WILTSHIRE POLICE FORCE POLICY

Similar documents
WILTSHIRE POLICE FORCE PROCEDURE

Business Continuity Management Policy and Procedure

Derbyshire Constabulary INFORMATION SHARING POLICY POLICY REFERENCE 06/101. This policy is suitable for Public Disclosure

Risk Management Strategy

Date: INFORMATION GOVERNANCE POLICY

Head of Security and Business Continuity

Bowmer. & Kirkland. Kirkland. & Accommodation. Health & Safety Policy.

Area Manager, Protection

Corporate policy. Business Continuity Management Policy. Issue sheet

IG01 Information Governance Management Framework

Information Governance Assurance Framework

Melanie Quinlan, Business Continuity & Compliance Manager, Resources & Quality Assurance

GOVERNANCE STRATEGY October 2013

Facilities Controller Job Description

Police Support Volunteers

Information Governance Policy

RISK MANAGEMENT COMMITTEE TERMS OF REFERENCE

Update from the Business Continuity Working Group

FRIENDS OF ELTON SCHOOL

GUIDANCE NOTE FOR DEPOSIT TAKERS (Class 1(1) and Class 1(2))

The Newcastle upon Tyne Hospitals NHS Foundation Trust. Business Continuity Management Policy

INFORMATION GOVERNANCE POLICY

POSITION DESCRIPTION SENIOR ENGINEER

SERVICE PROCEDURE NOVEMBER 2011

Records Management Plan

Compliance standard & framework

Quality Management Policy. University-wide Specific. Staff Only Students Only Staff and Students. Vice-Chancellor

IGPr002 - Information Governance Management Framework

RISK MANAGEMENT STRATEGY

POLICY ON MANAGING POLICIES, PROCEDURES AND GUIDANCE DOCUMENTS

Force Executive Board. Minutes of Meeting 13 January 2016

INFORMATION GOVERNANCE STRATEGY. Documentation control

See revision section. Resources, Roles, Responsibility, Accountability, and Authority. Section in OHSAS 18001:2007

CODE OF PRACTICE Appointment to Positions in the Civil Service and Public Service

Business and Finance Manager

Job title: Diversity & Inclusion Manager. Grade: PO 5. Role code: EBC0470. Status: Police Staff. Main purpose of the role:

CAMBRIDGESHIRE COUNTY COUNCIL SAFETY OF SPORTS GROUNDS FUNCTION POLICY DOCUMENT

CORPORATE GOVERNANCE King III - Compliance with Principles Assessment Year ending 31 December 2015

Bank of Botswana Internal Audit Charter March 18, 2013 INTERNAL AUDIT CHARTER BANK OF BOTSWANA

Company Secretary & Legal Affairs

Policy Work Health and Safety (WHS) RCPA Introduction WHS legislation

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN

Ethical leadership and corporate citizenship. Applied. Applied. Applied. Company s ethics are managed effectively.

LOCATION: Alpha Plus Fostering, Oldham

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

The Sector Skills Council for the Financial Services Industry. National Occupational Standards. Risk Management for the Financial Sector

HEALTH AND SAFETY STRATEGY

Business Continuity Planning and Disaster Recovery Planning

Establishing a Multi-Stakeholder Group and National Secretariat

Freedom of Information (FOI) Policy

East Riding of Yorkshire Council Corporate Health and Safety Policy

Human Resources Committee Charter

PROCEDURE Responding to Incidents. Number: D 0503 Date Published: 3 March 2016

Job Description. Senior Management Accountant. Financial Controller. Management Accountants

Job Description. SmartGrowth Administrator. SmartGrowth Programme Manager

City Infrastructure and Traffic Operations. Titles of Positions which report to Public Domain Team Leader are:

Risk Assessment Corporate Health and Safety Procedure

H.E.S.T. Australia Limited. (as Trustee for the Health Employees Superannuation Trust Australia) Governance Disclosures

Introducing ISO 22301

STATUTORY POWERS, DUTIES, ROLES AND RESPONSIBILITIES OF GOVERNORS

DECISION 10/2014/GB OF THE GOVERNING BOARD OF THE EUROPEAN POLICE COLLEGE ADOPTING THE EUROPEAN POLICE COLLEGE S INTERNAL CONTROL STANDARDS AND

Position Description Development Officer Infrastructure Planning

This document contains a summary of the Group s application of all of the principles contained in King III.

Loch Lomond & The Trossachs National Park Authority. Annual internal audit report Year ended 31 March 2015

KING III CHECKLIST. We do it better

Job Description. Department

Business Continuity Plan Activation and Review

Financial Accountant Job Description

Executive Board Terms of Reference. 1. Purpose 1.1

PRE-SCHOOL LEARNING ALLIANCE 50 FEATHERSTONE STREET LONDON EC1Y 8RT. Registered as an Educational Charity JOB DESCRIPTION

Part A (Acting) Returning Officer role and responsibilities

Board committees. Role of the board

CORPORATE GOVERNANCE KING III COMPLIANCE REGISTER 2017

King IV Application Register

Derbyshire Constabulary POLICE STAFF PROBATIONARY PERIOD GUIDANCE POLICY REFERENCE 06/169. This guidance is suitable for Public Disclosure

Chair Job Description and Person Specification

National Ambulance Service 1 of 21 NAS Headquarters Version th September 2011 Authorised by NAS Leadership Team

EQUALITY AND DIVERSITY COMMITTEE. Terms of Reference

KING IV APPLICATION REGISTER. We do it better

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

Policy Framework. Version Number 1.2. Effective from 04 March Authors: Senior Information Security Officer, Head of Information Governance

SENIOR INTERNAL AUDITOR

CORPORATE GOVERNANCE King III - Compliance with Principles Assessment Year ending 31 December 2016

Information Governance Policy and Management Framework

Position Description

INFORMATION GOVERNANCE POLICY

Humber Information Sharing Charter

Information Governance Policy

Audit and Risk Committee Charter

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead

King iii checklist 2013

Information Governance Strategic Management Framework

Terms of Reference. Quality and Value Audits

Isle of Wight Council Job Description

THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER

OH&S MANAGEMENT SYSTEM CHECKLIST - AS 4801:2001 (STATUS A = Acceptable; N = Not Acceptable; N/A = Not Applicable)

Governance Principles

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY

Data protection (GDPR) policy

NOT PROTECTIVELY MARKED. This paper is presented in line with the internal audit contract with Scottish Police Authority

Transcription:

Template v4 WILTSHIRE POLICE FORCE POLICY BUSINESS CONTINUITY MANAGEMENT SYSTEMS (BCMS) Effective from: July 2013 Last Review Date: January 2017 Version: 3.0 Next Review Date: January 2019

POLICY STATEMENT Wiltshire Police has a statutory duty to maintain plans to ensure that they can continue to perform their functions in the event of an Emergency, so far as is reasonably practicable. The Civil Contingencies Act 2004 (CCA) requires emergency responders to exercise all their functions, not just their emergency functions, in the event of an emergency. Business Continuity Management Systems (BCMS) must be put in place to ensure that these functions are carried out so far as is reasonably practicable. BCMS is a management process that helps manage the risks to the smooth running of an organisation or delivery of a service, ensuring it can continue to operate to the extent required in the event of disruption. These risks could be from the external environment (e.g. power outages, severe weather) or from within an organisation (e.g. systems failure, loss of key staff). BCMS is complementary to Risk Management which seeks to understand the wider risks (of which BCMS may be one) to the achievement of the aims and objectives of the force. It is important not to confuse Business Continuity Management with operational response to major incidents. Business continuity management focuses on internal issues to maintain organisational abilities whereas response to major incidents focuses on external events. Wiltshire Police provides the public of Wiltshire with a full policing service 365 days of the year. The purpose of our Business Continuity Management System is to ensure that in the event of any disruption of service, critical core police functions continue to be performed to an acceptable level of service and recovery from disruption is both timely and effective. The BCMS will be complimented by plans which contain force wide, divisional and departmental contingencies and details of how the force will deal with such threats if and when they do arise. Though disruptions in service delivery are anticipated the Force would not be regarded as efficient or effective if in the face of disruptive challenges, it was unable to continue delivery of service to an acceptable level. What is acceptable will depend to some extent on the circumstances and acceptance indicated by public opinion, public or judicial enquiries or inspectorate bodies such as HMIC. Adherence to this policy will ensure compliance with all relevant legislation and internal policies and ensure that the Force has effective BCMS in place which are regularly tested and maintained. Failure to adhere to this policy would be likely to attract criticism from those judging force performance and may expose the force to risks such as loss of reputation, financial penalties or punitive action against individuals. POLICY AIM The aim of this policy is to direct the Force towards a comprehensive framework for a Business Continuity Management System (BCMS) so that in the event of an emergency, Wiltshire Police can continue to provide the best possible service. The policy includes all slow time management activities and is complemented by plans which can be used in the event of a disruption, or threatened disruption, to the service provision of the force. The policy fully supports the Wiltshire Police objective To prevent crime and protect the public. Version: 3.0 21.01.2017 Next Review Date: January 2019 Page 2 of 8

In effect this policy will provide a framework for preparing and developing the plan and embedding business continuity within the culture of Wiltshire Police and the plan will detail the response to the threats posed. APPLICABILITY This policy is applicable to the whole Force and, where required in contracts, to persons or organisations contracted to provide goods and services on behalf of the Force. LEGAL BASIS AND DRIVING FORCE Civil Contingencies Act 2004 International Standard for Business Continuity ISO 22301 STRATEGIC PRIORITIES The Force Priorities linked to this document are set out below. Force Priorities Linked to this Policy SP4 Developing Sustainable Policing RELATED POLICIES, PROCEDURES and OTHER DOCUMENTS Risk Principles and Procedures Business Continuity Plans AUTHORISED PROFESSIONAL PRACTICE: There are no directly related areas of APP (This is currently being addressed by ACPO). DATA PROTECTION ACT 1998 Any information relating to identifiable individuals recorded as a consequence of this procedure will be dealt with in accordance with the Data Protection Act and the Force Data Protection Policy. FREEDOM OF INFORMATION ACT 2000 This document has been assessed as suitable for public release. MONITORING AND REVIEW The effectiveness of this policy will be monitored in line with the Forces Business Continuity Plan and the ability of the Force to minimise the risk of disruption from identified threats and to exercise all their functions, not just their emergency functions, in the event of an emergency. This policy will be reviewed annually in the light of any national policy or procedural change or due to changes to law or Force strategy or at such other times as may become necessary. WHO TO CONTACT ABOUT THIS POLICY This policy is owned by Operations Support, Major Incident Planning Department. All queries regarding this policy, the BCMS or the Business Continuity Plan should be directed to the Major Incident Planning Manager. Ownership and responsibility for activities is addressed in Appendix A below. Version: 3.0 21.01.2017 Next Review Date: January 2019 Page 3 of 8

Appendix A Chief Constable Strategic Lead (SRO) Deputy Chief Constable Force Business Continuity Working Group (FBCWG) (Force Business Continuity Manager / Force Business Continuity Coordinator/ Command SPOCS) Tasking & Coordination Command People Services Local Policing Operational Support Protective Services Finance and Logistics 1. The Chief Constable The Chief Constable is responsible and accountable to the Police Authority for the delivery of policing services. This includes business continuity. 2. Strategic Lead (Senior Responsible Officer) The Deputy Chief Constable (or nominated person) has overall responsibility for the Business Continuity Management (BCM) process and will assume the role of the Senior Responsible Officer (SRO). This member of the executive management board will: Ensure that Wiltshire Police fully complies with its statutory duties under the Civil Contingencies Act 2004 Provide clear strategic direction for the Business Continuity Programme (BCP) Ensure that BCM is effectively implemented in line with the agreed policy and strategy Oversee the development of the governance framework for the management of the organisation s BCM programme including responsibilities, monitoring and reporting to senior management Ensure that all senior managers fully support the BCM programme and the principles of BCM are embedded into the organisation Delegate responsibility for the ongoing management of the BCP to the Force Business Continuity Manager Version: 3.0 21.01.2017 Next Review Date: January 2019 Page 4 of 8

3. Force Business Continuity Manager The SRO will appoint a Force Business Continuity Manager. They will have a tactical level of responsibility for the Business Continuity Programme (BCP). Their primary roles are to: Consult with the SRO to ensure the BCP is progressing in line with the approved Business Continuity Strategy Ensure Wiltshire Police s BCP is project managed and a clear audit trail is in place Coordinate the work of the BCWG to ensure consistently and effectively Wiltshire Police s BCP is progressed Ensure the BCP is managed and progressed throughout the force on a day to day basis Produce and maintain key supporting documents required for the BCP Develop the methodology for creating business continuity plan(s) and oversee their implementation Provide advice and support to staff and all stakeholders involved in Wiltshire Police s BCP Quality assure Business Continuity documents completed by command SPOCs Provide a schedule for the reviewing, testing and exercising of Business Continuity Plans, to ensure that they are up to date, relevant and fit for purpose Promote Business Continuity awareness throughout Wiltshire Police through consultation, training, exercising and the testing of plans Act as the Force Business Continuity SPOC for all internal and external audits 4. Force Business Continuity Working Group The role of the forum will be to: Ensure Wiltshire Police is compliant with its legal and other requirements Ensure the development and implementation of the Business Continuity Programme within Wiltshire Police Ensure Wiltshire Police is able to respond to a disruption, irrespective of the cause Consider interdependencies between all stakeholders, including outside organisations and suppliers, that require collaborative working to promote force level Business Continuity planning Embed the principles and understanding of Business Continuity throughout Wiltshire Police by means of consultation, training and exercising Identify gaps and make recommendations to the force Executive and Command Heads Attend the Force Assurance and Organisational Learning Group Identify areas of the business at most risk and propose action to mitigate this risk 5. Force Business Continuity Coordinator The Force Business Continuity Coordinator will be appointed by the Force Business Continuity Manager. Their primary role will be to: Provide support to Force Business Continuity Manager Undertake planning and coordination work as required by the Force Business Continuity Manager Represent Wiltshire Police at relevant local, regional and national Business Continuity meetings as agreed by the Force Business Continuity Manager Version: 3.0 21.01.2017 Next Review Date: January 2019 Page 5 of 8

Maintain an awareness of local, regional and national events and publications that may impact on the BCP within Wiltshire Police 6. Heads of Command The Heads of Command are responsible for the production and maintenance of their respective Business Continuity Plans. They will also: Identify an appropriate manager(s) within their directorate to be the single point of contact(s) (SPOCs) for all Business Continuity work. Provide support and commitment to the Business Continuity SPOC(s) within their Command Promote the understanding and importance of Business Continuity within their Command Ensure the principles of Business Continuity are embedded within their command through training, exercising and raising staff awareness Ensure the completion of an analysis of critical functions within their command Oversee the production and regular maintenance of their Business Continuity plans Promote and support proactive work with contractors, suppliers and partners required to promote the BCP Ensure Business Continuity plans and associated documents are reviewed and tested effectively Approve and sign off completed Business Continuity documents Ensure Business continuity arrangements within their Command remain current to reflect any changes including human resources, office moves, working practices and processes. 7. Functional Commands Business Continuity Single Point of Contact (SPOC) This role will be fulfilled by staff deemed most appropriate by the Functional Commander. Their responsibilities include to: Support, promote, develop and manage the Business Continuity Programme within their Command Take an active role within the Force Business Continuity Working Group (BCWG) to ensure a consistent and progressive approach to Business Continuity within their Command and across Wiltshire Police Liaise closely with the Force Business Continuity Manager and Coordinator Participate in Business Continuity training, workshops and exercises to enable the development and testing of Business Continuity plans Promote embedding the principles of Business Continuity within their Command through training, exercising and raising staff awareness Ensure there is an effective audit trail in place for all Business Continuity activities within their Command Proactively seek to mitigate risks and vulnerabilities Identify alternative, off site facilities and services Present options and recommended solutions to senior management for approval Provide Heads of Command with completed Business Continuity documents to be approved and signed off Version: 3.0 21.01.2017 Next Review Date: January 2019 Page 6 of 8

DOCUMENT ADMINISTRATION Ownership: Department Responsible: HQ Operations - Major Incident Planning Procedure Owner/Author: Mr Robert YOUNG (Business Continuity Manager) Technical Author: Senior Officer/Manager Sponsor: ACO Business and People Development Revision History: Revision Date Version Summary of Changes 28.11.2012 1.1 Policy statement redrafted to include more detail on the forces obligations and the potential effect of failure to conform to this policy. Text from Legal Basis section moved to the Statement section. List of relevant legal documents added to Legal Basis section. 23.01.2013 1.2 Appendix A added to detail ownership and responsibility for activities. Draft now v1.3 16.07.2013 1.3 Policy approved by SCT Policy now substantive version 2.0 21.01.2017 3.0 Minor amendments to reflect changes in force structure Approvals: This document requires the following approvals: Name & Title Date of Approval Version Assurance Team 27.03.2013 1.2 Senior Command Team 16.07.2013 2.0 JNCC (Not required for all policies) N/A N/A Distribution: This document has been distributed via: Name & Title Date of Issue Version E-Brief Email to relevant affected Staff/Officers Equality Impact Assessment: Has an EIA been completed? If no, please indicate the date by which it will be completed. If yes, please send a copy of the EIA with the policy. Yes No Date: 14.07.2012 Version: 3.0 21.01.2017 Next Review Date: January 2019 Page 7 of 8

Consultation: List below who you have consulted with on this policy (incl. committees, groups, etc): Name & Title Date Consulted Version Implications of the Policy: ACC Stephen Hedley 27.03.2013 1.3 Robert Young 27.03.2013 1.3 Supt. Nick Ashley 27.03.2013 1.3 T/C/Supt Paul Mills 27.03.2013 1.3 Zoe Durrant 27.03.2013 1.3 C/Supt. Andrew Tatam 27.03.2013 1.3 Sue Leffers 27.03.2013 1.3 C/Supt. Kier Pritchard 27.03.2013 1.3 Clive Barker 27.03.2013 1.3 Training Requirements There is an ongoing training requirement but with the current changes within the organisation this is proving difficult to achieve. There is an e learning product on line and ACPO are developing on line learning package. IT Infrastructure On line training availability. Version: 3.0 21.01.2017 Next Review Date: January 2019 Page 8 of 8