Introduction to Business Continuity Planning



Similar documents
Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

Temple university. Auditing a business continuity management BCM. November, 2015

Business Continuity Plan

EPRR: Toolkit Facilitator Guide

Business Continuity Planning. Presentation and. Direction

Business Continuity Planning (800)

Business Continuity Management

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1

Business Continuity Planning. Description and Framework. White Paper. Preface. Contents

Business continuity plan

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

Business Resiliency Business Continuity Management - January 14, 2014

Fundamentals of Business Continuity Planning Have a Plan!

BUSINESS IMPACT ANALYSIS.5

Meeting FFIEC Requirements: Enterprise-Wide Testing of Your. Business Continuity Plan

Business Continuity Planning from the municipal perspective

The PNC Financial Services Group, Inc. Business Continuity Program

BUSINESS CONTINUITY PLAN

A BCP Tale: From Theory to Practice

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

Evaluating and Improving Your Business Continuity Plan

National Fire Protection Association s Contribution to Business Continuity Strategies

University of Glasgow. Policy for. Business Continuity Management

(Mr. Krirk Vanikkul) Assistant Governor, Financial Institutions Policy Group Governor For

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Policy : Enterprise Risk Management Policy

The Business Continuity Maturity Continuum

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Three

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Plan Development Getting from Principles to Paper

chapter 9 conduct a climate change

External Supplier Control Requirements BCM

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) Fax: (718)

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

Principles for BCM requirements for the Dutch financial sector and its providers.

Guideline - Business Continuity Plan

#316 The Security Elements of Business Continuity & Disaster Recovery Plans

Creating a Business Continuity Plan for your Health Center

CRISC Glossary. Scope Note: Risk: Can also refer to the verification of the correctness of a piece of data

Introduction to Business Continuity Planning. PCDC Introduction. Objectives. MPCA Series on Business Continuity Planning

MHA Consulting. Business Continuity Management 101

1.0 Policy Statement / Intentions (FOIA - Open)

Application / Hardware - Business Impact Analysis Template. MARC Configuration Requirements. Business Impact Analysis

This presentation will introduce you to the concepts and terminology related to disaster recovery planning for businesses.

CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Statement of Guidance

Bus incident management planning: Guidelines

The PNC Financial Services Group, Inc. Business Continuity Program

Measuring Continuity Planning Program. Performance

Chapter 1: An Overview of Emergency Preparedness and Business Continuity

BUSINESS CONTINUITY PLANNING GUIDELINES

Desktop Scenario Self Assessment Exercise Page 1

Chapter I: Fundamentals of Business Continuity Management

Good Security. Good Business

PBSi Business Continuity Planning

Business Continuity Template

BUSINESS CONTINUITY PLANNING

Business Continuity. Port environment

Your Guide to Developing a Disaster Recovery Plan

Overview of how to test a. Business Continuity Plan

Business Continuity Planning Guide

D2-02_01 Disaster Recovery in the modern EPU

Keys to Narrowing Business Continuity Planning Gaps: Training, Testing & Audits

Coping with a major business disruption. Some practical advice

Business Continuity & Disaster Recovery

Business Continuity and Risk Management. Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited

RSA ARCHER BUSINESS CONTINUITY MANAGEMENT AND OPERATIONS Solution Brief

An Introduction to. Business Continuity Planning

BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Business Continuity and Disaster Planning

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS

Business Continuity Planning. Donna Curran, Director Audit and Risk Management February, 2014

November 2007 Recommendations for Business Continuity Management (BCM)

Situation Manual Orange County Florida

Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

Building a Business Impact Analysis (BIA) Process

International Diploma in Risk Management Syllabus

Company Management System. Business Continuity in SIA

Prudential Practice Guide

Proposal for Business Continuity Plan and Management Review 6 August 2008

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY

Business Continuity Management

BUSINESS CONTINUITY PLANNING. Business Continuity Management Plan. Version 1.4

Business Continuity Planning Instructions

Subject Area 1 Project Initiation and Management

Preparing for the Convergence of Risk Management & Business Continuity

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO AUDITS, CERTIFICATION AND TRAINING

Transcription:

Introduction to Business Continuity Planning

Business Continuity Management Ensure continuity and survival of our organization in the event of an emergency event: Essential elements: Risk identification and prevention/mitigation before an emergency occurs Preparing to respond to an emergency Preparing to recover from an emergency 2

Why Have a Business Continuity Plan (BCP)? Safeguard human life Minimize confusion and enable effective decision-making during a time of crisis Reduce dependency on certain staff for critical operations Minimize loss of data and assets Facilitate timely recovery Ensure continued regulatory compliance Retain public confidence 3

BCP Success Must be an ongoing, living program that consists of several interdependent and reiterative projects Dependent on executive support Participation of all employees Core competency of organization Ongoing funding 4

Basic Steps 1. Develop team and project plan 2. Assess and reduce risks (HIRA hazard identification and risk assessment)) 3. Assess the business impact (BIA business impact analysis)) 4. Prioritize critical functions 5. Develop strategies to deliver critical functions 6. Establish Teams & Tasks 7. Write the plan 8. Train and exercise 9. Review and revise 5

Step 1: Develop Project Team and Project Plan Select overall project manager/lead Functional leads (core service programs, information technology, finance, human resources) Reporting structure Scope of plan Key deliverables Timelines 6

Step 2: Hazard Identification and Risk Assessment (HIRA) Develop organizational hazards (NFPA 1600 standard a good guide) Develop magnitude of consequences Develop scale of likelihood Create matrix: Risk = Consequence x Likelihood 7

HIRA Terminology Hazard: The danger inherent in an activity that is otherwise deemed beneficial, combined with an undesirable event. Likelihood: Chance of whether or not the undesirable event will occur. Consequence: Impact of the undesirable event. 8

HIRA Matrix High Risk Medium Risk Low Risk L I K E L I H O O D L4 4 8 12 16 L3 3 6 9 12 L2 2 4 6 8 L1 1 2 3 4 X C1 C2 C3 C4 CONSEQUENCE 9

Step 3: Business Impact Assessment (BIA) To communicate the inherent vulnerabilities of the business units, business processes and systems that comprise an organization Identify critical business functions and workflow Identify interdependencies Determine qualitative and quantitative impacts of a disruption Prioritize and establish recovery time objectives (RTOs) 10

SAMPLE BIA Activity Delivered By Provided To Dependencies Snow plowing of County Roads Ambulance Services Snowplow drivers Paramedics County residents County residents Fuel Vehicle Maint. Trained staff Dispatch Trained supr. Fuel Vehicle Maint. Roads Maint. Ambulance Supplies Minimum Functionality RTO < 4 hours <24 hours < 1 week <30 days 10 Snowplows < 4 hours 14 Ambulances < 4 hours 11

Step 4: Prioritize Critical Functions Sort functions across organization by RTO Prioritize within common RTOs 12

Step 5: Develop RTO Strategies Once you have prioritized functions, determine how you can achieve desired RTO E.g. can staff performing less critical functions be redeployed? If so, what cross-training needs to take place? 13

Step 6: Establish Teams and Tasks Emergency Response Team first aid, CPR, fire suppression, security, evacuation Damage Assessment Team IT, facilities, insurance adjusters Functional Response Teams staff designated to deliver critical functions Crisis Communication Team internal and external Functional Recovery Teams leading return to normal operations 14

The Rest is Easier! Step 7: Write the plan Present HIRA and BIA in a cogent format for executive decision-makers Step 8: Train and Exercise Make BCP a part of staff orientation and exercise annually Step 9: Review and Revise the plan annually 15