(Instructor-led; 2 Days)



Similar documents
BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION

(Instructor-led; 3 Days)

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

Overview of how to test a. Business Continuity Plan

Business Continuity Planning and Disaster Recovery Planning

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

BCP and DR. P K Patel AGM, MoF

Business Continuity Plan

Protecting Your Business

BUSINESS CONTINUITY MANAGEMENT REQUIREMENTS FOR SGX MEMBERS NEW RULES FOR INCLUSION IN SGX-ST RULES

TABLE OF CONTENTS CHAPTER TITLE PAGE

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Business Continuity and Disaster Recovery Planning

Business Continuity Planning

Disaster Recovery Plan (Business Continuity) Template

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CONTENTS. List of Tables List of Figures

Plan Development Getting from Principles to Paper

Moving from BS to ISO The new international standard for business continuity management systems. Transition Guide

DRAFT Disaster Recovery Policy Template

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

BUSINESS CONTINUITY PLANNING. Business Continuity Management Plan. Version 1.4

CHAPTER 11 COMPUTER SYSTEMS INFORMATION TECHNOLOGY SERVICES CONTROLS

Business Resiliency Business Continuity Management - January 14, 2014

Temple university. Auditing a business continuity management BCM. November, 2015

INFORMATION TECHNOLOGY CONTROLS

Domain 1 The Process of Auditing Information Systems

Schneps, Leila; Colmez, Coralie. Math on Trial : How Numbers Get Used and Abused in the Courtroom. New York, NY, USA: Basic Books, p i.

PAPER-6 PART-5 OF 5 CA A.RAFEQ, FCA

Samples of Management Consulting Assignments. Performed by DCAG are. Provided in the following pages.

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1

2014 NABRICO Conference

Company Management System. Business Continuity in SIA

Appendix 6c. Final Internal Audit Report Disaster Recovery Planning. June Report 6c Page 1 of 15

Supplier Security Assessment Questionnaire

OVERVIEW. In all, this report makes recommendations in 14 areas, such as. Page iii

DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS

BUSINESS CONTINUITY MANAGEMENT IN THE PUBLIC SECTOR A ROUGH GUIDE

Business Continuity Management Policy

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) Fax: (718)

Disaster Recovery Plan (Business Continuity) Template - Version 8.2

Disaster Recovery Plan Review Checklist. A High-Level Internal Planning Tool to Assist State Agencies with Their Disaster Recovery Plans

Disaster Recovery Journal Spring World 2014

Professional Practice Six - Business Continuity Plan Development and Implementation

Chapter 3: Audit of business Continuity plan... 3 Learning Objectives Introduction Steps of BCP Process

San Francisco Chapter. Information Systems Operations

A BCP Tale: From Theory to Practice

Business Continuity Management. Policy Statement and Strategy

^H 3RD EDITION ITGOVERNANCE A MANAGER'S GUIOE TO OATA SECURITY ANO DS 7799/IS ALAN CALDER STEVE WATKINS. KOGAN PAGE London and Sterling, VA

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Tufts Health Plan Corporate Continuity Strategy

PAPER-6 PART-4 OF 5 CA A.RAFEQ, FCA

Stewart County Schools DISASTER RECOVERY PLAN. Updated February 11, 2014

DISASTER RECOVERY PLANNING

The Business of Continuity

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

Protecting your Enterprise

Sound Transit Internal Audit Report - No

Proposal for Business Continuity Plan and Management Review 6 August 2008

Policy Outsourcing and Cloud Based File Sharing

Auditing in an Automated Environment: Appendix C: Computer Operations

Domain 3 Business Continuity and Disaster Recovery Planning

Business Continuity Policy

Business Continuity. Port environment

PROFESSIONAL PRACTICES FOR BUSINESS CONTINUITY PRACTITIONERS

TUFTS HEALTH PLAN CORPORATE CONTINUITY STRATEGY FREQUENTLY ASKED QUESTIONS OVERVIEW CORPORATE CONTINUITY PROGRAM.

SECTION 15 INFORMATION TECHNOLOGY

Our Colorado region is offering a FREE Disaster Recovery Review promotional through June 30, 2009!

Overview Of The Intergrated Approach To Data Management, Security, Litigation Readiness And Ediscovery

BT Conferencing Business Continuity Management. Planning to stay in business

Business Continuity/Disaster Recovery Planning Berkeley County Chamber of Commerce 7/20/12

Overview of Business Continuity Planning Sally Meglathery Payoff

Situation Manual Orange County Florida

DRII PP Introduction to the Professional Practices Page 1

Disaster Recovery Business Continuity Premium Edition

Virginia Commonwealth University School of Medicine Information Security Standard

It s the Business! Business continuity considerations for all organisations

PART 10 COMPUTER SYSTEMS

1.0 Policy Statement / Intentions (FOIA - Open)

ITIL Introducing service design

Information security controls. Briefing for clients on Experian information security controls

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Disaster Recovery and Business Continuity Plan

Business Continuity and Risk Management. Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited

BS BUSINESS CONTINUITY MANAGEMENT

(NOTE: ALL BS7799 REFERENCES IN THIS DOCUMENT ARE FROM BS7799-2:1999 and SHOULD BE AMENDED TO REFLECT BS7799-2:2002)

Acknowledgement. First edition August 2006 Second edition July 2009 Third edition June 2015

Unit Guide to Business Continuity/Resumption Planning

Fundamentals of Business Continuity Planning Have a Plan!

BC / DR Implementation Tying Disaster Recovery Investment to Measurable Business Value

Specialist Cloud Services Lot 4 Cloud EDRM Consultancy Services

IT SERVICE MANAGEMENT POLICY MANUAL

Information Commissioner's Office

Does it state the management commitment and set out the organizational approach to managing information security?

Business Continuity Management

Introduction UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT

Disaster Recovery Planning Process

Planning for Disaster. Ramesh Ramani CISM CGEIT 02 June 2010

Protecting Your Business

Review of Information Technology s Data System Backup and Disaster Recovery Process Page 2 of 10 September 30, 2013

Transcription:

Protecting Your Revenues: A Risk Management Approach to Business Continuity Planning (Instructor-led; 2 Days)

Module I. Project Initiation and Management A. DRII/BCI Project initiation and control B. Business continuity project activities C. Business Continuity Planning Scope D. Disaster Recovery Planning Scope E. Business Continuity Awareness 1. Communication to management 2. Communication to employees, vendors, customers, investors, and other stakeholders F. Planning steering committee G. Project planning 1. Budgetary requirements 2. Reporting to senior management H. Resources provided: 1. Checklist: Project Initiation 2. Example BCP/DRP Communication Briefing 3. Example Disaster Recovery Project 4. Example Business Continuity Project: Terms and Scope 5. Example Business Continuity Plan 6. Indicative Project Deliverables and Investment 7. Action Plan Project Initiation and Management 2

Module II. Risk Evaluation and Control A. DRII/BCI Risk Evaluation and Control B. Risk Assessment 1. Business needs 2. Health and safety 3. System safety programs 4. Risk management for finance and the finance sector 5. Food industry 6. Health care 7. Other industries C. Risk Assessment Guidance and Compliance 1. Statutory requirement and duty of care 2. The U.K. Combined Code (Turnbull Report) D. Risk Assessment Process E. Risk Management Methods F. Critical Component Failure Analysis G. Operational Risk Management H. Prioritizing Risk Management I. Security and Siting Risk Areas J. Case Studies K. Resources Provided: 1. Examples Possible threats to consider 2. Example Simple Risk Analysis 3

3. Case Study The E-Bomb Threat a) Definition b) History c) Technology d) Defense 4. Case Study: Fire Hazard from Computer Tapes a) Testing environment b) The tape burn c) Explanation of computer tapes and their pyrolysis products 5. Case Study: Smoke Tests 6. Case Study: Foot and Mouth Disease Disaster 7. Checklist: Site, Environmental, Health, and Safety Risk Assessment 8. Action Plan Risk Evaluation and Control Module III. Business Impact Analysis A. DRII/BCI Business Impact Analysis B. The BIA Project 1. BIA Data collection methods 2. Critical success factors / Business process matrix 3. Key performance indicators 4. Process flows 5. Outputs and deliverables 6. Activity categorization 7. Desk review 8. Questionnaires 4

9. Interviews C. Managing and Internally Promoting the BIA Project 1. Workshops 2. Financial justification for Business Continuity Management 3. Compliance and legal requirements 4. Designing an Impact Matrix D. A Tiered Approach to Business Continuity Planning 1. Business continuity and service-level agreements E. Resources Provided: 1. Example Resource and Timescale for Provisioning 2. Example Risk and Impact Analysis 3. Example A Service-Level Agreement Using Tier Rating 4. Action Plan Business Impact Analysis Module IV. Developing Continuity Strategies A. DRII/BCI Business Continuity Strategy Development B. Vital Materials and Backup C. Business Continuity Strategy Options 1. Continuous processing 2. Distributed processing 3. Alternate sites 4. Off-site storage 5. Reciprocal Agreements 6. Option Comparison D. Contractual Arrangements for Recovery Services (Outsourcing) 5

E. Insurance F. Consultants G. Resources Provided: 1. Example A Business Continuity Strategy Project 2. Action Plan Developing Continuity Strategies Module V. Emergency Response and Operations A. DRII/BCI Emergency Response and Operations B. Types of Emergencies C. Coordination with Public Authorities D. Emergency Response Standards E. International Coordination F. Public Relations and Crisis Communication 1. Media management 2. Communication with stakeholders G. Salvage and Restoration H. Resources Provided: 1. Examples Emergency Plans 2. Emergency Response Acronyms 3. Action Plan Emergency Response Module VI. Developing and Implementing the Business Continuity Plan A. Plan Components 1. Introduction 2. Business continuity teams 6

3. Tasks, actions, and functions 4. Roles and responsibilities a) BC Management b) Operations 5. Alternative standby locations 6. Internal and external contact details 7. Vital documents and materials 8. Resource requirements 9. Reporting processes and requirements 10. Audit trail 11. Plan confidentiality, version control, and document management 12. Plan structure B. Interim Plans C. Software Tools for Plan Development D. Resources Provided: 1. Example Office Services Plan for a Professional Practice 2. Example Contents of Generic BC Plan Appendices 3. Examples Commercially Available BC Planning Software 4. Checklist: BC Planning Software 5. Action Plan Developing and Implementing the Business Continuity Plan Module VII. Training Business Continuity/Disaster Recovery Awareness and A. DRII/BCI Awareness and Training Programs B. Objectives for Establishing Awareness and Training 7

C. Identifying Functional Awareness and Training Gaps D. Developing the Best Training Methodology E. Acquiring or Developing Training Aids F. Outsourcing Training G. Identifying Vehicles for Corporate Awareness H. Resources Provided: 1. Checklist: Staff Skills Assessment Matrix 2. Example: Disaster Management Event News Resources 3. Action Plan Business Continuity/Disaster Recovery Awareness and Training Module VIII. Maintaining and Testing the Business Continuity Plan and Disaster Recovery Plan A. DRII/BCI BCP/DRP Plan Maintenance and Testing B. Business Continuity Plan Audit and Review C. Testing 1. BC Plan audit areas 1. Justification 2. Testing strategy 3. Testing methods 4. Using a structured approach to plan testing 5. Post-Test reporting D. Resources Provided: 1. Example Notes from a Test Planning Meeting 2. Example Communications Brief for Test Observers 8

3. Case Study: Setting up Testing with Initial Briefings and Situation Reports 4. Action Plan - Maintaining and Testing the Business Continuity Plan and Disaster Recovery Plan Module IX. Business Continuity/Disaster Recovery Standards and Guidelines A. Overview B. Various Governmental Standards Bodies C. BS 7799 D. ISO 17799 E. Resources Provided: 1. Example Sources for Standards and Guidelines 9