Enterprise-wide Business Continuity and Disaster Recovery Planning. Presented by Kelley Okolita

Size: px
Start display at page:

Download "Enterprise-wide Business Continuity and Disaster Recovery Planning. Presented by Kelley Okolita"

Transcription

1 Enterprise-wide Business Continuity and Disaster Recovery Planning Presented by Kelley Okolita

2 Don t get caught without a plan

3 Gloom and Doom My job and yours is to preach Doom and Gloom

4 Planning, not panic In order to make sure we plan for potential risks

5 What to plan for Loss of site Loss of technology Loss of people Organizational Crisis

6 Obtaining Management Commitment Management should have a documented responsibility to the company in the development and testing of a viable Business Recovery Plan Without management commitment to this project, it will fail Require Management sign off and approvals at each major milestone of the project

7 Phased Approach Emergency Notification List Vital records backup and recovery Risk and Business Impact Analysis Strategy Development Alternate Site selection and planning Plan Development Testing, maintenance, update

8 Building a Team Business Resumption Plan Emergency Notification Emergency Response Recovery

9 Emergency Notification Identify the different types of recovery you will plan for Identify who would have the authority to declare a disaster depending on the scenario Identify who would be part of the recovery effort Build your notification list based on this information

10 Vital Records Do you know: Where they are? What is included in them? How to get them? Who is authorized to retrieve them? How long it will take to retrieve them? Where to have them delivered? How long it will take to restore them?

11 Risk Analysis Identify Business Risks Estimate Probabilities of Risk Occurring Identify Mitigating Factors Implement or Initiate Additional Controls Where Possible Risk analysis tells us where to spend our mitigating dollars

12 Risk Assessment Elements of Risk Threats Assets Mitigating Controls

13 Risk Definitions Financial Strategic Organizational Technology Operational Legal/Regulatory Risks that are an inherent part of the business environment and have an effect on business objectives and performance Risks that are part of a unit s environment relating to people, culture, organizational structure and values that can impact overall organization effectiveness Risks associated with the use of systems and technology, including availability, capacity integrity, operational support, functionality systems integration and change management Risks relating to enforceability of contracts, interpretation of laws, compliance with law and impact of regulation Liquidity, Cap & Funding Credit Market People Process Events Inability to raise debt or equity capital as needed for shortterm liquidity or long-term growth, as well as uncertainty in pricing or sales of assets or liabilities Exposure to loss relating to a change in the credit-worthiness of a counter-party, collateral, customer or partner that may impact the counterparty s ability to fulfill its obligations under a contractual agreement The uncertainty in the future market value of a portfolio of assets and / or liabilities The risk of loss resulting from people The risk of loss resulting from inadequate or failed processes The risk of loss resulting from an unexpected event That interferes With normal business

14 Protecting People and Workspaces Access Control/Key Management Alarm Monitoring Floor Warden/Evacuation Drills Background Investigations Workplace Violence Programs Landscape Design Lighting Cameras Visitor procedures Backup Power systems Facility design/facility sighting

15 Protecting Information Information Security policy and procedures Privacy Policy Firewalls Intrusion Detection Strong Passwords Controlling access to information/standard Access Definitions Vendor Management Secure offsite storage Proprietary Waste Disposal Virus Protection and Response

16 Protecting Reputation Strong Governance Media trained Communication Plans Internal and external audits Operational Management Recoverability Code of Ethics

17 Business Impact Analysis Identify Business Functions Determine Impact of incident Estimate Business loss Determine Recovery Timeframes Gather Requirements for Recovery Business Impact Analysis tells us how long we have before we need to be back in business

18 Impact of a Disaster A disaster may impact... Your Paycheck Company Reputation Customers Ability to meet regulatory requirements

19 Recovery Strategies for Business Recovery strategies will be driven by the recovery timeframe of the function. Recovery options might include the following: Self-service - A business can transfer work to another of its own locations which have available facilities Internal Arrangement - Training rooms, cafeterias, conference rooms, etc... may be equipped to support business functions. Reciprocal Agreements - Other business units may be able to accommodate those affected. This could involved the temporary suspension of non-critical functions at the business units not affected by the outage. Dedicated alternate sites - Built by your company to accommodate critical function recovery. External Suppliers - A number of external companies offer facilities covering a wide range of business recovery needs. No arrangement - for low priority business functions it may not be cost justified to plan to a detailed level. The minimum requirement would be to record a description of the functions, the maximum allowable lapse time for recover, and a list of the resources required.

20 Recovery Strategies for Technology Dual Data Center The applications are split between two geographically dispersed data centers and either load balanced between the two centers or hot swapped between to the two centers. Internal Hot site this site is standby ready with all necessary technology and equipment necessary to run the applications recovered there. External Hot Site - This strategy has equipment on the floor waiting for recovery but the environment must be re-built for the recovery. These are services contracted through a recovery service provider. Warm Site A leased or rented facility that is usually partially configured with some equipment, but not the actual computers. It will generally have all the cooling, cabling and networks in place to accommodate the recovery but the actual servers, mainframe etc equipment are delivered to the site at time of disaster. Cold Site A cold site is a shell or empty data center space with no technology on the floor. All technology must be purchased or acquired at the time of disaster.

21 Documenting the Plan When an emergency happens, everyone needs to know what to do next: GATHER, ASSESS, DECIDE, MOBILIZE, COMMUNICATE, and RECOVER The plan document needs to address all of this

22 Plan Components Purpose, Objectives and Assumptions Human Resources how you will take care of the people Finance How you will track and pay for recovery expenses Communications How you will communicate with stakeholders Recovery Strategies how you will recover Recovery Management how you will manage the over all recovery effort Declaration Procedures how a disaster is declared Offsite Storage procedures how to get your stuff back Alternate site location and directions Command Center locations Seat Assignments in the alternate site Recovery Priorities for Business operations and technology Logistics how you will manage logistical support for recovery (travel, food) Detailed recovery procedures

23 Exercising the Plan Types of Exercises Call Notification Walkthrough Actual/Simulated Comprehensive Set Exercise Objectives Develop an Exercise Plan Conduct the Exercises Document Exercise Results Plan Maintenance

24 Transition from Project to Program Business Continuity needs to become part of the culture of the organization Every single employee needs to know the answer to the question Use Business Continuity tools and practices to manage everyday events

25 Program Requirements Deliverables Emergency Notification List Business Functions/ Resource Requirements Business Resumption Plans with sign-off Training & Awareness Vital Records Program Technology Reviews Call Exercise Walk-Through Exercise Simulated Or Actual Exercise Compact Exercise Systems Loss Test Technology Recovery Exercises Due date Quarterly Semi-Annually Annually Quarterly On-going Annually Semi-Annually Annually Semi-Annually Annually Annually Semi-Annually

26

27 Technology Recovery Status Platform or Application RTO Last Tested Procedures Current & Offsite Recovery met RTO End User Validated Batch Cycle Recovered Successfully Mainframe 24 hours 02/13/2009 NA Peoplesoft 24 hours 02/13/2009 NA Accounting System 36 hours 02/13/2009 Website 12 hours 02/13/2009 NA

28 Imbedding in the Culture Event Management Process Facility Events Technology Events Workforce Impairment Events Information Security Events Crisis Leadership

29 Event Management Contingencies start with Event Management If you do not properly manage Events, all the other Risks may occur Event Management is about Communication and Response Event Management needs to be practiced

30 Goals of Event Management Single Source of Information Triage Rapid Escalation Consistent Problem Management Rumor Control Make sure everyone who needs to know does Allow the problem solvers room to solve Playbook which documents key roles and responsibilities Nearly everyone wants this and agrees that it is needed.

31 Process of Event Management Central reporting location Standing conference bridge Automated notification system Assessment Teams built by event type Team for very location Team for every primary application Assessment team contacted first Escalation needs decided at assessment based on event level Who else needs to know/who else needs to help

32 HERO Team Members Crisis Management Team Event Owner Technology Services Facilities/Real Estate Claims Info Security Regional Management LOCAL RVP, REGIONAL PRESIDENT TSC Contingency Planning/Crisis Team Leader Human Resources Event Management Team Event Manager Business Operations/Leader Technology Services Finance HR/Real Estate Claims Legal/Compliance Corporate Communications Contingency Planning Risk and Insurance Key Business Stakeholders - Event Communicator Call Center Mgmt Agency Services Mgmt Business Continuity Planners Business Leads

33 Communications by Event Level Event Level Management Teams Response Teams 0-1 per year 9/11 Catastrophic loss of Main office Katrina Executive Management Team Event Management Team (Technical, Business, Customer) Make Big Decisions Manage, Translate & Communicate Response Teams (Customer) Response Teams (Technical & /Business) Receive Communications & Act Investigate, Resolve & Update Crisis Management Team Investigate, Resolve, Update 3-6 per year Core system outages Facility fire Event Management Team (Manage Business Impact and Response) Crisis Management Team (Own fixing the problem) Response Teams - Customer (Communicate) Response Teams - Technical/Business (fix the problem) per year Power outages Severe weather Water leaks Outward facing application issues 100 s per year Server failure Internal Application issue Hurricane that doesn t hit Crisis Management Team (Own fixing the problem) Response Teams - Technical/Business (fix the problem) Response Teams - Technical/Business (fix the problem)

34 How ready are you? Pretend you are evacuated right now and you are standing in your assembly area and Facilities tells you that you can not work in the building for at least the next 2 weeks, Do you know what to do next? Does your staff? Business Continuity Planner HERO Initial Response Plans Alternate sites Pandemic Planning Testing

35 Step 1 Identify your team Identify your team and make certain you know how to reach them in an emergency

36 Step 2 Identify your vital records Identify vital records Procedure manuals forms vendor lists contact lists customer lists contracts source documents

37 Step 3 Identify Your Business Functions Identify the business functions for your functional areas Perform risk and business impact analysis for each function Establish the recovery time for your business functions Identify minimum staff requirements Identify Interdependencies

38 Step 4 Identify your desktop requirements Minimum desktop configuration Application connectivity Voice Requirements phones Fax Modems Print Requirements Proprietary software running on desktop

39 Step 5 Define Recovery Strategy Develop recovery strategy for business functions and technology based on the recovery priority

40 Step 6 Internal Site Survey Survey existing sites Identify equipment/phone services Identify desktops to be used for contingency Identify staff to be displaced or moved to off shift

41 Step 7 External Site Recovery Prepare RFP which includes all requirements Identify essential vs. nice to have Receive proposals from vendors Compare for requirements and costs Visit sites identified as potential vendors Select vendors

42 Step 8 Internal Systems Identify all platforms and applications supported by internal systems group Identify recovery priority for each application Identify recovery strategy which meets the business requirements Develop recovery procedures for critical applications

43 Step 9 Document Plan Pull the information together into a plan document and distribute

44 Step 10 Train your staff Everyone should know the answer to the question : If you couldn t get back in your building today, what would you do next?

45 Step 11 TEST, TEST, TEST Event Management tests Alternate site tests Test alternate site

46 Don t be the one taken by storm!! It could happen anywhere...

47 Don t get caught without a plan

CPOtracker Template Package

CPOtracker Template Package CPOtracker Template Package A set of companion planning documents complimenting your CPOtracker software system www.cpotracker.com The CPOtracker Template Package is an affordable and easy-to-use framework

More information

BCP Methodology Benefits realisation

BCP Methodology Benefits realisation www.pwc.com.cy BCP Methodology Benefits realisation Risk Assurance Consulting (RAC) Risk Assurance Consulting (RAC) helps management to make well informed decisions. The insight and independent assurance

More information

Business Continuity Through Planning, Prevention and Preparedness. READINESS RESOURCES

Business Continuity Through Planning, Prevention and Preparedness.  READINESS RESOURCES READINESS RESOURCES Federal Emergency Management Agency -- www.fema.gov Emergency Management Guide for Business & Industry: http://www.fema.gov/pdf/business/guide/bizindst.pdf American Red Cross -- www.redcross.org

More information

Building a Standard for Business Continuity Planning

Building a Standard for Business Continuity Planning Building a Standard for Business Continuity Planning John Lugo Sr. Business Continuity Analyst April 17, 2012 1 April 16 18, 2012 Talking Stick Resort Scottsdale, Arizona Business Continuity @ Citrix Statistics

More information

Disaster Recovery Planning Process

Disaster Recovery Planning Process Page 1 of 8 Disaster Recovery Planning Process By Geoffrey H. Wold Part I of III This is the first of a three-part series that describes the planning process related to disaster recovery. Based on the

More information

Protecting Information Assets - Week 9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets

Protecting Information Assets - Week 9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets Protecting Information Assets - Week 9 - Business Continuity and Disaster Recovery Planning MIS5206 Week 9 Case study discussion Business Continuity Planning (BCP) and Disaster Recovery (DR) Planning Test

More information

Citizens Property Insurance Corporation Business Continuity Framework

Citizens Property Insurance Corporation Business Continuity Framework Citizens Property Insurance Corporation Framework Dated September 2015 Approvals: Risk Committee: September 17, 2015 (via email) Adopted by the Audit Committee: Page 1 of 12 Table of Contents 1 INTRODUCTION...

More information

10 Steps to Preparedness

10 Steps to Preparedness 10 Steps to Preparedness Prepare to Survive. Today s Key Take-Aways Review basics of disaster recovery and business continuity. Understand what you can do to prepare your organization for an unplanned

More information

BCP Methodology Benefits realisation

BCP Methodology Benefits realisation www.pwc.com.cy/technology-consulting BCP Methodology Benefits realisation BCP Methodology Our BCP methodology incorporates five (5) phases. The phases take an organisation from prioritising core business

More information

Business Continuity Through Planning, Prevention and Preparedness. READINESS RESOURCES

Business Continuity Through Planning, Prevention and Preparedness.   READINESS RESOURCES READINESS RESOURCES Federal Emergency Management Agency Emergency Management Guide for Business & Industry: www.fema.gov/pdf/business/guide/bizindst.pdf PS-Prep - www.fema.gov/ps-preptm-voluntary-private-sector-preparedness

More information

Business Continuity Framework

Business Continuity Framework Business Continuity Framework A definition to the Components of Resiliency March, 1 Business Continuity Framework 1. INTRODUCTION... 3 2. PURPOSE... 3 3. THE FRAMEWORK... 4 4. STEERING COMMITTEE... 5 5.

More information

Creating an Actionable Disaster Recovery Plan

Creating an Actionable Disaster Recovery Plan Creating an Actionable Disaster Recovery Plan Presentation Outline Plan Justification Disaster Definitions & Facts Costs of a Disaster Benefits of Planning Building an Actionable Disaster Recovery Plan

More information

NATURAL DISASTERS AND THE WORKPLACE

NATURAL DISASTERS AND THE WORKPLACE NATURAL DISASTERS AND THE WORKPLACE Eight Steps Employers Should Take to Prepare Their Workplace for a Natural Disaster We may think, Natural disasters can t happen here, or That couldn t happen to us,

More information

BUSINESS CONTINUITY MANAGEMENT

BUSINESS CONTINUITY MANAGEMENT Loss Control BUSINESS CONTINUITY MANAGEMENT Preparing for the Unexpected Preparing your organization for a disaster can be an overwhelming task, but the risk of being unprepared can be even more devastating.

More information

An introduction to business continuity planning

An introduction to business continuity planning An introduction to business continuity planning What is business continuity, and is it relevant to me? Business continuity planning is about identifying the critical functions and services your business

More information

Effectively Communicating Enterprise-Wide Business Continuity to Senior Management and Stakeholders. October 7, 2014

Effectively Communicating Enterprise-Wide Business Continuity to Senior Management and Stakeholders. October 7, 2014 Effectively Communicating Enterprise-Wide Business Continuity to Senior Management and Stakeholders October 7, 2014 Agenda Background Program Elements What Makes it Enterprise-wide Recommended Strategies

More information

OmniMath, Inc. Business Continuity Services Overview

OmniMath, Inc. Business Continuity Services Overview OmniMath, Inc. Management Consultants P.O. Box 20440 Columbus Circle Station New York, NY 10023 (212) 865 5400 Business Continuity Services Overview Page Introduction 2 Business Continuity Goals 4 Key

More information

BUSINESS CONTINUITY: PROTECTING YOUR BUSINESS FUTURE

BUSINESS CONTINUITY: PROTECTING YOUR BUSINESS FUTURE BUSINESS CONTINUITY: PROTECTING YOUR BUSINESS FUTURE An insight into the current environment and importance that business continuity has on your business reputation. Table of Contents Introduction 3 Current

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning 4 Business Continuity Planning and Disaster Recovery Planning Learning Objectives To understand the concept of Business Continuity Management; To understand the key phases and components of a Business

More information

David Nolan, CEO Fusion Risk Management, Inc.

David Nolan, CEO Fusion Risk Management, Inc. David Nolan, CEO Fusion Risk Management, Inc. Business Continuity Risk Management ( BCRM ) What Defining BCRM Why Justifying BCRM Who Organizing BCRM Roles How Establishing a BCRM Process When Sustaining

More information

5/28/2018. Disaster Recovery Are You Ready. Speaker. Agenda

5/28/2018. Disaster Recovery Are You Ready. Speaker. Agenda Disaster Recovery Are You Ready Central Iowa American Payroll Association 2017 Statewide Conference Friday October 6 Speaker Bruce E. Phipps CPP APA Vice Presindent 2011 APA Payroll Man of the Year Principal

More information

Roger Peters Founder, Continuity Onward, Inc

Roger Peters Founder, Continuity Onward, Inc Roger Peters Founder, Continuity Onward, Inc. ContinuityOnward@gmail.com 612-360-3063 1 Welcome to secure360 2013 Don t forget to pick up your Certificate of Attendance at the end of each day. Please complete

More information

Protecting Information Assets - Unit #9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets

Protecting Information Assets - Unit #9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets Protecting Information Assets - Unit #9 - Business Continuity and Disaster Recovery Planning Agenda Contingency Planning (CP) IT Security Control Class and Family Business Continuity and Disaster Recovery

More information

Global Crises: What We Really Need to Do to Be Prepared. Day One / Session C5

Global Crises: What We Really Need to Do to Be Prepared. Day One / Session C5 Global Crises: What We Really Need to Do to Be Prepared Day One / Session C5 April 12, 2010 Clyde Berger Adam Chusid 0 Today s Objectives Present practical solutions for building a viable sustainable program

More information

Unit 3: Elements of a Viable Continuity Capability

Unit 3: Elements of a Viable Continuity Capability Unit 3: Elements of a Viable Continuity Capability Unit 3 Objectives Identify all organization essential functions and their effect upon staffing levels in a continuity event. Recognize and incorporate

More information

Continuity of Operations (COOP) For EMS Agencies

Continuity of Operations (COOP) For EMS Agencies Continuity of Operations (COOP) For EMS Agencies When the disaster hits home Linda A. Reissman, M.S. CIPS, EMT NYSVARA Pulse Check Conference Sept. 24, 2011 1 "There are risks and costs to a program of

More information

The Disaster Experience: Putting Business Continuity to the Test

The Disaster Experience: Putting Business Continuity to the Test The Disaster Experience: Putting Business Continuity to the Test Presented by Bob Mellinger, CBCV OM33 5/5/2018 1:15 PM The handout(s) and presentation(s) attached are copyright and trademark protected

More information

Business Continuity Planning. LGMA Conference October 27, 2011 Presented by Lisa Benini

Business Continuity Planning. LGMA Conference October 27, 2011 Presented by Lisa Benini Business Continuity Planning LGMA Conference October 27, 2011 Presented by Lisa Benini What is it? Business Continuity Planning Definition: Process of developing and documenting advance arrangements and

More information

LB35: Verifying IT and Business Continuity. Lucas G. Aimes & Terry DiVittorio, Project Performance Corporation (PPC)

LB35: Verifying IT and Business Continuity. Lucas G. Aimes & Terry DiVittorio, Project Performance Corporation (PPC) LB35: Verifying IT and Business Continuity Lucas G. Aimes & Terry DiVittorio, Project Performance Corporation (PPC) Introductions Lucas G. Aimes Deputy Practice Lead, Verification & Verification Practice

More information

Business Continuity Training and Testing: Narrowing the Gaps

Business Continuity Training and Testing: Narrowing the Gaps Business Continuity Training and Testing: Narrowing the Gaps Betty A. Kildow, CBCP, FBCI, Emergency Management Consultant Kildow Consulting 765/483-9365; BettyKildow@insightbb.com 92 nd Annual International

More information

Top 5 Things to Transform your Business Continuity Program

Top 5 Things to Transform your Business Continuity Program Top 5 Things to Transform your Business Continuity Program John Liuzzi National Director of Business Continuity Southern Glazer s Wine & Spirits Tejas Katwala Co-Founder & CEO Continuity Logic 5 Transformative

More information

1/8/2015. Learning Objectives. Why have a plan? Emergency Preparedness, Business Continuity, and Disaster Recovery. Can you anticipate the unexpected?

1/8/2015. Learning Objectives. Why have a plan? Emergency Preparedness, Business Continuity, and Disaster Recovery. Can you anticipate the unexpected? Emergency Preparedness, Business Continuity, and Disaster Recovery APPA-Institute for Facilities Management J. Craig Klimczak, D.V.M., M.S. 321 South Mosley Road St. Louis, MO 63141 compuvet@aol.com Learning

More information

BUSINESS CONTINUITY: PROTECTING YOUR BUSINESS FUTURE

BUSINESS CONTINUITY: PROTECTING YOUR BUSINESS FUTURE BUSINESS CONTINUITY: PROTECTING YOUR BUSINESS FUTURE An insight into the current environment and importance that business continuity has on your business reputation. 1 Table of Contents Introduction 3

More information

Crisis Management Who s In Charge?

Crisis Management Who s In Charge? Crisis Management Who s In Charge? Presented by: Cynthia Simeone, CBCP, PMP Satori Consulting Judith Walker, PMP Goldman Sachs Crisis Management What is Crisis Management? Crisis Management involves identifying

More information

ENTERPRISE CONTINUITY PLANNING PRINCIPLE OF DISASTER RECOVERY AND ENTERPRISE CONTINUITY. Presented by: John O. Adeika

ENTERPRISE CONTINUITY PLANNING PRINCIPLE OF DISASTER RECOVERY AND ENTERPRISE CONTINUITY. Presented by: John O. Adeika ENTERPRISE CONTINUITY PLANNING PRINCIPLE OF DISASTER RECOVERY AND ENTERPRISE CONTINUITY Presented by: John O. Adeika The Roles of DRP/ECP Team Members The process of DRP/ECP is a concatenated process involving

More information

How to move from crisis response to crisis management

How to move from crisis response to crisis management How to move from crisis response to crisis management Published on 19 Sep 2018 Governments and corporations face crisis events every day. An active shooter terrorises a campus. A cyber extortionist holds

More information

Disaster Planning Checklist for Chief Financial Officers of Healthcare Organizations

Disaster Planning Checklist for Chief Financial Officers of Healthcare Organizations According to the National Safety Council, the 10 most common problems or errors with emergency response plans are: 1. No upper management support 7. No communication methods to alert employees 2. Lack

More information

Staying Disaster-Ready in Treasury

Staying Disaster-Ready in Treasury Staying Disaster-Ready in Treasury A KEY ASPECT OF ANY BUSINESS CONTINUITY PLAN Where to Start?...2 Communications in a Crisis...3 Partner with Your Bank...3 Test to Evaluate Preparedness...5 All businesses

More information

BCM Lite a quick and easy guide to BCM for beginners and/or small businesses

BCM Lite a quick and easy guide to BCM for beginners and/or small businesses BCM Lite a quick and easy guide to BCM for beginners and/or small businesses Some important definitions Business Continuity Planning The process leading to a clearly defined and documented plan for use

More information

12.0 Business Continuity Management

12.0 Business Continuity Management Number 12.0 Policy Owner Information Security and Technology Policy Business Continuity Management Effective 01/01/2014 Last Revision 12/30/2013 Department of Innovation and Technology 12. Business Continuity

More information

Business Continuity Planning: As A Business Owner, What Do I Need to Consider? David Sutton Manager, Environment, Safety and Health.

Business Continuity Planning: As A Business Owner, What Do I Need to Consider? David Sutton Manager, Environment, Safety and Health. Business Continuity Planning: As A Business Owner, What Do I Need to Consider? David Sutton Manager, Environment, Safety and Health June 15, 2006 Qualifying Event Continuum Normal Business Operations Business

More information

Treasury Cyber Response Planning for a Quick Recovery

Treasury Cyber Response Planning for a Quick Recovery Treasury Cyber Response Planning for a Quick Recovery A clear, robust recovery plan that is tested regularly is essential if companies are to meet the challenge of an increasing number and variety of cyberthreats.

More information

BUSINESS CONTINUITY: PROTECTING YOUR BUSINESS FUTURE

BUSINESS CONTINUITY: PROTECTING YOUR BUSINESS FUTURE BUSINESS CONTINUITY: PROTECTING YOUR BUSINESS FUTURE An insight into the current environment and importance that business continuity has on your business reputation. Table of Contents Introduction 3 Current

More information

Business Recovery & Continuity Plan

Business Recovery & Continuity Plan Page 1 of 22 Business Recovery & Continuity Plan Document Control Responsible Person Review Frequency Reviewed by Chief Executive 3-Yearly (Strategic Review) Board Date Approved November 2017 Next Review

More information

How to apply the 10 BCP best practices to Treasury

How to apply the 10 BCP best practices to Treasury How to apply the 10 BCP best practices to Treasury Jill Piligra, Vice President Treasury Management Sales Consultant Seth Marlowe, Vice President Solutions Sales Consultant AFPWNY Lunch Meeting April 17,

More information

Business Resilience: Equipping the FM for Success

Business Resilience: Equipping the FM for Success Business Resilience: Equipping the FM for Success CEUs & CFM Maintenance Points You are eligible to receive Continuing Education Units and Certified Facility Manager maintenance points for attending sessions

More information

Keys to Narrowing Business Continuity Planning Gaps: Training, Testing & Audits

Keys to Narrowing Business Continuity Planning Gaps: Training, Testing & Audits Keys to Narrowing Business Continuity Planning Gaps: Training, Testing & Audits Betty A. Kildow, CBCP, FBCI, Emergency Management Consultant Kildow Consulting 765/483-9365; BettyKildow@comcast.net 94 nd

More information

Going Global. Michael Lazcano

Going Global. Michael Lazcano Going Global Michael Lazcano Agenda Building the organization where to start The shape of your organization The Scope of responsibility Crisis leadership starts with practice Summary and questions 1 Building

More information

Business Recovery & Continuity Plan

Business Recovery & Continuity Plan Page 1 of 22 Business Recovery & Continuity Plan Document Control Responsible Person Review Frequency Reviewed by Chief Executive 3-Yearly (Strategic Review) Board Date Approved November 2017 Next Review

More information

Introduction to BCP and DR Planning

Introduction to BCP and DR Planning Introduction to BCP and DR Planning Based on the book RESPONSE! Planning & Training for Emergency Recovery November 24, 2015 Tim Elemes Huber Advisors P.O. Box 175 Hugo, MN 55038 information@huberadvisors.com

More information

Service Business Plan

Service Business Plan Service Business Plan Service Name Information Technology Service Type Internal Service Owner Name Christine Swenor Budget Year 2017 Service Owner Title Service Description Director of IT Services An internal

More information

Citi Institutional Clients Group - Business Continuity Management

Citi Institutional Clients Group - Business Continuity Management Citi Institutional Clients Group - Business Continuity Management Enterprise Risk Management Establishing a Risk Control-based Continuity Program, CBCP, CBCP Senior Vice President, Citi Institutional Clients

More information

CONTINUITY OF OPERATIONS PLAN

CONTINUITY OF OPERATIONS PLAN CONTINUITY OF OPERATIONS PLAN (TEMPLATE) NAME OF ORGANIZATION/BUSINESS ADDRESS PHONE NUMBER Organization Logo Continuity of Operations Plan Version 1.5 Table of Contents I. Introduction... 1 II. Purpose...

More information

DISASTER PREPAREDNESS Guide & Template

DISASTER PREPAREDNESS Guide & Template Go Beyond The Cloud STEP-BY-STEP DISASTER PREPAREDNESS Guide & Template WHITEPAPER BY XVAND TECHNOLOGY CORPORATION Xvand Technology Corporation 832.204.4909 questions@xvand.com www.isutility.com Disaster

More information

IT Audit Process Prof. Liang Yao Week Three IT Risk Assessment

IT Audit Process Prof. Liang Yao Week Three IT Risk Assessment Week Three IT Risk Assessment Defining Risks Inherent Risk: The risk that an activity would pose if no controls or other mitigating factors were in place (the gross risk or risk before controls) Residual

More information

Jennie Clinton, Pearce Global Partners May 10 th, 2012

Jennie Clinton, Pearce Global Partners May 10 th, 2012 Jennie Clinton, Pearce Global Partners May 10 th, 2012 Workshop Overview Workshop will focus on three area of business resiliency: Business Continuity Plans and Crisis Response Look at how these plans

More information

WIC 104 RISK MANAGEMENT AND BUSINESS CONTINUITY PLANNING FOR LOCAL WIC AGENCIES. Peg Jackson, DPA, CPCU National WIC Association

WIC 104 RISK MANAGEMENT AND BUSINESS CONTINUITY PLANNING FOR LOCAL WIC AGENCIES. Peg Jackson, DPA, CPCU National WIC Association WIC 104 RISK MANAGEMENT AND BUSINESS CONTINUITY PLANNING FOR LOCAL WIC AGENCIES Peg Jackson, DPA, CPCU National WIC Association Learning Agenda Week 1 Risk Management and its role in WIC offices What is

More information

CONTINUITY OF OPERATIONS (COOP) WORKSHEETS

CONTINUITY OF OPERATIONS (COOP) WORKSHEETS CONTINUITY OF OPERATIONS (COOP) WORKSHEETS Martin O Malley, Governor Richard Muth, Director June 2009 Version 2.0 COOP WORKSHEETS These worksheets are tools to help you gather the raw data needed to develop

More information

Navigating the Storm: Disaster Contingency and Post-Event Strategies Following the Recent California Disasters

Navigating the Storm: Disaster Contingency and Post-Event Strategies Following the Recent California Disasters Navigating the Storm: Disaster Contingency and Post-Event Strategies Following the Recent California Disasters Laurel Sykes, CRCM SVP, Chief Risk Officer Montecito Bank & Trust lsykes@montecito.bank Objectives

More information

Business Continuity 101. Fairchild Resiliency Systems

Business Continuity 101. Fairchild Resiliency Systems Business Continuity 101 Fairchild Resiliency Systems Business Continuity Business Continuity (BC) is defined as the capability of the organization to continue delivery of products or services at acceptable

More information

Fordham University BCP / DRP Lunch. Lunch

Fordham University BCP / DRP Lunch. Lunch LearnIT @ Lunch LearnIT @ Lunch Why am I here and what is a TTE? LearnIT @ Lunch TTE While you were on the way over to the LearnIT @ Lunch all of the applications that support your business processes failed!

More information

Proven Strategies for Overcoming Business Continuity Challenges for Healthcare Organizations

Proven Strategies for Overcoming Business Continuity Challenges for Healthcare Organizations Proven Strategies for Overcoming Business Continuity Challenges for Healthcare Organizations Kathy Lee Patterson, CBCP Business Continuity & Disaster Recovery Manager Children's Hospital of Philadelphia

More information

(ISC)2 CISSP EXAM BUNDLE

(ISC)2 CISSP EXAM BUNDLE (ISC)2 CISSP EXAM BUNDLE Number: CISSP Passing Score: 800 Time Limit: 120 min File Version: 42.2 http://www.gratisexam.com/ (ISC)2 CISSP EXAM BUNDLE Exam Name: (ISC)2 Certified Information Systems Security

More information

Business Resilience They Cannot Do This Without You!

Business Resilience They Cannot Do This Without You! Business Resilience They Cannot Do This Without You! Maureen Roskoski, Facility Engineering Associates PC Laurie Gilmer, Facility Engineering Associates PC Meet Our Presenters: Maureen K. Roskoski, CFM,

More information

CLICNET TELECOMMUNICATIONS INC. Business Continuity Plan

CLICNET TELECOMMUNICATIONS INC. Business Continuity Plan CLICNET TELECOMMUNICATIONS INC. Business Continuity Plan 1 Emergency notification contacts Name Address Home Mobile phone 2 Revisions control page Date Summary of changes made Changes made by (Name) 3

More information

Business Continuity Guide

Business Continuity Guide Business Continuity Guide Introduction All businesses need to be aware of the risks facing them every day and how to effectively manage them. Within this business continuity guide we have provided high-level

More information

The 13th Annual Continuity Insights Management Conference

The 13th Annual Continuity Insights Management Conference The 13th Annual Continuity Insights Management Conference Presented by: Continuity Insights What Enterprise-Wide Business Continuity Really Means Communicating the value of BC to management and embedding

More information

How to disasterproof critical. business data. 5 steps for keeping systems online and accessible in any scenario.

How to disasterproof critical. business data. 5 steps for keeping systems online and accessible in any scenario. How to disasterproof critical business data 5 steps for keeping systems online and accessible in any scenario. The growth of DRaaS The tremendous growth of software as a service (SaaS) continues, while

More information

COMMUNICATION AND DISASTER RESPONSE. Denise O Shea Montclair State University

COMMUNICATION AND DISASTER RESPONSE. Denise O Shea Montclair State University COMMUNICATION AND DISASTER RESPONSE Denise O Shea Montclair State University October 2014 2 My Background Librarian, Head of Access Services & Systems, Harry A. Sprague Library Montclair State University

More information

Planning For and Installing LDRPS. Don Bailey, CBCP Fidelity Investments NEDRIX 2/24/2004

Planning For and Installing LDRPS. Don Bailey, CBCP Fidelity Investments NEDRIX 2/24/2004 Planning For and Installing LDRPS Don Bailey, CBCP Fidelity Investments NEDRIX 2/24/2004 Contents Background Risks and problems Evaluation process used Software Features Benefits Usage / Status report

More information

Evaluating Your Business Continuity Plan: Beyond Checklists and Walkthroughs. Troy Harris, Director McGladrey LLP. All Rights Reserved.

Evaluating Your Business Continuity Plan: Beyond Checklists and Walkthroughs. Troy Harris, Director McGladrey LLP. All Rights Reserved. Evaluating Your Business Continuity Plan: Beyond Checklists and Walkthroughs Troy Harris, Director McGladrey LLP Agenda Business Continuity Planning Overview Program Initiation and Management Disaster

More information

Abraham E. Binder MA, ABCP York University Disaster & Emergency Management Program

Abraham E. Binder MA, ABCP York University Disaster & Emergency Management Program Abraham E. Binder MA, ABCP York University Disaster & Emergency Management Program TTX Basics Real Relevant Refreshed Questions TTX Fundamentals Intermediate level For busy leadership teams Not a Walkthrough

More information

Don t Panic! How to develop and implement an emergency response plan for your attraction

Don t Panic! How to develop and implement an emergency response plan for your attraction Don t Panic! How to develop and implement an emergency response plan for your attraction Paul Chatelot, Director / Prevention, Safety & Environment DiSNEYLAND PARIS September 19, 2016 Agenda Don t panic

More information

The Challenge: Balancing Change and Control of Continuous Delivery at Scale

The Challenge: Balancing Change and Control of Continuous Delivery at Scale WWW.PLUTORA.COM SOLUTION BRIEF The Challenge: Balancing Change and Control of Continuous Delivery at Scale DevOps bridges the gap between development and operations to deliver business value more frequently.

More information

Advancing your BCP Program

Advancing your BCP Program BCP and DR Planning for Healthcare Organizations Advancing your BCP Program Agenda for Presentation Stick to the basics Know your crucial technology Get your clients input - BIA Obtaining senior management

More information

Executive Presentation on using Management Dashboards to support the processes of Infrastructure, Production, Compliance, and Recovery Certification

Executive Presentation on using Management Dashboards to support the processes of Infrastructure, Production, Compliance, and Recovery Certification Executive Presentation on using Dashboards to support the processes of Infrastructure, Production, Compliance, and Recovery Certification Created by: Thomas Bronack, CBCP Phone: (917) 673-6992 Email: bronackt@dcag.com

More information

BUSINESS CONTINUITY PLANNING WORKPROGRAM

BUSINESS CONTINUITY PLANNING WORKPROGRAM BUSINESS CONTINUITY PLANNING WORKPROGRAM EXAMINATION OBJECTIVE: Determine the quality and effectiveness of the organization s business continuity planning process, and determine whether the continuity

More information

A Guide to Business Continuity

A Guide to Business Continuity A Guide to Business Continuity Getting Started Business Continuity Management is a process driven from the top of the organisation. The first stage has to be an acceptance by the Board or the Executive

More information

BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNING. Marci McCloskey, CISA, ABCP Toan Nguyen, CIA, ABCP

BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNING. Marci McCloskey, CISA, ABCP Toan Nguyen, CIA, ABCP BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNING Marci McCloskey, CISA, ABCP Toan Nguyen, CIA, ABCP SPEAKER INFORMATION Marci McCloskey, CISA, ABCP Oklahoma City, Oklahoma University of Oklahoma Stinnett:

More information

Coastal Equities, Inc.

Coastal Equities, Inc. Coastal Equities, Inc. Business Continuity Plan Summary Updated On: March 1, 2017 The foregoing is a true and accurate representation of the business continuity steps taken by Coastal Equities, Inc. As

More information

Group Security Policy

Group Security Policy Our commitment to good business Focusing on health, safety and security 6 Version 1 July 2014 Our Business Principles 1 Demonstrating integrity in corporate conduct 2 Ensuring openness and transparency

More information

Pulling up the Roots: a Guide to Corporate Relocation

Pulling up the Roots: a Guide to Corporate Relocation Pulling up the Roots: a Guide to Corporate Relocation Overview It is Monday morning and you look forward to starting the new week at work. As you get to your office, you find a note on your desk. Your

More information

Ensuring Organizational & Enterprise Resiliency with Third Parties

Ensuring Organizational & Enterprise Resiliency with Third Parties Ensuring Organizational & Enterprise Resiliency with Third Parties Geno Pandolfi Tuesday, May 17, 2016 Room 7&8 (1:30-2:15 PM) Session Review Objectives Approaches to Third Party Risk Management Core Concepts

More information

Questions and Answers. For. NETWORK Services RFP #

Questions and Answers. For. NETWORK Services RFP # Questions and Answers For NETWORK Services RFP # 13170501 1. Can a tour of the supported facilities be available to be scheduled this week or next week?*, not at this time 2. Can the points of contacts

More information

Top 10 Mistakes Made During a Disaster

Top 10 Mistakes Made During a Disaster Top 10 Mistakes Made During a Disaster Bob Boyd, President & CEO Agility Recovery Today s session will be recorded. Links to the archived recording will be emailed to all registrants automatically tomorrow.

More information

Business Continuity Management (BCM) Chicagoland Safety Conference October 24, 2013

Business Continuity Management (BCM) Chicagoland Safety Conference October 24, 2013 Business Continuity Management (BCM) Chicagoland Safety Conference October 24, 2013 Carey A. Loukides, CBCP, ARM, MBCI Senior Consultant, Global Risk Consulting Enterprise Risk Management, Business Continuity

More information

Business Continuity Management and Resilience Framework

Business Continuity Management and Resilience Framework Business Continuity Management and Resilience Framework Approving authority University Council Approval date 3 December 2018 Advisor Next scheduled review 2021 Peter Bryant Vice President (Corporate Services)

More information

Business Continuity Maturity Matrix

Business Continuity Maturity Matrix Business Continuity Maturity Matrix A maturity model is one of the most valuable tools available for planning and sustaining a new Business Continuity program. Like the Business Continuity Planning (BCP)

More information

Minimizing Risk and Ensuring Continuity of Operations with Help from Symantec Consulting Services Business Continuity Management Practice

Minimizing Risk and Ensuring Continuity of Operations with Help from Symantec Consulting Services Business Continuity Management Practice Minimizing Risk and Ensuring Continuity of Operations with Help from Symantec Consulting Services Business Continuity Management Practice Pharmaceutical giant Pfizer delivers drugs that help people live

More information

Business Continuity Management (BCM) Toolkit

Business Continuity Management (BCM) Toolkit Business Continuity Management (BCM) Toolkit Version 1 Process Owner: Chief Executive Business Continuity & Risk Management Officer: Caroline Evans Jun-14 Version 1 Page 1 of 39 Acknowledgements We would

More information

Business Continuity / Disaster Recovery Follow-up

Business Continuity / Disaster Recovery Follow-up INTERNAL AUDIT REPORT Business Continuity / Disaster Recovery Follow-up R-17-5 June 1, 2017 Executive Summary Introduction A follow-up audit of the 2016 Business Continuity / Disaster Recovery Audit has

More information

Navigating the Intersection of Vendor Management and Business Continuity

Navigating the Intersection of Vendor Management and Business Continuity Navigating the Intersection of Vendor Management and Business Continuity MICHAEL BERMAN, J.D. Table of Contents Why are we here? Business Continuity and Vendor Management Primary Intersection BCP Each

More information

Subject Area 1 Project Initiation and Management

Subject Area 1 Project Initiation and Management Professional Practice Narrative: Establish the need for a Business Continuity Plan (BCP), including obtaining management support and organizing and managing the BCP project to completion. (This includes

More information

Mississippi Emergency Support Function #12 Energy Annex

Mississippi Emergency Support Function #12 Energy Annex Mississippi Emergency Support Function #12 Energy Annex ESF #12 Coordinator Mississippi Public Utilities Staff Primary Agencies Mississippi Public Utilities Staff Support Agencies Mississippi Emergency

More information

10 Steps To Business Preparedness

10 Steps To Business Preparedness 10 Steps To Business Preparedness Bob Boyd, President & CEO, Agility Recovery Solutions For Audio: Listen through PC speakers Dial 773-945-1011, use access code 281-118-941 Learn about the basics of disaster

More information

Self-Assessment for the CoSN Certified Education Technology Leader (CETL ) Certification Exam

Self-Assessment for the CoSN Certified Education Technology Leader (CETL ) Certification Exam Self-Assessment for the CoSN Certified Education Technology Leader (CETL ) Certification Exam COSN s Self-Assessment will help you determine your readiness for the CETL certification exam. It can also

More information

External Supplier Control Obligations

External Supplier Control Obligations External Supplier Control Obligations Resilience Control Title Control Description Why this is important 1.Resilience and recovery governance Supplier must establish effective governance to maintain resilience

More information

IN CASE OF EMERGENCY READ

IN CASE OF EMERGENCY READ IN CASE OF EMERGENCY READ ebook Everbridge Readiness Assessment In the past few years, an unprecedented number of disruptive events - from natural disasters to acts of man have impacted people, property

More information

Action List for Developing a Computer Security Incident Response Team (CSIRT)

Action List for Developing a Computer Security Incident Response Team (CSIRT) Action List for Developing a Computer Security Incident Response Team (CSIRT) This document provides a high-level overview of actions to take and topics to address when planning and implementing a Computer

More information

GUIDE TO CONTINUITY PLANNING

GUIDE TO CONTINUITY PLANNING Academic GUIDE TO CONTINUITY PLANNING The aim of WashU Continuity is to increase the university s resilience in the face of disruptive events. Resilience means being able to continue performing the university

More information