information Officer (APO06.05) Chief Information Officer (APO08.05) Service Manager (APO09.01) Service Manager (APO09.04) Chief Information Officer (APO12.01) Chief Information Officer (APO12.02) Chief Risk Officer (APO12.03) Chief Risk Officer (APO12.05) Head IT Operations (BAI04.03) Head IT Operations (BAI04.05) Head IT Operations (BAI09.01) Chief Information Officer (BAI09.04) Baseline of current capabilities Gaps and risk related current capabilities Capability SWOT analysis Chief Information Officer (APO12.01) B.1. Develop a baseline of the current business and IT environment, capabilities and services against 1.2 which future requirements can be compared. Include the relevant high-level detail of the current enterprise architecture (business, information, data, applications and technology domains), business processes, IT processes and procedures, the IT organisation structure, external service provision, governance of IT, and enterprisewide IT related skills and competencies. B.2. Identify risk from current, potential and declining technologies. 1.2 B.3. Identify gaps between current business and IT capabilities and services and reference standards 1.2 and best practices, competir business and IT capabilities, and comparative benchmarks of best practice and emerging IT service provision. B.4. Identify issues, strengths, opportunities and threats in the current environment, capabilities and 1.2 services understand current performance. Identify areas for improvement in terms of IT s contribution enterprise objectives. 33
34 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Officer Business Executives, Head Architect, Head Development, Head IT Operations APO07 - Manage Human Resources (Rating per ruolo :2.0) Provide a structured approach ensure optimal structuring, placement, decision rights and skills of human resources. This includes communicating the defined roles and responsibilities, learning and growth plans, and performance expectations, supported with competent and motivated people. Purpose Optimise human resources capabilities meet enterprise objectives. Process Outcomes (Goals) 1. The IT organisational structure and relationships are flexible and responsive. 2. Human resources are effectively and efficiently managed. APO Identify key IT personnel. (Rating per ruolo :2.0) 9.A.II.1 9.A.III.2 tilo Ambi del piano di continuità operativa Definizione del piano di continuità operativa e gestione delle crisi B.1. Minimise reliance on a single individual performing a critical job function through knowledge 1.8 capture (documentation), knowledge sharing, succession planning, staff backup, cross-training and job rotation initiatives. B.2. As a security precaution, provide guidelines on a minimum time of annual vacation be taken by 1.1 key individuals. B.3. Take expedient actions regarding job changes, especially job terminations. 1.1 B.4. Regularly test staff backup plans
35 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Officer Project Management Office, Head Human Resources, Head Architect, Head Development, Head IT Operations, Head IT Administration, Service Manager, Information Security Manager, Business Continuity Manager APO10 - Manage Suppliers (Rating per ruolo :2.0) Manage IT-related services provided by all types of suppliers meet enterprise requirements, including the selection of suppliers, management of relationships, management of contracts, and reviewing and moniring of supplier performance for effectiveness and compliance. Purpose Minimise the risk associated with non-performing suppliers and ensure competitive pricing. Process Outcomes (Goals) 1. Suppliers perform as agreed. 2. Supplier risk is assessed and properly addressed. 3. Supplier relationships are working effectively. APO Identify and evaluate supplier relationships and contracts. (Rating per ruolo :2.0) 9.A.II.1 tilo Ambi del piano di continuità operativa Input Supplier contracts from (Outside COBIT) Supplier significance and evaluation criteria Supplier catalogue Potential revisions supplier contracts Steering (Programmes/Projects) Committee (BAI02.02) B.1. Establish and maintain criteria relating type, significance and criticality of suppliers and supplier contracts, enabling a focus on preferred and important suppliers
36 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Officer Head IT Administration APO12 - Manage Risk (Rating per ruolo :2.6) Continually identify, assess and reduce IT-related risk within levels of lerance set by enterprise executive management. Purpose Integrate the management of IT-related enterprise risk with overall ERM, and balance the costs and benefits of managing IT-related enterprise risk. Process Outcomes (Goals) 1. IT-related risk is identified, analysed, managed and reported. 2. A current and complete risk profile exists. 3. All significant risk management actions are managed and under control. 4. Risk management actions are implemented effectively. APO Collect data. (Rating per ruolo :1.8) 9.A.II.1 tilo Ambi del piano di continuità operativa Input Evaluation of risk management activities Approved process for measuring risk management Key objectives be monired for risk management Risk management policies Gaps and risk related current capabilities Risk assessment Identified supplier delivery risk Incident status and trends report from Board (EDM03.01) Board (EDM03.02) Chief Information Officer (APO02.02) Chief Information Officer (APO02.05) Chief Information Officer (APO10.04) Head IT Operations (DSS02.07) 36
37 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Officer Data on the operating environment relating risk Data on risk events and contributing facrs Emerging risk issues and facrs Board (EDM03.01), Chief Executive Officer (APO01.03), Chief Information Officer (APO02.02) B.1. Establish and maintain a method for the collection, classification and analysis of IT risk-related data, accommodating multiple types of events, multiple categories of IT risk and multiple risk facrs. 1.8 Business Process Owners, Project Management Office, Chief Risk Officer, Chief Information Security Officer, Head Architect, Head Development, Head IT Operations, Head IT Administration, Service Manager, Information Security Manager, Business Continuity Manager, Privacy Officer APO Analyse risk. (Rating per ruolo :2.4) 9.A.II.1 9.A.II.2 9.A.III.2 tilo Ambi del piano di continuità operativa Analisi di impat Definizione del piano di continuità operativa e gestione delle crisi Input Business impact analyses Evaluations of potential threats Threat advisories from Chief Operating Officer (DSS04.02) Chief Information Security Officer (DSS05.01) (Outside COBIT) Scope of risk analysis efforts IT risk scenarios Risk analysis results Board (EDM03.03), Chief Executive Officer (APO01.03), Chief Information Officer (APO02.02), Steering (Programmes/Projects) Committee (BAI01.10) 37
38 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Officer B.1. Define the appropriate breadth and depth of risk analysis efforts, considering all risk facrs and the business criticality of assets. Set the risk analysis scope after performing a cost-benefit analysis. B.2. Build and regularly update IT risk scenarios, including compound scenarios of cascading and/or coincidental threat types, and develop expectations for specific control activities, capabilities detect and other response measures. B.3. Estimate the frequency and magnitude of loss or gain associated with IT risk scenarios. Take in account all applicable risk facrs, evaluate known operational controls and estimate residual risk levels. B.4. Compare residual risk acceptable risk lerance and identify exposures that may require a risk response. B.5. Analyse cost-benefit of potential risk response options such as avoid, reduce/mitigate, transfer/share, and accept and exploit/seize. Propose the optimal risk response. B.6. Specify high-level requirements for projects or programmes that will implement the selected risk responses. Identify requirements and expectations for appropriate key controls for risk mitigation responses. B.7. Validate the risk analysis results before using them in decision making, confirming that the analysis aligns with enterprise requirements and verifying that estimations were properly calibrated and scrutinised for bias Business Process Owners, Chief Risk Officer, Compliance, Audit APO Respond risk. (Rating per ruolo :1.9) 9.A.III.3 tilo Comunicazioni alla Banca d'italia Input Remedial actions address risk management deviations from Board (EDM03.03) 38
39 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Officer Risk-related incident response plans Risk impact communications Risk-related root causes Service Manager (DSS02.05) Chief Executive Officer (APO01.04), Chief Information Officer (APO08.04), Chief Operating Officer (DSS04.02) Service Manager (DSS02.03), Service Manager (DSS03.01), Head IT Operations (DSS03.02), Chief Operating Officer (DSS04.02), Chief Information Officer (MEA02.04), Audit (MEA02.07), Audit (MEA02.08) B.1. Prepare, maintain and test plans that document the specific steps take when a risk event may cause a significant operational or development incident with serious business impact. Ensure that plans include pathways of escalation across the enterprise. B.4. Examine past adverse events/losses and missed opportunities and determine root causes. Communicate root cause, additional risk response requirements and process improvements appropriate decision makers and ensure that the cause, response requirements and process improvement are included in risk governance processes Business Process Owners, Project Management Office, Chief Risk Officer, Chief Information Security Officer, Head Architect, Head Development, Head IT Operations, Head IT Administration, Service Manager, Information Security Manager, Business Continuity Manager, Privacy Officer MEA02 - Monir, Evaluate and Assess the System of Internal Control (Rating per ruolo :2.2) Continuously monir and evaluate the control environment, including self-assessments and independent assurance reviews. Enable management identify control deficiencies and inefficiencies and initiate improvement actions. Plan, organise and maintain standards for internal control assessment and assurance activities. Purpose Obtain transparency for key stakeholders on the adequacy of the system of internal controls and thus provide trust in operations, confidence in the achievement of enterprise objectives and an adequate understanding of residual risk. Process Outcomes (Goals) 1. Processes, resources and information meet enterprise internal control system requirements. 2. All assurance initiatives are planned and executed effectively. 3. Independent assurance that the system of internal control is operational and effective is provided. 4. Internal control is established and deficiencies are identified and reported. 39
40 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Officer MEA Monir internal controls. (Rating per ruolo :1.7) 9.A.II.3 tilo Definizione del piano di continuità operativa e gestione delle crisi Input Results of third-party risk assessments ISMS audit reports Industry standards and good practices from Chief Information Officer (APO12.04) Chief Information Security Officer (APO13.03) (Outside COBIT) Results of internal control moniring and reviews Results of benchmarking and other evaluations Board (EDM01.03), (All APO), (All BAI), (All DSS), (All MEA) Board (EDM01.03), (All APO), (All BAI), (All DSS), (All MEA) B.7. Assess the status of external service providers internal controls and confirm that service providers comply with legal and regulary requirements and contractual obligations. 1.7 Business Process Owners, Project Management Office, Chief Risk Officer, Compliance, Audit, Head Development, Head IT Operations, Head IT Administration, Service Manager, Information Security Manager, Business Continuity Manager, Privacy Officer MEA Identify and report control deficiencies. (Rating per ruolo :2.0) 9.A.III.3 tilo Comunicazioni alla Banca d'italia 40
41 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Chief Information Officer Input Root causes of quality delivery failures Risk-related root causes Root cause analyses and recommendations Results of processing effectiveness reviews Evidence of error correction and remediation from Chief Information Officer (APO11.05) Chief Information Officer (APO12.06) Business Executives (DSS06.01) Business Process Owners (DSS06.04) Control deficiencies Remedial actions (All APO), (All BAI), (All DSS), (All MEA) (All APO), (All BAI), (All DSS), (All MEA) B.1. Identify, report and log control exceptions, and assign responsibility for resolving them and 1.2 reporting on the status. B.2. Consider related enterprise risk establish thresholds for escalation of control exceptions and 1.2 breakdowns. B.3. Communicate procedures for escalation of control exceptions, root cause analysis, and reporting 1.2 process owners and IT stakeholders. B.4. Decide which control exceptions should be communicated the individual responsible for the 1.2 function and which exceptions should be escalated. Inform affected process owners and stakeholders. B.5. Follow up on all exceptions ensure that agreed-on actions have been addressed. 1.2 B.6. Identify, initiate, track and implement remedial actions arising from control assessments and 1.2 reporting. Business Process Owners, Project Management Office, Compliance, Audit, Head Development, Head IT Operations, Head IT Administration, Service Manager, Information Security Manager, Business Continuity Manager, Privacy Officer 41
42 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Head IT Operations Head IT Operations BAI04 - Manage Availability and Capacity (Rating per ruolo :2.9) Balance current and future needs for availability, performance and capacity with cost-effective service provision. Include assessment of current capabilities, forecasting of future needs based on business requirements, analysis of business impacts, and assessment of risk plan and implement actions meet the identified requirements. Purpose Maintain service availability, efficient management of resources, and optimisation of system performance through prediction of future performance and capacity requirements. Process Outcomes (Goals) 1. The availability plan anticipates the business expectation of critical capacity requirements. 2. Capacity, performance and availability meet requirements. 3. Availability, performance and capacity issues are identified and routinely resolved. BAI Assess current availability, performance and capacity and create a baseline. (Rating per ruolo :2.8) 9.A.II.2 9.A.III.2 tilo Analisi di impat Definizione del piano di continuità operativa e gestione delle crisi Input Requirements definition reposiry Requirements risk register from Steering (Programmes/Projects) Committee (BAI02.01) Steering (Programmes/Projects) Committee (BAI02.03) Availability, performance and capacity baselines Evaluations against SLAs Business Executives (APO09.05) 42
43 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Head IT Operations B.1. Consider the following (current and forecasted) in the assessment of availability, performance 2.2 and capacity of services and resources: cusmer requirements, business priorities, business objectives, budget impact, resource utilisation, IT capabilities and industry trends. B.2. Monir actual performance and capacity usage against defined thresholds, supported where 2.2 necessary with aumated software. B.3. Identify and follow up on all incidents caused by inadequate performance or capacity. 2.2 B.4. Regularly evaluate the current levels of performance for all processing levels (business demand, 2.2 service capacity and resource capacity) by comparing them against trends and SLAs, taking in account changes in the environment. Service Manager BAI Investigate and address availability, performance and capacity issues. (Rating per ruolo :2.1) 9.A.III.2 tilo Definizione del piano di continuità operativa e gestione delle crisi Performance and capacity gaps Corrective actions Emergency escalation procedure Chief Information Officer (APO02.02) Head IT Operations (DSS02.02) B.1. Obtain guidance from vendor product manuals ensure an appropriate level of performance availability for peak processing and workloads. B.2. Identify performance and capacity gaps based on moniring current and forecasted performance. Use the known availability, continuity and recovery specifications classify resources and allow prioritisation Business Process Owners, Head Architect, Service Manager 43
44 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Head IT Operations BAI09 - Manage Assets (Rating per ruolo :2.6) Manage IT assets through their life cycle make sure that their use delivers value at optimal cost, they remain operational (fit for purpose), they are accounted for and physically protected, and those assets that are critical support service capability are reliable and available. Manage software licences ensure that the optimal number are acquired, retained and deployed in relation required business usage, and the software installed is in compliance with licence agreements. Purpose Account for all IT assets and optimise the value provided by these assets. Process Outcomes (Goals) 1. Licences are compliant and aligned with business need. 2. Assets are maintained at optimal levels. BAI Manage critical assets. (Rating per ruolo :2.6) 9.A.II.1 9.A.II.2 9.A.III.2 tilo Ambi del piano di continuità operativa Analisi di impat Definizione del piano di continuità operativa e gestione delle crisi Communication of planned maintenance downtime Maintenance agreements Chief Information Officer (APO08.04) 44
45 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Head IT Operations B.1. Identify assets that are critical in providing service capability by referencing requirements in 1.5 service definitions, SLAs and the configuration management system. B.2. Monir performance of critical assets by examining incident trends and, where necessary, take 1.5 action repair or replace. B.3. On a regular basis, consider the risk of failure or need for replacement of each critical asset. 1.5 B.4. Maintain the resilience of critical assets by applying regular preventive maintenance, moniring 2.0 performance, and, if required, providing alternative and/or additional assets minimise the likelihood of failure. B.5. Establish a preventive maintenance plan for all hardware, considering cost-benefit analysis, 1.5 vendor recommendations, risk of outage, qualified personnel and other relevant facrs. B.6. Establish maintenance agreements involving third-party access organisational IT facilities for 2.0 on-site and off-site activities (e.g., outsourcing). Establish formal service contracts containing or referring all necessary security conditions, including access authorisation procedures, ensure compliance with the organisational security policies and standards. B.7. Communicate affected cusmers and users the expected impact (e.g., performance 1.5 restrictions) of maintenance activities. B.8. Ensure that remote access services and user profiles (or other means used for maintenance or 1.5 diagnosis) are active only when required. B.9. Incorporate planned downtime in an overall production schedule, and schedule the maintenance 1.5 activities minimise the adverse impact on business processes. Head Architect, Head Development, Head IT Administration DSS02 - Manage Service Requests and Incidents (Rating per ruolo :2.1) Provide timely and effective response user requests and resolution of all types of incidents. Resre normal service; record and fulfil user requests; and record, investigate, diagnose, escalate and resolve incidents. Purpose Achieve increased productivity and minimise disruptions through quick resolution of user queries and incidents. Process Outcomes (Goals) 1. IT-related services are available for use. 2. Incidents are resolved according agreed-on service levels. 3. Service requests are dealt with according agreed-on service levels and the satisfaction of users. 45
46 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Head IT Operations DSS Record, classify and prioritise requests and incidents. (Rating per ruolo :1.8) 9.A.III.3 tilo Comunicazioni alla Banca d'italia Input SLAs Emergency escalation procedure Incident tickets Asset moniring rules and event conditions Security incident tickets from Service Manager (APO09.03) Head IT Operations (BAI04.05) Head IT Operations (DSS01.03) Chief Information Security Officer (DSS05.07) Incident and service request log Classified and prioritised incidents and service requests Chief Information Officer (APO08.03), Service Manager (APO09.04), Chief Information Security Officer (APO13.03) B.1. Log all service requests and incidents, recording all relevant information so that they can be 1.3 handled effectively and a full hisrical record can be maintained. B.2. To enable trend analysis, classify service requests and incidents by identifying type and category. 1.3 B.3. Prioritise service requests and incidents based on SLA service definition of business impact and 1.3 urgency. Service Manager DSS Track status and produce reports. (Rating per ruolo :1.9) 9.A.III.3 tilo Comunicazioni alla Banca d'italia 46
47 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Head IT Operations Input OLAs Problem status reports Problem resolution reports Problem resolution moniring reports from Service Manager (APO09.03) Service Manager (DSS03.01) Head IT Operations (DSS03.02) Service Manager (DSS03.05) Incident status and trends report Request fulfilment status and trends report Chief Information Officer (APO08.03), Service Manager (APO09.04), Chief Information Officer (APO11.04), Chief Information Officer (APO12.01), Chief Information Officer (MEA01.03) Chief Information Officer (APO08.03), Service Manager (APO09.04), Chief Information Officer (APO11.04), Chief Information Officer (MEA01.03) B.1. Monir and track incident escalations and resolutions and request handling procedures 1.3 progress wards resolution or completion. B.2. Identify information stakeholders and their needs for data or reports. Identify reporting 1.3 frequency and medium. B.3. Analyse incidents and service requests by category and type establish trends and identify 1.3 patterns of recurring issues, SLA breaches or inefficiencies. Use the information as input continual improvement planning. B.4. Produce and distribute timely reports or provide controlled access online data. 1.3 Service Manager DSS04 - Manage Continuity (Rating per ruolo :2.6) Establish and maintain a plan enable the business and IT respond incidents and disruptions in order continue operation of critical business processes and required IT services and maintain availability of information at a level acceptable the enterprise. Purpose Continue critical business operations and maintain availability of information at a level acceptable the enterprise in the event of a significant disruption. Process Outcomes (Goals) 1. Business-critical information is available the business in line with minimum required service levels. 47
48 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Head IT Operations Sufficient resilience is in place for critical services. 3. Service continuity tests have verified the effectiveness of the plan. 4. An up--date continuity plan reflects current business requirements. 5. Internal and external parties have been trained in the continuity plan. DSS Manage backup arrangements. (Rating per ruolo :2.6) 9.A.II.3 9.A.III.2 tilo Definizione del piano di continuità operativa e gestione delle crisi Definizione del piano di continuità operativa e gestione delle crisi Test results of backup data B.1. Back up systems, applications, data and documentation according a defined schedule, 2.0 considering: Frequency (monthly, weekly, daily, etc.) Mode of backup (e.g., disk mirroring for realtime backups vs. DVD-ROM for long-term retention) Type of backup (e.g., full vs. incremental) Type of media Aumated online backups Data types (e.g., voice, optical) Creation of logs Critical end-user computing data (e.g., spreadsheets) Physical and logical location of data sources Security and access rights Encryption B.2. Ensure that systems, applications, data and documentation maintained or processed by third 1.7 parties are adequately backed up or otherwise secured. Consider requiring return of backups from third parties. Consider escrow or deposit arrangements. B.3. Define requirements for on-site and off-site srage of backup data that meet the business 1.7 requirements. Consider the accessibility required back up data. B.4. Roll out BCP awareness and training. 1.7 B.5. Periodically test and refresh archived and backup data. 2.0 Business Continuity Manager 48
49 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Service Manager Service Manager APO09 - Manage Service Agreements (Rating per ruolo :1.9) Align IT-enabled services and service levels with enterprise needs and expectations, including identification, specification, design, publishing, agreement, and moniring of IT services, service levels and performance indicars. Purpose Ensure that IT services and service levels meet current and future enterprise needs. Process Outcomes (Goals) 1. The enterprise can effectively utilise IT services as defined in a catalogue. 2. Service agreements reflect enterprise needs and the capabilities of IT. 3. IT services perform as stipulated in service agreements. APO Define and prepare service agreements. (Rating per ruolo :1.9) 9.A.II.3 tilo Definizione del piano di continuità operativa e gestione delle crisi Input Cusmer requirements for quality management from Business Executives (APO11.03) SLAs Operational level agreements (OLAs) Chief Executive Officer (APO05.03), Chief Information Officer (APO08.04), Chief Information Officer (DSS01.02), Chief Information Officer (DSS02.01), Head IT Operations (DSS02.02), Chief Operating Officer (DSS04.01), Chief Information Security Officer (DSS05.02), Chief Information Security Officer (DSS05.03) Chief Information Officer (DSS01.02), Head IT Operations (DSS02.07), Business Continuity Manager (DSS04.03), Chief Information Security Officer (DSS05.03) 49
50 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Service Manager B.1. Analyse requirements for new or changed service agreements received from business relationship management ensure that the requirements can be matched. Consider aspects such as service times, availability, performance, capacity, security, continuity, compliance and regulary issues, usability, and demand constraints. 1.9 Business Executives, Chief Information Officer, Head IT Operations, Head IT Administration DSS02 - Manage Service Requests and Incidents (Rating per ruolo :2.0) Provide timely and effective response user requests and resolution of all types of incidents. Resre normal service; record and fulfil user requests; and record, investigate, diagnose, escalate and resolve incidents. Purpose Achieve increased productivity and minimise disruptions through quick resolution of user queries and incidents. Process Outcomes (Goals) 1. IT-related services are available for use. 2. Incidents are resolved according agreed-on service levels. 3. Service requests are dealt with according agreed-on service levels and the satisfaction of users. DSS Resolve and recover from incidents. (Rating per ruolo :2.0) 9.A.III.2 tilo Definizione del piano di continuità operativa e gestione delle crisi Input Risk-related incident response plans Known error records Communication of knowledge learned from Chief Information Officer (APO12.06) Head IT Operations (DSS03.03) Service Manager (DSS03.04) Incident resolutions Service Manager (DSS03.04) 50
51 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Service Manager B.1. Select and apply the most appropriate incident resolutions (temporary workaround and/or permanent solution). 2.0 Head Development, Head IT Operations, Information Security Manager 51
52 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Continuity Manager Business Continuity Manager DSS04 - Manage Continuity (Rating per ruolo :3.8) Establish and maintain a plan enable the business and IT respond incidents and disruptions in order continue operation of critical business processes and required IT services and maintain availability of information at a level acceptable the enterprise. Purpose Continue critical business operations and maintain availability of information at a level acceptable the enterprise in the event of a significant disruption. Process Outcomes (Goals) 1. Business-critical information is available the business in line with minimum required service levels. 2. Sufficient resilience is in place for critical services. 3. Service continuity tests have verified the effectiveness of the plan. 4. An up--date continuity plan reflects current business requirements. 5. Internal and external parties have been trained in the continuity plan. DSS Develop and implement a business continuity response. (Rating per ruolo :3.6) tilo 9.I.3 Banche soggette ai requisiti applicabili a tutti gli operari (Allega A, Sezione II) 9.I.4 Banche soggette ai requisiti particolari per i processi a rilevanza sistemica (Allega A, Sezione III) 9.A.I.1 Premessa 9.A.II.1 Ambi del piano di continuità operativa 9.A.II.3 Definizione del piano di continuità operativa e gestione delle crisi 9.A.III.2 Definizione del piano di continuità operativa e gestione delle crisi 9.A.III.3 Comunicazioni alla Banca d'italia Input OLAs from Service Manager (APO09.03) 52
53 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Continuity Manager Incident response actions and communications BCP Chief Information Officer (DSS02.01) B.1. Define the incident response actions and communications be taken in the event of disruption. 2.8 Define related roles and responsibilities, including accountability for policy and implementation. B.2. Develop and maintain operational BCPs containing the procedures be followed enable 3.0 continued operation of critical business processes and/or temporary processing arrangements, including links plans of outsourced service providers. B.3. Ensure that key suppliers and outsource partners have effective continuity plans in place. Obtain 2.8 audited evidence as required. B.4. Define the conditions and recovery procedures that would enable resumption of business 2.5 processing, including updating and reconciliation of information databases preserve information integrity. B.5. Define and document the resources required support the continuity and recovery procedures, 2.8 considering people, facilities and IT infrastructure. B.6. Define and document the information backup requirements required support the plans, 2.5 including plans and paper documents as well as data files, and consider the need for security and offsite srage. B.7. Determine required skills for individuals involved in executing the plan and procedures. 2.5 B.8. Distribute the plans and supporting documentation securely appropriately authorised 2.6 interested parties and make sure they are accessible under all disaster scenarios. S.1. Include information security requirements in the BCP. 1.8 Business Process Owners, Chief Information Officer, Head IT Operations DSS Exercise, test and review the BCP. (Rating per ruolo :3.3) tilo 9.I.3 Banche soggette ai requisiti applicabili a tutti gli operari (Allega A, Sezione II) 9.I.4 Banche soggette ai requisiti particolari per i processi a rilevanza sistemica (Allega A, Sezione III) 9.A.I.1 Premessa 9.A.II.3 Definizione del piano di continuità operativa e gestione delle crisi 9.A.III.2 Definizione del piano di continuità operativa e gestione delle crisi 53
54 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Continuity Manager Test objectives Test exercises Test results and recommendations B.1. Define objectives for exercising and testing the business, technical, logistical, administrative, 2.6 procedural and operational systems of the plan verify completeness of the BCP in meeting business risk. B.2. Define and agree on with stakeholders exercises that are realistic, validate continuity procedures, 2.6 and include roles and responsibilities and data retention arrangements that cause minimum disruption business processes. B.3. Assign roles and responsibilities for performing continuity plan exercises and tests. 2.4 B.4. Schedule exercises and test activities as defined in the continuity plan. 2.4 B.5. Conduct a post-exercise debriefing and analysis consider the achievement. 2.5 B.6. Develop recommendations for improving the current continuity plan based on the results of the 2.4 review. Business Process Owners, Audit, Chief Information Officer, Head IT Operations DSS Conduct continuity plan training. (Rating per ruolo :2.2) 9.A.II.3 9.A.III.2 9.A.III.3 tilo Definizione del piano di continuità operativa e gestione delle crisi Definizione del piano di continuità operativa e gestione delle crisi Comunicazioni alla Banca d'italia Input List of personnel requiring training from (HR) Training requirements Moniring results of skills and competencies Chief Information Officer (APO07.03) Chief Information Officer (APO07.03) 54
55 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Continuity Manager B.1. Define and maintain training requirements and plans for those performing continuity planning, 1.9 impact assessments, risk assessments, media communication and incident response. Ensure that the training plans consider frequency of training and training delivery mechanisms. B.2. Develop competencies based on practical training including participation in exercises and tests. 1.6 B.3. Monir skills and competencies based on the exercise and test results. 1.6 Business Process Owners, Chief Information Officer, Head Development, Head IT Operations, Head IT Administration DSS Conduct post-resumption review. (Rating per ruolo :2.4) 9.A.II.3 9.A.III.3 tilo Definizione del piano di continuità operativa e gestione delle crisi Comunicazioni alla Banca d'italia Post-resumption review report Approved changes the plans Business Executives (BAI06.01) B.1. Assess adherence the documented BCP. 1.8 B.2. Determine the effectiveness of the plan, continuity capabilities, roles and responsibilities, skills 1.8 and competencies, resilience the incident, technical infrastructure, and organisational structures and relationships. B.3. Identify weaknesses or omissions in the plan and capabilities and make recommendations for 1.8 improvement. B.4. Obtain management approval for any changes the plan and apply via the enterprise change 1.8 control process. Business Process Owners, Chief Information Officer, Head IT Operations, Head IT Administration 55
56 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Continuity Manager
57 TITOLO V - Capilo 9 - LA CONTINUITÀ OPERATIVA Accountable: Business Continuity Manager C Circ. BI A.I.1 - Premessa; 7; 8; 52; 53 9.A.II.1 - Ambi del piano di continuità operativa; 7; 17; 23; 34; 35; 36; 37; 44; 52 9.A.II.2 - Analisi di impat; 15; 37; 42; 44 9.A.II.3 - Definizione del piano di continuità operativa e gestione delle crisi; 7; 8; 9; 11; 12; 13; 17; 18; 29; 30; 40; 48; 49; 52; 53; 54; 55 9.A.III.2 - Definizione del piano di continuità operativa e gestione delle crisi; 7; 8; 9; 13; 20; 22; 25; 26; 28; 34; 37; 42; 43; 44; 48; 50; 52; 53; 54 9.A.III.3 - Comunicazioni alla Banca d'italia; 5; 6; 8; 9; 33; 38; 40; 46; 52; 54; 55 9.I.3 - Banche soggette ai requisiti applicabili a tutti gli operari (Allega A, Sezione II); 7; 8; 9; 31; 52; 53 9.I.4 - Banche soggette ai requisiti particolari per i processi a rilevanza sistemica (Allega A, Sezione III); 7; 8; 9; 31; 52; 53 D Dominio COBIT5 APO APO01; 31 APO02; 32 APO07; 34 APO09; 49 APO10; 35 APO12; 20; 36 BAI BAI02; 17 BAI04; 15; 42 BAI06; 11 BAI07; 18 BAI09; 44 DSS DSS01; 22 DSS02; 45; 50 DSS04; 7; 47; 52 EDM EDM05; 5 MEA MEA01; 13 MEA02; 25; 28; 39 MEA03; 26; 29 57
Sound Transit Internal Audit Report - No. 2014-3
Sound Transit Internal Audit Report - No. 2014-3 IT Project Management Report Date: Dec. 26, 2014 Table of Contents Page Background 2 Audit Approach and Methodology 2 Summary of Results 4 Findings & Management
Revised October 2013
Revised October 2013 Version 3.0 (Live) Page 0 Owner: Chief Examiner CONTENTS: 1. Introduction..2 2. Foundation Certificate 2 2.1 The Purpose of the COBIT 5 Foundation Certificate.2 2.2 The Target Audience
Roles, Activities and Relationships
and in COBIT 5 Objective: Value Creation Benefits Realisation Risk Resource Enablers Scope Roles, Activities and Relationships Source: COBIT 5, figure 8 Key Roles, Activities and Relationships Roles, Activities
Digital Asset Manager, Digital Curator. Cultural Informatics, Cultural/ Art ICT Manager
Role title Digital Cultural Asset Manager Also known as Relevant professions Summary statement Mission Digital Asset Manager, Digital Curator Cultural Informatics, Cultural/ Art ICT Manager Deals with
Principles for BCM requirements for the Dutch financial sector and its providers.
Principles for BCM requirements for the Dutch financial sector and its providers. Platform Business Continuity Vitale Infrastructuur Financiële sector (BC VIF) Werkgroep BCM requirements 21 September 2011
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK
THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK ACCOUNTABLE SIGNATURE AUTHORISED for implementation SIGNATURE On behalf of Chief Executive Officer SAHRA Council Date Date
Chapter 3: Audit of business Continuity plan... 3 Learning Objectives... 3 3.1 Introduction... 3 3.2 Steps of BCP Process... 3 3.2.
Chapter 3: Audit of business Continuity plan... 3 Learning Objectives... 3 3.1 Introduction... 3 3.2 Steps of BCP Process... 3 3.2.1 Step 1: Identifying the mission or business-critical functions... 4
Domain 1 The Process of Auditing Information Systems
Certified Information Systems Auditor (CISA ) Certification Course Description Our 5-day ISACA Certified Information Systems Auditor (CISA) training course equips information professionals with the knowledge
How To Assess A Critical Service Provider
Committee on Payments and Market Infrastructures Board of the International Organization of Securities Commissions Principles for financial market infrastructures: Assessment methodology for the oversight
ENTERPRISE RISK MANAGEMENT FRAMEWORK
ROCKHAMPTON REGIONAL COUNCIL ENTERPRISE RISK MANAGEMENT FRAMEWORK 2013 Adopted 25 June 2013 Reviewed: October 2015 TABLE OF CONTENTS 1. Introduction... 3 1.1 Council s Mission... 3 1.2 Council s Values...
University of Sunderland Business Assurance Information Security Policy
University of Sunderland Business Assurance Information Security Policy Document Classification: Public Policy Reference Central Register Policy Reference Faculty / Service IG 003 Policy Owner Assistant
COBIT 5 for Risk. CS 3-7: Monday, July 6 4:00-5:00. Presented by: Nelson Gibbs CIA, CRMA, CISA, CISM, CGEIT, CRISC, CISSP ngibbs@pacbell.
COBIT 5 for Risk CS 3-7: Monday, July 6 4:00-5:00 Presented by: Nelson Gibbs CIA, CRMA, CISA, CISM, CGEIT, CRISC, CISSP [email protected] Disclaimer of Use and Association Note: It is understood that
Chayuth Singtongthumrongkul
IT is complicated. IT Governance doesn t have to be. Chayuth Singtongthumrongkul CISSP, CISA, ITIL Intermediate, PMP, IRCA ISMS (ISO/IEC 27001) Director of International Academic Alliance, ACIS Professional
Consultative report. Committee on Payment and Settlement Systems. Board of the International Organization of Securities Commissions
Committee on Payment and Settlement Systems Board of the International Organization of Securities Commissions Consultative report Principles for financial market infrastructures: Assessment methodology
CRISC Glossary. Scope Note: Risk: Can also refer to the verification of the correctness of a piece of data
CRISC Glossary Term Access control Access rights Application controls Asset Authentication The processes, rules and deployment mechanisms that control access to information systems, resources and physical
Stepping Through the Info Security Program. Jennifer Bayuk, CISA, CISM
Stepping Through the Info Security Program Jennifer Bayuk, CISA, CISM Infosec Program How to: compose an InfoSec Program cement a relationship between InfoSec program and IT Governance design roles and
Maturity Model. March 2006. Version 1.0. P2MM Version 1.0 The OGC logo is a Registered Trade Mark of the Office of Government Commerce
Maturity Model March 2006 Version 1.0 P2MM Version 1.0 The OGC logo is a Registered Trade Mark of the Office of Government Commerce This is a Value Added product which is outside the scope of the HMSO
Setting goals and measuring the value of Enterprise IT Architecture using COBIT 5 framework
Setting goals and measuring the value of Enterprise IT Architecture using COBIT 5 framework Karoline Westerlund, IT-strategist Umeå University, Sweden retirement Service Catalogue Defined framework Formalized
Sound Transit Internal Audit Report - No. 2014-6
Sound Transit Internal Audit Report - No. 2014-6 Maturity Assessment: Information Technology Division Disaster Recovery Planning Report Date: June 5, 2015 Table of Contents Page Executive Summary 2 Background
CISM Certified Information Security Manager
CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective
WEST LOTHIAN COUNCIL INFORMATION SECURITY POLICY
WEST LOTHIAN COUNCIL INFORMATION SECURITY POLICY DATA LABEL: PUBLIC INFORMATION SECURITY POLICY CONTENTS 1. INTRODUCTION... 3 2. MAIN OBJECTIVES... 3 3. LEGISLATION... 4 4. SCOPE... 4 5. STANDARDS... 4
CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT
CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14
Ohio Supercomputer Center
Ohio Supercomputer Center IT Business Continuity Planning No: Effective: OSC-13 06/02/2009 Issued By: Kevin Wohlever Director of Supercomputer Operations Published By: Ohio Supercomputer Center Original
Business Continuity Planning and Disaster Recovery Planning
4 Business Continuity Planning and Disaster Recovery Planning Basic Concepts 1. Business Continuity Management: Business Continuity means maintaining the uninterrupted availability of all key business
IS Audit and Assurance Guideline 2202 Risk Assessment in Planning
IS Audit and Assurance Guideline 2202 Risk Assessment in Planning The specialised nature of information systems (IS) audit and assurance and the skills necessary to perform such engagements require standards
www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014
www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 Agenda Key Definitions Risks Business Continuity Management Program BCM Capability Assessment Process BCM Value Proposition
Business Continuity Management
Business Continuity Management Standard Operating Procedure Notice: This document has been made available through the Police Service of Scotland Freedom of Information Publication Scheme. It should not
WEST YORKSHIRE FIRE & RESCUE SERVICE. Business Continuity Management Strategy
WEST YORKSHIRE FIRE & RESCUE SERVICE Business Continuity Management Strategy Date Issued: 12 November 2012 Review Date: 12 November 2015 Version Control Version Number Date Author Comment 0.1 June 2011
for Information Security
for Information Security The following pages provide a preview of the information contained in COBIT 5 for Information Security. The publication provides guidance to help IT and Security professionals
Presented by. Denis Darveau CISM, CISA, CRISC, CISSP
Presented by Denis Darveau CISM, CISA, CRISC, CISSP Las Vegas ISACA Chapter, February 19, 2013 2 COBIT Definition Control Objectives for Information and Related Technology (COBIT) is an IT governance framework
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program subsidiaries) 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis
MICHIGAN AUDIT REPORT OFFICE OF THE AUDITOR GENERAL THOMAS H. MCTAVISH, C.P.A. AUDITOR GENERAL
MICHIGAN OFFICE OF THE AUDITOR GENERAL AUDIT REPORT THOMAS H. MCTAVISH, C.P.A. AUDITOR GENERAL The auditor general shall conduct post audits of financial transactions and accounts of the state and of all
WEST COAST DISTRICT MUNICIPALITY IT GOVERNANCE FRAMEWORK IT CHARTER
WEST COAST DISTRICT MUNICIPALITY IT GOVERNANCE FRAMEWORK IT CHARTER MAY 2012 INDEX 1 Introduction... 1 2 Contextual background... 3 2.1 The CobiT 5 framework (2012)... 4 2.2 The ISO 27000 series (2005,
INFORMATION TECHNOLOGY SECURITY STANDARDS
INFORMATION TECHNOLOGY SECURITY STANDARDS Version 2.0 December 2013 Table of Contents 1 OVERVIEW 3 2 SCOPE 4 3 STRUCTURE 5 4 ASSET MANAGEMENT 6 5 HUMAN RESOURCES SECURITY 7 6 PHYSICAL AND ENVIRONMENTAL
Company Management System. Business Continuity in SIA
Company Management System Business Continuity in SIA Document code: Classification: Company Project/Service Year Document No. Version Public INDEX 1. INTRODUCTION... 3 2. SIA S BUSINESS CONTINUITY MANAGEMENT
ITIL 2011 Lifecycle Roles and Responsibilities UXC Consulting
ITIL 2011 Lifecycle Roles and Responsibilities UXC Consulting Date November 2011 Company UXC Consulting Version Version 1.5 Contact [email protected] http://www.uxcconsulting.com.au This summary
Certified Information Security Manager (CISM)
Certified Information Security Manager (CISM) Course Introduction Course Introduction Domain 01 - Information Security Governance Lesson 1: Information Security Governance Overview Information Security
IT Governance Regulatory. P.K.Patel AGM, MoF
IT Governance Regulatory Perspective P.K.Patel AGM, MoF Agenda What is IT Governance? Aspects of IT Governance What banks should consider before implementing these aspects? What banks should do for implementation
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page
Technology Risk Management
1 Monetary Authority of Singapore Technology Risk Guidelines & Notices New Requirements for Financial Services Industry Mark Ames Director, Seminar Program ISACA Singapore 2 MAS Supervisory Framework Impact
PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA
1 Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand
GUIDANCE NOTE FOR DEPOSIT-TAKERS. Operational Risk Management. March 2012
GUIDANCE NOTE FOR DEPOSIT-TAKERS Operational Risk Management March 2012 Version 1.0 Contents Page No 1 Introduction 2 2 Overview 3 Operational risk - fundamental principles and governance 3 Fundamental
Course: Information Security Management in e-governance. Day 1. Session 3: Models and Frameworks for Information Security Management
Course: Information Security Management in e-governance Day 1 Session 3: Models and Frameworks for Information Security Management Agenda Introduction to Enterprise Security framework Overview of security
IT General Controls Domain COBIT Domain Control Objective Control Activity Test Plan Test of Controls Results
Acquire or develop application systems software Controls provide reasonable assurance that application and system software is acquired or developed that effectively supports financial reporting requirements.
PORTFOLIO, PROGRAMME & PROJECT MANAGEMENT MATURITY MODEL (P3M3)
PORTFOLIO, PROGRAMME & PROJECT MANAGEMENT MATURITY MODEL (P3M3) 1st February 2006 Version 1.0 1 P3M3 Version 1.0 The OGC logo is a Registered Trade Mark of the Office of Government Commerce This is a Value
CISM ITEM DEVELOPMENT GUIDE
CISM ITEM DEVELOPMENT GUIDE Updated January 2015 TABLE OF CONTENTS Content Page Purpose of the CISM Item Development Guide 3 CISM Exam Structure 3 Writing Quality Items 3 Multiple-Choice Items 4 Steps
Part A OVERVIEW...1. 1. Introduction...1. 2. Applicability...2. 3. Legal Provision...2. Part B SOUND DATA MANAGEMENT AND MIS PRACTICES...
Part A OVERVIEW...1 1. Introduction...1 2. Applicability...2 3. Legal Provision...2 Part B SOUND DATA MANAGEMENT AND MIS PRACTICES...3 4. Guiding Principles...3 Part C IMPLEMENTATION...13 5. Implementation
SAFETY and HEALTH MANAGEMENT STANDARDS
SAFETY and HEALTH STANDARDS The Verve Energy Occupational Safety and Health Management Standards have been designed to: Meet the Recognised Industry Practices & Standards and AS/NZS 4801 Table of Contents
Avondale College Limited Enterprise Risk Management Framework 2014 2017
Avondale College Limited Enterprise Risk Management Framework 2014 2017 President s message Risk management is part of our daily life, something we do regularly; often without realising we are doing it.
IT Risk & Security Specialist Position Description
Specialist Position Description February 9, 2015 Specialist Position Description February 9, 2015 Page i Table of Contents General Characteristics... 1 Career Path... 2 Explanation of Proficiency Level
COBIT 5 For Cyber Security Governance and Management. Nasser El-Hout Managing Director Service Management Centre of Excellence (SMCE)
COBIT 5 For Cyber Security Governance and Management Nasser El-Hout Managing Director Service Management Centre of Excellence (SMCE) Cybersecurity Governance using COBIT5 Cyber Defence Summit Riyadh, KSA
DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES
APPENDIX 1 DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES March 2008 Auditor General s Office Jeffrey Griffiths, C.A., C.F.E. Auditor General City of Toronto TABLE OF CONTENTS EXECUTIVE SUMMARY...1
BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS
BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS DIRECTORATE OF BANKING SUPERVISION AUGUST 2009 TABLE OF CONTENTS PAGE 1.0 INTRODUCTION..3 1.1 Background...3 1.2 Citation...3
Information Technology
Information Technology Information Technology Session Structure Board of director actions Significant and emerging IT risks Practical questions Resources Compensating Controls at the Directorate Level
Information Security Program CHARTER
State of Louisiana Information Security Program CHARTER Date Published: 12, 09, 2015 Contents Executive Sponsors... 3 Program Owner... 3 Introduction... 4 Statewide Information Security Strategy... 4 Information
Information Technology Engineers Examination. Information Technology Service Manager Examination. (Level 4) Syllabus
Information Technology Engineers Examination Information Technology Service Manager Examination (Level 4) Syllabus Details of Knowledge and Skills Required for the Information Technology Engineers Examination
Program Management Professional (PgMP) Examination Content Outline
Program Management Professional (PgMP) Examination Content Outline Project Management Institute Program Management Professional (PgMP ) Examination Content Outline April 2011 Published by: Project Management
TOGAF. TOGAF & Major IT Frameworks, Architecting the Family. by Danny Greefhorst, MSc., Director of ArchiXL. IT Governance and Strategy
TOGAF TOGAF & Major IT Frameworks, Architecting the Family by Danny Greefhorst, MSc., Director of ArchiXL TOGAF is a registered trademark of The Open Group. Copyright 2013 ITpreneurs. All rights reserved.
B o a r d of Governors of the Federal Reserve System. Supplemental Policy Statement on the. Internal Audit Function and Its Outsourcing
B o a r d of Governors of the Federal Reserve System Supplemental Policy Statement on the Internal Audit Function and Its Outsourcing January 23, 2013 P U R P O S E This policy statement is being issued
Geoff Harmer PhD, CEng, FBCS, CITP, CGEIT Maat Consulting Reading, UK www.maatconsulting.com
COBIT 5 All together now! Geoff Harmer PhD, CEng, FBCS, CITP, CGEIT Maat Consulting Reading, UK www.maatconsulting.com 1 Copyright Notice COBIT is 1996, 1998, 2000, 2005 2012 ISACA and IT Governance Institute.
Procuring Penetration Testing Services
Procuring Penetration Testing Services Introduction Organisations like yours have the evolving task of securing complex IT environments whilst delivering their business and brand objectives. The threat
Risk Management Policy and Process Guide
Risk Management Policy and Process Guide Status: pending Next review date: December 2015 Page 1 Information Reader Box Directorate Medical Nursing Patients & Information Commissioning Operations (including
Certified Information Systems Auditor (CISA)
Certified Information Systems Auditor (CISA) Course Introduction Course Introduction Module 01 - The Process of Auditing Information Systems Lesson 1: Management of the Audit Function Organization of the
Information governance strategy 2014-16
Information Commissioner s Office Information governance strategy 2014-16 Page 1 of 16 Contents 1.0 Executive summary 2.0 Introduction 3.0 ICO s corporate plan 2014-17 4.0 Regulatory environment 5.0 Scope
How To Transform It Risk Management
The transformation of IT Risk Management kpmg.com The transformation of IT Risk Management The role of IT Risk Management Scope of IT risk management Examples of IT risk areas of focus How KPMG can help
CISM ITEM DEVELOPMENT GUIDE
CISM ITEM DEVELOPMENT GUIDE TABLE OF CONTENTS CISM ITEM DEVELOPMENT GUIDE Content Page Purpose of the CISM Item Development Guide 2 CISM Exam Structure 2 Item Writing Campaigns 2 Why Participate as a CISM
Microsoft s Compliance Framework for Online Services
Microsoft s Compliance Framework for Online Services Online Services Security and Compliance Executive summary Contents Executive summary 1 The changing landscape for online services compliance 4 How Microsoft
ICT Category Sub Category Description Architecture and Design
A A01 Architecture and Design Architecture and Design Enterprise & Business Architecture A02 Architecture and Design Information Architecture A03 Architecture and Design Solution Architecture B Benchmarking
BUSINESS CONTINUITY MANAGEMENT POLICY
BUSINESS CONTINUITY MANAGEMENT POLICY AUTHORISED BY: DATE: Andy Buck Chief Executive March 2011 Ratifying Committee: NHS Rotherham Board Date Agreed: Issue No: NEXT REVIEW DATE: 2013 1 Lead Director John
ITIL Roles Descriptions
ITIL Roles s Role Process Liaison Incident Analyst Operations Assurance Analyst Infrastructure Solution Architect Problem Manager Problem Owner Change Manager Change Owner CAB Member Release Analyst Test
ASX CLEAR (FUTURES) OPERATING RULES Guidance Note 10
BUSINESS CONTINUITY AND DISASTER RECOVERY The purpose of this Guidance Note The main points it covers To assist participants to understand the disaster recovery and business continuity arrangements they
fs viewpoint www.pwc.com/fsi
fs viewpoint www.pwc.com/fsi June 2013 02 11 16 21 24 Point of view Competitive intelligence A framework for response How PwC can help Appendix It takes two to tango: Managing technology risk is now a
Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015
Business Continuity Management Governance Frank Higgins Abu Dhabi March 2015 Different Names Same Concept BCM (Business Continuity Management) BSI 25999 IPOCM (Incident Preparedness & Operational Continuity
Cisco Unified Communications and Collaboration technology is changing the way we go about the business of the University.
Data Sheet Cisco Optimization s Optimize Your Solution using Cisco Expertise and Leading Practices Optimizing Your Business Architecture Today, enabling business innovation and agility is about being able
Information Services Strategy 2011-2013
Information Services Strategy Issue 1 1 Introduction The States of Jersey public sector is facing significant pressure for efficiencies and savings. This has created the context to take a fresh look at
A structured approach to Enterprise Risk Management (ERM) and the requirements of ISO 31000
A structured approach to Enterprise Risk Management (ERM) and the requirements of ISO 31000 Contents Executive summary Introduction Acknowledgements Part 1: Risk, risk management and ISO 31000 1 Nature
Supporting information technology risk management
IBM Global Technology Services Thought Leadership White Paper October 2011 Supporting information technology risk management It takes an entire organization 2 Supporting information technology risk management
Business Continuity Management Framework 2014 2017
Business Continuity Management Framework 2014 2017 Blackpool Council Business Continuity Framework V3.0 Page 1 of 13 CONTENTS 1.0 Forward 03 2.0 Administration 04 3.0 Policy 05 4.0 Business Continuity
Roles within ITIL V3. Contents
Roles within ITIL V3 Roles are employed in order to define responsibilities. In particular, they are used to assign Process Owners to the various ITIL V3 processes, and to illustrate responsibilities for
MINISTRY OF THE ENVIRONMENT DRINKING WATER QUALITY MANAGEMENT STANDARD
MINISTRY OF THE ENVIRONMENT DRINKING WATER QUALITY MANAGEMENT STANDARD October 2006 Introduction The Safe Drinking Water Act, 2002 (SDWA) requires Owners and Operating Authorities of municipal residential
Business Continuity Position Description
Position Description February 9, 2015 Position Description February 9, 2015 Page i Table of Contents General Characteristics... 2 Career Path... 3 Explanation of Proficiency Level Definitions... 8 Summary
Advisory Guidelines of the Financial Supervisory Authority. Requirements regarding the arrangement of operational risk management
Advisory Guidelines of the Financial Supervisory Authority Requirements regarding the arrangement of operational risk management These Advisory Guidelines have established by resolution no. 63 of the Management
Business Continuity Management Policy
Business Continuity Management Policy Business Continuity Policy Version 1.0 1 Version control Version Date Changes Author 0.1 April 13 1 st draft PH 0.2 June 13 Amendments in line with guidance PH 0.3
GAO. Year 2000 Computing Crisis: Business Continuity and Contingency Planning
GAO United States General Accounting Office Accounting and Information Management Division August 1998 Year 2000 Computing Crisis: Business Continuity and Contingency Planning GAO/AIMD-10.1.19 Preface
Telstra Service Management Framework. Your assurance of first-class network support
Telstra Service Framework Your assurance of first-class network support The Service Framework delivers comprehensive, integrated support Service Frame work SERVICE IMPROVEMENT & REPORTING Performance &
Overview. FedRAMP CONOPS
Concept of Operations (CONOPS) Version 1.0 February 7, 2012 Overview Cloud computing technology allows the Federal Government to address demand from citizens for better, faster services and to save resources,
ASX SETTLEMENT OPERATING RULES Guidance Note 10
BUSINESS CONTINUITY AND DISASTER RECOVERY The purpose of this Guidance Note The main points it covers To assist participants to understand the disaster recovery and business continuity arrangements they
Risk Management Guidelines
Business Continuity Management Understanding Risk We live in an unpredictable world. No matter how effectively a business protects itself through insurance, there are some risks that cannot be anticipated,
Performance Measurement
Performance Measurement Introduction Performance measurement is a fundamental building block of TQM and a tal quality organisation. Hisrically, organisations have always measured performance in some way
ISO27001 Controls and Objectives
Introduction This reference document for the University of Birmingham lists the control objectives, specific controls and background information, as given in Annex A to ISO/IEC 27001:2005. As such, the
JOE MOROLONG LOCAL MUNICIPALITY IT GOVERNANCE FRAMEWORK
JOE MOROLONG LOCAL MUNICIPALITY IT GOVERNANCE FRAMEWORK INDEX 1 Introduction... 2 Contextual background... 2.1 The CobiT 5 framework (2012)... 2.2 The ISO 27000 series (2005, 2011)... 2.3 The Risk IT
How To Manage Risk At Atb Financial
Guidelines for Financial Institutions Legislative Compliance Management (LCM) Date: July 2004 Introduction Regulatory risk is the risk of non-compliance with applicable regulatory requirements. For the
TOGAF TOGAF & Major IT Frameworks, Architecting the Family
Fall 08 TOGAF TOGAF & Major IT Frameworks, Architecting the Family Date: February 2013 Prepared by: Danny Greefhorst, MSc., Director of ArchiXL TOGAF is a registered trademark of The Open Group. TOGAF
Introduction UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT
INFORMATION SECURITY: UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT FACTSHEET This factsheet will introduce you to Business Continuity Management (BCM), which is a process developed to counteract systems
BUSINESS CONTINUITY MANAGEMENT FRAMEWORK
BUSINESS CONTINUITY MANAGEMENT FRAMEWORK Document Author: Civil Contingencies Service - Authorised by the CCS Joint Management Board - Version 1.0. Issued December 2012 Page 1 FRAMEWORK STATEMENT Business
MEMORANDUM. Date: October 28, 2013. Federally Regulated Financial Institutions. Subject: Cyber Security Self-Assessment Guidance
MEMORANDUM Date: October 28, 2013 To: Federally Regulated Financial Institutions Subject: Guidance The increasing frequency and sophistication of recent cyber-attacks has resulted in an elevated risk profile
AUSTRALIAN GOVERNMENT INFORMATION MANAGEMENT OFFICE CYBER SECURITY CAPABILITY FRAMEWORK & MAPPING OF ISM ROLES
AUSTRALIAN GOVERNMENT INFORMATION MANAGEMENT OFFICE CYBER SECURITY CAPABILITY FRAMEWORK & MAPPING OF ISM ROLES Final Report Prepared by Dr Janet Tweedie & Dr Julie West June 2010 Produced for AGIMO by
HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO 22301 AUDITS, CERTIFICATION AND TRAINING
HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO 22301 AUDITS, CERTIFICATION AND TRAINING ISO 22301 BUSINESS CONTINUITY MANAGEMENT SYSTEMS Most organisations will, at some point, be faced with having to respond
Governance and Management of Information Security
Governance and Management of Information Security Øivind Høiem, CISA CRISC Senior Advisor Information Security UNINETT, the Norwegian NREN About Øivind Senior Adviser at the HE sector secretary for information
