Governance Risk Awareness. Plans Procedures Facilities. Resilience Adaptability Culture

Size: px
Start display at page:

Download "Governance Risk Awareness. Plans Procedures Facilities. Resilience Adaptability Culture"

Transcription

1 Exercise Checklists Governance Risk Awareness People Capability Skills Drills Tabletops Simulations Live exercises January 2015 Resilience Adaptability Culture Plans Procedures Facilities Response Mitigation Opportunity Awareness

2 CONTENT Summary Checklist 1. Preparation for Exercises Exercise Format Checklist 2. Exercise Conduct Checklist 3. Exercise Analysis and Close Exercise Strategy Capability and Confidence Making Exercises Real SUMMARY Corpress LLP helps you get the best from your exercise programmes. We recognize the investment of time and resources required to create meaningful simulations and scenarios, the importance of accuracy and reality and the need to provide maximum benefit to the participating managers and executives. In response to conversations with clients we have introduced a number of new ideas and approaches to exercises and simulations, which are designed to engage senior executives, reduce development time and maximize engagement across the business. ü Executive immersive sessions; o time focused simulation exercises with intellectual challenge and defined objectives. ü Access to an issues and risk library; o allowing scenario development and realism to be achieved at lower costs. ü Engaging with staff; o through pre and post communications programmes. ü Linking capability and confidence; o through defined learning objectives Corpress partners offer a wealth of experience to help you develop, run and observe exercises. Allowing you to explore the full potential from simple desktop environments to full immersive simulations. We tailor the service to meet your needs. ü We develop exercises in line with established standards. ü Our exercises are designed to meet your objectives including the provision of individual and team training, demonstration of capability and understanding of risk impacts. ü We offer individual and team training in advance of an exercise to ensure participants are confident of their individual role and process to be followed. ü Our objective is to develop exercises that deliver value to our clients. Hundreds of successful exercises run by the Partners across all industry sectors Including some of the worlds largest commercial exercises Full spectrum of risks from cyber through legal to HR, continuity, security and physical incidents Interfacing with regulators, investors, media Exercises for training and awareness Exercises for testing plans and procedures Exercises for checking capability and capacity Executive team facilitation Crisis Leadership

3 Checklist 1. Preparation for Exercises The following checklist uses PD 25666:2010 and ISO as the basis for the key components of exercises, it also contains observations and points noted by Corpress partners who have extensive experience of running exercises., which means that it extends beyond the scope of the BSI and ISO documents but we hope benefits from this. Corpress has experience of preparing exercises across all business sectors, geographies and scale; covering local and global, small to exceedingly large, in both simple and complex settings, for training and testing purposes. The BSI document suggests that: exercises should, over time, seek to validate in full any continuity or contingency capability. It also contains the warning that a less demanding exercise scenario might not provide an accurate level of validation of the plans. Phase Component Element Corpress Comment Preparation Objectives Clarity over the exercise directives - Is the requirement for training or exercises? - What will be gained by running an exercise? - Who should participate? - What facilities need to be used? - What plans are to be used? - Are the plans up to date? - Check if the people involved have sufficient knowledge and experience to get the most out of the exercise proposed Programme Long term programme - Ensure it benefits the business - Aim to improve the competence and confidence of people progressively through the programme - Develop exercise specific elements which target the incident response capabilities to ensure that these work as expected - Promote the integration of incident response elements into a combined response - Identify any necessary improvements to the contingency or continuity strategy and response arrangements - Ensure a close linkage with the risk registers

4 Phase Component Element Corpress Comment - Don t ignore strategically important projects - Maintain a record of the programme, its objectives, deliverables and remedial actions Preparation Planning Risk, issues and impacts - Examine objectives against the wider business case - Look for opportunities to build storylines around current risks and issues - Identify stakeholders Planning Constraints - Analyse what the constraints are for running an exercise o Management commitment o Resources o Time - Recognise which constraints can be overcome Planning Budget - What are the financial constraints on exercising? o Better to conduct training in advance to ensure value from expenditure on a major exercise o Look at a 3 year budget for exercising to get maximum value from investment. Planning Select the method - Consider: o Drills o Workshops and seminars o Tabletops o Simulation o Live play Planning Scenario, storyline and documentation - The following points are captured from Corpress experience: o Does the storyline which describes the event and the implications, feel relevant and possible? o Has the storyline been used to create a detailed scenario? Note: there is a high level link with the scenario but the scenario is more complex o Has the storyline been analysed to identify the full range of issues, risks and impacts which could arise from the event?

5 Phase Component Element Corpress Comment o o o Have the needs and expectations of all stakeholders been taken in to account? Is the supporting documentation comprehensive? Have training modules been prepared for role players and observers? Communication Embedding knowledge - Now is the time to start communicating with the business; use the opportunity to raise awareness, discuss issues and focus attention on business objectives. o Communicate across the business not just with those involved in the exercise Preparation Risk Security and safety Preparation Procedure Exercise Conduct - Has an assessment been conducted of the impact of conducting an exercise to identify: o The exposure of people? o If facilities or assets could be harmed? o How reputation could be damaged? o If sensitive information could be released, damaged or lost? - How sensitive is the information contained in the scenario and have precautions been taken to control such information? - Appoint Exercise conduct roles: o Director o Controller o Observers o Umpires

6 Exercise format Selection of the most suitable format for an exercise must take into account a range of factors: The target audience Maturity of the participating team(s) Exercise objectives and cost Available resources, including time of key personnel Security, safety and risk considerations Corpress LLP will advise on the most suitable format to meet your objectives. Potential formats are illustrated opposite. Corpress LLP Background Corpress LLP services range from consultancy on crisis, business continuity, risk and resilience, through learning and capability development, to bespoke corporate exercises. We create tailored solutions designed to develop resilience and protect organisations. Exercise Type Complexity Exercise Process Variants Good Practice Frequency Simple Desk Check Review /challenge BCP Desk top exercises to understand emerging risks Medium Complex Walk through Simulation IT DR Live exercise with multiple teams Exercise Complexity Challenge BCP Familiarise users Test single components Proof of capability Scenario plus real time responses Integrate with other agencies Depts or single capability Eg callout Focus can change during the exercise from Incident response through business recovery to crisis management Frequent exercises to maintain familiarity. Programme over period of time to test every component and train teams Every 2-3 years. Ultimate demonstration of capability Our focus is the strategic integration of governance and risk management with real time business processes. We achieve this by placing a priority on people; our firm belief is that effective systems, policies and procedures are there to support highly capable individuals and teams. Simulation and exercise programmes deliver enhanced response capability but also form a key part of risk communication, governance and organisational resilience.

7 Checklist 2. Exercise Conduct Phase Component Element Corpress Comment Exercise Conduct Documentation Quality - Check accuracy of information - Ensure good document control - Ensure if appropriate that: o All role players have been briefed and provided with scripts and injects o Multi- media material is available o Instructions have been issued to control staff o Security arrangements for information control have been checked - Make it real Final check Control - Have exercise briefings been prepared for role- players, controllers, observers and umpires? - Final check on safety and security issues and communications at locations - Check access for role players, observers and participants - What controls are in place for third parties who are likely to become aware of the exercise (own staff, outsiders or media)? - Review briefing material for all participants on the exercise communications protocols and processes - Ensure arrangements are in place for suspending or stopping the exercise to respond to real life events - Are records maintained of the content of the briefing and the details of all participants and stakeholders who receive/attend the pre- exercise briefings? - Ensure all key personnel are aware of how the exercise will start - Check all communication links - Check points of exposure between exercise and real life are monitored Exercise Conduct Observation Coordination - Ensure observers are trained and competent in their role

8 Phase Component Element Corpress Comment - Check the instructions for observation of the exercise - Review the timeline and injects for agreed trigger points and actions and check these have been met - Prepare additional inputs to reinforce the scenario if required to ensure objectives will be met - As appropriate monitor and record actions, activities, decisions, facilities and human factors etc. - Ensure arrangements are in place for the Exercise Director to maintain contact with exercise controllers and observers during the exercise Simulation and exercise programmes deliver enhanced response capability but also form a key part of risk communication, governance and organisational resilience. Corpress LLP scenarios have addressed: Cyber security Whistleblowers Floods Building collapse IT software failures IT Hardware failures Loss of critical suppliers Utility failures Media, Public affairs NGO pressure Financial losses Fraud Human rights Liquidity Relatives Response Explosions Terrorism Strikes CSR Disease Community and social issues Anti trust legislation Regulator action Environmental incident Product recall Bribery and corruption

9 Checklist 3. Exercise Analysis and Close Phase Component Element Corpress Comment Analysis Administration Information - Ensure an accurate record is kept of all participants in the exercise - Gather all documents, photographs and electronic references - Implement a secure policy for retaining/disposing of sensitive documents Feedback Assessment - Gather observations from the participants as soon as practicable - Request observers to submit reports - Interview role players and collate their records - Create a timeline against the scenario - Check for exercise irregularities - Match actions and decisions with communications - Assess timelines - Review impacts, issues and decisions taken against the timeline - Check for actions and process against procedures - Review the use of procedures - Check how effective facilities were Close Documentation Report - Create exercise report - Communicate with key stakeholders - Communicate internally - Plan next exercise Action Plan - Prepare an action plan - Capture feedback on live issues and risks and share with compliance and risk department.

10 Phase Component Element Corpress Comment Reminder Exercise documentation can be discoverable in legal cases and may be subject to review by regulators. They need to be controlled documents. Exercise strategy Achieving a successful response to any incident or emerging or potential issue depends on having in place a response structure and procedures which have been exercised to validate the plans and to familiarise all potential response team members with the process to follow. Exercising can follow a range of formats; choosing the most appropriate depends on the objectives of the exercise, the scale of the potential risks facing the organisation and the resources available to support the exercise programme including time and funding. Corpress LLP consultants have wide experience of developing and conducting exercises in a wide range of business sectors. Exercise design in line with the model illustrated here is straightforward. Delivering a successful exercise which meets the objectives however does benefit from previous experience to recognise and manage the challenges and deliver value for money.

11 Capability and Confidence Alongside the testing of plans and facilities, exercises provide tremendously strong learning environments where the experiences, the practice and the skills learnt build the competence and capability of individuals and teams. Not only when implementing a response to Developing realistic scenarios, based on the organisation s risk profile and using current exposures, allows the lessons learnt during the exercises to be instantly translated back to the work place. To achieve this means that care must be taken to ensure the learning objectives tie in with staff development and that the scenarios are realistic and training/exercise environments provide the opportunity for experiential learning. Our approach of reinforcing learning through communications before, during and immediately after the exercises helps to embed the knowledge, ensure engagement with risks and reinforce the organisations compliance with regulatory, governance or internal standards. We offer a well established approach to exercise design and delivery which aligns with established standards ISO and BSi PD which give guidance on exercise and testing. Working with your team Corpress Consultants will develop a detailed project plan to deliver the exercise in line with your objectives. Making the exercises real an incident or continuity based events but in day- to- day business. Our approach delivers the link between exercises, training and staff development to achieve the maximum benefits from your investment. Knowing how to effectively handle problems, to manage risks and to work in challenging circumstances is a key component of staff development. It is important that the exercise creates the right environment for learning the right lessons. Who knows, tomorrow you could be faced with a very similar set of circumstances and problems and the last thing you want is a response based on false lessons gained from ineffective past exercises. Our approach is to ensure the scenario feels realistic. We recognise that in the real world nothing works perfectly so use this to build in a random element, which engages participants. When appropriate and possible we use live inputs delivered by role players who understand

12 the input and can answer questions confidently. We prepare additional inputs to guide the response team towards a full appreciation of potential impacts of events to the organisation. Working with you we tailor the exercise to meet the objectives: Team training? o Requires a progressive programme of different styles of exercises which allows time for team members, and nominated deputies, to learn their individual roles, understand the process and recovery capabilities available, work out their departmental strategy. o The exercise is preceded by briefings/training for team members to give them individual confidence. A rehearsal of a specific recovery strategy? o A technical exercise to test a capability probably assessable as success or failure. o Also requires a progressive programme to move from detailed testing to a large scale exercise to prove that the recovery strategy does scale up to protect the business. o Audience is both the participants and the external stakeholders regulators, customers and suppliers. Designed to challenge the ability to recover when faced by emerging threats? o This is about making the response and recovery capability real. o Work with risk to identify potential scenarios relevant to the organisation, which means the scenario is on the risk horizon with a level of impact that engages executive thinking. o Output is new areas of work to provide continuity management for emerging risks; better understanding of impacts which feeds back into the risk profile; senior management engagement because the outcome is relevant to their current concerns.

13 For more details on Corpress programmes including training, exercises and workshops please visit our web site at or us on David Evans Lynne Donaldson Duncan Ford EXERCISE Design and Development Course Make it Real For details:

The Sector Skills Council for the Financial Services Industry. National Occupational Standards. Risk Management for the Financial Sector

The Sector Skills Council for the Financial Services Industry. National Occupational Standards. Risk Management for the Financial Sector The Sector Skills Council for the Financial Services Industry National Occupational Standards Risk Management for the Financial Sector Final version approved April 2009 IMPORTANT NOTES These National Occupational

More information

For a leader to be effective in today s uncertain world, they have to. understand the nature of complexity and adapt their leadership role in a

For a leader to be effective in today s uncertain world, they have to. understand the nature of complexity and adapt their leadership role in a Exercise and Testing IDRC 2010 Emergent Leadership For a leader to be effective in today s uncertain world, they have to understand the nature of complexity and adapt their leadership role in a manner

More information

A Guide to Business Continuity

A Guide to Business Continuity A Guide to Business Continuity Getting Started Business Continuity Management is a process driven from the top of the organisation. The first stage has to be an acceptance by the Board or the Executive

More information

BUSINESS CONTINUITY AS A SERVICE

BUSINESS CONTINUITY AS A SERVICE BUSINESS CONTINUITY AS A SERVICE CONFIDENCE IN CONTINUITY From the launch of the UK s first managed online backup services over 15 years ago, to our leading Disaster Recovery as a Service (featured in

More information

Certificate in Internal Audit IV

Certificate in Internal Audit IV Certificate in Internal Audit IV The Senior Audit Role auditing key business activities Who should attend? Senior Auditors Audit Managers and those about to be appointed to that role Auditors that need

More information

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY

NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY 1 AUTHOR/ APPROVAL DETAILS Document Author Written By: Phil Hartwell Authorised Signature Authorised By: Helen Shields Date: 06

More information

Citizens Property Insurance Corporation Business Continuity Framework

Citizens Property Insurance Corporation Business Continuity Framework Citizens Property Insurance Corporation Framework Dated September 2015 Approvals: Risk Committee: September 17, 2015 (via email) Adopted by the Audit Committee: Page 1 of 12 Table of Contents 1 INTRODUCTION...

More information

Advanced Audit Techniques

Advanced Audit Techniques Advanced Audit Techniques Who should attend? Senior Auditors Audit Managers and those about to be appointed to that role Auditors that need to audit technical or complex business areas Assurance professionals

More information

Advanced Audit Techniques

Advanced Audit Techniques Certificate in Internal Audit 4 Advanced Audit Techniques Who should attend? Senior Auditors Audit Managers and those about to be appointed to that role Auditors that need to audit projects, contracts

More information

Business Continuity Policy

Business Continuity Policy Putting Barnsley People First Business Continuity Policy Version:.0 Approved By: Governing Body Date Approved: August 015 Reviewed October 016 Name of originator / author: Jamie Wike, Head of Planning,

More information

Testing and Exercising. Continuity Forum May 17, 2012

Testing and Exercising. Continuity Forum May 17, 2012 Testing and Exercising Continuity Forum May 17, 2012 Agenda Business Continuity @ DOT The Exercise Management Model Our Approach Exercising In Practice Moving Forward Considerations Resources Discussion

More information

Certificate in Internal Audit 3. Advanced Audit Techniques

Certificate in Internal Audit 3. Advanced Audit Techniques Certificate in Internal Audit 3 Advanced Audit Techniques Who should attend? Senior Auditors Audit Managers and those about to be appointed to that role Auditors that need to audit projects, contracts

More information

[RESTRICTED ACCESS: SECURITY] COMMONS EXECUTIVE COMMITTEE Update on business resilience capability and annual approval of Business Resilience Policy

[RESTRICTED ACCESS: SECURITY] COMMONS EXECUTIVE COMMITTEE Update on business resilience capability and annual approval of Business Resilience Policy EC2016.P.04 COMMONS EXECUTIVE COMMITTEE Update on business resilience capability and annual approval of Business Resilience Policy Paper from: David Leakey, Chair of the Business Resilience Group Paper

More information

Incident Management Framework. Part One: Overview and Policy. Final Draft. other plans. incident management framework. business as usual (BAU)

Incident Management Framework. Part One: Overview and Policy. Final Draft. other plans. incident management framework. business as usual (BAU) Final Draft Incident Management Framework Part One: Overview and Policy business as usual (BAU) incident management framework other plans Crisis Solutions 18 Hanover Square London, W1S 1HX Tel 0845 130

More information

Business Continuity Management Policy. Guidance

Business Continuity Management Policy. Guidance Management Guidance Document Type: Guidance Parent Policy: Management Policy Policy Owner: Chief Supt Department: Document Writer: Co-ordinator Effective Date: 12 th March 2015 Review Date: 12 th March

More information

City of Saskatoon Business Continuity Internal Audit Report

City of Saskatoon Business Continuity Internal Audit Report www.pwc.com/ca City of Saskatoon Business Continuity Internal Audit Report June 2018 Executive Summary The City of Saskatoon s (the City ) Strategic Risk Register identifies Business Continuity as a high

More information

Tabletop Exercises. for Cybersecurity. Maintaining a healthy incident response. White Paper. By Michael Everett, Security Analyst

Tabletop Exercises. for Cybersecurity. Maintaining a healthy incident response. White Paper. By Michael Everett, Security Analyst Tabletop Exercises for Cybersecurity Maintaining a healthy incident response White Paper By Michael Everett, Security Analyst Effectiveness of Incident Response Formulating and implementing an incident

More information

Oversight by Board, Risk Management & Audit Committee (RMAC) and other committees. Second line of defense

Oversight by Board, Risk Management & Audit Committee (RMAC) and other committees. Second line of defense 47 In the business environment that we live in, doing nothing might be the biggest risk of all. At Cim, the Board plays a crucial role in risk oversight; it is bringing more diverse viewpoints into the

More information

Additional Behaviours for 1 st level line managers in humanitarian response

Additional Behaviours for 1 st level line managers in humanitarian response RESOURCE 1: CBHA Core Humanitarian Competencies Framework with Limiting Behaviours Competency managers in Understanding of contexts and application of principles Key issues and practices impacting current

More information

Fail to Prepare, Prepare to Fail. Business Continuity Management in the Food Industry

Fail to Prepare, Prepare to Fail. Business Continuity Management in the Food Industry Fail to Prepare, Prepare to Fail Business Continuity Management in the Food Industry Fail to Prepare, Prepare to Fail Business Continuity Management in the Food Industry Business continuity (BC) systems

More information

Keys to Narrowing Business Continuity Planning Gaps: Training, Testing & Audits

Keys to Narrowing Business Continuity Planning Gaps: Training, Testing & Audits Keys to Narrowing Business Continuity Planning Gaps: Training, Testing & Audits Betty A. Kildow, CBCP, FBCI, Emergency Management Consultant Kildow Consulting 765/483-9365; BettyKildow@comcast.net 94 nd

More information

18 Business Continuity Management

18 Business Continuity Management 18 Business Continuity Management Business Continuity is the strategic and tactical capability of the organisation to plan for and respond to incidents and business disruptions in order to continue business

More information

Our Blueprint. Balfour Beatty s Sustainability Strategy LEAN, EXPERT, TRUSTED, SAFE. Version 2.0

Our Blueprint. Balfour Beatty s Sustainability Strategy LEAN, EXPERT, TRUSTED, SAFE. Version 2.0 Our Blueprint Balfour Beatty s Sustainability Strategy LEAN, EXPERT, TRUSTED, SAFE Version 2.0 Our Sustainability Blueprint 02 Foreword Our ambition is to continue to position sustainability at the heart

More information

Building Organisational Resilience

Building Organisational Resilience Building Organisational Resilience Through training, exercising, consultancy and support services Presented by: Ronnie Coutts MBE MA Director Training and Resilience History CCA 2004 CCA 2004 Service Company

More information

Business Continuity Planning for Major Disruptions Checklist 255

Business Continuity Planning for Major Disruptions Checklist 255 Business Continuity Planning for Major Disruptions Checklist 255 Introduction Major disruptions to organisations come in many forms. Extreme weather conditions, technical failure, people related factors

More information

Melanie Quinlan, Business Continuity & Compliance Manager, Resources & Quality Assurance

Melanie Quinlan, Business Continuity & Compliance Manager, Resources & Quality Assurance Executive Board meeting, 26 June 2017 Agenda item: 8 Report title: Report by: Action: Business Continuity Working Group update Melanie Quinlan, Business Continuity & Compliance Manager, Resources & Quality

More information

Business Continuity Management Policy. Date Version Number Planned Review Date Oct 2014 Issue 1 Oct 2017

Business Continuity Management Policy. Date Version Number Planned Review Date Oct 2014 Issue 1 Oct 2017 Business Continuity Management Policy Document Code PtHB / CGP 001 Date Version Number Planned Review Date Oct 2014 Issue 1 Oct 2017 Document Owner Approved by Date Civil Contingencies Executive Team 08/10/2014

More information

An introduction to business continuity planning

An introduction to business continuity planning An introduction to business continuity planning What is business continuity, and is it relevant to me? Business continuity planning is about identifying the critical functions and services your business

More information

Business Continuity. Building a Program Fit for Purpose

Business Continuity. Building a Program Fit for Purpose Business Continuity. Building a Program Fit for Purpose Tim Janes. Director Fulcrum Risk Services Tuesday 2 September. 11.30-12.45 T Janes. BC SLIDES. RIMS Risk Forum Aust 2014 v1.0 Building a BC Program

More information

INTERNAL AUDIT PLAN AND CHARTER 2018/19

INTERNAL AUDIT PLAN AND CHARTER 2018/19 INTERNAL AUDIT PLAN AND CHARTER 208/9 PURPOSE OF REPORT. To present the proposed 208/9 audit plan and charter to the Audit Committee for consideration and approval..2 The Internal Audit Plan for 208/9

More information

IT events and training at ramsac

IT events and training at ramsac IT events and training programme 2019 IT events and training at ramsac At ramsac we run a wide range of training courses and events to meet the needs of individuals working in business, not for profit

More information

Capability Manager, Security and Risk

Capability Manager, Security and Risk Capability Manager, Security and Risk Technology Services and Solutions, Service and System Transformation The Capability Manager a key role in the delivery of Security and Risk services across DIA. The

More information

The BEST Framework EDF Group s Expectations for Managing Health and Safety. The EDF Group BEST Framework

The BEST Framework EDF Group s Expectations for Managing Health and Safety. The EDF Group BEST Framework Version 1 The BEST Framework EDF Group s Expectations for Managing Health and Safety The EDF Group BEST Framework 2 CONTENTS 1 2 3 4 5 6 7 8 Leadership in Health and Safety 07 Incident Management 09 Contractor

More information

COMPETENCE & COMMITMENT STATEMENTS

COMPETENCE & COMMITMENT STATEMENTS COMPETENCE & COMMITMENT STATEMENTS The Institution for Rail Infrastructure Engineers A Permanent Way Engineer is one who supports and promotes the advancement of the design, construction and maintenance

More information

The board s role in confronting crisis

The board s role in confronting crisis The board s role in confronting crisis A corporate crisis in today s world accelerates more quickly with a larger impact than ever before. The 24-hour news cycle and prevalence of social media contribute

More information

Training & Development 2017/2018 ALERT + INFORM + ENABLE

Training & Development 2017/2018 ALERT + INFORM + ENABLE Training & Development 2017/2018 Training and Development Our course oerings include: Risk Management & Business Continuity International Consortium for Organisational Resilience Business Continuity Institute

More information

Business Continuity Management Policy and Framework

Business Continuity Management Policy and Framework Management Policy and Framework Version: 9 Produced by: University Manager with the assistance of the Operational Group Date Produced: 11 th March 2010 Approved by: Steering Group (14 December 2010) Updated:

More information

Health, Safety, Environment and Quality (HSEQ) Manager. HSEQ Management System Advisor

Health, Safety, Environment and Quality (HSEQ) Manager. HSEQ Management System Advisor Position description Title: Health, Safety, Environment and Quality (HSEQ) Manager July 2016 Reporting to: Chief Executive Officer Direct Reports: HSEQ Advisors (x2) HSEQ Management System Advisor PURPOSE

More information

Sub-section Content. 1 Preliminaries - Post title: Head of Group Risk - Reports to: CRO - Division: xxx - Department: xxx - Location: xxx

Sub-section Content. 1 Preliminaries - Post title: Head of Group Risk - Reports to: CRO - Division: xxx - Department: xxx - Location: xxx Sub-section Content 1 Preliminaries - Post title: Head of Group Risk - Reports to: CRO - Division: xxx - Department: xxx - Location: xxx 2 Job Purpose - To assist in the maintenance and development of

More information

Community Engagement Framework

Community Engagement Framework NATIONAL STRATEGY FOR DISASTER RESILIENCE Community Engagement Framework HANDBOOK 6 AUSTRALIAN EMERGENCY MANAGEMENT HANDBOOK SERIES Building a disaster resilient Australia NATIONAL STRATEGY FOR DISASTER

More information

B U S I N E S S R I S K M A N A G E M E N T L T D

B U S I N E S S R I S K M A N A G E M E N T L T D B U S I N E S S R I S K M A N A G E M E N T L T D Governance, Risk and Compliance (GRC) After completing this course you will be able to Course Level Understand the requirements and benefits of GRC Develop

More information

Elements of an FFIEC Compliant BCP Plan

Elements of an FFIEC Compliant BCP Plan Elements of an FFIEC Compliant BCP Plan Presented by: Joseph Compton CISSP, CISA Merri Voigt CRCM, CCBCO Planning Stage Appoint a Project Manager Divide Responsibilities Define Objectives and Deliverables

More information

REVIEW OF DISRUPTION TO THE RTGS SYSTEM ON 20 OCTOBER 2014: AN UPDATE TO THE BANK OF ENGLAND S RESPONSE SUMMARY

REVIEW OF DISRUPTION TO THE RTGS SYSTEM ON 20 OCTOBER 2014: AN UPDATE TO THE BANK OF ENGLAND S RESPONSE SUMMARY REVIEW OF DISRUPTION TO THE RTGS SYSTEM ON 20 OCTOBER 2014: AN UPDATE TO THE BANK OF ENGLAND S RESPONSE SUMMARY 1. The Bank of England is responsible for the operation of the United Kingdom s Real-Time

More information

NOT PROTECTIVELY MARKED BUSINESS CONTINUITY. Head of Protective Services Specialist Operations. Business Continuity Manager

NOT PROTECTIVELY MARKED BUSINESS CONTINUITY. Head of Protective Services Specialist Operations. Business Continuity Manager POLICY BUSINESS CONTINUITY Policy owners Policy holder Author Head of Services Specialist Operations Contingency Planning Business Continuity Manager Policy No. 132 Approved by Legal Services Policy owner

More information

Implementing The Wellbeing and Performance Agenda

Implementing The Wellbeing and Performance Agenda In House seminars from: The Implementing The Wellbeing and Performance Agenda Contact: for further details Telephone: Email: Page 1 Programmes for Leaders and Managers that Promote Wellbeing and Performance

More information

POSITION DESCRIPTION

POSITION DESCRIPTION NZSOC Operations Officer POSITION DESCRIPTION Unit/Branch, Directorate: Location: New Zealand Security Operations Centre, Intelligence Directorate Wellington Salary range: G $68,316 - $102,474 Purpose

More information

Policy Incident Communication Plan. Table of Contents

Policy Incident Communication Plan. Table of Contents Table of Contents Incident Communication Plan... 3 Overview... 3 Objective... 3 Policy... 4 Guidelines... 4 Request for Information... 5 Editorial or Letter to Editor Requests... 6 Requests for Interviews...

More information

UNIVERSITY OF ABERDEEN ADVISORY GROUP ON BUSINESS CONTINUITY & RESILIENCE BUSINESS CONTINUITY POLICY

UNIVERSITY OF ABERDEEN ADVISORY GROUP ON BUSINESS CONTINUITY & RESILIENCE BUSINESS CONTINUITY POLICY UNIVERSITY OF ABERDEEN ADVISORY GROUP ON BUSINESS CONTINUITY & RESILIENCE BUSINESS CONTINUITY POLICY 1 INTRODUCTION 1.1 The University of Aberdeen has a responsibility to ensure the health and welfare

More information

Creating a Business Continuity Plan for your Health Center

Creating a Business Continuity Plan for your Health Center Creating a Business Continuity Plan for your Health Center 1 Page Left Intentionally Blank 2 About This Manual This tool is the result of collaboration between the Primary Care Development Corporation

More information

WILTSHIRE POLICE FORCE POLICY

WILTSHIRE POLICE FORCE POLICY Template v4 WILTSHIRE POLICE FORCE POLICY BUSINESS CONTINUITY MANAGEMENT SYSTEMS (BCMS) Date of Publication: January 2017 Version: 3.0 Next Review Date: January 2019 POLICY STATEMENT Wiltshire Police has

More information

RC & CRISIS MANAGEMENT. risk compliance RISK & COMPLIANCE MAGAZINE. risk & compliance REPRINTED FROM: JUL-SEP 2015 ISSUE

RC & CRISIS MANAGEMENT. risk compliance RISK & COMPLIANCE MAGAZINE. risk & compliance REPRINTED FROM: JUL-SEP 2015 ISSUE R E P R I N T RC & risk compliance & CRISIS MANAGEMENT REPRINTED FROM: RISK & COMPLIANCE MAGAZINE JUL-SEP 2015 ISSUE RC & risk & compliance Visit the website to request a free copy of the full e-magazine

More information

EDINBURGH NAPIER UNIVERSITY BUSINESS CONTINUITY POLICY AND FRAMEWORK

EDINBURGH NAPIER UNIVERSITY BUSINESS CONTINUITY POLICY AND FRAMEWORK EDINBURGH NAPIER UNIVERSITY BUSINESS CONTINUITY POLICY AND FRAMEWORK Purpose This policy sets out the University s approach to maintaining and developing business continuity plans on an on-going basis

More information

BCM Lite a quick and easy guide to BCM for beginners and/or small businesses

BCM Lite a quick and easy guide to BCM for beginners and/or small businesses BCM Lite a quick and easy guide to BCM for beginners and/or small businesses Some important definitions Business Continuity Planning The process leading to a clearly defined and documented plan for use

More information

RISK ENGINEERING GUIDELINE

RISK ENGINEERING GUIDELINE RISK ENGINEERING GUIDELINE BUSINESS CONTINUITY MANAGEMENT (BCM) HDI Risk Consulting Business Interruption www.hdi.global Development and Implementation of a Business Continuity Management System (BCMS)

More information

The Incorporated Engineer Standard

The Incorporated Engineer Standard The Incorporated Engineer Standard Incorporated Engineers maintain and manage applications of current and developing technology, and may undertake engineering design, development, manufacture, construction

More information

Competency and Values Framework

Competency and Values Framework college.police.uk Competency and Values Framework Implementation guidance BetterProfessionals forbetterpolicing Limited (2017) This publication is licensed under the terms of the Non-Commercial College

More information

Transparency in the digital age: companies should talk about their cyber security

Transparency in the digital age: companies should talk about their cyber security Transparency in the digital age: companies should talk about their The cyber security of companies is an increasingly important issue for society. Nations depend on the of both public and private institutions

More information

INTEGRATED RISK BUSINESS CONTINUITY CYBER-SECURITY THE RESILIENCE FACTORS THAT DRIVE YOUR REPUTATION

INTEGRATED RISK BUSINESS CONTINUITY CYBER-SECURITY THE RESILIENCE FACTORS THAT DRIVE YOUR REPUTATION CYBER-SECURITY BUSINESS CONTINUITY INTEGRATED RISK THE RESILIENCE FACTORS THAT DRIVE YOUR REPUTATION INTRODUCTION We all work hard to build and protect our reputation, and in today s world of 24/7 news

More information

Human Aspects of Business Continuity. Guidance in support of BS25999 Why are people important in BCM? PD25111: guidance on human aspects

Human Aspects of Business Continuity. Guidance in support of BS25999 Why are people important in BCM? PD25111: guidance on human aspects Technical Briefing Human Aspects of Business Continuity Guidance in support of BS25999 Why are people important in BCM? PD25111: guidance on human aspects Delivering effective BCM... the practical, the

More information

Overview SFJCCAD2. Promote business continuity management

Overview SFJCCAD2. Promote business continuity management Overview This standard is about providing advice and assistance on business continuity management, including general advice for the business and voluntary sectors, and specific advice and assistance to

More information

Business Continuity Training and Testing: Narrowing the Gaps

Business Continuity Training and Testing: Narrowing the Gaps Business Continuity Training and Testing: Narrowing the Gaps Betty A. Kildow, CBCP, FBCI, Emergency Management Consultant Kildow Consulting 765/483-9365; BettyKildow@insightbb.com 92 nd Annual International

More information

The Boardroom DEVELOPING SALES LEADERS.

The Boardroom DEVELOPING SALES LEADERS. Developing Sales Leaders The Boardroom are a best practice sales and sales leadership Assessment and Development Programme, providing high value client-centric solutions to companies from all sectors across

More information

Introduction to Business

Introduction to Business ANALYSIS DESIGN IMPLEMENTATION Introduction to Business Continuity course This course is an introduction to the world of business continuity (BC). It is designed as a first step for newcomers to the subject

More information

ASSET MANAGEMENT SERVICES

ASSET MANAGEMENT SERVICES ASSET MANAGEMENT SERVICES Petrofac Engineering & Production Services 02 ASSET MANAGEMENT SERVICES ASSET MANAGEMENT SERVICES 03 Introducing Petrofac Asset Management Services Petrofac is an international

More information

Digital Industries Apprenticeship: Occupational Brief. Software Tester. March 2016

Digital Industries Apprenticeship: Occupational Brief. Software Tester. March 2016 Digital Industries Apprenticeship: Occupational Brief Software Tester March 2016 1 Digital Industries Apprenticeships: Occupational Brief Level 4 Software Tester Apprenticeship Minimum Standards and Grading

More information

pwc.co.uk Crisis management

pwc.co.uk Crisis management pwc.co.uk Crisis management Contents What s on your mind? 01 Our point of view 02 How can PwC support you? 04 What you gain 06 When to act 08 Intelligent Digital 09 What s on your mind? The ability to

More information

Internal Audit report

Internal Audit report Financial Conduct Authority Internal Audit report The FCA s incident response and crisis management capability Findings identified Major 2 Moderate 1 Minor 0 24 October 2014 1 1 Executive Summary 1.1 Summary

More information

Achieve. Performance objectives

Achieve. Performance objectives Achieve Performance objectives Performance objectives are benchmarks of effective performance that describe the types of work activities students and affiliates will be involved in as trainee accountants.

More information

EY s Africa Resilience Survey 2016

EY s Africa Resilience Survey 2016 EY s Africa Resilience Survey 2016 For more information, please visit: ey.com/za Follow us on Twitter: @EY_Africa B EY s Africa Resilience Survey 2016 Foreword Welcome to EY s Africa Resilience Survey

More information

ALE Global Health, Safety, Quality and Environmental Report for the year ended 31st December 2015.

ALE Global Health, Safety, Quality and Environmental Report for the year ended 31st December 2015. ALE Global Health, Safety, Quality and Environmental Report for the year ended 31st December 2015. Prepared By: Pierre De Villiers Global Health, Safety, Quality and Environmental Date: 31st December 2015

More information

The Emergency Planning Society Core Competences Framework

The Emergency Planning Society Core Competences Framework The Emergency Planning Society: The Organisation for Resilience Professionals www.the-eps.org Issue No. 2 June 2011 The Emergency Planning Society Core Competences Framework The Emergency Planning Society

More information

1.1 Contributes to the Trust s Organisational Development strategy to improve overall organisational performance and effectiveness

1.1 Contributes to the Trust s Organisational Development strategy to improve overall organisational performance and effectiveness JOB TITLE: OD Practitioner BAND: AFC 7 BASE: RESPONSIBLE TO: ACCOUNTABLE TO: XX OD Consultant (OD Lead) Director of OD and L&D JOB SUMMARY The Organisational Development Practitioner is responsible for

More information

TRAINING NEEDS ANALYSIS

TRAINING NEEDS ANALYSIS TRAINING NEEDS ANALYSIS A one-day workshop How are training needs currently identified in your organisation? How effective is your current approach? Could it be improved? Good training needs analysis is

More information

Business Continuity Management PHILIPPINES :: MALAYSIA :: VIETNAM :: INDONESIA :: INDIA :: CHINA

Business Continuity Management PHILIPPINES :: MALAYSIA :: VIETNAM :: INDONESIA :: INDIA :: CHINA Business Continuity Management PHILIPPINES :: MALAYSIA :: VIETNAM :: INDONESIA :: INDIA :: CHINA Learning Bites Understand the context and relevance of BCM A Philippine & Telco Perspective Comprehend how

More information

2017 CONTINUING PROFESSIONAL DEVELOPMENT PROGRAMME

2017 CONTINUING PROFESSIONAL DEVELOPMENT PROGRAMME INSTITUTE OF PUBLIC RELATIONS, GHANA Image is Everything 2017 CONTINUING PROFESSIONAL DEVELOPMENT PROGRAMME THEME: Upgrading professional knowledge while unlocking your business s great potentials through

More information

Creating an Actionable Disaster Recovery Plan

Creating an Actionable Disaster Recovery Plan Creating an Actionable Disaster Recovery Plan Presentation Outline Plan Justification Disaster Definitions & Facts Costs of a Disaster Benefits of Planning Building an Actionable Disaster Recovery Plan

More information

BARNSLEY METROPOLITAN BOROUGH COUNCIL

BARNSLEY METROPOLITAN BOROUGH COUNCIL BARNSLEY METROPOLITAN BOROUGH COUNCIL Audit Committee 23rd March 2016 ANNUAL GOVERNANCE REVIEW PROCESS 2015/16 1. Purpose of Report Report of the Service Director Finance 1.1 The purpose of this report

More information

Abraham E. Binder MA, ABCP York University Disaster & Emergency Management Program

Abraham E. Binder MA, ABCP York University Disaster & Emergency Management Program Abraham E. Binder MA, ABCP York University Disaster & Emergency Management Program TTX Basics Real Relevant Refreshed Questions TTX Fundamentals Intermediate level For busy leadership teams Not a Walkthrough

More information

Risks, Strengths & Weaknesses Statement. November 2016

Risks, Strengths & Weaknesses Statement. November 2016 Risks, Strengths & Weaknesses Statement November 2016 No Yorkshire Water November 2016 Risks, Strengths and Weaknesses Statement 2 Foreword In our Business Plan for 2015 2020 we made some clear promises

More information

Head of IT Services. Spot salary circa 50K (Negotiable subject to skills & experience)

Head of IT Services. Spot salary circa 50K (Negotiable subject to skills & experience) Head of IT Services Spot salary circa 50K (Negotiable subject to skills & experience) Thank you for your interest in joining our team. We have enclosed details of some of the benefits that form part of

More information

LI & FUNG LIMITED ANNUAL REPORT 2016

LI & FUNG LIMITED ANNUAL REPORT 2016 52 Our approach to risk management We maintain a sound and effective system of risk management and internal controls to support us in achieving high standards of corporate governance. Our approach to risk

More information

Perform. Business Better. Through Sustainable Strategies

Perform. Business Better. Through Sustainable Strategies 2018 Perform Business Better Through Sustainable Strategies TABLE OF CONTENTS Introduction to CSR 3 CSR Masterclass 4 CSR Strategy 6 Internal & External Communication 8 PR Channels of CSR 10 CSR Reporting,

More information

Disaster Preparedness & Your Supply Chain

Disaster Preparedness & Your Supply Chain Disaster Preparedness & Your Supply Chain Scott Teel, Agility Recovery Today s session will be recorded. Links to the archived recording will be emailed to all registrants automatically tomorrow. For copies

More information

Health and Safety Management Profile (HASMAP)

Health and Safety Management Profile (HASMAP) Health and Safety Management Profile (HASMAP) Contents Introduction 02 HASMAP overview 03 Getting started 04 Indicator summaries A Leadership 07 B Planning for emergencies 15 C Health and safety arrangements

More information

High Performance Crisis/Incident Management A Roundtable Discussion Regarding Best Practices

High Performance Crisis/Incident Management A Roundtable Discussion Regarding Best Practices High Performance Crisis/Incident Management A Roundtable Discussion Regarding Best Practices Brian Zawada (MBCP, MBCI) Avalution Consulting 2011 Avalution Consulting, LLC All Rights Reserved Introductions

More information

Duty Station (DS): Belgrade, Serbia One year, renewable subject to satisfactory performance and funds availability Closing Date: 1 May 2018

Duty Station (DS): Belgrade, Serbia One year, renewable subject to satisfactory performance and funds availability Closing Date: 1 May 2018 UNOPS helps its partners in the United Nations system meet the world s needs for building peace, recovering from disaster, and creating sustainable development. UNOPS is known for its ability to implement

More information

UNIVERSITY OF HOUSTON

UNIVERSITY OF HOUSTON UNIVERSITY OF HOUSTON EMERGENCY MANAGEMENT BUSINESS CONTINUITY PLANNING DEPARTMENT TEMPLATE University of Texas at El Paso School of Nursing All Hazards - Continuity of Operations Plan (COOP) Instructions:

More information

University of Birmingham. Protocol for the Governance of University Wholly Owned Subsidiary Companies and Companies

University of Birmingham. Protocol for the Governance of University Wholly Owned Subsidiary Companies and Companies University of Birmingham Protocol for the Governance of University Wholly Owned Subsidiary Companies and Companies Introduction Where the University Retains an Interest. 1.The University recognises that

More information

Meet Our Presenter. Equipping You For Success: An ISO Certification Case Study

Meet Our Presenter. Equipping You For Success: An ISO Certification Case Study Equipping You For Success: An ISO 22301 Certification Case Study March 28, 2017 10:45 11:45 am Maureen Roskoski, Corporate Sustainability Officer, Facility Engineering Associates, PC Meet Our Presenter

More information

Business Continuity Framework

Business Continuity Framework Business Continuity Framework A definition to the Components of Resiliency March, 1 Business Continuity Framework 1. INTRODUCTION... 3 2. PURPOSE... 3 3. THE FRAMEWORK... 4 4. STEERING COMMITTEE... 5 5.

More information

Roads to Revolution. Digital transformation: reshaping resilience for the future

Roads to Revolution. Digital transformation: reshaping resilience for the future Roads to Revolution Digital transformation: reshaping resilience for the future Roads to Revolution Digital transformation: reshaping resilience for the future 1. The challenge The digital revolution,

More information

Our Approach to Risk Management

Our Approach to Risk Management 62 Li & Fung Limited Annual Report 2017 Our Approach to Risk Management Our Approach to Risk Management We maintain a solid, effective system of risk management and internal controls to support us in achieving

More information

Seminars for Workplace Leaders 2018 Mike Deblieux All Rights Reserved

Seminars for Workplace Leaders 2018 Mike Deblieux All Rights Reserved A Mike Deblieux Program Summary Seminars for Workplace Leaders 2018 Mike Deblieux All Rights Reserved Program Summaries Table of Contents Effective Training 1 Workshops and Seminars 2 The Workplace Leader

More information

COMMUNICATIONS STRATEGY

COMMUNICATIONS STRATEGY COMMUNICATIONS STRATEGY 2016-2019 Introduction and purpose This strategy details how communications will support the delivery of shaping the future of urgent & emergency care (EEAST strategy 2016-21).

More information

IPSec Professional Risk Victorian Protective Data Security Standards Compliance Services Overview in Brief

IPSec Professional Risk Victorian Protective Data Security Standards Compliance Services Overview in Brief IPSec Professional Risk Victorian Protective Data Security Standards Compliance Services Overview in Brief Date: March 2017 Copyright & Confidentiality This document is copyright IPSec Pty Ltd (IPSec).

More information

Enterprise compliance Acting on today s risks to avoid tomorrow s crises

Enterprise compliance Acting on today s risks to avoid tomorrow s crises Enterprise compliance Acting on today s risks to avoid tomorrow s crises Enterprise compliance challenges cannot be ignored As many retailers know from recent history, compliance failures can lead to catastrophic

More information

How to create scenarios for change

How to create scenarios for change How to create scenarios for change Author Melanie Franklin Director Agile Change Management Limited Introduction Organisational change, by its very nature is uncertain. The best we can hope for is clarity

More information

New Mexico State University All Hazards - Continuity of Operations Plan (COOP) (Template available at )

New Mexico State University All Hazards - Continuity of Operations Plan (COOP) (Template available at  ) New Mexico State University All Hazards - Continuity of Operations Plan (COOP) (Template available at http://safety.nmsu.edu ) Instructions: To be better prepared, all NMSU departments and units may use

More information

Benefits and issues of managed services. Executive summary

Benefits and issues of managed services. Executive summary Benefits and issues of managed services Benefits and issues of managed services Executive summary March 2008 http://www.becta.org.uk page 1 of 7 Executive summary Introduction A managed service is any

More information

Cintra iq Implementation Methodology (C.I.M) Document for public distribution

Cintra iq Implementation Methodology (C.I.M) Document for public distribution Cintra iq Implementation Methodology (C.I.M) Document for public distribution Table of Contents Document history... 3 Background... 4 Stages... 4 Project Initiation... 5 Pre Implementation & Requirements

More information