B.1 DISASTER RECOVERY

Size: px
Start display at page:

Download "B.1 DISASTER RECOVERY"

Transcription

1 B.1 DISASTER RECOVERY Technology Recovery Strategy (20 hours) To confirm that MHS has developed an overall strategy to Standard: EM The hospital has an Emergency Operations Plan. (EP#4) manage information technology to minimize impact to business operations during a declared event. MHS Policy - Technology: Disaster Recovery, Section 1a Information Services will: Develop, monitor and maintain a disaster recovery plan for Information Services systems that include: a Business Impact Analysis, data backup procedures, emergency mode operation procedures, recovery procedures, and testing and revision procedures for Tier 1 production systems. Procedure I. D.2. All systems in the data centers and other critical systems will be supported with uninterrupted power sources and have access to emergency generator power by engineering. D.3. The data centers power requirements will be identified, documented, monitored and appropriately maintained by Engineering. DS4.1 - Ensure Continuous Service IT Continuity Framework. DS4.4 - Ensure Continuous Service Maintenance of the IT Continuity Plan. DS4.6 - Ensure Continuous Service IT Continuity Plan Training DS4.7 - Ensure Continuous Service IT Distribution of the IT Continuity Plan DS4.9 - Ensure Continuous Service Offsite Backup Storage 1. Assess whether MHS has developed an overall strategy for managing recovery of technology and systems. This includes: a. Existence of a written plan explaining the recovery strategy and actions to restore systems critical to patient care. b. Required procedures for IS systems (data back-up, emergency mode operations, recovery, testing, etc). c. Updates to the written plan when operations change. d. Training on plan components with key staff. e. Distribution of plan to key persons, and ensuring the plan is accessible under each disaster scenario. 2. Assess the process for managing the data centers and recovering servers during an emergency. Verify that: a. Processes exist to identify, prioritize and restore critical servers. b. Uninterruptible power sources are maintained and tested. c. Data center power requirements are identified, documented and monitored by Engineering. 3. Assess the adequacy of recovery processes for non-is managed systems. Business Impact Analysis (10 hours) To validate that MHS Policy - Technology: Disaster Recovery, Section 1a MHS has assessed Information Services will: Develop, monitor and maintain a disaster operations and recovery plan for Information Services systems that include: a aligned system Business Impact Analysis, Data Back-up Procedures, Emergency recovery plans with Mode Operations Procedures, Recovery Procedures, Testing & current business Revision Procedures needs for critical 1. Obtain a copy of the Business Impact Analysis (BIA). Assess for the following attributes: a. Reflects the current and complete MHS environment. b. Is current (within past 12 months). c. Documents the risks (qualitative/quantitative) and outcomes (opportunities/threats) for each department/ business process. 1

2 operations. 2. Validate there is a process in place to update the BIA when DS4.3 - Ensure Continuous Service Critical IT Resources changes to the MHS environment occurs. Recovery Objectives (10 hours) To verify there is a prioritization process to maximize critical resources and align business expectations with recovery objectives. MHS Policy - Technology: Disaster Recovery, Procedure I. E. Information Services and separate Information Systems Disaster Recovery Plans will be tested once a year on our Tier 1 production systems, either in response to an actual emergency or in planned drills. DS4.3 - Ensure Continuous Service Critical IT Resources 1. Assess whether IS has defined the ranges of recovery timelines for system downtime and lost data, based on process criticality. 2. Assess whether recovery time objectives (RTOs) and recovery point objectives (RPOs) have been assigned to system applications. Confirm the assigned objectives align to the Business Impact Analysis results. 3. Assess whether there is a process to communicate these objectives to the corresponding business entities/business owners. Test Plans and Schedules (30 hours) To validate that disaster recovery plans have been developed and tests have been scheduled to prepared for potential declared events. MHS Policy - Technology: Disaster Recovery, Section 1a Information Services will: Develop, monitor and maintain a disaster recovery plan for Information Services systems that include: a Business Impact Analysis, data backup procedures, emergency mode operation procedures, recovery procedures, and testing and revision procedures for Tier 1 production systems. MHS Policy - Technology: Disaster Recovery, Procedure I. E. Information Services and separate Information Systems Disaster Recovery Plans will be tested once a year on our Tier 1 production systems, either in response to an actual emergency or in planned drills. DS4.2 - Ensure Continuous Service IT Continuity Plans DS4.4 - Ensure Continuous Service Maintenance of the IT Continuity Plan DS4.5 - Ensure Continuous Service Testing of the IT Continuity Plan DS4.8 Ensure Continuous Service IT Services Recovery and Resumption 1. Verify that a schedule of tests and exercise activities have been created according to the Disaster Recovery plan. 2. Assess the process to document, update, store and collect/distribute test plans. 3. Obtain the Tier list of applications/systems used by Information Services. Assess the process for generating the list and verify the list is current (within the past year or since any major system change). 4. Select a sample of Tier 1 systems/applications and test for the following: a. Test plan has been created and is available b. Test plan is current c. Test plan identifies key personnel/responsibilities d. Test plan identifies primary actions to be performed for resumption, including data inputs/reports, other needed resources. Test Results and Remediation (20 hours) To validate that MHS Policy - Technology: Disaster Recovery, Procedure I. E. 1. Select a sample of Tier 1 applications and test for the 2

3 disaster recovery plans are effective to resume operations within expected recovery objectives and that test plans are updated based on identified improvements. Information Services and separate Information Systems Disaster Recovery Plans will be tested once a year on our Tier 1 production systems, either in response to an actual emergency or in planned drills. DS4.5 - Ensure Continuous Service Testing of the IT Continuity Plan DS Ensure Continuous Service Post-resumption Review following: a. System has been tested within the past year, either through a simulated test or an actual declared event b. Test results were documented c. A post-exercise review occurred, with recommendations to improve continuity identified 3

4 B.2 BUSINESS CONTINUITY Continuity Strategy (30 hours) To confirm that MHS has developed an overall strategy to ensure continuous operations and has implemented critical preparations in advance. Standard: EM The hospital engages in planning activities prior to developing its written Emergency Operations Plan. Standard: EM As part of its Emergency Operations Plan, the hospital prepares for how it will manage resources and assets during emergencies. Standard: EM As part of its Emergency Operations Plan, the hospital prepares for how it will manage patients during emergencies. Standard: EM The hospital evaluates the effectiveness of its emergency management planning activities. Section III. A. An HVA (Hazards Vulnerability Analysis) is completed to assess the likelihood and impact of emergencies and is used to guide the development of the Emergency Operations Plan (EOP) and Emergency Management Program. The HVA is reviewed and assessed annually to determine if the probability of emergencies has changed with changes annotated and plans revised as needed. Section III. E. The CEMP [comprehensive emergency management plan] clearly defines the process for activation and implementation of the plan. The description includes the command structure (ICS - Incident Command System) for the plan, the conditions requiring activation of the plan, and the individual(s) responsible for implementation of the plan. Washington State Emergency Management Department identifies 9 natural hazards for the state: Avalanche, Drought, Earthquake, Flood, Landslide, Severe Storm, Tsunami, Volcano, and Wildland Fire. The department also identifies 11 technological hazards: Abandoned Underground Mine, Chemical, Civil Disturbance, Dam Failure, Hazardous Material, Local Hazard, Pipeline, Radiological, Terrorism, Transportation, and Urban Fire. 1. Assess whether scenarios or criteria has been established to enact a continuity plan and declare an emergency event. 2. Validate that a comprehensive plan has been established for continuity of operations. This should address: a. Emergency Operations Center /Incident Command Center setup b. Chain of Command / Communications c. Activating and/or cancelling emergency procedures d. Instructions / Procedures to manage through events e. Alternate sites for care/treatment of patients f. Documenting results / reporting of the declared event 3. Assess management s oversight of Emergency Preparedness, including advisory board meetings and other established committees. 4. Verify that a Hazards Vulnerability Analysis (HVA) has been completed for all campuses at MHS. Select a sample of HVAs and review for the following: a. Has been updated within past 12 months b. Assesses all major Washington State hazards c. Assigns ratings and scoring of each hazard d. Has been approved by appropriate level of management 5. Validate that the hospital has prepared for sustaining operations for 96 hours. Verify the plan addresses: a. Medication/supplies management b. Staffing levels c. Food and water supplies d. Patient care 6. Validate that MHS coordinates with local and regional contacts for Emergency Preparedness. 7. Verify that an Inventory Asset Tracking process has been established to manage emergency supplies. Validate that: a. There is a process for updating this spreadsheet annually b. The spreadsheet completes all required fields c. A process is in place to meet the grant requirements for regionally-funded supplies. 8. Validate that MHS has maintains adequate levels of supplies and equipment for emergency use. Validate that supplies are 4

5 tracked and replaced when the shelf-life of perishable supplies has expired. Continuity Plans and Procedures (20 hours) To validate that response plans are successful through the ongoing planning, testing and revising of continuity plans. Standard: EM The hospital has an Emergency Operations Plan. Standard: EM The hospital evaluates the effectiveness of its Emergency Operations Plan. Section III. H. Periodic drills are essential for maintaining staff awareness of emergency procedures and for evaluating the effectiveness of plans. Section III. I. Scheduled drills and community exercises which activate the MHS CEMP provide opportunities to observe staff performance and identify opportunities for improvement. 1. Verify that an Emergency Operations Plan has been established for each hospital and it is current (last 12 months) and approved by the correct level of management/oversight. 2. Validate that a process is in place to create an emergency management plan for all clinic/off-site locations. 3. Select a sample of emergency management plans and review for the following: a. Plan is current b. Plan defines roles/key persons needed to perform the plan c. Plan outlines procedures/actions to be performed d. Plan has associated test results / lessons learned 4. Validate that MHS has developed a schedule for testing each hospital location, twice annually. Verify that MHS includes the following test scenarios in the at least one of the annual tests: a. A simulation of a surge/influx of patients b. The local community is unable to support the hospital c. Includes participation in a community-wide exercise Communications (10 hours) To validate the adequate communications can be maintained during and after a declared event to facilitate continuous operations and support of patient care. Standard: EM As part of its Emergency Operations Plan, the hospital prepares for how it will communicate during emergencies. Standard: EM The hospital evaluates the effectiveness of its Emergency Operations Plan. Section III. E. The CEMP [comprehensive emergency management plan] includes a list of key staff essential for full implementation of the plan and procedures for contacting them. Contact procedures include on-site and remote contact processes for both manual and automated capability. Section III. M. Redundant internal and external communications systems are in place and are interoperable with other healthcare and 1. Review the communication strategy in place, including available tools/channels, roles/responsibilities, and types of messages. 2. Validate processes are in place to maintain current communications information, including updating phone numbers, contact names/departments and other resources. 3. Validate that communications processes are developed for the following audiences during a declared event: a. Notifying staff & personnel b. Notifying patients/families, esp. if relocating patients c. Notifying external authorities d. Notifying media/community e. Notifying vendors/suppliers f. Notifying regional healthcare partners 4. Validate there is a process to monitor the effectiveness of communications (both internal and with external entities) 5

6 first responder agencies. during an emergency response exercise. Training (10 hours) To validate that personnel are prepared to handle a declared event. Standard: EM As part of its Emergency Operations Plan, the hospital prepares for how it will manage staff during an emergency. Standard: EM As part of its Emergency Operations Plan, the hospital prepares for how it will manage security and safety during an emergency. Section III. O. Staff knowledge of their role in CEMP [comprehensive emergency management plan] activation is evaluated annually. Changes in CEMP are incorporated into the annual mandatory education curriculum. Section IV. C. Department leaders are responsible for orienting new personnel to the procedures of the department and, as appropriate, to job and task specific responsibilities for emergency management. Section VII. C. Employees also receive departmental safety orientation at their respective work areas regarding hazards and their responsibilities to patients, visitors and co-workers. In addition, all staff will participate in periodic refresher training relative to the Hospital Command Center (HCC)/Emergency Operations Center (EOC). MHS Policy Emergency Credentialing/Privileging-Licensed Volunteers Washington Industrial Safety and Health Act (WISHA) Washington State RCW - Chapter Validate that MHS has trained staff on their emergency response roles during a declared event. Confirm there is a process to retrain staff periodically. 2. Validate there is a process for training staff on the use of emergency personal protective equipment (PPE), such as decontamination supplies. Confirm there is a process to periodically retrain staff. 3. Confirm there is a process to instruct volunteer licensed independent practitioners regarding their role in an emergency prior to a declared event. Verify there is a process to manage these volunteers during and after a declared event. 6

DISASTER RECOVERY/ BUSINESS CONTINUITY AUDITING: A CASE STUDY

DISASTER RECOVERY/ BUSINESS CONTINUITY AUDITING: A CASE STUDY 1 DISASTER RECOVERY/ BUSINESS CONTINUITY AUDITING: A CASE STUDY WAYNE PURVES DIRECTOR CHRISTA VOIE IT AUDITOR MULTICARE HEALTH SYSTEM TACOMA, WA AHIA 32 nd Annual Conference August 25-28, 2013 Chicago,

More information

Essential Components of Emergency Management Plans at Community Health Centers Crosswalk of Plan Elements

Essential Components of Emergency Management Plans at Community Health Centers Crosswalk of Plan Elements Plan Components Health centers will have an emergency management plan Plan and organization are NIMS compliant Bureau of Primary Health Care Policy Information Notice 2007-15 Plans and procedures for emergency

More information

Hospital Emergency Operations Plan

Hospital Emergency Operations Plan Hospital Emergency Operations Plan I-1 Emergency Management Plan I PURPOSE The mission of University Hospital of Brooklyn (UHB) is to improve the health of the people of Kings County by providing cost-effective,

More information

Appendix I. Joint Commission Emergency Management Standards and Related Elements of Performance

Appendix I. Joint Commission Emergency Management Standards and Related Elements of Performance Appendix I. Joint Commission Emergency Management Standards and Related Elements of Performance 0.0.0 - The hospital engages in planning activities prior to developing its written Emergency Operations

More information

Changes to the 2014 Acute Care Hospital Manual on Emergency Management Compliance. January 30, 2014 Brad Keyes, CHSP

Changes to the 2014 Acute Care Hospital Manual on Emergency Management Compliance. January 30, 2014 Brad Keyes, CHSP Changes to the 2014 Acute Care Hospital Manual on Emergency Management Compliance January 30, 2014 Brad Keyes, CHSP The New Manuals Why did we make changes to the old standards? Corrected some errors Eliminated

More information

The Joint Commission s Emergency Management Update - 2009

The Joint Commission s Emergency Management Update - 2009 The Joint Commission s Emergency Management Update - 2009 William M. Wagner, ScD CHCM CHSP CHEP Vice President-Education, Research & Development Safety Management Services, Inc. September 22, 2009 Goals

More information

The Joint Commission Approach to Evaluation of Emergency Management New Standards

The Joint Commission Approach to Evaluation of Emergency Management New Standards The Joint Commission Approach to Evaluation of Emergency Management New Standards (Effective January 1, 2008) EC. 4.11 through EC. 4.18 Revised EC. 4.20 Emergency Management Drill Standard Lewis Soloff

More information

CONTINUITY OF OPERATIONS PLAN TEMPLATE

CONTINUITY OF OPERATIONS PLAN TEMPLATE CONTINUITY OF OPERATIONS PLAN TEMPLATE For Long-Term Care Facilities CALIFORNIA ASSOCIATION OF HEALTH FACILITIES DISASTER PREPAREDNESS PROGRAM TABLE OF CONTENTS TABLE OF CONTENTS...2 SECTION 1: INTRODUCTION...3

More information

Creating a Business Continuity Plan for your Health Center

Creating a Business Continuity Plan for your Health Center Creating a Business Continuity Plan for your Health Center 1 Page Left Intentionally Blank 2 About This Manual This tool is the result of collaboration between the Primary Care Development Corporation

More information

Disaster and Pandemic Planning for Nonprofits. Continuity and Recovery Plan Template

Disaster and Pandemic Planning for Nonprofits. Continuity and Recovery Plan Template Disaster and Pandemic Planning for Nonprofits Continuity and Recovery Plan Template This publication was supported by Grant Cooperative Agreement number 5U90TP917012-08 from the U.S. Centers for Disease

More information

CCHC Emergency Preparedness Gap Analysis

CCHC Emergency Preparedness Gap Analysis This tool will help clinics and community health centers identify gaps in their planning for disaster response. If further emergency planning support is needed please review the tools and templates available

More information

South Puget Sound Community College Emergency Operations Plan Annex H RECOVERY

South Puget Sound Community College Emergency Operations Plan Annex H RECOVERY I. PURPOSE South Puget Sound Community College Emergency Operations Plan Annex H RECOVERY The purpose of this annex is to provide a process to facilitate the College s transition from a disaster situation

More information

The Joint Commission s 2012 Emergency Management Standards and HRSA Health Center Emergency Management Program Expectations. NACHC Webex Training

The Joint Commission s 2012 Emergency Management Standards and HRSA Health Center Emergency Management Program Expectations. NACHC Webex Training The Joint Commission s 2012 Emergency Management Standards and HRSA Health Center Emergency Management Program Expectations NACHC Webex Training February 2, 2012 Presented by: Virginia McCollum, MSN, RN

More information

Accreditation Program: Hospital. Emergency Management

Accreditation Program: Hospital. Emergency Management ccreditation Program: Hospital Emergency Management ccreditation of Healthcare Organizations ccreditation Program: Hospital Chapter: Emergency Management Standard EM.01.01.01 The [organization] engages

More information

Business Continuity and Disaster Recovery Planning

Business Continuity and Disaster Recovery Planning Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services

More information

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic

More information

Business Continuity Plan

Business Continuity Plan Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions

More information

How To Prepare For A Disaster

How To Prepare For A Disaster Building an effective Tabletop Exercise Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 3/26/2013 #1 Continuity Plan Testing Flowchart 3/26/2013 #2 1 Ongoing Multi-Year

More information

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC Assessing Your Disaster Recovery Plans Gregory H. Soule, CPA, CISA, CISSP, CFE Andrews Hooper Pavlik PLC Andrews Hooper Pavlik PLC Agenda Business Continuity Concepts Impact Analysis Risk Assessment Risk

More information

Boston College. Departmental Business Continuity Planning

Boston College. Departmental Business Continuity Planning Boston College Departmental Business Continuity Planning Spring 2013 1 BUSINESS CONTINUITY PROGRAM GOAL The goal of the Boston College Business Continuity Program is to ensure that all departments and

More information

Business Continuity Planning for Schools, Departments & Support Units

Business Continuity Planning for Schools, Departments & Support Units Business Continuity Planning for Schools, Departments & Support Units 1 What is Business Continuity Planning? Examples Planning for an adverse, major or catastrophic event that would cause a disruption

More information

SAMPLE IT CONTINGENCY PLAN FORMAT

SAMPLE IT CONTINGENCY PLAN FORMAT SAMPLE IT CONTINGENCY PLAN FORMAT This sample format provides a template for preparing an information technology (IT) contingency plan. The template is intended to be used as a guide, and the Contingency

More information

Business Continuity Planning Toolkit. (For Deployment of BCP to Campus Departments in Phase 2)

Business Continuity Planning Toolkit. (For Deployment of BCP to Campus Departments in Phase 2) Business Continuity Planning Toolkit (For Deployment of BCP to Campus Departments in Phase 2) August 2010 CONTENTS: Background Assumptions Business Impact Analysis Risk (Vulnerabilities) Assessment Backup

More information

4 Insurance 5 Availability of alternate sources for critical supplies/services

4 Insurance 5 Availability of alternate sources for critical supplies/services Hazard and Vulnerability Analysis Hazard and Vulnerability Analysis This document is a sample Hazard Vulnerability Analysis tool. It is not a substitute for a comprehensive emergency preparedness program.

More information

How to Prepare for an Emergency: A Disaster and Business Recovery Plan

How to Prepare for an Emergency: A Disaster and Business Recovery Plan How to Prepare for an Emergency: A Disaster and Business Recovery Plan Chapter 1: Overview of the Disaster and Business Recovery Plan Purpose: To develop and establish a comprehensive Disaster and Business

More information

Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM

Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM Business Continuity Planning and Disaster Recovery Planning Ed Crowley IAM/IEM 1 Goals Compare and contrast aspects of business continuity Execute disaster recovery plans and procedures 2 Topics Business

More information

Disaster Recovery Plan Checklist

Disaster Recovery Plan Checklist Disaster Recovery Plan Checklist Your guide for setting up or updating a Disaster Recovery Plan for your business. ArcSource Disaster Recovery Plan Checklist 1. Compile Your Internal Contacts Information

More information

Hospital Emergency Operations Plan Workshop

Hospital Emergency Operations Plan Workshop Hospital Emergency Operations Plan Workshop Updating the Hospital and Rural Medical Center EOP for the Use of Volunteers in Medical Surge AGENCY LOGO Acknowledgements: This workshop was developed by the

More information

Emergency Management Plan 2 0 1 3-2 0 1 4

Emergency Management Plan 2 0 1 3-2 0 1 4 Emergency Management Plan 2 0 1 3-2 0 1 4 Bedford Campus Lowell Campus Emergency Management Plan 1 Table of Contents Emergency Management Planning................................2 Emergency Management

More information

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain 1. What is the most common planned performance duration for a continuity of operations plan (COOP)? A. 30 days B. 60 days C. 90 days D. It depends on the severity of a disaster. 2. What is the business

More information

B U S I N E S S C O N T I N U I T Y P L A N

B U S I N E S S C O N T I N U I T Y P L A N B U S I N E S S C O N T I N U I T Y P L A N 1 Last Review / Update: December 9, 2015 Table of Contents Purpose...3 Background...3 Books and Records Back-up and Recovery...4 Mission Critical Systems...

More information

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010 Business Continuity and Emergency Preparedness Planning Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010 Overview Define key terms and list essential elements of business continuity

More information

BUSINESS CONTINUITY PLAN OVERVIEW

BUSINESS CONTINUITY PLAN OVERVIEW BUSINESS CONTINUITY PLAN OVERVIEW INTRODUCTION The purpose of this document is to provide Loomis customers with an overview of the company s Business Continuity Plan (BCP). Because of the specific and

More information

Ohio Supercomputer Center

Ohio Supercomputer Center Ohio Supercomputer Center IT Business Continuity Planning No: Effective: OSC-13 06/02/2009 Issued By: Kevin Wohlever Director of Supercomputer Operations Published By: Ohio Supercomputer Center Original

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning Business Continuity Planning and Disaster Recovery Planning Ed Crowley IAM/IEM 1 ISC 2 Key Areas of Knowledge Understand business continuity requirements 1. Develop and document project scope and plan

More information

Pilot Nursing Home Emergency Management Assessment Tool

Pilot Nursing Home Emergency Management Assessment Tool Pilot Nursing Home Emergency Management Assessment Tool Introduction The Pilot Nursing Home Emergency Management Project (NHEMP) Assessment Tool, developed by the Primary Care Development Corporation (PCDC),

More information

Continuity of Business

Continuity of Business White Paper Continuity of Business SAS Continuity of Business initiative reflects our commitment to our employees, to our customers, and to all of the stakeholders in our global business community to be

More information

The University of Iowa. Enterprise Information Technology Disaster Plan. Version 3.1

The University of Iowa. Enterprise Information Technology Disaster Plan. Version 3.1 Version 3.1 November 22, 2004 TABLE OF CONTENTS PART 1: DISASTER RECOVERY EXPECTATIONS... 3 OVERVIEW...3 EXPECTATIONS PRIOR TO AN INCIDENT OCCURRENCE...3 EXPECTATIONS PRIOR TO A DISASTER OCCURRENCE...4

More information

Business Continuity & Recovery Plan Summary

Business Continuity & Recovery Plan Summary Introduction An organization s ability to survive a significant business interruption is determined by the company s ability to develop, implement, and maintain viable recovery and business continuity

More information

Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services

Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 1 Today s Agenda Structure of Today s Discussion Set Objectives General overview of DR/BCP Exercise Assumptions Scenarios

More information

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015 Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level June 9, 2015 By: Tracy Hall MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company,

More information

Why Should Companies Take a Closer Look at Business Continuity Planning?

Why Should Companies Take a Closer Look at Business Continuity Planning? whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters

More information

Business Continuity & Recovery Plan Summary

Business Continuity & Recovery Plan Summary Introduction An organization s ability to survive a significant business interruption is determined by the company s ability to develop, implement, and maintain viable recovery and business continuity

More information

Continuity of Operations Planning. A step by step guide for business

Continuity of Operations Planning. A step by step guide for business What is a COOP? Continuity of Operations Planning A step by step guide for business A Continuity Of Operations Plan (COOP) is a MANAGEMENT APPROVED set of agreed-to preparations and sufficient procedures

More information

Recommended Practice for a Continuity of Operations Plan

Recommended Practice for a Continuity of Operations Plan Recommended Practice for a Continuity of Operations Plan Approved January 25, 2008 APTA Security Infrastructure Working Group Approved August 4, 2008 APTA Technical Oversight Authorized September 26, 2008

More information

Business Unit CONTINGENCY PLAN

Business Unit CONTINGENCY PLAN Contingency Plan Template Business Unit CONTINGENCY PLAN Version 1.0 (Date submitted) Submitted By: Business Unit Date Version 1.0 Page 1 1 Plan Review and Updates... 3 2 Introduction... 3 2.1 Purpose...

More information

DRAFT Disaster Recovery Policy Template

DRAFT Disaster Recovery Policy Template DRAFT Disaster Recovery Policy Template NOTE: This is a boiler plate template much information is needed from to finalizeconsider this document pre-draft FOREWARD... 3 Policy Overview...

More information

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14

More information

All-Hazard Continuity of Operations Plan. [Department/College Name] [Date]

All-Hazard Continuity of Operations Plan. [Department/College Name] [Date] d All-Hazard Continuity of Operations Plan [Department/College Name] [Date] TABLE OF CONTENTS SECTION I: INTRODUCTION... 3 Executive Summary... 3 Introduction... 3 Goal... 4 Purpose... 4 Objectives...

More information

Some companies never recover from a disaster related loss. A business that cannot operate will lose money, customers, credibility, and good will.

Some companies never recover from a disaster related loss. A business that cannot operate will lose money, customers, credibility, and good will. How Disaster Recovery Planning Can Be Leveraged For Electronic Discovery and Litigation Response Digital Discovery and e-evidence John Connell April 1. 2008 Hurricanes, floods, earthquakes, power outages,

More information

UNION COLLEGE INCIDENT RESPONSE PLAN

UNION COLLEGE INCIDENT RESPONSE PLAN UNION COLLEGE INCIDENT RESPONSE PLAN The college is committed to supporting the safety and welfare of all its students, faculty, staff and visitors. It also consists of academic, research and other facilities,

More information

A Framework to Support Healthcare Continuity of Operations in an Information Technology Failure:

A Framework to Support Healthcare Continuity of Operations in an Information Technology Failure: A Framework to Support Healthcare Continuity of Operations in an Information Technology Failure: Lessons learned from a novel exercise series Jendy Dunlop, MPH, CHEP Paul Biddinger, MD, FACEP http://001yourtranslationservice.com/computer-tips/protecting-your-computer.htm

More information

PBSi Business Continuity Planning

PBSi Business Continuity Planning Business Continuity Planning Definition Business Continuity planning is a planning process designed to reduce the risk that disruptive failures or events could seriously harm your business. It is designed

More information

Franklin County Emergency Management Department (FCEMD) All County Emergency Response Team (CERT) Agencies. Table of Contents

Franklin County Emergency Management Department (FCEMD) All County Emergency Response Team (CERT) Agencies. Table of Contents Concept of Operations Lead Agency Support Agency Standard Operating Procedures Emergency Operations Center (EOC) Franklin County Emergency Management Department (FCEMD) All County Emergency Response Team

More information

D2-02_01 Disaster Recovery in the modern EPU

D2-02_01 Disaster Recovery in the modern EPU CONSEIL INTERNATIONAL DES GRANDS RESEAUX ELECTRIQUES INTERNATIONAL COUNCIL ON LARGE ELECTRIC SYSTEMS http:d2cigre.org STUDY COMMITTEE D2 INFORMATION SYSTEMS AND TELECOMMUNICATION 2015 Colloquium October

More information

Emergency Management Program

Emergency Management Program Emergency Management Program The Emergency Management and Civil Protection Act, R.S.O. 1990,c.E.9 and its associated regulations and standards, requires all Ontario Municipalities to implement a mandatory

More information

Table of Contents... 1

Table of Contents... 1 ... 1 Chapter 1 Introduction... 4 1.1 Executive Summary... 4 1.2 Goals and Objectives... 5 1.3 Senior Management and Board of Directors Responsibilities... 5 1.4 Business Continuity Planning Processes...

More information

Emergency Preparedness Guidelines

Emergency Preparedness Guidelines DM-PH&SD-P7-TG6 رقم النموذج : I. Introduction This Guideline on supports the national platform for disaster risk reduction. It specifies requirements to enable both the public and private sector to develop

More information

Hospital Emergency Management Plan

Hospital Emergency Management Plan Hospital Emergency Management Plan Title: Purpose: Policy: Hospital Disaster Plan and Disaster Preparedness Committee General Information This policy intends to ensure that all departments are familiar

More information

DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS

DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS Appendix L DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS I. GETTING READY A. Obtain written commitment from top management of support for contingency planning objectives. B. Assemble

More information

Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP)

Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP) Preface Computer systems are the core tool of today s business and are vital to every business from the smallest to giant organizations. Money transactions, customer service are just simple examples. Despite

More information

BUSINESS CONTINUITY PLANNING GUIDELINES

BUSINESS CONTINUITY PLANNING GUIDELINES BUSINESS CONTINUITY PLANNING GUIDELINES Washington University in St. Louis The purpose of this guide is to serve as a tool to all departments, divisions, and labs across the University in building a Business

More information

Our Colorado region is offering a FREE Disaster Recovery Review promotional through June 30, 2009!

Our Colorado region is offering a FREE Disaster Recovery Review promotional through June 30, 2009! Disaster Recovery Review FREE Promotional Offer Our Colorado region is offering a FREE Disaster Recovery Review promotional through June 30, 2009! This review is designed to help the small business better

More information

WALLA WALLA COUNTY Comprehensive Emergency Management Plan

WALLA WALLA COUNTY Comprehensive Emergency Management Plan WALLA WALLA COUNTY Comprehensive Emergency Management Plan Walla Walla County CEMP EMERGENCY SUPPORT FUNCTION 12 ENERGY PRIMARY AGENCIES: Public and Private Energy and Utility Providers Walla Walla County

More information

Comprehensive Emergency Management Plan

Comprehensive Emergency Management Plan Washington State Comprehensive Emergency Management Plan - Basic Plan - June 2011 Washington State Military Department Emergency Management Division INTENTIONALLY LEFT BLANK Page ii Basic Plan June 2011

More information

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006 Department of Information Technology Data Center Disaster Recovery Audit Report Final Report September 2006 promoting efficient & effective local government Executive Summary Our audit found that a comprehensive

More information

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 AGENDA: Emergency Management Business Continuity Planning Q & A MONTH DAY, YEAR TITLE OF THE PRESENTATION 2 CANADIAN RED CROSS Disaster

More information

Table of Contents ESF-12-1 034-00-13

Table of Contents ESF-12-1 034-00-13 Table of Contents Primary Coordinating Agency... 2 Local Supporting Agencies... 2 State, Regional, and Federal Agencies and Organizations... 2 Purpose... 3 Situations and Assumptions... 4 Direction and

More information

Business Continuity Glossary

Business Continuity Glossary Developed In Conjuction with Business Continuity Glossary ACTIVATION: The implementation of business continuity capabilities, procedures, activities, and plans in response to an emergency or disaster declaration;

More information

MASON COUNTY COMPREHENSIVE EMERGENCY MANAGEMENT PLAN (CEMP)

MASON COUNTY COMPREHENSIVE EMERGENCY MANAGEMENT PLAN (CEMP) MASON COUNTY 2012 COMPREHENSIVE EMERGENCY MANAGEMENT PLAN (CEMP) Division of Emergency Management Mason County Public Works Department Updated: February 17, 2015 Adopted: November 13, 2012 TABLE OF CONTENTS

More information

Program Outline & Accreditation Application

Program Outline & Accreditation Application Program Outline & Accreditation Application The field of emergency management is emerging into higher visibility in communities throughout the nation as they are victimized by disasters that are increasing

More information

EMERGENCY MANAGEMENT BUSINESS CONTINUITY PLANNING TEMPLATE

EMERGENCY MANAGEMENT BUSINESS CONTINUITY PLANNING TEMPLATE EMERGENCY MANAGEMENT BUSINESS CONTINUITY PLANNING TEMPLATE A. BUSINESS CONTINUITY PLAN (BCP) To be better prepared, UHCL personnel and its programs may use this form to complete a Business Continuity Plan

More information

Evaluating and Improving Your Business Continuity Plan

Evaluating and Improving Your Business Continuity Plan Evaluating and Improving Your Business Continuity Plan As presented to the Northeast Florida IIA Chapter January 23, 2015 Contact Information Karen Weir, MAC, CISA, CBCP Manager kweir@accretivesolutions.com

More information

Maricopa County Emergency Management

Maricopa County Emergency Management Maricopa County Emergency Management Mission Provide community-wide education, planning, coordination, and continuity of government for the people of Maricopa County in order to protect lives, property

More information

Audit of IMS Disaster Recovery Plan

Audit of IMS Disaster Recovery Plan Audit of IMS Disaster Recovery Plan Internal Audit 378-1-615 April 29, 2009 TABLE OF CONTENTS EXECUTIVE SUMMARY...II 1.0 INTRODUCTION...5 2.0 AUDIT OBJECTIVES AND SCOPE...7 3.0 AUDIT APPROACH AND METHODOLOGY...7

More information

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS) Information Technology Disaster Recovery Policy Policy Statement This policy defines acceptable methods for disaster recovery planning, preparedness, management and mitigation of IT systems and services

More information

Table of Contents ESF-3-1 034-00-13

Table of Contents ESF-3-1 034-00-13 Table of Contents Primary Coordinating Agency... 2 Local Supporting Agencies... 2 State, Regional, and Federal Agencies and Organizations... 3 Purpose... 3 Situations and Assumptions... 4 Direction and

More information

William Rider Manager Disaster Recovery & Data Security The Johns Hopkins Health System & University

William Rider Manager Disaster Recovery & Data Security The Johns Hopkins Health System & University William Rider Manager Disaster Recovery & Data Security The Johns Hopkins Health System & University Competitive Leadership- Twelve Principles For Success Brian Billick Chapter 3 Be Be Prepared The time

More information

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745 ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan

More information

MHA Consulting. Business Continuity Management 101

MHA Consulting. Business Continuity Management 101 0 MHA Consulting Business Continuity Management 101 Presented by: Michael Herrera Brandon Magestro MHA Consulting Agenda MHA Consulting Introduction Business Continuity Management (BCM) Defined 2013 Trends

More information

Emergency Support Function 14 Long-Term Community Recovery and Mitigation

Emergency Support Function 14 Long-Term Community Recovery and Mitigation ESF Coordinator: Grant County Emergency Management Primary Agencies: Grant County Emergency Management Grant County Assessor s Office Grant County Public Works Grant County Building Department Support

More information

HOSPITALS STATUTE RULE CRITERIA. Current until changed by State Legislature or AHCA

HOSPITALS STATUTE RULE CRITERIA. Current until changed by State Legislature or AHCA HOSPITALS STATUTE RULE CRITERIA Current until changed by State Legislature or AHCA Hospitals and Ambulatory Surgical Centers Statutory Reference' 395.1055 (1)(c), Florida Statutes Rules and Enforcement.

More information

MANAGEMENT AUDIT REPORT DISASTER RECOVERY PLAN DEPARTMENT OF FINANCE AND ADMINISTRATIVE SERVICES INFORMATION TECHNOLOGY SERVICES DIVISION

MANAGEMENT AUDIT REPORT DISASTER RECOVERY PLAN DEPARTMENT OF FINANCE AND ADMINISTRATIVE SERVICES INFORMATION TECHNOLOGY SERVICES DIVISION MANAGEMENT AUDIT REPORT OF DISASTER RECOVERY PLAN DEPARTMENT OF FINANCE AND ADMINISTRATIVE SERVICES INFORMATION TECHNOLOGY SERVICES DIVISION REPORT NO. 13-101 City of Albuquerque Office of Internal Audit

More information

WHAT KINDS OF DISASTERS?

WHAT KINDS OF DISASTERS? OBJECTIVES We will discuss Natural and man-made disasters that have had public health consequences Need for future disaster planning Business continuity for health care WHAT KINDS OF DISASTERS? Man-Made

More information

Why COOP? 6 Goals of COOP. 6 Goals of COOP. General Guidelines for COOP Capability. COOP Program Model 7 Phases. Phase 1: Initiate COOP program

Why COOP? 6 Goals of COOP. 6 Goals of COOP. General Guidelines for COOP Capability. COOP Program Model 7 Phases. Phase 1: Initiate COOP program Overview What is continuity of operations (COOP) planning? Business continuity planning the all hazard approach 466 Brian Butler Columbus Public Health, Office of Emergency Preparedness 6 goals of COOP

More information

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard PUBLIC Version: 1.0 CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard (Approved by the Information Strategy and Governance Committee in December 2013; revision 1.1 approved by Chief

More information

NASCIO STATE RECOGNITION AWARDS 2015

NASCIO STATE RECOGNITION AWARDS 2015 DEPARTMENT OF TECHNOLOGY AND INFORMATION STATE OF DELAWARE 801 SILVER LAKE BLVD. DOVER, DELAWARE 19904 The Honorable James L. Collins, Chief Information Officer NASCIO STATE RECOGNITION AWARDS 2015 DELAWARE

More information

BUSINESS CONTINUITY PLANNING (BCP)

BUSINESS CONTINUITY PLANNING (BCP) BUSINESS CONTINUITY PLANNING (BCP) MASTER PLAN This BCP Master Plan is a management document explaining the methodology for assembling the BCP logistical manual, its maintenance, and how BCP is executed

More information

Audit, Finance and Legislative Committee Mayor Craig Lowe, Chair Mayor-Commissioner Pro Tem Thomas Hawkins, Member

Audit, Finance and Legislative Committee Mayor Craig Lowe, Chair Mayor-Commissioner Pro Tem Thomas Hawkins, Member City of Gainesville Inter-Office Communication April 3, 2012 TO: FROM: SUBJECT: Audit, Finance and Legislative Committee Mayor Craig Lowe, Chair Mayor-Commissioner Pro Tem Thomas Hawkins, Member Brent

More information

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP 2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level Tracy L. Hall, MBCP MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company, P.C.

More information

Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).

Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP). Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP). Ed Fortin President Fortin Consulting Paul Godden Consultant & Quotation Author Friday 24 th February 2012 Business Continuity Planning

More information

MGIC BUSINESS CONTINUITY PROGRAM

MGIC BUSINESS CONTINUITY PROGRAM MGIC BUSINESS CONTINUITY PROGRAM Mortgage Guaranty Insurance Corporation ("MGIC") and its affiliates recognize the importance of maintaining a viable business continuity strategy and have developed a comprehensive

More information

Guide to Physical Security Planning & Response

Guide to Physical Security Planning & Response Guide to Physical Security Planning & Response For Hospitals, Medical & Long Term Care Facilities Includes comprehensive section on evacuation best practices All hazards planning & response Templates Best

More information

Continuity of Operations in the Clinical Laboratory

Continuity of Operations in the Clinical Laboratory Continuity of Operations in the Clinical Laboratory Nathan Kendrick, MS, M(ASCP) State Training Coordinator Emergency Preparedness & Response Unit Paula M. (Snippes) Vagnone, MT(ASCP) Microbiology Supervisor

More information

Disaster Recovery Plan The Business Imperatives

Disaster Recovery Plan The Business Imperatives Disaster Recovery Plan The Business Imperatives Table of Contents Disaster Recovery Plan The Business Imperatives... 3 Introduction... 3 A Disaster Recovery Program The Need of the Hour... 3 Approach to

More information

What is an Exercise? Agenda. Types of Exercises. Tabletop Exercises for Executives. Defining the Tabletop Exercise. Types of Tabletop Exercises

What is an Exercise? Agenda. Types of Exercises. Tabletop Exercises for Executives. Defining the Tabletop Exercise. Types of Tabletop Exercises Tabletop Exercises for Executives Kathy Lee Patterson, CBCP, PMP Independence Blue Cross Defining the Tabletop Exercise Types of Tabletop Exercises Advantages to conducting Exercises Agenda 12 Step Approach

More information

This is the third and final presentation on HIPAA Security Administrative Safeguards. This presentation focuses on the last 2 standards under the

This is the third and final presentation on HIPAA Security Administrative Safeguards. This presentation focuses on the last 2 standards under the This is the third and final presentation on HIPAA Security Administrative Safeguards. This presentation focuses on the last 2 standards under the HIPAA Security rule: Contingency planning and evaluation.

More information

Unit Guide to Business Continuity/Resumption Planning

Unit Guide to Business Continuity/Resumption Planning Unit Guide to Business Continuity/Resumption Planning (February 2009) Revised June 2011 Executive Summary... 3 Purpose and Scope for a Unit Business Continuity Plan(BCP)... 3 Resumption Planning... 4 Assumptions

More information

Protecting your Enterprise

Protecting your Enterprise Understanding Disaster Recovery in California Protecting your Enterprise Session Overview Why do we Prepare What is? How do I analyze (measure) it? What to do with it? How do I communicate it? What does

More information

Emergency Operations California State University Los Angeles

Emergency Operations California State University Los Angeles Business Continuity Plan Emergency Operations California State University Los Angeles 1. Objective & Scope 2. Definition of Disaster 3. Risk and Business Impact Analysis Summary 4. Business Continuity

More information