Don Stewart, MBCP, MBCI, CCP

Similar documents
Meeting FFIEC Requirements: Enterprise-Wide Testing of Your. Business Continuity Plan

Pandemic Planning. Presented by: Ron Wagner, IT Examiner with FDIC & Dana Lavey, Supervision Analyst with NCUA

Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke

Proposal for Business Continuity Plan and Management Review 6 August 2008

The PNC Financial Services Group, Inc. Business Continuity Program

Business Continuity Planning

Business Continuity Planning: Bridging the Gap Between IT and Business

Contingency Plan for HIPAA

Business Continuity Trends and Risk Considerations Financial Executives International Portland Chapter June

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1

The Role of Internal Audit In Business Continuity Planning

Business Continuity & Disaster Recovery Planning

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four

The PNC Financial Services Group, Inc. Business Continuity Program

Business Continuity Planning Preparing Your Organization

MHA Consulting. Business Continuity Management 101

Guideline - Business Continuity Plan

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

Business Continuity Planning (800)

External Supplier Control Requirements BCM

Business Continuity Management 101. Patrick Potter, CBCP MHA Consulting ISACA November 19, 2009

Refresher on cloud computing

Western Intergovernmental Audit Forum

State of South Carolina Policy Guidance and Training

A Crisis Response, Information Sharing View of FFIEC Appendix J?

FINRMFS9 Facilitate Business Continuity Planning and disaster recovery for a financial services organisation

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Disaster Recovery & Business Continuity Related, but NOT the Same! Teri Stokes, Ph.D., Director GXP International

CERTIFICATION IN BUSINESS CONTINUITY By Walter G. Green III, Ph.D., CRP

Disaster recovery strategic planning: How achievable will it be?

a Disaster Recovery Plan

Domain 3 Business Continuity and Disaster Recovery Planning

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Vendor Management. Outsourcing Technology Services

Click to edit Master title style

NAVIGATING THROUGH A CATASTROPHIC DISASTER:

Cyber Security Auditing for Credit Unions. ACUIA Fall Meeting October 7-9, 2015

Disaster Recovery. Hendry Taylor Tayori Limited

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning MARCH 2003 IT EXAMINATION H ANDBOOK

NIST SP , Revision 1 Contingency Planning Guide for Federal Information Systems

Effectively Assessing IT General Controls

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

Outsourced Third Party Relationship Management/ Vendor Management. TTS Webinar July 15, 2015 Susan Orr CISA, CISM, CRISC, CRP

Best Practices in Developing an IT Disaster Recovery Plan. Vijaykumar Kulkarni AGM Product Management

Business Continuity Planning: Beyond Compliance

Why Should Companies Take a Closer Look at Business Continuity Planning?

BCP and DR. P K Patel AGM, MoF

The Business Continuity Maturity Continuum

Cloud Security & Risk. Adam Cravedi, CISA Senior IT Auditor acravedi@compassitc.com

Table of Contents... 1

OC Chapter. Vendor Risk Management. Cover the basics of a good VRM program, standards, frameworks, pitfall and best outcomes.

Disaster Recovery Plan Review Checklist. A High-Level Internal Planning Tool to Assist State Agencies with Their Disaster Recovery Plans

Business Continuity and Disaster Recovery

Identifying and Managing Third Party Data Security Risk

Evaluating and Improving Your Business Continuity Plan

Information Technology

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

Rogers Insurance Client Presentation

FFIEC Cybersecurity Assessment Tool

SECURITY AND EXTERNAL SERVICE PROVIDERS

Interagency Statement on Pandemic Planning

Disaster Recovery Business Continuity Premium Edition

The Emergence of the ISO in Community Banking Patrick H. Whelan CISA IT Security & Compliance Consultant

How to measure your business resiliency

Business Continuity Management

Jack Henry & Associates, Inc., Monett, Missouri, a technology service provider to

How to write a DISASTER RECOVERY PLAN. To print to A4, print at 75%.

Business Resiliency Business Continuity Management - January 14, 2014

NHS 24 - Business Continuity Strategy

POLICY. 1) Business Continuity Management 2) Disaster Recovery 3) Critical Incident Management 4) Risk Management

Business Continuity and the Cloud. Aaron Shaver US Signal, Solution Architect

BE PREPARED! Disaster Recovery Plan: Also known as (BCP) Business Continuity Plan

Measuring Continuity Planning Program. Performance

Consulting Solutions Disaster Recovery. Yucem Cagdar

Business Continuity and Disaster Recovery Planning

Disaster Preparedness & Response

2014 NABRICO Conference

BUSINESS CONTINUITY PLANNING. Business Continuity Management Plan. Version 1.4

Aligning Disaster Recovery and Business Continuity to Business Objectives. Session E7 John Jackson Fusion Risk Management, Inc.

Metro Business Continuity and Disaster Recovery Plan Response to vendor questions RFP

Transcription:

Moving production and disaster recovery securely into the cloud. Don Stewart, MBCP, MBCI, CCP

TOPIC OUTLINE What are the opportunities? Why do we care? How can we embrace best practices? Who should participate? Presentation will be posted

WHAT? BCP vs DRP Vendor Mgmt. as it relates to the BCP Methodologies and tools Our goal is to provide clear direction and opportunities

THE DIFFERENCE BETWEEN DR & BCP DR is what IT and Facilities does DRP (Disaster Recovery Programs) The rest of us do Continuity of Service to our Members Crosswalks (BIA, DRP, Risk, Vendor Mgmt.) BCP (Business Continuity Program) Enterprise Continuity

VENDOR MANAGEMENT & BCP Duplicate Vendor information Line staff Managers Accounts Payable Compliance or? Huge opportunity to merge/share

METHODOLOGIES Notebook, business cards, post-it notes Word/Excel/Access Shared or Public Lists in Outlook Dedicated Vendor Mgmt. Applications SharePoint Start simple! Feel the need to wrap your arms around a project before starting?

WHY? Regulatory compliance Critical Member services Reputation Risk Continuity of Service to our Members no matter what happens!

REGULATORY COMPLIANCE HIPPA FFIEC NCUA Complete list of DR/BCP regulations http://www.drj.com/resources/tools/dr-rulesand-regulations.html

CRITICAL MEMBER SERVICES We are outsourcing more and more Many interdependencies Network and Internet ATMs, Shared Branch, Online Banking, Mobile Mortgage, Indirect, Cards Contractors, Cleaning, Maintenance Support, Temp Hires, Consultants Member data?!?

REPUTATION RISK Most significant potential risk we face Your Members only see you Vendor issues are yours Response time, method, and message are critical, keep it simple Executive recognition is key

REPUTATION RISK Source: FIA tool

REPUTATION RISK Source: FIA tool

HOW? Tools - eliminate duplication of effort Merge (Contact Lists, Vendor Mgmt., DR, & BCP) Must be easy to use AND customize Training, development, and support Here is how we do it

DEPARTMENT LEVEL Connect to Outlook

DEPARTMENT LEVEL Have your team connect to Outlook

DEPARTMENT LEVEL Everyone in dept. is using the same list

DEPARTMENT LEVEL Vendor list backup (sync) is immediate

COLLATING DEPT. VENDORS Sync the dept. information forward

VENDOR MANAGEMENT

CONTINUOUS IMPROVEMENT Align Vendor Mgmt. requirements with FFIEC handbook and NCUA examiners Use same database for Accts. Payable Align tools with Risk Management Establish crosswalk to the BIA Provide IT with outcomes Monitor the IT/DR Program

WHO? Feel like there is a target on your back? Embrace opportunity to create win-win Accept continuous improvement Checklist (FFIEC, NCUA, & Best Practices) DR Exercises Think Opportunity!

CHECKLIST FFIEC handbook provides base list NCUA examiners add specifics Best Practices Common sense Constant change Reputation Risk

DR EXERCISE The BIA identified criticality & RPO IT establish priorities & dependencies Outcomes protect or assign risk Include vendors in your Exercise(s) Ask to participate in theirs Think Opportunity!

DR EXERCISE - LESSONS At least a couple vendors in each Vendor connectivity can be separate Ping is adequate for basic Plan carefully before doing live Live switch should be a goal Exercise, Exercise, Exercise

DR EXERCISE - LESSONS Alternate connectivity (eliminate single point) Do failure tests on alternates! Repeat test with change/update Record issues, opportunities, gaps, and action plans (sufficiency of controls, mitigation plan, residual threat, action plan) Project Management

SEIZE THE OPPORTUNITY! Vendor issues/outages are common Human error is THE most common Disaster (but this applies to vendors also!) Tie all these basics together Start simple and grow Synergy

CONTINUITY OF SERVICE TO THE MEMBER NO MATTER WHAT HAPPENS! Questions & Discussion Don Stewart, MBCP, MBCI, CCP dstewart@ongoingoperations.com 541-231-9255