Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.



Similar documents
Business Continuity Plan

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

Emergency Response and Business Continuity Management Policy

Principles for BCM requirements for the Dutch financial sector and its providers.

How to measure your business resiliency

BCP and DR. P K Patel AGM, MoF

Business Continuity Management Framework

Overview TECHIS Manage information security business resilience activities

NHS 24 - Business Continuity Strategy

NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00)

Temple university. Auditing a business continuity management BCM. November, 2015

Birmingham CrossCity Clinical Commissioning Group. Business Continuity Management Policy

Business Continuity Management Program Development Guide

Business Continuity Management

Business Continuity Management Policy

D2-02_01 Disaster Recovery in the modern EPU

How To Manage A Disruption Event

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY

Business Resiliency Business Continuity Management - January 14, 2014

Desktop Scenario Self Assessment Exercise Page 1

Business Continuity (Policy & Procedure)

Business Continuity Management

Business Continuity - IT Disaster Recovery Discussion Paper - - Commercial in Confidence Version V2.0R Wednesday, 5 September 2012

Guideline - Business Continuity Plan

Business Continuity Planning (BCP) 101

Proposal for Business Continuity Plan and Management Review 6 August 2008

Solihull Clinical Commissioning Group

Coping with a major business disruption. Some practical advice

Business Continuity Policy

Business Continuity Management. Policy Statement and Strategy

The PNC Financial Services Group, Inc. Business Continuity Program

Business Continuity Management Systems. Protecting for tomorrow by building resilience today

1.0 Policy Statement / Intentions (FOIA - Open)

Flinders University IT Disaster Recovery Framework

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd

eet Business continuity and disaster recovery Enhancing enterprise resiliency for the power and utilities industry Power and Utilities Fact Sheet

Business Continuity Management

Introduction UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT

RSA ARCHER BUSINESS CONTINUITY MANAGEMENT AND OPERATIONS Solution Brief

Business continuity management policy

BUSINESS CONTINUITY POLICY

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Three

Chapter I: Fundamentals of Business Continuity Management

BUSINESS CONTINUITY PLANNING GUIDELINES

Business Continuity Policy

Business Continuity Management Planning Methodology

Business Continuity Plan Toolkit

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

ESCB definitions of major business continuity terms in relation to payment and securities settlement systems 1

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Business Continuity Policy

BUSINESS CONTINUITY MANAGEMENT IN THE PUBLIC SECTOR A ROUGH GUIDE

State of South Carolina Policy Guidance and Training

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

HOW CAN YOU ENSURE BUSINESS CONTINUITY? ISO AUDITS, CERTIFICATION AND TRAINING

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1

Success or Failure? Your Keys to Business Continuity Planning. An Ingenuity Whitepaper

Why Should Companies Take a Closer Look at Business Continuity Planning?

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

Business Continuity and Risk Management. Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited

PAPER-6 PART-5 OF 5 CA A.RAFEQ, FCA

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard

Business Continuity Planning

NHS Hardwick Clinical Commissioning Group. Business Continuity Policy

NEEDS BASED PLANNING FOR IT DISASTER RECOVERY

Business Continuity Management

Module 7. Business Continuity Management

Business Continuity Planning and Disaster Recovery Planning

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity

BSO Board Director of Human Resources & Corporate Services Business Continuity Policy. 28 February 2012

Business Continuity and Disaster Recovery Planning

Kuala Lumpur, Malaysia, May Report

November 2007 Recommendations for Business Continuity Management (BCM)

Business Continuity Management Policy

Table of Contents... 1

Moving from BS to ISO The new international standard for business continuity management systems. Transition Guide

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

Business Continuity Planning for Risk Reduction

Business Continuity Management Software

Essex Clinical Commissioning Groups. Business Continuity Management System. Scope and Policy

Business Continuity Management (BCM) Policy

Business Continuity Planning (800)

The PNC Financial Services Group, Inc. Business Continuity Program

Disaster Recovery. Hendry Taylor Tayori Limited

Business Continuity Planning. Donna Curran, Director Audit and Risk Management February, 2014

Guidelines 1 on Information Technology Security

PBSi Business Continuity Planning

BUSINESS CONTINUITY PLAN. Specific Issues for Public Health Emergencies. Guidelines for Air Carriers

Application / Hardware - Business Impact Analysis Template. MARC Configuration Requirements. Business Impact Analysis

Business Continuity Planning in Indian Perspective

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four

Developing a Business Continuity Plan... More Than Disaster

Disaster Recovery and Business Continuity Plan

Ohio Supercomputer Center

Transcription:

Business Continuity Management & Disaster Recovery Planning Presented by: Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD. 1

What is Business Continuity Management? Is a holistic management process that identifies potential impacts that threaten an organization. Provides a framework for building resilience and the capability for an effective response. Safeguards the interests of its key stake holders, reputation, brand and value creating activities 2

Meaning This means BCM is therefore inclusive of : Disaster Recovery, Business Recovery, Crisis Management, Emergency Management, Incident Management, Business Impact Analysis, Risk Assessment Contingency Planning and just plain old plan B. BCM refers to a program that encompasses the development and management of policies and procedures to protect an organization s people, processes and supporting technology. 3

Some important definitions Business Continuity Planning The process leading to a clearly defined and documented plan for use in the event of a serious incident that impacts the people, functions and/or reputation of the business. Disaster Recovery Planning - The process of planning your response to an incident that may result in a serious loss of IT systems. Crisis Management The management of the specific incident at the actual time of its happening; in particular how communications are handled during the incident. Incident Management - A process to restore a normal service operation as quickly as possible and to minimize the impact on business operations, thus ensuring that the best possible levels of service quality and availability are maintained Business Impact Analysis - It is the process of analyzing the effect of interruptions to business operations or processes on all business functions. Vulnerability A weakness in an information system that could be exploited by an event to cause disruption in the system 4

Some important definitions Threats Are any circumstances or events with the potential to cause harm to an information resource by exploiting vulnerabilities in the system. Risk The possibility that something unpleasant or unwelcome will happen Risk Analysis Is a technique to identify and assess factors that may jeopardize the success of a project or achieving a goal? RPO - Refer to the age of the data the organization needs to be able to restore in the event of a disaster. RTO The length of time from the moment of an interruption until the time the process must be functioning. 5

What is Business Continuity? Mitigate Response Recover Business Continuity is more than just about recovering business function from a disaster BUT Ensuring that critical business function continue promptly in the event of a disruptive or disaster 6

Drivers of Business Continuity Environmental Natural Disasters (Like Earthquakes, Tsunami in South India, Japan, etc) Social Terrorism (Like 26/11 attack in Mumbai, Bombing at Mumbai Trains) Political Regulations Legislations Economic/Business Global marketplace Technological Increasingly complex Global connectivity Cybercrime Note : BCM should not be driven by focusing on the Threats alone rather than on the Impact of Business 7

Disaster Life Cycle Disaster Incident Pre-empt & Prevent Within minutes or hours Within hours or days Within weeks to months Timeline Reduce Respond Recover Resume Restore Return Recover : Critical IT Resume : Critical Business Crisis Management Major Plan Components Restore Non critical functions at alternate site Return to original location 8

Why Plan? Business Survival Minimize financial losses and embarrassment Fulfill obligations to employees, customers and shareholders React to a disaster/crisis with an understanding of: Critical Business Priorities Sources of support and services that could cause delays; which could be fatal to the organisation 9

Source: Ominitech 10

Business Planning Methodology Project Management Program Management Risk Analysis & Review BC Plan Testing & Exercising Business Impact Analysis BC Plan Plan Development Recovery Strategy Source: BCM Planning methodology by 11

Key Success Factors Senior Management Commitment Appointment of department representatives with appropriate authority Good BCM awareness Project Manager with mandate Focus approach 12

Business Planning Methodology Project Management Program Management Risk Analysis & Review Testing & Exercising Business Impact Analysis Plan Development Recovery Strategy Source: Business Planning methodology by 13

Business Planning Methodology Project Management Align Executive Management and set expectations. Establish the basis for a successful project. Establish and communicate the needs for BCM or DR Planning. Establish the project expectations. Obtain appropriate commitments with clear roles and responsibilities. Select the appropriate representation. Establish an efficient work plan and realistic timeline. Develop budget based on optimal estimate of resource requirements. Source: Business Planning methodology by 14

SUMMARY Solicit Support Define Scope and Objectives Form the BC Organization Prepare Schedule Request for Budget Obtain Endorsement 15

Business Planning Methodology Project Management Program Management Risk Analysis & Review Testing & Exercising Business Impact Analysis Plan Development Recovery Strategy Source: Business Planning methodology by 16

Business Planning Methodology Risk Analysis & Review Determine adverse threats affecting organizational assets and provide a risk treatment strategy to them. Identify external and internal threats to the organizational assets. Identify existing and potential disaster-mitigating systems/procedures. Source: Business Planning methodology by 17

SUMMARY Identify Threats and Vulnerabilities Determine and Rank Risks Mitigate Risks Establish Key Disaster Scenario Review Operational Processes Review Infrastructure Consolidate Findings 18

Business Planning Methodology Project Management Program Management Risk Analysis & Review Testing & Exercising Business Impact Analysis Plan Development Recovery Strategy Source: Business Planning methodology by 19

Business Planning Methodology Business Impact Analysis Identify all Critical Business Functions (CBF), financial and non-financial impacts resulting from disruptions, resources needed to recover these CBFs, recovery objectives, inter-dependencies and vital records. Develop business impact analysis methodology for data collection. Establish criteria for recovery prioritization. Identify and document CBFs, critical processes and critical application. Qualify and/or quantify losses and impacts as a result of such interruptions. Determine the tolerable downtime. Identify the minimum resources needed to recover the critical business functions. Determine Inter-dependencies and intra-dependencies. Identify vital records needed for recovery Analyze, report and present to executive management. Source: Business Planning methodology by 20

SUMMARY Establish MBCO* Establish Priority for Analyzing Impact Establish Critical Business Functions Determine Requirements to support CBFs** Consolidate Findings *MBCO Minimum BC Objectives ** CBFs- Critical Business Functions 21

Business Planning Methodology Project Management Program Management Risk Analysis & Review Testing & Exercising Business Impact Analysis Plan Development Recovery Strategy Source: Business Planning methodology by 22

Business Planning Methodology Recovery Strategy Identify recovery strategy solutions and requirements. Determine business units, corporate-wide, IT, telecommunication recovery strategies Develop cost benefit analysis for selected strategy. Select alternate sites and offsite storage. Identify alternative processing procedure for continuity of critical business functions whilst recovery is in progress. Identify and formalize backup for business and IT processes needed to survive a disaster. Consolidate strategy and present a list of strategic plans for recovering prioritized business functions to executive management. Source: Business Planning methodology by 23

SUMMARY Identify All Probable Options Evaluate Strategy Options Select and Consolidate Strategies Consolidate Findings 24

Business Planning Methodology Project Management Program Management Risk Analysis & Review Testing & Exercising Business Impact Analysis Plan Development Recovery Strategy Source: Business Planning methodology by 25

Business Planning Methodology Plan Development Put together a choreographed sequence of actions that counteracts or mitigate the effects of the threats or risks identified in the Risk Analysis and Review phase, the critical business function in the Business Impact Analysis (BIA) phase and the recovery strategies from the recovery strategy phase. Create a document which identifies the critical business functions in the organization to reestablishment in the least possible time and lowest cost. Provide easy to use plan templates. Ensure that the plan is easy to navigate and be understood by all participants of the recovery. Propose recovery team structure, staffing of the recovery teams with includes names of specific staff members. Develop and implement procedures to response and stabilize a situation following an emergency or incident. Establish procedures to coordinate with public authorities and external agencies during a disaster. Plan and coordinate the management of media during a crisis situation. Design and implement the BC, DR and/or CM plan. Source: Business Planning methodology by 26

SUMMARY Gather Requirements & Supporting Information Write the BC Plan Coordinate & Finalize Commitment Confirm the BC Plan Distribute the BC Plan 27

Business Planning Methodology Project Management Program Management Risk Analysis & Review Testing & Exercising Training & Awareness Business Impact Analysis Plan Development Recovery Strategy Source: Business Planning methodology by 28

Business Planning Methodology Training & Awareness Define Training Objectives Develop Various Type of Training Programs Computer based Classroom Test based Develop Awareness Programs Management Team members New employee orientation Identify Other Opportunities for Education Professional business continuity planning conferences and seminars User groups Publications Source: Business Planning methodology by 29

SUMMARY Identify Audience Types Identify Audience Needs Develop Awareness Programmes Develop Training Programmes Senior Management Approval Implement Programmes 30

Business Planning Methodology Exercising & Testing Coordinate, plan, evaluate and validate the testing of a documented plan. Define objectives, policies, guidelines, responsibilities and exercise specifications. Evaluate the effectiveness of procedures and the access to resources through testing. Establish and coordinate the exercise proper. Evaluate, update and report on exercise results to executive management. Source: Business Planning methodology by 31

SUMMARY Training to Prepare Teams for Exercise Preparation Before Tests and Exercises Conduct Tests and Exercise Document and Assess the Results Identify Corrective Actions Present to Management for Approval Implement Corrective Actions 32

Business Planning Methodology Project Management Program Management Risk Analysis & Review Testing & Exercising Business Impact Analysis Plan Development Recovery Strategy Source: Business Planning methodology by 33

Business Planning Methodology Program Management Ensure that the plan works and keep it current. Formalize plan maintenance process. Upkeep high awareness level. Link the Business Continuity (BC) effort to the organization performance. Incorporate BC as part of the key decision factors in business strategy formation. Benchmark Business Continuity Plan (BC Plan) and BCM program against international standards. Formulate an objective mechanism to validate the "workability" of the complete plan. Review and amend plan to reflect changes in staff, equipment and procedures. Maintain a Business Continuity (BC) or Disaster Recovery Management culture. Ensure that the BCM program and BC plan is audited periodically. Source: Business Planning methodology by 34

SUMMARY Align BCM to Organizational Mission-Vision Review Key BCM Elements Continuous Training & Awareness Rehearse & Exercise BC Plan Regular Audit & Assessment Review BCM Trends & Best Practices 35

INVESTMENT VS. RISK 36

Where You Want To Be Placed? 37

Where You Want To Be Placed? 38

Where You Want To Be Placed? 39

THANK YOU FOR YOUR ATTENTION 40

Difference between Disaster Recovery and Business Continuity 41