1 Business Continuity: The sixth international payment system conference MNB, Budapest 14 November, 2007.

Slides:



Advertisements
Similar presentations
Museum Presentation Intermuseum Conservation Association.
Advertisements

Business Continuity Training & Awareness by Sulia Toutai (ANZ)
BCM and Security ROGSI/DMS Präsentation ROGSI/DMS Suite for Corporate Survival ROGSI/Business Impact Analysis TOP 7 Best Practices for Business Continuity.
Reliability of the electrical service Business Continuity Management Business Impact Analysis (BIA) Critical ITC Services Minimum Business Continuity Objective.
Business Continuity and Disaster Recovery Planning.
CIOassist Technologies Your CIO on Demand… Business Continuity Planning Our Offering CIOassist Technologies (
Kpmg Business Continuity Planning An experience based approach Tamás Gaidosch Director, Information Risk Management KPMG Central and Eastern Europe +36.
© 2009 EMC Corporation. All rights reserved. Introduction to Business Continuity Module 3.1.
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP)
BCP/DRP Consultancy Project- An approach
Business Continuity Planning and Disaster Recovery Planning
Information System Economics IT PROJECT MANAGEMENT - revisited.
MSIS 110: Introduction to Computers; Instructor: S. Mathiyalakan1 Systems Design, Implementation, Maintenance, and Review Chapter 13.
TEL382 Greene Chapter /27/09 2 Outline What is a Disaster? Disaster Strikes Without Warning Understanding Roles and Responsibilities Preparing For.
Stephen S. Yau CSE , Fall Security Strategies.
Business Continuity and You! The Ohio State University Business & Finance Enterprise Continuity Program Quarterly Update October 2008Business and Finance.
Business Crisis and Continuity Management (BCCM) Class Session
Services Tailored Around You® Business Contingency Planning Overview July 2013.
November 2009 Network Disaster Recovery October 2014.
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
Unit Introduction and Overview
RBTC: Business Continuity 101 July 18, What is Business Continuity? Scenario Part 1 Why is BC important? What types of plans are needed? How do.
Making Business Continuity Child’s Play Solutions Ltd Business Continuity Management Contact details: Contact : Mick O’Regan Mobile :
Security Baseline. Definition A preliminary assessment of a newly implemented system Serves as a starting point to measure changes in configurations and.
A Major Business Disruption A Strategy for Minimising the Downtime Anthony Hegarty Mitigating Risks.
Unit 8:COOP Plan and Procedures  Explain purpose of a COOP plan  Propose an outline for a COOP plan  Identify procedures that can effectively support.
ISA 562 Internet Security Theory & Practice
NIST Special Publication Revision 1
Eric Holtel.  Introduction  Project Description  Demonstration  Deliverables  Conclusion.
2010 Virginia RIMS and PRIMA Conference October 5, 2010 Business Impact Analysis: The Road Map to Managing Risks.
Principles of Information Systems, Sixth Edition Systems Design, Implementation, Maintenance, and Review Chapter 13.
Business Continuity and Disaster Recovery Planning.
Perspectives on Business Continuity Management Bill Wheeler, EPO.
Business Continuity and Disaster Recovery Chapter 8 Part 1 Pages 897 to 914.
Business Continuity Management For Project Managers.
Principles of Information Systems, Sixth Edition Systems Design, Implementation, Maintenance, and Review Chapter 13.
Paul Hardiman and Rob Brown SMMT IF Planning and organising an audit.
Risk Management & Corporate Governance 1. What is Risk?  Risk arises from uncertainty; but all uncertainties do not carry risk.  Possibility of an unfavorable.
Phases of BCP The BCP process can be divided into the following life cycle phases: Creation of a business continuity and disaster recovery policy. Business.
2006 West Virginia GIS Forum. Objectives 1) Centralize all infrastructure responsibilities. 2) Select common (standard) hardware, software and service.
Business Continuity ALARM 04 CONFERENCE How to start a Business Continuity Plan by Bill Sulman and Jon Chesher Heath Lambert Group.
Principles of Information Systems, Sixth Edition 1 Systems Design, Implementation, Maintenance, and Review Chapter 13.
Key Terms Business Continuity Plan (BCP) – A comprehensive written plan to maintain or resume business in the event of a disruption Critical Process –
SOLUTION What kind of plan do we need? How will we know if the work is on track to be done? How quickly can we get this done? How long will this work take.
9 juni 2009 Alex van Os de Man BCI Forum 2009 Business Impact Analysis Process.
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
 How well is your organisation prepared for internal or external emergency situations? ◦ Do you consult with relevant emergency agencies? ◦ Do you.
DRP Disaster Recovery Planning. Social Networking... It's the way the 21st century communicates today.
Chapter 3: Business Continuity Planning. Planning for Business Continuity Assess risks to business processes Minimize impact from disruptions Maintain.
Writing an Emergency Operations Plan Why do we need to plan? Spring 2008.
Business Continuity Disaster Planning
SueDon Ltd - Business Continuity Management BCM Overview ©1999 SueDon Ltd Business Continuity Management.
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
A Lightweight Business Continuity & Disaster Recovery Plan Motahareh Moravej Issuers’ Affairs Director at CSDI PHD. Student of Computer Engineering, UT.
Disaster Recovery Planning (DRP) DRP: The definition of business processes, their infrastructure supports and tolerances to interruptions, and formulation.
AUDITING BUSINESS CONTINUITY PROGRAMS AND PLANS What to Look For Presented by: Tommye White, CBCP, DRP Chuck Walts, CBCP, CRP.
Business Continuity Planning 101
Dr. Gerry Firmansyah CID Business Continuity and Disaster Recovery Planning for IT (W-I)
MANAGEMENT of INFORMATION SECURITY, Fifth Edition
Chris Lintern Co-operative Financial Services
BUSINESS CONTINUITY BY HUI ZHENG.
Security on the Move & In the Clouds
Berry College Disaster Recovery Soft Exit
Audit Planning Presentation - Disaster Recovery Plan
CompTIA Security+ Study Guide (SY0-501)
Business Contingency Planning
Regional Joint Conference on Alexandria, Egypt, April 2007
BUSINESS CONTINUITY PLAN
Developing and testing the Plan
BUSINESS CONTINUITY PLAN
Presentation transcript:

1 Business Continuity: The sixth international payment system conference MNB, Budapest 14 November, 2007

2 Business Continuity Management at the MNB Péter Rajczy Integrated Risk Management Magyar Nemzeti Bank the central bank of Hungary

3 Introduction Operational risks in the central bank Financial and reputational losses Impact on the financial system of the country Risk management: Avoiding risk events / mitigating impacts Business Continuity Management: a special tool to manage certain types of risks (system disruption, external events etc.

4 Questions to discuss: 1. A Historical Outline: BCM in the MNB 2. Concept and Foundation 3. Organisation and Responsibilities 4. Maintenance of BCP/DRP database 5. BCP in the minds and in the practice 6. BCP at the Splitsite – the Immediate Backup Centre 7. The Key Personnel Project 8. Logistics Centre: Planning the Future

5 1.A historical outline: BCM in the MNB 2002: KPMG. Interviews, presentation and first steps: building up the bankwide system of BCM 2003: BCP data maintenance and testing: the great supply disruption test 2004: Overall revision of BCP/DRP data –business activities & resources, interdependencies, BIA – BCP’s – tests 2005: First split site testing, training of local BCP officers : Running a robust BCM; key persons 2008: BCP in the new split site: the Logistic Centre

6 2. Concept and Foundation BCM as a part of the integrated ORM Initial database and BIA: setting up the boundary conditions – what is the Worst Case Scenario (system downtime, missing key persons, buildings) Data acquisition and integrity The role of the Crisis Management Committee

7 3. Organisation and Responsibilities Starting with top-down sponsorship –maintaining data integrity, management of testing Department-based planning: bottom-up. Responsibility of the local BCP officers Crisis management: –Crisis Management Commitee (CMC): decision about relocating business to split site –Local Crisis Group (LCG) leader: activating single BCP’s

8 4. Maintenance of the BCP/DRP Database: the ÜFO a relational database to store basic parameters for business activities, IT resources etc. maintenance: Central BCP Manager data input: Local BCP Officers storing documents report queries BCP/DRP print-outs test print-outs

9 4. Maintenance of the BCP/DRP database: the ÜFO (continued)

10 4. Maintenance of the BCP/DRP database (continued 2) Structure of the database: –basic tables (organisation, personnel, formulas etc) –business activities (data, priorities, impact scaling etc) –resources (IT, Human, External, Others) –dependency scales –action plans (BCP, DRP) –documents of certification (tests)

11 4. Maintenance of the BCP/DRP database (continued 3) Functions of the database: –updating data Central BCP Administration: basic tables local BCP Officers: BCP/DRP action plans central BCP Officers: coordination –business impact analysis (BIA) –data management reports: BCP/DRP sheets, activity/risk matrices other queries, look-ups activity logging, integrity checks

12 4. Maintenance of the BCP/DRP database (continued 4) Business Impact Analysis –rating business activities by: priority targeted recovery time (TRT) dependency scale from resources –rating resources by operational reliability (downrisk) maximal tolerated downtime (MTD) –output: a list of recommended BCP’s

13 4. Maintenance of the BCP/DRP database (continued 4) Business Continuity & Disaster Recovery Plans –Basic data –Preparation phase –Response phase –Alternative working process –Phase of recovery –Phase of making checks

14 4. Maintenance of the BCP/DRP Database (continued 5) Testing a BCP –responsibility of the Local Crisis Group –depth of the tests: desktop check test in a simulated environment live test –scope of the test elementary: including one department integrated: with cooperation of several departments –surveillance of test status (Central BC P Manager)

15 5. BCP in the minds and in the practice BCP: Is it a burden for everybody? „Personal plans” vs bankwide BCP/DRP framework: to be better prepared for the unexpected transparency of the network of responsibilities Side-effects: –lessons we learned during tests –realizing the need of controlled data update Risks of data integrity disruption

16 6. BCP and the Splitsite – the Immediate Backup Centre Broadening the boundary conditions: business continuity in case of major IT disruptions or physical shocks Remote site access in case of crisis –operating the communication in crisis situation (telephone cascade) –preparation of the Crisis Management Committee’s decisions –transport supply –error detection and helpdesk service at the remote site

17 6. BCP and the Splitsite (continued) Crisis Managing Committee (CMC) Taking decisions about: –Starting work at an alternative site –Giving instructions to deviate from a BCP Efficiency of the informatical background - „warming up” Doing business in an unusual environment (training rutines)

18 7. The Key Personnel Project Demonstrations, strike of transport workers, some food health cases Avian flu issues 2007: need to expand BCP boundary conditions to loss of key personnel Definition of Key Local Crisis Group: responsibility of the LCG leader Central administration in the ÜFO

19 8. The Logistics Centre: Planning The Future Plans to dislocate key functions wich demand high security and availability (e.g. cash transport, note processing) Dislocating secondary (hot) site for data storing Establishing secondary IT (hot) site serving critical business processes Secondary site for continuing critical business processes in case of major disruption (Business Continuity Plan for missing site)