SlideShare ist ein Scribd-Unternehmen logo
1 von 15
The Business Continuity Institute
The Good Practice Guidelines – Real life
          Implementations



         Muhammad Ghazali
MBCI, CBCI, ISMS ISO 27001LA, BS25999 LA
   Associate Director – Head of BCM Service
       Protiviti Member firm Middle East
The Good Practice Guidelines

Why Good Practice Guidelines

The value of the GPG:

    Not Just What, but “Why” and
    “how”

    Baseline and common language

    Used for Entry examination

    Professional Reference document

    Stage-wise
The Good Practice Guidelines


1. BCM Program Management

2. Understanding the Organization

3. Determining BCM Strategies

4. Developing and Implementing

   BCM Response

5. Exercising Maintaining and

   Reviewing

6. Embedding BCM into Organization

   Culture
BCM Program Management


                        What                                            Why
1.   Develop the BCM Program
                                                        Objectives, Mission, Vision, Key
2.   Identification of owner/member and
                                                        Service, Product, future strategy,
     participants of Program
                                                        acquisitions, geographical scale,
3.   Development of BCM Policy of the organization
                                                        competitor strategy, regulatory
4.   Identification of inclusion and exclusion of the
                                                        obligation etc. etc..
     BCM Program
                                                                        How
5. Define and approve the scope of the program
                                                        Involve the Top Management
Examples:
                                                        team
         BCM Head – That’s probably you…
                                                        Review documents produced by
         BCM Steering Committee -Management
                                                        the organization
         BCM Roles – Strategic, Tactical and
                                                        • Business plans
         Operational
                                                        • Strategic plans
         BCM Forum – Selected team members
                                                        • Annual report
                                                        • Marketing report
A “Program” Not a “Project”

                 •   Set Objectives
                 •   See Obligations
Program Scope
                 •   Acceptable level of risk
                 •   Statutory, regulatory and contractual issues

                 • Top management commitment and approval
                 • Objectives of the business continuity and scope
                 • Communicated and reviewed
Organizational
    Policy       • Appropriate by nature, scale, complexity, geography
                   and criticality of business activities
                 • Reflect culture, dependencies and operating
                   environment

                 • Defined roles and responsibilities
Resources and
                 • Top management nominees / appointees
 Competence
                 • BCM competency
Understanding the Organization


                       What                                            Why
Know your                                                     Your Business depends on
         Process                                        •   Operations Staff/skills
                                                        •   Records/Data Assets
         People                                         •   Voice/Data Communications
         Infrastructures                                •   Facilities & Infrastructure
                                                        •   Equipment
         Environment
         Internal and external Suppliers
                                                                       How
         Threats to all requirement
                                                        There are three main activities to
         Impact of those threats
                                                        “Understanding the Organization”
{if you know your enemies and know yourself, you        • Business Impact Analysis (BIA)
will not be imperiled in a hundred battles} Sun Tzu     • Continuity Requirements
                                                          Analysis (CRA)
                                                        • Risk Assessment (RA)
Knowing Your Organization - Impact Analysis


Business Objectives      Key BIA Inputs                       Recovery Requirements as Output

                         Financial Impact
Key Business Areas       •   Lost sales revenue
                         •   Productivity loss
                         •   Permanent customer loss
                                                                  Recovery Time
                         •   Loss of interest income              Objective (RTO)
                         Operational Impacts
                         •   Brand image
 Critical Processes      •   Competitive advantage
                         •   Customer satisfaction
      - Business Lines   •   Increased regulatory oversight                             MTPOD
                         •   Employee Morale
      - Support Lines                                            Recovery Point
                         Management Tolerances                   Objective (RPO)
                         • Intolerable/acceptable downtime
                         • Intolerable/acceptable data loss


                         Resource Dependencies
                         •   Operations Staff                     Minimum
                         •   Records/Data Assets                  Operation
                         •   Voice/Data Communications
                         •   Facilities & Infrastructure
                                                                  Requirements
                         •   Equipment
Knowing Your Risks – Risk Assessment (RA)


 Business               Interviews
 Objectives           Questionnaires
                       Workshops

                                                  BIA
                        BIA of Critical
Critical Processes                            Dependency
                          Processes
                                            Impact over time



                                                                Business     Business
                                                               Continuity   Continuity
                                                                Strategy      Plans



                                             Risk Register
Key Risks / threats    Risk Assessment       Vulnerability
                                            Threats, Impact,
                                               Likelihood
Determining BCM Strategies


                        What                                          Why
                                                      Your Business requires to select
On the basis of your RTO (Recovery Time Objective),
                                                      Appropriate continuity options for
Recovery Point Objective (RPO) and Maximum
                                                      each activity that supports the
tolerable period of disruption (MTPOD), identify
                                                      delivery
strategies
• The faster you want it – the more it will cost!
Separation distance                                                     How
                                                      Asses Continuity options for each
• How far away do you need to be                      critical activity to following levels:
• Accessible yet recoverable                          1. Initial Continuity – to an initial
                                                           acceptable level
                                                      2. Recovery – to a sustainable
                                                           level
                                                      3. Resumption – back to the
                                                           normal level
Determining BCM Strategies – Considerations


Continuity Strategy    Continuity Strategy     Continuity Strategy
        for                    for                     for
  Key Processes            Technology               Facilities


                                                    Physical
Alternate processes        IT Systems
                                                 Location/Space

   Options to              Core / Main         Office Equipments/
   Customers               Application              Stationary


Alternate Channels      User/Branch Data
                           Processing             Power Supply
    of Delivery


Alternate methods       Data Center/Voice
                       and Communication        Communication
of communication


   Support to          Info. security / Data
                              Transfer           Transportation
   Customers
Developing & Implementing BCM Response


                        What                                            Why
The GPG identifies the following stages of response:
                                                        To identify and document
                                                        • Individual and Teams roles
• Emergency response – immediate actions
                                                        Actions required for
• Incident management – management of the
                                                            Invocation, Crisis, Incident,
  response to the incident
                                                                    Internal and
• Business/ IT Continuity – the initial business
                                                          External, Communication, call
  response to the
                                                                   lists, etc. etc.
  incident (essential activities at acceptable level)
                                                                         How
• Recovery – recovery of activities to sustainable        The Plan(s) developement include
  level                                                            Appoint an owner
• Resumption – resuming operations to ‘normal’               Define the objectives and scope
                                                           Create Teams for planning, response
                                                                Agree the responsibilities
                                                               Document actionable steps
                                                                    Populate the plan
                                                              Circulate and gather feedback
                                                                    Agree and validate
                                                                     Agree a program
Continuity Plans - Considerations

•   Simple language

•   Action Oriented – (Check list…)

•   Easy to access, maintain and

    Navigate

•   Plans are tools / guidelines to
use or follow in case required, do
not allow them to restrict your
thoughts and responses.
Exercising Maintaining and Reviewing


                          What                                         Why
Exercise                                                To Highlight doubtful assumptions
Verifies your assumptions about IT / Buss.              Provides Hidden information
Continuity                                              about
                                                        Gain confidence in exercice
Validates                                               participants
            Effectiveness of your plan                  Raise awareness of BCM
            Response of your teams                      Verify BCP/ IT Continuity Plans(s)
            Effectiveness of your strategies

Results offers Opportunities for improvement in                        How
                                                        Agree the Scope– what are your BCM
          Plans                                         priorities?
          Responses                                     Engage senior stakeholders
          Strategies                                    Communicate thoroughly –particularly
                                                        for senior staff
                                                        Plan frequently - Normal Business is
                                                        always Busy
                                                        Make sure the exercise type fits the
                                                        need
Embedding BCM into Organization Culture


                       What                                       Why
Let the organization know about BCM                Management Understanding of
Just like                                          Risk/ Impact/ Threat/Response
          Human Resource Management (HRM)
          Management Information System (MIS)      Transformation of understanding
          Financial Management System (FMS)        across the organizations
          Material / Supply Chain Management
          Procurement

Involve all members of the organization, because
                                                                 How
 Continuity is everyone Business                   •   Employee Handbook - Guidelines
                                                   •   BCM Business Cases
                                                   •   Email messages
                                                   •   Intranet BCP Web Site
                                                   •   New Employee Induction Program
                                                   •   Interactive Presentations with
                                                       Staff
                                                   •   Organize in-house Coaching
                                                       Sessions
The BCI GPG Presentation @ The BCI

Weitere ähnliche Inhalte

Was ist angesagt?

An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningNEBizRecovery
 
Implementing a Business Continuity Management System in Telecoms
Implementing a Business Continuity Management System in TelecomsImplementing a Business Continuity Management System in Telecoms
Implementing a Business Continuity Management System in TelecomsGlobal Risk Forum GRFDavos
 
How to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential StepsHow to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential StepsCase IQ
 
Business Continuity Plan PowerPoint Presentation Slides
Business Continuity Plan PowerPoint Presentation Slides Business Continuity Plan PowerPoint Presentation Slides
Business Continuity Plan PowerPoint Presentation Slides SlideTeam
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity PlanningDipankar Ghosh
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity ManagementECC International
 
Business continuity management system overveiw
Business continuity management system  overveiwBusiness continuity management system  overveiw
Business continuity management system overveiwNaresh Rao
 
Vulnerability assessment
Vulnerability assessment Vulnerability assessment
Vulnerability assessment Md Asif Hasan
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity PlanningJohn Wilson
 
ISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeMissionMode
 
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...Business Impact and Risk Assessments in Business Continuity and Disaster Reco...
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...Rochester Security Summit
 
Business Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesBusiness Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesSlideTeam
 
Environmental modeling and environmental impact assessments final
Environmental modeling and environmental impact assessments finalEnvironmental modeling and environmental impact assessments final
Environmental modeling and environmental impact assessments finalSanjay Singh
 
Bcm Business Continuity Management
Bcm Business Continuity ManagementBcm Business Continuity Management
Bcm Business Continuity ManagementBruno Storti
 
Planning to take action Objectives slideshare procedure
Planning to take action Objectives slideshare procedurePlanning to take action Objectives slideshare procedure
Planning to take action Objectives slideshare procedureTim Matthews
 
Developing and Managing Business Continuity Plan (BCP)
Developing and Managing Business Continuity Plan (BCP)Developing and Managing Business Continuity Plan (BCP)
Developing and Managing Business Continuity Plan (BCP)Goutama Bachtiar
 
ISO 22301 Business Continuity Management
ISO 22301 Business Continuity ManagementISO 22301 Business Continuity Management
ISO 22301 Business Continuity ManagementRamiro Cid
 

Was ist angesagt? (20)

An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery Planning
 
Implementing a Business Continuity Management System in Telecoms
Implementing a Business Continuity Management System in TelecomsImplementing a Business Continuity Management System in Telecoms
Implementing a Business Continuity Management System in Telecoms
 
Introduction to Business Continuity Management
Introduction to Business Continuity ManagementIntroduction to Business Continuity Management
Introduction to Business Continuity Management
 
How to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential StepsHow to Create a Risk Profile for Your Organization: 10 Essential Steps
How to Create a Risk Profile for Your Organization: 10 Essential Steps
 
Business Continuity Plan PowerPoint Presentation Slides
Business Continuity Plan PowerPoint Presentation Slides Business Continuity Plan PowerPoint Presentation Slides
Business Continuity Plan PowerPoint Presentation Slides
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Bcp
BcpBcp
Bcp
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
Strategic managment process
Strategic managment processStrategic managment process
Strategic managment process
 
Business continuity management system overveiw
Business continuity management system  overveiwBusiness continuity management system  overveiw
Business continuity management system overveiw
 
Vulnerability assessment
Vulnerability assessment Vulnerability assessment
Vulnerability assessment
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
ISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best PracticeISO 22301: The New Standard for Business Continuity Best Practice
ISO 22301: The New Standard for Business Continuity Best Practice
 
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...Business Impact and Risk Assessments in Business Continuity and Disaster Reco...
Business Impact and Risk Assessments in Business Continuity and Disaster Reco...
 
Business Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesBusiness Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation Slides
 
Environmental modeling and environmental impact assessments final
Environmental modeling and environmental impact assessments finalEnvironmental modeling and environmental impact assessments final
Environmental modeling and environmental impact assessments final
 
Bcm Business Continuity Management
Bcm Business Continuity ManagementBcm Business Continuity Management
Bcm Business Continuity Management
 
Planning to take action Objectives slideshare procedure
Planning to take action Objectives slideshare procedurePlanning to take action Objectives slideshare procedure
Planning to take action Objectives slideshare procedure
 
Developing and Managing Business Continuity Plan (BCP)
Developing and Managing Business Continuity Plan (BCP)Developing and Managing Business Continuity Plan (BCP)
Developing and Managing Business Continuity Plan (BCP)
 
ISO 22301 Business Continuity Management
ISO 22301 Business Continuity ManagementISO 22301 Business Continuity Management
ISO 22301 Business Continuity Management
 

Andere mochten auch

Crisis Communications_Plans and Exercises
Crisis Communications_Plans and ExercisesCrisis Communications_Plans and Exercises
Crisis Communications_Plans and ExercisesReginaPhelps
 
Comparison of ISO 22301 with BS 25999
Comparison of ISO 22301 with BS 25999Comparison of ISO 22301 with BS 25999
Comparison of ISO 22301 with BS 25999Steelhenge
 
Krizių komunikacija: trumpa apžvalga
Krizių komunikacija: trumpa apžvalgaKrizių komunikacija: trumpa apžvalga
Krizių komunikacija: trumpa apžvalgaLiutauras Ulevičius
 
Crisis Communication Simulation Exercise [Freberg]
Crisis Communication Simulation Exercise [Freberg]Crisis Communication Simulation Exercise [Freberg]
Crisis Communication Simulation Exercise [Freberg]Karen Freberg
 
Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery PresentationTimSchaefer
 
The A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoveryThe A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoverySirius
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IThhuihhui
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Narudom Roongsiriwong, CISSP
 
Crisis Management
Crisis ManagementCrisis Management
Crisis Managementeuweben01
 
Crisis management - Types and Examples
Crisis management - Types and ExamplesCrisis management - Types and Examples
Crisis management - Types and ExamplesNupur Bhardwaj
 

Andere mochten auch (10)

Crisis Communications_Plans and Exercises
Crisis Communications_Plans and ExercisesCrisis Communications_Plans and Exercises
Crisis Communications_Plans and Exercises
 
Comparison of ISO 22301 with BS 25999
Comparison of ISO 22301 with BS 25999Comparison of ISO 22301 with BS 25999
Comparison of ISO 22301 with BS 25999
 
Krizių komunikacija: trumpa apžvalga
Krizių komunikacija: trumpa apžvalgaKrizių komunikacija: trumpa apžvalga
Krizių komunikacija: trumpa apžvalga
 
Crisis Communication Simulation Exercise [Freberg]
Crisis Communication Simulation Exercise [Freberg]Crisis Communication Simulation Exercise [Freberg]
Crisis Communication Simulation Exercise [Freberg]
 
Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery Presentation
 
The A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoveryThe A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster Recovery
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
Crisis Management
Crisis ManagementCrisis Management
Crisis Management
 
Crisis management - Types and Examples
Crisis management - Types and ExamplesCrisis management - Types and Examples
Crisis management - Types and Examples
 

Ähnlich wie The BCI GPG Presentation @ The BCI

Business continuity management fundamentals update
Business continuity management fundamentals updateBusiness continuity management fundamentals update
Business continuity management fundamentals updateExo Futures
 
Krzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpiKrzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpibanqUP
 
Condensed Itu Workshop Report
Condensed Itu Workshop ReportCondensed Itu Workshop Report
Condensed Itu Workshop Reportjalilmaraicar
 
Bcp Dr Grant Thornton Llp(Danny Miller) Vfinal
Bcp Dr Grant Thornton Llp(Danny Miller) VfinalBcp Dr Grant Thornton Llp(Danny Miller) Vfinal
Bcp Dr Grant Thornton Llp(Danny Miller) VfinalDanny Miller
 
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy Modeler
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy ModelerRole Discovery and RBAC Design: A Case Study with IBM Role and Policy Modeler
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy ModelerProlifics
 
S&OP Leadership Exchange: Tailoring S&OP to Fit your Business
S&OP Leadership Exchange: Tailoring S&OP to Fit your BusinessS&OP Leadership Exchange: Tailoring S&OP to Fit your Business
S&OP Leadership Exchange: Tailoring S&OP to Fit your BusinessPlan4Demand
 
NFP Strategic Initiatives Process 2012
NFP Strategic Initiatives Process  2012NFP Strategic Initiatives Process  2012
NFP Strategic Initiatives Process 2012chaberkorn
 
Project design and management
Project design and managementProject design and management
Project design and managementAndrew Zolnai
 
Project Management in an Agency Environment
Project Management in an Agency Environment Project Management in an Agency Environment
Project Management in an Agency Environment Jeff Thaler
 
Ospmi Chapter Presentation
Ospmi Chapter PresentationOspmi Chapter Presentation
Ospmi Chapter PresentationDennis Bolles
 
Business Healthcheck Service By John Capper & Co
Business Healthcheck Service By John Capper & CoBusiness Healthcheck Service By John Capper & Co
Business Healthcheck Service By John Capper & CoJohn Capper & Co
 
Measuring the Results of your Agile Adoption
Measuring the Results of your Agile AdoptionMeasuring the Results of your Agile Adoption
Measuring the Results of your Agile AdoptionSoftware Guru
 
Syllabus capability maturity model
Syllabus capability maturity modelSyllabus capability maturity model
Syllabus capability maturity modelD&D Consulting
 
Managing cost and realising benefits from your SAP HCM or other HR system
Managing cost and realising benefits from your SAP HCM or other HR systemManaging cost and realising benefits from your SAP HCM or other HR system
Managing cost and realising benefits from your SAP HCM or other HR systemSven Ringling
 
Bpr training v 2.0 4.1.2012
Bpr training   v 2.0 4.1.2012Bpr training   v 2.0 4.1.2012
Bpr training v 2.0 4.1.2012Mohammad Saleh
 

Ähnlich wie The BCI GPG Presentation @ The BCI (20)

Business continuity management fundamentals update
Business continuity management fundamentals updateBusiness continuity management fundamentals update
Business continuity management fundamentals update
 
AdvisorAssist Compliance ROI
AdvisorAssist Compliance ROIAdvisorAssist Compliance ROI
AdvisorAssist Compliance ROI
 
Killing the Myth: Agile & CMMI
Killing the Myth: Agile & CMMIKilling the Myth: Agile & CMMI
Killing the Myth: Agile & CMMI
 
Krzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpiKrzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpi
 
Condensed Itu Workshop Report
Condensed Itu Workshop ReportCondensed Itu Workshop Report
Condensed Itu Workshop Report
 
Bpo risk management
Bpo risk managementBpo risk management
Bpo risk management
 
Bcp Dr Grant Thornton Llp(Danny Miller) Vfinal
Bcp Dr Grant Thornton Llp(Danny Miller) VfinalBcp Dr Grant Thornton Llp(Danny Miller) Vfinal
Bcp Dr Grant Thornton Llp(Danny Miller) Vfinal
 
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy Modeler
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy ModelerRole Discovery and RBAC Design: A Case Study with IBM Role and Policy Modeler
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy Modeler
 
S&OP Leadership Exchange: Tailoring S&OP to Fit your Business
S&OP Leadership Exchange: Tailoring S&OP to Fit your BusinessS&OP Leadership Exchange: Tailoring S&OP to Fit your Business
S&OP Leadership Exchange: Tailoring S&OP to Fit your Business
 
NFP Strategic Initiatives Process 2012
NFP Strategic Initiatives Process  2012NFP Strategic Initiatives Process  2012
NFP Strategic Initiatives Process 2012
 
Project design and management
Project design and managementProject design and management
Project design and management
 
Project Management in an Agency Environment
Project Management in an Agency Environment Project Management in an Agency Environment
Project Management in an Agency Environment
 
Ospmi Chapter Presentation
Ospmi Chapter PresentationOspmi Chapter Presentation
Ospmi Chapter Presentation
 
Business Healthcheck Service By John Capper & Co
Business Healthcheck Service By John Capper & CoBusiness Healthcheck Service By John Capper & Co
Business Healthcheck Service By John Capper & Co
 
Measuring the Results of your Agile Adoption
Measuring the Results of your Agile AdoptionMeasuring the Results of your Agile Adoption
Measuring the Results of your Agile Adoption
 
Crm for iit k
Crm for iit kCrm for iit k
Crm for iit k
 
How to Organize and Prioritize Requirements
How to Organize and Prioritize RequirementsHow to Organize and Prioritize Requirements
How to Organize and Prioritize Requirements
 
Syllabus capability maturity model
Syllabus capability maturity modelSyllabus capability maturity model
Syllabus capability maturity model
 
Managing cost and realising benefits from your SAP HCM or other HR system
Managing cost and realising benefits from your SAP HCM or other HR systemManaging cost and realising benefits from your SAP HCM or other HR system
Managing cost and realising benefits from your SAP HCM or other HR system
 
Bpr training v 2.0 4.1.2012
Bpr training   v 2.0 4.1.2012Bpr training   v 2.0 4.1.2012
Bpr training v 2.0 4.1.2012
 

Kürzlich hochgeladen

It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
A305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdfA305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdftbatkhuu1
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
Event mailer assignment progress report .pdf
Event mailer assignment progress report .pdfEvent mailer assignment progress report .pdf
Event mailer assignment progress report .pdftbatkhuu1
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Centuryrwgiffor
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesDipal Arora
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetCreating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetDenis Gagné
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 DelhiCall Girls in Delhi
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...Aggregage
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876dlhescort
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxpriyanshujha201
 

Kürzlich hochgeladen (20)

It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
A305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdfA305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdf
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
Event mailer assignment progress report .pdf
Event mailer assignment progress report .pdfEvent mailer assignment progress report .pdf
Event mailer assignment progress report .pdf
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetCreating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 

The BCI GPG Presentation @ The BCI

  • 1. The Business Continuity Institute The Good Practice Guidelines – Real life Implementations Muhammad Ghazali MBCI, CBCI, ISMS ISO 27001LA, BS25999 LA Associate Director – Head of BCM Service Protiviti Member firm Middle East
  • 2. The Good Practice Guidelines Why Good Practice Guidelines The value of the GPG: Not Just What, but “Why” and “how” Baseline and common language Used for Entry examination Professional Reference document Stage-wise
  • 3. The Good Practice Guidelines 1. BCM Program Management 2. Understanding the Organization 3. Determining BCM Strategies 4. Developing and Implementing BCM Response 5. Exercising Maintaining and Reviewing 6. Embedding BCM into Organization Culture
  • 4. BCM Program Management What Why 1. Develop the BCM Program Objectives, Mission, Vision, Key 2. Identification of owner/member and Service, Product, future strategy, participants of Program acquisitions, geographical scale, 3. Development of BCM Policy of the organization competitor strategy, regulatory 4. Identification of inclusion and exclusion of the obligation etc. etc.. BCM Program How 5. Define and approve the scope of the program Involve the Top Management Examples: team BCM Head – That’s probably you… Review documents produced by BCM Steering Committee -Management the organization BCM Roles – Strategic, Tactical and • Business plans Operational • Strategic plans BCM Forum – Selected team members • Annual report • Marketing report
  • 5. A “Program” Not a “Project” • Set Objectives • See Obligations Program Scope • Acceptable level of risk • Statutory, regulatory and contractual issues • Top management commitment and approval • Objectives of the business continuity and scope • Communicated and reviewed Organizational Policy • Appropriate by nature, scale, complexity, geography and criticality of business activities • Reflect culture, dependencies and operating environment • Defined roles and responsibilities Resources and • Top management nominees / appointees Competence • BCM competency
  • 6. Understanding the Organization What Why Know your Your Business depends on Process • Operations Staff/skills • Records/Data Assets People • Voice/Data Communications Infrastructures • Facilities & Infrastructure • Equipment Environment Internal and external Suppliers How Threats to all requirement There are three main activities to Impact of those threats “Understanding the Organization” {if you know your enemies and know yourself, you • Business Impact Analysis (BIA) will not be imperiled in a hundred battles} Sun Tzu • Continuity Requirements Analysis (CRA) • Risk Assessment (RA)
  • 7. Knowing Your Organization - Impact Analysis Business Objectives Key BIA Inputs Recovery Requirements as Output Financial Impact Key Business Areas • Lost sales revenue • Productivity loss • Permanent customer loss Recovery Time • Loss of interest income Objective (RTO) Operational Impacts • Brand image Critical Processes • Competitive advantage • Customer satisfaction - Business Lines • Increased regulatory oversight MTPOD • Employee Morale - Support Lines Recovery Point Management Tolerances Objective (RPO) • Intolerable/acceptable downtime • Intolerable/acceptable data loss Resource Dependencies • Operations Staff Minimum • Records/Data Assets Operation • Voice/Data Communications • Facilities & Infrastructure Requirements • Equipment
  • 8. Knowing Your Risks – Risk Assessment (RA) Business Interviews Objectives Questionnaires Workshops BIA BIA of Critical Critical Processes Dependency Processes Impact over time Business Business Continuity Continuity Strategy Plans Risk Register Key Risks / threats Risk Assessment Vulnerability Threats, Impact, Likelihood
  • 9. Determining BCM Strategies What Why Your Business requires to select On the basis of your RTO (Recovery Time Objective), Appropriate continuity options for Recovery Point Objective (RPO) and Maximum each activity that supports the tolerable period of disruption (MTPOD), identify delivery strategies • The faster you want it – the more it will cost! Separation distance How Asses Continuity options for each • How far away do you need to be critical activity to following levels: • Accessible yet recoverable 1. Initial Continuity – to an initial acceptable level 2. Recovery – to a sustainable level 3. Resumption – back to the normal level
  • 10. Determining BCM Strategies – Considerations Continuity Strategy Continuity Strategy Continuity Strategy for for for Key Processes Technology Facilities Physical Alternate processes IT Systems Location/Space Options to Core / Main Office Equipments/ Customers Application Stationary Alternate Channels User/Branch Data Processing Power Supply of Delivery Alternate methods Data Center/Voice and Communication Communication of communication Support to Info. security / Data Transfer Transportation Customers
  • 11. Developing & Implementing BCM Response What Why The GPG identifies the following stages of response: To identify and document • Individual and Teams roles • Emergency response – immediate actions Actions required for • Incident management – management of the Invocation, Crisis, Incident, response to the incident Internal and • Business/ IT Continuity – the initial business External, Communication, call response to the lists, etc. etc. incident (essential activities at acceptable level) How • Recovery – recovery of activities to sustainable The Plan(s) developement include level Appoint an owner • Resumption – resuming operations to ‘normal’ Define the objectives and scope Create Teams for planning, response Agree the responsibilities Document actionable steps Populate the plan Circulate and gather feedback Agree and validate Agree a program
  • 12. Continuity Plans - Considerations • Simple language • Action Oriented – (Check list…) • Easy to access, maintain and Navigate • Plans are tools / guidelines to use or follow in case required, do not allow them to restrict your thoughts and responses.
  • 13. Exercising Maintaining and Reviewing What Why Exercise To Highlight doubtful assumptions Verifies your assumptions about IT / Buss. Provides Hidden information Continuity about Gain confidence in exercice Validates participants Effectiveness of your plan Raise awareness of BCM Response of your teams Verify BCP/ IT Continuity Plans(s) Effectiveness of your strategies Results offers Opportunities for improvement in How Agree the Scope– what are your BCM Plans priorities? Responses Engage senior stakeholders Strategies Communicate thoroughly –particularly for senior staff Plan frequently - Normal Business is always Busy Make sure the exercise type fits the need
  • 14. Embedding BCM into Organization Culture What Why Let the organization know about BCM Management Understanding of Just like Risk/ Impact/ Threat/Response Human Resource Management (HRM) Management Information System (MIS) Transformation of understanding Financial Management System (FMS) across the organizations Material / Supply Chain Management Procurement Involve all members of the organization, because How Continuity is everyone Business • Employee Handbook - Guidelines • BCM Business Cases • Email messages • Intranet BCP Web Site • New Employee Induction Program • Interactive Presentations with Staff • Organize in-house Coaching Sessions