BUSINESS CONTINUITY MANAGEMENT THROUGH STANDARDS AND BEST PRACTICES Jasmina Trajkovski, CISA, CISM.

Slides:



Advertisements
Similar presentations
Museum Presentation Intermuseum Conservation Association.
Advertisements

Business Continuity Training & Awareness by Sulia Toutai (ANZ)
Business Continuity and Disaster Recovery Planning.
A briefing about your BCM Programme.  Why BCM  Benefits of BCM  Programme Objectives  Methodology  Tasks & Deliverables Programme Overview.
CIOassist Technologies Your CIO on Demand… Business Continuity Planning Our Offering CIOassist Technologies (
Module – 9 Introduction to Business continuity
Business Continuity Section 3(chapter 8) BC:ISMDR:BEIT:VIII:chap8:Madhu N PIIT1.
Your Role in the New Normal Increased knowledge and active participation in disaster preparedness and recovery prepare you for the New Normal Baton Rouge,
Managed Funds Association’s Sound Practices for Hedge Fund Managers 2009 Edition.
Introduction to Business Continuity Planning An Introduction to the Business Continuity Planning Process Including Developing your Process and the Plans.
© 2009 EMC Corporation. All rights reserved. Introduction to Business Continuity Module 3.1.
September 14, 2010 Measuring/Monitoring for Perfect Ground Transportation Services AGTA Meeting – San Antonio 10:45 AM Michael J. Corby, CISSP, CCP, PMP.
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP)
BCP/DRP Consultancy Project- An approach
Business Continuity Planning Jeremy Stacy. Objectives Understand the steps in Business Continuity Planning Understand the terminology used in Business.
Security Controls – What Works
Implementing BCM Lynda McMullan CBCI Business Continuity Manager.
TEL382 Greene Chapter /27/09 2 Outline What is a Disaster? Disaster Strikes Without Warning Understanding Roles and Responsibilities Preparing For.
Disaster Recovery and Business Continuity Ensuring Member Service in Times of Crisis.
Business Continuity The Basics Emergency Planning and Business Continuity Team.
Guide to Disaster Recovery
Business Continuity Planning April 29, 2005 Edmonton Sean Lawson, CBCP Linc Group Corp.
Gain Executive Support in Measuring the Effectiveness of Your BCM Program -Cheyene Haase BC Management, Inc.
RBTC: Business Continuity 101 July 18, What is Business Continuity? Scenario Part 1 Why is BC important? What types of plans are needed? How do.
Evolving IT Framework Standards (Compliance and IT)
Business Continuity Management May 20, 2010 Peter Zwingli ACME Business Consulting.
Business Crisis and Continuity Management (BCCM) Class Session
ISA 562 Internet Security Theory & Practice
CS3100 Software Project Management Week 26 - Quality Dr Tracy Hall.
Insurance Institute for Business & Home Safety Even if the worst happens, be prepared to stay.
David N. Wozei Systems Administrator, IT Auditor.
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Expecting the Unexpected By Shaun Lindfield. Nearly 1 in 5 businesses suffer a major disruption every year. Yours could be next. With no recovery plan,
Introduction to Business Continuity Management March 2014 Martin Sun Head of Security.
Business Continuity Management For Project Managers.
ISO GENERAL REQUIREMENTS. ISO Environmental Management Systems 2 Lesson Learning Goals At the end of this lesson you should be able to: 
Business Continuity Program Orientation (insert presentation date) (This presentation is a template that requires adjustments to meet your needs)
Phases of BCP The BCP process can be divided into the following life cycle phases: Creation of a business continuity and disaster recovery policy. Business.
Unit 3: Identifying and Safeguarding Vital Records Unit Introduction and Overview Unit objective:  Describe the elements of an effective vital records.
NFPA 1600 Disaster/Emergency Management and Business Continuity Programs.
SecSDLC Chapter 2.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
Crisis Management Crisis: any situation that has the potential to affect long-term confidence in an organisation or product and may interfere with its.
Author(s): Don M. Blumenthal, 2010 License: Unless otherwise noted, this material is made available under the terms of the Attribution – Non-commercial.
9 juni 2009 Alex van Os de Man BCI Forum 2009 Business Impact Analysis Process.
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
Albany Bank Corporation Security Incident Management Program.
Tom Lenart & John Field CT DEMHS Region 2.  Department of Emergency Services and Public Protection (DESPP)  Commission on Fire Prevention and Control.
Business Continuity Disaster Planning
Business Continuity Management 101. KeepItSafe Professional Services The portfolio of business continuity management is to ensure we assist our clients.
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
Business Continuity Management Business Continuity Management (BCM) is a holistic management process that identifies potential impacts that threaten an.
Business Continuity Planning 101
SEC 480 assist Expect Success/sec480assistdotcom FOR MORE CLASSES VISIT
Dr. Gerry Firmansyah CID Business Continuity and Disaster Recovery Planning for IT (W-I)
For more course tutorials visit SEC 480 Entire Course For more course tutorials visit SEC 480 Week 1 DQs SEC 480 Week.
THINK DIFFERENT. THINK SUCCESS.
Chris Lintern Co-operative Financial Services
Systems Analysis and Design in a Changing World, 4th Edition
BUSINESS CONTINUITY BY HUI ZHENG.
DISASTER RECOVERY INSTITUTE INTERNATIONAL
Business Continuity Plan Training
Current ‘Hot Topics’ in Information Security Governance Auditing
Business Continuity Plan
Business Continuity Basics
How to conduct Effective Stage-1 Audit
Business Continuity Program Overview
A Risk Management Approach to Business Continuity
Presentation transcript:

BUSINESS CONTINUITY MANAGEMENT THROUGH STANDARDS AND BEST PRACTICES Jasmina Trajkovski, CISA, CISM

What is BCM?  holistic management process  identifies potential impacts  framework for resilience and response capability  safeguard interests of key stakeholders or more simply…

 Not just a paper plan, it also requires organisation, planning, assessment, training, rehearsal and more. A process that establishes a secure and resilient business environment capable of mounting an immediate and effective response to a major incident.

Objective of business continuity management Time Level of business Critical recovery point Fully tested effective BCM No BCM – ‘lucky’ escape No BCM – likely outcome

Impact of Downtime Lost Revenue Know the downtime costs (per hour, day, two days...) Number of employees impacted (x hours out * hourly rate) Damaged Reputation Customers Suppliers Financial markets Banks Business partners Financial Performance Revenue recognition Cash flow Lost discounts (A/P) Payment guarantees Credit rating Stock price Other Expenses Temporary employees, equipment rental, overtime costs, extra shipping costs, travel expenses... Direct loss Compensatory payments Lost future revenue Billing losses Investment losses Lost Productivity

Availability Measurement – Levels of ‘9s’ Availability % Uptime% DowntimeDowntime per YearDowntime per Week 98%2%7.3 days3hrs 22 min 99%1%3.65 days1 hr 41 min 99.8%0.2%17 hrs 31 min20 min 10 sec 99.9%0.1%8 hrs 45 min10 min 5 sec 99.99%0.01%52.5 min1 min %0.001%5.25 min6 sec %0.0001%31.5 sec0.6 sec

Impact Scenarios 7  Loss or denial of physical space  Your work area has been destroyed and/or become inaccessible  Access to space, but loss of technology  Your area is intact, but without data/power/water/etc.  Both

Impact Categories 8  Financial  The cost to recover all functions + loss of revenue  Example: BP oil spill cost billions to clean + lost billions in product  Operational  The ability to physically execute a critical business function

Impact Categories 9  Legal/Regulatory  The ability to be fined, sued, or shut down  Customer  The ability to retain customer base when operating in Emergency Mode  Reputation  The ability to retain customer base when the story gets out

The business continuity plan Emergency response plan Activity Crisis management/ communication plan Business recovery plan Time objective A A successful outcome

What is wrong with current plans  Outdated or gathering dust on the shelves  ‰ Reads like a policy vs. a process to restore  ‰ Recovery team is not aware of plan contents or been trained  ‰ Only addresses restoring IT systems  ‰ Lacks an effective plan to:  restore connectivity between locations  manage communications to customers, local media, employees  ‰ Never been tested  ‰ A large single document  ‰ Saved only on the network  ‰ Does not address security incidents  ‰ Too much focus on catastrophic disasters or natural disasters  ‰ Does not address availability of critical vendors  ‰ One plan fits all disruptions

Some survey results 2014  One-third of respondents experienced outages reported stated that critical applications were lost for hours and sometimes multiple days.  Even more alarming was that one in four respondents said they had lost most, if not all of their datacenter for hours and in some cases days.  Nearly one in four respondents never tested their DR plans, and one-third of those surveyed tests their plans only once or twice a year. When companies do test, more than 65% do not pass their own DR tests 

BUT….. WHERE DO THE STANDARDS COME IN THE PICTURE?

Difference in objective / purpose  What has to be done  Agreed / accepted by a representative number of countries  Applicable to all types of organizations  What works well  How an activity can be done  A compilation of practices from various types of organizations StandardsBest practices

Standards….  ISO 22301:2012, "Societal security -- Business continuity management systems --- Requirements“  BS :2007, “Specification for Business Continuity Management” - replaced by ISO 22301:2012.  NFPA 1600: Standard on Disaster/Emergency Management and Business Continuity Programs.  ASIS/BSI BCM.01:2010 published Dec 2010  ANSI/ASIS SPC Organizational Resilience.

Best practices….  Business continuity institute – Good practice guidelines  Disaster recovery institute – reference materials  BS 25777, “Information and communications technology continuity management. Code of practice” – replaced with ISO27031: 2011, “Guidelines for information and communication technology readiness for business continuity”  ISO27002:2013, “Code of practice for information security controls”  ISO 22313:2012, "Societal security -- Business continuity management systems – Guidance“  ISO/IEC 27031:2011, "Information security - Security techniques — Guidelines for information and communication technology [ICT] readiness for business continuity“  BS :2006, “Business Continuity Management. Code of Practice” – replaced by ISO22313:2012  HB : A practitioners guide to business continuity management  HB : Executive guide to business continuity management  And many more….

ISO22301 Elements

ISO22301 clauses

Standards provides requirements for  Determining the context of the organization  List of legal, regulatory and other requirements  Scope of the BCMS (Business Continuity Management System) and explanation of exclusions  Business continuity policy and Business continuity objectives  Competences of personnel  Communication with interested parties  Process for business impact analysis and risk assessment  Business continuity procedures  Incident response procedures  Procedures for restoring and returning business from temporary measures  PDCA cycle

BCI Good Practice Guidelines  Policy and program management  Embedding business continuity  Analysis  Design  Implementation  Validation Management practicesTechnical practices

Best practices

Final words Do not just make the plan…. ….. Test to see if it works …. If it provides the required continuity …. And if the right people know how to use it.

JASMINA TRAJKOVSKI, CISA, CISM