Prepared by Rod Davis, ABCP, MCSA November, 2011

Similar documents
Temple university. Auditing a business continuity management BCM. November, 2015

BUSINESS CONTINUITY PLAN OVERVIEW

Intel Business Continuity Practices

Building Economic Resilience to Disasters: Developing a Business Continuity Plan

Business Impact Analysis (BIA) and Risk Mitigation

Business Continuity Management

BUSINESS CONTINUITY PLANNING GUIDELINES

Ohio Supercomputer Center

Continuity of Operations Planning. A step by step guide for business

BUSINESS CONTINUITY POLICY

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

This presentation will introduce you to the concepts and terminology related to disaster recovery planning for businesses.

RLI PROFESSIONAL SERVICES GROUP PROFESSIONAL LEARNING EVENT PSGLE 125. When Disaster Strikes Are You Prepared?

Business Continuity Planning for Schools, Departments & Support Units

Desktop Scenario Self Assessment Exercise Page 1

NCUA LETTER TO CREDIT UNIONS

Business Continuity Planning. Donna Curran, Director Audit and Risk Management February, 2014

Business Continuity and Disaster Recovery Planning

Kick Starting your Business Continuity Program

Threats and Hazards: Event Challenges and Impacts. Event Disruptions Are Always A Possibility Planning Is the Key to Surviving Them

Business Continuity Plan

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

Why Should Companies Take a Closer Look at Business Continuity Planning?

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Business Continuity Management. Dan Warnock, CSP, CFPS, ALCM Risk Control Manager Senn Dunn Insurance

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

Business Continuity Planning for Risk Reduction

Disaster Recovery Plan

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

Business Continuity and Disaster Recovery Planning 3/16/2011. Lee Goldstein CPCP, MBCI President Business Contingency Group

Business Continuity and Disaster Recovery Planning from an Information Technology Perspective

Business Continuity Planning Guide

BUSINESS CONTINUITY MANAGEMENT IN THE PUBLIC SECTOR A ROUGH GUIDE

Risk Assessment Guide

Chapter 1: An Overview of Emergency Preparedness and Business Continuity

TO AN EFFECTIVE BUSINESS CONTINUITY PLAN

Business Continuity Planning. Presentation and. Direction

CRITICAL INFRASTRUCTURE PROTECTION BUILDING ORGANIZATIONAL RESILIENCE

Overview of Business Continuity Planning Sally Meglathery Payoff

DASTA Guide to Business Continuity (BC) and Disaster Recovery (DR) Planning

Disaster Recovery Plan Checklist

Unit Guide to Business Continuity/Resumption Planning

Emergency Response and Business Continuity Management Policy

Establishing A Secure & Resilient Water Sector. Overview. Legislative Drivers

How To Handle An Emergency

Business Continuity & Disaster Recovery

Assessment of natural hazards, man made hazards, technical and societal related risks and associated impact.

Business Continuity Management

Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP)

Disaster Preparedness & Response

Draft 8/1/05 SYSTEM First Rev. 8/9/05 2 nd Rev. 8/30/05 EMERGENCY OPERATIONS PLAN

Business Continuity Planning and Disaster Recovery Planning

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Business, Resiliency and Effective Disaster Recovery. Anne Kleffner, PhD Haskayne School of Business, University of Calgary

South West Lincolnshire NHS Clinical Commissioning Group Business Continuity Policy

Information Security Management: Business Continuity Planning. Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt.

Table of Contents... 1

FORMULATING YOUR BUSINESS CONTINUITY PLAN

IF DISASTER STRIKES IS YOUR BUSINESS READY?

Company Management System. Business Continuity in SIA

Coping with a major business disruption. Some practical advice

Guideline on Business Continuity Management

From Big Data to Rich Data How Data Analytics Add Value to Security Risk Management. Patrick Hennies, Rainer Rex 15th European ASIS, 04/08/2016

Hong Kong Baptist University

Information Security Management System. Business Continuity and Disaster Recovery Plan Policy. The Smart Cube. Description Change

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Disaster Recovery. 1.1 Introduction. 1.2 Reasons for Disaster Recovery. EKAM Solutions Ltd Disaster Recovery

Beyond Effective Security. The Art and Science of Business Continuity Planning

Business Continuity and Disaster Survival Strategies for the Small and Mid Size Business.

Business Resiliency Business Continuity Management - January 14, 2014

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

BUSINESS IMPACT ANALYSIS.5

The Supply Chain and Business Continuity: Preparing to Survive the Next Disaster

Business Continuity Planning Instructions

National Fire Protection Association s Contribution to Business Continuity Strategies

How to Design and Implement a Successful Disaster Recovery Plan

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Disaster and Pandemic Planning for Nonprofits. Continuity and Recovery Plan Template

Performance Indicators for Disaster Recovery

Business Continuity Overview

NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00)

Building a strong business continuity plan

Developing a Business Continuity Plan... More Than Disaster

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP

Lessons Learned from a Basic Vulnerability Assessment and Emergency Response Plan Update Project in Greensboro

Interactive-Network Disaster Recovery

ITMF Disaster Recovery and Business Continuity Committee Report for the UGA IT Master Plan

Release: 1. BSBCON601B Develop and maintain business continuity plans

Business Continuity and Disaster Planning

Transcription:

Prepared by Rod Davis, ABCP, MCSA November, 2011

Disaster an event, which causes the loss of an essential service, or part of it, for a length of time which imperils mission achievement. (Andrew Hiles, Business : Best Practices) Rationale for Business Planning

If a terrorist attack targeted a major overseas center? If an ice storm struck a data center rendering several critical IT services unavailable? If an unsecured data server, workstations, and other equipment were confiscated from an overseas center? If a laptop carrying unencrypted data were stolen, potentially compromising personnel and projects? Rationale for Business Planning

The occurrence of some events could cause a temporary disruption of mission-critical services. Some scenarios could actually result in long-term loss of mission-critical capacity. The unthinkable might include disruption or shutdown of programs that these services and capacity support. Rationale for Business Planning

Organizations that experience major data loss without disaster recovery plans* Survive long-term 6% Close within two years 51% Never reopen 43% * Cummings, Haag, & McCubbrey (2005). Management Information Systems for the Information Age. Rationale for Business Planning

Business Planning Crisis Management Emergency Management Disaster Recovery Planning Business Planning

Business Planning a management approved strategic and comprehensive capability of an organization to plan for and respond to events and conditions in order to continue business operations*. It is the most proactive risk management discipline. * The International Consortium for Organizational Resilience, CS SS BCM 3030

6.) Business Plan Maintenance 1.) Risk Assessment 5.) Training, Testing & Auditing 2.) Business Impact Analysis 4.) Business Plan Development 3.) Risk Mitigation Strategy

Risk Assessment Natural/Environmental Threats Fire Flood Hurricane Winter storm Pandemics Tornado Lightning Drought Earthquake Volcano Tsunami Human Threats Fire (accidental or arson) Cyber-attack Data theft or loss Terrorist attack Sabotage/Vandalism Workplace violence Civil unrest & war Chemical or biological hazard Infrastructure Threats Power grid failure Petroleum supply disruption Food or water contamination Public utility failure (water, sewer, etc.) Heating/Cooling system failure (affects IT & people) Public transport disruption Assess the threat landscape and determine relevant threats.

Risk Assessment Threat Assessment Determine the most relevant threats; i.e., pick from the list which threats you should evaluate. Probability Assessment High frequency of electrical storms = high probability of lightning strike. Vulnerability Assessment Lack of lightning rod or surge protection = high vulnerability to a lightning strike.

Business Impact Analysis A process designed to identify and quantify impacts resulting from disruptive events and disaster scenarios. Results include: List of mission-critical functions, processes, & roles; Recovery priorities and their interdependencies Recovery Time Objectives (RTOs) for these priorities

Business Impact Analysis Create a list of the mission s functional areas. Assemble subject matter experts. Identify missioncritical functions, processes, and roles. Identify any external/ internal dependencies. Establish the Maximum Tolerable Outage. Determine the impact on mission of outage.

Risk Mitigation Strategy HR records, IT Recovery Documentation, Corporate Databases Network Operations, Essential IT Dependencies Protect Data and Operations Essential to Recovery Voice & Data Communications Networks

Risk Mitigation Strategy Work at home for key employees Alternate site for missioncritical IT operations Determine Recovery Options Alternate work-site

Business Plan Development Priorities Response and Recovery Vital Records, Databases, IT Services Teams Designated Roles and Responsibilities Contact Information Procedures Recovery of Mission-Critical IT Services Replacement of Critical Equipment Criteria Plan Activation: Transition Point from Emergency Response to Plan Activation Declaration: Disruptive Event to Disaster

Business Plan Development Plan should designate teams, roles, responsibilities; Plan should include actions required on a timeline basis response, recovery, & restoration; Particular attention should be given to protection and restoration of mission-critical processes and services.

Training, Testing & Auditing Testing Tests Information Technology & Telecommunications dependencies to find design flaws Exercises Reveals potential points of failure in the Business Plan Training Develops familiarity with the Business Plan and competence in its execution. Business Plan

Business Plan Maintenance Modify Business Plan Establish Audit Points to Monitor Feedback to Business Coordinator Monitor Exercises & Tests

Business Planning is... Project Initiation project oriented ongoing Business Plan Maintenance Risk Assessment multi-phased Training, Testing, Auditing Business Impact Analysis requires testing Business Plan Development Mitigation Strategy Development iterative