Desktop Scenario Self Assessment Exercise Page 1



Similar documents
Business Continuity Planning. Presentation and. Direction

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Table of Contents... 1

Business Continuity Planning for Risk Reduction

Business Continuity Planning and Disaster Recovery Planning

Why Should Companies Take a Closer Look at Business Continuity Planning?

Business Continuity and Disaster Planning

Temple university. Auditing a business continuity management BCM. November, 2015

Business Continuity Plan

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

Business Resiliency Business Continuity Management - January 14, 2014

Business Continuity Planning

London Borough of Merton

Business Continuity Management

NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00)

BUSINESS CONTINUITY PLAN

Intel Business Continuity Practices

Business Continuity Management

Business Unit CONTINGENCY PLAN

Business Continuity Planning (800)

Moving from BS to ISO The new international standard for business continuity management systems. Transition Guide

FlyntGroup.com. Enterprise Risk Management and Business Impact Analysis: Understanding, Treating and Monitoring Risk

PBSi Business Continuity Planning

An Introduction to. Business Continuity Planning

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

Business Continuity Management Policy

Information Services IT Security Policies B. Business continuity management and planning

Business Continuity Policy

Business Continuity Management

Business Continuity Planning Instructions

Business Continuity Planning in IT

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Three

Principles for BCM requirements for the Dutch financial sector and its providers.

Disaster Recovery Plan The Business Imperatives

Business Continuity and Disaster Survival Strategies for the Small and Mid Size Business.

Business Continuity and Disaster Recovery Planning from an Information Technology Perspective

Business Continuity and Disaster Recovery Planning 3/16/2011. Lee Goldstein CPCP, MBCI President Business Contingency Group

BUSINESS CONTINUITY STRATEGY

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY

BUSINESS CONTINUITY PLANNING

Company Management System. Business Continuity in SIA

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

This presentation will introduce you to the concepts and terminology related to disaster recovery planning for businesses.

Contingency Planning and Disaster Recovery for BOMA

Business Continuity Trends, Requirements and Expectations in Brian Zawada (MBCP) Director of Consulting Services Avalution Consulting

Developing a Business Continuity Plan... More Than Disaster

Guideline - Business Continuity Plan

Business Continuity Management AIRM Presentation

Emergency Response and Business Continuity Management Policy

Fundamentals of Business Continuity Planning Have a Plan!

Business Continuity Management

Business Continuity (Policy & Procedure)

Disaster Recovery. Stanley Lopez Premier Field Engineer Premier Field Engineering Southeast Asia Customer Services and Support

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

Business Continuity and Disaster Recovery Planning

Ohio Supercomputer Center

Taking a Proactive Approach to Crisis Management while Maintaining Business Continuity in a Tiered Environment

The PNC Financial Services Group, Inc. Business Continuity Program

Business Continuity, Risk Management & Pandemic Planning

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity

Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM

BUSINESS CONTINUITY PLAN. Specific Issues for Public Health Emergencies. Guidelines for Air Carriers

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Disaster Recovery. 1.1 Introduction. 1.2 Reasons for Disaster Recovery. EKAM Solutions Ltd Disaster Recovery

How to write a DISASTER RECOVERY PLAN. To print to A4, print at 75%.

Business Continuity and Disaster Recovery Planning

Disaster Recovery and Business Continuity What Every Executive Needs to Know

South West Lincolnshire NHS Clinical Commissioning Group Business Continuity Policy

ILLINOIS INSTITUTE OF TECHNOLOGY School of Applied Technology. Dave Wallenberg, Mario Russo and Batchum Mataruke Edited by Ray Trygstad

NHS Hardwick Clinical Commissioning Group. Business Continuity Policy

SCOPE; ENFORCEMENT; AUTHORITY; EXCEPTIONS

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

Prepared by Rod Davis, ABCP, MCSA November, 2011

Information Security Policy. Chapter 11. Business Continuity

Introduction UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT

Version: 3.0. Effective From: 19/06/2014

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

Building and Maintaining a Business Continuity Program

The PNC Financial Services Group, Inc. Business Continuity Program

Business Continuity Planning Guide

Virginia Commonwealth University School of Medicine Information Security Standard

19. Planning. 19 PLANNING p1

CISM Certified Information Security Manager

Business Continuity Glossary

TO AN EFFECTIVE BUSINESS CONTINUITY PLAN

London Borough of Bromley. Executive & Resources PDS Committee. Disaster Recovery Plans for London Borough of Bromley

Ohio Conference for Payroll Professionals Disaster Recovery

Clinic Business Continuity Plan Guidelines

BUSINESS CONTINUITY MANAGEMENT IN THE PUBLIC SECTOR A ROUGH GUIDE

Business Continuity Business Continuity Management Policy

Business Continuity Plan

Business Continuity Planning. Donna Curran, Director Audit and Risk Management February, 2014

HA / DR Jargon Buster High Availability / Disaster Recovery

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four

Ensure Absolute Protection with Our Backup and Data Recovery Services. ds-inc.com (609)

Business Continuity Management

DISASTER RECOVERY Steps You Need to Take (Before It s Too Late)

Transcription:

Page 1

Neil Jarvis Head of IT Security & IT Risk DHL Page 2

From reputation to data loss - how important is business continuity? Neil Jarvis Head of IT Security (EMEA) DHL Logistics IT Security Taking Care of Business Page 3

Objectives Understanding why we have Continuity and Disaster Recovery Planning Outline in Developing a Business Continuity Plan Any Other Questions? Page 4

Business Continuity Planning Planning to ensure the continuation of operations in the event of a catastrophic event. Business continuity planning goes beyond disaster recovery planning to include the actions to be taken, resources required, and procedures to be followed to ensure the continued availability of essential services, programs, and operations in the event of unexpected interruptions. Page 5

Why do we have Continuity and Disaster Recovery Planning? To protect our business and that of our customers To reduce unnecessary disruption of our work activities To fulfil our obligations to our clients To ensure if a problem occurs, in the Supply Chain or Client Production, we have a process to resolve the consequences. For us to plan for the unexpected! Page 6

Continuity Management Efficiency of Business Continuity Plan and Measures Proactive Measures Business Continuity Plan Event Crisis Management Reactive Measures Recovery time Contingency Plan Back to Normal Disaster Recovery Plan Recovery With Continuity Planning Business Continuity Recovery Without Continuity Planning time Page 7

Definitions Business Continuity Is managing the risks to business operations from disruptions. Business Continuity Planning: Is how a company prepares for future incidents that could jeopardize the Company and its long-term health. (Incidents include local incidents like building fires, regional incidents like earthquakes, or national incidents like pandemic illnesses) Business Continuity Plan: Documents how the company will recover and restore, partially or completely, interrupted critical function(s) within a predetermined time after a disaster or extended disruption. Continuity Management: Is the management process to help the development of Business Continuity Plans), Disaster Recovery Pans and ensuring that plans are matched, effective and tested. Disaster recovery Planning: Is the process of regaining access to the data, hardware/software and services necessary to resume critical business operations after a natural, accidental or human induced disaster. Disaster Recovery Plan: Documents how access to data, hardware/software and services necessary to resume critical business operations, after a disaster, will be undertaken to achieve the requirements of the Business, (as defined in the Business Continuity Plan). Page 8

Definitions Recovery Time Objective The period from when a disaster is declared to full recovery of critical functions. How long can the operation function without the system. This may require operations to be switched to standalone or paper based processes. The Business Continuity Plan must define the systems which must be restored and the timescale for restoration Recovery Point Objective The point in time to which data must be restored in order to resume processing. The Business Continuity Plan must define the amount of data that is required for the operation to continue after a disaster. Maximum Tolerable Downtime The maximum period for which the system can be down before there is a significant impact on the business Page 9

Business Continuity Process Assess - identify and triage all threats (BIA) Evaluate - assess likelihood and impact of each threat Prepare plan for contingent operations Mitigate - identify actions that may eliminate risks in advance Respond take actions necessary to minimize the impact of risks that materialize Recover return to normal as soon as possible Page 10

Business Impact Assessment Identify critical systems, processes and functions; Establish an estimate of the maximum tolerable downtime (MTD) for each business process Assess the impact of incidents that result in a denial of access to systems, services or processes; and, Determine the priorities and processes for recovery of critical business processes Page 11

BIA Review Factors Likelihood of Occurrence Impact of Outage on Operations System Interdependence Revenue Risk Personnel and Liability Risks Page 12

Risk Analysis Matrix High Medium Low Low Medium High Area of Major Concern Severity of Consequence Page 13

Prioritise Risk Factors Personal Safety Risk Services Risk Operational Risk Revenue Risk Liability Risk Good Will (Societal) Risk Page 14

It s Not Enough Just to Plan Use focus groups and brainstorming Seek what can go wrong Find alternate plans & manual work arounds Find innovative solutions to risks Contingency plans must be exercised Hold table top exercises for disasters Conduct fire drills of plans Train staff for action during emergencies Page 15

Scenario Testing Develop various scenarios and test your plans against these Don t develop plans specifically for scenarios Page 16

Other Thoughts Functionality - provides an acceptable level of service Practicality - is reasonable in terms of the time and resources needed to acquire, test, and implement the plan Cost Benefit - cost is justified by the benefit to be derived from the plan Page 17

Any Other Questions? Page 18

Page 19