Business Continuity Exercise Program (BCEP) Information Packet



Similar documents
Texas Department of Public Safety Texas Division of Emergency Management. Preparedness Standards for Emergency Management in Texas TDEM-100

Maryland Fire and Rescue Institute University of Maryland College Park

November is National Critical Infrastructure Security & Resilience Month

unified command course (MGT-314)

Tampa Bay Catastrophic Plan ANNEX L: HURRICANE PHOENIX EXERCISE

DON T MUSSEL WITH IDAHO TABLE TOP EXERCISE PLAYERS HANDBOOK

Emergency Preparedness at Nuclear Power Plants

ST. JOHNS COUNTY COMPREHENSIVE EMERGENCY MANAGEMENT PLAN APRIL Appendix E. Training Program

Cybersecurity Training

Overview Of Emergency Management Exercises

PHILADELPHIA GAS WORKS Business Continuity Plan and Consulting RFP # Questions & Answers ed April 21, 2014

Business Continuity Planning (800)

Appendix 3 Disaster Recovery Plan

Business Continuity Planning

STATE HOMELAND SECURITY GRANT PROGRAM

HSEEP Exercise Documentation

Bay Area Regional Catastrophic Planning Team Urban Shield 2013 Functional and Full Scale Exercise

Training Opportunities

The Homeland Security Exercise and Evaluation Program (HSEEP)

Recent Changes to Emergency Preparedness Mandates and Funding

Business Continuity Plan

Portal Storm: A Cyber/Business Continuity Exercise. Cyber Security Initiatives

SUPPORT ANNEX 16 TRAINING AND EXERCISES

July 2015-August 2016

The University of Southern Mississippi National Center for Spectator Sports Safety and Security. Sport Event Security Aware Designation

Homeland Security/Emergency Planning Update. IACLEA Mid-Year Conference Saturday, February 28, 2009 Georgia Tech Hotel & Conference Center

Department of Homeland Security Information Sharing Strategy

NIMS Study Guide. Lesson One: What Is the National Incident Management System (NIMS)? What is NIMS?

OCCUPATIONAL GROUP: Public Safety. CLASS FAMILY: Emergency Management CLASS FAMILY DESCRIPTION:

Final Exam for: IS-700.a: National Incident Management System (NIMS) An Introduction

Homeland Security Exercise and Evaluation Program. Volume IV: Sample Exercise Documents and Formats U.S. DEPARTMENT OF HOMELAND SECURITY

GUIDE TO DEVELOPING AND CONDUCTING BUSINESS CONTINUITY EXERCISES

SUPERVISORY AND REGULATORY GUIDELINES: PU BUSINESS CONTINUITY GUIDELINES

Security and Emergency Services Community of Interest 0089 Emergency Management Career Road Map

All Eyes: A Security Breach Exercise. Disaster Recovery/Security and Business Continuity Readiness

Homeland Security Exercise and Evaluation Program Terminology, Methodology, and Compliance Guidelines

Why Should Companies Take a Closer Look at Business Continuity Planning?

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) Fax: (718)

NIMS ICS 100.HCb. Instructions

Cornell University PREPAREDNESS PLAN

Homeland Security Exercise Evaluation Program (HSEEP) INTRODUCTION & HSEEP FUNDAMENTALS

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES

1) Introduction. Why do Organizations Conduct Exercises? Exercises are used by organizations to:

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Dust Explosion Incident Response & Coordination

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

9/3/2009. Information Systems Disaster Recovery. Learning Objectives. Why have a plan? unexpected? APPA-Institute for Facilities Management

Water Security Issues: The Federal Perspective. J. Alan Roberson, P.E. Director of Security and Regulatory Affairs AWWA Washington, DC

Prototype Curriculum for Associate Degrees in Emergency Management

External Supplier Control Requirements BCM

U.S. Department of Homeland Security Office for Domestic Preparedness 810 Seventh Street, NW. Washington, DC 20531

Business Continuity Planning: Bridging the Gap Between IT and Business

Managing a Unified Command (HMSY 2337) Online

NIMS Compliance for U.S. Hospitals

Does it state the management commitment and set out the organizational approach to managing information security?

Virginia Commonwealth University School of Medicine Information Security Standard

Why Crisis Response and Business Continuity Plans Fail

Business Continuity and Disaster Planning

NORTH CAROLINA EMERGENCY MANAGEMENT CERTIFICATION PROGRAM

National Domestic Preparedness Consortium. Preparing the Nation through Training

SECURITY-BASED TABLETOP EXERCISE

UCF Office of Emergency Management Strategic Plan

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015

EXECUTIVE CRISIS MANAGEMENT TRAINING. Presented by Roseanne Rostron, CBCP Raido Response

FINRMFS9 Facilitate Business Continuity Planning and disaster recovery for a financial services organisation

Community Disaster Recovery: A Framework Approach

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

What is an Exercise? Agenda. Types of Exercises. Tabletop Exercises for Executives. Defining the Tabletop Exercise. Types of Tabletop Exercises

Salem Community College Course Syllabus. Section I. Course Title: Principles of Emergency Management. Course Code: EME101.

Maryland Preparedness Planning Certificate Program Pilot Packet July 2014 June 2015

SCHEDULE 3.9 TO THE COMPREHENSIVE INFRASTRUCTURE AGREEMENT DISASTER RECOVERY PLAN GUIDELINES

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

EMERGENCY MANAGEMENT BUSINESS CONTINUITY PLANNING TEMPLATE

National Incident Management System (NIMS) Overview

Overview of how to test a. Business Continuity Plan

Emergency Support Function 14 Long-Term Community Recovery and Mitigation

Public Health Coalition Exercise Request for Proposal (RFP)

Business Continuity/Disaster Recovery Planning Berkeley County Chamber of Commerce 7/20/12

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP

After Action Report/Improvement Plan

BUSINESS CONTINUITY PLANNING AT THE NATIONAL GALLERY OF AUSTRALIA. Erica Persak

University of California Santa Cruz EMERGENCY RESPONSE PLAN

Emergency Management

Business Continuity and Crisis Management

City of Bellevue Emergency Management Program Strategic Plan

REQUEST FOR PROPOSALS. Business Continuity Planning Consultant Services APPENDIX C RFP STATEMENT OF WORK EXHIBITS 1-3

Appendix E: National Incident Management System (NIMS) Compliance Activities for Hospitals (public and private) 1 Organizational Adoption

CONNECTION BETWEEN RISK MANAGEMENT AND BUSINESS CONTINUITY DECEMBER 11, 2014

SFJCCAD2 Promote business continuity management

New Mexico Homeland Security and Emergency Management REQUEST TO USE FEDERAL GRANT FUNDS For Training, Conferences or Exercise Activities

Type 3 All-Hazard Incident Management System Credentialing Guide

Disaster Design: How to Develop and Conduct an Effective Tabletop Exercise

Boston College. Departmental Business Continuity Planning

How To Manage A Disruption Event

Disaster Recovery Plan Documentation for Agencies Instructions

Agenda. Creating a Robust Testing Program. Notification Tests. Overview of Testing. Beverly Schulz, CBCP

Lesson 1: What Is the National Incident Management System (NIMS)? Summary of Lesson Content

DISASTER RECOVERY FOR PUBLIC HEALTH. August 2007

NIMS National Incident Management System

Transcription:

BUSINESS CONTINUITY PLANNING Business Continuity Exercise Program (BCEP) Information Packet This exercise program was developed by the Texas Engineering Extension Service (TEEX) A Member of the Texas A&M University System

TEEX BUSINESS CONTINUITY PLANNING SOLUTIONS Given the recent lessons learned from the economic impact of hurricanes Katrina and Rita, TEEX is developing tools to decrease the impact of the next disaster on businesses. Disasters as well as the small disruptions affect your business, your customers, and your profits. According to U.S. Department of Labor Statistics, over 40% of all companies that experience a disaster never reopen and over 25% of the remaining companies close within two years. TEEX OFFERS THESE SOLUTIONS TO BUSINESSES IN TEXAS AND THROUGHOUT THE NATION Business Continuity Planning Course The Business Continuity Planning Course provides organization managers the information necessary to plan for, respond to and recover from catastrophic events. Built upon the concepts of risk analysis and business impact planning, this course is designed to provide the roadmap to organizational emergency response for the coordinated response during and after a catastrophic event in which company facilities and processes are interrupted. The 16-hour course provides the organizational managers with the critical decision making process and some key factors to be considered in the trans-, and post-event periods. Business Continuity Planning Technical Assistance The Business Continuity Planning Technical Assistance provides hands on development of the Business Continuity Plan for the requesting agency. The technical assistance commences with an on-site visit to determine the level of existing continuity planning, business processes and the scope of the organizational complexity. Through facilitated hands on development with the organizational Emergency Response Planning Team, the business continuity expert will assist in conducting a business impact assessment, risk analysis and will assist the ERT in development of the BCP for the organization. At the completion of the technical assistance the organization will have made the decisions and been equipped with the tools to manage a successful Business Continuity Program. Business Continuity Exercise Program The Business Continuity Exercise Program provides on site realistic disaster exercises to assess your continuity plan using field tested exercise and simulations incorporating Homeland Security Exercise and Evaluation Program (HSEEP) methodologies and the National Incident Management System (NIMS)/Incident Command System (ICS) principles. Planners work in a collaborative manner with your staff to fashion an exercise that achieves your goals and objectives. At the conclusion of the exercise, a formal After Action Report (AAR) and recommended Improvement Plan (IP) will be provided to the organization. 1

Exercise Objectives The Business Continuity Plan Exercise Program is designed to help prepare companies, corporations, jurisdictions or other entities to assess their continuity of operations response and recovery plans using field tested exercise and simulations developed by the National Emergency Response and Rescue Training Center (NERRTC). The exercise provides organization managers the opportunity to: 1) Test and review existing plans and procedures developed to ensure continued operations during and subsequent to a catastrophic event and 2) Provide useful information and feedback to tailor or revise these plans and procedures based on issues observed and learned as a result of the exercise. 3) Apply a format for the exercise that supports the organizations needs (e.g. tabletop, functional, or full scale as desired). The BCPEP is modeled after proven Homeland Security Exercise and Evaluation Program (HSEEP) methodologies and upon both the National Incident Management System (NIMS) and Incident Command System (ICS) principles. Exercise planners work in a collaborative manner with your staff to fashion an exercise that achieves your goals and objectives. Through an interactive tabletop, functional or complex full scale exercise, the BCPEP provides critical decision makers a rare opportunity to assess the organization s business continuity plan and implement with confidence necessary improvements identified during the exercise. The exercise focuses on the exchange of information between participants at various levels and often from a variety of agencies with strong emphasis on information acquisition, sharing, assessment and subsequent decision making. Subject matter experts (SMEs) with real world experience provide valuable assistance and feedback to the participants throughout the exercise and will aid in identification and documentation of strengths and weaknesses in the business continuity plan and decision making processes. At the conclusion of the exercise, a formal After Action Report (AAR) and recommended Improvement Plan (IP) will be provided to the organization if desired. All information obtained during the planning and exercise design and development stages, as well as the results of the exercise itself, are handled in accordance with the wishes of the organization to be exercised. Non-disclosure, trade secrets, sensitive information, proprietary data or information, and similar documents or information will be carefully and strictly handled in accordance with the guidance provided by the customer. Documents, disks, CDROMs, pictures, hard copy and any other electronic media utilized or developed will also be handled confidentially as directed and agreed. 2

Exercise Methodology/Process Phase 1 Exercise month minus 90 days Conduct Exercise Orientation Meeting Phase 2 Exercise month minus 90 to 60 days Conduct Exercise Planning Meetings Phase 3 Exercise month Conduct the Exercise Conduct After Action Reviews Phase 4 Exercise month plus 30 to 60 days Submit Post Exercise Report Exercise planners provide information on format of exercise, role of participants and controllers and facilitate development of exercise goals and objectives. Exercise planners work with company personnel to formulate relevant scenarios, timeline and scale of exercise. Simulated disaster incident with company staff working in roles they would play in actual event, facilitated by observer/controllers. Facilitated discussions during key phases of the exercise to review lessons learned, reinforce strengths in the plan/execution and identify areas of improvement. Per the customer s request, exercise planner provides a report highlighting the exercise events, training observations of facilitators and recommended improvement areas. Intended Audience The course should bring together representatives from the multiple departments that have responsibility to plan for, respond to, recover from and mitigate against any incident of such significance that the business continuity plan is implemented. The participants should include senior administrators, policy makers, decision makers, and selected management or supervisory level personnel of the business being exercised and other critical personnel identified by the business. The participants that will be invited will be at the discretion of the agency. The below listing identifies potential participants that might be selected to participate. Chief Operating Officers, Chief Executive Officers, and other Decision Makers Chief Financial Officer/Finance/Audit Internal Review Risk Management Business Continuity Legal Technology personnel, including Information Management, Network Services, etc. Human Resources/Personnel Communications Training Operations and Related Maintenance and Related 3

Quality Assurance/Control Sales/Marketing Inventory Management and Control Records Management Environmental Services Emergency Responders Facilities/Engineering Physical Security Public Information/Media Relations Customer Relations Emergency Management Contracted/supporting agencies/entities (as applicable and invited) Regulatory Agencies (as applicable and invited) Public sector agencies that might be involved in response; city, county/parish, state, and federal agency personnel who would work with the entity and aid in resolution during a business continuity incident (as applicable and invited) Like/similar entities (as applicable and invited) Other potentially involved professions or disciplines unique to the threat/risk (as applicable and invited) Resource Requirements The following items are provided by the customer for the delivery of the exercise: Classroom/facilities capable of handling sufficient tables and all exercise participants for the requested exercise format Projection screen Flip chart and/or whiteboard or chalkboard Flip chart markers and/or whiteboard markers or chalk Others The following items are provided by TEEX for delivery of the exercise: Exercise materials Facilitators to support requested exercise format Facilitation equipment 4