VMIA Business Continuity Initiatives



Similar documents
Business continuity management policy

Guideline - Business Continuity Plan

Business Continuity (Policy & Procedure)

IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS

Business Continuity Management

Guidance Note XGN XXX.1

Business Resiliency Business Continuity Management - January 14, 2014

Information Security Policy. Chapter 11. Business Continuity

International Diploma in Risk Management Syllabus

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO AUDITS, CERTIFICATION AND TRAINING

NHS 24 - Business Continuity Strategy

Business Continuity. Port environment

London Borough of Bromley. Executive & Resources PDS Committee. Disaster Recovery Plans for London Borough of Bromley

BUSINESS CONTINUITY POLICY

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

1.0 Policy Statement / Intentions (FOIA - Open)

Introduction to Business Continuity Planning

Tips and techniques a typical audit programme

Business Continuity Plan Toolkit

External Supplier Control Requirements BCM

Business Continuity Management Policy

Appendix 2 - Leicester City Council s Business Continuity Management Policy Statement and Strategy Business Continuity Policy Statement 2015

Appendix 1 - Leicester City Council s Business Continuity Management Strategy and Policy Statement

Coping with a major business disruption. Some practical advice

Risk Management & Business Continuity Manual

Business Continuity Policy and Business Continuity Management System

Business Continuity Management Policy

How to measure your business resiliency

South West Lincolnshire NHS Clinical Commissioning Group Business Continuity Policy

Evaluating and Improving Your Business Continuity Plan

BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

State of South Carolina Policy Guidance and Training

Business Continuity Management

FINRMFS9 Facilitate Business Continuity Planning and disaster recovery for a financial services organisation

Contingency Plan for HIPAA

Business Continuity and Risk Management. Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited

NOT PROTECTIVELY MARKED BUSINESS CONTINUITY. Specialist Operations Contingency Planning Business Continuity Manager

Accreditation Application Forms

Business Continuity Planning. Presentation and. Direction

Principles for BCM requirements for the Dutch financial sector and its providers.

Statement of Guidance

EPRR: BCP - Checklist

POLICY. 1) Business Continuity Management 2) Disaster Recovery 3) Critical Incident Management 4) Risk Management

How to Exercise a Business Continuity Plan (BCP)

Business Continuity Policy

AUDIT OF INFORMATION TECHNOLOGY Management (Action Plan) Responses February 2005 # PRIORITY DESCRIPTION MANAGEMENT RESPONSE

Business Continuity Management Framework

BCP and DR. P K Patel AGM, MoF

Business Continuity Policy

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

COMCARE BUSINESS CONTINUITY MANAGEMENT

BS BUSINESS CONTINUITY MANAGEMENT

NHS Hardwick Clinical Commissioning Group. Business Continuity Policy

BUSINESS CONTINUITY STRATEGY

Business Continuity Management and BS by Steve Chan, Head of Training - HK, BSI Management Systems

Business Continuity Overview

Business Continuity Business Continuity Management Policy

Business Continuity Planning Instructions

How To Manage A Disruption Event

Merrycon s Approach to Business Continuity Management

HB A Practitioners Guide to Business Continuity Management

Why Should Companies Take a Closer Look at Business Continuity Planning?

BUSINESS CONTINUITY & STRATEGY POLICY

EPRR: Toolkit Facilitator Guide

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

Business Continuity Management Policy and Framework

Overview TECHIS Manage information security business resilience activities

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

Business Continuity Management (BCM) Policy

Business Continuity Management Program Development Guide

BSO Board Director of Human Resources & Corporate Services Business Continuity Policy. 28 February 2012

Business Continuity - IT Disaster Recovery Discussion Paper - - Commercial in Confidence Version V2.0R Wednesday, 5 September 2012

BUSINESS CONTINUITY MANAGEMENT REQUIREMENTS FOR SGX MEMBERS NEW RULES FOR INCLUSION IN SGX-ST RULES

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP

A structured approach to Enterprise Risk Management (ERM) and the requirements of ISO 31000

NHS Commissioning Board Business Continuity Management Framework (service resilience)

Business Continuity Guide

Contents. About Perpetuuiti. Continuity Vault. Continuity Patrol. Ops Central. Questions & Answers. Section 2. Section 3. Section 4.

NIST SP , Revision 1 Contingency Planning Guide for Federal Information Systems

A BCP Tale: From Theory to Practice

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

Transcription:

VMIA Business Continuity Initiatives

The need for Business Continuity Identified as key risk area during Risk Framework Quality Reviews (2006-7) Identified Vic Gov Risk Management Framework Particular concern for Health Services - Impact on patient safety - Very short recovery timeframes DHS has also identified Business Continuity as a priority area

Recommendations for Healthcare - 2006 RFQR Summary Category High % Medium % Low % Grand Total Risk ID 37 26% 14 10% 2 5% 53 Responsibilities 10 7% 21 15% 10 26% 41 Risk Education 6 4% 20 15% 8 21% 34 Reporting 20 14% 6 4% 9 24% 35 Internal Audit & RA 12 8% 14 10% 1 3% 27 BCP 8 6% 17 12% 0% 25 Project RM 1 1% 23 17% 1 3% 25 Strategic RM 18 13% 5 4% 1 3% 24 Risk Appetite 12 8% 4 3% 3 8% 19 RMF 13 9% 4 3% 2 5% 19 KRI 5 4% 8 6% 0% 13 Risk Escalation 0% 1 1% 0% 1 Training 0% 0% 1 3% 1 142 137 38 317

BCM A Process Overview General Intent Comments Context / Scope BCM is a management process of considered activities. BCP is a tactical plan. Risk Assessment Response Crisis Recovery Maintenance Protection of Enterprise Value BCM process offers a considered management approach to address a prescribed threat / event. It Does not necessarily provide the solution - but it introduces the test of reasonableness into a measurable framework BCM process attempts to introduce rigour while retaining flexibility by way of application events simply don t happen they way we plan BCM activities overlap they are not sequential in their development or their application but they need to be managed in parallel across time BCM activities vary in their applied complexity and intensity as determined by the dynamics of the event.

BCM An approach for Health Services Context / Scope High Level Actions Determine Criticality of their Business within their operating environment Aim to protect Enterprise Value Be seen to Act Diligently Risk Assessment Assess Maximum Acceptable Outage for their business / location Derive - Business Recovery Options / Priorities / Alternatives Response Crisis Document - Structured actions for RESPONSE through RECOVERY Recovery Maintenance Engender a process of CONTINUOUS IMPROVEMENT

The VMIA Response Development of BCM Guidelines and Templates (2007) Pilots (2007): - 4 Metro Hospitals - 3 Regional Hospitals - 2 General Government Training - using different providers Clients started drafting own plans for specific functional areas 2008 Service Continuity Framework for Healthcare 2008 Hospital Resilience Program - DHS

Lessons Learned Significant organisational commitment needed Very short recovery time objectives Multiple inter-dependencies - Admissions, Medication, Sterilisation, Patient Records, Post Op/ wards Focus initially on appropriate strategy development, rather than detailed resource requirements Standard approach

Lessons Learned cont Resource implications: - Staff time and expertise - Cost of implementing not budgeted for Need to integrate with existing frameworks: - Emergency Management Response - Incident Command Structures - Crisis Management Team - CHOC - governance structures, plans etc.

External Environment External Interaction Healthcare Providers Department of Human Services (DHS) Third Party Providers Levels of Recovery Planning Internal Environment Health Service Municipal/ Local Level Crisis Management (Strategic) Regional Level State Level Emergency Response (Tactical) Incident Command Structure Business Continuity & Disaster Recovery (Operational) National Level Structured Co-ordination Workforce Capability Capacity Building Inter-operability of Plans Triggers Escalations Performance Drivers Health Sector Contingency Planning Model

VMIA Future state Revision of existing BCM draft to include more practical examples, worksheets Focus on strategy rather than resource requirements Revised BCM targeted to complete by July 2008 Training & awareness Simplified versions for specific sectors planned (Community Service Organisations)

Roger Gowlett (Risk Management Advisor) Patrick Ow (Risk Management Advisor)