• No results found

Guideline - Business Continuity Plan

N/A
N/A
Protected

Academic year: 2021

Share "Guideline - Business Continuity Plan"

Copied!
6
0
0

Loading.... (view fulltext now)

Full text

(1)

1

Guideline - Business Continuity Plan

1. Introduction:

The Business Continuity Plan is a component of the Risk and Business Management suite. This suite includes:

 Risk Management – including risk registers

 Business Continuity Plans – including business impact analysis  Emergency Response Plans

 Health and Safety Plans

“Business continuity management provides the availability of processes and resources in

order to ensure the continued achievement of critical objectives1

This means that we must consider:

 Clearly defining and understanding our critical objectives – “Our key deliverables”.  Identifying what could prevent us from delivering our critical objectives – “What are the

barriers and risks”?

 Evaluating and measuring our risk controls – “Identifying residual risk”

 Determining how Victoria will continue to achieve its critical objectives in the event of interruptions.

The following steps describe how business continuity takes a holistic risk management approach.

2. Content and Guidelines

The Business Continuity Plan is made of three stages:  Assessing risks;

 Analysing the impact of an adverse event on a business and its primary objectives; and  Documenting the necessary tasks and roles which will enable the business to recover

from the adverse event.

2.1 Risk assessment

Managers are responsible for assessing risk and escalating where appropriate as part of their business as usual responsibilities. Assessing risk is about identifying the threats and barriers that may be present in our operating environment and considering organisational

interdependencies which may be complex and varied in the University setting. Refer to the

Risk Management – Guidelines for Managers.

1

(2)

2

2.2 Business Impact Analysis

The Business Impact Analysis is an integral component of the Business Continuity Plan. It provides the background upon which a plan is developed. In the analysis managers are responsible for identifying the key business processes and analysing the impacts of an emergency event to service delivery. The manager should identify the business goals, and define the critical functions, components, assets and resources required to achieve the intended outcome.

Key considerations include:

 The damage to Victoria (or the individual business unit) resulting from an intolerable adverse event.

 Determine whether the deliverable is required by legislation.

 The different levels of disaster (this should be recorded in the Emergency Response Plan.).  Identify the importance or criticality of the goals.

 Confirm whether they affect the critical or long term success of the University.

 Understand and define the maximum tolerable “down time” for each function and prioritise recovery.

Each manager should define the recovery requirements for the items identified above and the infrastructure and resources required to enable Victoria to continue to function at a minimum acceptable level.

 Recovery requirements:

 The timeframe in which the items above must resume or be replaced.  The business requirements for recovery of the above.

 The technical requirements for the above.

 The manual process in place that will mitigate loss of the above. (This will also be recorded in the unit’s risk management plan).

 Identification of dependencies

A sample impact analysis is included as Appendix 1

2.3 Guidelines for Business Continuity Plans – Appendix 2

Managers should consider the following components when developing their Business Continuity Plan (BCP):

a. Ensure that the business objectives are clearly understood and recorded. This can be informed by an annual business planor similar.

b. Define the scope of the BCP. What are the limitations? Consider the critical business requirements or deliverables and BAU requirements. This can be informed by the business impact analysis described above.

c. Ensure that the maximum acceptable outage is considered.

d. Ensure that the BCP is properly coordinated to take into account information derived from the risk register and Emergency Response Plan. BCM is a component in the risk

management loop.

e. Ensure that any assumptions made during the planning process are sufficiently explained and documented.

f. Record members of the BCM team and ensure that their roles are clearly defined. It is important that this is included in training and testing the plan.

g. If an internal audit has been completed in relation to BCM, ensure that recommendations are addressed.

(3)

3 i. Implement a process for independent review of the plan – the Safety and Risk team will

review the plan annually.

j. Consider back up processes, alternative accommodation and off site storage.

k. To ensure that the plan remains current implement programme of periodic testing and review the plan in line with organisational changes.

Supporting documentation and processes may include: a. Risk Management Plan and risk register. b. Emergency Response plan.

c. Safety Plan

d. Business Continuity Plan

References

(4)

4

Appendix 1 – Business Impact Analysis (Sample)

Business unit: Campus Operations, Safety & Risk Date: 02/09/10

Responsible manager: Title: Telephone #: BIA prepared by: Title: Telephone #: Business objective/goal Business process

Risk1 Key process2 Key assets Maximum

acceptable outage (Downtime) Recovery requirements3 Provide mail service to VUW Mail collection and delivery Service delivery

Receive mail Mail room 8 hrs depending on day of week. Maximum severity on Monday due to multiple mail bags received

Alternative premises

Sort mail Staff

Premises

8 hrs depending on day of week. Maximum severity on Monday due to multiple mail bags received

Alternative premises Second staff from Caretakers team

Dispatch mail Sorting system Staff Trolleys Road vehicle Franking m/c 16 hrs. Consequential business effect and recovery time increases.

Alternative premises Second staff from Caretakers team

Hire or loan road vehicle (Get home safe van)

Replacement trolley, hire or procure.

Replacement or hire franking m/c

Substitute franking m/c with postage stamps.

(5)

5

and contract contractor

Record and recover costs for courier services

Computer system/network Staff

2 weeks Align with ITC BCP

Second staff from

Caretakers team or Admin staff from Campus

Operations team. Record costs on paper record

Supervision to Mail room staff

Supervisor 8 hrs Provide cover from

Caretakers team.

1. From risk assessment. Risk category E.G. Financial, service delivery 2. Rank key process. Critical business process

(6)

6

Appendix 2

Business Continuity Plan – Guideline for Managers.

1. Cover page

Name of the organisation, service or school Author

Approval Date

Document control information 2. Table of contents

3. Recovery plan

3.1 Roles and responsibilities of key staff who will need to perform functions and make decisions during the recovery stage to BAU.

3.2 Identify how the service or school will respond to a business interruption.

4. Technical recovery plan

4.1 Identify technical or specialist business functions such as IT, Payroll, Finance. 4.2 Document contingency plans

4.3 Document recovery plans

4.4 Identify alternate recovery options

5. Supporting documentation

5.1 Document a list of procedures and processes.

5.2 Ensure relevant documentation to support the BCP is safely stored.

5.3 Link also to the Crisis Management Framework and Emergency Response Plan.

6.0 Contact information.

6.1 Detail a list of employees, contractors and suppliers.

6.2 Document the technical and business relationship between VUW support services, suppliers and schools?

6.3 Identify key staff required to populate the recovery teams and those who will be charged with making decisions during the recovery phase. This will include reference to appropriate delegations.

6.4 Identify the roles and responsibilities of the recovery team.

References

Related documents

The callus were kept in storage by repeated sub-culturing in in vitro condition on MS medium fortified with 0.2 mgl -1 2,4-D and the preservation could be extended for nine

Our results suggest that account and local cardholder characteristics significantly influence card life span, load and debit activities, the shares of purchase transactions and cash

Media culture manipulation by increasing the temperature of the media had more significant effect on increasing growth rate, biomass and free fatty acid content for Spirulina

A study published in the Journal of Food Protection in 2001 cited concerns regarding fungi (the source of mycotoxins) in commercial pet foods and warned about the “risk for

positioned senior managers, academics, students and others, in distinct ways. The imbalance of power was made particularly explicit when it came to informal student voice

All department Business Continuity Plans will be submitted to the Emergency Management Working Groups to ensure a coordinated response and for inclusion in Emergency Operation

• Developing and Implementing Business Continuity Plans • Awareness and Training Programs. • Maintaining and Exercising Business Continuity Programs •

Using Grassmann-Cayley Algebra, the geometric conditions associated with the dependency of six Pl ¨ucker vectors of finite and infinite lines in the projective space P 3