• No results found

PBSi Business Continuity Planning

N/A
N/A
Protected

Academic year: 2021

Share "PBSi Business Continuity Planning"

Copied!
20
0
0

Loading.... (view fulltext now)

Full text

(1)

PBSi

Business Continuity

Business Continuity

Planning

(2)

PBSi

Definition

Definition

• Business Continuity planning is a

planning process designed to reduce

the risk that disruptive failures or events could seriously harm your business.

• It is designed to safeguard your

business by ensuring the continuity of a minimum set of business functions and a smooth return to normal operating

(3)

PBSi

Causes of Failure

Causes of Failure

• Failures or events may be external or internal in nature

• External: Loss of power,

communications, flooding, interruption of supply chain

• Internal: Loss of information, fire, corrupted IT systems, loss of key personnel

(4)

PBSi

Purpose

Purpose

• Provide predetermined actions to

– Allow prompt resumption of critical functions

– Reduce decision making during recovery operations

– Allow return to normal operating conditions at the earliest possible time

– Minimize financial loss and hardship – Minimize the extent of interruption

(5)

PBSi

Required By

Required By

• US Securities Exchange Commission for companies >$10M

• Emergency Preparedness Canada for all Government Departments

• National Contingency Planning Group and Treasury Board Secretariat for

Mission Critical government functions for Y2K

(6)

PBSi

Business Continuity Planning

Requirements Analysis (scoping study) Business Impact Analysis (BIA) Options Analysis Implementation Strategy Aggregate Continuity Plan Test / Validate / Update Plans Lifecycle Maintenance Risk Management Business Continuity Management Plan Business Plans, Policies, Objectives, Procedures Project Risk Assessment Business Risk Assessment Options Risk Assessment Strategic Risk Assessment Integrated Risk Assessment Update Risk Assessments Update Risk Assessments Integration Plans

(7)

PBSi

Benefits of Contingency

Benefits of Contingency

Planning

Planning

• Successfully deal with threats to survival

• Successfully deal with threats to continuing operations

• Successfully deal with interruptions of critical functions

• Allows comprehensive planning and implementation of procedures that do not have to be invented in time of crisis

(8)

PBSi Risk Mitigation Contingency Planning Contingency Planning (Disaster Recovery) Business Resumption Planning

Preparedness / Prevention Crisis Response Return to Normalcy

Determine Workarounds Stockpile

Establish Redundant Systems Remediate / Replace Current Systems

Execute Established Procedures

Restore Failed Systems Return to Pre-Crisis Operations Readiness Posture Crisis Response Posture Transition and RecoveryPosture

AIM: Prevent Failure of Critical Business Functions

AIM:To Restore a Minimum Level of Service Within the

Required Timeframe

AIM: To restore Normal Operating Conditions

Business Continuity

Planning

Normal Service Level

Minimum Service Level

(9)

PBSi

Process Diagram

Process Diagram

Risk Assessment Business Function Analysis Contingency Planning Crisis Response Recovery Planning Training Testing

(10)

PBSi

Process Steps

Process Steps

• Risk Assessment

• Business Function Analysis • Contingency Planning

• Crisis Response • Recovery Planning • Training

(11)

PBSi

Risk Assessment

Risk Assessment

• Appraisal/review of existing documents, policies, business plans and disaster

recovery plans

• Risk identification ensures that risks associated with all facets of business operations are captured

(12)

PBSi

Business Function Analysis

Business Function Analysis

• Define business functions and relative criticality

• Map assets and interdependencies of critical business functions

• Determine consequence of failures and identify key vulnerabilities

• Determine the minimum service level and identify gaps in ability to deliver minimum service level in a crisis.

(13)

PBSi Assets Critical Function Infrastructure Interdependenci es Transportation Utilities Government Services Services Communication Safety Others Functional Interdependencies

Assets & Interdependencies

Clients Others Suppliers Other Government Departments Employees Companies Embedded Systems Facilities Internal/ External Interfaces IT Systems IT Infrastructure End User Computing

(14)

PBSi

Contingency Plan

Contingency Plan

• Define options for the plan wrt to

function, process, system and people • Define responsibility and reporting

• Identify resources required to invoke plan and procedures

• Cost benefit analysis to select cost effective procedures

(15)

PBSi

Crisis Response

Crisis Response

• Crisis response activities include reporting and management response

• Developing plans and procedures to assess failures

• Describing thresholds for invoking contingencies

• Describing individual responsibilities and authorities

(16)

PBSi

Recovery Planning

Recovery Planning

• Defines the planning necessary to

return to normal operating conditions after a crisis.

• Dependent on the nature of business and contingency plans developed to-date

(17)

PBSi

Business Continuity

Business Continuity

Plan

Plan

Contingency Procedures & Triggers Contingency Plan Overview Crisis Response Plan Contingency Plan Business Resumption Plan Business Resumption Procedures Crisis Response Procedures Departmental Crisis Definition Crisis Scenarios

Training, Test & Maintenance Plan

(18)

PBSi

Training

Training

• Develop training plan

• Conduct the training for the

implementation of the business continuity plan

• Record lessons learned

• Make recommendations for changes to business continuity plan and procedures

(19)

PBSi

Testing

Testing

• Design test program, write test scenarios and exercises, and conduct the test of business continuity plans

• Tests may be structured walkthrough, operational or live exercise

• Assess performance

• Validate test and gather lessons learned • Develop recommendations and implement

(20)

PBSi

Network

Network

Timeline | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 Risk Assessment Business Function Analysis Contingency Planning Crisis Response Recovery Planning Training Testing Business Continuity Plan

References

Related documents

Business Impact Analysis Assessment Business Continuity Roadmap CONSULT Data Protection Systems Business Continuity Plan Audit Cloud Storage for Backup Storage Strategy

This paper presents guidelines for the definition of innovative business models for remanufacturing, utilizing both remanufacturing and PSS characteristics, and permitting

For Greg Gianforte, talking to potential customers – market research – was the foundation for an entrepreneurial business venture that was cash- flow positive from day one.. In

Risk assessment (gap analysis) Continuity strategy development St ra tegy imp lem en ta tion Plans exercise and maintenance Business impact analysis Dependency analysis Ris k-

Business Continuity Plan development – in combination with our Business Continuity Management (BCM) audit and Business Impact Analysis (BIA) – gives customers the opportunity to

Provide management a gap analysis and action plan identifying the necessary steps for completing the Disaster Recovery Planning and Business Continuity process. Business

• Understand FFIEC Requirements regarding Business Continuity Program / Business Impact Analysis (BIA) and the relationship to Testing.. • Financial Impact

The agreed action to update the business continuity disaster recovery plan for data centres has been amended as it has been agreed that the Business Impact Analysis process,