Copyright 2004 Turning Point Solutions Establishing Lines Of Communication Before a Crisis.

Slides:



Advertisements
Similar presentations
The Why, What and How of Disaster Recovery Plan Testing Presented By: Ed Deveau.
Advertisements

FMS. 2 Fires Terrorism Internal Sabotage Natural Disasters System Failures Power Outages Pandemic Influenza COOP/ Disaster Recovery/ Emergency Preparedness.
Business Continuity Training & Awareness by Sulia Toutai (ANZ)
Disaster Preparedness I Lessons Learned Don Hall Thomson Prometric 2006 Annual ConferenceAlexandria, Virginia Council on Licensure, Enforcement and Regulation.
Case Study: Business Continuity Planning for Site- Level Disaster Kimberley A. Pyles Northrop Grumman Corporation
Join the conference call by dialing the conference number in your Invitation or Reminder s. Please put your phone on mute. Please stand by! The webinar.
Records Emergency Planning and Response Webinar Session 2 Join the conference call by dialing the conference number in your Invitation or Reminder s.
© 2005, QEI Inc. all characteristics subject to change. For clarity purposes, some displays may be simulated. Any trademarks mentioned remain the exclusive.
Chapter © 2009 Pearson Education, Inc. Publishing as Prentice Hall.
OMB Circular A-123 – Management’s Responsibility for Internal Control Policy Applicability Sources of Information Assessment, Documentation and Reporting.
Spring 2008 Campus Emergency Management Program Overview
SOX and IT Audit Programs John R. Robles Thursday, May 31, Tel:
Managing the Information Technology Resource Jerry N. Luftman
Chapter 10 Information Systems Management. Agenda Information Systems Department Plan the Use of IT Manage Computing Infrastructure Manage Enterprise.
TEL382 Greene Chapter /27/09 2 Outline What is a Disaster? Disaster Strikes Without Warning Understanding Roles and Responsibilities Preparing For.
NIST framework vs TENACE Protect Function (Sestriere, Gennaio 2015)
Disaster Recovery and Business Continuity Ensuring Member Service in Times of Crisis.
Network security policy: best practices
Business Continuation Plan / Program Overview State CIO Council Meeting June 24, 2008.
Business Crisis and Continuity Management (BCCM) Class Session
Services Tailored Around You® Business Contingency Planning Overview July 2013.
Visa Olympic Experience Steve Vanhinsbergh March 2012 Presentation Title / 18 August,
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
National Public Health Performance Standards Local Assessment Instrument Essential Service:3 Inform, Educate, and Empower People about Health Issues.
Unit Introduction and Overview
Continuity of Operations Planning COOP Overview for Leadership (Date)
Security Baseline. Definition A preliminary assessment of a newly implemented system Serves as a starting point to measure changes in configurations and.
WORKING EFFECTIVELY IN AN INFORMATION TECHNOLOGY ENVIRONMENT
ISA 562 Internet Security Theory & Practice
Rich Archer Partner, Risk Advisory Services KPMG LLP Auditing Business Continuity Plans.
Roles and Responsibilities
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Technology Planning. Primary Elements Stakeholders Leadership team Needs assessment Technology components Work plan Budget Policies Evaluation.
December 14, 2011/Office of the NIH CIO Operational Analysis – What Does It Mean To The Project Manager? NIH Project Management Community of Excellence.
Certification and Accreditation CS Phase-1: Definition Atif Sultanuddin Raja Chawat Raja Chawat.
Business Continuity and Disaster Recovery Planning.
LeToia Crozier, Esq., CHC Vice President, Compliance & Regulatory Affairs Corey Wilson Director of Technical Services & Security Officer Interactive Think.
Developing Plans and Procedures
Ali Pabrai, CISSP, CSCS ecfirst, chairman & ceo Preparing for a HIPAA Security Audit.
1 Chapter Nine Conducting the IT Audit Lecture Outline Audit Standards IT Audit Life Cycle Four Main Types of IT Audits Using COBIT to Perform an Audit.
Business Continuity & Disaster Recovery Larry Corrigan-Tractor Supply Co Sarah Gunterman-Gunterman Consulting.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Unit 3: Identifying and Safeguarding Vital Records Unit Introduction and Overview Unit objective:  Describe the elements of an effective vital records.
Pro-active Security Measures
Local Government Business Continuity, Avian Flu & Emergency Management Roy Mentkow Director, Department of Technology City of Roanoke Virginia.
Managing Records: Good government, Better business. FOI Presentations to Boards & Committees Cayman Islands National Archive November 2008.
Office of Emergency Management University of Houston-Clear Lake Business Continuity Planning.
NEACS: CRO Perspective William Feher Vice President, Internal Audit and Chief Risk Officer October 27, 2015.
Key Terms Business Continuity Plan (BCP) – A comprehensive written plan to maintain or resume business in the event of a disruption Critical Process –
1 Managing Operations Operations - Essential 33% budget for programming 70% maintenance 30% new development 10% administration 57% operations.
Chapter 3: Business Continuity Planning. Planning for Business Continuity Assess risks to business processes Minimize impact from disruptions Maintain.
Business Continuity Disaster Planning
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
AUDITING BUSINESS CONTINUITY PROGRAMS AND PLANS What to Look For Presented by: Tommye White, CBCP, DRP Chuck Walts, CBCP, CRP.
Disaster Recovery Management By: Chris Rozic COSC 481.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Business Continuity Planning 101
Business Continuity Steven S. Keleman, CPM. Emergency Management Prevention Response Preparation Mitigation Recovery.
EECS David C. Chan1 Computer Security Management Session 1 How IT Affects Risks and Assurance.
Business Continuity Plan Training
Audit Plan Michelangelo Collura, Folake Stella Alabede, Felice Walden, Matthew Zimmerman.
Business Continuity Planning
Cybersecurity Special Public Meeting/Commission Workshop for Natural Gas Utilities September 27, 2018.
Continuity of Operations Planning
BUSINESS CONTINUITY PLAN
The Survival Plan.
Information Technology Organization Overview RFP #220-05
BUSINESS CONTINUITY PLAN
Presentation transcript:

Copyright 2004 Turning Point Solutions Establishing Lines Of Communication Before a Crisis

Copyright 2004 Turning Point Solutions Organizing & Developing The Plan Establishing Lines Of Communication Before a Crisis

Copyright 2004 Turning Point Solutions Who Owns BCP In Your Organization? 43% - Information Technology 33% - Corporate/General Management 8% - Risk Management 6% - Facilities Management 5% - Information Security 5% - Other CPM/KPMG Study % - Information Technology 22% - BCP Department 15% - Other 12% - Risk Management 7% - Security 5% - Financial Strohl Systems Survey May 2003 Statistics to Ponder

Copyright 2004 Turning Point Solutions What Is Executive Sponsor’s Title? 28% - Vice President 23% - Other 16% - CIO 14% - CEO/President 8% - Manager 8% - CFO Strohl Systems Survey May 2003 Statistics to Ponder Who Defines Recovery Strategies? 76% - Information Technology 5% - CEO 4% - Non-IT Management Veritas Study 2003

Copyright 2004 Turning Point Solutions  Make Planning Part of an Organization-Wide Program  Obtain support at the highest levels of the organization  Develop a Organization-Wide approach to recovery planning & strategies Organizing & Developing The Plan  Identify and Include External Support Teams In The Plan Organization (Municipal Agencies, Vendors, Suppliers, Tech Support Orgs)

Copyright 2004 Turning Point Solutions  Recovery requirements and strategies must include the business perspective Organizing & Developing The Plan Faculty & Administrative Units Business Impact Business Partners, Students & Families Work-In- Progress Transaction Processing Application & Desktop Requirements Functional Impact Data Center Processing Platform Requirements Data Storage Backup & Requirements Applications Requirements Data Communication s Requirements User Desktop Requirements Recovery Time Objectives, Requirements, & Priorities

Copyright 2004 Turning Point Solutions Where is Your Plan Kept? 62% - The company's main data center 20% - Company building away from data center 15% - Off-site at a third party's secure location 5% - Don’t Know Veritas Study 2003 Statistics to Ponder What Does the Plan Cover? 23% - Do not cover all essential data center functions. 20% - Include recovery of the desktop environment 15% - include IT recovery for remote offices Veritas Study 2003

Copyright 2004 Turning Point Solutions  Ensure that Facultative and Administrative Requirements are Identified and Communicated  IT Platform & Data Backup Requirements  Review Data Backup and offsite Storage frequencies  Establish Battleboxes and send them offsite  Meet with IT to work recovery objectives and Requirements  Special Requirements/Protection for Research Programs Organizing & Developing The Plan  Student Requirements

Copyright 2004 Turning Point Solutions Organizing Communications Establishing Lines Of Communication Before a Crisis

Copyright 2004 Turning Point Solutions How Many Employees are involved in Plan Development & Maintenance? 48% - Less than 10 29% % - More than % Strohl Systems Survey May 2003 Statistics to Ponder Is the Employees DR/BCP Plan Awareness & Training Program Sufficient? 75% - No 26% - Yes CPM/KPMG Study 2002

Copyright 2004 Turning Point Solutions What Is the Extent of Your organization’s reliance on 3 rd party service providers? 39% - Moderate Use 35% - Minor Use 20% - Significant Use 6% - No use CPM/KPMG Study 2002 Statistics to Ponder During Call Tree Tests only 60% of the primary people on call lists are successfully contacted Composite of Actual Test Results TPS

Copyright 2004 Turning Point Solutions  Develop an Effective Internal & External Emergency Management Organization Organizing Communications Executive Emergency Management Team (Include: SVPs, etc) Operations Emergency Management Team (Include: Facilities, Security, Key IT Support & Key Faculty & Admin Owners) External Recovery Support Teams Incident Response Team (IRT) (Include: Facilities, Security, Key IT Support & Municipal Authorities) IT Support Recovery Teams Faculty & Administrative Support Teams Students & Families

Copyright 2004 Turning Point Solutions  Identify the roles and requirements of all internal and external Groups involved  Identify 3 rd party vendors supporting applications software and other critical IT components  Conduct recovery walkthroughs and tests with 3 rd party support vendors  Include 3 rd party vendor contact information in the emergency contact section of the plan  Examine SLAs for emergency response provisions Organizing Communications

Copyright 2004 Turning Point Solutions  Ensure that systems and networking infrastructure recovery requirements and strategies are included  Identify dial access requirements  Establish network recovery strategies for remote offices, branches, vendor and customer links Organizing Communications  Establish a conference bridge phone line to conduct assessment, decision making and status review meetings  Establish a Emergency Status Information line to publish recorded recovery status messages for staff and employees

Copyright 2004 Turning Point Solutions  Establish Connections with Emergency Management Agencies  NEDRIX Notify  MEMA ESF18 Organizing Communications  Establish Credentials to Identify Essential Employees  CEAS/BNET-NE (Boston Approved, State considering it, Cambridge just starting to organize)

Copyright 2004 Turning Point Solutions  Establish Connections with Local Media  Provide names of contact person to keep on file Organizing Communications  Establish 3 Emergency Operations Center locations  One in the building  One in building nearby  One at recovery site

Copyright 2004 Turning Point Solutions Maintaining & Testing The Plan Establishing Lines Of Communication Before a Crisis

Copyright 2004 Turning Point Solutions Maintaining & Testing The Plan  Establish policies and guidelines to foster a culture where recovery planning and plan maintenance are part of the standard process  Include DR planning review in the change control process and enforce it  Include DR planning/requirements expense in all project budgets  Include DR planning review in all business related projects (acquisitions, reorgs, new customers, etc.)  Include DR planning review in the systems development life cycle

Copyright 2004 Turning Point Solutions Maintaining & Testing The Plan  Fostering a DR Planning Culture (continued)  Train the Auditors  Add DR planning objectives and responsibilities to job descriptions and performance appraisals

Copyright 2004 Turning Point Solutions Maintaining & Testing The Plan  Promote awareness of the plan  Conduct annual internal seminars for business and IT teams to meet and learn facets of the plan  Make DR part of the standard ongoing tasks/projects review at all staff meetings and activity reports  Meet with marketing and public relations to relate selling points of the program  Include plan reviews in Staff meetings

Copyright 2004 Turning Point Solutions What About Testing? 24% - Companies that do not test 34% - US Companies the do not test 48% - Said they don’t have time Veritas Study 2003 Statistics to Ponder

Copyright 2004 Turning Point Solutions Maintaining & Testing The Plan  Make testing a continual program in all parts of the organization  Conduct integrated testing wherever possible  Include offsite storage inventory reviews as part of the testing program  Develop test schedules for all critical IT components  Include business units in testing  Make call tree tests part of the program

Copyright 2004 Turning Point Solutions Maintaining & Testing The Plan  Testing (continued)  Expand testing objectives beyond the data center  Use plan testing as a means for training, validating and updating plans  Test to validate recoverability. Test reporting should identify results, issues and next steps.

Copyright 2004 Turning Point Solutions Be Ready when opportunity comes. Luck is the time when preparation and opportunity meet. Roy D. Chapin Jr.

Copyright 2004 Turning Point Solutions Questions??????????????