Business Continuity Management and Business Impact Analysis (BIA)

Size: px
Start display at page:

Download "Business Continuity Management and Business Impact Analysis (BIA)"

Transcription

1 Presented by Richard A. Harris, CBCP, MPMP Absolute Continuity Solutions Consultants, LLC Absolute solutions for all your enterprise s consulting needs Business Continuity Management and Business Impact Analysis (BIA) Scope, Comprehension, and Expectations

2 Overview Scope, Comprehension, Expectations SCOPE Often, senior leaders in the enterprise are reluctant to engage in the BIA, a most critical portion of BCM. An epidemic of geocentric thinking can be the downfall of numerous BCM Planning efforts.

3 Overview Scope, Comprehension, Expectations COMPREHENSION Many enterprises continue to view BCM as a Business Recovery Genie that cures all ills when there is a fault in the business while condemning BCM as a concept that doesn t work. In very many cases, BCM is used synonymously with Continuity of Operations (COOP). This is apples and oranges! (See NIST ).

4 Overview Scope, Comprehension, Expectations EXPECTATIONS Expectations can obscure what BCM is designed to do, leading to a lack of confidence. This session will discuss what BCM really is and how these efforts are most effective when initiated with clear scope, comprehension and expectations.

5 Business Impact Analysis (BIA)... Is the foundation of an enterprise's business continuity plan. Includes an exploratory component to uncover any risks and vulnerabilities, and a planning component to develop strategies for minimizing risk. Identifies the possibilities of failures. Usually assessed in terms of their impacts on safety, finances, marketing, legal compliance, and quality assurance. Where possible, impact is expressed monetarily for purposes of comparison. For example, a business may spend three times as much on marketing in the wake of a disaster to rebuild customer confidence.

6 What is a Business Impact Analysis The BIA will: help identify which major business functions, operations and processes are essential to the survival of the business. will facilitate the identification of how soon essential business functions and/or processes have to return to full operation following a disaster, incident, or situation that cause interruptions for a significant time. help your enterprise determine what would be classified as a significant time of interruption and assign a monetary value of the affects of interruptions to the enterprises bottom line.

7 What is a Business Impact Analysis (continued) allow you to place a cost of the interruption on an hourly, daily, weekly, and/or monthly basis (if that interruption were to last that long), and cost the impact on the organization s ability to deliver products and/or support mission-critical services. facilitate the identification of the resources required to resume operations to a survival level. identify impacts based on a worst-case scenario. Assuming that the physical infrastructure supporting each respective business function has been severely interrupted and is not accessible within 30 days.

8 Why Do Business Impact Analysis SCOPE A thorough BIA will enable the enterprise to : identify costs linked to failures, such as loss of cash flow, replacement of equipment, salaries paid to catch up with a backlog of work, loss of profits, etc.. quantify the importance of business components and suggests appropriate fund allocation for measures to protect them. identify and prioritize the business Mission Essential Functions (MEF), to act as a triage method in an event or interruption. identify all the dependencies, controls, inputs, resources, and outputs associated with each business function.

9 Business Impact Analysis SCOPE Customer/Stakeholder Requirements Federal/State/Local Mandates Ethical Issues Policies/Statutes Legal Requirements Controls/Mandates Dependencies Utilities Support Services Supplies/Equipment Vital Records Communications Mission Essential Business Function Vital Resources Human Capital Contract/Vendor Support Software/Hardware/Telecommunications Venue/Location Stakeholders Outputs Products Services Information

10 Why Do Business Impact Analysis The main objectives of the BIA are to: EXPECTATIONS Estimate the financial and operational impacts for each major business function, assuming a worst-case scenario. Define the estimated number of personnel and other resources required for recovery operations. Identify the organization s business functions and processes and the estimated Recovery Time* and Recovery Point* for each major business function. *NOTE: Recovery Time Objectives (RTO) are the predetermined timeframes that the enterprise believes they can regain functionality from the time the incident or event occurred. Recovery Point Objectives (RPO) are the desired points (most critical) at which the enterprise will resume business in relation to the point at which business was being conducted at the time the incident or event

11 Business Continuity Management COMPREHENSION Signs of not fully understanding Business Continuity Management (BCM) are : Designing BCM around what-if incidents rather than interruptions of business functions. Designing BCM recovery activities around people or positions of affluence in the enterprise. - Single Points of Failure (SPOF) Failure to integrate BCM into Strategic and Operational Planning, as well other business/organizational development initiatives.

12 Business Continuity Management COMPREHENSION (continued) Lack of processes for incident probability (before) and early detection (after and incident), event severity determination procedures when the event occurs, and plan escalation procedures. Lack of enterprise-wide notification procedures and testing of those procedures. Inefficient and inadequate succession planning and proliferation of succession plans throughout the enterprise. Inadequate or nonexistent coordination with internal and external dependencies.

13 Business Continuity Management COMPREHENSION (continued) Ambiguous recovery goals and objectives (see Recovery Time/Point Objectives above) that are not data-driven nor support the mission and enterprise s customers. Inadequate, outdated, or nonexistent policies, standards, and governance by which the enterprise can follow for direction and clarity. Inadequate documentation, proliferation, and articulation of policies, standards, and governance throughout the enterprise for all employees to comprehend. Inadequate, outdated, or nonexistent procedures by which the enterprise can follow for direction and to take appropriate actions (at all levels of the enterprise).

14 Business Continuity Management COMPREHENSION (continued) Failure to adequately test existing plans - compounded by having outdated plans, procedures, and policies in place when testing is done. Inappropriate combination of testing approaches. Meaning, testing is quite often done using live exercises and drills. These testing processes are effective, however, they should only be done after their have been a series of tabletop exercises first to identify major gaps in the plan before committing resources to a live exercise. Infrequent, inappropriate*, and/or nonexistent testing procedures for recovery goals and objectives.

15 Business Continuity Management COMPREHENSION (Continued) Live exercises are necessary but are very taxing on financial resources due to downtime and commitment of Human Capital. Quite often, only the upper echelons of the organization have any knowledge of the enterprise s business continuity plans and their contents. In most instances, the operations-level of the business don t even understand what Business Continuity Management really is!

16 Business Continuity Management SOLUTIONS Thoroughly assessing, documenting, and testing your enterprises: Business Impact Analysis before starting the planning process. Policies, Standards, and Governance Incident Probability and Early Detection Assessment, Event Impact Severity Determination, and Plan Activation and Escalation Activities Incident Assessment, Event Severity Determination, and Plan Escalation Enterprise Notification Procedures Succession Planning Alternate Location Readiness (cold, warm, hot site preparedness) Command Center/Emergency Operations Management Coordination with Internal and External Dependencies and Stakeholders Recovery Time and Point Objectives Set Realistic Goals

17 Business Continuity Management QUESTIONS and ANSWERS

Protecting Information Assets - Week 9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets

Protecting Information Assets - Week 9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets Protecting Information Assets - Week 9 - Business Continuity and Disaster Recovery Planning MIS5206 Week 9 Case study discussion Business Continuity Planning (BCP) and Disaster Recovery (DR) Planning Test

More information

Business Continuity & IT Disaster Recovery

Business Continuity & IT Disaster Recovery Business Continuity & IT Disaster Recovery DONALD L. SCHMIDT, ARM, CBCP, MCP, CBCLA, CEM PREPAREDNESS, LLC MARCH 30, 2017 www.preparednessllc.com What are Business Continuity & IT Disaster Recovery? BUSINESS

More information

Protecting Information Assets - Unit #9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets

Protecting Information Assets - Unit #9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets Protecting Information Assets - Unit #9 - Business Continuity and Disaster Recovery Planning Agenda Contingency Planning (CP) IT Security Control Class and Family Business Continuity and Disaster Recovery

More information

Yale University Business Continuity Planning Quick Start Guide

Yale University Business Continuity Planning Quick Start Guide Yale University Business Continuity Planning Quick Start Guide Introduction A Business Continuity Plan (BCP) (previously referred to as Continuity of Operations Plan or COOP) is a collection of resources,

More information

Mission Essential Functions

Mission Essential Functions Texas Emergency Management Conference 2017 Mission Essential Functions Identification and Prioritization Continuity of Operations (COOP) Program Management Lifecycle Alan Sowell, TDEM COOP Unit Supervisor

More information

BOLD CREATING A CULTURE OF PREPAREDNESS. Preparedness Cycle Framework. With the BOLDplanning. boldplanning.com

BOLD CREATING A CULTURE OF PREPAREDNESS. Preparedness Cycle Framework. With the BOLDplanning. boldplanning.com BOLD p l a n n i n g CREATING A CULTURE OF PREPAREDNESS With the BOLDplanning Preparedness Cycle Framework boldplanning.com THE CONTENTS THE CHALLENGE: CREATING A CULTURE OF PREPAREDNESS 03 THE SOLUTION:

More information

US Business Continuity Safeguarding Your Business from a Disaster

US Business Continuity Safeguarding Your Business from a Disaster US Business Continuity Safeguarding Your Business from a Disaster Juanita Hardin BMO Harris Bank Head TPS Risk and Compliance William Simmons BMO Harris Bank Vice President Business Continuity Management

More information

Coastal Equities, Inc.

Coastal Equities, Inc. Coastal Equities, Inc. Business Continuity Plan Summary Updated On: March 1, 2017 The foregoing is a true and accurate representation of the business continuity steps taken by Coastal Equities, Inc. As

More information

BUSINESS CONTINUITY MANAGEMENT

BUSINESS CONTINUITY MANAGEMENT Loss Control BUSINESS CONTINUITY MANAGEMENT Preparing for the Unexpected Preparing your organization for a disaster can be an overwhelming task, but the risk of being unprepared can be even more devastating.

More information

Meet Our Presenter. Equipping You For Success: An ISO Certification Case Study

Meet Our Presenter. Equipping You For Success: An ISO Certification Case Study Equipping You For Success: An ISO 22301 Certification Case Study March 28, 2017 10:45 11:45 am Maureen Roskoski, Corporate Sustainability Officer, Facility Engineering Associates, PC Meet Our Presenter

More information

Business Continuity Management An Auditor s Perspective July 25, 2017

Business Continuity Management An Auditor s Perspective July 25, 2017 NASPL 2017 Professional Development Seminar Nashville, TN Business Continuity Management An Auditor s Perspective July 25, 2017 Presented by Mark Caiazzo, Principal Agenda Business Continuity Process BCM

More information

Business Continuity Management and Resilience Framework

Business Continuity Management and Resilience Framework Business Continuity Management and Resilience Framework Approving authority University Council Approval date 3 December 2018 Advisor Next scheduled review 2021 Peter Bryant Vice President (Corporate Services)

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning 4 Business Continuity Planning and Disaster Recovery Planning Learning Objectives To understand the concept of Business Continuity Management; To understand the key phases and components of a Business

More information

Citi Institutional Clients Group - Business Continuity Management

Citi Institutional Clients Group - Business Continuity Management Citi Institutional Clients Group - Business Continuity Management Enterprise Risk Management Establishing a Risk Control-based Continuity Program, CBCP, CBCP Senior Vice President, Citi Institutional Clients

More information

University Information Technology Services. Business Impact Analysis For {System Name}

University Information Technology Services. Business Impact Analysis For {System Name} University Information Technology Services Business Impact Analysis For {System Name} Prepared by Victor Font UITS Business Continuity / Disaster Recovery Coordinator January 2013 1. Overview... 3 1.1

More information

Tier I assesses an institution's process for identifying and managing risks. Tier II provides additional verification where risk is eviden

Tier I assesses an institution's process for identifying and managing risks. Tier II provides additional verification where risk is eviden Appendix A: Examination Procedures EXAMINATION OBJECTIVE: Determine the quality and effectiveness of the organization's business continuity planning process, and determine whether the continuity testing

More information

City of Saskatoon Business Continuity Internal Audit Report

City of Saskatoon Business Continuity Internal Audit Report www.pwc.com/ca City of Saskatoon Business Continuity Internal Audit Report June 2018 Executive Summary The City of Saskatoon s (the City ) Strategic Risk Register identifies Business Continuity as a high

More information

Business Continuity Management Policy. Guidance

Business Continuity Management Policy. Guidance Management Guidance Document Type: Guidance Parent Policy: Management Policy Policy Owner: Chief Supt Department: Document Writer: Co-ordinator Effective Date: 12 th March 2015 Review Date: 12 th March

More information

Emerging Threats: The importance of Interagency Coordination WEATHERING THE STORM 6 TH ANNUAL REGIONAL DISASTER CONFERENCE

Emerging Threats: The importance of Interagency Coordination WEATHERING THE STORM 6 TH ANNUAL REGIONAL DISASTER CONFERENCE Emerging Threats: The importance of Interagency Coordination WEATHERING THE STORM 6 TH ANNUAL REGIONAL DISASTER CONFERENCE WORLDWIDE THREAT ASSESSMENT of the US INTELLIGENCE COMMUNITY February 9, 2016

More information

BCP Methodology Benefits realisation

BCP Methodology Benefits realisation www.pwc.com.cy BCP Methodology Benefits realisation Risk Assurance Consulting (RAC) Risk Assurance Consulting (RAC) helps management to make well informed decisions. The insight and independent assurance

More information

Management Update: A Business Continuity Management Program Is Critical

Management Update: A Business Continuity Management Program Is Critical IGG-07162003-03 R. Witty Article 16 July 2003 Management Update: A Business Continuity Management Program Is Critical Enterprises that do not have a business continuity management (BCM) program are on

More information

Minimizing Risk and Ensuring Continuity of Operations with Help from Symantec Consulting Services Business Continuity Management Practice

Minimizing Risk and Ensuring Continuity of Operations with Help from Symantec Consulting Services Business Continuity Management Practice Minimizing Risk and Ensuring Continuity of Operations with Help from Symantec Consulting Services Business Continuity Management Practice Pharmaceutical giant Pfizer delivers drugs that help people live

More information

CITY OF JOHANNESBURG METROPOLITAN MUNICIPALITY BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

CITY OF JOHANNESBURG METROPOLITAN MUNICIPALITY BUSINESS CONTINUITY MANAGEMENT FRAMEWORK CITY OF JOHANNESBURG METROPOLITAN MUNICIPALITY BUSINESS CONTINUITY MANAGEMENT FRAMEWORK Effective Date 1 July 2016 TABLE OF CONTENTS GLOSSARY OF TERMS... 4 PRIMARY LEGISLATIVE AND REGULATORY PROVISIONS...

More information

Global Crises: What We Really Need to Do to Be Prepared. Day One / Session C5

Global Crises: What We Really Need to Do to Be Prepared. Day One / Session C5 Global Crises: What We Really Need to Do to Be Prepared Day One / Session C5 April 12, 2010 Clyde Berger Adam Chusid 0 Today s Objectives Present practical solutions for building a viable sustainable program

More information

Testing and Exercising. Continuity Forum May 17, 2012

Testing and Exercising. Continuity Forum May 17, 2012 Testing and Exercising Continuity Forum May 17, 2012 Agenda Business Continuity @ DOT The Exercise Management Model Our Approach Exercising In Practice Moving Forward Considerations Resources Discussion

More information

BCP Methodology Benefits realisation

BCP Methodology Benefits realisation www.pwc.com.cy/technology-consulting BCP Methodology Benefits realisation BCP Methodology Our BCP methodology incorporates five (5) phases. The phases take an organisation from prioritising core business

More information

Citizens Property Insurance Corporation Business Continuity Framework

Citizens Property Insurance Corporation Business Continuity Framework Citizens Property Insurance Corporation Framework Dated September 2015 Approvals: Risk Committee: September 17, 2015 (via email) Adopted by the Audit Committee: Page 1 of 12 Table of Contents 1 INTRODUCTION...

More information

FOUNDATION OF THE PLAN WAS A RISK ANALYSIS. Basic Flaw focus on threat probability instead of potential impact

FOUNDATION OF THE PLAN WAS A RISK ANALYSIS. Basic Flaw focus on threat probability instead of potential impact FOUNDATION OF THE PLAN WAS A RISK ANALYSIS Basic Flaw focus on threat probability instead of potential impact NOBODY KNEW ANYTHING How do you create a plan? How do you do a Risk Analysis? How much processing

More information

Business Continuity Planning. LGMA Conference October 27, 2011 Presented by Lisa Benini

Business Continuity Planning. LGMA Conference October 27, 2011 Presented by Lisa Benini Business Continuity Planning LGMA Conference October 27, 2011 Presented by Lisa Benini What is it? Business Continuity Planning Definition: Process of developing and documenting advance arrangements and

More information

STRATEGIC CRISIS MANAGEMENT & COMMUNICATIONS FOR HR

STRATEGIC CRISIS MANAGEMENT & COMMUNICATIONS FOR HR 40% CASH BACK The Productivity Innovation Credit (PIC) Scheme* Register Now Only S$2345 + GST STRATEGIC CRISIS MANAGEMENT & COMMUNICATIONS FOR HR Building Human Capital Resiliency & Ensuring Business MASTERCLASS

More information

BP3: Decomposing the Crisis/ Incident Management Timeline

BP3: Decomposing the Crisis/ Incident Management Timeline BP3: Decomposing the Crisis/ Incident Management Timeline Eric Staffin, MBCI, CISSP VP and Global Head, Product & Infrastructure Risk Management Investment & Advisory 646 223 6980 eric.staffin@thomsonreuters.com

More information

Building and Maintaining a Business Continuity Program

Building and Maintaining a Business Continuity Program Building and Maintaining a Business Continuity Program Successful strategies for financial institutions for effective preparation and recovery 1 Building and Maintaining a Business Continuity Program Table

More information

(ISC)2 CISSP EXAM BUNDLE

(ISC)2 CISSP EXAM BUNDLE (ISC)2 CISSP EXAM BUNDLE Number: CISSP Passing Score: 800 Time Limit: 120 min File Version: 42.2 http://www.gratisexam.com/ (ISC)2 CISSP EXAM BUNDLE Exam Name: (ISC)2 Certified Information Systems Security

More information

University of Houston Downtown. Continuity of Operations Plan (COOP) Liaison Program

University of Houston Downtown. Continuity of Operations Plan (COOP) Liaison Program University of Houston Downtown Continuity of Operations Plan (COOP) Liaison Program Presented by: Carol Manousos Director, Emergency Management & Fire Safety COOP Program Manager Objectives: By the end

More information

Unit 3: Elements of a Viable Continuity Capability

Unit 3: Elements of a Viable Continuity Capability Unit 3: Elements of a Viable Continuity Capability Unit 3 Objectives Identify all organization essential functions and their effect upon staffing levels in a continuity event. Recognize and incorporate

More information

External Supplier Control Obligations

External Supplier Control Obligations External Supplier Control Obligations Resilience Control Title Control Description Why this is important 1.Resilience and recovery governance Supplier must establish effective governance to maintain resilience

More information

Continuity of Operations Planning (COOP)

Continuity of Operations Planning (COOP) Continuity of Operations Planning (COOP) Business Continuity and Disaster Recovery State of Delaware 2008 NASCIO Nomination Page: 1 CONTINUITY OF OPERATIONS PLANNING EXECUTIVE SUMMARY Business Continuity

More information

Business Continuity. Building a Program Fit for Purpose

Business Continuity. Building a Program Fit for Purpose Business Continuity. Building a Program Fit for Purpose Tim Janes. Director Fulcrum Risk Services Tuesday 2 September. 11.30-12.45 T Janes. BC SLIDES. RIMS Risk Forum Aust 2014 v1.0 Building a BC Program

More information

BUSINESS CONTINUITY PLANNING WORKPROGRAM

BUSINESS CONTINUITY PLANNING WORKPROGRAM BUSINESS CONTINUITY PLANNING WORKPROGRAM EXAMINATION OBJECTIVE: Determine the quality and effectiveness of the organization s business continuity planning process, and determine whether the continuity

More information

D ISASTER AND C ONTINUITY P LANNING IS YOUR F ACILITY PREPARED?

D ISASTER AND C ONTINUITY P LANNING IS YOUR F ACILITY PREPARED? Christian Brothers Services D ISASTER AND C ONTINUITY P LANNING IS YOUR F ACILITY PREPARED? Audio-Conference Companion Guide Page 2 Audio-Conference Companion Guide The following is a summary of the central

More information

3 keys to effective business continuity management. Visibility. Measurement. Collaboration.

3 keys to effective business continuity management. Visibility. Measurement. Collaboration. 3 keys to effective business continuity management Visibility. Measurement. Collaboration. Managing business continuity without visibility into downtime and data loss risks is like flying at night without

More information

BACK TO BASICS BUSINESS CONTINUITY MANAGEMENT 101. June 11, 2013

BACK TO BASICS BUSINESS CONTINUITY MANAGEMENT 101. June 11, 2013 BACK TO BASICS BUSINESS CONTINUITY MANAGEMENT 101 June 11, 2013 Your Presenter Shanda Chronowich, CBCP, CRM Senior Manager MNP LLC 2 There cannot be a crisis next week. My schedule is already full. U.S.

More information

How to disasterproof critical. business data. 5 steps for keeping systems online and accessible in any scenario.

How to disasterproof critical. business data. 5 steps for keeping systems online and accessible in any scenario. How to disasterproof critical business data 5 steps for keeping systems online and accessible in any scenario. The growth of DRaaS The tremendous growth of software as a service (SaaS) continues, while

More information

Leading Change: Building Organisational Resilience. Jean D. Rowe, MBCI, CDCP May 1, 2017

Leading Change: Building Organisational Resilience. Jean D. Rowe, MBCI, CDCP May 1, 2017 Leading Change: Building Organisational Resilience Jean D. Rowe, MBCI, CDCP May 1, 2017 Jean.Rowe@ae.ey.com Agenda What is Organizational Resilience? Why Should You Care? Are You Prepared? What Do You

More information

Forward. My Plan Today. Continuity / Disaster Recovery Planning. bank s current Business Continuity / Disaster Plan

Forward. My Plan Today. Continuity / Disaster Recovery Planning. bank s current Business Continuity / Disaster Plan My Plan Today Forward 1. Discuss the responsibilities of Business Continuity / Disaster Recovery Planning 2. Provide a Framework for Accessing your bank s current Business Continuity / Disaster Plan 3.

More information

Business Continuity Through Planning, Prevention and Preparedness. READINESS RESOURCES

Business Continuity Through Planning, Prevention and Preparedness.  READINESS RESOURCES READINESS RESOURCES Federal Emergency Management Agency -- www.fema.gov Emergency Management Guide for Business & Industry: http://www.fema.gov/pdf/business/guide/bizindst.pdf American Red Cross -- www.redcross.org

More information

Keep Your Company Moving After A Disaster With A Business Continuity Plan (BCP)

Keep Your Company Moving After A Disaster With A Business Continuity Plan (BCP) Keep Your Company Moving After A Disaster With A Business Continuity Plan (BCP) HR Benefits Payroll gnapartners.com It only takes one major interruption to its business operations for a company to recognize

More information

Broadridge Business Process Outsourcing, LLC Business Continuity Plan Disclosure

Broadridge Business Process Outsourcing, LLC Business Continuity Plan Disclosure Broadridge Business Process Outsourcing, LLC Business Continuity Plan Disclosure I. Summary In accordance with FINRA Rule 4370, Broadridge Business Process Outsourcing, LLC (the Firm ) is providing you

More information

Staying Disaster-Ready in Treasury

Staying Disaster-Ready in Treasury Staying Disaster-Ready in Treasury A KEY ASPECT OF ANY BUSINESS CONTINUITY PLAN Where to Start?...2 Communications in a Crisis...3 Partner with Your Bank...3 Test to Evaluate Preparedness...5 All businesses

More information

Advancing your BCP Program

Advancing your BCP Program BCP and DR Planning for Healthcare Organizations Advancing your BCP Program Agenda for Presentation Stick to the basics Know your crucial technology Get your clients input - BIA Obtaining senior management

More information

DRI CBCP. Certified Business Continuity Professional.

DRI CBCP. Certified Business Continuity Professional. DRI CBCP Certified Business Continuity Professional http://killexams.com/exam-detail/cbcp Question: 118 Which are included in the Business Continuity professional's role? Select all that apply: A. Act

More information

Enterprise-wide Business Continuity and Disaster Recovery Planning. Presented by Kelley Okolita

Enterprise-wide Business Continuity and Disaster Recovery Planning. Presented by Kelley Okolita Enterprise-wide Business Continuity and Disaster Recovery Planning Presented by Kelley Okolita Don t get caught without a plan Gloom and Doom My job and yours is to preach Doom and Gloom Planning, not

More information

Continuity of Operations (COOP) Training

Continuity of Operations (COOP) Training Kent County Disaster Mental Health & Human Services Committee Continuity of Operations (COOP) Training May 10, 2011 Lt. Jack Stewart, Kent County Emergency Manager Deputy Chief Gary Szotko,, City of Grand

More information

BUSINESS CONTINUITY MANAGEMENT

BUSINESS CONTINUITY MANAGEMENT BUSINESS CONTINUITY MANAGEMENT RCG020-V1-01/2017 Page 1 2017 Royal & Sun Alliance Insurance plc Contents Introduction... 3 Business Continuity Management... 3 Getting started... 3 Business Impact Analysis...

More information

Action List for Developing a Computer Security Incident Response Team (CSIRT)

Action List for Developing a Computer Security Incident Response Team (CSIRT) Action List for Developing a Computer Security Incident Response Team (CSIRT) This document provides a high-level overview of actions to take and topics to address when planning and implementing a Computer

More information

A Guide to Business Continuity

A Guide to Business Continuity A Guide to Business Continuity Getting Started Business Continuity Management is a process driven from the top of the organisation. The first stage has to be an acceptance by the Board or the Executive

More information

Emergency Management, Business Continuity, & Crisis Management Self-Assessment Checklist

Emergency Management, Business Continuity, & Crisis Management Self-Assessment Checklist Emergency Management, Business Continuity, & Crisis Management Self-Assessment Checklist Self-assessment tool for evaluating preparedness using NFPA 1600 Standard on Disaster/Emergency Management and Business

More information

Business Continuity Maturity Matrix

Business Continuity Maturity Matrix Business Continuity Maturity Matrix A maturity model is one of the most valuable tools available for planning and sustaining a new Business Continuity program. Like the Business Continuity Planning (BCP)

More information

HB A Practitioners Guide to Business Continuity Management

HB A Practitioners Guide to Business Continuity Management HB 292 2006 A Practitioners Guide to Business Continuity Management HB HB 292 2006 Handbook A practitioners guide to business continuity management First published as HB 292 2006. COPYRIGHT Standards Australia

More information

BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNING. Marci McCloskey, CISA, ABCP Toan Nguyen, CIA, ABCP

BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNING. Marci McCloskey, CISA, ABCP Toan Nguyen, CIA, ABCP BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNING Marci McCloskey, CISA, ABCP Toan Nguyen, CIA, ABCP SPEAKER INFORMATION Marci McCloskey, CISA, ABCP Oklahoma City, Oklahoma University of Oklahoma Stinnett:

More information

Business Continuity Through Planning, Prevention and Preparedness. READINESS RESOURCES

Business Continuity Through Planning, Prevention and Preparedness.   READINESS RESOURCES READINESS RESOURCES Federal Emergency Management Agency Emergency Management Guide for Business & Industry: www.fema.gov/pdf/business/guide/bizindst.pdf PS-Prep - www.fema.gov/ps-preptm-voluntary-private-sector-preparedness

More information

An introduction to business continuity planning

An introduction to business continuity planning An introduction to business continuity planning What is business continuity, and is it relevant to me? Business continuity planning is about identifying the critical functions and services your business

More information

Creating a Business Continuity Plan for your Health Center

Creating a Business Continuity Plan for your Health Center Creating a Business Continuity Plan for your Health Center 1 Page Left Intentionally Blank 2 About This Manual This tool is the result of collaboration between the Primary Care Development Corporation

More information

Points of Discussion

Points of Discussion Business Continuity Planning Considerations for Business Process Offshoring Todd Litman, CBCP DRJ Spring World March 18, 2013 1 Points of Discussion Business Process Offshoring Benefits & Risks Business

More information

5/28/2018. Disaster Recovery Are You Ready. Speaker. Agenda

5/28/2018. Disaster Recovery Are You Ready. Speaker. Agenda Disaster Recovery Are You Ready Central Iowa American Payroll Association 2017 Statewide Conference Friday October 6 Speaker Bruce E. Phipps CPP APA Vice Presindent 2011 APA Payroll Man of the Year Principal

More information

The Disaster Experience: Putting Business Continuity to the Test

The Disaster Experience: Putting Business Continuity to the Test The Disaster Experience: Putting Business Continuity to the Test Presented by Bob Mellinger, CBCV OM33 5/5/2018 1:15 PM The handout(s) and presentation(s) attached are copyright and trademark protected

More information

CONTINUITY OF OPERATIONS PLANNING FOR PUBLIC HEALTH ENTITIES

CONTINUITY OF OPERATIONS PLANNING FOR PUBLIC HEALTH ENTITIES CONTINUITY OF OPERATIONS PLANNING FOR PUBLIC HEALTH ENTITIES Raphael M. Barishansky Developed for the Fifth National Emergency Management Summit September 2011 WHAT IS COOP? COOP allows for the continuation

More information

Keys to Creating a Culture of Preparedness

Keys to Creating a Culture of Preparedness Use existing culture to build readiness throughout the organization UNPREPARED Whether you call it business continuity, disaster recovery or risk management, it all leads towards the same thing a culture

More information

EMERGENCY OPERATIONS PLANNING AND CONTINUITY OF OPERATIONS

EMERGENCY OPERATIONS PLANNING AND CONTINUITY OF OPERATIONS EMERGENCY OPERATIONS PLANNING AND CONTINUITY OF OPERATIONS County Commissioner Clerks/Engineers Administrative Professional Association Winter Conference - Columbus Convention Center Emergency Management

More information

RISK ENGINEERING GUIDELINE

RISK ENGINEERING GUIDELINE RISK ENGINEERING GUIDELINE BUSINESS CONTINUITY MANAGEMENT (BCM) HDI Risk Consulting Business Interruption www.hdi.global Development and Implementation of a Business Continuity Management System (BCMS)

More information

Going Global. Michael Lazcano

Going Global. Michael Lazcano Going Global Michael Lazcano Agenda Building the organization where to start The shape of your organization The Scope of responsibility Crisis leadership starts with practice Summary and questions 1 Building

More information

Equipping You For Success

Equipping You For Success Equipping You For Success Maureen Roskoski, CFM, SFP, LEED AP O+M, Senior Professional Corporate Sustainability Officer Identify Benefits Implement System Engage Team Evaluate Performance Identify Benefits

More information

Starting a Business Continuity Program? Where do I jump on?

Starting a Business Continuity Program? Where do I jump on? Starting a Business Continuity Program? Where do I jump on? Paul D. Kamikawa CBCP Always in Business Continuity Planning, LLC. pkamikawa@frontier.com https://www.linkedin.com/in/pauldkamikawa/ http://www.paulkamikawa.com/

More information

CONTINUITY OF OPERATIONS (COOP) WORKSHEETS

CONTINUITY OF OPERATIONS (COOP) WORKSHEETS CONTINUITY OF OPERATIONS (COOP) WORKSHEETS Martin O Malley, Governor Richard Muth, Director June 2009 Version 2.0 COOP WORKSHEETS These worksheets are tools to help you gather the raw data needed to develop

More information

2016 Business Continuity / Disaster Recovery Internal Audit Report

2016 Business Continuity / Disaster Recovery Internal Audit Report Internal Audit 2016 Business Continuity / Disaster Recovery Internal Audit Report Approved: Isaac S. Clarke May 13, 2016 Report Reference: R-16-2 Executive Summary Background and Procedures Performed Disaster

More information

Auditing the Corporate Business Continuity Plan. Seth Davis, CIA, CFSA, CPA, CISA, CISSP, CFA, CPCU

Auditing the Corporate Business Continuity Plan. Seth Davis, CIA, CFSA, CPA, CISA, CISSP, CFA, CPCU Auditing the Corporate Business Continuity Plan Seth Davis, CIA, CFSA, CPA, CISA, CISSP, CFA, CPCU RLI Insurance Background About 1000 employees, half in branch offices Hybrid IT Infrastructure On-premises

More information

Business Continuity Planning

Business Continuity Planning University of Houston Business Continuity Planning Office of Emergency Management University of Houston 4343 Elgin Houston TX, 77204 What is Emergency Management? The mission of the emergency management

More information

Top 10 pitfalls to avoid when re-inventing your disaster recovery program

Top 10 pitfalls to avoid when re-inventing your disaster recovery program The Essential DR Cheat Sheet: Top 10 pitfalls to avoid when re-inventing your disaster recovery program Consult Build Transform Support Every new malicious attack or weather catastrophe underscores the

More information

Business Continuity Management Policy. Date Version Number Planned Review Date Oct 2014 Issue 1 Oct 2017

Business Continuity Management Policy. Date Version Number Planned Review Date Oct 2014 Issue 1 Oct 2017 Business Continuity Management Policy Document Code PtHB / CGP 001 Date Version Number Planned Review Date Oct 2014 Issue 1 Oct 2017 Document Owner Approved by Date Civil Contingencies Executive Team 08/10/2014

More information

Disaster Recovery Strategies for the BlackBerry Enterprise Solution

Disaster Recovery Strategies for the BlackBerry Enterprise Solution Disaster Recovery Strategies for the BlackBerry Enterprise Solution An Overview Contents Audience... 1 Purpose... 1 Introduction to disaster recovery planning... 1 Key considerations in disaster recovery

More information

For a leader to be effective in today s uncertain world, they have to. understand the nature of complexity and adapt their leadership role in a

For a leader to be effective in today s uncertain world, they have to. understand the nature of complexity and adapt their leadership role in a Exercise and Testing IDRC 2010 Emergent Leadership For a leader to be effective in today s uncertain world, they have to understand the nature of complexity and adapt their leadership role in a manner

More information

University of Houston Business Continuity Planning Office of Emergency Management

University of Houston Business Continuity Planning Office of Emergency Management University of Houston Business Continuity Planning Office of Emergency Management University of Houston 4343 Elgin Houston TX, 77204 What is Emergency Management? The mission of the emergency management

More information

What s the Weakest Link in DR plans? Canadian companies confess their shortcomings

What s the Weakest Link in DR plans? Canadian companies confess their shortcomings What s the Weakest Link in DR plans? Canadian companies confess their shortcomings An evaluation of Canadian organizations and their response to disaster recovery processes. A joint survey in partnership

More information

Enabling a Comprehensive Platform for BCMP that integrates People, Process and Technology

Enabling a Comprehensive Platform for BCMP that integrates People, Process and Technology Enabling a Comprehensive Platform for BCMP that integrates People, Process and Technology TM Overview Perpetuuiti provides an intelligent, end-to-end automated approach towards Business Continuity Planning

More information

Developing an Effective Disaster Recovery Plan

Developing an Effective Disaster Recovery Plan Developing an Effective Disaster Recovery Plan We will figure it out! or What is the point, anyway? January 2017 1 MHA CONSULTING, INC. KEY FACTS A 17-year proven track record of applying industry standards

More information

BCM Lite a quick and easy guide to BCM for beginners and/or small businesses

BCM Lite a quick and easy guide to BCM for beginners and/or small businesses BCM Lite a quick and easy guide to BCM for beginners and/or small businesses Some important definitions Business Continuity Planning The process leading to a clearly defined and documented plan for use

More information

Business/Academic Continuity Guidebook UTA Ready

Business/Academic Continuity Guidebook UTA Ready Summary: The business continuity planning process is designed to address how departments across campus will carry on with teaching, research, service, and support functions without dramatic interruptions

More information

CISSP Certified Information Systems Security Professional (CISSP)

CISSP Certified Information Systems Security Professional (CISSP) QUESTION 1 CISSP Certified Information Systems Security Professional (CISSP) During a recovery procedure, one important step is to maintain records of important events that happen during the procedure.

More information

Disaster Recovery Planning

Disaster Recovery Planning Disaster Recovery Planning Presented by Matt Stolk Associate Director Northwest Regional Data Center Florida State University FAEDS 2015 Why are we here? Over the last couple of years, business continuity

More information

Moving from BS to ISO The new international standard for business continuity management systems

Moving from BS to ISO The new international standard for business continuity management systems Transition Guide Moving from BS 25999-2 to ISO 22301 The new international standard for business continuity management systems Extract from The Route Map to Business Continuity Management: Meeting the

More information

Building a Standard for Business Continuity Planning

Building a Standard for Business Continuity Planning Building a Standard for Business Continuity Planning John Lugo Sr. Business Continuity Analyst April 17, 2012 1 April 16 18, 2012 Talking Stick Resort Scottsdale, Arizona Business Continuity @ Citrix Statistics

More information

Business Continuity Overview

Business Continuity Overview Business Continuity Overview Introductions Goal for this Workshop What happens when an organization doesn t have a BCP? Why FBNYC encourages our network to have a BCP? Business Continuity Plan What is

More information

Discovering the TAC 202 Information Security Standard

Discovering the TAC 202 Information Security Standard This PathMaker Group white paper describes the subject matter within the standard and purpose of each area of measurement. Ryker Exum Introduction The TAC 202 is a freely available security standards framework

More information

Business Continuity Management (BCM) Chicagoland Safety Conference October 24, 2013

Business Continuity Management (BCM) Chicagoland Safety Conference October 24, 2013 Business Continuity Management (BCM) Chicagoland Safety Conference October 24, 2013 Carey A. Loukides, CBCP, ARM, MBCI Senior Consultant, Global Risk Consulting Enterprise Risk Management, Business Continuity

More information

Introducing ISO 22301

Introducing ISO 22301 Introducing ISO 22301 1 2 Background How was the ISO22301 formed? Contributors 3 Context 4 Source documents included BS25999-2 NFPA 1600 ASIS OR standard Singapore standards ISO 27031 ISO Guide 73 ISOPAS22399

More information

Proven Strategies for Overcoming Business Continuity Challenges for Healthcare Organizations

Proven Strategies for Overcoming Business Continuity Challenges for Healthcare Organizations Proven Strategies for Overcoming Business Continuity Challenges for Healthcare Organizations Kathy Lee Patterson, CBCP Business Continuity & Disaster Recovery Manager Children's Hospital of Philadelphia

More information

EY s Africa Resilience Survey 2016

EY s Africa Resilience Survey 2016 EY s Africa Resilience Survey 2016 For more information, please visit: ey.com/za Follow us on Twitter: @EY_Africa B EY s Africa Resilience Survey 2016 Foreword Welcome to EY s Africa Resilience Survey

More information

GUIDE TO CONTINUITY PLANNING

GUIDE TO CONTINUITY PLANNING Academic GUIDE TO CONTINUITY PLANNING The aim of WashU Continuity is to increase the university s resilience in the face of disruptive events. Resilience means being able to continue performing the university

More information

Business Continuity Guide 2017

Business Continuity Guide 2017 Business Continuity Guide 2017 June 2017 Page 1 Acknowledgements The Business Continuity Guide is the primary resource document for the Government of Alberta s departments in the development of a business

More information

Strategic Safety Planning: Step 1 Conducting a Thorough Assessment

Strategic Safety Planning: Step 1 Conducting a Thorough Assessment Strategic Safety Planning: Step 1 Conducting a Thorough Assessment March 15, 2016 In This Session We Seek To: Identify the reasons to conduct an assessment. Outline what to assess. Outline the elements

More information