Evaluating and Improving Your Business Continuity Plan



Similar documents
Business Continuity and Disaster Recovery Planning

Temple university. Auditing a business continuity management BCM. November, 2015

MHA Consulting. Business Continuity Management 101

Business Resiliency Business Continuity Management - January 14, 2014

How To Plan A Crisis Management Program

Business Continuity Plan

Subject Area 1 Project Initiation and Management

2014 NABRICO Conference

BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION

Principles for BCM requirements for the Dutch financial sector and its providers.

Business Continuity Standards A Primer

National Fire Protection Association s Contribution to Business Continuity Strategies

Business Continuity and Disaster Recovery Planning 3/16/2011. Lee Goldstein CPCP, MBCI President Business Contingency Group

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

BUSINESS CONTINUITY PLAN OVERVIEW

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

The PNC Financial Services Group, Inc. Business Continuity Program

Business Continuity Planning for Water Utilities: Guidance Document [Project #4319]

Western Intergovernmental Audit Forum

Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke

Business Continuity and Disaster Recovery

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

BUILDING A SECURITY CONSCIOUS BUSINESS CONTINUITY MANAGEMENT (BCM) PROGRAM

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

RLI PROFESSIONAL SERVICES GROUP PROFESSIONAL LEARNING EVENT PSGLE 125. When Disaster Strikes Are You Prepared?

Business Continuity Planning (800)

Business Continuity (Policy & Procedure)

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

SCADA Business Continuity and Disaster Recovery. Presented By: William Biehl, P.E (mobile)

DRII PP Introduction to the Professional Practices Page 1

DRAFT BUSINESS CONTINUITY MANAGEMENT POLICY

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

Business Continuity Management

Business Continuity. Port environment

Business Continuity for the New Professional. Britt Corra Enterprise BCM Erika Voss Senior BCM

The PNC Financial Services Group, Inc. Business Continuity Program

Business Continuity Glossary

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

A BCP Tale: From Theory to Practice

Emergency Response and Business Continuity Management Policy

White Paper: ISO Business Continuity Management An Overview. ISO Business Continuity Management An Overview

Proposal for Business Continuity Plan and Management Review 6 August 2008

Business Continuity & Disaster Recovery

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

PBSi Business Continuity Planning

State of South Carolina Policy Guidance and Training

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Business Continuity Planning Preparing Your Organization

Business Continuity Management Program Development Guide

The ABC s of BCP. Jeremy Sucharski Governance Risk and Compliance G31

#316 The Security Elements of Business Continuity & Disaster Recovery Plans

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

External Supplier Control Requirements BCM

Disaster Recovery Planning

Loss Control Webcast. Disaster Recovery Planning we re not in Kansas anymore

Business Continuity and Crisis Management

Plan Development Getting from Principles to Paper

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES

Ohio Conference for Payroll Professionals Disaster Recovery

Assessment of natural hazards, man made hazards, technical and societal related risks and associated impact.

Table of Contents... 1

Moving from BS to ISO The new international standard for business continuity management systems. Transition Guide

Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).

Building and Maintaining a Business Continuity Program

The Role of Internal Audit In Business Continuity Planning

Beyond Disaster Recovery: Why Your Backup Plan Won t Work

Tips and techniques a typical audit programme

BUSINESS CONTINUITY POLICY

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

Protecting your Enterprise

Why Should Companies Take a Closer Look at Business Continuity Planning?

How To Prepare For A Disaster

PROFESSIONAL PRACTICES FOR BUSINESS CONTINUITY PRACTITIONERS

Business Continuity Management AIRM Presentation

Il nuovo standard ISO sulla Business Continuity Scenari ed opportunità

COMCARE BUSINESS CONTINUITY MANAGEMENT

Company Management System. Business Continuity in SIA

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning MARCH 2003 IT EXAMINATION H ANDBOOK

Creating a Business Continuity Plan for your Health Center

EMERGENCY MANAGEMENT PLANNING CRITERIA FOR AMBULATORY SURGICAL CENTERS

Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP)

Business Continuity in Healthcare

Staying In Business. A Business Continuity White Paper by. Paul O Brien and Gerard Joyce. LinkResQ Limited

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard

Business Continuity Planning for Schools, Departments & Support Units

Continuity of operations for critical infrastructure. Disclosure of critical information to the government.

HB A Practitioners Guide to Business Continuity Management

D2-02_01 Disaster Recovery in the modern EPU

Business Continuity Planning

Transcription:

Evaluating and Improving Your Business Continuity Plan As presented to the Northeast Florida IIA Chapter January 23, 2015

Contact Information Karen Weir, MAC, CISA, CBCP Manager kweir@accretivesolutions.com Jennifer Hensley Client Development jhensley@accretivesolutions.com p 904-208-5607 Accretive Solutions 76 South Laura St., Suite 202 Jacksonville, FL 32202 www.accretivesolutions.com 1

Agenda 1. Business Continuity Overview 2. Industry Regulations 3. BCP Standards 4. Common Components 5. Determining Adequacy 2 2

Determine Adequacy 1. Determine your standard 2. Support your determination with facts, verify with management 3. Assess your organization s current BCP policies, process, and procedures 4. Measure and document perceived gaps 5. Formulate and present recommendations 3

4 Business Continuity Overview

Business Continuity is The method by which organizations can: Identify the likelihood and potential impact of unplanned business interruptions, Implement controls to prevent, alert, or mitigate effects of unplanned business interruptions, Recover critical functionality within an acceptable timeframe, and Restore full functionality to the organization, while suffering minimal downtime and revenue losses. 5

Business Interruption Examples Natural Events Hurricane* Tornado Fire/Flood Gas Leak/Explosion Power Outage H1N1 Corporate Image Scandal Product Recall Compliance Breach Man-Made, Intentional Terrorism* Sabotage Hacker/Virus Man-Made, Accidental Human Error Hazardous Spill/Leak Incident Response Program?

Common Factors/Any Organization Business Continuity Internal Control Framework (Policy & Procedure) Trained & Experienced Workforce Disaster Recovery Facilities (Building, Office Space, Machinery) Technology and Infrastructure (Applications, Servers, Databases) 7

Acronyms BCM Business Continuity Management BCP Business Continuity/Continuation Planning/Program EOC Emergency Operations Center ERP Emergency Response Plan BIA Business Impact Analysis ERT Emergency Response Team BRP Business Resumption Plan FEMA Federal Emergency Management Agency CMP Crisis Management Plan ICS Incident Command System CMT Crisis Management Team DAP Damage Assessment Plan DAT Damage Assessment Team DHS Department of Homeland Security DRP Disaster Recovery Plan MAD Maximum Acceptable/Allowable Downtime PRC Property Risk Control RPO Recovery Point Objective RTO Recovery Time Objective SCM Supply Chain Management 8

9 Industry Regulations

Regulated Industries - Examples Financial Services Insurance Energy Telecommunications Political & Public Affairs HealthCare Automotive Catalog Retail Market Research/Surveys Banking Mortgage Life & Health Property & Casualty Credit Card Utilities Service Provider? Cloud Service Provider? 10

Regulatory Bodies - Examples PCI (Payment Card Industry) Consumer Product Safety Commission Federal Trade Commission (FTC) Food and Drug Administration (FDA) Communications Commission (FCC) Fair Debt Collection Practices Act (FDCPA) Truth in Lending Act (TILA) Real Estate Settlement Procedures Act (RESPA) Health Insurance Portability and Accountability Act (HIPAA) Digital Millennium Copyright Banking Fair Credit Reporting Act Act (FRCA) Federal Financial Institutions Examination Council (FFIEC) 11

Rules and Regulations by Industry Disaster Recovery Journal website provides a comprehensive document that pulls together the DR/BCP regulations by affected industries: For these Industries Provides this Info on Regulations Banking & Finance Title Public Health & Healthcare Regulation / Standard (Reg, Stf) Transportation & Shipping Governing Body Energy (including nuclear) Country Industry Summary / Description Agriculture, Food Supply & Water Significant Dates, Fines, Penalties Information Distribution & Communications Category (Enf, Amb, Wat, IAI) Government & Public Agencies Notes /Comments Link www.drj.com 12

13 BCP Standards

BCP Standards Three standards currently recognized by DHS as part of the voluntary certification program: ANSI/ASIS SPC.1-2009 Organizational Resilience: Security, Preparedness, and Continuity Management Systems-Requirements with Guidance for Use; BS 25999-2:2007-A Specification for BCM; and NFPA 1600:2010 Standard on Disaster/Emergency Management and Business Continuity Programs 14

ANSI/ASIS SPC.1-2009 Organizational Resilience Process approach Understanding an organization s risk, security, preparedness, response, continuity, and recovery requirements; Establishing a policy and objectives to manage risks; Implementing and operating controls to manage an organization s risks within the context of the organization s mission; Monitoring and reviewing the performance and effectiveness of the organizational resilience management system; and Continual improvement based on objective measurement. 15

BS 25999-2:2007-A Specification for BCM By the British Standards Institution (BSI) Part 1 provides concept introduction/ guidance Ten (10) Sections, similar to DRJ/DRII Subject Areas Part 2 provides requirements for implementation, application, and continuous improvement of the BCM. Six (6) Sections, uses PDCA model of continuous improvement. Also in line with DRJ/DRII Subject Areas and GAP 16

NFPA 1600:2010 Standard on Disaster/Emergency Management and Business Continuity Programs Process approach Understanding an organization s risk, security, preparedness, response, continuity, and recovery requirements; Establishing a policy and objectives to manage risks; Implementing and operating controls to manage an organization s risks within the context of the organization s mission; Monitoring and reviewing the performance and effectiveness of the organizational resilience management system; and Continual improvement based on objective measurement. 17

My Starting Point Professional Practices for Business Continuity Practitioners: Joint effort of the Disaster Recovery Journal and the Business Continuity Institute based in the UK. Generally Accepted Practices (GAP) includes input and cooperation from: Association of Records Management Administration (ARMA) DRI International (DRII) Financial Services Technology Consortium (FSTC) Standards Australia/Standards New Zealand National Fire Protection Association (NFPA) 18

19 BCP Components

Ten Subject Areas 1. Program Initiation and Management 2. Risk Evaluation and Control 3. Business Impact Analysis 4. Business Continuity Strategies 5. Emergency Response and Operations 6. Business Continuity Plans 7. Awareness and Training Programs 8. Business Continuity Plan Exercise, Audit and Maintenance 9. Crisis Communications 10. Coordination with External Agencies 20

Program Initiation and Management Establish the need for Business Continuity Management Business Continuity Policy Obtain management support and project approval Program Champion 21

Risk Evaluation and Control Identify Potential Exposures/Risks Qualify and Prioritize Identify Controls and Safeguards Evaluate Effectiveness Prioritized Approved by Management Quantified, both in probabilities and potential impacts Corp. Scandal Flood Random Violence Risk Assessment 22

Business Impact Analysis Identify the impacts of interruptions Identify time-critical functions Identify interdependencies Prioritize Time Systems Key People Facility Needs RTO: Recovery Time Obj. RPO: Recovery Point Obj. Applications Alternative work-arounds Cross-training recommendations Back-ups Alternate Office Space, Laptops 23

24 BIA Exercise

Business Continuity Strategies Determine organizational needs Determine functional/ departmental needs Identify and Present Solutions to meet both Guiding Decisions Go/No-go circumstances Facilities Secondary/Tertiary Office Space Relocation 25

Emergency Response and Operations Identify Potential Emergencies and Responses Review Evacuation Plans Command and Control Procedures (Alternate Hierarchy) Emergency Response Plan(s) Communication Plan Roles and Responsibilities 26

27 Emergency Response Exercise

Business Continuity Plans Identify Plan Requirements Strategic Tactical Operational Assumptions & Scenarios BC Plan Hurricane Prep, for example Disaster Recovery Critical Functions Recovery Procedures Warning Signs 1-800 Employee Communication Line Info Alternate Facility Prioritized System Recovery 28

Awareness and Training Programs Corporate Awareness Programs Emergency Responder Training (CPR, Fire Extinguisher, etc.) Functional & Technical (Practice) Training Calendar Schedules Specialized First Responder Training Schedule Periodic Awareness Messages for Employee Base 29

Business Continuity Plan Exercise, Audit and Maintenance Exercise/Testing Program Plan Maintenance Program Business Continuity Audit Process Communicate Exercise/Test Results Diagram by Karn G. Bulsuk (http://www.bulsuk.com) 30

31 BCP Exercises

Crisis Communications Crisis Communications Program Escalation procedures Roles and Responsibilities Audience groups and messages Crisis Communication Plan ID Designated Speaker(s) Scripts Development By situation Internal/External Media Relationships 32

Coordination with External Agencies Coordinate Emergency Management with External Agencies Identify relevant external agencies (Police Department, Fire & Rescue) Identify statutory requirements Involve external agencies as appropriate Review plans & recommend improvements Participate in exercises Provide training 33

34 Determining Adequacy

Review and Evaluation 1. For each subject area, determine what is appropriate for your organization 2. Support your determination with facts, verify with management 3. Assess your organization s current policies, process, and procedures 4. Document perceived gaps 5. Formulate recommendations 35

36 36 Questions?