Central Bank of India. Business Continuity Management Policy



Similar documents
PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Overview TECHIS Manage information security business resilience activities

Coping with a major business disruption. Some practical advice

Board of Directors Meeting 12/04/2010. Operational Risk Management Charter

The PNC Financial Services Group, Inc. Business Continuity Program

Business Continuity Planning and Disaster Recovery Planning

DATA RECOVERY SOLUTIONS EXPERT DATA RECOVERY SOLUTIONS FOR ALL DATA LOSS SCENARIOS.

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

Business Continuity Management

Desktop Scenario Self Assessment Exercise Page 1

Business Resiliency Business Continuity Management - January 14, 2014

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) Fax: (718)

Business Continuity and Disaster Planning

The PNC Financial Services Group, Inc. Business Continuity Program

External Supplier Control Requirements BCM

Intel Business Continuity Practices

Operational Risk Management Policy

Application / Hardware - Business Impact Analysis Template. MARC Configuration Requirements. Business Impact Analysis

The Business Continuity Maturity Continuum

BUSINESS CONTINUITY MANAGEMENT IN THE PUBLIC SECTOR A ROUGH GUIDE

What is Business Continuity Planning (BCP) / Disaster Recovery Plan(DRP)?

ESKITP Manage IT service delivery performance metrics

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY

ISO 22301: Societal Security Terminology ISO 22313: BCMS Guidance ISO 22398: Exercises and Testing - Guidance

IT Services Management Service Brief

BUSINESS IMPACT ANALYSIS

Information Security Management: Business Continuity Planning. Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt.

ESCB definitions of major business continuity terms in relation to payment and securities settlement systems 1

Monetary Authority of Singapore BUSINESS CONTINUITY MANAGEMENT GUIDELINES

Business Continuity Management Policy

BCP and DR. P K Patel AGM, MoF

Table of Contents... 1

Aberdeen City Council IT Disaster Recovery

Guideline - Business Continuity Plan

Managing business risk

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Transition and Transformation. Transitioning services with minimal risk

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

Why You Should Consider Cloud- Based Archiving. A whitepaper by The Radicati Group, Inc.

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Business Continuity and Disaster Recovery Planning

Business Continuity. Is your Business Prepared for the worse? What is Business Continuity? Why use a Business Continuity Plan?

Service Availability Metrics

CRISC Glossary. Scope Note: Risk: Can also refer to the verification of the correctness of a piece of data

Skelta BPM and High Availability

Business Continuity Management Group Policy

Business Continuity Management Policy

COL FINANCIAL GROUP, INC. RISK MANAGEMENT SYSTEM

Risk Management Policy and Framework

Advisory Guidelines of the Financial Supervisory Authority. Requirements regarding the arrangement of operational risk management

Why Should Companies Take a Closer Look at Business Continuity Planning?

Documentation. Disclaimer

Architecture Principles

Qulliq Energy Corporation Job Description

Risk Management How to manage your brand & build business resilience to improve your bottom line

NHS 24 - Business Continuity Strategy

Business Continuity Management

Disaster Management and Business Continuity Plan for Bankers

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity

MAILGUARD LIVE. Continuity. Trust the innovator to simplify cloud security

DIXIT INFOTECH SERVICES

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Sustainability through Business Continuity Management

Business Continuity Planning for Schools, Departments & Support Units

Incident Management & Communications. Top 8 Focus Areas to Mitigate Risk

2014 NABRICO Conference

RISK MANAGEMENT AND COMPLIANCE

Managed IT Services. Eliminating technology pains in small businesses

Managed IT Services. Eliminating technology pains in small businesses

IT Service Continuity Management PinkVERIFY

SAFETY FIRST. Emerging Trends in IT Disaster Recovery. By Cindy LaChapelle, Principal Consultant.

Disaster Recovery. Stanley Lopez Premier Field Engineer Premier Field Engineering Southeast Asia Customer Services and Support

NOS for Network Support (903)

Business Continuity and Disaster Survival Strategies for the Small and Mid Size Business.

BS BUSINESS CONTINUITY MANAGEMENT

RSA ARCHER BUSINESS CONTINUITY MANAGEMENT AND OPERATIONS Solution Brief

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

Business Continuity Management

Datacenter Migration Think, Plan, Execute

The case for cloud-based data backup

ESKISP Direct security testing

Transcription:

Central Bank of India Business Continuity Management Policy DataCenter Version 1.0 February 2012

Table of Contents 1. Purpose... 3 2. Objective... 3 3. Scope... 4 4. Policy Statement... 4 5. Top Management Commitment... 4 Page 2 of 5

1. Purpose The Purpose of Business Continuity Management Policy is: To enable Central Bank Of India (henceforth referred as CBI) to provide continuity of critical IT Systems in the event of an emergency/disruption with minimal impact To enhance CBI s reputation by protecting interest of its key customers, stakeholders and employees by demonstrating a proactive attitude that will lead to continuity of operations/services even in the case of a disaster To ensure CBI s meets its all legal, regulatory and compliance requirements. 2. Objective The objective of Business Continuity Management Policy is to enable CBI in establishing organisational survival & continuity capability against emergency/disaster events thereby ensuring:- Profits and Shareholder Value are maintained and do not suffer significant deterioration Operations are not adversely affected, thus maintaining the quality of service to customers Customer expectations continue to be met, or managed, in such a way that customers are retained and new business opportunities met Reputation and image to stakeholders and the public are not negatively affected following business disruption Compliance to all regulatory guidelines( RBI) and directives is maintained Page 3 of 5

3. Scope The Business Continuity Management System applies to Central Bank of India Data Centre at Navi Mumbai and Disaster Recovery Centre at Hyderabad that includes CBS Systems, ATM Switch, Payment Systems, Treasury Servers, HRMS, Single Data Repository of Central Bank of India and Regional Rural Banks sponsored by Central Bank of India, for continuous and reliable services covering critical aspects of people, process and technology, supported through legal regulatory, facilities management and IT operations. The scope of Business continuity is limited to IT systems within Data Centre at Navi Mumbai and Disaster Recovery Centre at Hyderabad 4. Policy Statement CBI recognizes the strategic, operational, financial, and reputational and stakeholder support risks associated with the service interruptions and the importance of maintaining viable capability to continue CBI s business processes with minimum impact in event of an emergency. The CBI Business Continuity is applicable to all CBI staff, facility and IT systems in Data centre located at Belapur, Navi Mumbai. CBI shall be prepared for scenarios including, but not limited to natural disaster, power outage, and hardware and data availability. Day-to-day operational problems such as minor computer equipment malfunctions, data loss, and employee leave (like emergency medical/sick leave) are excluded as business continuity disasters in the context of this plan. 5. Top Management Commitment Top management shall guide, support and participate in the all phase of continuity assurance program as per the requirements. They shall assume the ownership for program success & outcome, and shall ensure adequate time & resources are committed to the development of the program. Resources could include both financial considerations and the effort of all personnel involved. The Business Continuity Management policy shall be reviewed at the time of any major change(s) in the existing IT infrastructure environment affecting policies and procedures or on an Annual basis, whichever is earlier. Page 4 of 5

It is the policy of the CBI to ensure that: 1. Program shall be owned by the Senior / Executive Management 2. Program shall be in alignment with the CBI s strategic objectives, priorities and requirements 3. Program shall ensure compliance to all legal/regulatory requirements applicable to CBI 4. Program shall be supported by well-defined organization structure with clear defined roles & responsibilities 5. All identified IT Systems shall be subjected to Business Impact Analysis (BIA) exercise to establish business recovery priorities and requirements 6. Business continuity risks shall be identified, assessed and treated for identified critical IT Systems, technology assets and supporting infrastructure elements 7. Continuity strategies shall be defined and implements for all identified business critical IT Systems, technology assets and supporting infrastructure elements based on established recovery requirements and risks exposure 8. Business Continuity & Disaster Recovery, and Emergency Management Plan shall be developed & maintained as part of the program 9. Detailed recovery procedures shall be documented and maintained for implemented recovery strategies 10. Identified teams/stakeholders shall be provided adequate training & support for fulfilling their roles & responsibilities 11. Plan owners shall be responsible to carrying out periodic test to ensure their plans are viable, effective and meet the recovery objective 12. All program components including processes, plans and other deliverables shall be reviewed periodically for changes, updates & improvement, and maintained 13. Periodic audits shall be conducted to ensure compliance to established program policy, framework and processes 14. All managers are responsible for implementing the policy within their areas of responsibility and own all resulting business continuity plans 15. Business continuity considerations shall be taken into consideration as part of all new projects implementations/rollouts Page 5 of 5