SlideShare ist ein Scribd-Unternehmen logo
1 von 19
Downloaden Sie, um offline zu lesen
Business Impact Analysis – Understanding
     what is required for BS 25999:2

               Hilary Estall
              28th April 2010
Contents
•   Introduction
•   Key elements of the BIA development process
•   Important terminology
•   Do’s and don’ts for certification to BS 25999:2
•   Lessons learnt from certified organisations
Straw Poll
• Hands up if you are seeking to align your BCM
  arrangements to BS 25999
• Hands up if you are planning to become
  certified to BS 25999
• Hands up if you have already achieved
  certification to BS 25999
• What are the drivers for your company to
  consider working with BS 25999?
Introduction
• 12 years experience in Management Systems
• In 2007 established BSI Business Continuity
  scheme for certifying companies to BS 25999
• Taken part in > 20 BS 25999 audits (at BSI)
• CBCI and AMBCI
• BCM/1 Committee Member
What to expect
• This presentation WILL    • This presentation WILL
  provide insight into        NOT tell you how to
  what BS 25999 Part 2        conduct a BIA for
  expects you to do to be     business continuity
  compliant (and to keep      management purposes
  the auditors happy)
• It will give you some
  tips on what to do and
  what to avoid
The BIA process
• Different ways (ie methodologies) to conduct
  a BIA. Questionnaires, workshops, 1 to 1’s.
• Choose wisely – what suits your business?
• The broader the involvement the better
• Ensure Top Management support (that means
  manpower and time!) to get best results
• The more time spent on the BIA the better
Key elements of the BIA development
process                                     Identify
                                         activities that
                   Critical activity      support the
                                                               Identify
                      resource           key products
                                                             impacts over
                    requirements          and services
                                                                 time




    RTO for the                                                              Establish the
  resumption of                             BIA                              MTPD for each
 critical activities                     Elements                               activity




                Determine what
                      BCM                                    Recovery priority
               arrangements are                               for all activities
                  in place for            Identify all       and identify the
               suppliers/Partners       dependencies         critical activities
                                          relevant to
                                       critical activities
BIA elements
• Ensure that BCMS scope includes the same
  key products and services as the BIA does
• Consider ALL activities that are performed to
  support its key products and services (not just
  critical ones). This will support the
  prioritisation process later
                    Audit Aware
  Auditors will expect to see a clear focus on the
  products and services that have been selected
BIA elements cont..
• Identify the impact to these activities if
  disrupted and how these would vary over time
                   Audit aware
  Be able to discuss what the business considers
  to be the biggest impacts and why
  Be able to discuss what timeframes were
  selected and why. (eg. Peak work periods).
  What is the link back to business priorities?
BIA elements cont..
• Establish the Maximum Tolerable Period of
  Disruption (MTPD) for each activity
• Prioritise activities for recovery and identify
  the critical activities

• Remember that activities not considered
  critical now may become so during a
  disruption
BIA elements cont..
• Identify all dependencies on critical activities
  including suppliers and outsource partners
• Determine BCM arrangements for the
  suppliers/outsourced partners on whom
  critical activities depend
                     Audit Aware
• This goes beyond asking if they have a BC
  Policy. Demonstrate a deeper understanding
  of their arrangements for the relevant
  products and services that they provide to you
Important terminology
• Maximum Tolerable Period of Disruption
  “Duration after which an organisation’s viability will
    be irrevocably threatened if product and service
    delivery cannot be resumed” BS 25999:1

• Recovery Time Objective
  “Target time set for resumption of product, service
    or activity delivery after an incident” BS 25999:1
Maximum Tolerable Period of
                     Disruption
               • Overall BCMS entity (based on chosen scope)
Organisation




               • Corporate level definition or
 Product or
  Service      • Deliverable outputs

               • Operational relationship with Product/Services or
  Activity     • Support/Strategic relationship


               • Resources, suppliers, outsource partners etc
Dependencies
Recovery Time Objective
• Use the same approach as for MTPD (4 levels)

• Expand the application of RTO’s to beyond
  critical activities to include product/service
  and dependencies
Clarification provided by BCM/1
• BCM/1 approved a clarification note in June
  2009 to help BCM practitioners
• Published on Continuity Central website
http://www.continuitycentral.com/feature0677.
  html
• Article on MTPD by Jacque Rupert
http://www.continuitycentral.com/feature0675.
  html
Do’s and don’ts for certification to
       BS 25999:2 (BIA only)
• DO make sure that Top     • DON’T adopt a
  Management are fully        template mentality and
  aware of BIA findings       copy someone else’s
  and are able to discuss     BIA format for the sake
  them                        of it
• DO be able to justify the • DON’T over complicate
  methodology & content       the BIA so that it
  of your BIA                 becomes a monster
• DO adhere to every
  clause requirement
Lessons learnt from certified
            organisations
• “Seek contributions from a wide range of staff”
• “Take sufficient time to get it right. If you do your
  BIA properly, writing plans becomes very easy”
• “Engage key customers and suppliers”
• “Make sure you have evidence that you have covered
  every element of the standard.”
• “the template in particular has evolved through
  multiple iterations based on user feedback.”
Thanks for listening

       Hilary Estall

Hilary.estall@pslinfo.co.uk
    www.pslinfo.co.uk

Weitere ähnliche Inhalte

Was ist angesagt?

Business Continuity Planning Seminar
Business Continuity Planning SeminarBusiness Continuity Planning Seminar
Business Continuity Planning Seminarcmckinney
 
02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIABCM Institute
 
Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planingHanaysha
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planninggcleary
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Narudom Roongsiriwong, CISSP
 
How to write an IT DR plan
How to write an IT DR planHow to write an IT DR plan
How to write an IT DR planDatabarracks
 
Business Continuity Workshop Final
Business Continuity Workshop   FinalBusiness Continuity Workshop   Final
Business Continuity Workshop FinalBill Lisse
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery PlanningJohn Wilson
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planningalanlund
 
Business continuity planning and disaster recovery
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recoverymadunix
 
Business continuity planning
Business continuity planningBusiness continuity planning
Business continuity planningSandeep Kashyap
 
business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929Andy Willams
 
Managing and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's FirstManaging and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's FirstBCM Institute
 
IT Governance - Capability Assessment using COBIT 5
IT Governance - Capability Assessment using COBIT 5IT Governance - Capability Assessment using COBIT 5
IT Governance - Capability Assessment using COBIT 5Eryk Budi Pratama
 
Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301mascot4u
 

Was ist angesagt? (20)

Business Continuity Planning Seminar
Business Continuity Planning SeminarBusiness Continuity Planning Seminar
Business Continuity Planning Seminar
 
02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA
 
Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planing
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
How to write an IT DR plan
How to write an IT DR planHow to write an IT DR plan
How to write an IT DR plan
 
Business Continuity Workshop Final
Business Continuity Workshop   FinalBusiness Continuity Workshop   Final
Business Continuity Workshop Final
 
Bcp drp
Bcp drpBcp drp
Bcp drp
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery Planning
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Business continuity planning and disaster recovery
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recovery
 
Business continuity planning
Business continuity planningBusiness continuity planning
Business continuity planning
 
business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929
 
Managing and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's FirstManaging and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's First
 
9 Bcp+Drp
9 Bcp+Drp9 Bcp+Drp
9 Bcp+Drp
 
Iso 20000 presentation
Iso 20000 presentationIso 20000 presentation
Iso 20000 presentation
 
IT Governance - Capability Assessment using COBIT 5
IT Governance - Capability Assessment using COBIT 5IT Governance - Capability Assessment using COBIT 5
IT Governance - Capability Assessment using COBIT 5
 
Business Continuity Planning Presentation
Business Continuity Planning PresentationBusiness Continuity Planning Presentation
Business Continuity Planning Presentation
 
BCP Awareness
BCP Awareness BCP Awareness
BCP Awareness
 
Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301
 

Andere mochten auch

Bs25999 business continuity implementation
Bs25999 business continuity implementationBs25999 business continuity implementation
Bs25999 business continuity implementationiso27001consulting
 
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015Digital Queensland
 
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...Digital Queensland
 
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...Digital Queensland
 
Business Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In PracticeBusiness Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In PracticeDipankar Ghosh
 

Andere mochten auch (6)

Bs25999 business continuity implementation
Bs25999 business continuity implementationBs25999 business continuity implementation
Bs25999 business continuity implementation
 
Business Continuity.Bs25999
Business Continuity.Bs25999Business Continuity.Bs25999
Business Continuity.Bs25999
 
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015
 
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...
 
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...
 
Business Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In PracticeBusiness Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In Practice
 

Ähnlich wie Technical Briefing: Business Impact Analysis: understanding what is required for BS 25999

How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?Abdul Naseer
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...PECB
 
Business Continuity Management: How to get started
Business Continuity Management: How to get startedBusiness Continuity Management: How to get started
Business Continuity Management: How to get startedIT Governance Ltd
 
The project manager and business analyst partnership - ensuring project success
The project manager and business analyst partnership - ensuring project successThe project manager and business analyst partnership - ensuring project success
The project manager and business analyst partnership - ensuring project successMark Troncone MBA, PMP, CBAP, ITILv3, CSM
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity ManagementECC International
 
Business continuity management system overveiw
Business continuity management system  overveiwBusiness continuity management system  overveiw
Business continuity management system overveiwNaresh Rao
 
EBR's: prepping, producing, and presenting
EBR's: prepping, producing, and presentingEBR's: prepping, producing, and presenting
EBR's: prepping, producing, and presentingGainsight
 
BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...BCM Institute
 
Sami Tayara BI Presentation ATT Jan07B
Sami Tayara BI Presentation ATT Jan07BSami Tayara BI Presentation ATT Jan07B
Sami Tayara BI Presentation ATT Jan07BSami Tayara
 
Business continuity management www.reconglobal.in
Business continuity management   www.reconglobal.inBusiness continuity management   www.reconglobal.in
Business continuity management www.reconglobal.inSatya Yadav
 
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...TheBCI
 
NQA ISO 22301 Business Continuity Checklist
NQA ISO 22301 Business Continuity ChecklistNQA ISO 22301 Business Continuity Checklist
NQA ISO 22301 Business Continuity ChecklistNQA
 
How Business Process Assurance Can Enhance Quality When Applying Agile Method...
How Business Process Assurance Can Enhance Quality When Applying Agile Method...How Business Process Assurance Can Enhance Quality When Applying Agile Method...
How Business Process Assurance Can Enhance Quality When Applying Agile Method...Cognizant
 
Bpr training v 2.0 4.1.2012
Bpr training   v 2.0 4.1.2012Bpr training   v 2.0 4.1.2012
Bpr training v 2.0 4.1.2012Mohammad Saleh
 
90 days to make a difference - approach
90 days to make a difference - approach90 days to make a difference - approach
90 days to make a difference - approachStuart Creasey
 
An introduction to an effective earned value management system (EVMS) webinar...
An introduction to an effective earned value management system (EVMS) webinar...An introduction to an effective earned value management system (EVMS) webinar...
An introduction to an effective earned value management system (EVMS) webinar...Association for Project Management
 

Ähnlich wie Technical Briefing: Business Impact Analysis: understanding what is required for BS 25999 (20)

How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
 
Business Continuity Management: How to get started
Business Continuity Management: How to get startedBusiness Continuity Management: How to get started
Business Continuity Management: How to get started
 
The project manager and business analyst partnership - ensuring project success
The project manager and business analyst partnership - ensuring project successThe project manager and business analyst partnership - ensuring project success
The project manager and business analyst partnership - ensuring project success
 
Cisco Data Sheet SORM
Cisco Data Sheet SORM Cisco Data Sheet SORM
Cisco Data Sheet SORM
 
CISSP Chapter 1 BCP
CISSP Chapter 1 BCPCISSP Chapter 1 BCP
CISSP Chapter 1 BCP
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
Business continuity management system overveiw
Business continuity management system  overveiwBusiness continuity management system  overveiw
Business continuity management system overveiw
 
Business Continuity Audit
Business Continuity AuditBusiness Continuity Audit
Business Continuity Audit
 
SAMA BCM Framework
SAMA BCM Framework SAMA BCM Framework
SAMA BCM Framework
 
EBR's: prepping, producing, and presenting
EBR's: prepping, producing, and presentingEBR's: prepping, producing, and presenting
EBR's: prepping, producing, and presenting
 
BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...
 
Sami Tayara BI Presentation ATT Jan07B
Sami Tayara BI Presentation ATT Jan07BSami Tayara BI Presentation ATT Jan07B
Sami Tayara BI Presentation ATT Jan07B
 
Business continuity management www.reconglobal.in
Business continuity management   www.reconglobal.inBusiness continuity management   www.reconglobal.in
Business continuity management www.reconglobal.in
 
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...
 
NQA ISO 22301 Business Continuity Checklist
NQA ISO 22301 Business Continuity ChecklistNQA ISO 22301 Business Continuity Checklist
NQA ISO 22301 Business Continuity Checklist
 
How Business Process Assurance Can Enhance Quality When Applying Agile Method...
How Business Process Assurance Can Enhance Quality When Applying Agile Method...How Business Process Assurance Can Enhance Quality When Applying Agile Method...
How Business Process Assurance Can Enhance Quality When Applying Agile Method...
 
Bpr training v 2.0 4.1.2012
Bpr training   v 2.0 4.1.2012Bpr training   v 2.0 4.1.2012
Bpr training v 2.0 4.1.2012
 
90 days to make a difference - approach
90 days to make a difference - approach90 days to make a difference - approach
90 days to make a difference - approach
 
An introduction to an effective earned value management system (EVMS) webinar...
An introduction to an effective earned value management system (EVMS) webinar...An introduction to an effective earned value management system (EVMS) webinar...
An introduction to an effective earned value management system (EVMS) webinar...
 

Mehr von BSI British Standards Institution

BSI Brochure: Customer Contact Association Global Standard - Your partner for...
BSI Brochure: Customer Contact Association Global Standard - Your partner for...BSI Brochure: Customer Contact Association Global Standard - Your partner for...
BSI Brochure: Customer Contact Association Global Standard - Your partner for...BSI British Standards Institution
 
Guide to making a new standard - Standards & Standardization - Making a New W...
Guide to making a new standard - Standards & Standardization - Making a New W...Guide to making a new standard - Standards & Standardization - Making a New W...
Guide to making a new standard - Standards & Standardization - Making a New W...BSI British Standards Institution
 
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE Direc...
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE  Direc...PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE  Direc...
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE Direc...BSI British Standards Institution
 
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...BSI British Standards Institution
 
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?BSI British Standards Institution
 
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...BSI British Standards Institution
 

Mehr von BSI British Standards Institution (20)

BSI Brochure: Customer Contact Association Global Standard - Your partner for...
BSI Brochure: Customer Contact Association Global Standard - Your partner for...BSI Brochure: Customer Contact Association Global Standard - Your partner for...
BSI Brochure: Customer Contact Association Global Standard - Your partner for...
 
BSI's Top 10 standards that matter to consumers
BSI's Top 10 standards that matter to consumersBSI's Top 10 standards that matter to consumers
BSI's Top 10 standards that matter to consumers
 
BSI leaflet on easy-to-open packaging
BSI leaflet on easy-to-open packagingBSI leaflet on easy-to-open packaging
BSI leaflet on easy-to-open packaging
 
Defining social responsibility with BS ISO 26000
Defining social responsibility with BS ISO 26000Defining social responsibility with BS ISO 26000
Defining social responsibility with BS ISO 26000
 
Guide to making a new standard - Standards & Standardization - Making a New W...
Guide to making a new standard - Standards & Standardization - Making a New W...Guide to making a new standard - Standards & Standardization - Making a New W...
Guide to making a new standard - Standards & Standardization - Making a New W...
 
Standards & standardization handout
Standards & standardization handoutStandards & standardization handout
Standards & standardization handout
 
A proposal for working with higher education
A proposal for working with higher educationA proposal for working with higher education
A proposal for working with higher education
 
Standards and standardization
Standards and standardization Standards and standardization
Standards and standardization
 
Standards and standardization
Standards and standardizationStandards and standardization
Standards and standardization
 
The perfect business continuity manager
The perfect business continuity managerThe perfect business continuity manager
The perfect business continuity manager
 
Nano website presentation bsi template december 2010
Nano website presentation bsi template december 2010Nano website presentation bsi template december 2010
Nano website presentation bsi template december 2010
 
Nano website presentation bsi template december 2010
Nano website presentation bsi template december 2010Nano website presentation bsi template december 2010
Nano website presentation bsi template december 2010
 
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE Direc...
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE  Direc...PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE  Direc...
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE Direc...
 
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...
 
Fire safety brochure
Fire safety brochureFire safety brochure
Fire safety brochure
 
BSI Presentation: Working with Higher Education
BSI Presentation: Working with Higher EducationBSI Presentation: Working with Higher Education
BSI Presentation: Working with Higher Education
 
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?
 
Case Study: BS25999 in a multi-site enterprise
Case Study: BS25999 in a multi-site enterpriseCase Study: BS25999 in a multi-site enterprise
Case Study: BS25999 in a multi-site enterprise
 
PD25888: Recovery Planning
PD25888: Recovery PlanningPD25888: Recovery Planning
PD25888: Recovery Planning
 
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...
 

Kürzlich hochgeladen

BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLkapoorjyoti4444
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with CultureSeta Wicaksana
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Sheetaleventcompany
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...lizamodels9
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentationuneakwhite
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperityhemanthkumar470700
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfAmzadHosen3
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfAdmir Softic
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxWorkforce Group
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityEric T. Tung
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...Aggregage
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...daisycvs
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataExhibitors Data
 
Phases of negotiation .pptx
 Phases of negotiation .pptx Phases of negotiation .pptx
Phases of negotiation .pptxnandhinijagan9867
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noidadlhescort
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableSeo
 

Kürzlich hochgeladen (20)

BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdf
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors Data
 
Phases of negotiation .pptx
 Phases of negotiation .pptx Phases of negotiation .pptx
Phases of negotiation .pptx
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 

Technical Briefing: Business Impact Analysis: understanding what is required for BS 25999

  • 1. Business Impact Analysis – Understanding what is required for BS 25999:2 Hilary Estall 28th April 2010
  • 2. Contents • Introduction • Key elements of the BIA development process • Important terminology • Do’s and don’ts for certification to BS 25999:2 • Lessons learnt from certified organisations
  • 3. Straw Poll • Hands up if you are seeking to align your BCM arrangements to BS 25999 • Hands up if you are planning to become certified to BS 25999 • Hands up if you have already achieved certification to BS 25999 • What are the drivers for your company to consider working with BS 25999?
  • 4. Introduction • 12 years experience in Management Systems • In 2007 established BSI Business Continuity scheme for certifying companies to BS 25999 • Taken part in > 20 BS 25999 audits (at BSI) • CBCI and AMBCI • BCM/1 Committee Member
  • 5. What to expect • This presentation WILL • This presentation WILL provide insight into NOT tell you how to what BS 25999 Part 2 conduct a BIA for expects you to do to be business continuity compliant (and to keep management purposes the auditors happy) • It will give you some tips on what to do and what to avoid
  • 6.
  • 7. The BIA process • Different ways (ie methodologies) to conduct a BIA. Questionnaires, workshops, 1 to 1’s. • Choose wisely – what suits your business? • The broader the involvement the better • Ensure Top Management support (that means manpower and time!) to get best results • The more time spent on the BIA the better
  • 8. Key elements of the BIA development process Identify activities that Critical activity support the Identify resource key products impacts over requirements and services time RTO for the Establish the resumption of BIA MTPD for each critical activities Elements activity Determine what BCM Recovery priority arrangements are for all activities in place for Identify all and identify the suppliers/Partners dependencies critical activities relevant to critical activities
  • 9. BIA elements • Ensure that BCMS scope includes the same key products and services as the BIA does • Consider ALL activities that are performed to support its key products and services (not just critical ones). This will support the prioritisation process later Audit Aware Auditors will expect to see a clear focus on the products and services that have been selected
  • 10. BIA elements cont.. • Identify the impact to these activities if disrupted and how these would vary over time Audit aware Be able to discuss what the business considers to be the biggest impacts and why Be able to discuss what timeframes were selected and why. (eg. Peak work periods). What is the link back to business priorities?
  • 11. BIA elements cont.. • Establish the Maximum Tolerable Period of Disruption (MTPD) for each activity • Prioritise activities for recovery and identify the critical activities • Remember that activities not considered critical now may become so during a disruption
  • 12. BIA elements cont.. • Identify all dependencies on critical activities including suppliers and outsource partners • Determine BCM arrangements for the suppliers/outsourced partners on whom critical activities depend Audit Aware • This goes beyond asking if they have a BC Policy. Demonstrate a deeper understanding of their arrangements for the relevant products and services that they provide to you
  • 13. Important terminology • Maximum Tolerable Period of Disruption “Duration after which an organisation’s viability will be irrevocably threatened if product and service delivery cannot be resumed” BS 25999:1 • Recovery Time Objective “Target time set for resumption of product, service or activity delivery after an incident” BS 25999:1
  • 14. Maximum Tolerable Period of Disruption • Overall BCMS entity (based on chosen scope) Organisation • Corporate level definition or Product or Service • Deliverable outputs • Operational relationship with Product/Services or Activity • Support/Strategic relationship • Resources, suppliers, outsource partners etc Dependencies
  • 15. Recovery Time Objective • Use the same approach as for MTPD (4 levels) • Expand the application of RTO’s to beyond critical activities to include product/service and dependencies
  • 16. Clarification provided by BCM/1 • BCM/1 approved a clarification note in June 2009 to help BCM practitioners • Published on Continuity Central website http://www.continuitycentral.com/feature0677. html • Article on MTPD by Jacque Rupert http://www.continuitycentral.com/feature0675. html
  • 17. Do’s and don’ts for certification to BS 25999:2 (BIA only) • DO make sure that Top • DON’T adopt a Management are fully template mentality and aware of BIA findings copy someone else’s and are able to discuss BIA format for the sake them of it • DO be able to justify the • DON’T over complicate methodology & content the BIA so that it of your BIA becomes a monster • DO adhere to every clause requirement
  • 18. Lessons learnt from certified organisations • “Seek contributions from a wide range of staff” • “Take sufficient time to get it right. If you do your BIA properly, writing plans becomes very easy” • “Engage key customers and suppliers” • “Make sure you have evidence that you have covered every element of the standard.” • “the template in particular has evolved through multiple iterations based on user feedback.”
  • 19. Thanks for listening Hilary Estall Hilary.estall@pslinfo.co.uk www.pslinfo.co.uk