Business Continuity Planning. LGMA Conference October 27, 2011 Presented by Lisa Benini

Similar documents
Building a Standard for Business Continuity Planning

Introducing ISO 22301

Business Continuity Framework

Security Guideline for the Electricity Sector: Business Processes and Operations Continuity

Business Continuity. Building a Program Fit for Purpose

Standards, Standards and more Standards Are you confused? And really which one should my organiza:on follow?

12.0 Business Continuity Management

Business Continuity & Disaster Recovery

Business Continuity Management Policy. Guidance

Protecting Information Assets - Week 9 - Business Continuity and Disaster Recovery Planning. MIS 5206 Protecting Information Assets

Navigating the Intersection of Vendor Management and Business Continuity

Business Continuity Planning and Disaster Recovery Planning

Business Continuity & IT Disaster Recovery

Citizens Property Insurance Corporation Business Continuity Framework

US Business Continuity Safeguarding Your Business from a Disaster

Business Continuity/ Disaster Recovery. Sean Gunasekera

Business Continuity Planning: As A Business Owner, What Do I Need to Consider? David Sutton Manager, Environment, Safety and Health.

Disaster Preparedness & Your Supply Chain

Business Continuity Guide 2017

BCP Methodology Benefits realisation

BUSINESS CONTINUITY PLANNING WORKPROGRAM

2016 Business Continuity / Disaster Recovery Internal Audit Report

Disaster Preparedness & Your Supply Chain

The Sector Skills Council for the Financial Services Industry. National Occupational Standards. Risk Management for the Financial Sector

ISO Business Continuity Management. Your implementation guide

Coastal Equities, Inc.

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM)

Head of Security and Business Continuity

Global Crises: What We Really Need to Do to Be Prepared. Day One / Session C5

Strategic Business Continuity Management

Minimizing Risk and Ensuring Continuity of Operations with Help from Symantec Consulting Services Business Continuity Management Practice

An introduction to business continuity planning

Tier I assesses an institution's process for identifying and managing risks. Tier II provides additional verification where risk is eviden

December 2015 THE STATUS OF GOVERNMENT S GENERAL COMPUTING CONTROLS:

Yale University Business Continuity Planning Quick Start Guide

NOT PROTECTIVELY MARKED BUSINESS CONTINUITY. Head of Protective Services Specialist Operations. Business Continuity Manager

The Six Stages of a Crisis. Stage Five: Resolution

EMERGENCY MANAGEMENT BC OVERVIEW. Provincial Emergency Program

ShakeOut Drill Scripts For Businesses and Organizations

Essential Concepts. For Effective. Business Continuity Planning

Fordham University BCP / DRP Lunch. Lunch

Building and Maintaining a Business Continuity Program

(ISC)2 CISSP EXAM BUNDLE

Workplace Violence. Workplace Violence. Work Safe: Preventing Injuries and Workplace Violence. Gene R. La Suer Davis Brown Law Firm

PUBLIC SAFETY California State University Los Angeles

How Your Business Survival Depends On Disaster Recovery.

Business Continuity Policy. Interim Governance Consultant. October Greenwich Executive Group

Business Resilience They Cannot Do This Without You!

Good Practice Guidelines 2013 Global Edition Edited Highlights

CLICNET TELECOMMUNICATIONS INC. Business Continuity Plan

JCU Business Continuity Management Plan

Business Continuity & Risk Management

CONTINUITY OF OPERATIONS PLANNING FOR PUBLIC HEALTH ENTITIES

How Does Business Continuity Differ from Emergency Preparedness?

Evaluating Your Business Continuity Plan: Beyond Checklists and Walkthroughs. Troy Harris, Director McGladrey LLP. All Rights Reserved.

Information Technology Division Service Level Agreement (SLA) Description and Process

Incident Command, Control and Communications. During Catastrophic Events

GOVERNMENT EMERGENCY MANAGEMENT REGULATION

5 Steps to Implementing Business Continuity Services. By David Davis, vexpert. Brought to you by Symantec Keeping Your Applications Running

Business Continuity and Natural Disaster Resilience: Where Are We Heading? Adopting best practices for weather safety based on new science

BUSINESS CONTINUITY MANAGEMENT POLICY

GUIDE TO BUSINESS CONTINUITY MANAGEMENT

White Paper: ITSC Planning: Performing Business Impact Analysis

Guide to Business Continuity and Recovery Planning

Business Resilience: Equipping the FM for Success

CONTINUITY OF OPERATIONS (COOP) WORKSHEETS

NATURAL DISASTERS AND THE WORKPLACE

WIC 104 RISK MANAGEMENT AND BUSINESS CONTINUITY PLANNING FOR LOCAL WIC AGENCIES. Peg Jackson, DPA, CPCU National WIC Association

10 REASONS WHY YOU SHOULD INVEST IN RESILIENCY

Guide to Business Continuity and Recovery Planning

Risk Advisory Services Developing your organisation s governance for competitive advantage

My name is Sam Mulholland and I am the Managing Director of Standby Consulting.

University of Houston Business Continuity Planning Office of Emergency Management

Solution Track 5. Managing Vendor Risk and Contingency Plans. March 26, Strategic BCP, Inc. All rights reserved. strategicbcp.

Effective Business Continuity Management Guidelines for Mobile Network Operators

Relax and eat your breakfast. Thanks for coming to listen to me today, before we are done you will wish it was Friday.

Disaster Preparedness. Solutions for Response & Resiliency

ISO 28002: RESILIENCE IN THE SUPPLY CHAIN: REQUIREMENTS WITH GUIDANCE FOR USE

Moving from BS to ISO The new international standard for business continuity management systems

Diversified Services. Our Diversified Services include:

INSIDE. 2 Introduction 12 Conclusion 4 6. How Prepared Are Corporate Law Departments?

Presentation on Crisis Management and Business Continuity. ISCA Breakfast Talk 13 September See Hong Pek, Partner, PwC

Continuity of business and operations of MSMES vis-à-vis disaster scenarios. Theoretical Module. Economic and Technical Cooperation

Business Continuity Management for Singapore s Logistics Sector. By Singapore Business Federation and Singapore Logistics Association

Business Loans Network Limited ("ThinCats", the Firm ) Business Continuity Policy ( BCP ) v.2

Community Resilience Enhancement Intervention Handouts

Leading financial institutions are transforming the way they manage IT risk

BP3: Decomposing the Crisis/ Incident Management Timeline

DERDACK White Paper Business continuity and the role of communication

Emergency Management, Business Continuity, & Crisis Management Self-Assessment Checklist

Guidelines for continuity of business and operations of MSMES vis-à-vis disaster scenarios

Disaster Recovery Planning

Module 3 Assessing Climate Change Risk

DeVry Approach to ERM

Point of view Digital Business Resilience in Financial Services

Preparing for Disaster

IBM Smarter Cities Public Safety Emergency Management

WHO Guidance for business continuity planning World Health Organization

ENTERPRISE RISK SERVICES Managing Risk, Driving Results

Essential Records Webinar

Transcription:

Business Continuity Planning LGMA Conference October 27, 2011 Presented by Lisa Benini

What is it? Business Continuity Planning Definition: Process of developing and documenting advance arrangements and procedures that enable an organization to respond to an event that lasts for an unacceptable period of time and return to performing its critical functions after an interruption. source: www.drj.com SAFETY / EMERGENCY PREPAREDNESS SECURITY CONSEQUENCE MANAGEMENT ENTERPRISE RISK MANAGEMENT EMERGENCY RESPONSE BUSINESS CONTINUITY CRISIS COMMUNICATIONS INFORMATION TECHNOLOGY RECOVERY CRITICAL INFRASTRUCTURE RECOVERY October 27, 2011 Benini Consulting Ltd. 2

Why Are We Concerned? Disasters increasing in frequency and severity How many internal disasters go unreported? Indirect impacts from Catastrophic Disasters Kelowna Fire October 27, 2011 Benini Consulting Ltd. 3

Why Are We Concerned? Aging infrastructure Emerging new risks (e.g. Pandemic) Highly dependent on Communications & Technology Government October 27, 2011 Benini Consulting Ltd. 4

Hazards in BC www.pep.bc.ca Earthquakes Floods Tsunami Severe Weather Fires Avian Influenza 5

Why is it important? Expectations of key stakeholders Essential management function Becoming a common practice Some organizations have set policy for it Makes good business sense Sustainability & Survivability October 27, 2011 Benini Consulting Ltd. 6

What is it? Who executes the plan s actions? Employees Management People are your most important asset Business Partners / Key Stakeholders October 27, 2011 Benini Consulting Ltd. 7

What is it? Where will your people go to resume operations? Work from a Hotel / Boardroom Work from Home Alternate Site Another Civic Facility October 27, 2011 Benini Consulting Ltd. 8

What is it? When will your operations resumed? October 27, 2011 Benini Consulting Ltd. 9

What is it? What do you need to resume operations? Printers Copiers Workspace Computers Computer Center Telephones Office Furniture Paper Records Assets October 27, 2011 Benini Consulting Ltd. 10

How will this be done? April 30, 2008 Benini Consulting Ltd. 11

10 Step Process 1 Project Initiation and Management 2 Risk Evaluation and Control 3 Business Impact Analysis 4 Develop Business Continuity Strategies 5 Emergency Response and Operations 6 Develop/Implement BCPs 7 Awareness and Training Programs 8 Exercise and Maintain BCPs 9 Crisis Communications 10 Coordination with External Agencies April 30, 2008 Benini Consulting Ltd. 12

1. Project Initiation / Control Everyone needs a Plan You need Senior Mgmt Buy-in You need a Policy, Objectives & Scope You should manage it as a project & give it some dollars You need people to do the work You need Management to Approve it April 30, 2008 Benini Consulting Ltd. 13

2. Risk Evaluation/Control Anything done to date? What are your threats? What is likelihood & consequences? What is an acceptable levels of risk? Are you addressing high risks? What controls are in place? What else can you do reduce the impact? You need Management to Approve it April 30, 2008 Benini Consulting Ltd. 14

3. Business Impact Analysis What are your critical functions? Identify Business Functions Determine Maximum Allowable Outage Determine Impact (Qualitative/Quantitative) Identify Dependencies & Resources Define Recovery Objectives & Time Sensitivities Determine Alternates Procedures / Arrangements How do you do a BIA? Create Prioritization of critical functions You need Management to Approve it April 30, 2008 Benini Consulting Ltd. 15

4. Develop Strategies What can I do to mitigate the high risks? What can I do when a business disruption occurs to continue my critical business? What is the advantages & disadvantages? What will these options cost? Which are the most feasible options? Can I consolidate these options? April 30, 2008 Benini Consulting Ltd. 16

4. Develop BC Strategies Need to consider: Key Personnel Place to Work Means of Communicating Computers/Data Networks Supplies Key Records, Information, Data Resource Availability Timeframe Capability to Recover April 30, 2008 Benini Consulting Ltd. 17

5. Emergency Response / Operations Everyone needs to know what to do in an emergency & what is their role? How will you escalate? Who will you call? Who is authorized to activate the plan? How will you manage the incident Try to reduce damage and secure the site Integrate emergency response with business continuity organization & activities April 30, 2008 Benini Consulting Ltd. 18

6. Develop Business Continuity Plan Alternate Facilities & Resources Timing Escalation Call Lists Actions Recovery Inventories Organization Administration Maintenance & Exercising 1. 2. 3. 4. Priorities Responsibilities April 30, 2008 Benini Consulting Ltd. 19

7. Awareness and Training Start early with awareness Everyone needs to know about the plan and what is your expectations Train your continuity teams before you exercise Make sure it happens Continue to Monitor it April 30, 2008 Benini Consulting Ltd. 20

8. Exercise and Maintain BCPs Make sure the plan works and the people know what to do Identifies strengths & weaknesses Document lessons learned Make sure they are assigned and followed up Keep exercising your plan April 30, 2008 Benini Consulting Ltd. 21

8. Exercise and Maintain BCPs When changes occurs, update your plan: Acquire new business line Reorganize your service offerings Implement a new computer system Changes in staff / stakeholders New risks emerge Check your control programs Continuously update your plan Let Management know how you are doing April 30, 2008 Benini Consulting Ltd. 22

9. Crisis Communications Do you have Media Relations Procedures? Who will liaise with other Agencies? Who are your major Stakeholders and who will liaise with them? What and How will you communicate? Who is responsible? Make sure you exercise the communication process April 30, 2008 Benini Consulting Ltd. 23

10. Coordination with Public Authorities Which other Public Authorities do you deal with? Make contact with them How will you coordinate with them in an event? What are the procedures for dealing with them? Invite them to an exercise or ask to participate in their exercise April 30, 2008 Benini Consulting Ltd. 24

What will it achieve? Protects People, Property, Assets and Information Identifies tolerable outage Minimizes confusion and chaos Enables effective decision making Minimizes loss of data, revenue, clients Allows pre-positioning critical resources and arrangements October 27, 2011 Benini Consulting Ltd. 25

What will it achieve? Reduces dependency on specific personnel Coordinate with inter-dependencies Facilitates timely recovery of business functions Meet regulatory requirements Maintains public image and reputation October 27, 2011 Benini Consulting Ltd. 26

Final Thought "The unfortunate truth is our ability to imagine and plan for catastrophic disasters is woefully inadequate. 1 A broad assessment from Dr. Irwin E. Redlener, the director of the National Center for Disaster Preparedness at Columbia University 1. Business Week, 9/19/05, p. 35 June 8, 2010 Benini Consulting Ltd. 27

Q & A Thank you Lisa Benini Benini Consulting Ltd. Ltbenini@shaw.ca 250.813.2435