BP3: Decomposing the Crisis/ Incident Management Timeline

Size: px
Start display at page:

Download "BP3: Decomposing the Crisis/ Incident Management Timeline"

Transcription

1 BP3: Decomposing the Crisis/ Incident Management Timeline Eric Staffin, MBCI, CISSP VP and Global Head, Product & Infrastructure Risk Management Investment & Advisory Doug Weldon, FBCI, CBRM VP, Product & Infrastructure Risk Management Investment & Advisory

2 Presentation Outline Introductions Quiz Standards Help, but. What is the Incident Management Timeline? What are the Anchor Specifications of the Timeline? The More Comprehensive Set of Specifications! The More Fully Articulated Timeline Summary and Questions

3 QUIZ The Product The product is an automated system for generating financial information to customers. Some specifications include: Needs to recover from any operational interruption and be fully functional in 5 minutes or less When the product is recovered, its databases must be exactly as they were at the point of the interruption there must be no data loss or corruption The product is read only and the databases are updated nightly (changes once per 24 hours) What is the RPO for this product?

4 QUIZ Some Help Definitions of Recovery Point Objective (RPO) from various Authoritative Sources: The maximum amount of data loss an organization can sustain during an event. (DRJ Glossary) The tolerance for lost data measured in time. (BRCCI) The Point to which information must be restored to enable an activity to operate once it is resumed. (Good Practices Guidelines of the BCI Section 2) Represents the amount of data that can be lost without severely impacting the recovery of operations or the point in time in which systems and data must be recovered (e.g., the date and time of a business disruption). (FFIEC Business Continuity Handbook)

5 QUIZ Some Help What is the RPO for this product? RPO = 0 hours RPO = 5 minutes RPO = 24 hours None of the above Answer?

6 Incident Management Timeline What is it? And why look at it? Is it really this simple? Let s look at a typical approach and then dig into the timeline

7 Timeline Example Copyright Sentryx (

8 Specifications Apply to All Critical Resources these recovery objectives require management to determine which essential personnel, technologies, facilities, communications systems, vital records, and data must be recovered and what processing sequence should be followed so that activities that fall directly on the critical path receive the highest priority (FFIEC Business Continuity Handbook) People Technology Data Facilities The Key Resources Multiple Inter dependent RTOs may be Integrated Into the Recovery Specifications of a Process/Product!

9 The Oil Rig Customers Customer #1 Customer #2 Customer #3 Customer #4 Customer # 5 Customer # 6 Products & Services Prod #1 Prod #2 Svc #1 Svc #2 Prod #3 Prod #4 Svc #3 Svc #4 Prod #5 Svc #5 Processes Process #1 Process #2 Process #3 Process #4 Process #5 Sites Site #1 Site #2 People Site #3 Site #4 Process Platforms & Resources Technology Facilities Data Suppliers Supplier #1 Supplier #2 Supplier #3 Supplier #4 Supplier #n Copyright Vigilant Services Group (

10 Why All the Specs? ( Promoting the Art & Science of Business Continuity Management Worldwide The BCI) BCM is not simply a management exercise, it is an engineering discipline that requires technical engineering and human engineering to look at people, data and systems as an ecosystem that must be understood and in balance with: Enterprise Objectives Risk Appetite of the Enterprise Customer Requirements Legal/Regulatory Requirements and Compliance with other Codes of Practice including Standards This is NOT Your Father s RPOs/RTOs Anymore!

11 The Anchor Specifications Maximum Tolerable Period of Disruption (MTPoD BS25999) the point in time after a significant interruption after which an organization s viability will be irrevocably threatened if product and service delivery cannot be resumed Maximum Tolerable Downtime (MTD Sentryx) or Business as Usual Time Objective (BTO Vigilant Services Group) the point in time after a significant interruption at which the product or process returns to a business as usual state in consideration of work queues, lost data, etc. (operating as if nothing happened) Maximum Allowable Downtime (MAD FFIEC Business Continuity Handbook) the point in time after a significant interruption at which the product or process can no longer be inoperable NOT RPOs/RTOs at All!

12 Policy Management with Anchors Since most failure scenarios are NOT smoke and rubble, planning for efforts to be under the MAD and/or MTPoD thresholds is critical Organizational policy must be upheld to ensure that no new solutions can be brought to market without an explicit articulation of MAD and MTPoD Economics of design follow MAD and MTPoD Worst case scenarios follow MTPoD SLAs usually follow MAD Profitability and likely to recommend metrics follow penalties and SLA performance

13 The Anchor Specifications Independent Variables MAD, BTO/MTD, and MTPoD are anchor specifications because they may be driven by external mandates: Customer requirements such as SLAs Regulatory requirements such as FINRA Enterprise Policy such as quality/reliability guidelines Anchor specifications may/may not vary by scenario: Data corruption Pandemic Act of God ISSUE these various standards/guidelines do not provide engineering level specifications with which to design solutions! RPOs/RTOs are Dependent Variables!

14 Operational vs. Business as Usual MAD + WRT = MTD/BTO Work Recovery Time (WRT Sentryx) is the difference in time between full operational recovery and return to business as usual WRT includes: Recovering all lost data beyond RPO specification of lost data as required Processing accumulated workloads down to normal queuing levels Processing any accumulated manual processing of workloads Other activities as required to return to normal performance levels Does NOT imply return to business as usual operating environment! ISSUE Who is responsible for the recovery of lost work/data? SLAs are often Based on MAD, not MTD

15 In Practice Is One Anchor Enough? Should the Maximum Tolerable Period of Disruption (MTPoD) only be applied to smoke and rubble scenarios? If not, is it enough to consider MTPoD (by itself) to define our optimal resiliency solution levels?

16 When MTPoD is the ONLY Anchor! Incident Duration (Hours) Commercial Exposure ($ Millions) MTPoD = $15MM Total Product Revenue $40MM Exposure ($ Millions) Duration (Hours) Single Incident with Duration X MTPoD

17 Ok So They Can Both Be Anchors Now What!? Incident Duration (Hours) Commercial Exposure ($ Millions) MAD = $2.5MM MTPoD = $15MM Total Product Revenue $40MM MTPoD Use historical incident management data to predict the likelihood of a disruptive event occurring adjust resiliency and recoverability levels ASAP!! Exposure ($ Millions) Duration (Hours) Single Incident with Duration X Cumulative Incident Duration Cumulative Commercial Exposure

18 MAD & MTPoD Are Now Anchors!! Incident Duration (Hours) Commercial Exposure ($ Millions) MAD = $2.5MM MTPoD = $15MM Total Product Revenue $40MM Exposure ($ Millions) Optimal resiliency solutions MUST incorporate single incident and cumulative incident exposure levels to ensure that MAD and MTPoD thresholds are NOT exceeded. Anchors MUST be established in the definition and planning phases of the SDLC propositions cannot go to market if anchors aren t LOCKED in place. Duration (Hours) Single Incident with Duration X Cumulative Incident Duration Cumulative Commercial Exposure

19 We re Good Right?? Remember FFIEC and the Oil Rig: Technology Facilities Data People Let s take a closer look at RTOs, MAD and RCOs and then we can incorporate everything into the IM timeline.

20 RTO vs. MAD MAD is the time required to achieve full operational recovery Recovery Time Objective (RTO) represents the maximum allowable downtime that can occur without severely impacting the recovery of operations or the time in which systems, applications, or business functions must be recovered after an outage (FFIEC) RTO: Has historically applied to the time required to recover a specific resource Does not appropriately describe the recovery of a full process, function, or product that has a number of supporting and dependent resources ISSUE Supporting Process/Product Resources may have interdependencies requiring prioritization Multiples RTOs may apply to define a single Process/Product MAD

21 Now We re Really Ready! We ve got our anchors, MAD & MTPoD, We ve got multiple RTOs We ve identified critical WRTs We understand BTO Now let s see how this looks on the Incident Management timeline.

22 Timeline Decomposition Lifecycle Approach RPO Interruption Incident Starts This line, with the additional milestone red and green dots, represents the full Lifecycle of the Incident Incident Ends Permanent Restoration

23 Timeline Decomposition Phase 1 RPO Warning Signs Interruption! Automated Failover Mitigation Fails Last backup of data at RPO point in time If we built monitoring we might now see early signs of a problem in advance of the interruption Incident begins! High and Continuous Availability Systems may failover automatically but don t forget about the backlog!! Now everyone knows!!! The problem has been detected (did you factor this time into the RTO??) Diagnosis phase begins the clock is still ticking!! Great we know what s wrong problem officially diagnosed. Attempted mitigation begins crisis management efforts may avert/reduce the need for recoveries Mitigation Fails (did we consider this when we sold the RTO to management??) Did we think about MAD and the possibility that it could take time to get to this point!!??

24 Timeline Decomposition Phase 2 Backlog Grows Warning Signs Interruption! Automated Failover Mitigation Fails Manual Failover or Recovery Recovery Time (RTO) YES! we knew this could happen and factored it into the design (always thinking about MAD) This part we know executing the failover plan is trivial since we ve proceduralized the process and tested it enough to repeat CONSISTENTLY But we also know that many of the high likelihood scenarios could impact more than just one product or infrastructure Or that the products/processes we are recovering may require the recovery of a number of components in sequences defined by dependencies So, since we know that there isn t just one RTO have we accounted for all of them?

25 Timeline Decomposition Phase 2 RTO Breakout Backlog Grows Warning Signs Interruption! Automated Failover Mitigation Fails Manual Failover or Recovery Recovery Time (RTO) Validation Dependent RTOs must be fully articulated for facilities, people, data, and people Remediation efforts for recovery may need to include smoke testing or QA/QC Validate system restoration plan and ensure that there is an orderly process for restoring data with or without other services being exposed to customers or downstream systems must be noted in RTOs for each service/component Revalidate based on dependencies across all other related infrastructures Isolate critical ingredients and reduce SPOFs that have more than single impact Why Test? Validate what you know in what timescale + What you don t know > dependencies

26 Timeline Decomposition Phase 2 Backlog Grows Warning Signs Interruption! Automated Failover Mitigation Fails Manual Failover or Recovery Recovery Time (RTO) Validation Product at RCO & RPO YES we knew this could happen and factored this into the design (always thinking about MAD) This part we know executing the failover plan is trivial since we ve proceduralized the process and tested it enough to repeat CONSISTENTLY Good thing we factored in the RTOs for each of the supporting and attendant resources without this, we might have blown by MAD! Dependencies cleared Serial and parallel activities will be completed here just like we planned it!! Validation begins smoke testing is still critical this isn t a drill and the risk of support or product failure is REAL if test plans aren t carried out efficiently Good news the product has been identified as fully functional at RPO loss of data and the RCO is validated What is RCO and why is it important?

27 Recovery Capacity Objective (RCO) RCO (source: Vigilant Services Group) is the capacity level to which each Process/Product resource is recovered at the RTO point in time for that resource RCO has NOT been identified in any standard/guideline to date RCO: Can only be determined based on a detailed understanding of the workload backlogs that can accumulate over time during the interruption of a Process/Product RCO may actually be greater than normal processing capacity if workload backlogs accumulate at a high rate relative MAD and MTD/BTO ISSUE If RCO is not adequately specified, WRT may be severely protracted beyond the point of MTPoD! Multiples RCOs may apply to define a single Process/Product MAD

28 Timeline Decomposition Phase 3 Backlog Grows Warning Signs Interruption! Automated Failover Mitigation Fails Manual Failover or Recovery Recovery Time (RTO) Validation Product at RCO & RPO Work Recovery Time (WRT) Return to BAU Failover Capability Restored Failback Procedures Failback Capability Permanent Restoration How are we doing still under MAD any SLA exposure or did we factor that into the design as well? Remember our Work Recovery Time (WRT) discussion Recovering all lost data beyond RPO specification of lost data as required Processing accumulated workloads down to normal queuing levels Processing any accumulated manual processing of workloads Other activities as required to return to normal performance levels Does NOT imply return to business as usual operating environment! Looks solid and we ve reached another green dot we have returned to Business as Usual (BTO) Was this the first outage in the measurement period check SLA and MTPoD thresholds Next step is to restore the failover capability and return the primary data center to available service levels Execute failback procedures invoked (if necessary) Validate failback success Permanent restoration of services achieved!

29 More Fully Articulated Timeline

30 One Major Incident Can Kick Off Many Timelines Product Data Center 1 Product Data Center 2 Customer Data Center PROD 1 PROD 2 PROD 3 PROD 4 PROD X PROD Y C PROD A C PROD B INCIDENT RTOs MAD MTPoD Dependencies can exist at the resource/component level or the full product level! INCIDENT DEPENDENCY RTOs MAD MTPoD

31 Summary RTOs and RPOs are the legacy specifications of BCM dating back to our origins in the time of mainframes (late 70s) More specifications are required to fully articulate the requirements not only of today s more complex technology architectures but also of the other supporting resources (people, data, facilities) and their complex interrelationships We must tie back to standards to anchor our requirements specifications, but must interpret standards level definitions to support engineering level development Bottom line we must mature our approach to developing BC/DR operational capabilities

Introducing ISO 22301

Introducing ISO 22301 Introducing ISO 22301 1 2 Background How was the ISO22301 formed? Contributors 3 Context 4 Source documents included BS25999-2 NFPA 1600 ASIS OR standard Singapore standards ISO 27031 ISO Guide 73 ISOPAS22399

More information

Protecting Information Assets - Week 9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets

Protecting Information Assets - Week 9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets Protecting Information Assets - Week 9 - Business Continuity and Disaster Recovery Planning MIS5206 Week 9 Case study discussion Business Continuity Planning (BCP) and Disaster Recovery (DR) Planning Test

More information

Protecting Information Assets - Unit #9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets

Protecting Information Assets - Unit #9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets Protecting Information Assets - Unit #9 - Business Continuity and Disaster Recovery Planning Agenda Contingency Planning (CP) IT Security Control Class and Family Business Continuity and Disaster Recovery

More information

PLANNING TO SUCCEED: EXECUTING A BC/DR STRATEGY DURING A DIGITAL TRANSFORMATION

PLANNING TO SUCCEED: EXECUTING A BC/DR STRATEGY DURING A DIGITAL TRANSFORMATION WHITEPAPER PLANNING TO SUCCEED: EXECUTING A BC/DR STRATEGY DURING A DIGITAL TRANSFORMATION By Nick Cavalancia www.veeam.com The age old concept of a business being defined by its location is long dead.

More information

Operational Resiliency for a Virtualized Environment

Operational Resiliency for a Virtualized Environment Operational Resiliency for a Virtualized Environment Peter Laz, MBCP, MBCI Managing Consultant Forsythe Brendan Foye Enterprise Account Manager Zerto AGENDA Operational Resiliency vs. Disaster Recovery

More information

Business Continuity Management and Resilience Framework

Business Continuity Management and Resilience Framework Business Continuity Management and Resilience Framework Approving authority University Council Approval date 3 December 2018 Advisor Next scheduled review 2021 Peter Bryant Vice President (Corporate Services)

More information

Top 10 pitfalls to avoid when re-inventing your disaster recovery program

Top 10 pitfalls to avoid when re-inventing your disaster recovery program The Essential DR Cheat Sheet: Top 10 pitfalls to avoid when re-inventing your disaster recovery program Consult Build Transform Support Every new malicious attack or weather catastrophe underscores the

More information

Business Continuity & IT Disaster Recovery

Business Continuity & IT Disaster Recovery Business Continuity & IT Disaster Recovery DONALD L. SCHMIDT, ARM, CBCP, MCP, CBCLA, CEM PREPAREDNESS, LLC MARCH 30, 2017 www.preparednessllc.com What are Business Continuity & IT Disaster Recovery? BUSINESS

More information

BC & RISK MANAGEMENT: CONVERGENCE IS REAL David Halford Forsythe Solutions Group Frank Perlmutter Strategic BCP

BC & RISK MANAGEMENT: CONVERGENCE IS REAL David Halford Forsythe Solutions Group Frank Perlmutter Strategic BCP BC & RISK MANAGEMENT: CONVERGENCE IS REAL David Halford Forsythe Solutions Group Frank Perlmutter Strategic BCP WHY THE CONVERGENCE OF BUSINESS CONTINUITY & RISK MANAGEMENT? The convergence of BC and RM

More information

How to disasterproof critical. business data. 5 steps for keeping systems online and accessible in any scenario.

How to disasterproof critical. business data. 5 steps for keeping systems online and accessible in any scenario. How to disasterproof critical business data 5 steps for keeping systems online and accessible in any scenario. The growth of DRaaS The tremendous growth of software as a service (SaaS) continues, while

More information

An introduction to business continuity planning

An introduction to business continuity planning An introduction to business continuity planning What is business continuity, and is it relevant to me? Business continuity planning is about identifying the critical functions and services your business

More information

City of Saskatoon Business Continuity Internal Audit Report

City of Saskatoon Business Continuity Internal Audit Report www.pwc.com/ca City of Saskatoon Business Continuity Internal Audit Report June 2018 Executive Summary The City of Saskatoon s (the City ) Strategic Risk Register identifies Business Continuity as a high

More information

Effectively Communicating Enterprise-Wide Business Continuity to Senior Management and Stakeholders. October 7, 2014

Effectively Communicating Enterprise-Wide Business Continuity to Senior Management and Stakeholders. October 7, 2014 Effectively Communicating Enterprise-Wide Business Continuity to Senior Management and Stakeholders October 7, 2014 Agenda Background Program Elements What Makes it Enterprise-wide Recommended Strategies

More information

BCI Track Session 2. Driving Risk Management Governance into the BCM Life Cycle

BCI Track Session 2. Driving Risk Management Governance into the BCM Life Cycle BCI Track Session 2 Driving Risk Management Governance into the BCM Life Cycle Doug Weldon, FBCI Vice President of Product & Infrastructure Risk Management, Thomson Reuters and President, BCI-USA Chapter

More information

University Information Technology Services. Business Impact Analysis For {System Name}

University Information Technology Services. Business Impact Analysis For {System Name} University Information Technology Services Business Impact Analysis For {System Name} Prepared by Victor Font UITS Business Continuity / Disaster Recovery Coordinator January 2013 1. Overview... 3 1.1

More information

Leading Change: Building Organisational Resilience. Jean D. Rowe, MBCI, CDCP May 1, 2017

Leading Change: Building Organisational Resilience. Jean D. Rowe, MBCI, CDCP May 1, 2017 Leading Change: Building Organisational Resilience Jean D. Rowe, MBCI, CDCP May 1, 2017 Jean.Rowe@ae.ey.com Agenda What is Organizational Resilience? Why Should You Care? Are You Prepared? What Do You

More information

What s the Weakest Link in DR plans? Canadian companies confess their shortcomings

What s the Weakest Link in DR plans? Canadian companies confess their shortcomings What s the Weakest Link in DR plans? Canadian companies confess their shortcomings An evaluation of Canadian organizations and their response to disaster recovery processes. A joint survey in partnership

More information

Business Continuity 101. Fairchild Resiliency Systems

Business Continuity 101. Fairchild Resiliency Systems Business Continuity 101 Fairchild Resiliency Systems Business Continuity Business Continuity (BC) is defined as the capability of the organization to continue delivery of products or services at acceptable

More information

Global Crises: What We Really Need to Do to Be Prepared. Day One / Session C5

Global Crises: What We Really Need to Do to Be Prepared. Day One / Session C5 Global Crises: What We Really Need to Do to Be Prepared Day One / Session C5 April 12, 2010 Clyde Berger Adam Chusid 0 Today s Objectives Present practical solutions for building a viable sustainable program

More information

Introduction to Business

Introduction to Business ANALYSIS DESIGN IMPLEMENTATION Introduction to Business Continuity course This course is an introduction to the world of business continuity (BC). It is designed as a first step for newcomers to the subject

More information

GUIDE TO CONTINUITY PLANNING

GUIDE TO CONTINUITY PLANNING Academic GUIDE TO CONTINUITY PLANNING The aim of WashU Continuity is to increase the university s resilience in the face of disruptive events. Resilience means being able to continue performing the university

More information

Business Continuity. Building a Program Fit for Purpose

Business Continuity. Building a Program Fit for Purpose Business Continuity. Building a Program Fit for Purpose Tim Janes. Director Fulcrum Risk Services Tuesday 2 September. 11.30-12.45 T Janes. BC SLIDES. RIMS Risk Forum Aust 2014 v1.0 Building a BC Program

More information

October WFE Response to the BoE-FCA-PRA Discussion Paper: Operational Resilience

October WFE Response to the BoE-FCA-PRA Discussion Paper: Operational Resilience October 2018 WFE Response to the BoE-FCA-PRA Discussion Paper: Operational Resilience Background The World Federation of Exchanges (WFE) is the global trade association for exchanges and clearing houses,

More information

Meet Our Presenter. Equipping You For Success: An ISO Certification Case Study

Meet Our Presenter. Equipping You For Success: An ISO Certification Case Study Equipping You For Success: An ISO 22301 Certification Case Study March 28, 2017 10:45 11:45 am Maureen Roskoski, Corporate Sustainability Officer, Facility Engineering Associates, PC Meet Our Presenter

More information

BUSINESS CONTINUITY PLANNING WORKPROGRAM

BUSINESS CONTINUITY PLANNING WORKPROGRAM BUSINESS CONTINUITY PLANNING WORKPROGRAM EXAMINATION OBJECTIVE: Determine the quality and effectiveness of the organization s business continuity planning process, and determine whether the continuity

More information

Consequences of Poorly Performing Software Systems

Consequences of Poorly Performing Software Systems Consequences of Poorly Performing Software Systems COLLABORATIVE WHITEPAPER SERIES Poorly performing software systems can have significant consequences to an organization, well beyond the costs of fixing

More information

Moving from BS to ISO The new international standard for business continuity management systems

Moving from BS to ISO The new international standard for business continuity management systems Transition Guide Moving from BS 25999-2 to ISO 22301 The new international standard for business continuity management systems Extract from The Route Map to Business Continuity Management: Meeting the

More information

External Supplier Control Obligations

External Supplier Control Obligations External Supplier Control Obligations Resilience Control Title Control Description Why this is important 1.Resilience and recovery governance Supplier must establish effective governance to maintain resilience

More information

Tier I assesses an institution's process for identifying and managing risks. Tier II provides additional verification where risk is eviden

Tier I assesses an institution's process for identifying and managing risks. Tier II provides additional verification where risk is eviden Appendix A: Examination Procedures EXAMINATION OBJECTIVE: Determine the quality and effectiveness of the organization's business continuity planning process, and determine whether the continuity testing

More information

The 13th Annual Continuity Insights Management Conference

The 13th Annual Continuity Insights Management Conference The 13th Annual Continuity Insights Management Conference Presented by: Continuity Insights What Enterprise-Wide Business Continuity Really Means Communicating the value of BC to management and embedding

More information

Business Continuity Management PHILIPPINES :: MALAYSIA :: VIETNAM :: INDONESIA :: INDIA :: CHINA

Business Continuity Management PHILIPPINES :: MALAYSIA :: VIETNAM :: INDONESIA :: INDIA :: CHINA Business Continuity Management PHILIPPINES :: MALAYSIA :: VIETNAM :: INDONESIA :: INDIA :: CHINA Learning Bites Understand the context and relevance of BCM A Philippine & Telco Perspective Comprehend how

More information

reasons to invest in a CMMS

reasons to invest in a CMMS 11 reasons to invest in a CMMS 11 reasons to invest in a CMMS 1. Effectively plan preventive maintenance The purpose of preventive maintenance (PM) is to plan scheduled inspections so that defects are

More information

Disaster Recovery Service Guide

Disaster Recovery Service Guide Disaster Recovery Service Guide Getting Started Overview of the HOSTING Unified Cloud The HOSTING Unified Cloud is our approach for helping you achieve better business outcomes. It combines the industry's

More information

FOUNDATION OF THE PLAN WAS A RISK ANALYSIS. Basic Flaw focus on threat probability instead of potential impact

FOUNDATION OF THE PLAN WAS A RISK ANALYSIS. Basic Flaw focus on threat probability instead of potential impact FOUNDATION OF THE PLAN WAS A RISK ANALYSIS Basic Flaw focus on threat probability instead of potential impact NOBODY KNEW ANYTHING How do you create a plan? How do you do a Risk Analysis? How much processing

More information

BUSINESS CONTINUITY MANAGEMENT

BUSINESS CONTINUITY MANAGEMENT Loss Control BUSINESS CONTINUITY MANAGEMENT Preparing for the Unexpected Preparing your organization for a disaster can be an overwhelming task, but the risk of being unprepared can be even more devastating.

More information

US Business Continuity Safeguarding Your Business from a Disaster

US Business Continuity Safeguarding Your Business from a Disaster US Business Continuity Safeguarding Your Business from a Disaster Juanita Hardin BMO Harris Bank Head TPS Risk and Compliance William Simmons BMO Harris Bank Vice President Business Continuity Management

More information

Business Continuity Planning for Major Disruptions Checklist 255

Business Continuity Planning for Major Disruptions Checklist 255 Business Continuity Planning for Major Disruptions Checklist 255 Introduction Major disruptions to organisations come in many forms. Extreme weather conditions, technical failure, people related factors

More information

Always On: Unitrends DRaaS Disaster Recovery Services

Always On: Unitrends DRaaS Disaster Recovery Services Always On: Unitrends DRaaS Disaster Recovery Services Always On: Unitrends DRaaS Disaster Recovery Services What keeps you up at night? Are you thinking about what would happen to your business in the

More information

BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNING. Marci McCloskey, CISA, ABCP Toan Nguyen, CIA, ABCP

BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNING. Marci McCloskey, CISA, ABCP Toan Nguyen, CIA, ABCP BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNING Marci McCloskey, CISA, ABCP Toan Nguyen, CIA, ABCP SPEAKER INFORMATION Marci McCloskey, CISA, ABCP Oklahoma City, Oklahoma University of Oklahoma Stinnett:

More information

Enabling a Comprehensive Platform for BCMP that integrates People, Process and Technology

Enabling a Comprehensive Platform for BCMP that integrates People, Process and Technology Enabling a Comprehensive Platform for BCMP that integrates People, Process and Technology TM Overview Perpetuuiti provides an intelligent, end-to-end automated approach towards Business Continuity Planning

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning 4 Business Continuity Planning and Disaster Recovery Planning Learning Objectives To understand the concept of Business Continuity Management; To understand the key phases and components of a Business

More information

Aligning IT risk management with strategic business goals

Aligning IT risk management with strategic business goals IBM Global Technology Services White Paper IBM Business Continuity and Resiliency Services Aligning IT risk management with strategic business goals New metrics and technologies help meet the challenges

More information

Keep All of Your Business-Critical Jobs On Track. CA Workload Automation idash Helps You Reduce Missed SLAs and Lower Costs

Keep All of Your Business-Critical Jobs On Track. CA Workload Automation idash Helps You Reduce Missed SLAs and Lower Costs Keep All of Your Business-Critical Jobs On Track CA Workload Automation idash Helps You Reduce Missed SLAs and Lower Costs Workload Management Is Growing in Importance and Complexity Whether you re processing

More information

12.0 Business Continuity Management

12.0 Business Continuity Management Number 12.0 Policy Owner Information Security and Technology Policy Business Continuity Management Effective 01/01/2014 Last Revision 12/30/2013 Department of Innovation and Technology 12. Business Continuity

More information

Business Continuity Management and Business Impact Analysis (BIA)

Business Continuity Management and Business Impact Analysis (BIA) Presented by Richard A. Harris, CBCP, MPMP Absolute Continuity Solutions Consultants, LLC Absolute solutions for all your enterprise s consulting needs Business Continuity Management and Business Impact

More information

Citi Institutional Clients Group - Business Continuity Management

Citi Institutional Clients Group - Business Continuity Management Citi Institutional Clients Group - Business Continuity Management Enterprise Risk Management Establishing a Risk Control-based Continuity Program, CBCP, CBCP Senior Vice President, Citi Institutional Clients

More information

Business Continuity & Disaster Recovery

Business Continuity & Disaster Recovery Business Continuity & Disaster Recovery Richard Long, Senior Advisory Consultant MHA Consulting Presented at CopperPoint SafetyWorks Aug & Sep, 2017 2017 MHA CONSULTING. ALL RIGHTS RESERVED. COMPANY BACKGROUND

More information

Roger Peters Founder, Continuity Onward, Inc

Roger Peters Founder, Continuity Onward, Inc Roger Peters Founder, Continuity Onward, Inc. ContinuityOnward@gmail.com 612-360-3063 1 Welcome to secure360 2013 Don t forget to pick up your Certificate of Attendance at the end of each day. Please complete

More information

Finally, Affordable Enterprise-Grade Disaster Recovery Using the Cloud

Finally, Affordable Enterprise-Grade Disaster Recovery Using the Cloud Finally, Affordable Enterprise-Grade Disaster Recovery Using the Cloud Until recently, enterprise-grade disaster recovery had been prohibitively expensive for most organizations. Thanks to the rapid development

More information

HB A Practitioners Guide to Business Continuity Management

HB A Practitioners Guide to Business Continuity Management HB 292 2006 A Practitioners Guide to Business Continuity Management HB HB 292 2006 Handbook A practitioners guide to business continuity management First published as HB 292 2006. COPYRIGHT Standards Australia

More information

Business Resilience: Equipping the FM for Success

Business Resilience: Equipping the FM for Success Business Resilience: Equipping the FM for Success CEUs & CFM Maintenance Points You are eligible to receive Continuing Education Units and Certified Facility Manager maintenance points for attending sessions

More information

The Easy Guide to Determining Business Continuity Strategies

The Easy Guide to Determining Business Continuity Strategies Continuity In Business business continuity resources for busy continuity planners The Easy Guide to Determining Business Continuity Strategies You ve got a BIA! Now you need to work out the strategies

More information

The Uber Orchestrator from CA Technologies

The Uber Orchestrator from CA Technologies The Uber Orchestrator from CA Technologies Table of Contents Executive Summary Simplify Complexity Maintain Control Improve User Experience Bridge Islands of Automation Automate Disaster Recovery Plans

More information

Executive Presentation on using Management Dashboards to support the processes of Infrastructure, Production, Compliance, and Recovery Certification

Executive Presentation on using Management Dashboards to support the processes of Infrastructure, Production, Compliance, and Recovery Certification Executive Presentation on using Dashboards to support the processes of Infrastructure, Production, Compliance, and Recovery Certification Created by: Thomas Bronack, CBCP Phone: (917) 673-6992 Email: bronackt@dcag.com

More information

Equipping You For Success

Equipping You For Success Equipping You For Success Maureen Roskoski, CFM, SFP, LEED AP O+M, Senior Professional Corporate Sustainability Officer Identify Benefits Implement System Engage Team Evaluate Performance Identify Benefits

More information

BUSINESS CONTINUITY AS A SERVICE

BUSINESS CONTINUITY AS A SERVICE BUSINESS CONTINUITY AS A SERVICE CONFIDENCE IN CONTINUITY From the launch of the UK s first managed online backup services over 15 years ago, to our leading Disaster Recovery as a Service (featured in

More information

ITIL from brain dump_formatted

ITIL from brain dump_formatted ITIL from brain dump_formatted Number: 000-000 Passing Score: 800 Time Limit: 120 min File Version: 1.0 Экзамен A QUESTION 1 Which role is responsible for carrying out the activities of a process? A. Process

More information

Points of Discussion

Points of Discussion Business Continuity Planning Considerations for Business Process Offshoring Todd Litman, CBCP DRJ Spring World March 18, 2013 1 Points of Discussion Business Process Offshoring Benefits & Risks Business

More information

CISSP Certified Information Systems Security Professional (CISSP)

CISSP Certified Information Systems Security Professional (CISSP) QUESTION 1 CISSP Certified Information Systems Security Professional (CISSP) During a recovery procedure, one important step is to maintain records of important events that happen during the procedure.

More information

Business Continuity Management Policy. Guidance

Business Continuity Management Policy. Guidance Management Guidance Document Type: Guidance Parent Policy: Management Policy Policy Owner: Chief Supt Department: Document Writer: Co-ordinator Effective Date: 12 th March 2015 Review Date: 12 th March

More information

Introduction to BCP and DR Planning

Introduction to BCP and DR Planning Introduction to BCP and DR Planning Based on the book RESPONSE! Planning & Training for Emergency Recovery November 24, 2015 Tim Elemes Huber Advisors P.O. Box 175 Hugo, MN 55038 information@huberadvisors.com

More information

Subject Area 1 Project Initiation and Management

Subject Area 1 Project Initiation and Management Professional Practice Narrative: Establish the need for a Business Continuity Plan (BCP), including obtaining management support and organizing and managing the BCP project to completion. (This includes

More information

BCM Lite a quick and easy guide to BCM for beginners and/or small businesses

BCM Lite a quick and easy guide to BCM for beginners and/or small businesses BCM Lite a quick and easy guide to BCM for beginners and/or small businesses Some important definitions Business Continuity Planning The process leading to a clearly defined and documented plan for use

More information

6 Key Elements of Successful DRaaS

6 Key Elements of Successful DRaaS 6 Key Elements of Successful DRaaS Business resiliency is no longer an option it s mandatory In today s world of around-the-clock operations, few companies can afford IT downtime, yet most can t afford

More information

5/28/2018. Disaster Recovery Are You Ready. Speaker. Agenda

5/28/2018. Disaster Recovery Are You Ready. Speaker. Agenda Disaster Recovery Are You Ready Central Iowa American Payroll Association 2017 Statewide Conference Friday October 6 Speaker Bruce E. Phipps CPP APA Vice Presindent 2011 APA Payroll Man of the Year Principal

More information

BCP. from Theory to Practice. Theory Business Continuity Management Overview. Presented by Mark Pryce & Karl D. Bryant.

BCP. from Theory to Practice. Theory Business Continuity Management Overview. Presented by Mark Pryce & Karl D. Bryant. BCP from Theory to Practice Presented by Mark Pryce & Karl D. Bryant 18 March 2013 Theory Business Continuity Management Overview Karl D. Bryant, CBCP, MBCI, PMP, CBCLA Senior Vice President Marsh Risk

More information

DRJ Spring World 2009

DRJ Spring World 2009 DRJ Spring World 2009 Continuously Drive, Recognize, Exploit, and Create value from your BC/DR program with an Recovery Lifecycle Management approach Recovery Lifecycle Management Rick Galietta / David

More information

The ABCs of BDR: A Primary on the Essentials of Backup and Disaster Recovery

The ABCs of BDR: A Primary on the Essentials of Backup and Disaster Recovery WHITE PAPER The ABCs of BDR: A Primary on the Essentials of Backup and Disaster Recovery 1. INTRODUCTION In an increasingly data-driven world, the need for businesses to plan for the continuity of operations

More information

Energy Exchange Talking Points Resilience for Mission Assurance: Value Proposition of Resilience Investments August 17, 2017

Energy Exchange Talking Points Resilience for Mission Assurance: Value Proposition of Resilience Investments August 17, 2017 Slide 1 Thank you for inviting me back to speak. So, I was looking at the presentation in Phoenix and noticed something. This topic of energy resilience was embedded in one of the sessions within the Integrated

More information

The NextGen of BC/DR Planning

The NextGen of BC/DR Planning The NextGen of BC/DR Planning Jim Mitchell, Director ebrp Solutions Tools for Next Generation of Planning Tools What do they do? Benefits What are the benefits of using a tool? Market Scan Tools currently

More information

Challenges and Direction of Business Continuity

Challenges and Direction of Business Continuity Challenges and Direction of Business Continuity Don DeMarco Vice President IBM Business Resilience & Security Services Let s go back to mid-2000 The Future State of Our Industry: Business Process Continuity

More information

The Future of Workload Automation in the Application Economy

The Future of Workload Automation in the Application Economy The Future of Workload Automation in the Application Economy Success Requires Agility in the Application Economy The link between data center operations and business agility has never been stronger. If

More information

Business Continuity Maturity Model (BCMM) Overview & Standards Compliance Assessment v2.5

Business Continuity Maturity Model (BCMM) Overview & Standards Compliance Assessment v2.5 Business Continuity Maturity Model (BCMM) Overview & Standards Compliance Assessment v2.5 Virtual Corporation, Inc. 100 Enterprise Drive Suite 301 Rockaway, NJ 07866 973-426-1444 virtual-corp.com/business-continuity

More information

Business Continuity Planning. LGMA Conference October 27, 2011 Presented by Lisa Benini

Business Continuity Planning. LGMA Conference October 27, 2011 Presented by Lisa Benini Business Continuity Planning LGMA Conference October 27, 2011 Presented by Lisa Benini What is it? Business Continuity Planning Definition: Process of developing and documenting advance arrangements and

More information

Starting a Vendor Assessment Program

Starting a Vendor Assessment Program Starting a Vendor Assessment Program Kevin Brandt, CBCP Agenda Why? Wait Really Why? Overview Policies and Procedures Implementation Work Effort Assessment Tips Special Case What About? Looking Forward

More information

RISK ENGINEERING GUIDELINE

RISK ENGINEERING GUIDELINE RISK ENGINEERING GUIDELINE BUSINESS CONTINUITY MANAGEMENT (BCM) HDI Risk Consulting Business Interruption www.hdi.global Development and Implementation of a Business Continuity Management System (BCMS)

More information

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM)

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM) The Intersection of Enterprise-wide Risk (ERM) and Business Continuity (BCM) Marc Dominus 2005 Protiviti Inc. EOE Agenda Terminology and Process Introductions ERM Process Overview BCM Process Overview

More information

Backups Can Drive a Successful Data Management Strategy

Backups Can Drive a Successful Data Management Strategy Backups Can Drive a Successful Data Management Strategy Keeping everything forever is not a strategy, not keeping enough will get you fired! INTRODUCTION Gone are the days of managing backups just for

More information

TECHNOLOGY brief: Event Management. Event Management. Nancy Hinich-Gualda

TECHNOLOGY brief: Event Management. Event Management. Nancy Hinich-Gualda TECHNOLOGY brief: Event Event Nancy Hinich-Gualda Principal Consultant CA s Table of Contents Executive Summary 1 section 1: Challenge 2 Simplifying ITIL How to Use the CA Process Maps Section 4: Conclusions

More information

Critical IT Incident Management Best Practices: IT Experts on Communication and Collaboration

Critical IT Incident Management Best Practices: IT Experts on Communication and Collaboration Critical IT Incident Management Best Practices: IT Experts on Communication and Collaboration The Impact of IT Incidents and Disasters When an IT incident causes system downtime and service disruptions,

More information

BCS ITILF Exam. Volume: 289 Questions

BCS ITILF Exam. Volume: 289 Questions Volume: 289 Questions Question No: 1 Which of the following are sources of best practice? 1. Academic research 2. Internal experience 3. Industry practices A. All of the above B. 1 and 3 only C. 1 and

More information

2014 new ITIL Foundation exam (2011 syllabus) Practice sample questions (220+) PDF file download

2014 new ITIL Foundation exam (2011 syllabus) Practice sample questions (220+) PDF file download 2014 new ITIL Foundation exam (2011 syllabus) Practice sample questions (220+) PDF file download Number: EX0-117 Passing Score: 800 Time Limit: 120 min File Version: 12.5 2014 new ITIL Foundation exam

More information

(ISC)2 CISSP EXAM BUNDLE

(ISC)2 CISSP EXAM BUNDLE (ISC)2 CISSP EXAM BUNDLE Number: CISSP Passing Score: 800 Time Limit: 120 min File Version: 42.2 http://www.gratisexam.com/ (ISC)2 CISSP EXAM BUNDLE Exam Name: (ISC)2 Certified Information Systems Security

More information

Developing an Effective Disaster Recovery Plan

Developing an Effective Disaster Recovery Plan Developing an Effective Disaster Recovery Plan We will figure it out! or What is the point, anyway? January 2017 1 MHA CONSULTING, INC. KEY FACTS A 17-year proven track record of applying industry standards

More information

Abraham E. Binder MA, ABCP York University Disaster & Emergency Management Program

Abraham E. Binder MA, ABCP York University Disaster & Emergency Management Program Abraham E. Binder MA, ABCP York University Disaster & Emergency Management Program TTX Basics Real Relevant Refreshed Questions TTX Fundamentals Intermediate level For busy leadership teams Not a Walkthrough

More information

An Overview of the AWS Cloud Adoption Framework

An Overview of the AWS Cloud Adoption Framework An Overview of the AWS Cloud Adoption Framework Version 2 February 2017 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Notices This document is provided for informational purposes

More information

Management Update: A Business Continuity Management Program Is Critical

Management Update: A Business Continuity Management Program Is Critical IGG-07162003-03 R. Witty Article 16 July 2003 Management Update: A Business Continuity Management Program Is Critical Enterprises that do not have a business continuity management (BCM) program are on

More information

Strategic Business Continuity Management

Strategic Business Continuity Management Strategic Business Continuity Management Steven J. Ross Deloitte & Touche New York Prospering in the Secure Economy Leading organizations must confront the new realities of today s uncertain economy The

More information

Citizens Property Insurance Corporation Business Continuity Framework

Citizens Property Insurance Corporation Business Continuity Framework Citizens Property Insurance Corporation Framework Dated September 2015 Approvals: Risk Committee: September 17, 2015 (via email) Adopted by the Audit Committee: Page 1 of 12 Table of Contents 1 INTRODUCTION...

More information

Operational Resilience Measure and Report

Operational Resilience Measure and Report Operational Resilience Measure and Report 26 Sept 2017 Lewis McKenzie Andrew Charlton Evolution of Resilience Regulation Regulatory Challenge Board accountability for critical infrastructure. Requirement

More information

ISO Business Continuity Management. Your implementation guide

ISO Business Continuity Management. Your implementation guide ISO 22301 Business Continuity Management Your implementation guide Build a robust and resilient organization with ISO 22301 It s never been more important to protect your business from the unexpected.

More information

Business Continuity and Disaster Recovery Overview

Business Continuity and Disaster Recovery Overview Business Continuity and Disaster Recovery Overview Prepared by, Ingram Micro Cloud, META Contents 1. Introduction... 3 2. Overview of (BC/DR)... 4 2.1 What is the difference between business continuity

More information

BACK TO BASICS BUSINESS CONTINUITY MANAGEMENT 101. June 11, 2013

BACK TO BASICS BUSINESS CONTINUITY MANAGEMENT 101. June 11, 2013 BACK TO BASICS BUSINESS CONTINUITY MANAGEMENT 101 June 11, 2013 Your Presenter Shanda Chronowich, CBCP, CRM Senior Manager MNP LLC 2 There cannot be a crisis next week. My schedule is already full. U.S.

More information

The Basics of ITIL Help Desk for SMB s

The Basics of ITIL Help Desk for SMB s The Basics of ITIL Help Desk for SMB s This three-step process will provide you the information necessary to understand ITIL, help you write your strategic IT plan and develop the implementation plan for

More information

Moving data successfully: Take 10 for a smooth transition to new storage

Moving data successfully: Take 10 for a smooth transition to new storage EXECUTIVE WHITE PAPER Moving data successfully: Take 10 for a smooth transition to new storage A lot can transpire between the time you take delivery of your new storage and the day it s fully integrated

More information

Business Resilience They Cannot Do This Without You!

Business Resilience They Cannot Do This Without You! Business Resilience They Cannot Do This Without You! Maureen Roskoski, Facility Engineering Associates PC Laurie Gilmer, Facility Engineering Associates PC Meet Our Presenters: Maureen K. Roskoski, CFM,

More information

CASE STUDY FULLY MANAGED IZO HYBRID CLOUD PLATFORM GIVES INFOR FUTURE-PROOF COMPUTING.

CASE STUDY FULLY MANAGED IZO HYBRID CLOUD PLATFORM GIVES INFOR FUTURE-PROOF COMPUTING. CASE STUDY FULLY MANAGED IZO HYBRID CLOUD PLATFORM GIVES INFOR FUTURE-PROOF COMPUTING. MISSION-CRITICAL MANUFACTURING APPS FROM INFOR HOSTED BY TATA COMMUNICATIONS CONFER COMPETITIVE EDGE ON ONE OF THE

More information

INTELLECTUAL PROPERTY MANAGEMENT ENTERPRISE ESCROW BEST PRACTICES REPORT

INTELLECTUAL PROPERTY MANAGEMENT ENTERPRISE ESCROW BEST PRACTICES REPORT INTELLECTUAL PROPERTY MANAGEMENT ENTERPRISE ESCROW BEST PRACTICES REPORT What is Mission Critical to You? Before you acquire mission-critical technology from a third-party software vendor, take a few minutes

More information

Achieving Enterprise Resiliency and Corporate Certification August 2, 2013

Achieving Enterprise Resiliency and Corporate Certification August 2, 2013 The following article was created to explain how a company can achieve more effective recovery and compliance through Enterprise Resiliency and Corporate Certification. It is intended to provide a solid

More information

David Nolan, CEO Fusion Risk Management, Inc.

David Nolan, CEO Fusion Risk Management, Inc. David Nolan, CEO Fusion Risk Management, Inc. Business Continuity Risk Management ( BCRM ) What Defining BCRM Why Justifying BCRM Who Organizing BCRM Roles How Establishing a BCRM Process When Sustaining

More information