Fundamentals of a Business Impact Analysis

Slides:



Advertisements
Similar presentations
Directions for this Template  Use the Slide Master to make universal changes to the presentation, including inserting your organization’s logo –“View”
Advertisements

Oregon Department of Education Business Continuity / Disaster Recovery Program Implementation Mark Tyler Nigel Crowhurst.
1 The process of analyzing all core business functions and establishing an optimized timetable for recovery. Provides baseline for:  Justification for.
1 Disaster Recovery “Protecting City Data” Ron Bergman First Deputy Commissioner Gregory Neuhaus Assistant Commissioner THE CITY OF NEW YORK.
Systems Analysis and Design in a Changing World, Fourth Edition
Chapter 4: Beginning the Analysis: Investigating System Requirements
Gulf Coast Energy International Business Continuity / Disaster Recovery Planning and Design Proposal Prepared by Andrew Rolf, Felipe Torres, Pranay Jaiswal.
Business Continuation Plan / Program Overview State CIO Council Meeting June 24, 2008.
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
Chapter 4: Beginning the Analysis: Investigating System Requirements
Unit Introduction and Overview
Continuity of Operations Planning COOP Overview for Leadership (Date)
Business Continuity Planning Completing a Business Impact Assessment Pamela Hill Managing Director Hyperion Global Partners Judi Flournoy CIO Loeb & Loeb.
Do it pro bono. Strategic Scorecard Service Grant The Strategy Management Practice is presented by Wells Fargo. The design of the Strategic Scorecard Service.
David N. Wozei Systems Administrator, IT Auditor.
Module N° 8 – SSP implementation plan. SSP – A structured approach Module 2 Basic safety management concepts Module 2 Basic safety management concepts.
SacProNet An Overview of Project Management Techniques.
Project Life Cycle.
DRP World Class Operations - Impact Workshop Info-Tech Research Group, Inc. Is a global leader in providing IT research and advice. Info-Tech’s products.
Job Analysis - Competency Modeling MANA 5322 Dr. Jeanne Michalski
This course, Essential Records Seminar, is part of
Key Terms Business Continuity Plan (BCP) – A comprehensive written plan to maintain or resume business in the event of a disruption Critical Process –
Project Organization Chart Roles & Responsibilities Matrix Add Project Name.
Chapter 3: Business Continuity Planning. Planning for Business Continuity Assess risks to business processes Minimize impact from disruptions Maintain.
Introduction to ITIL and ITIS. CONFIDENTIAL Agenda ITIL Introduction  What is ITIL?  ITIL History  ITIL Phases  ITIL Certification Introduction to.
Business Continuity Disaster Planning
Leadership Guide for Strategic Information Management Leadership Guide for Strategic Information Management for State DOTs NCHRP Project Information.
Plan for Application Consolidation. Successful application consolidation relies on assessment of the application portfolio to determine the best candidates.
Presented by: Carmen D’Agostino and Dan Gutwein CPOD “If you don’t set goals, you can’t regret not reaching them.” Yogi Berra.
Business Continuity Planning 101
Info-Tech Research Group1 1 Info-Tech Research Group, Inc. is a global leader in providing IT research and advice. Info-Tech’s products and services combine.
ITIL® Core Concepts “Foundations to the Framework” Thatcher Deane 02/12/2010.
MANAGEMENT of INFORMATION SECURITY, Fifth Edition.
Overview MRD Enterprise MRD Process
4 Chapter 4: Beginning the Analysis: Investigating System Requirements Systems Analysis and Design in a Changing World, 3 rd Edition.
THINK DIFFERENT. THINK SUCCESS.
Sample Fit-Gap Kick-off
Utilizing Your Business Continuity Plan.
The case for a disaster recovery strategy for component XYZ
CPA Gilberto Rivera, VP Compliance and Operational Risk
BANKING INFORMATION SYSTEMS
Business Continuity / Recovery
Identify the Risk of Not Doing BA
CHAPTER11 Project Risk Management
Implementation Strategy July 2002
Develop and Document a Disaster Recovery Plan for the Small Enterprise
Overview – Guide to Developing Safety Improvement Plan
TSMO Program Plan Development
How does a Requirements Package Vary from Project to Project?
Mission Essential Functions Identification and Prioritization
“The Link” - Continuity of Operations and Emergency Management
Continuity of Operations 101
Overview – Guide to Developing Safety Improvement Plan
Getting Started with Your Malnutrition Quality Improvement Project
Project Organization Chart Roles & Responsibilities Matrix
Audit Planning Presentation - Disaster Recovery Plan
Establish Process Governance
Vendor Management and Software Asset Management
Mark Tyler Nigel Crowhurst
1915(i)& (k) Implementation Update
Business Impact Analysis
Continuity of Operations Planning
GRC - A Strategic Approach
Manage Business Continuity Introductory Brief
ISSUE MANAGEMENT PROCESS MONTH DAY, YEAR
Using State and Local Data to Improve Results
Facilitating Change (AET 560)
Establishing a Continuity of Operations Planning program
Central New York HEALTH EMERGENCY PREPAREDNESS COALITION
Conducting a Business Impact Analysis (BIA)
Presentation transcript:

May 2018 Fundamentals of a Business Impact Analysis

Welcome! Learn More Continuity Guidance Circular circular-cgc Continuity Resource Toolkit: toolkit 2 Presenter Michelle Neisen, CBCP Business Continuity Coordinator Texas Department of Health and Human Services President, Association of Continuity Professionals

Objectives  Identify purpose of a Business Impact Analysis (BIA)  Discuss development and delivery BIA processes  Provide a basic understanding of BIA findings 3

Definitions Continuity Of Operations (COOP)  Ensures an organization can continue to perform its essential functions, provide essential services, and deliver core capabilities during a disruption to normal operations. Mission Essential Functions (MEFs)  Essential functions directly related to accomplishing the organization’s mission and must be continued or resumed quickly after a disruption of normal activities. Essential Supporting Activities (ESAs)  Functions that support performance of MEFs, but do not reach the threshold of MEFs. 4

Definitions Disaster Recovery (DR)  A set of policies and procedures to enable the recovery or continuation of vital technology infrastructure and systems following any disaster, which focuses on IT/technology supporting critical business functions (i.e. MEFs). Business Impact Analysis (BIA)  Identifies and evaluates the consequences of failing to perform a critical business function and gathers information needed to develop recovery strategies. Recovery Time Objective (RTO)  The targeted duration of time within which a business function/process must be restored after a disaster (or disruption) to avoid unacceptable consequences if not continued. 5

Definitions Recovery Point Objective (RPO)  It is the maximum targeted period in which data might be lost from an Information Technology service due to a major incident. Concept – Recovery Time Objective looks forward and the Recovery Point Objective looks back. 6

Why a BIA?  Identify time sensitive or critical functions and the financial and operational impacts resulting from disruption of those functions  Gather information about resource requirements to support the time sensitive or critical business functions from each program  Set prioritized timeframes for resuming these functions; considering time which the impacts of not resuming them would become unacceptable 7

Why a BIA?  Business function requirements are compared to critical support application capabilities, resource availability and other factors which reveal gaps  Gap analyses and risk analyses are performed cross- functionally with leadership and staff  Enables Candidate MEF identification and prioritization for recommendation for review, validation and final prioritization by leadership 8

9 Now You See it Now You Don’t!

BIA Process Probably the longest-running and most critical among all continuity activities; iterative process Is an extensive data gathering and deep analysis across an entire organization 10

BIA Process Data Gathering Tools  Organizational charts  Interviews  Questionnaires  Data flow diagrams  BIA software 11

BIA Phases PHASE 1: INITIATION OF BIA  Secure Senior Leadership support and sponsor the BIA process  Define the BIA Goals and Objectives  Form a BIA Project Team 12

BIA Phases PHASE 2: DATA GATHERING  Develop a BIA Questionnaire for delivery to senior managers, team leaders, supervisors, subject matter experts and task performers with knowledge about the functions  Facilitate meetings with respondents to update and/or validate responses; invite executive leadership  Begin to develop a draft BIA Report with the information collected 13

BIA Phases PHASE 2: QUESTIONNAIRE DESIGN  Develop in a software tool for managed distribution and monitored completion  Design an Excel or Word document to collect responses  Questions drive responses to meet objectives and goals 14

PHASE 3: ANALYSIS OF INFORMATION  Review and analysis can be completed through a computer or manually, whichever is available while also practical and reliable  Identify functions with shorter RTOs and most severe impact(s) to begin a prioritized list (MEFs – Tier Levels)  Identify required human and technology resources to maintain optimal level of operations (ESAs)  Review expected RTOs and adjust responses where needed 15 BIA Phases

PHASE 4: DOCUMENTATION OF FINDINGS  Develop a BIA Report for presentation to executive leadership  There are no rules or standards, recommendations of items to include: o Executive Summary o Explanation of Purpose and Processes used o Analysis of the information collected and reviewed o Detailed findings with impacts, acceptable RTOs and recommendations for top tier MEFs 16 BIA Phases

MEF PRIORITIZATION INFLUENCES  Business Function RTOs  Support of Organizational Core Mission(s)  Regulatory Requirements  Management Preference  Impacts if Not Conducted 17 MEF Prioritization

Prioritize and group essential functions:  Tier 1 – Critical – Restore within 12 hours  Tier 2 – Vital – Restore within 24 hours  Tier 3 – Necessary – Restore within days  Tier 4 – Desirable – Restore within 10 days  Tier 5 – Low Priority – Restore as resources become available 18

Leadership Approval 19

Leadership Approval  Executive Summary  Mission Essential Function Data Sheet  Supporting Documentation 20

THANK YOU! If you would like more information about this presentation, please feel free to contact: Michelle Neisen at: 21