BS 25999 Certification Essentials. Andrew Pettitt Business Continuity Senior Consultant SunGard Availability Services Professional Services

From this document you will learn the answers to the following questions:

What is one of the things the BCM Lifecycle does?

What does the BCM Lifecycle focus on?

What should Top management do to the issue of BCM strategy?

Similar documents
By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd

Business Continuity Management and BS by Steve Chan, Head of Training - HK, BSI Management Systems

Il nuovo standard ISO sulla Business Continuity Scenari ed opportunità

Proposal for Business Continuity Plan and Management Review 6 August 2008

Business Continuity Management

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY

Business Continuity Planning

Business Continuity Management

Business Continuity Management (BCM) Policy

Global Statement of Business Continuity

CHAPTER 1: BUSINESS CONTINUITY MANAGEMENT STRATEGY AND POLICY

INFORMATION ASSURANCE

Business Continuity Management Policy and Framework

Business Continuity. Is your Business Prepared for the worse? What is Business Continuity? Why use a Business Continuity Plan?

South Norfolk Council Business Continuity Policy

External Supplier Control Requirements BCM

NHS Central Manchester Clinical Commissioning Group (CCG) Business Continuity Management (BCM) Policy. Version 1.0

Business Continuity Management Policy

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

Tips and techniques a typical audit programme

Solihull Clinical Commissioning Group

Disaster Recovery Journal Spring World 2014

Community and Built Environment Localities and Safer Communities Business Continuity Management Policy Andrew Fyfe

Business Continuity - IT Disaster Recovery Discussion Paper - - Commercial in Confidence Version V2.0R Wednesday, 5 September 2012

Council Policy Business Continuity Management

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Business Continuity Management

TABLE OF CONTENTS...II EXECUTIVE SUMMARY... 3 DISCLAIMER... 4 REPORT STRUCTURE... 5 WORKSHOP DETAILS... 6 INTRODUCTION... 8 LEGISLATION...

University of Glasgow. Policy for. Business Continuity Management

DORSET & WILTSHIRE FIRE AND RESCUE AUTHORITY Performance, Risk and Business Continuity Management Policy

Business Continuity Policy and Business Continuity Management System

EMBEDDING BCM IN THE ORGANIZATION S CULTURE

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Business Continuity Planning

AVAILABILITY SERVICES RECOVERY SERVICES

Business Continuity Management Framework

Business Continuity Management Program Development Guide

Implementing and Auditing a Successful Business Continuity Plan

Staying In Business. A Business Continuity White Paper by. Paul O Brien and Gerard Joyce. LinkResQ Limited

BSO Board Director of Human Resources & Corporate Services Business Continuity Policy. 28 February 2012

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO AUDITS, CERTIFICATION AND TRAINING

Company Management System. Business Continuity in SIA

" # $% "%&$& Lesley Fayers Exercising the BCP workbook.doc Page 1 of 12

Business Continuity Management

Principles for BCM requirements for the Dutch financial sector and its providers.

FINRMFS9 Facilitate Business Continuity Planning and disaster recovery for a financial services organisation

ESKITP6034 IT Disaster Recovery Level 4 Role

NAVIGATING THROUGH A CATASTROPHIC DISASTER:

BUSINESS CONTINUITY MANAGEMENT POLICY

Emergency Response and Business Continuity Management Policy

abcdefghijklmnopqrstu

How to Exercise a Business Continuity Plan (BCP)

1.0 Policy Statement / Intentions (FOIA - Open)

Internal Audit Report. Corporate Services. Review of Business Continuity

Business Continuity Management For Small to Medium-Sized Businesses

Coping with a major business disruption. Some practical advice

BUSINESS CONTINUITY STRATEGY

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

Birmingham CrossCity Clinical Commissioning Group. Business Continuity Management Policy

Risk Management Guidelines

Business Continuity Management Policy

Business Continuity Policy

Business Continuity Management. Policy Statement and Strategy

Update from the Business Continuity Working Group

Business continuity management policy

IMPLEMENTING BUSINESS CONTINUITY MANAGEMENT IN A DISTRIBUTED ORGANISATION: A CASE STUDY

Disaster Recovery and Unstable Furniture

Recommendation Current Position and Explanation for Slippage: Target Dates:

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00)

ENVIRONMENTAL POLICY STATEMENT

HOW THE SCHOOL HAS IMPLEMENTED BUSINESS CONTINUITY MANAGEMENT. Andrew Webb Director of Business Continuity

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1

Business Continuity Policy

Aligning Disaster Recovery and Business Continuity to Business Objectives. Session E7 John Jackson Fusion Risk Management, Inc.

BCP and DR. P K Patel AGM, MoF

WILTSHIRE POLICE FORCE POLICY

ISO 22301: Societal Security Terminology ISO 22313: BCMS Guidance ISO 22398: Exercises and Testing - Guidance

Annex 1. Business Continuity Management Policy

Update from the Business Continuity Working Group

Checklist of ISO Mandatory Documentation

AVAILABILITY SERVICES MANAGED SERVICES

Bawden Contracting Services Ltd Job Profile. Contracts Manager. Purpose of the Job

South West Lincolnshire NHS Clinical Commissioning Group Business Continuity Policy

West Midlands Police and Crime Commissioner Records Management Policy 1 Contents

Sustainability through Business Continuity Management

Temple university. Auditing a business continuity management BCM. November, 2015

BUSINESS CONTINUITY POLICY RM03

Disaster Recovery. Hendry Taylor Tayori Limited

GUIDANCE DOCUMENT FOR COMPLETION OF RESIDENTIAL CARE ESTABLISHMENTS BUSINESS CONTINUITY PLAN TEMPLATE WEST MIDLANDS

How To Manage A Business Continuity Strategy

DORSET & WILTSHIRE FIRE AND RESCUE AUTHORITY Performance, Risk and Business Continuity Management Policy

NHS Durham Dales, Easington and Sedgefield Clinical Commissioning Group. Business Continuity Plan

NOT PROTECTIVELY MARKED BUSINESS CONTINUITY. Specialist Operations Contingency Planning Business Continuity Manager

BUSINESS CONTINUITY POLICY

Business Continuity (Policy & Procedure)

Making the business case for C4RISK databasebased Operational Risk Management software

Asset Management Strategy ( ) Doing things Differently A New Approach for a sustainable future

Business Continuity Management IT Disaster Recovery Green IT Information Security Crisis Management IT Service Management Quality.

Transcription:

BS 25999 Certification Essentials Andrew Pettitt Business Continuity Senior Consultant SunGard Availability Services Professional Services

Essentials Getting the fundamentals right Strategies - covering all the bases Implementation birth pains? Learning to walk then run Weaving continuity into the fabric of your organisation

BCM Lifecycle (BS25999) understanding the organisation exercising, maintenance and review BCM programme management determining BCM strategies developing and implementing a BCM response

Getting the fundamentals right? What to plan for? Business-type functions? Statutory obligations? Emergency-type activities? Silo approach evident in many organisations Approach to BC disjointed Left hand doesn t know what right hand is doing Wasteful Time-consuming

Jumping the gun Pharmaceutical Company IT Recovery Contracts in place understanding the organisation Workplace Recovery in place BUT exercising, maintenance and review BCM programme management determining BCM strategies No BIA completed No strategy development developing and implementing a BCM response

Jumping the gun BIA showed Inappropriate RTOs and RPOs for IT Existing recovery plans beyond capabilities of staff Fundamental misunderstandings of business processes at senior level Unnecessary expenditure Paying for a Ferrari solution Needed a motorbike-sidecar and a Transit van instead

Jumping the gun Understanding the organisation is fundamental to success of BC management understanding the organisation Shortcuts to implementation result in bad planning that won t work and expensive mistakes BS25999 exercising, maintenance and review BCM programme management determining BCM strategies Restates what we know anyway and yet is often ignored Top management should sign this off developing and implementing a BCM response External review can pick up mistakes BUT

Strategies covering all the bases People Continuity of core skills & knowledge Premises Where do you go? Technology Appropriate RTOs and RPOs Information Confidentiality, integrity, availability & currency Stakeholders Supplies Top management signs these off!

Suppliers Supplier dependencies Ignore them? understanding the organisation Accept vague assurances? Eliminate by bringing everything in-house? Carry out audit of their BCM? exercising, maintenance and review BCM programme management determining BCM strategies Mostly ignore or accept it ll be alright on the night Get them to use BS25999! developing and implementing a BCM response

Implementation Disaster Event! Overall recovery objective: Back to normal as quickly as possible Time Zero The Disaster Timeline Time Line Emergency Response Business Continuity Within minutes to hours: Staff & visitors accounted for Casualties dealt with Damage containment / limitation Damage assessment Invocation of BCP Within hours to days: Contact staff, customers, suppliers, etc. Recovery of critical business processes Rebuild lost work-in-progress Recovery - back to normal Within weeks to months: Damage repair / replacement Relocation to permanent place of work Recovery of costs from insurers SunGard Availability Services (UK) Ltd

Implementation Incident Management Plans Must be flexible, easy to use and understandable Continuity Plans Often over-complex Never mind the quality, feel the width Implementing your response Not just about plans People, technology, communications etc.

Walking then running Exercise Test Rehearse Practice Keep on doing it!!!

The BCM fitness cycle Develop Continuity Implement Update Live Test Update Train Update Exercise Audit BCP SunGard Availability Services (UK) Ltd

If you don t.. BCM atrophies It becomes mummified It s inaccurate, invalid, irrelevant BS25999 Audit and self assessment Suggested programme for exercising BCM strategies Dodgy Continuity presents: I used to be a Business Continuity Manager coming to a business near you

Weaving continuity into the fabric Tell people about it!!! Awareness training Skills training Leadership! Involve people! Build roles Give responsibilities Devolve Involve in testing

Going forward BS25999 provides level playing field Applicable to public, private and voluntary sectors Size doesn t matter Links with CCA 2004, Companies Act 2006 & FSA Guidelines Being adopted in many EU countries and further afield as a de facto standard Part 1 provides roadmap to improved BCM Can be used to enhance current BCM Incentive for senior management to take it more seriously Helps get buy-in within an organisation Window of opportunity prior to Part 2

Thank you