BUSINESS CONTINUITY PLANNING



Similar documents
Business Continuity Planning for Schools, Departments & Support Units

OREGON STATE UNIVERSITY MASTER EMERGENCY MANAGEMENT PLAN

UNION COLLEGE SCHENECTADY, NY EMERGENCY MANAGEMENT PROCEDURES

Page Administrative Summary...3 Introduction Comprehensive Approach Conclusion

Business Continuity & Disaster Recovery

Cornell University EMERGENCY MANAGEMENT PROGRAM

JOB ANNOUNCEMENT. Chief Security Officer, Cheniere Energy, Inc.

Information Services IT Security Policies B. Business continuity management and planning

All-Hazard Continuity of Operations Plan. [Department/College Name] [Date]

Identify and Protect Your Vital Records

Western Washington University Basic Plan A part of Western s Comprehensive Emergency Management Plan

Continuity of Operations Plan Template

PBSi Business Continuity Planning

Cornell University RECOVERY PLAN

Business Continuity Planning (800)

Desktop Scenario Self Assessment Exercise Page 1

Stetson University College of Law Crisis Communications Plan

INFORMATION SECURITY STRATEGIC PLAN

BUSINESS CONTINUITY POLICY

Department of Defense INSTRUCTION. Reference: (a) DoD Directive , Defense Continuity Programs (DCP), September 8, 2004January 9, 2009

PUBLIC HEALTH EMERGENCY RESPONSE PLAN

The PNC Financial Services Group, Inc. Business Continuity Program

Office of Homeland Security

Water Critical Infrastructure and Key Resources Sector-Specific Plan as input to the National Infrastructure Protection Plan Executive Summary

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES

Emergency Operations California State University Los Angeles

Business Resiliency Business Continuity Management - January 14, 2014

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard

CISM Certified Information Security Manager

Emergency Response Plan

ANNEX W OVERARCHING ACADEMIC/BUSINESS CONTINUITY PLAN (OA/BCP)

University of California Santa Cruz EMERGENCY RESPONSE PLAN

State of Utah Emergency Operations Plan. APPENDIX #1 TO ESF #11 Cultural Property

UCF Office of Emergency Management Strategic Plan

BUSINESS CONTINUITY PLAN. Specific Issues for Public Health Emergencies. Guidelines for Air Carriers

The PNC Financial Services Group, Inc. Business Continuity Program

TEXAS HOMELAND SECURITY STRATEGIC PLAN : PRIORITY ACTIONS

BRYN MAWR COLLEGE EMERGENCY RESPONSE PLAN Revised 1/2016 (abridged)

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

Subject: Critical Infrastructure Identification, Prioritization, and Protection

THE WHITE HOUSE. Office of the Press Secretary. For Immediate Release February 12, February 12, 2013

Overview of Business Continuity Planning Sally Meglathery Payoff

BRYN MAWR COLLEGE EMERGENCY RESPONSE PLAN Revised 3/17/08 (abridged)

Success or Failure? Your Keys to Business Continuity Planning. An Ingenuity Whitepaper

December 17, 2003 Homeland Security Presidential Directive/Hspd-7

NAIT Guidelines. Implementation Date: February 15, 2011 Replaces: July 1, Table of Contents. Section Description Page

Continuity Planning and Disaster Recovery

Hospital Emergency Operations Plan

UNLV Programs in Crisis and Emergency Management FALL, 2016 Admissions Information

Continuity of Operations Actions

Business Continuity Planning Toolkit. (For Deployment of BCP to Campus Departments in Phase 2)

Pandemic Preparedness Plan

Unit Guide to Business Continuity/Resumption Planning

Utica College. Information Security Plan

Table of Contents ESF

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Lessons from Defending Cyberspace

NASCIO 2014 State IT Recognition Awards

BUSINESS CONTINUITY PLANNING GUIDELINES

Why Should Companies Take a Closer Look at Business Continuity Planning?

Guidelines 1 on Information Technology Security

Mt. San Antonio College Campus Emergency Response and Evacuation Plan

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) Fax: (718)

How To Manage Information Security At A University

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

Business Continuity Plan

Creating a Business Continuity Plan for your Health Center

Ohio Homeland Security Strategic Plan

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

Draft 8/1/05 SYSTEM First Rev. 8/9/05 2 nd Rev. 8/30/05 EMERGENCY OPERATIONS PLAN

Emergency Support Function 14 Long-Term Community Recovery and Mitigation

EMERGENCY RESPONSE PLAN SUMMARY PRESENTATION

v. 03/03/2015 Page ii

Chapter I: Fundamentals of Business Continuity Management

Business Continuity Plan (BCP)

U.S. Fire Administration. The Critical Infrastructure Protection Process Job Aid

Emergency Management Plan

Business Continuity and Disaster Planning

PART 2 LOCAL, STATE, AND FEDERAL EMERGENCY RESPONSE SYSTEMS, LAWS, AND AUTHORITIES. Table of Contents

BUSINESS IMPACT ANALYSIS.5

ANNEX J INSTITUTIONAL CONTINUITY PLAN

Federal Emergency Preparedness and Response System

University Emergency Management Plan

Emergency Response and Business Continuity Management Policy

UNIVERSITY OF CALIFORNIA, MERCED EMERGENCY NOTIFICATION SYSTEM (UCMAlert)

Subject: Internal Audit of Information Technology Disaster Recovery Plan

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Business Continuity Planning and Disaster Recovery Planning

LAWRENCE COUNTY, KENTUCKY EMERGENCY OPERATIONS PLAN ESF-13

Transcription:

Policy 8.3.2 Business Responsible Party: President s Office BUSINESS CONTINUITY PLANNING Overview The UT Health Science Center at San Antonio (Health Science Center) is committed to its employees, students, patients and stakeholders to ensure the availability of essential services, including teaching, research, health care and community service activities, in the event of an operational disruption, or an adverse, major or catastrophic event (e.g., environmental disasters, equipment or system failures, loss of facilities or utilities, and/or deliberate acts of disruption). This policy is in support of a comprehensive program for business continuity, disaster prevention and total business recovery. Business continuity, disaster recovery, and contingency plans are required by some federal and state regulatory agencies to meet various program requirements and accreditation certifications. The Health Science Center takes into consideration all of these regulatory requirements in its overall Business Continuity Plan. The business continuity planning process is an ongoing process that includes business recovery, disaster recovery, business resumption, contingency planning, and crisis management planning. Policy In order for the Health Science Center to resume its operations within a reasonable period of time following any event or disruption, each critical functional support department and business unit will have a Business Continuity Plan. This plan may be unit specific or may be part of a larger entity-level plan. For mission critical activities, particularly those relying heavily on information technology, the institution s Business Team will conduct a business impact analysis and a risk assessment. Business Continuity Plans will be reviewed and updated annually, or as critical processes change. The plans will be approved by the appropriate unit management. Each unit management will also certify annually that the Business Continuity Plan has been reviewed, tested and employees have been trained on the Plan. In addition, each mission critical plan will be certified annually through the institution s Business Team. Executive leadership will have final accountability for unit plans and stewardships of resources. Page 1 of 5

Policy 8.3.2 Business Responsible Party: President s Office All Business Continuity Plans will be stored in a central repository to ensure they are readily available to institutional leadership and the Business Team during an event. Definitions All-Hazards: An approach for mitigation, prevention, preparedness, response, and recovery that addresses a full range of threats and hazards, including domestic terrorist attacks, natural and man-made disasters, accidental disruptions and other emergencies. Business Continuity Plan: The documentation of a predetermined set of instructions or procedures that describe how the institution s business functions and units will be sustained during and after a significant event or disruption. Business : The strategic act of planning an event or preventing, if possible, and minimizing and managing the consequences of an event that interrupts critical business processes. The process includes development of advance arrangements and procedures that enables the Health Science Center to respond to an interruption in such a manner that critical business functions continue with planned levels of interruption or essential change. Business Impact Analysis: Involves the identification of critical business functions and workflows; identifies critical information resources; determines the qualitative and quantitative impact of a disruption; and, prioritizes recovery objectives. Mission Critical Activities: Any significant operational and/or business support activities, either provided internally or externally, without which the Health Science Center would be unable to achieve its objectives. Also, any supported health care delivery activity, which, if interrupted, could result in a life and safety event for patients. Risk Assessment: A systematic and analytical approach that identifies and assesses risk to business processes and provides recommendations to avoid or reduce risk. Unit: Critical functional areas for business continuity planning and business resumption activities, such as a Health Science Center Page 2 of 5

Policy 8.3.2 Business Responsible Party: President s Office institute, center, department or other areas that have some operational function within the institution. Business Continuity Planning Team The Business Team is composed of individuals who are trained in and understand business continuity planning and emergency management. The Team has overall responsibilities for any emergencies or disruption of services. Responsibilities include: Developing strategies and coordinating the development of the Business Continuity Plan and keeping the Plan updated. Conducting business impact analyses and risk assessments. Approving unit business continuity plans. Conducting training for responding and recovery during an event or disaster. Ongoing responsibilities for business continuity plan maintenance, testing and exercising. Serving as the response management team, in coordination with the President s Office, for major or catastrophic incidents involving business continuity and continuing of academic, research, patient care, and administrative operations in the event of an emergency. Providing communication updates to the President s Office and campus community during an incident. Business Continuity Planning Team Members The Business Team members work in coordination with the President, or his designee, the Senior Executive Vice President and Chief Operating Officer. The Team is composed of leadership with expertise in law enforcement, safety, information technology systems, communication, and business processes and functions. The Team will be composed of the following individuals: Senior Executive Vice President and Chief Operating Officer Page 3 of 5

Policy 8.3.2 Business Responsible Party: President s Office Executive Vice President for Facility Planning and Operations Vice President and Chief Information Officer Vice President for Academic, Faculty and Student Affairs Assistant Vice President for Strategic Planning & Institutional Analysis, Chair Assistant Vice President for Business Affairs Assistant Vice President for Environmental Safety Assistant Vice President for Facilities Chief of University Police Senior Executive Director of Communications Senior Director for Information Security & Operations Director for Laboratory Animal Resources Senior Manager, Systems Planning & Engineering Project Coordinator, Strategic Planning & Institutional Analysis Departmental Responsibilities Academic, research, health care and business continuity planning plays a vital role in the all-hazards disaster preparedness approach for the Health Science Center. It is through the Business process the University units will develop the necessary understanding of their core processes and interdependencies required for an effective prevention of and response to operational disruptions or adverse events. The Health Science Center s policy is that each Executive Committee member and their respective units will be responsible for the operational continuity in their respective areas of responsibility. The Executive Committee members and their respective areas of responsibility should plan and receive input from their faculty and staff for all aspects of Page 4 of 5

Policy 8.3.2 Business Responsible Party: President s Office critical functional operations. The institution will provide training and tools for the development of business continuity plans at the unit level. Each unit will provide a reasonable amount of time and resources towards developing their unit Business Continuity Plans, with oversight and direction from the Business Team. Plans will be updated annually, or as needed and periodic testing of the plan will be conducted with oversight from the Business Team. Major or Catastrophic Events In the event of a major or catastrophic event, University Police has jurisdiction in the investigation of any disaster occurring on-campus. University Police should be notified immediately so the President s Office and other appropriate officials may be alerted. Also, the Business Team will be activated and will notify and provide guidance to others affected by the event in accordance with the institution s Business Continuity Plan. The Office of Communications has the overall responsibility of providing the media with information about a major or catastrophic event. If necessary, any other interested individuals (e.g. employees, students, patients, etc.) will be notified in accordance with the communication plan included as part of the institutional Business Continuity Plan. Training Each department or unit will be responsible for training their employees on their Business Continuity Plans on an annual basis so all employees are ready to respond to and implement any recovery activities in the event of an operational disruption, or an adverse, major or catastrophic event. Page 5 of 5