DISASTER RECOVERY/ BUSINESS CONTINUITY AUDITING: A CASE STUDY
|
|
|
- Stewart Norman
- 10 years ago
- Views:
Transcription
1 1 DISASTER RECOVERY/ BUSINESS CONTINUITY AUDITING: A CASE STUDY WAYNE PURVES DIRECTOR CHRISTA VOIE IT AUDITOR MULTICARE HEALTH SYSTEM TACOMA, WA AHIA 32 nd Annual Conference August 25-28, 2013 Chicago, Illinois
2 Learning Objectives 2 Explain Disaster Recovery (DR) and Business Continuity Process (BCP) core concepts and critical risks. Share best practices in DR and BCP auditing approaches. Discuss the unique considerations when auditing DR and BCP requirements within the healthcare industry.
3 Presenters 3 Wayne Purves, Director Corporate Compliance and Internal Audit Certifications: MBA, CIA, CISA, CFE, CHC, CRMA 20+ years experience in internal audit, regulatory compliance, risk advisory and consulting Christa Voie, IT Ad Auditor Corporate Compliance and Internal Audit Certifications: CISA, PCIP 10 years experience in internal audit, compliance, finance and accounting
4 MultiCare Health System (MHS) 4 Located in Tacoma, Washington, serving Pierce and South King County regions 5 Hospitals, 100+ Clinics with Diagnostic Imaging g Centers and Laboratory Services 9K+ employees, $1.6B Annual Revenue
5 Presentation Outline 5 Definitions Setting the Stage: Healthcare Industry Our Approach Current Environment Frameworks Scope, Objective, Audit Program Lessons Learned / Other Considerations
6 Question 6 What comes to mind when you think about disaster preparedness in the workplace?
7 What is Disaster Recovery? 7 Disaster Recovery (DR) is the process of rebuilding your operation or infrastructure after the disaster has passed. (SANS Institute)
8 What is Business Continuity? 8 Business Continuity (BC) refers to the activities required to keep your organization running during a period of displacement or interruption of normal operation. (SANS Institute) BC is the capability of the organization to continue delivery of products or services at acceptable predefined levels following a disruptive incident. (ISO 22301:2012) 2012)
9 Setting the Stage: Healthcare Industry 9 In emergencies, the community runs TO a hospital, NOT away from it! Caring for patients, visitors, employees, community Criticality for testing surge plans, simulations Practice, training, more practice, and more training! Integrated Electronic Medical Record System 24x7 operations (hospitals) vs. limited hours (clinics) Simultaneously offline limited paper records Downtime procedures = Possible lives saved!
10 Our Approach: Assess Current Environment 10 Comments from prior IT risk assessment Corporate communications Discussions with Information Services department Internal Survey
11 Our Approach: Select A Framework 11 Option: Kitchen Sink / FishNet Approach I NEED EVERYTHING I can find on the topic. Result: Overwhelmed. Forced to sift out essentials. Option: Default Approach Just use COBIT. I always use COBIT. Result: Decide v4 vs. v5, may not align with company standards or have buy-in with client. Option: Selective / Hybrid Approach Use a mix of select sources with the most authority. Result: Winning combination!
12 Our Approach: Selected Frameworks 12 Joint Commission Standards Emergency Management Chapter Information Management Chapter MHS Company Policies Technology: Disaster Recovery policy Comprehensive Emergency Management Plan (CEMP) COBIT 5 Framework DSS04 Manage Continuity
13 Audit Scope 13 Technology disaster recovery program, including planning and testing efforts for critical systems and applications. Centralized activities for managing business continuity plans, including the overall continuity strategy, development and testing of the emergency management plans, staff training, and communications.
14 Audit Objective 14 To assess whether MHS has established and tested a comprehensive business continuity and technology disaster recovery strategy. To assess whether MHS could resume critical operations in response to a declared disaster or emergency event.
15 Audit Program 15 Disaster Recovery Technology Recovery Strategy Business Impact Analysis Recovery Objectives Test Plans and Schedules Test Results and Remediation Business Continuity Continuity Strategy Continuity Plans and Procedures Communications Training
16 DR - Technology Recovery Strategy 16 Review the strategy for managing recovery of technology and systems. The process for managing g the data centers and recovering servers during an emergency. Recovery yprocesses for non-is managed systems.
17 DR - Business Impact Analysis 17 Review the Business Impact Analysis (BIA) and verify: It is current It is complete It documents risks and outcomes Update the BIA after major changes.
18 DR - Recovery Objectives 18 Review the recovery objectives and timelines for system downtime and minimizing lost data. Recovery Time Objective Maximum tolerable time limit within which the data must recovered. Recovery Point Objective Maximum tolerable data loss that is acceptable in a disaster situation.
19 DR - Test Plans and Schedules 19 Review process for scheduling and planning disaster recovery tests. Review a sample of Mission Critical systems to verify: Test plans exist Test plans are current Test plans identify responsibilities and actions
20 DR - Test Results and Remediation 20 Review a sample of Mission Critical systems to verify: Recovery testing has occurred Testing is documented Post-exercise reviews were documented, with recommendations to improve continuity identified
21 Audit Program 21 Disaster Recovery Technology Recovery Strategy Business Impact Analysis Recovery Objectives Test Plans and Schedules Test Results and Remediation Business Continuity Continuity Strategy Continuity Plans and Procedures Communications Training
22 BC - Continuity Strategy 22 Review the enterprise-wide business continuity strategy and processes including: Corporate emergency management plans Management oversight/governance Hazard vulnerability assessments (HVAs) Hospital planning for 96-hours of self-sustainment Partnership with community resources Tracking/management of emergency supplies and equipment
23 BC Continuity Plans and Procedures 23 Emergency plans in place for each hospital/facility. Current Approved by Management Coverage for offsite locations, clinics
24 BC - Continuity Plans and Procedures (cont.) 24 Review emergency operations plans and validate they: Exist Are current Define key roles, persons Outline procedures/actions to be performed Have associated test results / lessons learned Includes defined follow-up, assigned actions and owners
25 BC - Continuity Plans and Procedures (cont.) 25 Review that testing occurs twice annually for each hospital (per Joint Commission requirements). Tests include: A simulation of a surge/influx of patients The local community is unable to support the hospital Participation in a community-wide exercise
26 BC Communications 26 Review the tools and processes for managing communications during an emergency. Review processes for maintaining current contact information. Review processes during an emergency response exercise to monitor and assess the effectiveness of communications (both internal and with external entities).
27 BC Communications (cont.) 27 Notification processes in place for: Staff & personnel Patients/Families, esp. if relocating patients External authorities Media/Community Vendors/Suppliers Regional healthcare partners
28 BC Training 28 Review employee training on emergency practices. Training on emergency equipment and supplies. Managing emergency volunteers. Licensed independent practitioners
29 MHS Lessons Learned 29 Corporate Executive Buy-In / Executive Advocacy Tell a Compelling Story Mercy Hospital in Joplin, MS Associate risks and impact of issues with organization s mission (MHS: Quality Patient Care) Actual disruptions to business continuity assisted with this point Incorporate ERM Efforts to promote preparedness Ask Management: Do we want to be the hospital system that evacuates or stands firm during an emergency?
30 MHS Lessons Learned (cont.) 30 Business Impact Analysis Process managed through I.S. or within Operations? I.S. assumes priorities on behalf of Operations. Disconnect between priorities, recovery timelines What are the mission critical systems? Different answer depending on who you ask General (but undocumented) understanding of actual impact/risks to operations in the event of system downtime.
31 MHS Lessons Learned (cont.) 31 Sample Selection Even if policy states all Mission Critical systems require the same standard for continuity, try to include judgmental sampling to include major EMR system/s, not just select a random sample.
32 Other Considerations 32 Understanding Hospital Incident Command System vs. Business Continuity Client confusion on differences HICS Centralized Communication/Framework for Control BC Overall continuity activities, includes HICS Resource Plans 96 hour Self-Sustainability Rule Single resource provider and proximity plans Back-up, and back-up to the back-up
33 Resources 33 Addendum 1: MHS DR/BC Audit Program FEMA Federal Emergency Management Agency NIMS National Incident Management System State Emergency Management Department State SaeLaws Revised Code of Washington (RCWs) Local County Requirements OSHA Occupational Safety and Health Admin.
34 Resources (cont.) 34 OMB Circular A-133 Joint Commission Standards Emergency Mgmt, Info Mgmt Chapters COBIT 5 Framework DSS04 (Manage Continuity) Mercy HealthCare System (Joplin, Missouri) i) YouTube: Mercy/ROi Joplin Story The Business Continuity Institute
35 Resources (cont.) 35 SANS Institute Info Sec Reading Room White Paper: Introduction to Business Continuity Planning The Institute of Internal Auditors Global Technology Audit Guide GTAG #10 Business Continuity Management
36 Questions? 36 Thank you! Wayne Purves (253) Christa Voie (253)
37 Save the Date September 21-24, rd Annual Conference Austin, Texas 37
B.1 DISASTER RECOVERY
B.1 DISASTER RECOVERY Technology Recovery Strategy (20 hours) To confirm that MHS has developed an overall strategy to Standard: EM.02.01.01 - The hospital has an Emergency Operations Plan. (EP#4) manage
Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010
Business Continuity and Emergency Preparedness Planning Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010 Overview Define key terms and list essential elements of business continuity
Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain
1. What is the most common planned performance duration for a continuity of operations plan (COOP)? A. 30 days B. 60 days C. 90 days D. It depends on the severity of a disaster. 2. What is the business
Business Continuity and Disaster Recovery Planning
Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services
How To Prepare For A Disaster
Building an effective Tabletop Exercise Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 3/26/2013 #1 Continuity Plan Testing Flowchart 3/26/2013 #2 1 Ongoing Multi-Year
State of South Carolina Policy Guidance and Training
State of South Carolina Policy Guidance and Training Policy Workshop All Agencies Business Continuity Management Policy June 2014 Agenda Questions & Follow-Up Policy Workshop Overview & Timeline Policy
IT GOVERNANCE PANEL BRING VALUE BY AUDITING IT GOVERNANCE GET THE
1 IT GOVERNANCE PANEL BRING VALUE BY AUDITING IT GOVERNANCE GET THE ANSWERS AND PRACTICAL TIPS FROM THE IT GOVERNANCE AUDIT PROFESSIONALS JOHAN LIDROS, PRESIDENT EMINERE GROUP KATE MULLIN, CISO, HEALTH
OFFICE OF AUDITS & ADVISORY SERVICES IT DISASTER RECOVERY AUDIT FINAL REPORT
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES IT DISASTER RECOVERY AUDIT FINAL REPORT Chief of Audits: Juan R. Perez Audit Manager: Lynne Prizzia, CISA, CRISC Senior Auditor:
Proposal for Business Continuity Plan and Management Review 6 August 2008
Proposal for Business Continuity Plan and Management Review 6 August 2008 2008/8/6 Contents About Newton IT / Quality of our services. BCM & BS25999 Overview 2. BCM Development in line with BS25999 3.
MHA Consulting. Business Continuity Management 101
0 MHA Consulting Business Continuity Management 101 Presented by: Michael Herrera Brandon Magestro MHA Consulting Agenda MHA Consulting Introduction Business Continuity Management (BCM) Defined 2013 Trends
Internal Audit Department NeighborWorks America. Audit Review of the Business Continuity Plan (BCP) Management and Documentation
Department NeighborWorks America Audit Review of the Business Continuity Plan (BCP) and Documentation Project Number: ADMN.BCP.2013 Audit Review of of BCP Table of Contents Project Completion Letter...
Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745
ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan
CISM Certified Information Security Manager
CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective
Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC
Assessing Your Disaster Recovery Plans Gregory H. Soule, CPA, CISA, CISSP, CFE Andrews Hooper Pavlik PLC Andrews Hooper Pavlik PLC Agenda Business Continuity Concepts Impact Analysis Risk Assessment Risk
Business Continuity Management
Business Continuity Management cliftonlarsonallen.com Introductions Brian Pye CliftonLarsonAllen Senior Manager Business Risk Services group 15 years of experience with Business Continuity Megan Moore
Western Intergovernmental Audit Forum
Western Intergovernmental Audit Forum Business Continuity & Disaster Recovery Planning September 12, 2013 Presented by: City of Phoenix City Auditor Department Aaron Cook, Sr Internal Auditor IT Audit
CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT
CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT April 16, 2014 INTRODUCTION Purpose The purpose of the audit is to give assurance that the development of the Metropolitan Council s Continuity
Hospital Emergency Operations Plan
Hospital Emergency Operations Plan I-1 Emergency Management Plan I PURPOSE The mission of University Hospital of Brooklyn (UHB) is to improve the health of the people of Kings County by providing cost-effective,
SAMPLE IT CONTINGENCY PLAN FORMAT
SAMPLE IT CONTINGENCY PLAN FORMAT This sample format provides a template for preparing an information technology (IT) contingency plan. The template is intended to be used as a guide, and the Contingency
Business continuity management policy
Business continuity management policy health.wa.gov.au Effective: XXX Title: Business continuity management policy 1. Purpose All public sector bodies are required to establish, maintain and review business
DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES
APPENDIX 1 DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES March 2008 Auditor General s Office Jeffrey Griffiths, C.A., C.F.E. Auditor General City of Toronto TABLE OF CONTENTS EXECUTIVE SUMMARY...1
AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1
AUDITING A BCP PLAN Thomas Bronack Auditing a BCP Plan presentation Page: 1 What are the Objectives of a Good BCP Plan Protect employees Restore critical business processes or functions to minimize the
Temple university. Auditing a business continuity management BCM. November, 2015
Temple university Auditing a business continuity management BCM November, 2015 Auditing BCM Agenda 1. Introduction 2. Definitions 3. Standards 4. BCM key elements IT Governance class - IT audit program
SCADA Business Continuity and Disaster Recovery. Presented By: William Biehl, P.E. 913-601-0104 (mobile) [email protected]
SCADA Business Continuity and Disaster Recovery Presented By: William Biehl, P.E. 913-601-0104 (mobile) [email protected] Business Continuity Planning, a Sound Process A Business Continuity Plan: "A
Beyond Disaster Recovery: Why Your Backup Plan Won t Work
Beyond Disaster Recovery: Why Your Backup Plan Won t Work Contents Introduction... 3 The Data Backup Model - Upgraded for 2015... 4 Why Disaster Recovery Isn t Enough... 5 Business Consequences with DR-Only
KEYS TO AN EFFECTIVE DIRECTOR CORPORATE COMPLIANCE AND INTERNAL AUDIT MULTICARE HEALTH SYSTEM TACOMA, WA
KEYS TO AN EFFECTIVE ANTI-FRAUD PROGRAM WAYNE PURVES DIRECTOR CORPORATE COMPLIANCE AND INTERNAL AUDIT MULTICARE HEALTH SYSTEM TACOMA, WA AHIA 32 nd Annual Conference August 25-28, 2013 Chicago, Illinois
The Role of Internal Audit In Business Continuity Planning
The Role of Internal Audit In Business Continuity Planning Dan Bailey, MBCP Page 0 Introduction Dan Bailey, MBCP Senior Manager Protiviti Inc. [email protected] Actively involved in the Information
Continuity Plan Testing Flowchart
Building an effective Tabletop Exercise Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services Continuity Plan Testing Flowchart 1 Ongoing Multi-Year Testing Full Scale Exercises
Business Continuity Planning: Bridging the Gap Between IT and Business
Business Continuity Planning: Bridging the Gap Between IT and Business Steve Burns, President EverGreen Data Continuity, Inc. [email protected] 1 The Hard Facts One-third of businesses don t include
Domain 3 Business Continuity and Disaster Recovery Planning
Domain 3 Business Continuity and Disaster Recovery Planning Steps (ISC) 2 steps [Har10] Project initiation Business Impact Analysis (BIA) Recovery strategy Plan design and development Implementation Testing
COMPUTER OPERATIONS - BACKUP AND RESTORATION
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES COMPUTER OPERATIONS - BACKUP AND RESTORATION FINAL AUDIT REPORT Chief of Audits: Julie Nieminski, CPA, CIA, CFE, CISA, MPA
Business Continuity Management Emerging Trends
Business Continuity Management Emerging Trends Presentation Title Goes Here Samir Shah CA, CISA, DISA, CIA, CISSP, CFE, ISO 22301 LI Associate Director Axis Risk Consulting March 2013 Outline 2 1. Business
The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)
Information Technology Disaster Recovery Policy Policy Statement This policy defines acceptable methods for disaster recovery planning, preparedness, management and mitigation of IT systems and services
How to Plan for Disaster Recovery and Business Continuity
A TAMP Systems White Paper TAMP Systems 1-516-623-2038 www.drsbytamp.com How to Plan for Disaster Recovery and Business Continuity By Tom Abruzzo, President and CEO Contents Introduction 1 Definitions
Building an effective Tabletop Exercise. Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services
Building an effective Tabletop Exercise Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 3/26/2013 #1 Con$nuity Plan Tes$ng Flowchart 3/26/2013 #2 Ongoing Mul$ Year Tes$ng
Why Should Companies Take a Closer Look at Business Continuity Planning?
whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters
Regulatory Requirements for Disaster Recovery/Business Continuity Programs
Regulatory Requirements for Disaster Recovery/Business Continuity Programs Al Berman Business Continuity Planning Practice Post 9/11 Surge in Business Continuity Regulations and Standards Post 9-11 20
Creating a Business Continuity Plan. What We ll Cover... What is a BCP? Micky Hogue, CRM
Creating a Business Continuity Plan Micky Hogue, CRM Sandia National Laboratories Albuquerque, NM 505-844-6640 [email protected] What We ll Cover... What is a Business Continuity Plan Why create a BCP?
STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015
STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 AGENDA: Emergency Management Business Continuity Planning Q & A MONTH DAY, YEAR TITLE OF THE PRESENTATION 2 CANADIAN RED CROSS Disaster
Business Impact Analysis (BIA) and Risk Mitigation
Texas Emergency Management Conference 2015 Business Impact Analysis (BIA) and Risk Mitigation Alan Sowell, COOP Unit Supervisor Paul Morado, COOP Unit Planner BIA Implementation Process BIA Private Sector
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP). Ed Fortin President Fortin Consulting Paul Godden Consultant & Quotation Author Friday 24 th February 2012 Business Continuity Planning
CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT
CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14
Situation Manual Orange County Florida
Situation Manual Orange County Florida 530 Minutes Situation Manual Tabletop Exercise 1 Disaster Resistant Communities Group www.drc-group.com Comeback Ordeal Start Exercise During the exercise it will
Integrated Risk Management. Balancing Risk and Budget
Integrated Risk Management The Current Risk Landscape Organizations which depend upon information systems are challenged by serious threats that can exploit both known and unknown vulnerabilities in systems.
MANAGEMENT AUDIT REPORT DISASTER RECOVERY PLAN DEPARTMENT OF FINANCE AND ADMINISTRATIVE SERVICES INFORMATION TECHNOLOGY SERVICES DIVISION
MANAGEMENT AUDIT REPORT OF DISASTER RECOVERY PLAN DEPARTMENT OF FINANCE AND ADMINISTRATIVE SERVICES INFORMATION TECHNOLOGY SERVICES DIVISION REPORT NO. 13-101 City of Albuquerque Office of Internal Audit
FINRMFS9 Facilitate Business Continuity Planning and disaster recovery for a financial services organisation
Facilitate Business Continuity Planning and disaster recovery for a Overview This unit is suitable for those working in risk management roles who have responsibility for facilitating business continuity
Business Continuity (Policy & Procedure)
Business Continuity (Policy & Procedure) Publication Scheme Y/N Can be published on Force Website Department of Origin Force Operations Policy Holder Ch Supt Head of Force Ops Author Business Continuity
BCP and DR. P K Patel AGM, MoF
BCP and DR P K Patel AGM, MoF Key difference between BS 25999 and ISO 22301 ISO 22301 puts a much greater emphasis on setting the objectives, monitoring performance and metrics aligning BC to top management
Integrated Healthcare, Hospital and Medical Contingency Planning
Integrated Healthcare, Hospital and Medical Contingency Planning James Paturas, CEM, EMTP, CBCP, FACCP Deputy Director, Clinical Services, Yale New Haven Center for Emergency Preparedness and Disaster
AUDIT LOGGING/LOG MANAGEMENT
1 AUDIT LOGGING/LOG MANAGEMENT KATHLEEN A MULLIN, MBA, CIA, CISA, CISSP, ISA, CISM, CRISC, CGEIT DIRECTOR OF IT SECURITY/CISO HEALTHPLAN SERVICES (HPS) AHIA 31 st Annual Conference August 26-29, 2012 Philadelphia
Plan Development Getting from Principles to Paper
Plan Development Getting from Principles to Paper March 22, 2015 Table of Contents / Agenda Goals of the workshop Overview of relevant standards Industry standards Government regulations Company standards
Mecklenburg County Department of Internal Audit. PeopleSoft Application Security Audit Report 1452
Mecklenburg County Department of Internal Audit PeopleSoft Application Security Audit Report 1452 February 9, 2015 Internal Audit s Mission Through open communication, professionalism, expertise and trust,
Business Continuity Plan
Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions
An Overview of Professional Directors and Officers Liability in Disaster Preparedness and Recovery Planning
An Overview of Professional Directors and Officers Liability in Disaster Preparedness and Recovery Planning Eric Martin Scott Southern University Law Center Preparation for disasters involves a variety
Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: [email protected] Fax: (718) 380-7322
Business Continuity and Disaster Recovery Job Descriptions Table of Contents Business Continuity Services Organization Chart... 2 Director Business Continuity Services Group... 3 Manager of Business Recovery
2014 NABRICO Conference
Business Continuity Planning 2014 NABRICO Conference September 19, 2014 6 CityPlace Drive, Suite 900 St. Louis, Missouri 63141 314.983.1200 1520 S. Fifth Street, Suite 309 St. Charles, Missouri 63303 636.255.3000
Disaster Recovery Plan (Business Continuity) Template
Brochure More information from http://www.researchandmarkets.com/reports/2786932/ Disaster Recovery Plan (Business Continuity) Template Description: The Disaster Planning Template is over 200 pages and
Disaster Recovery and Business Continuity Plan
Disaster Recovery and Business Continuity Plan Table of Contents 1. Introduction... 3 2. Objectives... 3 3. Risks... 3 4. Steps of Disaster Recovery Plan formulation... 3 5. Audit Procedure.... 5 Appendix
Mazzone & Associates, Inc.
Mazzone & Associates, Inc. Business Continuity Plan (BCP) Introduction. As a result of our ever-changing and evolving world, it has become necessary for firms in the financial services industry to take
The Joint Commission s 2012 Emergency Management Standards and HRSA Health Center Emergency Management Program Expectations. NACHC Webex Training
The Joint Commission s 2012 Emergency Management Standards and HRSA Health Center Emergency Management Program Expectations NACHC Webex Training February 2, 2012 Presented by: Virginia McCollum, MSN, RN
Business Continuity Management
Business Continuity Management Version 1 approved by SMG December 2013 Business Continuity Policy Version 1 1 of 9 Business Continuity Management Summary description: This document provides the rationale
Business Continuity Management Policy
Business Continuity Management Policy Business Continuity Policy Version 1.0 1 Version control Version Date Changes Author 0.1 April 13 1 st draft PH 0.2 June 13 Amendments in line with guidance PH 0.3
Evaluating and Improving Your Business Continuity Plan
Evaluating and Improving Your Business Continuity Plan As presented to the Northeast Florida IIA Chapter January 23, 2015 Contact Information Karen Weir, MAC, CISA, CBCP Manager [email protected]
Business Continuity Planning Preparing Your Organization
Business Continuity Planning Preparing Your Organization Nicholas De Laurentis, CRM, IGP [email protected] 1 Objectives Understand the importance of Business Continuity Planning Know
Fundamentals of Business Continuity Planning Have a Plan!
Fundamentals of Business Continuity Planning Have a Plan! Michael Kadar, MBCP, CISSP 2008 MK Continuity & Availability LLC [email protected] InfraGard Meeting Walsh College, Novi March 25, 2008
Measuring Continuity Planning Program. Performance
Measuring Continuity Planning Program Performance Carl B Jackson Director Crisis Management & Continuity Planning Resource Center (CMCPRC) Measuring Continuity Planning Program Performance Session Agenda
Staying In Business. A Business Continuity White Paper by. Paul O Brien and Gerard Joyce. LinkResQ Limited
Staying In Business A Business Continuity White Paper by Paul O Brien and Gerard Joyce LinkResQ Limited Contents: Introduction. 2 What is Business Continuity? 2 Loss Events = Opportunities for Disaster..
Department of Public Utilities Customer Information System (BANNER)
REPORT # 2010-06 AUDIT of the Customer Information System (BANNER) January 2010 TABLE OF CONTENTS Executive Summary..... i Comprehensive List of Recommendations. iii Introduction, Objective, Methodology
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page
ShakeOut Exercise Manual For Hospitals
Are You Ready to ShakeOut? Major earthquakes can cause unprecedented catastrophes. With earthquakes as an inevitable part of our future, hospitals should make plans and take actions to ensure that disasters
Essential Components of Emergency Management Plans at Community Health Centers Crosswalk of Plan Elements
Plan Components Health centers will have an emergency management plan Plan and organization are NIMS compliant Bureau of Primary Health Care Policy Information Notice 2007-15 Plans and procedures for emergency
Business Continuity in Healthcare
Business Continuity in Healthcare Cynthia Simeone, CBCP, PMP Director Business Resilience Catholic Health Initiatives Scott Ream President Virtual Corporation 1 Session Speakers Cynthia Simeone, CBCP,
NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems
NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems Marianne Swanson NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY 1 Table Of Contents Introduction to NIST SP 800-34
Contingency Planning and Disaster Recovery for BOMA
Contingency Planning and Disaster Recovery for BOMA Steve Elliot President & CEO Elliot Consulting Hazards & Vulnerabilities Continuity of Business Operations Normal Business Processes SALES MANUFACTURING
EMERGENCY PREPAREDNESS PLAN Business Continuity Plan
EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic
Chatham County Disaster Recovery Plan Recovery Planning Update. Mark Misczak, Brock Long, & Corey Reynolds Hagerty Consulting April 7, 2015
Chatham County Disaster Recovery Plan Recovery Planning Update Mark Misczak, Brock Long, & Corey Reynolds Hagerty Consulting April 7, 2015 Welcome Introduction to Recovery Planning Recovery Planning Process
Unit Guide to Business Continuity/Resumption Planning
Unit Guide to Business Continuity/Resumption Planning (February 2009) Revised June 2011 Executive Summary... 3 Purpose and Scope for a Unit Business Continuity Plan(BCP)... 3 Resumption Planning... 4 Assumptions
Disaster Recovery, Business Continuity, and Hosting Solutions for IFS Applications IFS CUSTOMER SUMMIT 2011, CHICAGO
Disaster Recovery, Business Continuity, and Hosting Solutions for IFS Applications IFS CUSTOMER SUMMIT 2011, CHICAGO Richard Francart DIRECTOR INFORMATION TECHNOLOGY SYSTEMS & SERVICES [email protected]
Business Continuity. Port environment
Business Continuity Port environment DEFINE BUSINESS CONTINUITY WHAT IT IS NOT RECOVERY FOCUS: PEOPLE PROCESSES TECHNOLOGY DELIVERABLES INFRAGARD DEFINITION MANAGEMENT PROCESS DEVELOPING ADVANCE PROCEDURES
Update from the Business Continuity Working Group
18 June 2015 Performance and Resources Board 14 To note Update from the Business Continuity Working Group Issue 1 The Business Continuity Working Group oversees the development, maintenance and improvement
By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd
BS 25999 Business Continuity Management By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd 1 Contents slide BSI British Standards 2006 BS 25999(Business Continuity) 2002 BS 15000
Business Continuity Policy and Business Continuity Management System
Business Continuity Policy and Business Continuity Management System Summary: This policy sets out the structure for ensuring that the PCT has effective Business Continuity Plans in place in order to maintain
Audit of the Disaster Recovery Plan
Audit of the Disaster Recovery Plan Report # 11-05 Prepared by Office of Inspector General J. Timothy Beirnes, CPA, Inspector General Kit Robbins, CISA, CISM, CRISC, Lead Information Systems Auditor TABLE
