Business Continuity. Port environment



Similar documents
Business Continuity Roadmap -One Port s Approach. - Rich Baratta, ARM, ABCP Director, Risk Management Port of Long Beach

Why Should Companies Take a Closer Look at Business Continuity Planning?

Business Resiliency Business Continuity Management - January 14, 2014

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

State of South Carolina Policy Guidance and Training

CISM Certified Information Security Manager

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Business Continuity & Recovery Plan Summary

Continuity of Operations Planning. A step by step guide for business

Temple university. Auditing a business continuity management BCM. November, 2015

Business Continuity Planning and Disaster Recovery Planning

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Business Continuity & Recovery Plan Summary

The PNC Financial Services Group, Inc. Business Continuity Program

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

PBSi Business Continuity Planning

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

BUSINESS CONTINUITY PLANNING GUIDELINES

Assessment of natural hazards, man made hazards, technical and societal related risks and associated impact.

PAPER-6 PART-5 OF 5 CA A.RAFEQ, FCA

9/3/2009. Information Systems Disaster Recovery. Learning Objectives. Why have a plan? unexpected? APPA-Institute for Facilities Management

Business Continuity and Disaster Recovery Planning

William Rider Manager Disaster Recovery & Data Security The Johns Hopkins Health System & University

Business Continuity Plan

BUSINESS CONTINUITY PLAN OVERVIEW

Unit Guide to Business Continuity/Resumption Planning

Fundamentals of Business Continuity Planning Have a Plan!

Disaster Recovery Planning

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

How To Manage A Disruption Event

Principles for BCM requirements for the Dutch financial sector and its providers.

BC / DR Implementation Tying Disaster Recovery Investment to Measurable Business Value

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015

Disaster Recovery and Business Continuity Plan

BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION

Interagency Statement on Pandemic Planning

Disaster Recovery Journal Spring World 2014

CONTINUITY OF OPERATIONS PLAN (COOP) Planning Guide and Outline

Business Continuity Planning (800)

Tips and techniques a typical audit programme

Professional Practice Six - Business Continuity Plan Development and Implementation

Business Continuity Management Policy

Contingency Planning and Disaster Recovery for BOMA

Evaluating and Improving Your Business Continuity Plan

A Business Continuity Plan for Government. George Bomar Dianne Casey Texas Department of Licensing and Regulation

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) Fax: (718)

Business Continuity Planning: Bridging the Gap Between IT and Business

Creating a Business Continuity Plan for your Health Center

Desktop Scenario Self Assessment Exercise Page 1

IT Disaster Recovery Plan Template

Information Security Management: Business Continuity Planning. Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt.

IT Disaster Recovery and Business Resumption Planning Standards

SCADA Business Continuity and Disaster Recovery. Presented By: William Biehl, P.E (mobile)

How to Design and Implement a Successful Disaster Recovery Plan

IF DISASTER STRIKES IS YOUR BUSINESS READY?

Technology Recovery Plan Instructions

Statement of Guidance

Supervisory Policy Manual

Ohio Conference for Payroll Professionals Disaster Recovery

1.0 Policy Statement / Intentions (FOIA - Open)

Business Continuity Overview

Documentation. Disclaimer

Business Continuity Management

Business Continuity Planning for Schools, Departments & Support Units

FRAMEWORK. Approving authority. University Council. Approval date

ESCB definitions of major business continuity terms in relation to payment and securities settlement systems 1

Company Management System. Business Continuity in SIA

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP

Business Continuity Planning Preparing Your Organization

Business Continuity Planning

BT Conferencing Business Continuity Management. Planning to stay in business

BUSINESS CONTINUITY PLANNING

How To Prepare For A Disaster

Department of Defense INSTRUCTION. Reference: (a) DoD Directive , Defense Continuity Programs (DCP), September 8, 2004January 9, 2009

Interactive-Network Disaster Recovery

How to write a DISASTER RECOVERY PLAN. To print to A4, print at 75%.

Business Continuity Planning. Presentation and. Direction

Business Continuity and Disaster Recovery Planning from an Information Technology Perspective

Offsite Disaster Recovery Plan

MHA Consulting. Business Continuity Management 101

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Business Continuity Program Overview

Business Continuity Glossary

The University of Iowa. Enterprise Information Technology Disaster Plan. Version 3.1

Proposal for Business Continuity Plan and Management Review 6 August 2008

CITY OF RICHMOND CONTINUITY OF OPERATIONS (COOP) DEPARTMENT PLAN TEMPLATE

Business Continuity & Disaster Recovery

Planning for Disaster Disaster

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY

Business Continuity and Disaster Planning

VMIA Business Continuity Initiatives

DISASTER PLANNING AND RECOVERY

Is Your Port Prepared to Recover from a Disaster? Can you keep the cash register ringing when bad things happen?

Emergency Response and Business Continuity Management Policy

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Table of Contents ESF

Application / Hardware - Business Impact Analysis Template. MARC Configuration Requirements. Business Impact Analysis

Transcription:

Business Continuity Port environment

DEFINE BUSINESS CONTINUITY WHAT IT IS NOT RECOVERY FOCUS: PEOPLE PROCESSES TECHNOLOGY DELIVERABLES

INFRAGARD DEFINITION MANAGEMENT PROCESS DEVELOPING ADVANCE PROCEDURES ENABLING THE ORGANIZATION TO COPE ALLOWING CRITICAL BUSINESS FUNCTIONS TO CONTINUE

HOW IT FITS TOGETHER Emergency Mgmt. Crisis Mgmt. Business Resumption Plan IT - Disaster Recovery Plan PEOPLE Evacuation Procedures Emergency Response PEOPLE RECOVERY OF FACILITIES Corporate & Local Crisis Management Teams Command, Control, Communications & Collaboration BUSINESS PROCESSES INFORMATION SYSTEMS PROCESS CONTINUITY TECHNOLOGY AVAILABILITY B U S I N E S S C O N T I N U I T Y

Key Components Comprehensive Program Emergency Response Focus: People Action: Emergency Responders Escalated Response Communications Personnel Accountability Personnel Evacuation Employee Education Transition to Crisis Mgmt Team Crisis Management Focus: Decision Processes Action: Crisis Mgmt Team Activation Notification Incident Containment Initial Assessment 800# recorded Web Banner rolls Transition to Business Continuity Team Preparedness Critical Process Id Recovery Strategies Approved by Mgmt. Plans Tested & Improved Vital Records Program IIS, Telecom, Facilities Partner Support Alternate sites selected Business Resumption Focus: Business Revenue Action: Business Continuity Team Recovery Alternate site announced Owners Notified Plans initiated Mail / phone switch redirected Web banner info updated Resumption (to pre-event condition) Site(s) announced Executive Protection Owners Notified Plans Implemented Web banner info updated

Security System Model Situational Awareness Risk/Vulnerability Assessment Mitigation Preparedness Response Recovery Business Continuity

Business Continuity Program (BCP) BCP Structure SITE EMERGENCY RESPONSE PLAN (Linked to HAZMAT and Fire Prevention Plans) ESCALATED RESPONSE COMMUNICATIONS PERSONNEL ACCOUNTABILITY PERSONNEL EVACUATION EMERGENCY RESPONSE EMPLOYEE EDUCATION FOCUS: PEOPLE OSHA REQUIREMENTS SITE CRISIS MANAGEMENT PLAN TRANSITION TO BUSINESS CONTINGENCY TEAM INITIAL ASSESSMENT INCIDENT CONTAINMENT RESPONSIBILITIES NOTIFICATIONS ACTIVATION FOCUS: DECISION PROCESSES SITE AND/OR FUNCTION/ IPT BUSINESS RESUMPTION PLANS PROCESS CONTINGENCY PLANS (FOR CRITICAL PROCESSES) RECOVERY STRATEGIES APPROVED BY MANAGEMENT CRITICAL PROCESS IDENTIFICATION MANAGEMENT GUIDANCE & ANALYSIS FOCUS: BUSINESS REVENUE VITAL RECORDS PROGRAM INFORMATION SYSTEMS, TELECOMMUNICATIONS, AND FACILITIES BUSINESS IMPACT ANALYSIS RISK ASSESSMENT & VULNERABILITIES ANALYSIS EXECUTIVE PROTECTION CORPORATE AND SECTOR REQUIREMENTS

PROGRAM GOALS LIFE SAFETY OF THE EMPLOYEES CONTINUE CRITICAL BUSINESS FUNCTIONS RETURN TO STATE OF NORMALCY? QUICKLY EFFICIENTLY

SCOPE OF THE PROGRAM? PORT AUTHORITY FACILITIES REGIONAL INFRASTRUCTURE WATERWAYS TERMINAL OPERATIONS SUPPLY CHAIN AMERICAN ECONOMY

ISSUES? AUTHORITY JURISDICTION GOVERNMENTAL UPSTREAM LEGAL AND CONTRACTUAL BUSINESS COMPETITION PRIVACY STAKEHOLDER POLICY

DHS DIRECTIVE ON RECOVERY MARITIME INFRASTRUCTURE RECOVERY PLAN PROTECT AMERICAN ECONOMY RESTORATION OF PASSENGER AND CARGO FLOW, SPECIFICALLY CONTAINER CARGO DOES NOT ADDRESS LONG TERM INTERRUPTIONS NOT A PLAN FOR THE PHYSICAL RECOVERY OF A PORT PROVIDES GUIDANCE FOR THE REDIRECTION OF CONTAINER CARGO EXPERIENCE AT POLB/POLA LABOR ACTION OF 2002

COAST GUARD INTEREST PAST EXERCISES LEAD SHIELD ROGUE X WORKSHOP CRITICAL PATH UPCOMING SYMPOSIUM

CA ENHANCEMENT PLAN INITIATIVE 5: ENHANCE PORT SECURITY PROJECT 5: REGIONAL BUSINESS & GOVERNMENT CONTINUITY PLANNIING PROGRAM MANAGEMENT: DAMAGE AND SAFETY ASSESSMENTS STRUCTURAL INSPECTIONS MITIGATION AND CONSTRUCTION ACTIVITIES PERSONNEL AVAILABILITY BUSINESS PROCESSES, VENDORS, SUPPLIERS UTILITIES RESTORATION LAND AND WATER TRANSPORTATION RESTORATION PRIORITIZED RESTORATION OF BUSINESS AND GOVERNMENT

CRITICAL PATH NUMEROUS STAKEHOLDERS BINDING RELATIONSHIPS? UNSTRUCTURED ENTERPRISE INDEPENDENT INTERESTS BUSINESS HUMAN

STAKEHOLDERS HOW MANY? WHO?

RISK ASSESSMENT BUSINESS IMPACT ANALYSIS CRITICAL PROCESSES CONSEQUENCES HUMAN PHYSICAL PSYCOLOGICAL ALL STAKEHOLDERS FINANCIAL COSTS DAMAGE CASHFLOW DOWNTIME/OVERTIME MAXIMUM ALLOWABLE OUTAGE & RECOVERY TIME OBJECTIVES TIME BEFORE IMPACT IS UNACCEPTABLE SHORTAGE ALLOWABLE OUTAGE RESTORED FIRST ESTABLISH DIFFERENT RECOVERY TIME OBJECTIVES COST OF ALTERNATIVE PROCEDURES VERSUS WAITING FOR RESTORATION

RTO AND RPO Recovery Time Objective (RTO) is the length of time a business process can be unavailable before the overall business is severely impacted. As part of the impacts reviewed, the Recovery Point Objective (RPO) was included in the BIA update. Recovery Point Objective (RPO) is the timeframe where information must be recovered or it will be become useless due to outdating or volume levels exceeding recovery capabilities.

PORT OF LONG BEACH 3,300 acres of land 33% of all CA port cargo 2 nd Busiest port in U.S. Significant HazMat handling Passenger handling 8.1 million population within a 25 mile radius 10 piers 80 berths 7 container terminals 71 gantry cranes 76-foot-deep main channel 5,300 vessel calls in 2005

SAN PEDRO BAY: ONE HARBOR TWO PORTS

BUSINESS CONTINUITY PORT AUTHORITY ORGANIZATION FACILITIES PROCESSES INFRASTRUCTURE VENDORS AND SUPPLIERS IT SYSTEMS

ORGANIZATION TOP LEVEL POLICY PROTECT PEOPLE, PROPERTY & BUSINESS INTERESTS OWNERSHIP OF SYSTEMS, PROCESSES AND RESOURCES MANAGEMENT STRUCTURE DECISION MAKING: QUORUM SUCCESSION PLANNING PERSONAL PROTECTION TRAVEL BRIEFINGS KITS EVACUATION PLANS INSURANCE SOS MEDICAL PPQ S

ORGANIZATION (cont d) KEY EMPLOYEES TRACKING AVIAN FLU NO SINGLE POINT FAILURES CROSSTRAINING DOCUMENTED JOB FUNCTION DESK TOP PROCEDURES TELEWORK POLICY DOCUMENTED PRACTICED EXPEDITED EMERGENCY REPLACEMENT POLICY TEMP AGENCIES PRE- IDENTIFIED EMPLOYEE SKILL SURVEYS BEYOND JOB FUNCTIONS SHELTER IN PLACE?

FACILITIES BACKUP LOCATION PRE-IDENTIFIED LOGISTICAL SUPPORT WITHIN AREA OF THREAT? SAME POWER GRID? TRANSPORTATION FOR EMPLOYEES REDIRECTION OF MAIL AND DELIVERIES

PROCESSES CRITICAL FLOWCHARTED INTERPERSONAL AND INTERDEPARTMENTAL RELIANCES KEY OPERATIONAL SUPPORT BUSINESS RECORDS CAVEAT: IF NOT CRITICAL?

INFRASTRUCTURE WATER POWER SANITARY SEWER TELESYSTEMS ROADS BRIDGES

VENDORS AND SUPPLIERS KOBE EARTHQUAKE SINGLE SOURCE? JUST IN TIME VULNERABILITY ASSESSMENTS SITE VISITS VALIDATED BC PLANS REQUIREMENT IN K

IT SYSTEMS SEPARATE PLAN PLUG AND PLAY BACKUP SITES COLD V. HOT LOCATION

ALTERNATIVES ATTAINABLE HIGH PROBABLILITY OF SUCCESS VERIFIABLE THROUGH TESTS AND EXERCISES COST EFFECTIVE APPROPRIATE FOR THE SIZE AND SCOPE OF THE OPERATION

CONSIDER PRIVATE SECTOR CAPABILITIES EQUIPMENT SUPPLIES TECHNICAL EXPERTISE LOGISTICAL CAPABILITIES GOVERNMENT DOES NOT UNDERSTAND BUSINESS MODELS AND ECONOMIC IMPACT

CRITICAL SOCIETAL FUNCTIONS FOOD TRANSPORTATION SHELTER HEALTH AND SANITATION BANKS FAMILIES

MEDICAL PLANNING FIRST RESPONDERS STOCKPILES OF MEDICINES PROPHYLACTIC TREATMENT PSYCHOLOGICAL SUPPORT GRIEVING AREA? LONDON EXPERIENCE

BUSINESS CONTINUITY OPERATIONS CENTER CONTENTS TEAM ACTIVATION LOCATION

BUSINESS CONTINUITY CULTURE ASSESSING DESIGNING AND DELIVERING EXERCISING OF PLANS MAINTENANCE AUDITS SELF EXTERNAL

DESIRED END RESULT RESILIENCY ORGANIZATION INFRASTRUCTURE PROCESSES QUICK DECISION MAKING ADAPTABILITY PRE-IDENTIFIED ALTERNATIVES

BUSINESS CONTINUITY Business Continuity Plan PEOPLE BUSINESS PROCESSES PROCESS CONTINUITY Comprehensive and documented plan utilized in the event of a disaster, focus solely on the business operations. Plan defines resources, actions, tasks and data required to manage the recovery effort in the event of a business interruption. Identifies: Primary location Alterative Recovery Sites (Alt 1 and Alt 2) Interdependencies (internal and external) RTOs and RPOs Critical People Applications Data Vendors Vital Records 800 numbers Web sites (internal and external)

CHALLENGE NATIONAL PRIORITY SYMPOSIUM LOCAL PLANNING IDENTIFIED SCOPE SUPPLY CHAIN CRITICAL PATH INTEGATION OF ALL STAKEHOLDERS