SlideShare ist ein Scribd-Unternehmen logo
1 von 21
Downloaden Sie, um offline zu lesen
1 
ISO22301 BCMS Implementation and Sharing of BCM Best Practices for an European Bank 
Stelios Aronis, BCCLA 
Head of Business Continuity 
Alpha Bank Group
2Alpha Bank Group Overview: 
•Alpha Bank s.a. founded in 1879 
•One of the largest banks in Greece: 
17.655 Employees (Greece: 11.911, International: 5.744) 
Over 1.000 service points (Branch Network) 
One of the highest capital adequacy rations in Europe. 
•International subsidiaries: 
i.Albania 
ii.Bulgaria 
iii.Cyprus 
iv.F.Y.R.O.M 
v.Romania 
vi.Serbia 
vii.United Kingdom 
•11 Subsidiaries in Greece (Investment Banking / Asset Management, Venture Capital, Leasing/Factoring, Insurance, Athens Hilton Hotel, etc) 
•Recently acquired consumer banking business of Citibank International Plc in Greece, including Diners Club. Our Values: Quality at work, Quality in communication, Meritocracy, Moral Standards, CreativityOur Vision: To be a bank of reference in Southeastern EuropeOur Aim: To provide high-quality services and pioneering products
3IS022301 –BCMS Certification: 
•Alpha Bank s.a. (parent company): 
Information Technology (including Data centers) 
Financial Markets –Treasury 
Back Office Operations: Funds Transfer operations / Cheques clearing / Treasury Back Office / Loans Administration / International Trade / Custody & Shareholders Registry / Cash Centers/ Alternative Networks Support / Private Banking Support. 
•Alpha Supporting Services:IT Infrastructure management and operation for Alpha Bank Group Subsidiaries in Greece and Abroad 
•Alpha Bank Romania:IT, Treasury, Back Office Operations (certification project in progress) Number of Personnel in sectors certified with ISO22301, exceeds 1300 people. 
Same BCM Methodology and procedures are applied to all Units of the Alpha Bank Group
CRITICAL FUNCTIONSBUSINESS CONTINUITY PLANDISASTER RECOVERY PLAN 
CRISIS MANAGEMENTEVACUATION PLAN 
PEOPLE / RESOURCES 
THREAT REMEDIATIONRISK ASSESSMENTCATASTROPHIC EVENTTELECOMMS DISRUPTIONFLOOD / EARTHQUAKEFIRE4HINTS ON SUCCESSFUL IMPLEMENTATION OF A BCMS
BCM METHODOLOGY –ISO22301 
PROJECT MANAGEMENTRISK ANALYSIS AND REVIEWBUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGY 
PLAN 
DEVELOPMENT 
5 
TESTING AND EXERCISING 
PROGRAM MANAGEMENT
6HINTS –PROJECT MANAGEMENT PHASEObtain Executive Management support and commitment: 
BCM Project Sponsor: Alpha Bank’s COO, member of Executive Board 
Project Steering Committee: Divisions’ Heads: Organization, Risk, IT, Information Security, International Network 
ProjectManager: Head of Group BCM Office 
Country Project Sponsor: IT & Operations Head (or COO) Resources: 
Group BCM Office: Central Point of communication and support 
Company BCM Offices/Coordinators(International Network) 
Business Unit BCM Coordinators 
External Consultants (optional)
7HINTS –PROJECT MANAGEMENT PHASEProject Definition Document: Indicative contents: 
Project Definition: Vision, Scope, Objectives, Deliverables 
Project Organization: Roles and Stakeholders, Communication Plan to Stakeholders (frequency of reporting, meetings, etc), Responsibilities per Role 
Project Plan / Milestones 
Project Considerations / Risks: 
Resourcing issues 
Project Dependencies (e.g. centralized systems) 
Country (local) Risks (e.g. premises availability) 
Legal / Compliance Issues
BCM METHODOLOGY –ISO22301 
PROJECT MANAGEMENTRISK ANALYSIS AND REVIEWBUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGY 
PLAN 
DEVELOPMENT 
8 
TESTING AND EXERCISING 
PROGRAM MANAGEMENT
9HINTS –RISK ANALYSIS PHASERisk Management Process (based on ISO 31000): RISK IDENTIFICATIONRISK ANALYSISRISK EVALUATIONRISK ASSESSMENT: RISK TREATMENTAPPROVAL BY OPERATIONAL RISK COMMITTEE OR EXECUTIVE BOARD!!! 
RCSA –Risk Control Self Assessment (BU Level) 
Threat & Risk Assessment (Organization Level) 
Premises & Physical Security 
IT / Information Security / Data Backup 
Critical Vendors / Service Providers (Outsourcing) 
Personnel Awareness on emergency proceduresESTABLISH CONTEXTRe-evaluate residual risk after Risk Treatment Plan implementation
BCM METHODOLOGY –ISO22301PROJECT MANAGEMENT 
RISK ANALYSIS AND REVIEW 
BUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGYPLANDEVELOPMENT10TESTING AND EXERCISINGPROGRAM MANAGEMENT
11HINTS –BIA PHASE 
•RTO (Recovery Time Objective)Definition: The maximum acceptable time interval within which an operation/business function must be resumed, so that there is no severe impact to the Organization. 
•RTO Scale: 
Same Day (1 or 8 hours) 
Next Day (24 hours) 
Within 3 Days 
Within a Week 
•METHODOLOGY: 
Data Collection and impact assessment 
Data Validation 
I.Data Completion Check 
II.RTO Validation against: 
oGroup RTO in respective or similar activities (benchmark) 
oPrevious year’s RTO of the respective Function / Activity 
oIndustry RTO Benchmarks (provided by external consultants) (any RTO variations should be justified by the Business Units) 
Final Confirmation by each Business Unit before formal issuance
12HINTS –BIA PHASECritical Business functions (“same day” recovery) 
•IT Infrastructure Management and Operations (Data Center) 
•Funds Transfers / Payments(Incoming, Outgoing) 
•LoansBackOffice 
•International Trade 
•Clearing(Cheques, Securities& Derivatives) 
•Trading (Front Office, Back Office and Controls over Limits) 
•Instant Credit (Loan Authorizations) 
•Relationship Management (Corporate/Private Banking, Shipping, etc.) 
•Customer Service / Help Desk 
•Credit Cards: Lost & Stolen Declaration /Transactions Authorizations and Disputes Resolution
BCM METHODOLOGY –ISO22301PROJECT MANAGEMENT 
RISK ANALYSIS AND REVIEW 
BUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGYPLANDEVELOPMENT13TESTING AND EXERCISINGPROGRAM MANAGEMENT
14HINTS –B.C. STRATEGY PHASEHOT SITEWARM SITE / DISPLACEMENTCOLD SITE3 Days or more“Next Day” recovery 
“Same Day” recovery 
DEFINITIONS: 
•HOT SITE: Fully equipped and preconfiguredfacilities which can be used for instant recovery of business operations 
•WARM SITE:Equipped but not preconfigured facilities. PCs are installed but require configuration before use 
•COLD SITE: Non equipped but “wired” empty space.
BCM METHODOLOGY –ISO22301 
PROJECT MANAGEMENTRISK ANALYSIS AND REVIEWBUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGYPLANDEVELOPMENT15TESTING AND EXERCISINGPROGRAM MANAGEMENT
16HINTS –PLAN DEVELOPMENT PHASEBCP GOVERNANCE: Emergency Management TeamInitial Response Team 
D.R. 
CoordinatorTECHNICAL TEAMS (Systems, Databases, Networks) 
Business Recovery Teams 
B.C. CoordinatorEmergency Support TeamEach team has specific roles and responsibilities that are documented in the Business Continuity Plan.
BCM METHODOLOGY –ISO22301PROJECT MANAGEMENTRISK ANALYSIS AND REVIEWBUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGYPLANDEVELOPMENT17TESTING AND EXERCISING 
PROGRAM MANAGEMENT
18 
HINTS –EXERCISING AND TESTINGTesting Scenarios: 
•Scenario1: Accessto premises is not feasible, but application and communication systems are intact 
•Scenario 2: Accessto premises is not feasible and also the application and communication systemsare not available (DR also activated) 
•Scenario 3: Premises are available for use, but application and communication systemsare not available (DR activation) 
•Scenario 4: More than 20% of the Personnel is not available for a period more than a week(e.g. due to Pandemic) 
•Scenario 5: Interruption in the operations of a critical service provider 
Internal Audit to be present in tests as an independent observer 
Record test details and results (use of template) 
Update Senior Management regularly on test results /corrective actionsAvoid Disruptions Caused by Plan Misuse!!!! Key Points:
BCM METHODOLOGY –ISO22301PROJECT MANAGEMENTRISK ANALYSIS AND REVIEWBUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGYPLANDEVELOPMENT23TESTING AND EXERCISINGPROGRAM MANAGEMENT
24HINTS –PROGRAM MANAGEMENTFOCUS ON CONTINIOUS IMPROVEMENT MAINTAINANCE & REVIEW 
Perform Internal Audits (ensure objectivity) 
Set goals / Monitor near misses 
Review / improve the Plan and the BCMSCOMPETENCE & AWARENESS 
Enhance BCM culture to the Organization 
Train and Educate Personnel (use of external certification bodies )
25THANK YOU FOR YOUR ATTENTION

Weitere ähnliche Inhalte

Was ist angesagt?

ERM-Enterprise Risk Management
ERM-Enterprise Risk ManagementERM-Enterprise Risk Management
ERM-Enterprise Risk Management
Jorge Vaz Girão , CISA, PMP, PMDPro I, ERMCP
 
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information StandardQuick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
PECB
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
Rishabh Software
 
Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance framework
Ceyeap
 

Was ist angesagt? (20)

2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdf2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdf
 
IT security consultancy company profile
IT security consultancy company profileIT security consultancy company profile
IT security consultancy company profile
 
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdfISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
 
ISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overview
 
ISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best Practice
 
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk MethodologyPECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
PECB Webinar: Aligning ISO 31000 and Management of Risk Methodology
 
Business Continuity Workshop Final
Business Continuity Workshop   FinalBusiness Continuity Workshop   Final
Business Continuity Workshop Final
 
CISA Summary V1.0
CISA Summary V1.0CISA Summary V1.0
CISA Summary V1.0
 
Iso 27001 awareness
Iso 27001 awarenessIso 27001 awareness
Iso 27001 awareness
 
ERM-Enterprise Risk Management
ERM-Enterprise Risk ManagementERM-Enterprise Risk Management
ERM-Enterprise Risk Management
 
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information StandardQuick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
 
Awareness iso 22301 danang suryo
Awareness iso 22301 danang suryoAwareness iso 22301 danang suryo
Awareness iso 22301 danang suryo
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
 
Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)
 
Enterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating ModelEnterprise Cybersecurity: From Strategy to Operating Model
Enterprise Cybersecurity: From Strategy to Operating Model
 
Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance framework
 
Risk Assessment Process NIST 800-30
Risk Assessment Process NIST 800-30Risk Assessment Process NIST 800-30
Risk Assessment Process NIST 800-30
 
CISA Domain- 1 - InfosecTrain
CISA Domain- 1  - InfosecTrainCISA Domain- 1  - InfosecTrain
CISA Domain- 1 - InfosecTrain
 
Iso 22301
Iso 22301Iso 22301
Iso 22301
 

Ähnlich wie Stelios Aronis ISO 22301 BCMS Implementation and Sharing of BCM Best Practices for an European Bank

Confluentia. Front to back analysis: Mortgage and asset-backed securities. Ca...
Confluentia. Front to back analysis: Mortgage and asset-backed securities. Ca...Confluentia. Front to back analysis: Mortgage and asset-backed securities. Ca...
Confluentia. Front to back analysis: Mortgage and asset-backed securities. Ca...
Confluentia
 
Key Career Primary Responsiblities
Key Career Primary ResponsiblitiesKey Career Primary Responsiblities
Key Career Primary Responsiblities
msrslide
 
Aravinda Nadig - Business Analyst
Aravinda Nadig - Business AnalystAravinda Nadig - Business Analyst
Aravinda Nadig - Business Analyst
Aravinda Nadig
 
CV Template Jack Bond
CV Template Jack BondCV Template Jack Bond
CV Template Jack Bond
Jack Bond
 
Cognizant_Introduction to management consulting in Switzerland
Cognizant_Introduction to management consulting in SwitzerlandCognizant_Introduction to management consulting in Switzerland
Cognizant_Introduction to management consulting in Switzerland
audrey miguel
 
Curriculum Vitae 20161012 - PM - (LinkedIn)
Curriculum Vitae 20161012 - PM - (LinkedIn)Curriculum Vitae 20161012 - PM - (LinkedIn)
Curriculum Vitae 20161012 - PM - (LinkedIn)
Nigel Thurston-Smith
 

Ähnlich wie Stelios Aronis ISO 22301 BCMS Implementation and Sharing of BCM Best Practices for an European Bank (20)

BA and Beyond 18 - Peter Maeseele and Meritxell Chavigne Jorba - Going agile ...
BA and Beyond 18 - Peter Maeseele and Meritxell Chavigne Jorba - Going agile ...BA and Beyond 18 - Peter Maeseele and Meritxell Chavigne Jorba - Going agile ...
BA and Beyond 18 - Peter Maeseele and Meritxell Chavigne Jorba - Going agile ...
 
Agile pgm
Agile pgmAgile pgm
Agile pgm
 
Confluentia. Front to back analysis: Mortgage and asset-backed securities. Ca...
Confluentia. Front to back analysis: Mortgage and asset-backed securities. Ca...Confluentia. Front to back analysis: Mortgage and asset-backed securities. Ca...
Confluentia. Front to back analysis: Mortgage and asset-backed securities. Ca...
 
Project Management Overview
Project Management OverviewProject Management Overview
Project Management Overview
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Suchasmita Padhi Resume
Suchasmita Padhi ResumeSuchasmita Padhi Resume
Suchasmita Padhi Resume
 
Key Career Primary Responsiblities
Key Career Primary ResponsiblitiesKey Career Primary Responsiblities
Key Career Primary Responsiblities
 
Practical experiences of portfolio management
Practical experiences of portfolio managementPractical experiences of portfolio management
Practical experiences of portfolio management
 
Fear and Loathing in Agility: Long Live the Accounting Department
Fear and Loathing in Agility: Long Live the Accounting DepartmentFear and Loathing in Agility: Long Live the Accounting Department
Fear and Loathing in Agility: Long Live the Accounting Department
 
Project portfolio management
Project portfolio managementProject portfolio management
Project portfolio management
 
Aravinda Nadig - Business Analyst
Aravinda Nadig - Business AnalystAravinda Nadig - Business Analyst
Aravinda Nadig - Business Analyst
 
PM
PMPM
PM
 
CV Template Jack Bond
CV Template Jack BondCV Template Jack Bond
CV Template Jack Bond
 
Elico Solutions' Odoo ERP Project Management Implementation Approach
Elico Solutions' Odoo ERP Project Management Implementation ApproachElico Solutions' Odoo ERP Project Management Implementation Approach
Elico Solutions' Odoo ERP Project Management Implementation Approach
 
Business Continuity Management: How to get started
Business Continuity Management: How to get startedBusiness Continuity Management: How to get started
Business Continuity Management: How to get started
 
Leveraging Your Security System to Impact Your Bottom line
Leveraging Your Security System to Impact Your Bottom lineLeveraging Your Security System to Impact Your Bottom line
Leveraging Your Security System to Impact Your Bottom line
 
IT Application Development - with SDLC.pptx
IT Application Development - with SDLC.pptxIT Application Development - with SDLC.pptx
IT Application Development - with SDLC.pptx
 
Cvjj portal english
Cvjj portal englishCvjj portal english
Cvjj portal english
 
Cognizant_Introduction to management consulting in Switzerland
Cognizant_Introduction to management consulting in SwitzerlandCognizant_Introduction to management consulting in Switzerland
Cognizant_Introduction to management consulting in Switzerland
 
Curriculum Vitae 20161012 - PM - (LinkedIn)
Curriculum Vitae 20161012 - PM - (LinkedIn)Curriculum Vitae 20161012 - PM - (LinkedIn)
Curriculum Vitae 20161012 - PM - (LinkedIn)
 

Mehr von BCM Institute

Mehr von BCM Institute (20)

Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
Business Continuity and Resilience: What Lies in the Future and What Steps Ca...
 
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...Enterprise Risk Management and Business Continuity: How Can They Work Togethe...
Enterprise Risk Management and Business Continuity: How Can They Work Togethe...
 
Winning Over The Challenges of Implementing BCM in a BPO by Jeremias Astrero,...
Winning Over The Challenges of Implementing BCM in a BPO by Jeremias Astrero,...Winning Over The Challenges of Implementing BCM in a BPO by Jeremias Astrero,...
Winning Over The Challenges of Implementing BCM in a BPO by Jeremias Astrero,...
 
Operational and Business Continuity Management Strategy for Multi-type Nation...
Operational and Business Continuity Management Strategy for Multi-type Nation...Operational and Business Continuity Management Strategy for Multi-type Nation...
Operational and Business Continuity Management Strategy for Multi-type Nation...
 
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...
Business Continuity Management in Healthcare by Dexter Chia, Director, GCOO's...
 
Does Your BCP Need A BCP - Outsourcing Business Continuity by Irene Lye, Ente...
Does Your BCP Need A BCP - Outsourcing Business Continuity by Irene Lye, Ente...Does Your BCP Need A BCP - Outsourcing Business Continuity by Irene Lye, Ente...
Does Your BCP Need A BCP - Outsourcing Business Continuity by Irene Lye, Ente...
 
The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...
The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...
The Evolving Role of BCM and its Importance in Any Industries by Dr Goh Moh H...
 
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...Experience Sharing - Risk Management, Crisis Management & BCM In An Education...
Experience Sharing - Risk Management, Crisis Management & BCM In An Education...
 
Planning For The Haze by Jeremy Wong, , Senior Vice President of GMH Continui...
Planning For The Haze by Jeremy Wong, , Senior Vice President of GMH Continui...Planning For The Haze by Jeremy Wong, , Senior Vice President of GMH Continui...
Planning For The Haze by Jeremy Wong, , Senior Vice President of GMH Continui...
 
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...
Challenges, Opportunities and Trends for BCM Profession by Dr Goh Moh Heng, P...
 
DR Plan Implementation Experience: A Government Agency's Perspective by Inthr...
DR Plan Implementation Experience: A Government Agency's Perspective by Inthr...DR Plan Implementation Experience: A Government Agency's Perspective by Inthr...
DR Plan Implementation Experience: A Government Agency's Perspective by Inthr...
 
Navigating The Path To BCM Excellence by Dr Suhazimah Dzazali, Deputy Directo...
Navigating The Path To BCM Excellence by Dr Suhazimah Dzazali, Deputy Directo...Navigating The Path To BCM Excellence by Dr Suhazimah Dzazali, Deputy Directo...
Navigating The Path To BCM Excellence by Dr Suhazimah Dzazali, Deputy Directo...
 
BCM Institute Course Schedule 2016
BCM Institute Course Schedule 2016BCM Institute Course Schedule 2016
BCM Institute Course Schedule 2016
 
Deploying A Crisis Management and Business Continuity Approach to Product Tam...
Deploying A Crisis Management and Business Continuity Approach to Product Tam...Deploying A Crisis Management and Business Continuity Approach to Product Tam...
Deploying A Crisis Management and Business Continuity Approach to Product Tam...
 
Cyber Resilience – Strengthening Cybersecurity Posture & Preparedness by Phil...
Cyber Resilience – Strengthening Cybersecurity Posture & Preparedness by Phil...Cyber Resilience – Strengthening Cybersecurity Posture & Preparedness by Phil...
Cyber Resilience – Strengthening Cybersecurity Posture & Preparedness by Phil...
 
Considerations for Developing Your Organisation’s Pandemic Plan by Jeremy Won...
Considerations for Developing Your Organisation’s Pandemic Plan by Jeremy Won...Considerations for Developing Your Organisation’s Pandemic Plan by Jeremy Won...
Considerations for Developing Your Organisation’s Pandemic Plan by Jeremy Won...
 
Pandemics & Infectious Diseases: Stepping Up Your Business Continuity Prepare...
Pandemics & Infectious Diseases: Stepping Up Your Business Continuity Prepare...Pandemics & Infectious Diseases: Stepping Up Your Business Continuity Prepare...
Pandemics & Infectious Diseases: Stepping Up Your Business Continuity Prepare...
 
Certified Crisis Management Professional Programme Brochure
Certified Crisis Management Professional Programme Brochure Certified Crisis Management Professional Programme Brochure
Certified Crisis Management Professional Programme Brochure
 
BCM Institute Malaysia Course Schedule 2015
BCM Institute Malaysia Course Schedule 2015 BCM Institute Malaysia Course Schedule 2015
BCM Institute Malaysia Course Schedule 2015
 
Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...
Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...
Dr Goh Moh Heng Building Your Organization Business Continuity Management Com...
 

Kürzlich hochgeladen

No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
Sheetaleventcompany
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
Kayode Fayemi
 
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
amilabibi1
 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
Kayode Fayemi
 

Kürzlich hochgeladen (20)

No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
No Advance 8868886958 Chandigarh Call Girls , Indian Call Girls For Full Nigh...
 
My Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle BaileyMy Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle Bailey
 
Air breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animalsAir breathing and respiratory adaptations in diver animals
Air breathing and respiratory adaptations in diver animals
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
 
ICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdfICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdf
 
Dreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIIDreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio III
 
Report Writing Webinar Training
Report Writing Webinar TrainingReport Writing Webinar Training
Report Writing Webinar Training
 
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
 
Introduction to Prompt Engineering (Focusing on ChatGPT)
Introduction to Prompt Engineering (Focusing on ChatGPT)Introduction to Prompt Engineering (Focusing on ChatGPT)
Introduction to Prompt Engineering (Focusing on ChatGPT)
 
BDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 97 Noida Escorts >༒8448380779 Escort Service
 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
 
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfAWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
 
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 93 Noida Escorts >༒8448380779 Escort Service
 
lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.
 
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
 
Dreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video TreatmentDreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video Treatment
 
Causes of poverty in France presentation.pptx
Causes of poverty in France presentation.pptxCauses of poverty in France presentation.pptx
Causes of poverty in France presentation.pptx
 
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
 
Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510
 
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdfThe workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
 

Stelios Aronis ISO 22301 BCMS Implementation and Sharing of BCM Best Practices for an European Bank

  • 1. 1 ISO22301 BCMS Implementation and Sharing of BCM Best Practices for an European Bank Stelios Aronis, BCCLA Head of Business Continuity Alpha Bank Group
  • 2. 2Alpha Bank Group Overview: •Alpha Bank s.a. founded in 1879 •One of the largest banks in Greece: 17.655 Employees (Greece: 11.911, International: 5.744) Over 1.000 service points (Branch Network) One of the highest capital adequacy rations in Europe. •International subsidiaries: i.Albania ii.Bulgaria iii.Cyprus iv.F.Y.R.O.M v.Romania vi.Serbia vii.United Kingdom •11 Subsidiaries in Greece (Investment Banking / Asset Management, Venture Capital, Leasing/Factoring, Insurance, Athens Hilton Hotel, etc) •Recently acquired consumer banking business of Citibank International Plc in Greece, including Diners Club. Our Values: Quality at work, Quality in communication, Meritocracy, Moral Standards, CreativityOur Vision: To be a bank of reference in Southeastern EuropeOur Aim: To provide high-quality services and pioneering products
  • 3. 3IS022301 –BCMS Certification: •Alpha Bank s.a. (parent company): Information Technology (including Data centers) Financial Markets –Treasury Back Office Operations: Funds Transfer operations / Cheques clearing / Treasury Back Office / Loans Administration / International Trade / Custody & Shareholders Registry / Cash Centers/ Alternative Networks Support / Private Banking Support. •Alpha Supporting Services:IT Infrastructure management and operation for Alpha Bank Group Subsidiaries in Greece and Abroad •Alpha Bank Romania:IT, Treasury, Back Office Operations (certification project in progress) Number of Personnel in sectors certified with ISO22301, exceeds 1300 people. Same BCM Methodology and procedures are applied to all Units of the Alpha Bank Group
  • 4. CRITICAL FUNCTIONSBUSINESS CONTINUITY PLANDISASTER RECOVERY PLAN CRISIS MANAGEMENTEVACUATION PLAN PEOPLE / RESOURCES THREAT REMEDIATIONRISK ASSESSMENTCATASTROPHIC EVENTTELECOMMS DISRUPTIONFLOOD / EARTHQUAKEFIRE4HINTS ON SUCCESSFUL IMPLEMENTATION OF A BCMS
  • 5. BCM METHODOLOGY –ISO22301 PROJECT MANAGEMENTRISK ANALYSIS AND REVIEWBUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGY PLAN DEVELOPMENT 5 TESTING AND EXERCISING PROGRAM MANAGEMENT
  • 6. 6HINTS –PROJECT MANAGEMENT PHASEObtain Executive Management support and commitment: BCM Project Sponsor: Alpha Bank’s COO, member of Executive Board Project Steering Committee: Divisions’ Heads: Organization, Risk, IT, Information Security, International Network ProjectManager: Head of Group BCM Office Country Project Sponsor: IT & Operations Head (or COO) Resources: Group BCM Office: Central Point of communication and support Company BCM Offices/Coordinators(International Network) Business Unit BCM Coordinators External Consultants (optional)
  • 7. 7HINTS –PROJECT MANAGEMENT PHASEProject Definition Document: Indicative contents: Project Definition: Vision, Scope, Objectives, Deliverables Project Organization: Roles and Stakeholders, Communication Plan to Stakeholders (frequency of reporting, meetings, etc), Responsibilities per Role Project Plan / Milestones Project Considerations / Risks: Resourcing issues Project Dependencies (e.g. centralized systems) Country (local) Risks (e.g. premises availability) Legal / Compliance Issues
  • 8. BCM METHODOLOGY –ISO22301 PROJECT MANAGEMENTRISK ANALYSIS AND REVIEWBUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGY PLAN DEVELOPMENT 8 TESTING AND EXERCISING PROGRAM MANAGEMENT
  • 9. 9HINTS –RISK ANALYSIS PHASERisk Management Process (based on ISO 31000): RISK IDENTIFICATIONRISK ANALYSISRISK EVALUATIONRISK ASSESSMENT: RISK TREATMENTAPPROVAL BY OPERATIONAL RISK COMMITTEE OR EXECUTIVE BOARD!!! RCSA –Risk Control Self Assessment (BU Level) Threat & Risk Assessment (Organization Level) Premises & Physical Security IT / Information Security / Data Backup Critical Vendors / Service Providers (Outsourcing) Personnel Awareness on emergency proceduresESTABLISH CONTEXTRe-evaluate residual risk after Risk Treatment Plan implementation
  • 10. BCM METHODOLOGY –ISO22301PROJECT MANAGEMENT RISK ANALYSIS AND REVIEW BUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGYPLANDEVELOPMENT10TESTING AND EXERCISINGPROGRAM MANAGEMENT
  • 11. 11HINTS –BIA PHASE •RTO (Recovery Time Objective)Definition: The maximum acceptable time interval within which an operation/business function must be resumed, so that there is no severe impact to the Organization. •RTO Scale: Same Day (1 or 8 hours) Next Day (24 hours) Within 3 Days Within a Week •METHODOLOGY: Data Collection and impact assessment Data Validation I.Data Completion Check II.RTO Validation against: oGroup RTO in respective or similar activities (benchmark) oPrevious year’s RTO of the respective Function / Activity oIndustry RTO Benchmarks (provided by external consultants) (any RTO variations should be justified by the Business Units) Final Confirmation by each Business Unit before formal issuance
  • 12. 12HINTS –BIA PHASECritical Business functions (“same day” recovery) •IT Infrastructure Management and Operations (Data Center) •Funds Transfers / Payments(Incoming, Outgoing) •LoansBackOffice •International Trade •Clearing(Cheques, Securities& Derivatives) •Trading (Front Office, Back Office and Controls over Limits) •Instant Credit (Loan Authorizations) •Relationship Management (Corporate/Private Banking, Shipping, etc.) •Customer Service / Help Desk •Credit Cards: Lost & Stolen Declaration /Transactions Authorizations and Disputes Resolution
  • 13. BCM METHODOLOGY –ISO22301PROJECT MANAGEMENT RISK ANALYSIS AND REVIEW BUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGYPLANDEVELOPMENT13TESTING AND EXERCISINGPROGRAM MANAGEMENT
  • 14. 14HINTS –B.C. STRATEGY PHASEHOT SITEWARM SITE / DISPLACEMENTCOLD SITE3 Days or more“Next Day” recovery “Same Day” recovery DEFINITIONS: •HOT SITE: Fully equipped and preconfiguredfacilities which can be used for instant recovery of business operations •WARM SITE:Equipped but not preconfigured facilities. PCs are installed but require configuration before use •COLD SITE: Non equipped but “wired” empty space.
  • 15. BCM METHODOLOGY –ISO22301 PROJECT MANAGEMENTRISK ANALYSIS AND REVIEWBUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGYPLANDEVELOPMENT15TESTING AND EXERCISINGPROGRAM MANAGEMENT
  • 16. 16HINTS –PLAN DEVELOPMENT PHASEBCP GOVERNANCE: Emergency Management TeamInitial Response Team D.R. CoordinatorTECHNICAL TEAMS (Systems, Databases, Networks) Business Recovery Teams B.C. CoordinatorEmergency Support TeamEach team has specific roles and responsibilities that are documented in the Business Continuity Plan.
  • 17. BCM METHODOLOGY –ISO22301PROJECT MANAGEMENTRISK ANALYSIS AND REVIEWBUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGYPLANDEVELOPMENT17TESTING AND EXERCISING PROGRAM MANAGEMENT
  • 18. 18 HINTS –EXERCISING AND TESTINGTesting Scenarios: •Scenario1: Accessto premises is not feasible, but application and communication systems are intact •Scenario 2: Accessto premises is not feasible and also the application and communication systemsare not available (DR also activated) •Scenario 3: Premises are available for use, but application and communication systemsare not available (DR activation) •Scenario 4: More than 20% of the Personnel is not available for a period more than a week(e.g. due to Pandemic) •Scenario 5: Interruption in the operations of a critical service provider Internal Audit to be present in tests as an independent observer Record test details and results (use of template) Update Senior Management regularly on test results /corrective actionsAvoid Disruptions Caused by Plan Misuse!!!! Key Points:
  • 19. BCM METHODOLOGY –ISO22301PROJECT MANAGEMENTRISK ANALYSIS AND REVIEWBUSINESS IMPACT ANALYSISBUSINESS CONTINUITY STRATEGYPLANDEVELOPMENT23TESTING AND EXERCISINGPROGRAM MANAGEMENT
  • 20. 24HINTS –PROGRAM MANAGEMENTFOCUS ON CONTINIOUS IMPROVEMENT MAINTAINANCE & REVIEW Perform Internal Audits (ensure objectivity) Set goals / Monitor near misses Review / improve the Plan and the BCMSCOMPETENCE & AWARENESS Enhance BCM culture to the Organization Train and Educate Personnel (use of external certification bodies )
  • 21. 25THANK YOU FOR YOUR ATTENTION