• No results found

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity

N/A
N/A
Protected

Academic year: 2021

Share "KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity"

Copied!
38
0
0

Loading.... (view fulltext now)

Full text

(1)

INFORMATION RISK MANAGEMENT

ADVISORY

KPMG Information Risk Management

Business Continuity Management

(2)

Contents

Agenda:

Global trends and BCM challenges

BCM strategy and approach

(3)

INFORMATION RISK MANAGEMENT

ADVISORY

(4)

Global Trends

High availability systems – 24x7 on demand services

Complex operational models including joint ventures and

collaboration

Mergers and acquisitions increasing

Greater use of outsourcing for IT and business processes

Off-shoring is increasing

Globalisation

On-line competitors from other countries

Increased governance regulation

(5)

Challenges

Understanding downtime tolerance and organisational impacts

Understanding business processes and key dependencies

Rapidly changing organisational processes, systems and infrastructure

Knowing who is responsible for BCM and DR risks in outsourced

environments

Understanding, managing and communicating BCM remotely

Broad scope of threats across and between countries

Direct threats from competitors – especially remotely

Awareness of and management of regulatory requirements in different

jurisdictions

Increased shareholder expectations

BCM still buried in information technology

(6)

INFORMATION RISK MANAGEMENT

ADVISORY

(7)

Strategy

Consider all of the business

Address the expected and the unexpected across all business areas

Consider day-to-day risks as well as catastrophic events

Consider critical infrastructure obligations

Understand the business needs and tolerances

Consider:

risk reduction and organisational hardening

operations during a crisis

business recovery and

business resumption

Set a target that is affordable

(8)

Strategy considerations

B

B

u

u

s

s

i

i

n

n

e

e

s

s

s

s

I

I

n

n

t

t

e

e

r

r

r

r

u

u

p

p

t

t

i

i

o

o

n

n

Business processes:

• Supplier failure

• Breakdowns

• Legal shutdown

Technology:

• Stopped

• Erroneous/corrupted

• Erratic

Premises:

• Damaged

• Destroyed

• Utility failure (power/water)

People:

• Sick or injured

• Unavailable for work

(9)

KPMG approach

Project Planning and Initiation

Business

Process

Analysis

Business Impact Analysis

Interim Recovery Controls

and 'Quick Wins'

Cost effective Strategies and Options including alternate recovery

strategies

DRP Development and Deployment

Plan Testing including exercise and quality assurance

Plan Administration Including maintenance and enhancement

Phase 3:

Test and handover the

BCP

Phase 2:

Develop and deploy the

BCP

(10)

Business Process Analysis

A highly detailed identification and

process-level assessment of the

recovery and resource requirements of

individual business units.

Key business units are asked to assess

their core business practices regarding:

Dependencies on business processes,

suppliers and IT systems and processes;

Maximum tolerable outage times;

Acceptable levels of data loss;

Dependencies on 3

rd

party providers; and

Human and technical resource

requirements.

(11)

IT infrastructure and 3

rd

party provider analysis

As part of the business process

analysis, you should focus on

understanding the IT infrastructure

and external service arrangements

that support all critical IT

processes and systems.

You should also undertake a

detailed technical analysis of your

infrastructure to identify

weaknesses and potential failure

points.

The IT infrastructure and 3

rd

party provider analysis will enable your systems

(12)

Risk and Vulnerability Assessment

The risk and vulnerability assessment

facilitates a detailed analysis of the

potential threats to the continuity of

your systems and processes.

The assessment considers:

Environmental and geographic hazards;

Physical and logical security;

Exposure to malicious intent;

All locations that house critical resources,

eg. Head Office, Operations, and Data

Centres; and

General disaster responses.

(13)

Business Impact Analysis

The results of the risk and

vulnerability assessment and the

business process analysis are

combined into a complete, highly

detailed picture of businesses

recovery requirements in the

Business Impact Analysis (“BIA”)

report.

This report provides:

The consolidated findings;

A detailed account of the residual

risks facing the business; and

The scope of business recovery

requirements.

(14)

Business impact analysis

#

Key business

functions

Purpose

Key

dependencies

Consequences of

disruption

Maximum

Tolerable Outage

Recovery

Point

Objective

Service level

commitment

Notes

1 Management

accounting

To produce reports

that management

can use to monitor

results and

manage the

company

profitability.

„

Procedure:

o

Determine

financial

information

needed

o

Prepare the

information

o

Continuously

evaluate the

effectiveness

Financial

and other

information

from key IT

system A

and manual

system B.

Incorrect

management

reports that may

result in financial

and/or reputation

damage due to

management

changes made

from inaccurate

information.

48 hours

24 hours

Committed to

executive

management

that

management

accounts will

be completed

within 4 days

of period end.

Any

observations

and

long-term affects

and how

they may

affect the

end result.

(15)

Interim recovery controls, quick wins and recovery options

As a result of the business process

and impact analysis, you can:

Plan for the best use of existing controls

(prior to the BCP being deployed);

Identify and implement “quick win”

measures to mitigate risks prior to BCP

deployment; and

Assess the most cost efficient process

capabilities and infrastructure resource

options for inclusion in the BCP. This

may include developing BCP capabilities

in-house, engaging external service

providers or a suitable combination of

the two.

(16)

Crisis Management

In the event of a major business interruption, an organisation must

react immediately to reduce the impact of the situation. A Crisis

Management Plan (CMP) assists organisations to effectively

manage, respond and recover from such a situation.

The CMP should cover:

Emergency Management Team Structure, Roles & Responsibilities;

Communications plan for “chain of command”, staff, media, regulators,

family/friends, market analysts;

Emergency Services Roles & Responsibilities;

Emergency Preparation Procedures & Checklists,

Emergency Activation Procedures & Checklists;

Recovery Procedures & Checklists; and

(17)

Business Continuity Plan

The business continuity plan

(“BCP”) includes advanced

arrangements and procedures to

enable an organisation to respond

to an event in such a manner that

the critical business functions

continue with minimal interruption

or essential change.

The plan includes guidance on:

Definition on roles and

responsibilities;

Procedures for invocation and

recovery;

Recovery activity schedules; and

(18)

Disaster Recovery Plan

The disaster recovery plan

(“DRP”) is a clear, concise course

of action to be taken in the event

of an IT disaster.

The plan includes guidance on:

The prioritisation of recovery

procedures enabling critical

business functions to be restored

first;

Communications plans;

Detailed action plans for the

restoration of systems and

processes; and

The optimum resumption of

‘business-as-usual’ processes.

(19)

Test and administer DRP and BCP

A plan is not complete until it is tested

and an administration plan has been

agreed.

A testing strategy should ensure your

plans are fully functional, and tests your

team’s preparedness and responses to

potential incidents.

The test plan should provide for :

Development of relevant test scenarios;

Management and coordination of the test;

and

Detailed analysis and recommendations.

An administration and maintenance plan

will enable the plan to be a living

(20)

INFORMATION RISK MANAGEMENT

ADVISORY

(21)

Some risks to consider

Epidemic (eg SARS)

Workplace accidents

Industrial disputation

Major external events

Natural disasters (flood,

storm, earthquake)

Terrorism

Neighbourhood events

(gas leak,

demonstration)

Criminality

Attacks and vandalism

Hardware failure

Software failures and

viruses

Loss of utilities (power,

telco, water, gas)

(22)

Assessing the risks - options

Risk workshops

Involve all key areas of the business

Should use an experienced facilitator

Encourage discussion on likelihood and impact

Aim for consensus on prioritisation of risks

Questionnaires/surveys

Useful for multiple locations

Provide consistency

Might not disclose unusual or unique risks

Should always be discussed and clarified

Generic risks

(23)

INFORMATION RISK MANAGEMENT

ADVISORY

(24)

KPMG’s Asia-Pacific BCM Benchmarking Survey

In order to understand the needs of our Asia-Pacific clients, KPMG

conducted a BCM Benchmarking Survey. The objective of the

Asia-Pacific BCM Benchmarking Survey was to provide insight into the

BCM trends in the Asia-Pacific region and within specific industries.

To achieve this, a comprehensive survey containing 73 questions

covering a wide range of aspects of Business Continuity was

produced. The survey aimed to:

Provide insight into current BCM trends and what organisations around the

Asia-Pacific region are experiencing and actioning with respect to BCM;

Understand the perceived risk of the current environment, the key drivers

for BCM, and the actual impact on organisations in the region; and

Allow organisations to have a current view of BCM activities in their

particular industry and to enable them to place their own current state into

perspective.

(25)
(26)

KPMG’s Asia-Pacific BCM Benchmarking Survey results

Key findings include:

Catastrophic events are focusing actions

Risks and costs of downtime not understood

Increased reliance on technology - more than 50% have

maximum tolerable outages of 7 hours or less

On-going maintenance is a problem

(27)
(28)

Downtime tolerance

“More than half across

all industry groups have

maximum tolerable

(29)

Status of BCM implementation

(30)

BCM drivers

Top 4:

Hardware failure

Software failure

Communications failure

Security breach

Lowest 4:

Regional political activity

Social unrest

Economic changes

(31)

Which industries are doing better?

(32)

Frequency of risk assessments

(33)

Responsibility for BCM

(34)

Downtime costs

(35)

Survey conclusion

The state of BCM governance is not good enough

Efforts are still misdirected

Stakeholders are at risk

(36)
(37)

Peter McNally - Partner

Professional Career

Peter is the Asia Pacific Security, Privacy and Continuity Partner in KPMG’s Information Risk Management

(IRM) practice.

Peter’s Business Continuity experience includes conducting continuity workshops for a European Airline,

plan assessment at a financial services (funds management) client, and development of plans for an

international airport.

Peter is a recognised spokesperson on business continuity having been quoted in the press and has

delivered a number of industry presentations, most recently on critical infrastructure protection. He also

managed and authored the KPMG November 2003 Asia Pacific business continuity survey.

Clients

Seven Network

Tenix

Qantas Airways Limited

Brisbane Airport Corporation

Virgin Express

Experience

BCP/DRP review and maintenance

BCP/DRP development

(38)

KPMG Contacts

Global, Asia Pacific and Australia Partner in Charge

Information Risk Management

Egidio Zarrella

KPMG in Australia

+61 (2) 9335 7590

[email protected]

Asia Pacific Leader, Business Continuity

Information Risk Management

Peter McNally

KPMG in Australia

+61 (2) 9335 7987

[email protected]

National Partner in charge

Information Risk Management

Richard Chen

KPMG in Taiwan

+886 2 2715 9813

[email protected]

Disclaimer

The information contained herein is of a general nature

and is not intended to address the circumstances of

any particular individual or entity.

Although we endeavour to provide accurate and timely

information, there can be no guarantee that such

information is accurate as of the date it is received or

that it will continue to be accurate in the future.

References

Related documents

Interfacing with the business and IT Service Continuity Management on the dependencies of business units and their business processes with the supporting IT services contained

NOTE: Business continuity management involves managing the recovery or continuation of business activities in the event of a business disruption, and management of the overall

Five Key considerations: • Business Impact Analysis • Continual Updates to Business Continuity Plan • Tailoring the Cloud Recovery Service • Service Level Agreements •

Design, develop, and implement Business Continuity and Crisis Management plans that provides continuity within the recovery time objective and recovery point objective1.

Key Process in Service Business Suppliers / Subcontractors • Capacity Management • Service Level Management • Continuity & Availability Management • Security Management

Explain the need for and benefits of training of key staff for: 7.2.1 Business continuity programme management 7.2.2 Business impact analyses and risk assessments. 7.2.3

Business Continuity Plan development – in combination with our Business Continuity Management (BCM) audit and Business Impact Analysis (BIA) – gives customers the opportunity to

polysaccharide Prevent phago and complement Neonatal meningitis Verotoxin/ shiga like Inactivate 60S Gastroenteritis bloody Head stable/liable. enterotoxin Fluid