SlideShare a Scribd company logo
1 of 15
The Business Continuity Institute
The Good Practice Guidelines – Real life
          Implementations



         Muhammad Ghazali
MBCI, CBCI, ISMS ISO 27001LA, BS25999 LA
   Associate Director – Head of BCM Service
       Protiviti Member firm Middle East
The Good Practice Guidelines

Why Good Practice Guidelines

The value of the GPG:

    Not Just What, but “Why” and
    “how”

    Baseline and common language

    Used for Entry examination

    Professional Reference document

    Stage-wise
The Good Practice Guidelines


1. BCM Program Management

2. Understanding the Organization

3. Determining BCM Strategies

4. Developing and Implementing

   BCM Response

5. Exercising Maintaining and

   Reviewing

6. Embedding BCM into Organization

   Culture
BCM Program Management


                        What                                            Why
1.   Develop the BCM Program
                                                        Objectives, Mission, Vision, Key
2.   Identification of owner/member and
                                                        Service, Product, future strategy,
     participants of Program
                                                        acquisitions, geographical scale,
3.   Development of BCM Policy of the organization
                                                        competitor strategy, regulatory
4.   Identification of inclusion and exclusion of the
                                                        obligation etc. etc..
     BCM Program
                                                                        How
5. Define and approve the scope of the program
                                                        Involve the Top Management
Examples:
                                                        team
         BCM Head – That’s probably you…
                                                        Review documents produced by
         BCM Steering Committee -Management
                                                        the organization
         BCM Roles – Strategic, Tactical and
                                                        • Business plans
         Operational
                                                        • Strategic plans
         BCM Forum – Selected team members
                                                        • Annual report
                                                        • Marketing report
A “Program” Not a “Project”

                 •   Set Objectives
                 •   See Obligations
Program Scope
                 •   Acceptable level of risk
                 •   Statutory, regulatory and contractual issues

                 • Top management commitment and approval
                 • Objectives of the business continuity and scope
                 • Communicated and reviewed
Organizational
    Policy       • Appropriate by nature, scale, complexity, geography
                   and criticality of business activities
                 • Reflect culture, dependencies and operating
                   environment

                 • Defined roles and responsibilities
Resources and
                 • Top management nominees / appointees
 Competence
                 • BCM competency
Understanding the Organization


                       What                                            Why
Know your                                                     Your Business depends on
         Process                                        •   Operations Staff/skills
                                                        •   Records/Data Assets
         People                                         •   Voice/Data Communications
         Infrastructures                                •   Facilities & Infrastructure
                                                        •   Equipment
         Environment
         Internal and external Suppliers
                                                                       How
         Threats to all requirement
                                                        There are three main activities to
         Impact of those threats
                                                        “Understanding the Organization”
{if you know your enemies and know yourself, you        • Business Impact Analysis (BIA)
will not be imperiled in a hundred battles} Sun Tzu     • Continuity Requirements
                                                          Analysis (CRA)
                                                        • Risk Assessment (RA)
Knowing Your Organization - Impact Analysis


Business Objectives      Key BIA Inputs                       Recovery Requirements as Output

                         Financial Impact
Key Business Areas       •   Lost sales revenue
                         •   Productivity loss
                         •   Permanent customer loss
                                                                  Recovery Time
                         •   Loss of interest income              Objective (RTO)
                         Operational Impacts
                         •   Brand image
 Critical Processes      •   Competitive advantage
                         •   Customer satisfaction
      - Business Lines   •   Increased regulatory oversight                             MTPOD
                         •   Employee Morale
      - Support Lines                                            Recovery Point
                         Management Tolerances                   Objective (RPO)
                         • Intolerable/acceptable downtime
                         • Intolerable/acceptable data loss


                         Resource Dependencies
                         •   Operations Staff                     Minimum
                         •   Records/Data Assets                  Operation
                         •   Voice/Data Communications
                         •   Facilities & Infrastructure
                                                                  Requirements
                         •   Equipment
Knowing Your Risks – Risk Assessment (RA)


 Business               Interviews
 Objectives           Questionnaires
                       Workshops

                                                  BIA
                        BIA of Critical
Critical Processes                            Dependency
                          Processes
                                            Impact over time



                                                                Business     Business
                                                               Continuity   Continuity
                                                                Strategy      Plans



                                             Risk Register
Key Risks / threats    Risk Assessment       Vulnerability
                                            Threats, Impact,
                                               Likelihood
Determining BCM Strategies


                        What                                          Why
                                                      Your Business requires to select
On the basis of your RTO (Recovery Time Objective),
                                                      Appropriate continuity options for
Recovery Point Objective (RPO) and Maximum
                                                      each activity that supports the
tolerable period of disruption (MTPOD), identify
                                                      delivery
strategies
• The faster you want it – the more it will cost!
Separation distance                                                     How
                                                      Asses Continuity options for each
• How far away do you need to be                      critical activity to following levels:
• Accessible yet recoverable                          1. Initial Continuity – to an initial
                                                           acceptable level
                                                      2. Recovery – to a sustainable
                                                           level
                                                      3. Resumption – back to the
                                                           normal level
Determining BCM Strategies – Considerations


Continuity Strategy    Continuity Strategy     Continuity Strategy
        for                    for                     for
  Key Processes            Technology               Facilities


                                                    Physical
Alternate processes        IT Systems
                                                 Location/Space

   Options to              Core / Main         Office Equipments/
   Customers               Application              Stationary


Alternate Channels      User/Branch Data
                           Processing             Power Supply
    of Delivery


Alternate methods       Data Center/Voice
                       and Communication        Communication
of communication


   Support to          Info. security / Data
                              Transfer           Transportation
   Customers
Developing & Implementing BCM Response


                        What                                            Why
The GPG identifies the following stages of response:
                                                        To identify and document
                                                        • Individual and Teams roles
• Emergency response – immediate actions
                                                        Actions required for
• Incident management – management of the
                                                            Invocation, Crisis, Incident,
  response to the incident
                                                                    Internal and
• Business/ IT Continuity – the initial business
                                                          External, Communication, call
  response to the
                                                                   lists, etc. etc.
  incident (essential activities at acceptable level)
                                                                         How
• Recovery – recovery of activities to sustainable        The Plan(s) developement include
  level                                                            Appoint an owner
• Resumption – resuming operations to ‘normal’               Define the objectives and scope
                                                           Create Teams for planning, response
                                                                Agree the responsibilities
                                                               Document actionable steps
                                                                    Populate the plan
                                                              Circulate and gather feedback
                                                                    Agree and validate
                                                                     Agree a program
Continuity Plans - Considerations

•   Simple language

•   Action Oriented – (Check list…)

•   Easy to access, maintain and

    Navigate

•   Plans are tools / guidelines to
use or follow in case required, do
not allow them to restrict your
thoughts and responses.
Exercising Maintaining and Reviewing


                          What                                         Why
Exercise                                                To Highlight doubtful assumptions
Verifies your assumptions about IT / Buss.              Provides Hidden information
Continuity                                              about
                                                        Gain confidence in exercice
Validates                                               participants
            Effectiveness of your plan                  Raise awareness of BCM
            Response of your teams                      Verify BCP/ IT Continuity Plans(s)
            Effectiveness of your strategies

Results offers Opportunities for improvement in                        How
                                                        Agree the Scope– what are your BCM
          Plans                                         priorities?
          Responses                                     Engage senior stakeholders
          Strategies                                    Communicate thoroughly –particularly
                                                        for senior staff
                                                        Plan frequently - Normal Business is
                                                        always Busy
                                                        Make sure the exercise type fits the
                                                        need
Embedding BCM into Organization Culture


                       What                                       Why
Let the organization know about BCM                Management Understanding of
Just like                                          Risk/ Impact/ Threat/Response
          Human Resource Management (HRM)
          Management Information System (MIS)      Transformation of understanding
          Financial Management System (FMS)        across the organizations
          Material / Supply Chain Management
          Procurement

Involve all members of the organization, because
                                                                 How
 Continuity is everyone Business                   •   Employee Handbook - Guidelines
                                                   •   BCM Business Cases
                                                   •   Email messages
                                                   •   Intranet BCP Web Site
                                                   •   New Employee Induction Program
                                                   •   Interactive Presentations with
                                                       Staff
                                                   •   Organize in-house Coaching
                                                       Sessions
The BCI GPG Presentation @ The BCI

More Related Content

What's hot

Risk management process diagram
Risk management process diagramRisk management process diagram
Risk management process diagram
Kobi Vider
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
PECB
 
Information technology risks
Information technology risksInformation technology risks
Information technology risks
salman butt
 
Risk Management ERM Presentation
Risk Management ERM PresentationRisk Management ERM Presentation
Risk Management ERM Presentation
alygale
 

What's hot (20)

Risk management process diagram
Risk management process diagramRisk management process diagram
Risk management process diagram
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
Business continuity planning and disaster recovery
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recovery
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
 
Strategic Risk Management as a CFO: Getting Risk Management Right
Strategic Risk Management as a CFO: Getting Risk Management RightStrategic Risk Management as a CFO: Getting Risk Management Right
Strategic Risk Management as a CFO: Getting Risk Management Right
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Risk management
Risk managementRisk management
Risk management
 
Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)
 
Risk and Business Continuity Management
Risk and Business Continuity ManagementRisk and Business Continuity Management
Risk and Business Continuity Management
 
Risk Mitigation Strategy PowerPoint Presentation Slides
Risk Mitigation Strategy PowerPoint Presentation SlidesRisk Mitigation Strategy PowerPoint Presentation Slides
Risk Mitigation Strategy PowerPoint Presentation Slides
 
Financial governance and the role of the board
Financial governance and the role of the boardFinancial governance and the role of the board
Financial governance and the role of the board
 
ERM Presentation
ERM PresentationERM Presentation
ERM Presentation
 
Cisa exam mock test questions-1
Cisa exam mock test questions-1Cisa exam mock test questions-1
Cisa exam mock test questions-1
 
CISA Training - Chapter 1 - 2016
CISA Training - Chapter 1 - 2016CISA Training - Chapter 1 - 2016
CISA Training - Chapter 1 - 2016
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
 
Information technology risks
Information technology risksInformation technology risks
Information technology risks
 
Assessing the impact of a disruption: Building an effective business impact a...
Assessing the impact of a disruption: Building an effective business impact a...Assessing the impact of a disruption: Building an effective business impact a...
Assessing the impact of a disruption: Building an effective business impact a...
 
Risk Management ERM Presentation
Risk Management ERM PresentationRisk Management ERM Presentation
Risk Management ERM Presentation
 
Risk Management Maturity Model (RMMM)
Risk Management Maturity Model (RMMM)Risk Management Maturity Model (RMMM)
Risk Management Maturity Model (RMMM)
 
Risk assessment facilitation guide
Risk assessment facilitation guideRisk assessment facilitation guide
Risk assessment facilitation guide
 

Viewers also liked

Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery Presentation
TimSchaefer
 
An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery Planning
NEBizRecovery
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
hhuihhui
 
Crisis Management
Crisis ManagementCrisis Management
Crisis Management
euweben01
 
Crisis management - Types and Examples
Crisis management - Types and ExamplesCrisis management - Types and Examples
Crisis management - Types and Examples
Nupur Bhardwaj
 

Viewers also liked (12)

Crisis Communications_Plans and Exercises
Crisis Communications_Plans and ExercisesCrisis Communications_Plans and Exercises
Crisis Communications_Plans and Exercises
 
Comparison of ISO 22301 with BS 25999
Comparison of ISO 22301 with BS 25999Comparison of ISO 22301 with BS 25999
Comparison of ISO 22301 with BS 25999
 
Krizių komunikacija: trumpa apžvalga
Krizių komunikacija: trumpa apžvalgaKrizių komunikacija: trumpa apžvalga
Krizių komunikacija: trumpa apžvalga
 
Crisis Communication Simulation Exercise [Freberg]
Crisis Communication Simulation Exercise [Freberg]Crisis Communication Simulation Exercise [Freberg]
Crisis Communication Simulation Exercise [Freberg]
 
ISO 22301 Business Continuity Management
ISO 22301 Business Continuity ManagementISO 22301 Business Continuity Management
ISO 22301 Business Continuity Management
 
Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery Presentation
 
An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery Planning
 
The A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoveryThe A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster Recovery
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
Crisis Management
Crisis ManagementCrisis Management
Crisis Management
 
Crisis management - Types and Examples
Crisis management - Types and ExamplesCrisis management - Types and Examples
Crisis management - Types and Examples
 

Similar to The BCI GPG Presentation @ The BCI

Krzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpiKrzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpi
banqUP
 
Condensed Itu Workshop Report
Condensed Itu Workshop ReportCondensed Itu Workshop Report
Condensed Itu Workshop Report
jalilmaraicar
 
Project design and management
Project design and managementProject design and management
Project design and management
Andrew Zolnai
 
Syllabus capability maturity model
Syllabus capability maturity modelSyllabus capability maturity model
Syllabus capability maturity model
D&D Consulting
 

Similar to The BCI GPG Presentation @ The BCI (20)

Business continuity management fundamentals update
Business continuity management fundamentals updateBusiness continuity management fundamentals update
Business continuity management fundamentals update
 
AdvisorAssist Compliance ROI
AdvisorAssist Compliance ROIAdvisorAssist Compliance ROI
AdvisorAssist Compliance ROI
 
Killing the Myth: Agile & CMMI
Killing the Myth: Agile & CMMIKilling the Myth: Agile & CMMI
Killing the Myth: Agile & CMMI
 
Krzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpiKrzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpi
 
Condensed Itu Workshop Report
Condensed Itu Workshop ReportCondensed Itu Workshop Report
Condensed Itu Workshop Report
 
Bpo risk management
Bpo risk managementBpo risk management
Bpo risk management
 
Bcp Dr Grant Thornton Llp(Danny Miller) Vfinal
Bcp Dr Grant Thornton Llp(Danny Miller) VfinalBcp Dr Grant Thornton Llp(Danny Miller) Vfinal
Bcp Dr Grant Thornton Llp(Danny Miller) Vfinal
 
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy Modeler
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy ModelerRole Discovery and RBAC Design: A Case Study with IBM Role and Policy Modeler
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy Modeler
 
S&OP Leadership Exchange: Tailoring S&OP to Fit your Business
S&OP Leadership Exchange: Tailoring S&OP to Fit your BusinessS&OP Leadership Exchange: Tailoring S&OP to Fit your Business
S&OP Leadership Exchange: Tailoring S&OP to Fit your Business
 
NFP Strategic Initiatives Process 2012
NFP Strategic Initiatives Process  2012NFP Strategic Initiatives Process  2012
NFP Strategic Initiatives Process 2012
 
Project design and management
Project design and managementProject design and management
Project design and management
 
Project Management in an Agency Environment
Project Management in an Agency Environment Project Management in an Agency Environment
Project Management in an Agency Environment
 
Ospmi Chapter Presentation
Ospmi Chapter PresentationOspmi Chapter Presentation
Ospmi Chapter Presentation
 
Business Healthcheck Service By John Capper & Co
Business Healthcheck Service By John Capper & CoBusiness Healthcheck Service By John Capper & Co
Business Healthcheck Service By John Capper & Co
 
Measuring the Results of your Agile Adoption
Measuring the Results of your Agile AdoptionMeasuring the Results of your Agile Adoption
Measuring the Results of your Agile Adoption
 
Crm for iit k
Crm for iit kCrm for iit k
Crm for iit k
 
How to Organize and Prioritize Requirements
How to Organize and Prioritize RequirementsHow to Organize and Prioritize Requirements
How to Organize and Prioritize Requirements
 
Syllabus capability maturity model
Syllabus capability maturity modelSyllabus capability maturity model
Syllabus capability maturity model
 
Managing cost and realising benefits from your SAP HCM or other HR system
Managing cost and realising benefits from your SAP HCM or other HR systemManaging cost and realising benefits from your SAP HCM or other HR system
Managing cost and realising benefits from your SAP HCM or other HR system
 
Bpr training v 2.0 4.1.2012
Bpr training   v 2.0 4.1.2012Bpr training   v 2.0 4.1.2012
Bpr training v 2.0 4.1.2012
 

Recently uploaded

unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
Abortion pills in Kuwait Cytotec pills in Kuwait
 
Mifepristone Available in Muscat +918761049707^^ €€ Buy Abortion Pills in Oman
Mifepristone Available in Muscat +918761049707^^ €€ Buy Abortion Pills in OmanMifepristone Available in Muscat +918761049707^^ €€ Buy Abortion Pills in Oman
Mifepristone Available in Muscat +918761049707^^ €€ Buy Abortion Pills in Oman
instagramfab782445
 

Recently uploaded (20)

Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All TimeCall 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
Mifepristone Available in Muscat +918761049707^^ €€ Buy Abortion Pills in Oman
Mifepristone Available in Muscat +918761049707^^ €€ Buy Abortion Pills in OmanMifepristone Available in Muscat +918761049707^^ €€ Buy Abortion Pills in Oman
Mifepristone Available in Muscat +918761049707^^ €€ Buy Abortion Pills in Oman
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Falcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial WingsFalcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial Wings
 
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
 
New 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck TemplateNew 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck Template
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
Buy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From SeosmmearthBuy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From Seosmmearth
 
Cracking the 'Career Pathing' Slideshare
Cracking the 'Career Pathing' SlideshareCracking the 'Career Pathing' Slideshare
Cracking the 'Career Pathing' Slideshare
 
Cannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 UpdatedCannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 Updated
 
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSCROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
 

The BCI GPG Presentation @ The BCI

  • 1. The Business Continuity Institute The Good Practice Guidelines – Real life Implementations Muhammad Ghazali MBCI, CBCI, ISMS ISO 27001LA, BS25999 LA Associate Director – Head of BCM Service Protiviti Member firm Middle East
  • 2. The Good Practice Guidelines Why Good Practice Guidelines The value of the GPG: Not Just What, but “Why” and “how” Baseline and common language Used for Entry examination Professional Reference document Stage-wise
  • 3. The Good Practice Guidelines 1. BCM Program Management 2. Understanding the Organization 3. Determining BCM Strategies 4. Developing and Implementing BCM Response 5. Exercising Maintaining and Reviewing 6. Embedding BCM into Organization Culture
  • 4. BCM Program Management What Why 1. Develop the BCM Program Objectives, Mission, Vision, Key 2. Identification of owner/member and Service, Product, future strategy, participants of Program acquisitions, geographical scale, 3. Development of BCM Policy of the organization competitor strategy, regulatory 4. Identification of inclusion and exclusion of the obligation etc. etc.. BCM Program How 5. Define and approve the scope of the program Involve the Top Management Examples: team BCM Head – That’s probably you… Review documents produced by BCM Steering Committee -Management the organization BCM Roles – Strategic, Tactical and • Business plans Operational • Strategic plans BCM Forum – Selected team members • Annual report • Marketing report
  • 5. A “Program” Not a “Project” • Set Objectives • See Obligations Program Scope • Acceptable level of risk • Statutory, regulatory and contractual issues • Top management commitment and approval • Objectives of the business continuity and scope • Communicated and reviewed Organizational Policy • Appropriate by nature, scale, complexity, geography and criticality of business activities • Reflect culture, dependencies and operating environment • Defined roles and responsibilities Resources and • Top management nominees / appointees Competence • BCM competency
  • 6. Understanding the Organization What Why Know your Your Business depends on Process • Operations Staff/skills • Records/Data Assets People • Voice/Data Communications Infrastructures • Facilities & Infrastructure • Equipment Environment Internal and external Suppliers How Threats to all requirement There are three main activities to Impact of those threats “Understanding the Organization” {if you know your enemies and know yourself, you • Business Impact Analysis (BIA) will not be imperiled in a hundred battles} Sun Tzu • Continuity Requirements Analysis (CRA) • Risk Assessment (RA)
  • 7. Knowing Your Organization - Impact Analysis Business Objectives Key BIA Inputs Recovery Requirements as Output Financial Impact Key Business Areas • Lost sales revenue • Productivity loss • Permanent customer loss Recovery Time • Loss of interest income Objective (RTO) Operational Impacts • Brand image Critical Processes • Competitive advantage • Customer satisfaction - Business Lines • Increased regulatory oversight MTPOD • Employee Morale - Support Lines Recovery Point Management Tolerances Objective (RPO) • Intolerable/acceptable downtime • Intolerable/acceptable data loss Resource Dependencies • Operations Staff Minimum • Records/Data Assets Operation • Voice/Data Communications • Facilities & Infrastructure Requirements • Equipment
  • 8. Knowing Your Risks – Risk Assessment (RA) Business Interviews Objectives Questionnaires Workshops BIA BIA of Critical Critical Processes Dependency Processes Impact over time Business Business Continuity Continuity Strategy Plans Risk Register Key Risks / threats Risk Assessment Vulnerability Threats, Impact, Likelihood
  • 9. Determining BCM Strategies What Why Your Business requires to select On the basis of your RTO (Recovery Time Objective), Appropriate continuity options for Recovery Point Objective (RPO) and Maximum each activity that supports the tolerable period of disruption (MTPOD), identify delivery strategies • The faster you want it – the more it will cost! Separation distance How Asses Continuity options for each • How far away do you need to be critical activity to following levels: • Accessible yet recoverable 1. Initial Continuity – to an initial acceptable level 2. Recovery – to a sustainable level 3. Resumption – back to the normal level
  • 10. Determining BCM Strategies – Considerations Continuity Strategy Continuity Strategy Continuity Strategy for for for Key Processes Technology Facilities Physical Alternate processes IT Systems Location/Space Options to Core / Main Office Equipments/ Customers Application Stationary Alternate Channels User/Branch Data Processing Power Supply of Delivery Alternate methods Data Center/Voice and Communication Communication of communication Support to Info. security / Data Transfer Transportation Customers
  • 11. Developing & Implementing BCM Response What Why The GPG identifies the following stages of response: To identify and document • Individual and Teams roles • Emergency response – immediate actions Actions required for • Incident management – management of the Invocation, Crisis, Incident, response to the incident Internal and • Business/ IT Continuity – the initial business External, Communication, call response to the lists, etc. etc. incident (essential activities at acceptable level) How • Recovery – recovery of activities to sustainable The Plan(s) developement include level Appoint an owner • Resumption – resuming operations to ‘normal’ Define the objectives and scope Create Teams for planning, response Agree the responsibilities Document actionable steps Populate the plan Circulate and gather feedback Agree and validate Agree a program
  • 12. Continuity Plans - Considerations • Simple language • Action Oriented – (Check list…) • Easy to access, maintain and Navigate • Plans are tools / guidelines to use or follow in case required, do not allow them to restrict your thoughts and responses.
  • 13. Exercising Maintaining and Reviewing What Why Exercise To Highlight doubtful assumptions Verifies your assumptions about IT / Buss. Provides Hidden information Continuity about Gain confidence in exercice Validates participants Effectiveness of your plan Raise awareness of BCM Response of your teams Verify BCP/ IT Continuity Plans(s) Effectiveness of your strategies Results offers Opportunities for improvement in How Agree the Scope– what are your BCM Plans priorities? Responses Engage senior stakeholders Strategies Communicate thoroughly –particularly for senior staff Plan frequently - Normal Business is always Busy Make sure the exercise type fits the need
  • 14. Embedding BCM into Organization Culture What Why Let the organization know about BCM Management Understanding of Just like Risk/ Impact/ Threat/Response Human Resource Management (HRM) Management Information System (MIS) Transformation of understanding Financial Management System (FMS) across the organizations Material / Supply Chain Management Procurement Involve all members of the organization, because How Continuity is everyone Business • Employee Handbook - Guidelines • BCM Business Cases • Email messages • Intranet BCP Web Site • New Employee Induction Program • Interactive Presentations with Staff • Organize in-house Coaching Sessions