Business Continuity Management Policy and Framework

Similar documents
Head of Security and Business Continuity

UNIVERSITY OF ABERDEEN ADVISORY GROUP ON BUSINESS CONTINUITY & RESILIENCE BUSINESS CONTINUITY POLICY

Business Continuity Management Policy. Guidance

Melanie Quinlan, Business Continuity & Compliance Manager, Resources & Quality Assurance

WILTSHIRE POLICE FORCE POLICY

Business Continuity. Building a Program Fit for Purpose

NOT PROTECTIVELY MARKED BUSINESS CONTINUITY. Head of Protective Services Specialist Operations. Business Continuity Manager

The Newcastle upon Tyne Hospitals NHS Foundation Trust. Business Continuity Management Policy

Business Continuity Policy. Interim Governance Consultant. October Greenwich Executive Group

Update from the Business Continuity Working Group

POL:10:EP:003:03:NIBT PAGE 1 of 7

Bowmer. & Kirkland. Kirkland. & Accommodation. Health & Safety Policy.

Introducing ISO 22301

JCU Business Continuity Management Plan

Business Continuity Planning and Disaster Recovery Planning

Risk Management Strategy

Business Continuity Management Policy and Procedure

Yale University Business Continuity Planning Quick Start Guide

Business Continuity Management for Singapore s Logistics Sector. By Singapore Business Federation and Singapore Logistics Association

JOB DESCRIPTION. Service Line Manager for [one of Education/Research/Business/Infrastructure] Job Family/Level: Professional Services, level 6

BSB Research Strategy

GOVERNANCE STRATEGY October 2013

BUSINESS CONTINUITY MANAGEMENT POLICY

Information Governance Strategic Management Framework

Quality Management Policy. University-wide Specific. Staff Only Students Only Staff and Students. Vice-Chancellor

Group Accountant (Children s Services)

Corporate policy. Business Continuity Management Policy. Issue sheet

BUSINESS CONTINUITY AS A SERVICE

Business Continuity Policy

H.E.S.T. Australia Limited. (as Trustee for the Health Employees Superannuation Trust Australia) Governance Disclosures

NHS Hull Clinical Commissioning Group. Commissioning Prioritisation Framework V3.0

Facilities Manager 1 Role Profile

Date: INFORMATION GOVERNANCE POLICY

Environmental Sustainability Policy.

Information Governance Policy

BUSINESS CONTINUITY MANAGEMENT POLICY

219 Make sure your own actions reduce risks to health and safety

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

ISO Business Continuity Management. Your implementation guide

Planning Construction Procurement. A guide to health and safety and employment standards at work

The Sector Skills Council for the Financial Services Industry. National Occupational Standards. Risk Management for the Financial Sector

Humber Information Sharing Charter

Job Description. Department

Job title: Diversity & Inclusion Manager. Grade: PO 5. Role code: EBC0470. Status: Police Staff. Main purpose of the role:

NHS HEALTH SCOTLAND PARTNERSHIP AGREEMENT

Global Crises: What We Really Need to Do to Be Prepared. Day One / Session C5

RISK MANAGEMENT POLICY

IG01 Information Governance Management Framework

Citizens Property Insurance Corporation Business Continuity Framework

How to to transition to ISO One year on. Rob Acker Business Continuity Lead Assessor LRQA Ltd

STATUTORY POWERS, DUTIES, ROLES AND RESPONSIBILITIES OF GOVERNORS

BCP Methodology Benefits realisation

Interim Head of Internal Communications (Fixed Term)

Work Health and Safety

HEALTH AND SAFETY STRATEGY

Corporate Policy and Strategy Committee

JOB DESCRIPTION. Ambulance Operations Manager. EMS Area Manager

GROUP BUSINESS CONTINUITY MANAGEMENT POLICY

Title: Administration Officer Location: Toowoomba Catholic Schools Office

OPERATIONAL RISK MANAGEMENT MODULE

JOB DESCRIPTION. SUP 03/04 ( 17,439-21,549) dependant on qualifications and experience**

National model for regional working

Quality Assurance Framework for Safeguarding Children

Exercise Tangaroa Evaluation Plan. V1.0 4 February 2016

ASBESTOS MANAGEMENT PLAN. July Document Version: 1

Business Continuity Plan Activation and Review

Business Continuity Framework

RISK MANAGEMENT STRATEGY

National Joint Council for Local Government Services

Records Management Plan

DRAFT ROLE DESCRIPTION Riverina Murray Destination Network, Administrative Assistant

Health, Safety and Environmental Management Systems Audit Report

Good Practice Guidelines 2013 Global Edition Edited Highlights

University of Birmingham

Audit Committee Charter ISSUE DATE: 22 JUNE 2017 AUDIT COMMITTEE CHARTER. ISSUE DATE: 22 JUNE 2017 PAGE 01 OF 07

RISK MANAGEMENT COMMITTEE TERMS OF REFERENCE

Information Governance Strategy and Management Framework

COMMUNICATIONS STRATEGY

Environment and resource efficiency Strategy and action plan 2016/17

Network Rail Limited (the Company ) Terms of Reference. for. The Audit and Risk Committee of the Board

Chairman of Hillingdon HealthWatch. Recruitment Pack

THE UNIVERSITY OF NOTTINGHAM. Recruitment Role Profile. Governance Services and Executive Support (Executive Office)

Humber Information Sharing Charter

King lll Principle Comments on application in 2013 Reference in 2013 Integrated Report

Data Quality Policy

Role Title: Chief Officer Responsible to: CCG chairs - one employing CCG Job purpose/ Main Responsibilities

Customer Advocacy. Complaints Management Policy

HEALTH AND WELLBEING STRATEGY

Defending the Fortress Women in FM 15 th July Samantha Bowman Senior Facilities Manager

The anglo american Safety way. Safety Management System Standards

2 Collaborate to increase immediate safety. 3 Facilitate links to further support. 4 Review and report on support provided

THE HARBOUR MEDICAL PRACTICE EASTBOURNE

Volunteer Development Strategy

Health, Safety and Environmental Manager

This role is based within IT support. You will be required to work as part of a team to provide customer-focussed day-to-day IT support.

Performance Standards for Self-insurers

King lll Principle Comments on application in 2016 Reference Chapter 1: Ethical leadership and corporate citizenship Principle 1.

Equality and Diversity Policy

James Cook University. Internal Audit Protocol

Glasgow Caledonian University

Transcription:

Management Policy and Framework Version: 9 Produced by: University Manager with the assistance of the Operational Group Date Produced: 11 th March 2010 Approved by: Steering Group (14 December 2010) Updated: 5 July 2010, 14 December 2010, 19 May 2011, 5 April 2012, 21 September 2012, 3 January 2013, 30 January 2014, 17 March 2015, 29 January 2016 This document consists of Policy Statement: outlining the approach of the University to Management (BCM) Operational Framework: explaining the management of the University s BCM Programme and the roles and responsibilities of those involved in the delivery of the programme The Operational Group will review the Policy and Framework on an annual basis; it will also be reviewed when significant changes occur within the University. The Business Continuity Steering Group is responsible for formally approving this document and it will be re- issued when revisions are made. This document is intended for to all staff at the University. Page Introduction 2 Policy Statement 3 Operational Framework 4 Roles and Responsibilities 4 Links to Other Areas 7 Reporting Structure 8

Introduction Management (BCM) is a process that enables the University of Sheffield to proactively identify and plan to minimise the impact of risks that could affect its objectives, operations and infrastructure. BCM provides the capability for the University to ensure continuity of teaching and research, together with support for its students, staff, departments and faculties following any disruptive event. Whilst the University does not have a specific statutory duty to undertake BCM, it is a business imperative; also the University has legal and moral responsibilities for staff, students and visitors and recognises the importance of this process in ensuring it can continue its urgent activities after a disruption and to protect its reputation as a leading university in the UK. The process starts with Incident Management for which the University also has a Major Incident Plan - as illustrated below 1 : INCIDENT'MANAGEMENT'' Immediate;'focuses'on'the'priorities' 'welfare'of'people,'damage' assessment'/'limitation'e.g.'structural'damage' BUSINESS'CONTINUITY' INCIDENT' After'immediate'response' 'focuses'on'restoring'urgent' activities'affected'by'the'incident RECOVERY'' Damage'repair/replacement,'relocation,'recovery' of'insurance'costs'etc' The University of Sheffield has defined two types of incident: 1. Minor incidents are interruptions / disruptions that are sufficiently disruptive to require the implementation of business continuity arrangements. They can be addressed by a departmental response - using business continuity plans. They are smaller scale events, affecting one or a small number of departments e.g. a localised computer virus, a minor power cut for a short period etc. However sometimes minor incidents can become major incidents. 2. Major incidents require the implementation of the University s Major Incident Plan, when they meet the plan s criteria of causing serious harm to staff, students, the University community, property or its reputation. This plan is focused on larger scale events e.g. a national emergency, a power cut affecting the campus etc. Using the power cut example, the Major Incident Team (MIT) would focus on the immediate priorities i.e. the welfare of people and the safety / security of buildings. In addition, a business continuity response would be required in terms of how the University would continue its urgent activities those that need to be recovered first - and the Major Incident Team may require sub group/s to deal with specific issues. TIME' 1 This diagram is intended to show the considerations after an incident - the timescales may change and in reality there may be overlap between phases e.g. the business continuity stage could start earlier. 2

Policy Statement Aim and Objectives Management is concerned with improving the resilience of the University of Sheffield.. This means developing its ability to detect, prevent, minimise and where necessary deal with the impact of disruptive events or incidents. In the aftermath of an incident business continuity enables the urgent or priority activities of the University to continue; in the longer term it will help the University to recover and return to business as usual as soon as possible. The University of Sheffield aims to develop, implement and resource a BCM Programme that will enable it to respond to and manage any disruptions that occur. The Management Programme has the following key objectives: To raise the profile of BCM within the University of Sheffield. This will include arrangements to make staff aware of plans, their roles in them and are trained appropriately To identify urgent or priority (time critical) activities across the University and develop suitable business continuity arrangements for them To establish defined structures to plan for and respond to incidents To have on- going BCM arrangements that are subject to regular reviews, audits and exercises To develop and review the Programme for continuous improvement, with reference to best practice, such as the Institute s Good Practice Guidelines and ISO22301 2 To embed into the culture of the University so it becomes an integral part of decision making Scope It has been agreed that the scope of the Management Programme will operate across the Institution, covering the five Faculties, all departments within them and Professional Services based in Sheffield. CiCS will remain responsible for specific Disaster Recovery arrangements relating to the recovery of IT servers/applications that they operate. The University of Sheffield works with a number of partner institutions to deliver its services and a risk- based approach will be adopted in terms of the University s expectations on these organisations, focusing on those for which the University has primary responsibility for the building and would be considered the greatest risk. The BCM Programme is focused on protecting and recovering the priority activities of the University and links to the aim of the University outlined in its vision and guiding principles of being one of the best universities in the world. This means being able to deliver its teaching, research and supporting the student experience. A priority activity is identified based on how quickly it needs to be resumed and the impact if it is not available on the safety of people, on the reputation of the University, its finances and customers. Initially the focus of the programme is on the first week after an incident. 2 ISO22301:2012: Societal Security, Business continuity management systems - Requirements 3

Operational Framework Management of the Management Programme The Programme will follow the Lifecycle set out in ISO22301 and will align 3 itself as considered appropriate with the requirements of the Standard Whilst Faculties may oversee planning, it is expected that all University departments will go through the process. This will involve identifying their priority activities, the resources required and appropriate arrangements in the event of a disruption The Programme will be co- ordinated by the University Manager, however individual departments will be expected to nominate appropriate people to co- ordinate the development of their department s arrangements All documentation will be reviewed as a minimum on an annual basis, and will also be updated when there are significant changes to personnel, premises, suppliers etc Documentation should be stored in the incident contacts system, which would be available if the incident was affecting the provision of IT on campus Exercises of Plans will be held on an annual basis Training and awareness will be an on- going part of the Management Programme Roles and Responsibilities University Manager The University Manager is responsible for co- ordinating the Programme on behalf of the University. This involves: Raising the profile of across the University as an on- going responsibility and ensuring that information is available to staff (with the aim of embedding BCM into the activities of the University) Providing advice and assistance throughout the BCM process Developing appropriate templates for the University to detail its arrangements, ensuring consistency in the Programme with flexibility to recognise the differences across faculties and departments Supporting departments in completing the documentation from a Business Impact Analysis (BIA) to developing a Plan (BCP) Assisting in the development of overarching arrangements to support departmental plans Ensuring that the University s arrangements are regularly reviewed and exercised Providing training to appropriate staff and leading on the development of corporate exercises to review arrangements that have been put in place Monitoring the level of planning in the institution and reporting to the groups on this 3 Alignment to the standard has not been officially defined, but the University of Sheffield has interpreted it as following the principles of the standard and adopting practices that fit with the approach of the institution 4

Reviewing the Programme to ensure it remains fit for purpose and to continuously improve the arrangements in place Lead The Chief Financial Officer is the lead for across the University. This involves: Being the champion in terms of business continuity at strategic level by endorsing and supporting the Management Programme Assisting with raising the profile of at a strategic level Chairing the Steering Group Reporting on the BCM Programme and the state of readiness to University Executive Board Steering Group (BCSG) As the senior decision making group, the Steering Group is responsible for: Supporting and endorsing the BCM Programme and awareness raising regarding Business Continuity with the aim of embedding it into the culture of the University Ensuring there is a consistent approach to across the University, in accordance with the Programme Supporting the continuous improvement of the Programme Approving recommendations from and allocating actions to the Operational Group as appropriate Ensuring that a risk assessment approach is taken in the development of arrangements Operational Group (BCOG) The Operational Group is the tactical group and will be responsible for: Making recommendations to the Steering Group regarding the BCM Programme and taking forward actions on its behalf Assisting with the review and development of the Management Programme and support continuous improvement of the Programme including o Updating this Policy as appropriate o Receiving status reports on and identifying any actions o Identifying cross cutting issues and co- ordinating planning including prioritising actions from BCSG, incidents, exercises etc. Supporting the Manager in raising the profile of by ensuring that the departments in Faculties and Professional Services are engaged Supporting the exercising of plans to ensure that they remain up to date and fit for purpose Ensuring there is a consistent approach to across the University, in accordance with the BCM Programme Leading on the development of the University s Incident Management planning arrangements including the review and development of the Major Incident Plan, reporting 5

on the arrangements in place and ensuring the plan is exercised on an annual basis (unless a major incident occurs that has tested arrangements in the plan) Acting as Representatives for the department/faculty that they represent (their responsibilities are outlined below) Representatives (Faculty/Professional Services department level) The role of the Representative is to assist the University Manager in championing BCM by: Acting as a single point of contact within the Faculty / department for issues Being able to explain how it works, the benefits of undertaking it and ensuring that the faculty / department is engaged with the process Acting as a conduit for any queries / issues raised Providing feedback on progress either directly at BCOG (if a member), through the BCOG member for the department / Faculty or via the Manager Co- ordinators (Department level) The Co- ordinators are the people nominated to lead on for a specific department. They also require a deputy. It is expected that this will be the Head of Department (or appropriate deputy.) This will include: Staff Attending relevant training and awareness sessions to develop knowledge and understanding of Management Completing the required documentation, with assistance/involvement from other members of the department Ensuring documentation remains fit for purpose and up to date Attending corporately run exercises and participate/lead in the running of exercises for the individual department as appropriate Attending, participating and sometimes leading debriefs and other events as required to review and test the plan In some instances the Co- ordinator will also be the Representative It is important that everyone at the University is aware of the BCM Programme. Staff should be aware of any arrangements in their department s plan that may affect them e.g. how they will be contacted / notified of an incident, where they should report to if they are not able to access their usual place of work etc. There is a pocket size guide to incidents card available for all staff, together with information on the website. 6

Links to Other Areas Risk Management Management and Risk Management work closely together, as both are concerned with good governance and raising awareness about risks. However the focus of the two areas is different; Management is only concerned with managing those risks or what might be termed as threats or vulnerabilities that could cause a disruption to the University s operations, whereas Risk Management has a wider remit. A threat register is produced for Risk Review Group twice annually to identify the current vulnerabilities affecting the University. BCM may be used as a treatment of some risks identified in risk registers and is noted on the University s Corporate Risk Register. When developing business continuity arrangements, priority should be given to treating threats or vulnerabilities identified as being most likely and having the greatest impact. Internal Audit As part of the review and monitoring of the Programme, in addition to the reviews undertaken by the University Manager, Internal Audit has an important role in ensuring that the Management Programme achieves its objectives as set out in this document. Information Security Information security covers the protection of all forms of information and is concerned with ensuring its confidentiality, availability and integrity. A key part of the process focuses on protecting against a potential loss of resources, including essential information, thereby ensuring it is stored appropriately and remains available after a disruption. Information Security should be considered when developing alternative arrangements to store/access key information. The loss of University information either by a loss of access to it or by someone else being able to access it - could have serious implications and dependent on the severity, would be classed as an incident at department level and also potentially for the University. 7

Reporting Structure Lead - Chair Steering Group Member Risk Management Approve recommendations and set actions to be delivered Chair of BCOG attends BCSG Suggest recommendations and deliver actions Share information and make recommendations Act as representative for Faculty/department (all BC Co- ordinators) and provide updates Operational Group Representatives BC Reps attend BCOG The University Business Continuity Manager will have overall co- ordination of this process and will input into the different levels as required. The University Manager will attend Steering Group and Business Continuity Operational Group Share information and receive reports on progress Department level - Co- ordinate the development of bc arrangements within the department BC Co- ordinators report on progress to BC Representative Internal Audit will review this process when undertaking an audit of the BCM Programme Co- ordinators Sharing information with staff Be aware of what to do if an incident occurs and, as appropriate, assist with the completion of business continuity documentation Staff Feedback issues and updates 8