Building an effective Tabletop Exercise. Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services



Similar documents
Continuity Plan Testing Flowchart

How To Prepare For A Disaster

Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

Disaster Recovery. Stanley Lopez Premier Field Engineer Premier Field Engineering Southeast Asia Customer Services and Support

Fundamentals of Business Continuity Planning Have a Plan!

BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1

Certified Disaster Recovery Engineer

Business Continuity and Disaster Recovery Planning

CERTIFIED DISASTER RECOVERY ENGINEER

SCADA Business Continuity and Disaster Recovery. Presented By: William Biehl, P.E (mobile)

Business Continuity & Disaster Recovery

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

Beyond Disaster Recovery: Why Your Backup Plan Won t Work

Keys to Narrowing Business Continuity Planning Gaps: Training, Testing & Audits

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY

The handouts and presentations attached are copyright and trademark protected and provided for individual use only.

Domain 3 Business Continuity and Disaster Recovery Planning

Planning for Disaster. Ramesh Ramani CISM CGEIT 02 June 2010

Disaster Recovery and Business Continuity Plan

Child Care Emergency Preparedness Training. Participant Manual

PHILADELPHIA GAS WORKS Business Continuity Plan and Consulting RFP # Questions & Answers ed April 21, 2014

Business Continuity Plan

Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Can your Organization survive a natural disaster?

CONTINUITY OF OPERATIONS PLANNING

Business Continuity and Disaster Recovery Planning

Disaster Recovery Policy

MANAGEMENT AUDIT REPORT DISASTER RECOVERY PLAN DEPARTMENT OF FINANCE AND ADMINISTRATIVE SERVICES INFORMATION TECHNOLOGY SERVICES DIVISION

Technology Infrastructure Services

Planning for Disaster Disaster

Business Impact Analysis (BIA) and Risk Mitigation

Evaluating and Improving Your Business Continuity Plan

Overview of how to test a. Business Continuity Plan

This presentation will introduce you to the concepts and terminology related to disaster recovery planning for businesses.

Continuity of Operations in the Clinical Laboratory

INFORMATION SECURITY FOR YOUR AGENCY

Creating a Business Continuity Plan for your Health Center

Business Continuity Training and Testing: Narrowing the Gaps

Disaster Recovery and Business Continuity What Every Executive Needs to Know

What is an Exercise? Agenda. Types of Exercises. Tabletop Exercises for Executives. Defining the Tabletop Exercise. Types of Tabletop Exercises

DISASTER RECOVERY/ BUSINESS CONTINUITY AUDITING: A CASE STUDY

Unit Guide to Business Continuity/Resumption Planning

Overview Of Emergency Management Exercises

Disaster Recovery. July Specialists in IT Outsourcing and Consultancy

It also provides guidance for rapid alerting and warning to key officials and the general public of a potential or occurring emergency or disaster.

Business Continuity Management

TABLETOP EXERCISE FACILITATOR S GUIDE:

Situation Manual Orange County Florida

Western Intergovernmental Audit Forum

Why COOP? 6 Goals of COOP. 6 Goals of COOP. General Guidelines for COOP Capability. COOP Program Model 7 Phases. Phase 1: Initiate COOP program

How to write a DISASTER RECOVERY PLAN. To print to A4, print at 75%.

11 Common Disaster Planning Mistakes

Business Continuity Planning Guide

State of South Carolina Policy Guidance and Training

Proposal for Business Continuity Plan and Management Review 6 August 2008

MARQUIS DISASTER RECOVERY PLAN (DRP)

BUSINESS CONTINUITY PLAN

Week 09 Assignment 9-3. William Slater. CYBR 625 Business Continuity Planning and Recovery. Bellevue University

Expecting the Unexpected. Disaster Preparedness Strategies for Small Business

RLI PROFESSIONAL SERVICES GROUP PROFESSIONAL LEARNING EVENT PSGLE 125. When Disaster Strikes Are You Prepared?

NIST SP , Revision 1 Contingency Planning Guide for Federal Information Systems

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

New Mexico Homeland Security and Emergency Management REQUEST TO USE FEDERAL GRANT FUNDS For Training, Conferences or Exercise Activities

Saving SharePoint. Presented By: Sean McDonough Product Manager, SharePoint Products Idera

White Paper: Librestream Security Overview

ST. JOHNS COUNTY COMPREHENSIVE EMERGENCY MANAGEMENT PLAN APRIL Appendix E. Training Program

How To Plan For A Disaster

Clinic Business Continuity Plan Guidelines

The Joint Commission Approach to Evaluation of Emergency Management New Standards

Clinic Business Continuity Plan Guidelines

CONTINUITY OF OPERATION PLAN (COOP) FOR NONPROFIT HUMAN SERVICES PROVIDERS

2014 NABRICO Conference

OPTIONS FOR EDUCATION AND TRAINING...3 LEARNING RESOURCES...5 TABLE TOP EXERCISE: POWER OUTAGE SCENARIO...7

Protecting your Enterprise

Business Continuity Planning and Disaster Recovery Planning

IT DISASTER RECOVERY TRAINING PDF

Temple university. Auditing a business continuity management BCM. November, 2015

Protec'ng Informa'on Assets - Week 8 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protec/ng Informa/on Assets Greg Senko

DATA RECOVERY SOLUTIONS EXPERT DATA RECOVERY SOLUTIONS FOR ALL DATA LOSS SCENARIOS.

White Paper AN INTRODUCTION TO BUSINESS CONTINUITY PLANNING AND SOLUTIONS FOR IT AND TELECOM DECISION MAKERS. Executive Summary

Disaster Recovery Hosting Provider Selection Criteria

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Emergency Support Function #14 Long Term Community Recovery and Mitigation

Overview. Emergency Response. Crisis Management

BUSINESS CONTINUITY TABLETOP EXERCISE (TTEX) GUIDE

Transcription:

Building an effective Tabletop Exercise Presented by: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services 3/26/2013 #1

Con$nuity Plan Tes$ng Flowchart 3/26/2013 #2

Ongoing Mul$ Year Tes$ng Full Scale Exercises Orientation Tabletops Drills / Test Functional Exercises Capabilities Planning / Training Discussion Based Operations Based 3/26/2013 #3

Types of Tests 3/26/2013 #4

Defining Roles and responsibili$es Position DR/BCP Coordinator / Information Security Officer Roles and Responsibilities Coordinate schedule / Exercise facilitator Management Team Provide guidance and approval of Exercise Plan IT Manager / Network Admin Coordinate IT Recovery Plans Plan and conduct IT Tests Support BCP Coordinator in Development and exercising Participants (all employees, DR/BCP Team, Business Area Managers/SME) Member of recovery team Familiar with Plan Know assignments Perform specific business duties 3/26/2013 #5

Func$onal and Full Scale Tests IT Recovery test restore of technology, (i.e. data, network) Going offsite to a backup location tests recovery site preparedness, communications and utilities Trained and informed personnel are typically performing recovery steps Transaction testing verifies restore, connectivity and access using a person that knows the business process Community resources may be involved What verifies the completeness of the Plan? 3/26/2013 #6

Why Tabletop Exercises? Provide a forum for the following: ƒteam Building ƒvalidate the Plan Documentation Information Collection and Sharing ƒobtain consensus from team Evaluation of Differing Perspectives 3/26/2013 #7

Why Tabletop Exercises? Provide a forum for the following: ƒproblem solving of complex issues ƒtest considerations for new situations, ideas, processes and/or procedures ƒtraining/awareness for management and staff 3/26/2013 #8

Exercise Development Steps 3/26/2013 #9

Exercise Development Steps Scope: Exercise Activities Departments Involved Hazard Type of Threat Source Geographic or outage Impact Area Staff Impacted Facilities Impacted 3/26/2013 #10

Building a Scenario Exercise Development Steps Choosing a Threat to Test Threat Risk Asmt Vulnerability Threat Assessment Start with simple basic scenarios basic Fire minimal damage Note: For example tornado incidents in the Midwest increased awareness of their threat risk. The state may provide ongoing tasks of planning, preparing, and training for Tornado preparedness. 3/26/2013 #11

Building a Scenario Exercise Development Steps As your DR/BC matures make scenarios more complex Consider the unexpected Don t share the full scenario before the event Does the DR/BCP Team always know when a tabletop will occur? 3/26/2013 #12

Building a Scenario Exercise Development Steps How quickly can you pull together key Business Team Members? How quickly can all key individuals be contacted and mobilized to the alternate location? Do you test the involvement of any outside parties? (i.e. law enforcement, safety, utilities, telephone, ISP 3/26/2013 #13

Objectives of Exercise Tabletop Exercise Program Objectives To improve operational readiness by demonstrating knowledge of the DR/BCP Plan overall To improve bank wide coordination and response capabilities for effective disaster response To identify communication pathways and problem areas between IT, outside entities (utilities, media) business areas, regional and state emergency operations centers To establish timely response for safety, recovery and restore to normal operation. 3/26/2013 #14 Exercise Development Steps

Tips for an Effec$ve Tabletop Decide how much gloom and doom you want. Do you want this to be a physical event with assets damaged and destroyed, Do you just want things inaccessible? Do you want death and injuries, or just to test the ability to get work up and going someplace else? How long will your downtime duration be? 3/26/2013 #15

Conduc$ng the Exercise Set the Ground Rules Silence Cell Phones Establish timelines Maximum 4 Hours breaks, lunch etc.. Who leads the exercise? Consider issues that need to be tabled for later discussion 3/26/2013 #16

Conduc$ng the Exercise Set the Ground Rules Accept the Scenario as Real Stay in the Scenario stay in the mindset that the disaster is really occurring Who will take notes record issues / follow up Consider taping the exercise on an audio recorder 3/26/2013 #17

Exercise Evaluate Update Planned Test scheduled in advance Attendance by all BCP Team required Team is aware of test scenario Document Team Member Attendance Confirm that all Team Members have their own up to date copy of the plan The BC coordinator confirms updates are in the plan. 3/26/2013 #18

Exercise Evaluate Update Review policies and procedures Discuss business area changes since last updates? Confirm accuracy of phone numbers Verify Secure and accessible storage of plan (at home) Executive summary of the test and discussion results 3/26/2013 #19

Resources NIST SP800 84 Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities Homeland Security Exercise and Evaluation Program (HSEEP) hseep.dhs.gov, FEMA: www.ready.gov/ Michigan Emergency Partnership www.michigan.gov/msp/ 0,4643,7 123 1593_3507_8920,00.html CSOonline Business Continuity, www.csoonline.com FIPCO, www.fipco.com/itservices 3/26/2013 #20 TIP Experience has shown that well planned and interesting exercises yield a high level of preparedness with personnel who are able to better cope with the stressful environment of an actual emergency.

Sample Tabletop Exercise Testing Fire in the Server Room (a/k/a Data Center) CLICK HERE 3/26/2013 #21