Business Continuity Planning (BCP) 101



Similar documents
Introduction to Business Continuity Planning

Business Continuity Management Planning Methodology

Crisis Communication and Management: Lessons from Some Recent Crises/ Disasters

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

The Resilient IT Infrastructure

Business Continuity Plan

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Principles for BCM requirements for the Dutch financial sector and its providers.

University of Glasgow. Policy for. Business Continuity Management

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity

Emergency Response and Business Continuity Management Policy

Business Continuity for the New Professional. Britt Corra Enterprise BCM Erika Voss Senior BCM

BCP and DR. P K Patel AGM, MoF

Tips and techniques a typical audit programme

ISO BUSINESS CONTINUITY MANAGEMENT SYStEMS (BCMS) EXPERT IMPLEMENTER

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Management. Policy Statement and Strategy

BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION

Business Continuity Management Policy

Business Continuity (Policy & Procedure)

Business Continuity Management Framework

1.0 Policy Statement / Intentions (FOIA - Open)

Information Services IT Security Policies B. Business continuity management and planning

Business Continuity Management

IT DISASTER RECOVEry

Overview TECHIS Manage information security business resilience activities

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Business Continuity Management

CHAPTER 1: BUSINESS CONTINUITY MANAGEMENT STRATEGY AND POLICY

Subject Area 1 Project Initiation and Management

Preparing for the Convergence of Risk Management & Business Continuity

Business Continuity - IT Disaster Recovery Discussion Paper - - Commercial in Confidence Version V2.0R Wednesday, 5 September 2012

De Nederlandsche Bank N.V. May Assessment Framework for Financial Core Infrastructure Business Continuity Management

State of South Carolina Policy Guidance and Training

#316 The Security Elements of Business Continuity & Disaster Recovery Plans

Business Continuity Planning (800)

Introduction UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT

Temple university. Auditing a business continuity management BCM. November, 2015

Standard for Business Continuity/Disaster Recovery (BC/DR) Service Providers

Information Security ISO Standards. Feb 11, Glen Bruce Director, Enterprise Risk Security & Privacy

Business Continuity Policy

IRM CERTIFICATE AND DIPLOMA OUTLINE SYLLABUS

Information Security Policy. Chapter 11. Business Continuity

Business Continuity Management Software

Business Continuity Policy

HB A Practitioners Guide to Business Continuity Management

International Diploma in Risk Management Syllabus

Birmingham CrossCity Clinical Commissioning Group. Business Continuity Management Policy

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four

Business Continuity Management Policy

Monetary Authority of Singapore BUSINESS CONTINUITY MANAGEMENT GUIDELINES

Flinders University IT Disaster Recovery Framework

BT Conferencing Business Continuity Management. Planning to stay in business

Business Resiliency Business Continuity Management - January 14, 2014

Business Continuity and Disaster Recovery Planning

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Three

Q uick Guide to Disaster Recovery Planning An ITtoolkit.com White Paper

Planning for Disaster. Ramesh Ramani CISM CGEIT 02 June 2010

Raising Business Continuity Management Awareness in Malaysia

How To Manage A Disruption Event

Guideline - Business Continuity Plan

NEEDS BASED PLANNING FOR IT DISASTER RECOVERY

Il nuovo standard ISO sulla Business Continuity Scenari ed opportunità

Project Roles and Responsibilities

BUSINESS CONTINUITY MANAGEMENT SINGAPORE SS540 BCM STANDARDS. LSA Consultants Pte Ltd

BCM and DRP - RFP Template

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

Business Continuity Management

Stepping Through the Info Security Program. Jennifer Bayuk, CISA, CISM

(Instructor-led; 3 Days)

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO AUDITS, CERTIFICATION AND TRAINING

Moving from BS to ISO The new international standard for business continuity management systems. Transition Guide

Planning for Disaster Disaster

The Role of Internal Audit In Business Continuity Planning

Unit Guide to Business Continuity/Resumption Planning

Training Catalogue. Ace Service Training Catalogue Ver 7.0. Ace Services

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

Business Continuity Policy

Chapter I: Fundamentals of Business Continuity Management

eet Business continuity and disaster recovery Enhancing enterprise resiliency for the power and utilities industry Power and Utilities Fact Sheet

BUSINESS CONTINUITY POLICY

Guideline on Business Continuity Management

Business Continuity Planning

Business Continuity Management Policy

Business Continuity / Disaster Recovery Context

Business Continuity Management AIRM Presentation

Information security controls. Briefing for clients on Experian information security controls

Company Management System. Business Continuity in SIA

Transcription:

2011/EPWG/WKSP/004 Intro 1 Business Continuity Planning (BCP) 101 Submitted by: Business Continuity Management Institute Workshop on Private Sector Emergency Preparedness Sendai, Japan 1-3 August 2011

APEC EPWG Workshop: Private Sector Emergency Preparedness BCP 101 August 2, 2011 Hotel Monterey Sendai Sendai, Japan Dr Goh Moh Heng PhD BCCE DRCE BCCLA CBCP FBCI President 2 Copyright @ 2011 BCM Institute 1

Introduction 1: Business Continuity Planning (BCP) 101 09:45-11:10 Overview, including benefits and challenges to implementation, practices for mitigating threats and risks, and examples of BCP Dr Goh Moh Heng President Business Continuity Management (BCM) Institute www.bcm-institute.org Managing Director GMH Continuity Architects Asia Pacific BCM Consulting Firm www.gmhasia.com Professional BCM Appointments Technical Advisor for TR19:2005 & SS540:2008 BCM Standard (Management Council and Technical Committee) www.ss540.org Project Director, Technical Working Group for SS507:2004 ISO/IEC 24762 Guidelines for BC-DR Services http://www.bcmpedia.org/wiki/dr_goh_moh_heng Copyright @ 2011 BCM Institute 2

Dr Goh Moh Heng Prior Appointments Government of Singapore Investment Corporation (GIC) Standard Chartered Bank Global Head for BCM PriceWaterhouse (Coopers) Past Certification Broad Member for DRI International s Certification Board Past Executive Director for DRI Asia Senior Technical Advisor, China Business Continuity Management Forum http://www.bcmpedia.org/wiki/dr_goh_moh_heng BCM Institute Started in January 2005. Provide competency based BC-DR training to all levels. p y g Certify BC-DR professionals globally. Started Certification programme in April 2007. Trained more than 3000 professionals from 850 organizations and 40 countries. Copyright @ 2011 BCM Institute 3

Agenda (Part 1 of BCM-101) Business Continuity Management Overview and Fundamentals BCM Planning Methodology Planning Process Comparison with BCM Standards Flexibility and consistency in global compliance Process for implementing business continuity IT RECOVERY BUSINESS CONTINUITY Incidents, Emergencies, Events, Disasters SECURITY CRISIS Plan IT DR PLAN BC PLAN SPECIFIC PLANS SECURITY PLAN SPECIFIC CRISIS MANAGEMENT PLAN Copyright @ 2011 BCM Institute 4

BCM Planning Methodology http://www.bcmpedia.org/wiki/ BCM_Planning_Process_or_Methodology Key International BCM Standards BS 25999 SS 540 NFPA 1600 ANZ 5050 10 Copyright @ 2011 BCM Institute 5

BCM Planning Methodology Ste-by-Step Approach Project Management Objectives Formulate a workable project proposal. Seek endorsement and commitment on the project from management committee: Objective Scope Approach Schedule Manpower Establish project management structure and control. Tasks BCM Steering Committee & BCP Project Team Review and understand organisation environment. Agree and formalise project management structure and resource allocation. Establish project administration reporting and control mechanism. Deliverables Project plan proposal includes: Definition Scope Objective Roles & Responsibilities Project workplan. Project reporting mechanism. Copyright @ 2011 BCM Institute 6

Risk Analysis and Review Objectives identify vulnerabilities Establish reliable recommendations for: Minimizing impact of identified threats Immediate and effective response to potential causes of disaster Tasks Identify exposure to internal & external threats and the likelihood of these threats occurring Recommend preventive responses and escalation procedures in conjunction with crisis management implementation Evaluate findings and prepare a status report & recommendation. Deliverables Comprehensive risk and threat profile to the organization, with key disaster scenario Recommendation for: Countermeasures Immediate Response Procedures Security Risk Review to be implemented to minimize the risks Summary report of recommendations agreed with senior management Business Impact Analysis Objectives Determine impact of unavailability/failure/ disaster on business functions. Determine critical business needs and tolerable limits. Establish business criticality/ impact criteria using Business Impact Analysis Questionnaires (BIAQ). Prioritise the importance of each business unit vis-à-vis established criteria. Consolidate findings and rankings. Present results to management committee to confirm critical classifications and priority listings. Detailed report on findings (approved by management) containing: - tolerable limits; classification of criticality; prioritised critical business functions; minimum resources; Critical applications and systems; and - restoration priority. Impact analysis of unavailability of business functions (quantitative and qualitative). Copyright @ 2011 BCM Institute 7

Recovery Strategy Objectives Establish business functions & job priorities vis-à-vis business needs. Determine processing requirements for priority business functions. Identify and formalise backup for everything needed to survive a disaster. Ensure that alternative processing procedure is available for continuity of critical business needs whilst recovery is in progress. Tasks Analyse all division functions to prioritise them based on business needs. Analyse hardware and software requirements to run high priority critical functions so that sufficient backup can be arranged. Review and establish backup arrangements, if necessary. Identify necessary interim processing procedures for critical functions. Seek management s review and endorsement of findings and recommendations. Deliverables List of strategic plans for recovering prioritised critical functions. List of critical functions requiring interim manual processing procedures. Recommend alternate interim processing procedures. Plan Development Objectives Train and equip users with skill to complete the Microsoft Word plan template. Establish recovery procedures to fully restore normal business operations after a disaster, based on selected strategies. Ensure consistency and comprehensiveness of coverage. Tasks Determine recovery teams set-up and functional responsibilities. Identify members of each recovery team. Develop specific procedures for each recovery team. Review and edit (based on agreed structure) the plan component to ensure consistency and comprehensiveness of documentation. Deliverables Propose: Recovery team structure; Staffing of the recovery teams with names of specific staff members; and List of action steps to be taken by each member of respective recovery team. Completed Business Continuity Plan. Copyright @ 2011 BCM Institute 8

Testing and Exercising Objectives Formulate an objective mechanism to validate the "workability" of the complete Business Continuity Plan. Tasks Design an overall program for testing of plan. Develop plans and schedules for specific tests. Develop an evaluation mechanism. Deliverables List of tests to be conducted. List of responsibilities of parties involved: Objectives, policies, guidelines, responsibilities and test specifications. Specific test plan: Description, scenarios, procedures and criteria. Evaluation forms/checklists for recovery plan tests. Building Organizational Competency BCM Internal Auditor Organization BCM Manager Business Unit Coordinator/ Representative BCM Steering Committee Organization BCM Manager Copyright @ 2011 BCM Institute 9

BCMpedia: Common Language www.bcmpedia.org BCM Community Forum Building a Community 80% Asian and Middle Eastern BCM and DR Professionals 3331 bcmi.groupsite.com Copyright @ 2011 BCM Institute 10

THANK YOU Dr Goh Moh Heng President Mobile: +65 96711022 Tel: +65 63231500 Email: moh_heng@bcm-institute.org Copyright @ 2011 BCM Institute 11