• No results found

Business Continuity Planning (BCP) 101

N/A
N/A
Protected

Academic year: 2021

Share "Business Continuity Planning (BCP) 101"

Copied!
12
0
0

Loading.... (view fulltext now)

Full text

(1)

Business Continuity Planning (BCP) 101

Submitted by: Business Continuity Management Institute

Workshop on Private Sector Emergency

Preparedness

Sendai, Japan

(2)

APEC EPWG

Workshop: Private

Sector Emergency

Preparedness

BCP 101

August 2, 2011

Hotel Monterey Sendai

Sendai, Japan

Dr Goh Moh Heng

PhD BCCE DRCE BCCLA CBCP FBCI

P

id

t

(3)

Introduction 1: Business

Continuity Planning

(BCP) 101

09:45- 11:10

Overview, including benefits and

challenges to implementation, practices

for mitigating threats and risks, and

examples of BCP

Dr Goh Moh Heng

President

Business Continuity Management

(BCM) Institute

(BCM) Institute

www.bcm-institute.org

Managing Director

GMH Continuity Architects

Asia Pacific BCM Consulting Firm

www.GMHasia.com

Professional BCM Appointments

Technical Advisor for TR19:2005 &

SS540:2008 BCM Standard

(Management Council and Technical

(Management Council and Technical

Committee) www.ss540.org

Project Director, Technical Working

Group for SS507:2004

ISO/IEC 24762 Guidelines for BC-DR

Services

(4)

Dr Goh Moh Heng

Prior Appointments

Government of Singapore Investment

Corporation (GIC)

Standard Chartered Bank

Global Head for BCM

PriceWaterhouse (Coopers)

Past Certification Broad Member for

DRI International’s Certification Board

Past Executive Director for DRI Asia

Past Executive Director for DRI Asia

Senior Technical Advisor, China

Business Continuity Management

Forum

http://www.bcmpedia.org/wiki/Dr_Goh_Moh_Heng

BCM Institute

Started in January 2005.

Provide competency based BC-DR training to all levels.

p

y

g

Certify BC-DR professionals globally.

Started Certification programme in April 2007.

Trained more than 3000 professionals from 850

(5)

Agenda (Part 1 of BCM-101)

Business Continuity Management

Overview and Fundamentals

BCM Planning Methodology

Planning Process

Comparison with BCM Standards

Flexibility and consistency in global compliance

Process for implementing business continuity

CRISIS IT

RECOVERY CONTINUITYBUSINESS SECURITY

Incidents, Emergencies, Events, Disasters

Plan

SPECIFIC CRISIS MANAGEMENT PLAN IT DR PLAN BC PLAN SPECIFICPLANS SECURITY PLAN

(6)

BCM Planning Methodology

http://www.bcmpedia.org/wiki/ BCM_Planning_Process_or_Methodology

Key International BCM Standards

BS 25999

BS 25999

SS 540

SS 540

BS 25999

BS 25999

NFPA 1600

(7)

BCM Planning

Methodology

Ste-by-Step Approach

y

p pp

Project Management

Objectives

• Formulate a workable project proposal. • Seek endorsement and

commitment on the project from management committee: Objective

Tasks

• BCM Steering Committee & BCP Project Team • Review and understand

organisation environment. • Agree and formalise

project management

Deliverables

• Project plan proposal includes: – Definition – Scope – Objective – Objective – Scope – Approach – Schedule – Manpower • Establish project management structure and control. project management structure and resource allocation.

• Establish project administration reporting and control mechanism.

– Roles & Responsibilities • Project workplan. • Project reporting

(8)

Risk Analysis and

Review

Objectives

• identify vulnerabilities • Establish reliable recommendations for: – Minimizing impact of

Tasks

• Identify exposure to internal & external threats and the likelihood of these threats occurring

• Recommend preventive responses and escalation

Deliverables

• Comprehensive risk and threat profile to the organization, with key disaster scenario • Recommendation for: – Countermeasures Immediate Response impact of identified threats – Immediate and effective response to potential causes of disaster

responses and escalation procedures in conjunction with crisis management implementation • Evaluate findings and

prepare a status report & recommendation.

– Immediate Response Procedures

– Security Risk Review – to be implemented to

minimize the risks • Summary report of

recommendations agreed with senior management

Business Impact

Analysis

Objectives

• Determine impact of unavailability/failure/ disaster on business functions. • Determine critical business needs and

• Establish business criticality/ impact criteria using Business Impact Analysis Questionnaires (BIAQ).

• Prioritise the importance of each business unit vis-à-vis established criteria.

• Detailed report on findings (approved by management) containing: – - tolerable limits; – classification of criticality; – prioritised critical business functions;

business needs and tolerable limits.

established criteria. • Consolidate findings and

rankings. • Present results to

management committee to confirm critical

classifications and priority listings.

; – minimum resources; – Critical applications and

systems; and – - restoration priority. • Impact analysis of

unavailability of business functions (quantitative and qualitative).

(9)

Recovery Strategy

Objectives

• Establish business functions & job priorities vis-à-vis business needs. • Determine processing

requirements for priority business functions. • Identify and formalise

b k f thi

Tasks

• Analyse all division functions to prioritise them based on business needs.

• Analyse hardware and software requirements to run high priority critical functions so that sufficient backup can be arranged.

R i d t bli h b k

Deliverables

• List of strategic plans for recovering prioritised critical functions. • List of critical functions

requiring interim manual processing procedures

backup for everything needed to survive a disaster.

• Ensure that alternative processing procedure is available for continuity of critical business needs whilst recovery is in progress.

• Review and establish backup arrangements, if necessary. • Identify necessary interim

processing procedures for critical functions.

• Seek management’s review and endorsement of findings and recommendations. processing procedures. • Recommend alternate interim processing procedures.

Plan Development

Objectives

• Train and equip users with skill to complete the Microsoft Word plan template. • Establish recovery

procedures to fully

Tasks

• Determine recovery teams set-up and functional responsibilities.

• Identify members of each recovery team.

• Develop specific procedures

Deliverables

• Propose:

– Recovery team structure; – Staffing of the

recovery teams with names of specific

restore normal business operations after a disaster, based on selected strategies. • Ensure consistency and

comprehensiveness of coverage.

for each recovery team. • Review and edit (based on

agreed structure) the plan component to ensure consistency and comprehensiveness of documentation.

staff members; and – List of action steps to

be taken by each member of respective recovery team. • Completed Business

(10)

Testing and

Exercising

Objectives

• Formulate an objective mechanism to validate the "workability" of the complete Business Continuity Plan.

Tasks

• Design an overall program for testing of plan. • Develop plans and

schedules for specific tests. • Develop an evaluation

Deliverables

• List of tests to be conducted. • List of responsibilities of parties involved: – Objectives, policies, guidelines,

responsibilities and test

y Develop an evaluation mechanism.

responsibilities and test specifications.

• Specific test plan: – Description, scenarios,

procedures and criteria.

• Evaluation forms/checklists for recovery plan tests.

Building Organizational

Competency

Organization BCM Manager BCM Internal

Auditor Business Unit Coordinator/

Representative BCM Steering Committee

Organization BCM Manager

(11)

BCMpedia: Common Language

www.bcmpedia.org

BCM Community Forum

Building a Community

80% Asian and 

Middle Eastern BCM 

and DR 

Professionals

3331

(12)

THANK YOU

Dr Goh Moh Heng

President

President

Mobile: +65 96711022

Tel: +65 63231500

References

Related documents

The fact is clear that all the proceeds derived from the sale or confiscation of the sugar stocks belonging to the planters in Negros Occidental were retained as

Provide management a gap analysis and action plan identifying the necessary steps for completing the Disaster Recovery Planning and Business Continuity process. Business

Business Impact Analysis is about assigning the right resources to the most critical areas of the business in the event of a disaster... Core Elements of

 Disaster recovery planning : The technological aspect of business continuity planning necessary to minimise losses and ensure continuity of critical business functions

• Analyzing interdependencies represents a critical step in the business continuity process and is an integral part of a business impact analysis. • A “work flow” analysis

For Greg Gianforte, talking to potential customers – market research – was the foundation for an entrepreneurial business venture that was cash- flow positive from day one.. In

Our Business Continuity Planning services offer one of the broadest ranges of services in the industry, consisting of Business Impact Analysis, Information Availability,

A complete business impact analysis is the foundation for a comprehensive disaster recovery plan, as it determines the priority for the recovery of critical county