书签 分享 收藏 举报 版权申诉 / 77
上传文档赚钱

类型CBCP业务连续性管理专家培训材料-Area8课件.ppt

  • 上传人(卖家):晟晟文业
  • 文档编号:3911979
  • 上传时间:2022-10-24
  • 格式:PPT
  • 页数:77
  • 大小:441.57KB
  • 【下载声明】
    1. 本站全部试题类文档,若标题没写含答案,则无答案;标题注明含答案的文档,主观题也可能无答案。请谨慎下单,一旦售出,不予退换。
    2. 本站全部PPT文档均不含视频和音频,PPT中出现的音频或视频标识(或文字)仅表示流程,实际无音频或视频文件。请谨慎下单,一旦售出,不予退换。
    3. 本页资料《CBCP业务连续性管理专家培训材料-Area8课件.ppt》由用户(晟晟文业)主动上传,其收益全归该用户。163文库仅提供信息存储空间,仅对该用户上传内容的表现方式做保护处理,对上传内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知163文库(点击联系客服),我们立即给予删除!
    4. 请根据预览情况,自愿下载本文。本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
    5. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007及以上版本和PDF阅读器,压缩文件请下载最新的WinRAR软件解压。
    配套讲稿:

    如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。

    特殊限制:

    部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。

    关 键  词:
    CBCP 业务 连续性 管理 专家 培训 材料 _Area8 课件
    资源描述:

    1、Business Continuity ManagementCourse for Advanced Professionals Introduction1Subject Area 8:Maintaining&Exercising Business Continuity Plans2Lesson OverviewnElements of a testing&exercise programnTypes of tests and exercisesnBCM program maintenancenThe plan review and audit methodology nMaintaining

    2、the plan nChange factors nPlan document control proceduresnBCM program maintenance3Professional Practices forBusiness Continuity Professionals1.Project Initiation and Management2.Risk Evaluation and Control3.Business Impact Analysis4.Developing Business Continuity Strategies5.Emergency Response and

    3、Operations6.Developing and Implementing Business Continuity Plans7.Awareness and Training Programs8.Maintaining&Exercising Business Continuity Plans9.Crisis Communications10.Coordination with External Agencies4ObjectivesnPre-plan and coordinate plan exercises,and evaluate and document plan exercise

    4、results.Develop processes to maintain the currency of continuity capabilities and the Plan documents in accordance with the organization.s strategic direction.Verify that the Plans will prove effective by comparison with a suitable standard,and report results in a clear and concise manner.5The Profe

    5、ssionals Role(1/2)1.Pre-plan and Coordinate the Exercises2.Facilitate the Exercises3.Evaluate and Document the Exercise Results4.Update the Plan6The Professionals Role(2/2)1.Report Results/Evaluation to Management2.Coordinate Ongoing Plan Maintenance3.Assist in Establishing Audit Program for the Bus

    6、iness Continuity Plan7The Planning ProcessRiskAssessment&AnalysisPlanDevelopmentProjectPlanningStrategyDevelopmentBusiness Impact AnalysisAwareness&TrainingObjective Subject the plan to tests and exercises to ensure that it is operationalSome key tasks Establish objectives,scope and types of tests&e

    7、xercises Conduct the tests&exercisesSome key deliverables Post-test/exercise results,evaluations,&reports Plan revisionsTesting&Exercising8“The safety policy and procedures were in place:the practice was deficient.”extract from Lord Cullens report into the Piper Alpha disasterhttp:/news.bbc.co.uk/1/

    8、hi/uk/127335.stm9Definitions TestingnEquipmentnTechnologiesnDurable goods Server UPS device Generator Telecommunications ExercisingnPeople Evacuation procedures Call trees Familiarity with alternate locations Interim procedures Manual processes Self Assessment10Testing&Exercising Goal“The goal of te

    9、sting and exercising your plan is not to find out if it works,but to determine how it doesnt.”11Benefits of Testing&ExercisingnAssesses viability of plannPractice procedures before disasternSatisfies legal and internal audit requirementsnIdentifies areas that need modificationnEnables BCM program to

    10、 remain active,up-to-date,understood,and usable nDemonstrates the ability to recovernProvides a mechanism for maintaining and updating the plan12Benefits of Testing&Exercising I hear.I forget.I see.I rememberI do.I understandChinese Proverb13Commitment&MotivationnSenior management needs to understan

    11、d An untested/unexercised plan is unlikely to succeed in an actual disaster situation Program maintenance and plan review,updating and exercising is an integral part of the plan development and implementation process An untested/unexercised plan could,in an actual disruption be dangerousnSenior mana

    12、gement should support program by Reading reports Providing direction Allocating resources14Testing&Exercising MethodologynThe plans are tested to the fullest extent possiblenThe costs are not prohibitivenService disruptions are minimalnThe results provide a high degree of assurance in recovery capab

    13、ilitynEvaluation provides quality input to plan review and updates15Test&Exercise Program DesignnUse the scenario to design emergency situations that:Promote preparedness Improve response capability Validate plans,policies,procedures,and systems Determine effectiveness of command,control,and communi

    14、cation functions16Test&Exercise PrioritizationnPhased approach to exercising Start simple Build upon mastery Add complexity Target a comprehensive exercise17Test&Exercise PrioritizationnFunctional area criticality Those with roles&responsibilities in plannEarly participants can serve as valuable rol

    15、e models&advocates to other participantsnManagers who are“On the fence”18Testing/Exercising as part of Plan Life CycleFullcapabilityexercisedMinor elements testedExtent ofTest/ExerciseDuring plandesignPlan issuedPlan beingmaintained19Types of TestsnQuarterly evaluations of alert and notification pro

    16、cedures and systemsnEvaluate the ability to access current vital records,systems,and data management software and equipmentnEvaluate the logical support,services,and infrastructurenEvaluate communications20Types of TestsnStatic Essential components in placenDynamic Equipment satisfies operational re

    17、quirementsnFunctional Procedures for operating equipment are correct21How would you design a test to cover the different levels and functions?AccountsEmailCRMWeb serverfor salesApplicationDatabaseSystem&NetworkHardware22“This has been a test.In the eventof an actual emergency,Im outta here!”23Types

    18、of ExercisesnScheduled or surprisenPlan reviewnTabletop/desktopnWalk through/hands-onnModular/componentnFunctional/LOBnSimulation/mocknComprehensive/full-scale24Exercise Best PracticesnExercise public/private partnerships Emergency evacuations Shelter-in-place Hazardous materials drills Community Em

    19、ergency Response Teams(CERT)25Exercise Best PracticesnUse real-life situations to test emergency procedures Emergency Situation26Testing&Exercise ProgramBusiness Continuity PlanTesting/Exercise ProgramComprehensivePlan ReviewTabletopFunctionalModularWalkthroughSimulationSelf-Assessment27Confidential

    20、itynEstablish ground rules to address confidentialitynEnsure that confidential test data is protected after exercise28Test/Exercise FrequencynAt least annually or as significant changes occurnShould be ongoing and increase in complexitynDocument and budget BCM testing&exercising as an ongoing,multi-

    21、year program29Define Test&Exercise RequirementsnObjectives and levels of successnIdentify types of tests&exercisesnEstablish and document scopenProvide a schedule nLogistics and pre-planning componentsnPlan and reporting structure30Planning Test&Exercise ObjectivesnTo see if plan can be executednTo

    22、familiarize participants with plan nTo demonstrate plan is accurate and completenTo validate plans assumptionsnTo confirm that the plan will help to recover the organization31Planning&Coordinating ExercisesnDetermine scope of exercise What will be exercise?Elements of the worst-case scenario Who wil

    23、l be involved?Those with plan roles and responsibilities When will exercise occur and under what timeframe?Why will exercise occur?Where will the exercise occur?32Facilitating Tests&ExercisenFacilitation during tests&exercisesnPersonnelnMaterialsnProcedures in the test/exercise should be consistent

    24、with those required in an actual event33Evaluating Test/Exercise&ResultsnBC planning team and audit department might work together to evaluate a test or exercisenObservation or qualitative methodnDocumentation or quantitative method Use quantifiable criteria Compare timelines from previous exercises

    25、 Benchmark comparisons Measurable objectives Incident logs Legal,contractual,or regulatory requirementsnProvide feedback on results to participants 34Documenting Test/Exercise ResultsnPart of the permanent record of the organization Demonstrate due diligence Prudent business practices Chronicle the

    26、organizational BCM program commitment over time.Materials and reports generated during test/exercise Action items and issues logs Plan updates and changes Lessons learned Next steps35Analyzing ResultsnUse the forms provided nCompare expected performance to actual resultsnCompare exercise to prior te

    27、sts/exercisesnReference key recovery documents BIAnAnalyze information gathered36Analyzing ResultsnAnalyze and compare recovery timesnValidate that procedures are documented and up to datenValidate specific aspects of organizations BCM programnIs key scenario still valid?nIs overall recovery possibl

    28、e?Puzzle37Professional Practices forBusiness Continuity Professionals1.Project Initiation and Management2.Risk Evaluation and Control3.Business Impact Analysis4.Developing Business Continuity Strategies5.Emergency Response and Operations6.Developing and Implementing Business Continuity Plans 7.Aware

    29、ness and Training Programs8.Maintaining&Exercising Business Continuity Plans9.Crisis Communications10.Coordination with External Agencies38The Planning ProcessRiskAssessment&AnalysisPlanDevelopmentProjectPlanningStrategyDevelopmentBusiness ImpactAnalysisAwareness&TrainingObjective Update the Plan(s)

    30、constantly to reflect changed conditions in the organizationSome key tasks Perform periodic review and update at least annually Update when there are changes to the organizationSome key deliverables A current and actionable plan A change management processTesting&ExercisingBCM PlanMaintenance&Updati

    31、ng39BCM Maintenance ActivitiesExercisePlan Review&UpdatesTrainingAwarenessTechnologyProgramBusinessProject40Maintenance ObjectivenTo evaluate consistency within the plan,between the plan and other aspects of the overall program,and between the plans and the current characteristics of the organizatio

    32、n41Why Conduct a Plan Review and Audit?nOrganize,manage,and coordinate effects of changenEstablish standards to incorporate change on routine schedulenReduce negotiations on Who/How/When/Why/Where maintenance is donenClarify effects of change on interdependent recovery functions42Plan Review&Audit M

    33、ethodologynCreate goals&methods for conducting review Specific,measurable statements that elicit conclusions about whether the plan satisfies the objective(s)Should define how the team will go about collecting the necessary information43Plan Review&Audit MethodologynCritique organization and plans i

    34、nternal consistency to determine usabilitynDoes the plan incorporate RTO?nGain an understanding of functional requirements Check internal documents Review of service agreements44Plan Review&Audit MethodologynAddresses consistency Within plan Between plan and BCM program Between plan and current char

    35、acteristics of the organization Structure Business processes Outsourcing relationships45Plan Review&Audit MethodologynAuditsn Business continuity planner responsibilities1.Assist auditorn Auditor responsibilities1.Set audit objectives and scope 2.Assess and select audit method 3.Audit administrative

    36、 aspects of the BCM program4.Audit plan structure,content,and action sections5.Audit plan documentation control procedures46Plan Review&Audit MethodologynA plan review should involven Key staff of that plann Participants becoming familiar with the plan document n Participants validate that the plan

    37、represents strategies and objectivesn Participants revealing gaps,oversights,and mistakes47Plan Review&Audit MethodologynShould address(minimum)n Personnel and assigned recovery tasksn Personnel and contact numbers n Text(recovery procedure)changesn Back-up process and what is included n Periodic re

    38、views with known deadlines n Where input can be made to review process48GoalsnEfficient or effective?n Is your goal to be efficient?Maintaining the plan by doing the job on time and as expectedn Is your goal to be effective?Doing the right thing vs.doing the job rightnBe careful not to make changes

    39、that invalidate senior management and business unit approvals!49ObjectivesnDoes your plan measure up?n Is it accurate,thorough,and complete?n Is it logical and make suitable assumptions?n Does it support the resumption of necessary information systems and business processes within appropriate timefr

    40、ames?n Are management,personnel,and other stakeholders capable of executing plan?50Audit ObjectivesnIs the structure of plan correct?nIs plan and supporting documentation valid?nDo the assumptions and scope match the contents?nIs the team structure and members current?nAre the roles,responsibilities

    41、,and tasks current and executable?nIs the plan integrated and does it support any dependent plans and the overall organizational objectives?51Maintenance ResponsibilitiesnWho should review plan?n Business continuity staff n Auditors n Plan owners/dept.chairn Teams n Senior management n Other52Mainte

    42、nance ResponsibilitiesnExamples BCM planner directs and controls plan maintenance Team members are responsible for team sections Department heads are responsible for detail relating to their department BoD and senior management review and approve plan Internal audit examines plan to determine if it

    43、satisfies recovery objectives of organization,is accurate,and up-to-date Self Assessment53Maintenance SchedulenDevelop plan maintenance schedule Scheduled Time-driven Scheduled at decided time intervals at last annually Unscheduled Event-driven Result of major changes to organization Personnel Chang

    44、es to team member responsibilities Equipment54Maintaining PlansnMaintain the plan Select tools Monitor activities Establish update process Audit and control55Sources of change InformationnExercise resultsnOrganization directives,announcements,internal messages,strategic business meetingsnRegularly s

    45、cheduled meetings with recovery team leaders nChange management meetings56Change FactorsnChange in Procedure Organizational structure Personnel Physical Technology Recovery requirements Testing issues 57Change FactorsnTracking changes helps to Carry out more effective reviews Hold more effective exe

    46、rcises Point to areas of plan that need closer attention Develop scenarios for exercises58Documenting ReviewnDocument how review is carried out nWhat issues are encounterednConclusions reachednReview after plan is revisednEvaluate all versions of the plan nParticipation of individuals not on testing

    47、 team59Plan Component and Impact of ChangesChangeStrategiesRecoveryInstructionsRelocation InstructionsRequiredResourcesAdd/delete a business function or new line of businessMediumHighMediumMediumAdd/delete applicationsLowHighMediumMediumAdd/lose/change key staffLowLow MediumHighChange to the busines

    48、s functions recovery time objectives(RTOs)or recovery point objectives(RPOs)HighHighHighMediumChange of the business functions back-up strategies or the back-up/recovery technologyLow MediumMediumMedium60Plan Component and Impact of ChangesChangePlan1Plan2Plan3Plan4Add/delete a business function or

    49、new line of businessHighLowHighMediumAdd/delete applicationsMediumMediumLowHighAdd/lose/change key staffLowHighMediumLowChange to the business functions recovery time objectives(RTOs)or recovery point objectives(RPOs)MediumHighMediumLowChange of the business functions back-up strategies or the back-

    50、up/recovery technologyMediumLowHighMedium61Plan Maintenance LogBusiness Continuity PlanMaintenance DateSection NumberProcedureNumberReason forUpdateCommentsApproved By62Program Change&ImpactnExecutive sponsor Recognize and communicate organizational changesnSteering Committee Communicate between tea

    展开阅读全文
    提示  163文库所有资源均是用户自行上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作他用。
    关于本文
    本文标题:CBCP业务连续性管理专家培训材料-Area8课件.ppt
    链接地址:https://www.163wenku.com/p-3911979.html

    Copyright@ 2017-2037 Www.163WenKu.Com  网站版权所有  |  资源地图   
    IPC备案号:蜀ICP备2021032737号  | 川公网安备 51099002000191号


    侵权投诉QQ:3464097650  资料上传QQ:3464097650
       


    【声明】本站为“文档C2C交易模式”,即用户上传的文档直接卖给(下载)用户,本站只是网络空间服务平台,本站所有原创文档下载所得归上传人所有,如您发现上传作品侵犯了您的版权,请立刻联系我们并提供证据,我们将在3个工作日内予以改正。

    163文库