Chapter 3: Business Continuity Planning. Planning for Business Continuity Assess risks to business processes Minimize impact from disruptions Maintain.

Slides:



Advertisements
Similar presentations
1 Documentation Legal Framework Air Navigation Orders Guidelines ATS Manual Airport Manual Safety Management Manual ICAO Annexes Licenses / Certificates.
Advertisements

Module N° 4 – ICAO SSP framework
Business Continuity Planning Presentation to Management.
Continuity of Operations (COOP) Awareness Training
Process and Procedure Documentation. Agenda Why document processes and procedures? What is process and procedure documentation? Who creates and uses this.
Business Continuity and Disaster Recovery Planning.
Project Management Gaafar 2007 / 1 This Presentation is uses information from PMBOK Guide 2000 Project Management Risk Management* Dr. Lotfi Gaafar.
1 Continuity Planning for transportation agencies.
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP)
Business Continuity Planning and Disaster Recovery Planning
Contractor Management and ISO 14001:2004
Security Controls – What Works
Action Implementation and Monitoring A risk in PHN practice is that so much attention can be devoted to development of objectives and planning to address.
Unit # 3: Information Security and Risk Management
ENVIRONMENTAL MANAGEMENT PLAN
TEL382 Greene Chapter /27/09 2 Outline What is a Disaster? Disaster Strikes Without Warning Understanding Roles and Responsibilities Preparing For.
Planning for Contingencies
Managing Project Risk.
Gulf Coast Energy International Business Continuity / Disaster Recovery Planning and Design Proposal Prepared by Andrew Rolf, Felipe Torres, Pranay Jaiswal.
Business Continuity and You! The Ohio State University Business & Finance Enterprise Continuity Program Quarterly Update October 2008Business and Finance.
Business Continuation Plan / Program Overview State CIO Council Meeting June 24, 2008.
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
Unit Introduction and Overview
Continuity of Operations Planning COOP Overview for Leadership (Date)
PRM 702 Project Risk Management Lecture #28
PMI Knowledge Areas Risk Management.
Module 3 Develop the Plan Planning for Emergencies – For Small Business –
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Basics of OHSAS Occupational Health & Safety Management System
SMS Operation.  Internal safety (SMS) audits are used to ensure that the structure of an SMS is sound.  It is also a formal process to ensure continuous.
Continuity of Operations (COOP) Awareness Training.
© 2001 by Carnegie Mellon University PSM-1 OCTAVE SM : Senior Management Briefing Software Engineering Institute Carnegie Mellon University Pittsburgh,
Unit 8:COOP Plan and Procedures  Explain purpose of a COOP plan  Propose an outline for a COOP plan  Identify procedures that can effectively support.
ISA 562 Internet Security Theory & Practice
Alachua County Continuity of Government (COG) Alachua County Emergency Operations Center (EOC) 19 February hrs.
1. 2 Cost to Recover Time to Recover Last Backup Work Backlog Created Lost Data Recovery Operations Time Cost Disaster Recovery Time Frame Reconstruct.
Business Continuity and Disaster Recovery Chapter 8 Part 1 Pages 897 to 914.
Hazards Identification and Risk Assessment
DRP World Class Operations - Impact Workshop Info-Tech Research Group, Inc. Is a global leader in providing IT research and advice. Info-Tech’s products.
Business Continuity Program Orientation (insert presentation date) (This presentation is a template that requires adjustments to meet your needs)
INFORMATION SECURITY MANAGEMENT L ECTURE 3: P LANNING FOR C ONTINGENCIES You got to be careful if you don’t know where you’re going, because you might.
Phases of BCP The BCP process can be divided into the following life cycle phases: Creation of a business continuity and disaster recovery policy. Business.
Risk Management CS5493. Risk Management The process of ● identifying, ● assessing, ● prioritizing, and ● mitigating risks.
Unit 3: Identifying and Safeguarding Vital Records Unit Introduction and Overview Unit objective:  Describe the elements of an effective vital records.
NFPA 1600 Disaster/Emergency Management and Business Continuity Programs.
Office of Emergency Management University of Houston-Clear Lake Business Continuity Planning.
This course, Essential Records Seminar, is part of
Key Terms Business Continuity Plan (BCP) – A comprehensive written plan to maintain or resume business in the event of a disruption Critical Process –
Introduction to Project Management Chapter 9 Managing Project Risk
Information Security Governance and Risk Chapter 2 Part 2 Pages 69 to 100.
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
Revision N° 11ICAO Safety Management Systems (SMS) Course01/01/08 Module N° 9 – SMS operation.
Business Continuity Disaster Planning
Company LOGO. Company LOGO PE, PMP, PgMP, PME, MCT, PRINCE2 Practitioner.
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
AUDITING BUSINESS CONTINUITY PROGRAMS AND PLANS What to Look For Presented by: Tommye White, CBCP, DRP Chuck Walts, CBCP, CRP.
This courseware is copyrighted © 2016 gtslearning. No part of this courseware or any training material supplied by gtslearning International Limited to.
Business Continuity Planning 101
Dr. Gerry Firmansyah CID Business Continuity and Disaster Recovery Planning for IT (W-I)
MANAGEMENT of INFORMATION SECURITY, Fifth Edition.
THINK DIFFERENT. THINK SUCCESS.
Utilizing Your Business Continuity Plan.
CompTIA Security+ Study Guide (SY0-401)
Business Continuity / Recovery
Recognization and management of RISK in educational projects
Berry College Disaster Recovery Soft Exit
Fundamentals of a Business Impact Analysis
CompTIA Security+ Study Guide (SY0-501)
Business Continuity Planning
Continuity of Operations Planning
Presentation transcript:

Chapter 3: Business Continuity Planning

Planning for Business Continuity Assess risks to business processes Minimize impact from disruptions Maintain continuity of being able to perform mission-critical business tasks Main steps: – Project scope and planning – Business impact assessment – Continuity planning – Approval and implementation

Project Scope and Planning Business organization analysis BCP team selection Resource requirements Legal and regulatory requirements

Business Organization Analysis Identify all departments Identify critical services Identify senior executives and key individuals

BCP Team Selection Needs members from every department/division Include members from: – IT – Senior management – Legal – Security

Resource Requirements BCP development BCP testing, training, and maintenance BCP implementation Mostly personnel but may include IT and physical resource allocation

Legal and Regulatory Requirements Federal, state, and local laws or regulations Emergency services Industry regulations Country-specific laws Service-level agreements

Business Impact Assessment Quantitative decision making vs. qualitative decision making Identify priorities Identify risk Assess likelihood Assess impact Prioritize resources

Identify Priorities Critical prioritization of business processes Assess by department, then organization Assign an AV (asset value) to each process Determine MTD (maximum tolerable downtime) Choose an RTO (recovery time objective)

Risk Identification Inventory-specific risks Natural and man-made Logical and physical and social Don’t overlook the cloud Get input from all departments

Likelihood Assessment Determine frequency of occurrence Establish an ARO (annualized rate of occurrence) Based on history, experience, and experts

Impact Assessment Evaluate consequences of a breach EF (exposure factor) SLE (single loss expectancy) – SLE = AV x EF ALE (annualized loss expectancy) – ALE = SLE x ARO Consider nonmonetary impacts

Resource Prioritization Biggest ALE is biggest risk concern Combine qualitative priorities with quantitative priorities Work at addressing each item from largest ALE value first

Continuity Planning Strategy development Provisions and processes Plan approval Plan implementation Training and education

Strategy Development Bridge between BIA and BCP crafting Determine which risks to address in this BCP crafting time frame Determine acceptable risks vs. those that require mitigation Commit sufficient resources to resolve priorities

Provisions and Processes People Building and facilities – Hardening provisions – Alternate sites Infrastructure – Physically hardening systems – Alternative systems

Plan Approval Top-level management endorsement Educate top executives about plan concepts and details Senior executive approval establishes plan credibility throughout organization

Plan Implementation Define an implementation schedule Use allocated implementation resources Achieve process and provisioning goals Implement BCP maintenance program

Training and Education Assign responsibilities Plan overview briefing Dedicated training for those with assigned responsibilities A backup or replacement person for each position

BCP Documentation Continuity planning goals Statement of importance Statement of priorities Statement of organizational responsibility Statement of urgency and timing Risk assessment Risk acceptance/mitigation Vital records program Emergency-response guidelines Maintenance Testing and exercises

Continuity Planning Goals To set goals To ensure the continuous operation of the business in the face of an emergency situation To meet organizational needs

Statement of Importance Reflects criticality of BCP Disclosed in a memo to all employees Should be signed by CEO to avoid compliance resistance

Statement of Priorities Directly reflects designed BCP priorities Includes evaluation of priorities Focuses on importance to the continued operation of business functions in the event of an emergency

Statement of Organizational Responsibility Business continuity is everyone’s responsibility Reinforces organization’s commitment to BCP Informs individuals of the expectation to assist and support

Statement of Urgency and Timing Stresses priority of implementation Defines the roll-out timetable

Risk Assessment A recap of the BCP decision-making process Summary of BIA Discloses quantitative and qualitative analysis results

Risk Acceptance/Mitigation Identifies those risks deemed acceptable Identifies those risks deemed unacceptable – List risk management provisions – Define processes and responses – Define how the risk is reduced or managed

Vital Records Program Determine where critical records will be stored Set procedures for backing up critical records Identity critical records Digital and paper should be considered Includes records needed to reconstruct the organization in the event of a disaster

Emergency-Response Guidelines Define responsibilities in an emergency Detail activation of BCP elements Immediate response procedures Individuals to notify of the incident Secondary response procedures Goal: to minimize response time

Maintenance The BCP is a living document. The BCP should be periodically updated. Drastic changes may require a complete re-design and re-crafting. You should practice good version control. Include the BCP in job descriptions/responsibilities.

Testing and Exercises Establish a formalized testing program Train personnel on their tasks and responsibilities See disaster recovery testing in Chapter 18