RBC Business Continuity Management Program Exercising our Plans. BCAW Presentation



Similar documents
The PNC Financial Services Group, Inc. Business Continuity Program

Business Continuity and Disaster Recovery Planning

External Supplier Control Requirements BCM

Global Statement of Business Continuity

Business Continuity for the New Professional. Britt Corra Enterprise BCM Erika Voss Senior BCM

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity

BT Conferencing Business Continuity Management. Planning to stay in business

The PNC Financial Services Group, Inc. Business Continuity Program

EMC GLOBAL DATA PROTECTION INDEX KEY FINDINGS & RESULTS FOR ITALY

Table of Contents... 1

Guideline on Business Continuity Management

How To Manage A Business Continuity Strategy

Business Continuity Planning for Risk Reduction

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Business Continuity Management AIRM Presentation

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

EMC GLOBAL DATA PROTECTION INDEX GLOBAL KEY RESULTS & FINDINGS

Disaster Recovery Planning. By Janet Coggins

How To Ensure That Non-Peoplesoft Applications Can Withstand Adverse Events

Keys to Narrowing Business Continuity Planning Gaps: Training, Testing & Audits

DATA RECOVERY SOLUTIONS EXPERT DATA RECOVERY SOLUTIONS FOR ALL DATA LOSS SCENARIOS.

MHA Consulting. Business Continuity Management 101

THE DOMESTIC SURVEY AND THE CONSEQUENT RECOMMENDATIONS

EMC GLOBAL DATA PROTECTION INDEX KEY FINDINGS & RESULTS FOR SINGAPORE

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

Enterprise Risk Services. Aware vs. committed where do you stand? Business continuity management

Advanced High. Architecture.

Tips and techniques a typical audit programme

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY

Business Continuity Plan

a Disaster Recovery Plan

Business Continuity Training and Testing: Narrowing the Gaps

Incident Management Team The Eight Step Implementation Model. The 8 Step

Professional Practice Eight - Business Continuity Plan Exercise, Audit, and Maintenance

RISK AND COMPLIANCE COMMITTEE CHARTER

GUIDELINES FOR BUSINESS CONTINUITY IN WHOLESALE MARKETS AND SUPPORT SYSTEMS MARKET SUPERVISION OFFICE. October 2004

The State Of Business Continuity Preparedness

Domain 3 Business Continuity and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

THE BUSINESS CASE FOR BUSINESS CONTINUITY MANAGEMENT SOFTWARE

BME CLEARING s Business Continuity Policy

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015

Business Continuity at CME Group

IT Service Continuity Management PinkVERIFY

Overview TECHIS Manage information security business resilience activities

AVANTGARD Hosting and Managed Services

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

The Pitfalls of DIY Approaches to Disaster Recovery

How To Manage A Disruption Event

NHS 24 - Business Continuity Strategy

Disaster Recovery Policy

Sample risk committee charter

Business Continuity and Risk Management. Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard

Proposal for Business Continuity Plan and Management Review 6 August 2008

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

VERITAS Volume Replicator in an Oracle Environment

Coping with a major business disruption. Some practical advice

Business Continuity Planning

CYBERSECURITY IN FINANCIAL SERVICES POINT OF VIEW CHALLENGE 1 REGULATORY COMPLIANCE ACROSS GEOGRAPHIES

Reducing Risk of Data Loss and System Downtime

(Mr. Krirk Vanikkul) Assistant Governor, Financial Institutions Policy Group Governor For

MarketAxess Business Continuity Plan Disclosure

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP

Advisory Guidelines of the Financial Supervision Authority. Requirements for Organising the Business Continuity Process of Supervised Entities

Supervisory Policy Manual

> State Street. Corporate Continuity Program. Continuity Organizational Structure. Program Oversight

ISSUES PAPER PAYMENT SYSTEMS BUSINESS CONTINUITY

Flinders University IT Disaster Recovery Framework

Desktop Scenario Self Assessment Exercise Page 1

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Testimony of. Edward L. Yingling. On Behalf of the AMERICAN BANKERS ASSOCIATION. Before the. Subcommittee on Oversight and Investigations.

Business Continuity Planning (800)

MEMORANDUM. Date: October 28, Federally Regulated Financial Institutions. Subject: Cyber Security Self-Assessment Guidance

Statement of Guidance

INFOSEC.MY KNOWLEDGE SHARING SESSION

Cybersecurity The role of Internal Audit

Business Continuity and Crisis Management. Interactive workshop on the application of best practice (and more)

The Business of Continuity

Audit & Inspection Management. Enterprise Cloud Audit & Inspection Management Solution

How To Back Up A Virtual Machine

BlueBay Asset Management LLP Environmental, Social and Governance (ESG) Investment Risk Policy

Business Continuity Management Framework

How To Understand The State Of Business Continuity Preparedness

NAVIGATING THROUGH A CATASTROPHIC DISASTER:

ASX CLEAR (FUTURES) OPERATING RULES Guidance Note 10

Advisory Guidelines of the Financial Supervisory Authority. Requirements regarding the arrangement of operational risk management

BUSINESS CONTINUITY PLAN. Specific Issues for Public Health Emergencies. Guidelines for Air Carriers

WorldReach Your Property Risk is Our Business

NCUA LETTER TO CREDIT UNIONS

White Paper: ISO Business Continuity Management An Overview. ISO Business Continuity Management An Overview

How to plan for a Disaster Recovery strategy. Nicholas Gee BCAP Jodie Rugless RDNS SA

GUIDANCE NOTE FOR DEPOSIT-TAKERS. Operational Risk Management. March 2012

Business Continuity Planning

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

Business Continuity Planning:

Legislative Council Panel on Information Technology and Broadcasting. Hacking and Virus Activities and Preventive Measures

AVANTGARD Private Cloud and Managed Services

Transcription:

RBC Business Continuity Management Program Exercising our Plans BCAW Presentation

Key Elements of the Program The RBC BCM program is global in scope Oversight of BCM is provided by the Enterprise Business Continuity Management Committee Responsible for governance throughout RBC Membership includes Sr Executive representation from across all major functions and business lines Enterprise Crisis Management Team Accountable for management of enterprise-wide incidents and crises Has representation from across RBC business lines and head office areas Incident Management Teams Accountable for management of local, regional, business-line specific issues Continuity Planning Activities The business and the BCM team are engaged in planning requirements Reporting Risk The BCM team publishes a quarterly BCM risk report across all RBC business lines 2

RBC Global Business Continuity Management Team 1 Director 34 Advisors, supporting all global business lines. 11 Senior Managers, supporting all global BCM Advisors & activities. 22 advisors in Canada supporting Canada, South America 4 advisors in the United States supporting USA 3 advisor in Trinidad supporting the Caribbean 4 advisors in United Kingdom supporting UK, Channel Islands and Europe 1 advisor in Hong Kong supporting Asia and Australia 3

Purpose of Exercising Plans Validate continuity strategies (Work Area Recovery, remote access, etc.) outlined in the plans Create awareness around the types of scenarios that would require an activation of a plan Familiarize teams with Work Area Recovery locations Familiarize employees with the business continuity strategies for their teams Create awareness around the types of scenarios that would require an Incident Management Team (IMT) to be convened Help define the decision making and communication process utilized Determine roles of team members and to assist members recognize their supporting teams Validate employee contact information and the ability to contact staff in a timely manner 4

Types of Exercises Contact Exercises Work Area Recovery Exercises Defines the requirement to be able to contact our staff Business are responsible to ensure their respective staff have updated their contact information in centralized system Testing is done at minimum annually for ALL staff globally Business is required to exercise their ability to work from alternate sites annually at a minimum Exercise event must be documented and approved in centralized BCM data base BCM completes second line of defense by approving results Business owns Plans BCM owns policy & standards IT owns Application DR Plans BCM owns governance Technology Exercises Defines application criticality through Business Impact Analysis Business executives are accountable to ensure their respective critical applications are tested according to established frequency Joint first line of defense with IT for Disaster Recovery Testing Supplier Exercises Supplier plans are to be exercised and evidence provided to RBC annually or as stipulated in contract Exercise events must be documented in centralized BCM data base Incident Tabletop Exercises Crisis and Incident management teams complete table top walkthroughs to ensure that they continually exercise their ability to think through and manage potential incidents 5

Contact Exercises Automated Use automated call out tool that can send multiple notification to multiple devices simultaneously Success criteria is identified in the plan and is set by business System provides reporting on contact capabilities by time BCM guides business unit Manual Business is required to complete the contacts directly Success criteria is identified in the plan and is set by business Business provides reporting on success Business unit owns risk IT supports business unit Emergency Automated system can be maintained to allow for quick callouts in emergency BCM maintains an Employee Emergency line that can be utilized by business to broadcast information 6

Contact Exercise Statistics In 2009, we conducted 366 exercises, testing recovery for 46,472 employees. In 2014, we conducted 174 exercises, testing recovery for 69,634 employees. We are doing half as many exercises and due to efficiencies, we covering almost 1.5 times as many employees. 7

Work Area Recovery Exercises Remote Access Business determines strategy and ability to utilize this Business typically uses this as part of regular everyday BCM guides business unit Recovery Site Dedicated recovery site geographically disparate from production Site is set up to mirror IT requirements from production Site must be exercised annually to ensure feasibility Business unit owns risk IT supports business unit Split Operations For critical business that cannot tolerate any downtimes Operations are physically split between to active production sites Sites are in perpetual state of exercise 8

Work Area Recovery Statistics In 2009, we conducted 391 exercises, testing recovery for 12,314 employees. In 2014, we conducted 696 exercises, testing recovery for 32,830 employees. We are doing 1.5 times more exercises and providing assurance for 2.6 times as many employees. 9

Technology Exercises Disaster Recovery Exercise cycles are tied to business recovery time objectives identified in business impact analysis Can be component based or full failover Centralized application inventory updated based on results Disaster recovery plans are documented by IT Events are documented and approved in centralized BCM repository Business unit owns risk BCM guides business unit IT supports business unit 10

Technology Exercise Statistics In 2009, we conducted 663 Disaster Recovery Exercises In 2014, we conducted 1381 Disaster Recovery Exercises 11

Supplier Exercises Transparent Suppliers exercise their own plans with no participation from RBC Supplier exercises have no impact on RBC processes we do not even know they are in an exercise event Supplier provides evidence after the exercise is completed BCM guides business unit Integrated Suppliers exercise their plans in conjunction with RBC Prior notification and exercise details provided to RBC RBC participates in exercise from production or recovery Joint accountability with RBC to identify and close gaps Business unit owns risk IT supports business unit Industry Wide Large scale involving many suppliers and regulators Provides opportunity to exercise RBC plans at the same time as suppliers Confirms supplier ability to recover services and for RBC to access Supplier in recovery Challenges industry to introduce systemic risk exposures 12

Supplier Exercise Statistics In 2009, we reviewed exercise information for 69 Suppliers. In 2014, we reviewed exercise information for 508 Suppliers. 13

Incident Tabletop Exercises Crisis Management Team Conducts exercises to provide learning opportunities and identify areas for improvement. Examples of exercises that have been conducted include: Assessing the impacts of a 6.0 magnitude earthquake event in Montreal, affecting our staff, operations, premises, including physical damages BCM guides business unit Reputational Crisis Management Team Conducts exercises to provide learning opportunities and identify areas for improvement. Examples of exercises that have been conducted include : Assessing the impacts of outsourcing activities affecting our staff and reputation. Business unit owns risk IT supports business unit Building/ Regional Incident Management Team Conducts exercises to provide learning opportunities and identify areas for improvement. Examples of exercises that have been conducted include: Assessing the impacts of food poisoning at a regional event affecting our staff and operations. 14

Questions??? 15