Identify and Protect Your Vital Records
|
|
|
- Derrick Austin
- 10 years ago
- Views:
Transcription
1 Identify and Protect Your Vital Records INTRODUCTION The Federal Emergency Management Agency s Federal Preparedness Circular 65 states The protection and ready availability of electronic and hardcopy documents, references, records, and information systems needed to support essential functions under the full spectrum of emergencies is another critical element of a successful COOP plan. Agency personnel must have access to and be able to use these records and systems in conducting their essential functions. Each Federal agency is responsible for establishing a Vital Records Program for the identification and protection of those records needed for Continuity of Operations Plans (COOP) before, during, and after emergencies and those records needed to protect the legal and financial rights of the Government and persons affected by Government activities. This means identifying, safeguarding, and having readily available documents, databases, and information systems that support an organization s performance of its essential functions or are critical to preserving rights and interests. Vital records are required to support an organization s roles and responsibilities during and following an event that significantly disrupts normal operations, such as a national security emergency or natural disaster. The identification and protection of copies of vital records and the implementation of records disaster mitigation and recovery programs are an insurance policy against disruption of critical agency operations. To effect that insurance policy, Federal agencies must act to achieve the aims of continuing operations, resuming normal business operations, protecting legal and financial rights, and recovering damaged records. A review of statutory and regulatory responsibilities and current file plans of offices that perform essential functions or preserve rights and interests is critical to the identification of vital records. Vital records should comprise a relatively small fraction of the organization s total volume of records and be an integral part of the organization s overall COOP. To comply with the statutory and regulatory requirements, the Department of Energy (DOE) issued DOE O 243.2, Vital Records, which sets forth requirements and responsibilities for implementing and maintaining a vital records program. WHAT ARE VITAL RECORDS? 36 CFR 1223, Managing Vital Records, defines two basic categories of records - emergency operating and rights and interest. Emergency Operating Records Emergency operating records are those vital records essential to the continued functioning or reconstitution of an organization during and after an emergency. Emergency operating records include those records an organization needs in order to perform functions in support of another office s essential functions. (For example, information regarding foreign travel may be routine to the travel office but essential to an organization with personnel overseas who need to return during a crisis.)
2 Emergency operating records are based on emergency missions, functions, and plans of operation. They include records that support both critical activities and resumption of normal operations once the emergency or disaster has passed. The possibility that normal operations might not resume at the organization s original operating facility (for example, in the case in which the original facility is destroyed) should be considered. Emergency operating records support the most critical activities the organization must perform if it operates under other than normal business conditions and in a facility other than its normal place of business. If emergency operating records are retained in electronic form, appropriate equipment (computers, software and supporting services such as air conditioning and power) must be available at the emergency operations center and the alternate operating location to readily permit their use. Records in paper form are often appropriate as emergency operating records because their use does not rely on mechanical or electronic equipment. If available, electronic records may be accessed from remote locations via remote access or compact disks and may be the most accessible option, if the use of paper records is prevented by the emergency. Examples of Emergency Operating Records include but are not limited to: Emergency plans and directive(s), or other authorizing issuances, including information needed to operate the emergency operations center and its equipment, and records recovery plans and procedures Orders of succession Delegations of authority Staffing assignments Relocation plans Lists of emergency staff assigned to the emergency operations center, or other emergency duties and authorized access to damaged facilities to assess the extent of damage (include names, addresses, and telephone numbers and comparable data for alternates) Next-of-kin information so that families of those injured can be notified Vital records inventory, locations, file plans, and protection methods Site maps and engineering drawings, especially those that would be required to recover the use of a facility Documentation for any electronic system designated an emergency operating system Records required to protect the health and safety of personnel Records required to support personnel on travel Resources necessary to acquire office space and equipment. Rights and Interests Records Rights and interest records are those needed to protect an organization s essential legal and financial functions and activities and the legal and financial rights of individuals directly affected by the organization. These records may not be needed during an emergency, so storage locations do not have to be at or in the vicinity of emergency operating facilities. Such records may be stored at a Federal Records Center (FRC) or similar repository. Examples of rights and interest records include: Payroll, Financial, Budget records, accounts receivable records Personnel, Leave, Health, and Insurance records Military, Social Security, and Retirement records
3 Contracts and Agreements Grants and Leases Entitlements Obligations, which if lost would impose a legal or financial risk Systems documentation for electronic systems that manage personnel and financial records. WHAT ARE YOUR RESPONSIBILITIES? Executive Order 12656, Assignment of Emergency Preparedness Responsibilities, sets forth the emergency functions, leads, and support responsibilities of each agency. Among the Department s responsibilities under EO are: Develop implementation plans, operational systems and priorities for the allocation of all energy resource requirements Identify energy facilities essential to the mobilization, deployment and sustainment of resources to support the national security and national welfare Develop energy supply and demand strategies to ensure continued provision of minimum essential services in national security emergencies Assure the security of nuclear materials, nuclear weapons, and devices in the custody of Departmental production facilities Ensure protection of unique research and development programs significant to the national welfare, defense and security. Each DOE element must implement a vital records program. Each DOE element s functional responsibilities and business needs are different and each must decide which records are vital records and assign responsibility for them to the appropriate staff. However, all vital records programs must include: Identifying, protecting controlling access to, and ensuring availability of records and certain information systems Accessing records required to support critical activities the organization performs when operating under abnormal business conditions and/or in a location other than the normal place of business Establishing and maintaining a vital records inventory An inventory system that identifies hard copy and electronic records Protection against and assessment of records damage or loss The timely and efficient assessment of records damage or loss and recovering records affected by an emergency disaster Storing and maintaining records Continual reappraisal of the vital records with at least an annual review Recovering records that are damaged in an emergency or disaster Ensuring that contracting officers transmit vital records requirements to the contractors. DOE O contains detailed descriptions of the above requirements. Responsibilities of emergency operations staff, emergency management program administrators, and Program Records Officials (PRO) are also outlined in the Order.
4 VITAL RECORDS INVENTORY Each DOE element should develop a vital records plan. The first part of the plan is an inventory of vital records that are vital to continued agency operations or for the protection of legal and financial rights. The plan should include specific measures for storing copies of the records at a number of different locations to ensure immediate access in any situation and measures to cycle (update) the copies. Continuous reappraisal of vital records is imperative. A review should be performed at least annually to ensure changing conditions are addressed and records are complete and up to date. The inventory should contain the records series or system title, description, type of vital record, name of office and individual responsible, media, software /hardware requirements, physical location of copies, and date of last update. PROTECTION OF VITAL RECORDS Vital records must be protected against damage and loss. They must be kept current, complete, and available. The most important factor guiding the selection of a method of protection for vital records is the ratio of the effectiveness of the protection method to the cost of that protection. The best choice is the one for which the cost of security is most closely aligned with the degree of risk. Beyond the evaluation of actual risk of loss for vital records, other factors that have a measure of importance in the selection of protection methods and the location of the backup copies include: Need for accessibility Volume and length of retention Frequency of update required Security precautions Physical susceptibility to destruction. Some common methods of protection for vital records are: Preservation of existing duplicate copies at another location Creation of special duplicate copies for offsite preservation Preservation of source records which could be used to reconstruct vital records Storage in special equipment, such as fire resistant cabinets, safes, or vaults. In choosing duplicate storage, a location should be selected that reduces the probability that the same disaster, which affects the original records might also destroy the duplicate records. Some records require special environmental storage conditions, which should be considered when selecting a storage facility. A common protection method is maintenance of electronic copies on-site and off-site storage of duplicate paper copies at an FRC or other records storage facility. Whatever method is used, it is essential to develop a rotation schedule to keep the records up to date and to dispose of duplicates that are no longer needed. If electronic backups are maintained, the software and hardware must be routinely tested. As records are duplicated and/or sent to storage, they should be indexed to ensure easy accessibility when the information is required. Time is a crucial factor in emergencies; therefore, regular systematic indexing of all vital records is a necessity.
5 RECORDS RECOVERY However, when emergencies or disasters occur, even the best of protective measures may not prevent damage to records. Each DOE Element must develop and maintain a plan to recover records that are damaged in an emergency or disaster, regardless of their media. To assist in such emergencies, a resource list of disaster recovery firms should be maintained with the vital records inventory. Records recovery specialists often concentrate on different areas of expertise (water damage, fire, mold, tape deterioration etc.), so the list should be comprehensive and current. The recovery plan should identify priorities and options for recovery or replacement. Current copies of records such as employee contact lists, vital records inventory, and information recovery plans should be maintained at multiple off-site locations to facilitate their use. RESOURCES Title 36 CFR Part 1223, Maintaining Vital Records Executive Order 12656, Assignment of Emergency Preparedness Responsibilities, Part 7, Department of Energy NARA s Vital Records and Records Disaster Mitigation and Recovery: An Instructional Guide Federal Preparedness Circular 65, Federal Emergency Management Agency ASSISTANCE For assistance in identifying and protecting emergency operating records, contact the Office of Emergency Operations, NA-40. For assistance with rights and interest records, contact the PRO in your organization. The PRO list is available via or contact the Departmental Records Officer, Office of the Chief Information Officer, at or via at [email protected]. September 2011
Vital Records Management
National Archives and Records Administration Northeast Region Vital Records Management A Briefing for Federal Agencies Pentagon, September 11, 2004 Federal Records A record is anything created or received
15 Organisation/ICT/02/01/15 Back- up
15 Organisation/ICT/02/01/15 Back- up 15.1 Description Backup is a copy of a program or file that is stored separately from the original. These duplicated copies of data on different storage media or additional
Education and Workforce Development Cabinet POLICY/PROCEDURE. Policy Number: EDU-06 Effective Date: April 15, 2006 Revision Date: December 20, 2012
Education and Workforce Development Cabinet POLICY/PROCEDURE Policy Number: EDU-06 Effective Date: April 15, 2006 Revision Date: December 20, 2012 Subject: Backup Procedures Tower and Server Farms Policy:
SAMPLE IT CONTINGENCY PLAN FORMAT
SAMPLE IT CONTINGENCY PLAN FORMAT This sample format provides a template for preparing an information technology (IT) contingency plan. The template is intended to be used as a guide, and the Contingency
BUSINESS CONTINUITY PLANNING
Policy 8.3.2 Business Responsible Party: President s Office BUSINESS CONTINUITY PLANNING Overview The UT Health Science Center at San Antonio (Health Science Center) is committed to its employees, students,
RECORDS MANAGEMENT RECORDS MANAGEMENT SERVICES. Cost-Effective, Legally Defensible Records Management
RECORDS MANAGEMENT RECORDS MANAGEMENT SERVICES Cost-Effective, Legally Defensible Records Management Does This Sound Familiar? A data breach could send our share price tumbling. I need to minimise our
Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: [email protected] Fax: (718) 380-7322
Business Continuity and Disaster Recovery Job Descriptions Table of Contents Business Continuity Services Organization Chart... 2 Director Business Continuity Services Group... 3 Manager of Business Recovery
Section 28.1 Purpose. Section 28.2 Background. DOT Order 1351.28 Records Management. CIOP Chapter 1351.28 RECORDS MANAGEMENT
CIOP Chapter 1351.28 RECORDS MANAGEMENT TABLE OF CONTENTS Section 28.1 Purpose... 1 Section 28.2 Background... 1 Section 28.3 Scope and Applicability... 2 Section 28.4 Definitions... 4 Section 28.5 Policy...
RECORDS MANAGEMENT VITAL RECORDS MANAGEMENT
RECORDS MANAGEMENT AND VITAL RECORDS MANAGEMENT OBJECTIVES Explain the purpose of Records Management (RM). Teach you how to properly create, maintain, and preserve all Marine Corps records. Help you understand
UMHLABUYALINGANA MUNICIPALITY
UMHLABUYALINGANA MUNICIPALITY BACKUP AND RESTORE POLICY Backup and Restore Policy Approval and Version Control Approval Process: Position or Meeting Number: Date: Originator Recommended by Director of
Glossary of Records Management Terms
Glossary of Records Management Terms Active record: A record referenced often in the conduct of current departmental business. Administrative record: Records documenting the day to day operation and administration
RECORDS AND INFORMATION MANAGEMENT AND RETENTION
RECORDS AND INFORMATION MANAGEMENT AND RETENTION Policy The Health Science Center recognizes the need for orderly management and retrieval of all official records and a documented records retention and
Continuity Planning and Disaster Recovery
Responsible Officer: AVP - Information Technology Services & UC Chief Information Officer Responsible Office: IT - Information Technology Services Issuance Date: 7/27/2007 Effective Date: 7/27/2007 Scope:
HOW TO DEVELOP A RECORDS PROCEDURES MANUAL. New York State Unified Court System Division of Court Operations Office of Records Management
HOW TO DEVELOP A RECORDS PROCEDURES MANUAL New York State Unified Court System Division of Court Operations Office of Records Management June 2003 HOW TO DEVELOP A RECORDS PROCEDURES MANUAL PURPOSE OF
The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)
Information Technology Disaster Recovery Policy Policy Statement This policy defines acceptable methods for disaster recovery planning, preparedness, management and mitigation of IT systems and services
Comprehensive Emergency Management Plan (CEMP) Annex V CONTINUITY OF OPERATIONS PLAN (COOP)
Annex V CONTINUITY OF OPERATIONS PLAN (COOP) Milwaukee County Office of the Sheriff (MCSO) Division of Emergency Management Milwaukee County, ANNEX V CONTINUITY OF OPERATIONS PLAN (COOP) TABLE OF CONTENTS
Information Security Policy September 2009 Newman University IT Services. Information Security Policy
Contents 1. Statement 1.1 Introduction 1.2 Objectives 1.3 Scope and Policy Structure 1.4 Risk Assessment and Management 1.5 Responsibilities for Information Security 2. Compliance 3. HR Security 3.1 Terms
Approved by: Vice President, Human Resources & Corporate Resources and Vice President, Treasury & Compliance Date: October 14, 2009
RECORDS AND INFORMATION Approved by: Vice President, Human Resources & Corporate Resources and Vice President, Treasury & Compliance Date: October 14, 2009 PURPOSE Penn West recognizes that responsible
CONTINUITY OF OPERATION PLAN (COOP) FOR NONPROFIT HUMAN SERVICES PROVIDERS
A L L I A N C E F O R H U M A N S E R V I C E S www.alliance4hs.org CONTINUITY OF OPERATION PLAN (COOP) FOR NONPROFIT HUMAN SERVICES PROVIDERS ALLIANCE FOR HUMAN SERVICES & MIAMI-DADE COUNTY OFFICE OF
DEPARTMENT OF THE NAVY RECORDS MANAGEMENT PROGRAM
...-=". DEPARTMENT OF THE NAVY OFFICE OF THE CHIEF OF NAVAL OPERATIONS 2000 NAVY PENTAGON WASH INGTON, D.C. 20350 2000 IN REPLY RE FER T O SECNAVINST 5210.8D DONCIO SECNAV INSTRUCTION 5210.8D From: Subj:
Operational Risk Publication Date: May 2015. 1. Operational Risk... 3
OPERATIONAL RISK Contents 1. Operational Risk... 3 1.1 Legislation... 3 1.2 Guidance... 3 1.3 Risk management process... 4 1.4 Risk register... 7 1.5 EBA Guidelines on the Security of Internet Payments...
Records & Information Management Policy
2014 Records & Information Management Policy VerQu CONTENTS Document Control... 2 Purpose... 3 Scope... 3 Organizational Placement... 3 Roles and Responsibilities... 3 Corporate Records Manager... 3 Record
September 28 2011. Tsawwassen First Nation Policy for Records and Information Management
Tsawwassen First Nation Policy for Records and Information Management September 28 2011 Tsawwassen First Nation Policy for Records and Information Management Table of Contents 1. RECORDS AND INFORMATION
This policy is not designed to use systems backup for the following purposes:
Number: AC IT POL 003 Subject: Backup and Restore Policy 1. PURPOSE The backup and restore policy establishes the need and rules for performing periodic system backup to permit timely restoration of Africa
PPSADOPTED: OCT. 2012 BACKGROUND POLICY STATEMENT PHYSICAL FACILITIES. PROFESSIONAL PRACTICE STATEMENT Developing a Business Continuity Plan
PROFESSIONAL PRACTICE STATEMENT Developing a Business Continuity Plan OCT. 2012 PPSADOPTED: What is a professional practice statement? Professional Practice developed by the Association Forum of Chicagoland
BUSINESS CONTINUITY PLAN
BUSINESS CONTINUITY PLAN Business Name: Phone # Cell # Emergency Contact Information: Dial 9-1-1 in an Emergency Non-Emergency: Police: Fire: Insurance Provider: Emergency Planning Team: I. CRITICAL OPERATIONS
Which Backup Option is Best?
Which Backup Option is Best? Which Backup Option is Best? Why Protect Your Data? Data loss disasters happen more frequently than you would think, for many different reasons: Human error and accidental
OFFICIAL. NCC Records Management and Disposal Policy
NCC Records Management and Disposal Policy Issue No: V1.0 Reference: NCC/IG4 Date of Origin: 12/11/2013 Date of this Issue: 14/01/2014 1 P a g e DOCUMENT TITLE NCC Records Management and Disposal Policy
FINAL May 2005. Guideline on Security Systems for Safeguarding Customer Information
FINAL May 2005 Guideline on Security Systems for Safeguarding Customer Information Table of Contents 1 Introduction 1 1.1 Purpose of Guideline 1 2 Definitions 2 3 Internal Controls and Procedures 2 3.1
How To Manage Records And Information Management In Alberta
8. RECORDS AND INFORMATION MANAGEMENT Overview This chapter is intended to help public bodies understand how good records and information management practices assist in the effective administration of
RECORDKEEPING MATURITY MODEL
Introduction Maturity Rating Definitions 1 Level 1 Inadequate/Sub-standard Practice is not formalised or documented. Processes and practices are fragmented or non-existent. Where processes and practices
Sierra College ADMINISTRATIVE PROCEDURE No. AP 3721
Sierra College ADMINISTRATIVE PROCEDURE No. AP 3721 Electronic Information Security and Data Backup Procedures Date Adopted: 4/13/2012 Date Revised: Date Reviewed: References: Health Insurance Portability
BACKUP SECURITY GUIDELINE
Section: Information Security Revised: December 2004 Guideline: Description: Backup Security Guidelines: are recommended processes, models, or actions to assist with implementing procedures with respect
State of Michigan Records Management Services. Frequently Asked Questions About E mail Retention
State of Michigan Records Management Services Frequently Asked Questions About E mail Retention It is essential that government agencies manage their electronic mail (e mail) appropriately. Like all other
CHAPTER 9 RECORDS MANAGEMENT (Revised April 18, 2006)
CHAPTER 9 RECORDS MANAGEMENT (Revised April 18, 2006) WHAT IS THE PURPOSE OF RECORDS MANAGEMENT? 1. To implement a cost-effective Department-wide program that provides for adequate and proper documentation
Guidelines for Off-Site Storage of Inactive Local Government Records
Guidelines for Off-Site Storage of Inactive Local Government Records Archives Technical Information Series #42 1993, rev., 1996, 2006 This publication provides advice to local governments on establishing
Records Management. Training 101
Records Management Training 101 Learning Objectives This training is designed to help you: Understand the importance of Records Management and why records are maintained Understand your RM responsibilities
Creating a Business Continuity Plan for your Health Center
Creating a Business Continuity Plan for your Health Center 1 Page Left Intentionally Blank 2 About This Manual This tool is the result of collaboration between the Primary Care Development Corporation
How to Prepare for an Emergency: A Disaster and Business Recovery Plan
How to Prepare for an Emergency: A Disaster and Business Recovery Plan Chapter 1: Overview of the Disaster and Business Recovery Plan Purpose: To develop and establish a comprehensive Disaster and Business
MANAGEMENT AUDIT REPORT DISASTER RECOVERY PLAN DEPARTMENT OF FINANCE AND ADMINISTRATIVE SERVICES INFORMATION TECHNOLOGY SERVICES DIVISION
MANAGEMENT AUDIT REPORT OF DISASTER RECOVERY PLAN DEPARTMENT OF FINANCE AND ADMINISTRATIVE SERVICES INFORMATION TECHNOLOGY SERVICES DIVISION REPORT NO. 13-101 City of Albuquerque Office of Internal Audit
BASIC STEPS IN A RECORDS MANAGEMENT PROGRAM. The basic steps in implementing a records management program are: Inventory Appraisal Scheduling
INTRODUCTION Records are indispensable in the efficient and economical operation of state government. They serve as the memory; they are the evidence of past events and the basis for future actions. When
DISASTER RECOVERY PLANNING GUIDE
DISASTER RECOVERY PLANNING GUIDE AN INTRODUCTION TO BUSINESS CONTINUITY PLANNING FOR JD EDWARDS SOFTWARE CUSTOMERS www.wts.com WTS Disaster Recovery Planning Guide Page 1 Introduction This guide will provide
Department of Defense INSTRUCTION. Reference: (a) DoD Directive 3020.26, Defense Continuity Programs (DCP), September 8, 2004January 9, 2009
Department of Defense INSTRUCTION SUBJECT: Defense Continuity Plan Development NUMBER 3020.42 February 17, 2006 Certified current as of April 27, 2011 Reference: (a) DoD Directive 3020.26, Defense Continuity
March 2007 Report No. 07-009. FDIC s Contract Planning and Management for Business Continuity AUDIT REPORT
March 2007 Report No. 07-009 FDIC s Contract Planning and Management for Business Continuity AUDIT REPORT Report No. 07-009 March 2007 FDIC s Contract Planning and Management for Business Continuity Results
Records Management Policy.doc
INDEX Pages 1. DESCRIPTORS... 1 2. KEY ROLE PLAYERS... 1 3. CORE FUNCTIONS OF THE RECORDS MANAGER... 1 4. CORE FUNCTIONS OF THE HEAD OF REGISTRIES... 1 5. PURPOSE... 2 6. OBJECTIVES... 2 7. POLICY... 2
Massachusetts Institute of Technology. Functional Area Recovery Management Team Plan Development Template
Massachusetts Institute of Technology Functional Area Recovery Management Team Plan Development Template Public Distribution Version For further information, contact: Jerry Isaacson MIT Information Security
TERRITORY RECORDS OFFICE BUSINESS SYSTEMS AND DIGITAL RECORDKEEPING FUNCTIONALITY ASSESSMENT TOOL
TERRITORY RECORDS OFFICE BUSINESS SYSTEMS AND DIGITAL RECORDKEEPING FUNCTIONALITY ASSESSMENT TOOL INTRODUCTION WHAT IS A RECORD? AS ISO 15489-2002 Records Management defines a record as information created,
Cloud Computing and Records Management
GPO Box 2343 Adelaide SA 5001 Tel (+61 8) 8204 8773 Fax (+61 8) 8204 8777 DX:336 [email protected] www.archives.sa.gov.au Cloud Computing and Records Management June 2015 Version 1 Version
Workforce Solutions Business Continuity Plan May 2014
Workforce Solutions Business Continuity Plan May 2014 Contents 1. Purpose... 3 2. Declaration of Emergency... 4 3. Critical Operations... 4 3.1 Communication... 4 3.1.1 Internal Communication During Emergencies...
UNIVERSITY OF NAIROBI POLICY ON RECORDS MANAGEMENT
UNIVERSITY OF NAIROBI POLICY ON RECORDS MANAGEMENT APRIL 2011 POLICY ON RECORDS MANAGEMENT TABLE OF CONTENTS DEFINITION OF TERMS AND ACRONYMS... 5 1.0 BACKGROUND... 5 1.1 RATIONALE... 5 1.2 VISION... 5
Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION
Federal Financial Institutions Examination Council FFIEC Business Continuity Planning MARCH 2003 MARCH 2008 BCP IT EXAMINATION H ANDBOOK TABLE OF CONTENTS INTRODUCTION... 1 BOARD AND SENIOR MANAGEMENT
Exhibit to Data Center Services Service Component Provider Master Services Agreement
Exhibit to Data Center Services Service Component Provider Master Services Agreement DIR Contract No. DIR-DCS-SCP-MSA-002 Between The State of Texas, acting by and through the Texas Department of Information
Information Security Policy
Information Security Policy Author: Responsible Lead Executive Director: Endorsing Body: Governance or Assurance Committee Alan Ashforth Alan Lawrie ehealth Strategy Group Implementation Date: September
CONTINUITY OF OPERATIONS PLAN TEMPLATE
CONTINUITY OF OPERATIONS PLAN TEMPLATE For Long-Term Care Facilities CALIFORNIA ASSOCIATION OF HEALTH FACILITIES DISASTER PREPAREDNESS PROGRAM TABLE OF CONTENTS TABLE OF CONTENTS...2 SECTION 1: INTRODUCTION...3
HIPAA Security. 2 Security Standards: Administrative Safeguards. Security Topics
HIPAA Security SERIES Security Topics 1. Security 101 for Covered Entities 5. 2. Security Standards - Organizational, Security Policies Standards & Procedures, - Administrative and Documentation Safeguards
85-01-55 Overview of Business Continuity Planning Sally Meglathery Payoff
85-01-55 Overview of Business Continuity Planning Sally Meglathery Payoff Because a business continuity plan affects all functional units within the organization, each functional unit must participate
All-Hazard Continuity of Operations Plan. [Department/College Name] [Date]
d All-Hazard Continuity of Operations Plan [Department/College Name] [Date] TABLE OF CONTENTS SECTION I: INTRODUCTION... 3 Executive Summary... 3 Introduction... 3 Goal... 4 Purpose... 4 Objectives...
9/12/2014. Part 3: Records Systems, Storage and Retrieval. Basic Concepts
Records Systems, Storage and Retrieval Part 3: Records Systems, Storage and Retrieval Basic Concepts Filing Systems Filing System Design Records Storage and Retrieval File Conversions Records Storage Facilities
Department of Defense INSTRUCTION
Department of Defense INSTRUCTION NUMBER 5015.02 February 24, 2015 DoD CIO SUBJECT: DoD Records Management Program References: See Enclosure 1 1. PURPOSE. This instruction reissues DoD Directive (DoDD)
DIA Records Management Program
DEFENSE INTELLIGENCE AGENCY DIAl 5015.001 WASHINGTON, DC 20340-5100 29 Sep 04 OPR:_ DIA Records Management Program References: (a) DIAM 13-1, "Records Maintenance and Disposition", 30 September] 998 (canceled)
1. The records have been created, sent or received in connection with the compilation.
Record Retention & Destruction Policy Bradley Kirschner PC recognizes that the firm s engagement and administrative files are critical assets. As such, the firm has established this formal written policy
RECORD RETENTION & DESTRUCTION POLICY
City & County of San Francisco BOARD OF APPEALS RECORD RETENTION & DESTRUCTION POLICY The Board of Appeals Record Retention and Destruction Policy is adopted pursuant to Chapter 8 of the San Francisco
Offsite Disaster Recovery Plan
1 Offsite Disaster Recovery Plan Offsite Disaster Recovery Plan Presented By: Natan Verkhovsky President Disty Portal Inc. 2 Offsite Disaster Recovery Plan Introduction This document is a comprehensive
COMPLIANCE WITH THIS DOCUMENT IS MANDATORY
COVER SHEET NAME OF DOCUMENT TYPE OF DOCUMENT DOCUMENT NUMBER Procedure DATE OF PUBLICATION Published: October 2002 Revised: October 2004 Revised: September 2005 Revised: February 2011 Revised: November
Attachment #2. BUSINESS CONTINUITY PLAN Plan Development Guidelines
Version 2 May 2004 TABLE OF CONTENTS PURPOSE OF DOCUMENT... 2 ASSOCIATION RULE REQUIREMENT BY-LAW NO. 17.19.... ERROR! BOOKMARK NOT DEFINED. GUIDELINES FOR NING... 2 SCOPE OF THE PLAN... 2 GOVERNANCE AND
Records Management. 1. Introduction. 2. Strategic Plan Desired Outcomes
Records Management Classification: Policy Name: First Issued / Approved: Last Reviewed: Council Policy Records Management 13/9/2011, CCS0036 12 August 2014, Cl9829 24 February 2015, C10054 Next Review:
RECORDS MANAGEMENT POLICY
RECORDS MANAGEMENT POLICY GENERAL INFORMATION Policy Statement: Washington University requires that its records be managed in a manner consistent with applicable law, and in accordance with plans developed
DEPARTMENT OF THE NAVY HEADQUARTERS UNITED STATES MARINE CORPS 3000 MARINE CORPS PENTAGON WASHINGTON, DC 20350 3000
DEPARTMENT OF THE NAVY HEADQUARTERS UNITED STATES MARINE CORPS 3000 MARINE CORPS PENTAGON WASHINGTON, DC 20350 3000 MCO 3030.1 POC MARINE CORPS ORDER 3030.1 From : To: Commandant of the Marine Corps Distribution
RECORDS MANAGEMENT MANUAL
RECORDS MANAGEMENT MANUAL Date: September, 2007 Authored By: University Archives Contents 1. Records Management at UBC 3 A) Purpose of The Records Manual 3 B) Benefits of Records Management 3 C) Some Records
Continuity of Business
White Paper Continuity of Business SAS Continuity of Business initiative reflects our commitment to our employees, to our customers, and to all of the stakeholders in our global business community to be
SUPERVISORY AND REGULATORY GUIDELINES: PU19-0406 BUSINESS CONTINUITY GUIDELINES
SUPERVISORY AND REGULATORY GUIDELINES: PU19-0406 Business Continuity Issued: 1 st May, 2007 Revised: 14 th October 2008 BUSINESS CONTINUITY GUIDELINES I. INTRODUCTION The Central Bank of The Bahamas (
Building and Maintaining a Business Continuity Program
Building and Maintaining a Business Continuity Program Successful strategies for financial institutions for effective preparation and recovery Table of Contents Introduction...3 This white paper was written
What We ll Cover. Defensible Disposal of Records and Information Litigation Holds Information Governance the future of records management programs
What We ll Cover Foundations of Records and Information Management Creating a Defensible Retention Schedule Paper v. Electronic Records Organization and Retrieval of Records and Information Records Management
Business Continuity Plan (BCP)
1. Emergency Contact Persons CSCM s primary emergency contact persons are: John Stepp, Managing Director and CEO Phone #: 913 485 8809 Michael Horton, Branch Manager Phone #: 316 259 4449 These names will
Developing a Records Retention Program
Developing a Records Retention Program This site is intended to help you design and implement a records retention program for your organization. Here you will find a basic explanation of a records retention
RECORDS MANAGEMENT POLICY
RECORDS MANAGEMENT POLICY PURPOSE The purpose of this policy is to: Assist departments in effective utilization of space and efficient information retrieval; Establish guidelines for disposal of records;
RECORDS MANAGEMENT POLICY
RECORDS MANAGEMENT POLICY ADOPTED BY COUNCIL 13 JUNE 2006 REVIEWED BY COUNCIL 6 NOVEMBER 2006 REVIEWED BY COUNCIL 10 MAY 2010 1. INTRODUCTION The State Records Act 1997 governs the obligations and responsibilities
IT Disaster Recovery and Business Resumption Planning Standards
Information Technology Disaster Recovery and Business IT Disaster Recovery and Business Adopted by the Information Services Board (ISB) on May 28, 1992 Policy No: Also see: 500-P1, 502-G1 Supersedes No:
Disaster Recovery Policy
Disaster Recovery Policy Organizational Functional Area: Policy for: Executive Division Bank Disaster Recovery Program Board Reviewed: September 14, 2011 Department/Individual Responsible for Maintaining/Updating
FINAL AUDIT REPORT WITH RECOMENDATIONS Information Technology No. 11-001
FINAL AUDIT REPORT WITH RECOMENDATIONS Information Technology No. 11-001 SUBJECT: Review of Emergency Plans DATE: September 24, 2010 for Critical Information Technology Operations and Financial Systems
CISM Certified Information Security Manager
CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective
