Continuity of Operations:

Similar documents
Federal Continuity Directive 1 (FCD 1)

FEDERAL PREPAREDNESS CIRCULAR Federal Emergency Management Agency Washington, D.C FPC 67

Federal Continuity Directive 1 (FCD 1) Federal Continuity Directive 1 (FCD 1)

Continuity Guidance Circular 2 (CGC 2)

Devolution of Operations Plan Template

Continuity of Operations Plan Template

Comprehensive Emergency Management Plan (CEMP) Annex V CONTINUITY OF OPERATIONS PLAN (COOP)

SAMPLE IT CONTINGENCY PLAN FORMAT

Technology Infrastructure Services

DEPARTMENT OF THE NAVY HEADQUARTERS UNITED STATES MARINE CORPS 3000 MARINE CORPS PENTAGON WASHINGTON, DC

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Department of Defense INSTRUCTION. Reference: (a) DoD Directive , Defense Continuity Programs (DCP), September 8, 2004January 9, 2009

Chapter 1: An Overview of Emergency Preparedness and Business Continuity

THE WHITE HOUSE. Office of the Press Secretary. For Immediate Release February 12, February 12, 2013

FEDERAL EMERGENCY MANAGEMENT AGENCY (FEMA) INDEPENDENT STUDY COURSE INTRO TO INCIDENT COMMAND SYSTEM FOR FEDERAL WORKERS (IS-100.

CONTINUITY OF OPERATIONS PLAN TEMPLATE

Miami-Dade County, Florida Emergency Operations Center (EOC) (your Dept. name here instead of EOC) Continuity of Operations Plan (COOP) Template

It also provides guidance for rapid alerting and warning to key officials and the general public of a potential or occurring emergency or disaster.

This presentation will introduce you to the concepts and terminology related to disaster recovery planning for businesses.

All-Hazard Continuity of Operations Plan. [Department/College Name] [Date]

D2-02_01 Disaster Recovery in the modern EPU

BUSINESS CONTINUITY PLANNING

CAPABILITY 2: Community Recovery

Continuity of Operations Actions

ready? are you [ ] An Elected Official s Guide to Emergency Management

[Organization Name] Continuity Multi-Year Strategy and Program Management Plan (MYSPMP) Template February 2014

HALIFAX COMMUNITY COLLEGE BUSINESS CONTINUITY PLAN

Business Continuity & Disaster Recovery

CONTINUITY OF OPERATIONS PLAN (COOP)

Overview of Business Continuity Planning Sally Meglathery Payoff

Creating a Business Continuity Plan for your Health Center

Workforce Solutions Business Continuity Plan May 2014

Continuity of Operations Plan Template and Instructions for Federal Departments and Agencies July [Department/Agency Name] [Month Day, Year]

Pandemic Influenza Continuity of Operations Annex Template

Cornell University RECOVERY PLAN

NIMS ICS 100.HCb. Instructions

Building and Maintaining a Business Continuity Program

Continuity of Healthcare Operations 7 Mission Essential Functions

Business Impact Analysis (BIA) and Risk Mitigation

Why COOP? 6 Goals of COOP. 6 Goals of COOP. General Guidelines for COOP Capability. COOP Program Model 7 Phases. Phase 1: Initiate COOP program

Business Continuity Planning for Schools, Departments & Support Units

Prepared by Rod Davis, ABCP, MCSA November, 2011

Continuity Plan Template and Instructions for Non-Federal Governments

CONTINUITY OF OPERATIONS PLAN (COOP)

Disaster Recovery Planning Procedures and Guidelines

Emergency Management Certification and Training (EMC & T) Refresher Terry Hastings, DHSES Senior Policy Advisor

RECONSTITUTION PLAN K-1

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Course Title: HSE-101 Introduction to Homeland Security Prerequisites: None Credit Hours: 3 lectures, 3 hours

Continuity of Operations Plan (COOP) Guidelines for Skilled Nursing & Assisted Living Facilities (Name of Facility)

NAIT Guidelines. Implementation Date: February 15, 2011 Replaces: July 1, Table of Contents. Section Description Page

The Supply Chain and Business Continuity: Preparing to Survive the Next Disaster

Business Unit CONTINGENCY PLAN

All. Presidential Directive (HSPD) 7, Critical Infrastructure Identification, Prioritization, and Protection, and as they relate to the NRF.

The Role of Elected Officials During Disasters. The Florida Division of Emergency Management

Business Continuity Planning in IT

U.S. Department of Energy Washington, D.C.

CONTINUITY OF OPERATIONS

CONTINUITY OF OPERATIONS PLAN (COOP) Planning Guide and Outline

Business Continuity Plan

Statement of Guidance

Continuity of Operations Planning. A step by step guide for business

TO AN EFFECTIVE BUSINESS CONTINUITY PLAN

Unit Guide to Business Continuity/Resumption Planning

Success or Failure? Your Keys to Business Continuity Planning. An Ingenuity Whitepaper

CYBER SECURITY GUIDANCE

Continuity Plan Template for Non-Federal Governments

Department of Homeland Security Information Sharing Strategy

Emergency Preparedness: Learning Objectives. Minimizing and Controlling Future Disasters. SHRM Disaster Preparedness Survey 3.

Ohio Supercomputer Center

DISASTER RECOVERY PLANNING GUIDE

The Joint Commission Approach to Evaluation of Emergency Management New Standards

UNION COLLEGE INCIDENT RESPONSE PLAN

White Paper AN INTRODUCTION TO BUSINESS CONTINUITY PLANNING AND SOLUTIONS FOR IT AND TELECOM DECISION MAKERS. Executive Summary

U.S. Fire Administration. The Critical Infrastructure Protection Process Job Aid

ESF 02 - Communications Annex, 2015

Temple university. Auditing a business continuity management BCM. November, 2015

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Table of Contents ESF

DISASTER RECOVERY FOR PUBLIC HEALTH. August 2007

Business Continuity Management Policy and Plan

Disaster Recovery and Business Continuity Plan

Business Continuity Planning Toolkit. (For Deployment of BCP to Campus Departments in Phase 2)

EMERGENCY MANAGEMENT PLANNING CRITERIA FOR AMBULATORY SURGICAL CENTERS

BUSINESS CONTINUITY PLAN OVERVIEW

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

Transcription:

Continuity of Operations: By Robert Marinelli The past twelve months have provided many challenges due to severe weather events. Massachusetts has withstood a major tropical storm, tornados, and several floods. A large percentage of the state s population had to endure at least one night by candlelight. Many lost their homes or were evacuated. The weather events created a major interruption in daily life. One result was a surge in sales of generators, a modest investment that helps us take some control over our circumstances and allows us to continue basic, day-to-day functions. In the business community, the ability to function during and after an interruption is critical to survival. Operating risk is the term for the potential loss of essential systems. The incapacity of key systems can result in a huge financial loss often not insurable. Business continuity, therefore, has become an important goal of many private organizations, not only as a matter of survival but also as a way to prevent any interruption from becoming costly. Many private organizations were already addressing this risk before the National Fire Protection Association in 1995 published its Recommended Practices for Disaster Management (NFPA 1600), which evolved into the Business Continuity Standard in 2000. Continuity of Operations in Government In the government sector, continuity of operations efforts originated during the Cold War, with President Dwight Eisenhower s executive order outlining measures to ensure that the federal government would continue to operate following a potential nuclear attack. This plan was originally known as Continuity of Government. Each successive president has issued executive orders pertaining to emergency preparedness, ranging from mobilization of resources to reorganization or the creation of federal departments. The terrorist attacks of September 11, 2001, prompted the Executive Branch to focus on continuity of operations. National Security Presidential Directive 51 and Homeland Security Presidential Directive 20 established a National Continuity Policy, which specifies requirements for continuity plan development, including the requirement that all Executive Branch departments and agencies develop an integrated, overlapping continuity capability. In 2008, Federal Continuity Directive 1 Robert Marinelli, ARM, CPSI, RSSP, is the MIIA Member Services Risk Control Manager. 16 MUNICIPAL ADVOCATE Vol. 26, No. 3

A Guide for Local Governments was released to provide guidance to Executive Branch agencies. FCD 1 does not require non-federal organizations to develop continuity programs, but the Federal Emergency Management Agency strongly recommends that all agencies develop viable continuity programs. FEMA developed Continuity Guidance Circular 1 to help non-federal organizations with continuity planning. CGC 1 parallels FCD 1 closely, but is geared toward states, territories, and tribal and local governments. CGC 1 states that, Continuity planning facilitates the performance of essential functions during all-hazards emergencies or other situations that may disrupt normal operations. By continuing the performance of essential functions through a catastrophic emergency, the state, local, territorial, and tribal governments support the ability of the federal government to perform national essential functions, continue enduring constitutional government, and ensure that essential services are provided to the nation s citizens. A comprehensive and integrated continuity capability will enhance the credibility of our national security posture and enable a more rapid and effective response to, and recovery from, a national emergency. In other words, the federal government doesn t require local governments to develop continuity of operations plans, but feels that doing so would contribute to the continuity of overlapping essential functions at various levels of government. A local continuity of operations plan provides for the continuation of essential functions while enabling rapid response to an emergency. Such a plan documents what will occur, how quickly continuity actions must occur, when continuity operations will occur, and who participates in the continuity operations. Monson Town Administrator Gretchen Neggers, whose town was devastated by a tornado on June 1, offers this advice: When your workplace is in ruins and you are responsible for providing critical services, that is not the time to start thinking about continuity of operations. Pillars and Phases FEMA s Continuity Guidance Circular 1 provides a framework for continuity of operations plans. The circular identifies the four pillars that support an organization s capability to perform its essential functions: leadership, staff, facilities, and communication systems. Leadership provided by local officials is critical in providing support for continuity planning, an effort that must be driven from the top down. Without direction from leadership, staff are not able to be fully effective during emergency events. Staff must be sufficiently trained and cross-trained to perform duties in a continuity environment. Facilities must be adequate, and backup locations should be designated to ensure the execution of essential functions. Communications systems and technology must be interoperable, robust and reliable. The FEMA circular also identifies the four phases of a continuity plan: 1. Readiness and preparedness 2. Activation and relocation 3. Continuity operations 4. Reconstitution. Phases of Continuity Plan Readiness and Preparedness Event/Threat Activation and Relocation Continuity Operations Reconstruction MUNICIPAL ADVOCATE Vol. 26, No. 3 17

Continuity of Operations: A Guide for Local Governments Readiness is the ability of an organization to respond to a continuity event. Although readiness is a function of planning and training, it is ultimately the responsibility of leadership to ensure that an organization through normal procedures or with a continuity plan can perform its mission-essential functions before, during, and after an all-hazards emergency or disaster. Activation is the process for attaining operational capability at continuity of operations sites as soon as possible within twelve hours at most and with minimal disruption to operations. Organizations should identify essential functions that must be continued without disruption and ensure that these can be conducted under all conditions. The process should include the activation of plans, procedures, and schedules for the continuation of essential functions, as well as for the personnel, vital records and databases, and equipment involved with these functions, with minimal disruption. Continuity operations are activities performed to continue essential functions. This phase includes accounting for all personnel; performing essential functions; establishing communications with supporting and supported organizations and constituents; and conducting recovery activities. Reconstitution is the process of resuming normal operations. Functions that were discontinued during the emergency should be reconstituted first. Once this is done, most essential functions should be transferred back to normal operations. Reconstitution often runs concurrently with recovery efforts. The Program Cycle The Continuity Program Cycle is a four-step process: planning; tests, training and exercises; evaluations; and corrective action plans. The process is standardized to ensure consistency across all continuity programs. It establishes consistent performance metrics, prioritizes implementation plans, promulgates best practices, and facilitates consistent cross-agency continuity evaluations. A cyclic-based model that incorporates planning, training, evaluating, and implementing corrective actions gives leaders and essential personnel the baseline information, awareness, and experience necessary to fulfill their continuity program management responsibilities. Continuity plans should be evaluated pre- and post-event, tested or exercised, and assessed during the development of corrective action plans. Objective evaluations and assessments, developed from tests and exercises, provide feedback on continuity planning, procedures, and training. This feedback in turn supports a corrective action process that helps to establish priorities, informs budget decision making, and drives improvements in plans and procedures. Even if it s written down, says Neggers, the local continuity of operations plan needs to be practiced to find out what isn t going to work and to correct it before an emergency occurs. The continuity program management cycle should be used by all organizations as they develop and implement their continuity programs. CONTINUITY PROGRAM MANAGEMENT CYCLE Plans and Procedures Continuity Capability Performance of Essential Functions Develop Corrective Action Plans Leadership Staff Facilities Communications Test, Training, and Exercise Continuity Planning and Program Management Evaluations, After-Action Reports, and Lessons Learned 18 MUNICIPAL ADVOCATE Vol. 26, No. 3

The following steps should be taken to identify and analyze Mission-Essential Functions: COURTESY PHOTO Review the organization s functions as directed by applicable laws and statutory authorities. Monson s Town Hall was struck by a tornado on June 1, testing the small town s ability to continue providing key services. Elements of a Continuity Plan The FEMA circular identifies the following ten essential elements for a viable continuity plan: 1. Determine Essential Functions Essential functions are those that enable a public entity to provide vital services, exercise civil authority, maintain public safety, and sustain the economic base. In a nutshell, essential functions are the business functions that must continue with minimal or no interruption. Identifying all organizational Mission-Essential Functions is a prerequisite for continuity. This step establishes the parameters that drive the organization s efforts in all other planning and preparedness areas. [The National Continuity Policy Implementation Plan references an MEF Initial Screening Aid; organizations can develop their own initial screening aid template as appropriate.] MEF INITIAL SCREENING AID Is the function directed by law, statute, YES presidential directive, or executive order? If yes, identify which. NO YES NO Did a business process analysis determine that the function should be performed under all circumstances either uninterrupted, with minimal interruption, or requiring immediate execution in an emergency? If the answer to one or both of these questions is No, the function is probably not an MEF. Conduct a business process analysis to identify and map the functional processes, workflows, activities, personnel expertise, systems, data, and facilities inherent to the execution of each identified MissionEssential Function that should be performed under all circumstances, either uninterrupted, with minimal interruption, or requiring immediate execution in an emergency. (For example, define how each MEF is performed and executed, using a business-process flow map.) Identify those Mission-Essential Functions that provide vital interdependent support to an MEF performed by another organization or by an emergency support function. Identify those Mission-Essential Functions that require vital support from another organization to ensure the execution of their mission, and identify when and where the particular interdependency is executed within the business-process flow. Have each organization head validate and approve the identified Mission-Essential Functions and business process analysis. These steps allow local governments to refine their essential mission, while also supporting the continuity efforts of state and federal agencies. 2. Develop Orders of Succession In the event that the leadership of a local government is unavailable, debilitated, or incapable of performing their legally authorized duties, roles and responsibilities, it is critical that there be an orderly and predefined assumption of senior agency duties. Not only should succession orders be a part of continuity planning, but they should be developed to support day-to-day functions. The town of West Boylston, which was hit hard by a severe ice storm in 2008, addresses succession in its continuity of operations plan. We annually amend the succession planning portion of the document, says Town Administrator Leon Gaumond. Dealing with succession issues is always preferable when there is not an emergency to deal with at the same time. 3. Delegate Authority Delegations of authority are formal documents specifying the activities that may be performed by certain individuals authorized to act on behalf of an agency head or other key officials. Such documents should outline the legal authority for officials to make key policy decisions during a continuity event. This ensures continued operations as well as rapid response to an emergency. 4. Determine Continuity Facilities Continuity facilities allow local governments to continue operations away from primary operating facilities in the event that the primary facilities are unavailable. These backup locations should be located far enough away from the primary facility so as to not MUNICIPAL ADVOCATE Vol. 26, No. 3 19

Continuity of Operations: A Guide for Local Governments be affected by the incident that disabled the primary facility. The tornado in Monson, for example, hit the town offices, where the majority of the town s department heads work. Of particular concern were public safety offices, which were relocated, but not without challenges. The Police Department worked briefly out of a condemned building and moved to a trailer within a week; the department was not fully functional until six weeks after the tornado. Neggers says she was impressed that many of the town s police officers were in fact very handy with hammers and nails. Continuity plans should also identify alternates to continuity facilities in the event that they, too, are affected. Special consideration should be given to alternate power sources (e.g., generators) and sanitary facilities for employees. 5. Determine Continuity Communications Ensuring effective communications is a critical aspect of continuity plans, as this is often an area of breakdown during an emergency. Continuity communications must be redundant, available within twelve hours, or sooner, and be sustainable for up to thirty days, or until normal operations can be resumed. Local governments should consider non-terrestrial forms of communication (e.g., satellite phones and Internet access). 6. Manage Vital Records All local governments have documents, files, and other materials that are vital to the organization and its operations. Vital records fall into two categories: emergency operating records and rights and interest records. Emergency operating records are those required for an organization s performance of essential functions. Rights and interest records are critical in carrying out the organization s essential legal and financial functions. A vital Ten Essential Elements of a Continuity Plan 1. Determining Essential Functions 2. Developing Orders of Succession 3. Delegating Authority 4. Determining Continuity Facilities 5. Determining Continuity Communications 6. Maintaining Vital Records Management 7. Summarizing Human Capital 8. Implementing a Test, Training and Exercises Program 9. Implementing a Devolution Plan 10. Outlining Reconstitution Procedures 20 MUNICIPAL ADVOCATE Vol. 26, No. 3 records program is mandatory for federal agencies and strongly suggested for non-federal organizations. In Monson, the records program enabled the town to pay employees after the tornado struck. We saved our electronic data, says Neggers, and were able to move town offices to an alternate location, thus allowing us to process payroll for our employees. 7. Summarize Human Capital Human capital is the accumulation of talent, energy, knowledge, and enthusiasm that people invest in their work. During an Continuity communications must be redundant, available within twelve hours, or sooner, and be sustainable for up to thirty days, or until normal operations can be resumed. emergency, local governments may be forced to perform essential functions with reduced staffing. For this reason, all personnel who will be performing essential functions need to be adequately trained and cross-trained. Critical elements associated with human capital include designating those who will be engaged in emergency operations, communicating with and providing guidance to all employees, and determining the best uses of continuity personnel. 8. Implement a Test, Training and Exercises Program Tests, training and exercises are the best ways to promote consistency and uniformity of continuity plan functions. Local governments need to measure their capacity to support the continued execution of essential functions throughout the duration of an emergency event. An effective test, training and exercise program will provide training in areas appropriate to mission readiness, as well as opportunities to acquire and apply the skills and knowledge needed for continuity operations. After the tornado struck, the town of Monson realized that it did not have enough redundancy in trained staff to accommodate for important positions where the individual was out of town and unable to respond, Neggers says. Non-public-safety personnel, particularly, lacked adequate training as to performance expectations in an emergency. 9. Implement a Devolution Plan Devolution is the ability to transfer statutory authority and the responsibility for essential functions from an agency s primary operating staff and facilities to other employees and facilities. 10. Outline Reconstitution Procedures The processes by which organizations resume normal operations should be outlined to make a smooth transition from a relocation site to a new or repaired facility. Evaluation, Corrective Action and Support Evaluations and after-action reports are important parts of the continuity program cycle. Organizations need to document the results of their continuity activities, whether from a training

exercise or an actual event. After-action reports are then incorporated into correctiveaction plans, the fourth phase of the continuity cycle. Corrective-action plans incorporate specific response information from an event into the greater continuity of operations plan. Monson s after-action reports indicated a need for redundancy in key positions, Neggers says, so if someone is gone it doesn t mean we have to do without, and this should be a part of any continuity of operations plan. Numerous support functions dovetail into a continuity of operations plan. A risk management model of identifying threats, assessing vulnerability, implementing measures to prevent or reduce the impact of incidents, and evaluating results are basic principles that should be applied to all operations and serve as a critical support element of a continuity of operations plan. The financial aspect of continuity planning should not be overlooked. An effective process for ensuring the timely procurement of equipment, supplies and services can reduce the administrative burden during a continuity event, allowing the local government to focus on emergency response and restoration activities. Another important element is family support. Employees may be deployed for a number of days either locally or at a distance through mutual aid. It s important to ensure that the families of these employees are not left vulnerable during such an absence. Effective communication between the employer, employee, and family can be a significant factor in reducing anxiety for family members at home. Employees that may be activated during a continuity event should ensure that provisions and resources are available for their families. Most municipalities have the emergency response part of a disaster down to a science, but it is the continuing function of government operations that may set a community back. There are costs associated with a prolonged shutdown financial costs as well as decreased morale and a tarnished reputation. Such costs can be minimized with effective continuity planning. It s worthwhile to take an honest look at your operation s risks and take steps now to reduce them before an emergency cripples your organization. MUNICIPAL ADVOCATE Vol. 26, No. 3 21