Evaluating and Improving Your Business Continuity Plan
|
|
|
- Randolph Craig
- 10 years ago
- Views:
Transcription
1 Evaluating and Improving Your Business Continuity Plan As presented to the Northeast Florida IIA Chapter January 23, 2015
2 Contact Information Karen Weir, MAC, CISA, CBCP Manager Jennifer Hensley Client Development p Accretive Solutions 76 South Laura St., Suite 202 Jacksonville, FL
3 Agenda 1. Business Continuity Overview 2. Industry Regulations 3. BCP Standards 4. Common Components 5. Determining Adequacy 2 2
4 Determine Adequacy 1. Determine your standard 2. Support your determination with facts, verify with management 3. Assess your organization s current BCP policies, process, and procedures 4. Measure and document perceived gaps 5. Formulate and present recommendations 3
5 4 Business Continuity Overview
6 Business Continuity is The method by which organizations can: Identify the likelihood and potential impact of unplanned business interruptions, Implement controls to prevent, alert, or mitigate effects of unplanned business interruptions, Recover critical functionality within an acceptable timeframe, and Restore full functionality to the organization, while suffering minimal downtime and revenue losses. 5
7 Business Interruption Examples Natural Events Hurricane* Tornado Fire/Flood Gas Leak/Explosion Power Outage H1N1 Corporate Image Scandal Product Recall Compliance Breach Man-Made, Intentional Terrorism* Sabotage Hacker/Virus Man-Made, Accidental Human Error Hazardous Spill/Leak Incident Response Program?
8 Common Factors/Any Organization Business Continuity Internal Control Framework (Policy & Procedure) Trained & Experienced Workforce Disaster Recovery Facilities (Building, Office Space, Machinery) Technology and Infrastructure (Applications, Servers, Databases) 7
9 Acronyms BCM Business Continuity Management BCP Business Continuity/Continuation Planning/Program EOC Emergency Operations Center ERP Emergency Response Plan BIA Business Impact Analysis ERT Emergency Response Team BRP Business Resumption Plan FEMA Federal Emergency Management Agency CMP Crisis Management Plan ICS Incident Command System CMT Crisis Management Team DAP Damage Assessment Plan DAT Damage Assessment Team DHS Department of Homeland Security DRP Disaster Recovery Plan MAD Maximum Acceptable/Allowable Downtime PRC Property Risk Control RPO Recovery Point Objective RTO Recovery Time Objective SCM Supply Chain Management 8
10 9 Industry Regulations
11 Regulated Industries - Examples Financial Services Insurance Energy Telecommunications Political & Public Affairs HealthCare Automotive Catalog Retail Market Research/Surveys Banking Mortgage Life & Health Property & Casualty Credit Card Utilities Service Provider? Cloud Service Provider? 10
12 Regulatory Bodies - Examples PCI (Payment Card Industry) Consumer Product Safety Commission Federal Trade Commission (FTC) Food and Drug Administration (FDA) Communications Commission (FCC) Fair Debt Collection Practices Act (FDCPA) Truth in Lending Act (TILA) Real Estate Settlement Procedures Act (RESPA) Health Insurance Portability and Accountability Act (HIPAA) Digital Millennium Copyright Banking Fair Credit Reporting Act Act (FRCA) Federal Financial Institutions Examination Council (FFIEC) 11
13 Rules and Regulations by Industry Disaster Recovery Journal website provides a comprehensive document that pulls together the DR/BCP regulations by affected industries: For these Industries Provides this Info on Regulations Banking & Finance Title Public Health & Healthcare Regulation / Standard (Reg, Stf) Transportation & Shipping Governing Body Energy (including nuclear) Country Industry Summary / Description Agriculture, Food Supply & Water Significant Dates, Fines, Penalties Information Distribution & Communications Category (Enf, Amb, Wat, IAI) Government & Public Agencies Notes /Comments Link 12
14 13 BCP Standards
15 BCP Standards Three standards currently recognized by DHS as part of the voluntary certification program: ANSI/ASIS SPC Organizational Resilience: Security, Preparedness, and Continuity Management Systems-Requirements with Guidance for Use; BS :2007-A Specification for BCM; and NFPA 1600:2010 Standard on Disaster/Emergency Management and Business Continuity Programs 14
16 ANSI/ASIS SPC Organizational Resilience Process approach Understanding an organization s risk, security, preparedness, response, continuity, and recovery requirements; Establishing a policy and objectives to manage risks; Implementing and operating controls to manage an organization s risks within the context of the organization s mission; Monitoring and reviewing the performance and effectiveness of the organizational resilience management system; and Continual improvement based on objective measurement. 15
17 BS :2007-A Specification for BCM By the British Standards Institution (BSI) Part 1 provides concept introduction/ guidance Ten (10) Sections, similar to DRJ/DRII Subject Areas Part 2 provides requirements for implementation, application, and continuous improvement of the BCM. Six (6) Sections, uses PDCA model of continuous improvement. Also in line with DRJ/DRII Subject Areas and GAP 16
18 NFPA 1600:2010 Standard on Disaster/Emergency Management and Business Continuity Programs Process approach Understanding an organization s risk, security, preparedness, response, continuity, and recovery requirements; Establishing a policy and objectives to manage risks; Implementing and operating controls to manage an organization s risks within the context of the organization s mission; Monitoring and reviewing the performance and effectiveness of the organizational resilience management system; and Continual improvement based on objective measurement. 17
19 My Starting Point Professional Practices for Business Continuity Practitioners: Joint effort of the Disaster Recovery Journal and the Business Continuity Institute based in the UK. Generally Accepted Practices (GAP) includes input and cooperation from: Association of Records Management Administration (ARMA) DRI International (DRII) Financial Services Technology Consortium (FSTC) Standards Australia/Standards New Zealand National Fire Protection Association (NFPA) 18
20 19 BCP Components
21 Ten Subject Areas 1. Program Initiation and Management 2. Risk Evaluation and Control 3. Business Impact Analysis 4. Business Continuity Strategies 5. Emergency Response and Operations 6. Business Continuity Plans 7. Awareness and Training Programs 8. Business Continuity Plan Exercise, Audit and Maintenance 9. Crisis Communications 10. Coordination with External Agencies 20
22 Program Initiation and Management Establish the need for Business Continuity Management Business Continuity Policy Obtain management support and project approval Program Champion 21
23 Risk Evaluation and Control Identify Potential Exposures/Risks Qualify and Prioritize Identify Controls and Safeguards Evaluate Effectiveness Prioritized Approved by Management Quantified, both in probabilities and potential impacts Corp. Scandal Flood Random Violence Risk Assessment 22
24 Business Impact Analysis Identify the impacts of interruptions Identify time-critical functions Identify interdependencies Prioritize Time Systems Key People Facility Needs RTO: Recovery Time Obj. RPO: Recovery Point Obj. Applications Alternative work-arounds Cross-training recommendations Back-ups Alternate Office Space, Laptops 23
25 24 BIA Exercise
26 Business Continuity Strategies Determine organizational needs Determine functional/ departmental needs Identify and Present Solutions to meet both Guiding Decisions Go/No-go circumstances Facilities Secondary/Tertiary Office Space Relocation 25
27 Emergency Response and Operations Identify Potential Emergencies and Responses Review Evacuation Plans Command and Control Procedures (Alternate Hierarchy) Emergency Response Plan(s) Communication Plan Roles and Responsibilities 26
28 27 Emergency Response Exercise
29 Business Continuity Plans Identify Plan Requirements Strategic Tactical Operational Assumptions & Scenarios BC Plan Hurricane Prep, for example Disaster Recovery Critical Functions Recovery Procedures Warning Signs Employee Communication Line Info Alternate Facility Prioritized System Recovery 28
30 Awareness and Training Programs Corporate Awareness Programs Emergency Responder Training (CPR, Fire Extinguisher, etc.) Functional & Technical (Practice) Training Calendar Schedules Specialized First Responder Training Schedule Periodic Awareness Messages for Employee Base 29
31 Business Continuity Plan Exercise, Audit and Maintenance Exercise/Testing Program Plan Maintenance Program Business Continuity Audit Process Communicate Exercise/Test Results Diagram by Karn G. Bulsuk ( 30
32 31 BCP Exercises
33 Crisis Communications Crisis Communications Program Escalation procedures Roles and Responsibilities Audience groups and messages Crisis Communication Plan ID Designated Speaker(s) Scripts Development By situation Internal/External Media Relationships 32
34 Coordination with External Agencies Coordinate Emergency Management with External Agencies Identify relevant external agencies (Police Department, Fire & Rescue) Identify statutory requirements Involve external agencies as appropriate Review plans & recommend improvements Participate in exercises Provide training 33
35 34 Determining Adequacy
36 Review and Evaluation 1. For each subject area, determine what is appropriate for your organization 2. Support your determination with facts, verify with management 3. Assess your organization s current policies, process, and procedures 4. Document perceived gaps 5. Formulate recommendations 35
37 36 36 Questions?
Business Continuity and Disaster Recovery Planning
Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services
Temple university. Auditing a business continuity management BCM. November, 2015
Temple university Auditing a business continuity management BCM November, 2015 Auditing BCM Agenda 1. Introduction 2. Definitions 3. Standards 4. BCM key elements IT Governance class - IT audit program
MHA Consulting. Business Continuity Management 101
0 MHA Consulting Business Continuity Management 101 Presented by: Michael Herrera Brandon Magestro MHA Consulting Agenda MHA Consulting Introduction Business Continuity Management (BCM) Defined 2013 Trends
www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014
www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 Agenda Key Definitions Risks Business Continuity Management Program BCM Capability Assessment Process BCM Value Proposition
How To Plan A Crisis Management Program
Building a Security Conscious Business Continuity Management (BCM) Program Sam Stahl, CBCP, MBCI EMC Global Professional Services Program Manager [email protected] ASIS Singapore, 2014 Agenda Overview
Business Continuity Plan
Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions
Subject Area 1 Project Initiation and Management
DRII/BCI Professional Practice Narrative: Establish the need for a Business Continuity Plan (BCP), including obtaining management support and organizing and managing the BCP project to completion. (This
2014 NABRICO Conference
Business Continuity Planning 2014 NABRICO Conference September 19, 2014 6 CityPlace Drive, Suite 900 St. Louis, Missouri 63141 314.983.1200 1520 S. Fifth Street, Suite 309 St. Charles, Missouri 63303 636.255.3000
BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION
BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION EXCERPT FROM THE FOREWORD TO THE 2ND EDITION The events of 9/11 have cast a long shadow over the world and led to a vital reappraisal of Enterprise Risk
Principles for BCM requirements for the Dutch financial sector and its providers.
Principles for BCM requirements for the Dutch financial sector and its providers. Platform Business Continuity Vitale Infrastructuur Financiële sector (BC VIF) Werkgroep BCM requirements 21 September 2011
Business Continuity Standards A Primer
INTELLIGENT NOTIFICATION Alphabet Soup: Making Sense of BC/DR Standards Part 1: Business Continuity Standards A Primer Why all the attention now? One of the hottest topics in BC/DR these days is standards.
National Fire Protection Association s Contribution to Business Continuity Strategies
National Fire Protection Association s Contribution to Business Continuity Strategies about me 1. Retired AVP Senior Business Risk Consultant 2. FM Global Trained: 1. 35 Years Service 2. Founder Member
Business Continuity and Disaster Recovery Planning 3/16/2011. Lee Goldstein CPCP, MBCI President Business Contingency Group
Business Continuity and Disaster Recovery Planning 3/16/2011 Lee Goldstein CPCP, MBCI President Business Contingency Group Business Continuity/Disaster Recovery Planning to ensure the continuation/recovery
Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015
Business Continuity Management Governance Frank Higgins Abu Dhabi March 2015 Different Names Same Concept BCM (Business Continuity Management) BSI 25999 IPOCM (Incident Preparedness & Operational Continuity
BUSINESS CONTINUITY PLAN OVERVIEW
BUSINESS CONTINUITY PLAN OVERVIEW INTRODUCTION The purpose of this document is to provide Loomis customers with an overview of the company s Business Continuity Plan (BCP). Because of the specific and
Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC
Assessing Your Disaster Recovery Plans Gregory H. Soule, CPA, CISA, CISSP, CFE Andrews Hooper Pavlik PLC Andrews Hooper Pavlik PLC Agenda Business Continuity Concepts Impact Analysis Risk Assessment Risk
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program subsidiaries) 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis
Business Continuity Planning for Water Utilities: Guidance Document [Project #4319]
Business Continuity Planning for Water Utilities: Guidance Document [Project #4319] ORDER NUMBER: 4319 DATE AVAILABLE: June 2013 PRINCIPAL INVESTIGATORS: Jack Moyer, Rhiannon Kincaid, Kory Wilmot, Kate
Western Intergovernmental Audit Forum
Western Intergovernmental Audit Forum Business Continuity & Disaster Recovery Planning September 12, 2013 Presented by: City of Phoenix City Auditor Department Aaron Cook, Sr Internal Auditor IT Audit
Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke
Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke Agenda Key components essential to a FFIEC compliant Business Continuity Plan Recovery Time Objectives & Recovery Point
Business Continuity and Disaster Recovery
Business Continuity and Disaster Recovery Trends, Considerations, & Leading Practices November 13, 2014 Presented by: Jon Bronson Los Angeles Trey MacDonald Atlanta Today s Presenters Jon Bronson is a
PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA
Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand
BUILDING A SECURITY CONSCIOUS BUSINESS CONTINUITY MANAGEMENT (BCM) PROGRAM
BUILDING A SECURITY CONSCIOUS BUSINESS CONTINUITY MANAGEMENT (BCM) PROGRAM SAM STAHL, CBCP, MBCI EMC GLOBAL PROFESSIONAL SERVICES PROGRAM MANAGER [email protected] ASIS SHANGHAI, 2015 1 AGENDA Overview
Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010
Business Continuity and Emergency Preparedness Planning Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010 Overview Define key terms and list essential elements of business continuity
RLI PROFESSIONAL SERVICES GROUP PROFESSIONAL LEARNING EVENT PSGLE 125. When Disaster Strikes Are You Prepared?
RLI PROFESSIONAL SERVICES GROUP PROFESSIONAL LEARNING EVENT PSGLE 125 When Disaster Strikes Are You Prepared? Copyright Materials This presentation is protected by US and International Copyright laws.
Business Continuity Planning 101. +1 610 768-4120 (800) 634-2016 www.strohlsystems.com [email protected]
Business Continuity Planning 101 Presentation Overview What is business continuity planning Plan Development Plan Testing Plan Maintenance Future advancements in BCP Question & Answer What is a Disaster?
Business Continuity (Policy & Procedure)
Business Continuity (Policy & Procedure) Publication Scheme Y/N Can be published on Force Website Department of Origin Force Operations Policy Holder Ch Supt Head of Force Ops Author Business Continuity
EMERGENCY PREPAREDNESS PLAN Business Continuity Plan
EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic
SCADA Business Continuity and Disaster Recovery. Presented By: William Biehl, P.E. 913-601-0104 (mobile) [email protected]
SCADA Business Continuity and Disaster Recovery Presented By: William Biehl, P.E. 913-601-0104 (mobile) [email protected] Business Continuity Planning, a Sound Process A Business Continuity Plan: "A
DRII PP Introduction to the Professional Practices Page 1
Professional Practice Introduction Business Continuity Management (BCM) is a management process that identifies risk, threats and vulnerabilities that could impact an entity s continued operations and
DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY
DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY This document outlines a set of policies and procedures for formalising a Business Continuity programme, and provides guidelines for developing, maintaining
CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT
CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14
Business Continuity Management
Business Continuity Management cliftonlarsonallen.com Introductions Brian Pye CliftonLarsonAllen Senior Manager Business Risk Services group 15 years of experience with Business Continuity Megan Moore
Business Continuity. Port environment
Business Continuity Port environment DEFINE BUSINESS CONTINUITY WHAT IT IS NOT RECOVERY FOCUS: PEOPLE PROCESSES TECHNOLOGY DELIVERABLES INFRAGARD DEFINITION MANAGEMENT PROCESS DEVELOPING ADVANCE PROCEDURES
Business Continuity for the New Professional. Britt Corra Enterprise BCM Erika Voss Senior BCM
Business Continuity for the New Professional Britt Corra Enterprise BCM Erika Voss Senior BCM New to Business Continuity? Agenda & Experience 3-5 years experience? Seasoned veteran? What is BCM Tool Kit?
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page
Business Continuity Glossary
Developed In Conjuction with Business Continuity Glossary ACTIVATION: The implementation of business continuity capabilities, procedures, activities, and plans in response to an emergency or disaster declaration;
With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS
How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning The world has experienced a great deal of natural and man-made upheaval and destruction in the past few years, including tornadoes,
A BCP Tale: From Theory to Practice
A BCP Tale: From Theory to Practice Presenter: Gord Novoselnik Problem & Configuration Manager, Enterprise Solutions Division, MTS Allstream [email protected] 1 10 Commandments of BCM I.
Emergency Response and Business Continuity Management Policy
Emergency Response and Business Continuity Management Policy Owner: John Duffy, Registrar & Secretary Last updated: September 2012 Version: 04 Document control Date Version Author Changes To be populated
White Paper: ISO 22301 Business Continuity Management An Overview. ISO 22301 Business Continuity Management An Overview
White Paper: ISO 22301 Business Continuity Management An Overview ISO 22301 Business Continuity Management An Overview Introduction As incidents such as malicious activism, terrorist attacks and environmental
Proposal for Business Continuity Plan and Management Review 6 August 2008
Proposal for Business Continuity Plan and Management Review 6 August 2008 2008/8/6 Contents About Newton IT / Quality of our services. BCM & BS25999 Overview 2. BCM Development in line with BS25999 3.
Business Continuity & Disaster Recovery
Business Continuity & Disaster Recovery Safety First Quality Every Time 1 Business Continuity & Disaster Recovery Planning Who here has a formal Business Continuity & Disaster Recovery plan? The purpose
Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745
ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan
PBSi Business Continuity Planning
Business Continuity Planning Definition Business Continuity planning is a planning process designed to reduce the risk that disruptive failures or events could seriously harm your business. It is designed
State of South Carolina Policy Guidance and Training
State of South Carolina Policy Guidance and Training Policy Workshop All Agencies Business Continuity Management Policy June 2014 Agenda Questions & Follow-Up Policy Workshop Overview & Timeline Policy
PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA
1 Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand
Business Continuity Planning Preparing Your Organization
Business Continuity Planning Preparing Your Organization Nicholas De Laurentis, CRM, IGP [email protected] 1 Objectives Understand the importance of Business Continuity Planning Know
Business Continuity Management Program Development Guide
Business Continuity Management Program Development Guide Prepared by The NS Emergency Management Office, Winter 2012 Version 1.1 Page 2 of 24 Document Revision History Date Author Revision Notes Fall 2011
The ABC s of BCP. Jeremy Sucharski Governance Risk and Compliance G31
The ABC s of BCP Jeremy Sucharski Governance Risk and Compliance G31 Jeremy Sucharski, CISA, CRISC Over 12 years of experience CISA and CRISC Certifications Governance, Risk and Compliance Practice Leader
#316 The Security Elements of Business Continuity & Disaster Recovery Plans
#316 The Security Elements of Business Continuity & Disaster Recovery Plans Ken Doughty CISA CBCP ODAS [email protected] Presentation Outline Introduction Overview of Business Continuity Security
Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION
Federal Financial Institutions Examination Council FFIEC Business Continuity Planning MARCH 2003 MARCH 2008 BCP IT EXAMINATION H ANDBOOK TABLE OF CONTENTS INTRODUCTION... 1 BOARD AND SENIOR MANAGEMENT
Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK
Federal Financial Institutions Examination Council FFIEC Business Continuity Planning BCP FEBRUARY 2015 IT EXAMINATION H ANDBOOK Table of Contents Introduction 1 Board and Senior Management Responsibilities
External Supplier Control Requirements BCM
External Supplier Control Requirements BCM BCM Requirement Description BCM Tiers Recovery Time Objective Why this is important 1. Business Continuity Policy Supplier will have a documented Business Continuity
Disaster Recovery Planning
Disaster Recovery Planning This is a brief guide, with a suggested table of contents, to help you get started with putting together your Disaster Recovery Plan (DRP) Pensar can assist you in completing
Loss Control Webcast. Disaster Recovery Planning we re not in Kansas anymore
Loss Control Webcast Disaster Recovery Planning we re not in Kansas anymore May 15, 2013 1 The information presented in this material has been developed from sources believed to be reliable. It is presented
Business Continuity and Crisis Management
Business Continuity and Crisis Management Crisis Management, Business Continuity and The Incident Command System Understanding Differences and Putting it all together? by Max Ckonjevic FBCI, CBCP 1 Objectives
Plan Development Getting from Principles to Paper
Plan Development Getting from Principles to Paper March 22, 2015 Table of Contents / Agenda Goals of the workshop Overview of relevant standards Industry standards Government regulations Company standards
DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES
APPENDIX 1 DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES March 2008 Auditor General s Office Jeffrey Griffiths, C.A., C.F.E. Auditor General City of Toronto TABLE OF CONTENTS EXECUTIVE SUMMARY...1
Ohio Conference for Payroll Professionals Disaster Recovery
Ohio Conference for Payroll Professionals Disaster Recovery Speaker Bruce E. Phipps CPP 2011 APA Payroll Man of the Year Principal Product Manager US Legislative Analyst ORACLE Corporation [email protected]
Assessment of natural hazards, man made hazards, technical and societal related risks and associated impact.
Aon Business Continuity Planning The Aon Business Continuity Planning practice provides consulting services that allow Aon clients to measure and manage their strategic and tactical risks through Crisis
Table of Contents... 1
... 1 Chapter 1 Introduction... 4 1.1 Executive Summary... 4 1.2 Goals and Objectives... 5 1.3 Senior Management and Board of Directors Responsibilities... 5 1.4 Business Continuity Planning Processes...
Moving from BS 25999-2 to ISO 22301. The new international standard for business continuity management systems. Transition Guide
Transition Guide Moving from BS 25999-2 to ISO 22301 The new international standard for business continuity management systems Extract from The Route Map to Business Continuity Management: Meeting the
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP). Ed Fortin President Fortin Consulting Paul Godden Consultant & Quotation Author Friday 24 th February 2012 Business Continuity Planning
Building and Maintaining a Business Continuity Program
Building and Maintaining a Business Continuity Program Successful strategies for financial institutions for effective preparation and recovery Table of Contents Introduction...3 This white paper was written
The Role of Internal Audit In Business Continuity Planning
The Role of Internal Audit In Business Continuity Planning Dan Bailey, MBCP Page 0 Introduction Dan Bailey, MBCP Senior Manager Protiviti Inc. [email protected] Actively involved in the Information
Beyond Disaster Recovery: Why Your Backup Plan Won t Work
Beyond Disaster Recovery: Why Your Backup Plan Won t Work Contents Introduction... 3 The Data Backup Model - Upgraded for 2015... 4 Why Disaster Recovery Isn t Enough... 5 Business Consequences with DR-Only
Tips and techniques a typical audit programme
Auditing Business Continuity Planning Tips and techniques a typical audit programme Karen Wills, Senior Internal Auditor St James s Place Wealth Management February 2014 Contents Background Roles and Responsibilities
BUSINESS CONTINUITY POLICY
BUSINESS CONTINUITY POLICY Document Type Corporate Policy Unique Identifier CO-038 Document Purpose To provide a structure through which: i. A comprehensive business continuity management system (BCMS)
The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)
Information Technology Disaster Recovery Policy Policy Statement This policy defines acceptable methods for disaster recovery planning, preparedness, management and mitigation of IT systems and services
Protecting your Enterprise
Understanding Disaster Recovery in California Protecting your Enterprise Session Overview Why do we Prepare What is? How do I analyze (measure) it? What to do with it? How do I communicate it? What does
Why Should Companies Take a Closer Look at Business Continuity Planning?
whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters
How To Prepare For A Disaster
Building an effective Tabletop Exercise Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 3/26/2013 #1 Continuity Plan Testing Flowchart 3/26/2013 #2 1 Ongoing Multi-Year
PROFESSIONAL PRACTICES FOR BUSINESS CONTINUITY PRACTITIONERS
PROFESSIONAL PRACTICES FOR BUSINESS CONTINUITY PRACTITIONERS INTRODUCTION... 3 SUBJECT AREA OVERVIEW... 3 SUBJECT AREA 1 - PROGRAM INITIATION AND MANAGEMENT... 5 SUBJECT AREA 2 - RISK EVALUATION AND CONTROL...
Business Continuity Management AIRM Presentation
16 January, 2008 Business Continuity Management AIRM Presentation David Hamilton, Senior Consultant http://www.marsh.ie Presentation Overview Terms used for BCP Where BCM fits in a business plan Business
Il nuovo standard ISO 22301 sulla Business Continuity Scenari ed opportunità
Il nuovo standard ISO 22301 sulla Business Continuity Scenari ed opportunità Massimo Cacciotti Business Services Manager BSI Group Italia Agenda BSI: Introduction 1. Why we need BCM? 2. Benefits of BCM
COMCARE BUSINESS CONTINUITY MANAGEMENT
COMCARE BUSINESS CONTINUITY MANAGEMENT Title Business Continuity Management Version 2.1 Authorised by Executive Committee Effective date Authorisation date 10/7/2012 10/7/2012 COMCARE BUSINESS CONTINUITY
Company Management System. Business Continuity in SIA
Company Management System Business Continuity in SIA Document code: Classification: Company Project/Service Year Document No. Version Public INDEX 1. INTRODUCTION... 3 2. SIA S BUSINESS CONTINUITY MANAGEMENT
Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning MARCH 2003 IT EXAMINATION H ANDBOOK
Federal Financial Institutions Examination Council FFIEC Business Continuity Planning MARCH 2003 BCP IT EXAMINATION H ANDBOOK TABLE OF CONTENTS INTRODUCTION... 1 BOARD AND SENIOR MANAGEMENT RESPONSIBILITIES...
Creating a Business Continuity Plan for your Health Center
Creating a Business Continuity Plan for your Health Center 1 Page Left Intentionally Blank 2 About This Manual This tool is the result of collaboration between the Primary Care Development Corporation
EMERGENCY MANAGEMENT PLANNING CRITERIA FOR AMBULATORY SURGICAL CENTERS
EMERGENCY MANAGEMENT PLANNING CRITERIA FOR AMBULATORY SURGICAL CENTERS The following criteria are to be used when developing Comprehensive Emergency Management Plans (CEMP) for all ambulatory surgical
Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP)
Preface Computer systems are the core tool of today s business and are vital to every business from the smallest to giant organizations. Money transactions, customer service are just simple examples. Despite
Business Continuity in Healthcare
Business Continuity in Healthcare Cynthia Simeone, CBCP, PMP Director Business Resilience Catholic Health Initiatives Scott Ream President Virtual Corporation 1 Session Speakers Cynthia Simeone, CBCP,
Staying In Business. A Business Continuity White Paper by. Paul O Brien and Gerard Joyce. LinkResQ Limited
Staying In Business A Business Continuity White Paper by Paul O Brien and Gerard Joyce LinkResQ Limited Contents: Introduction. 2 What is Business Continuity? 2 Loss Events = Opportunities for Disaster..
CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard
PUBLIC Version: 1.0 CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard (Approved by the Information Strategy and Governance Committee in December 2013; revision 1.1 approved by Chief
Business Continuity Planning for Schools, Departments & Support Units
Business Continuity Planning for Schools, Departments & Support Units 1 What is Business Continuity Planning? Examples Planning for an adverse, major or catastrophic event that would cause a disruption
Continuity of operations for critical infrastructure. Disclosure of critical information to the government.
Regulatory compliance is a significant factor influencing the development of your business resilience strategy. Moreover, while Business Continuity or Disaster Recovery regulations may not apply in every
HB 292 2006 A Practitioners Guide to Business Continuity Management
HB 292 2006 A Practitioners Guide to Business Continuity Management HB HB 292 2006 Handbook A practitioners guide to business continuity management First published as HB 292 2006. COPYRIGHT Standards Australia
D2-02_01 Disaster Recovery in the modern EPU
CONSEIL INTERNATIONAL DES GRANDS RESEAUX ELECTRIQUES INTERNATIONAL COUNCIL ON LARGE ELECTRIC SYSTEMS http:d2cigre.org STUDY COMMITTEE D2 INFORMATION SYSTEMS AND TELECOMMUNICATION 2015 Colloquium October
Business Continuity Planning
Business Continuity Planning We believe all organisations recognise the importance of having a Business Continuity Plan, however we understand that it can be difficult to know where to start. That s why
