SlideShare a Scribd company logo
1 of 15
The Business Continuity Institute
The Good Practice Guidelines – Real life
          Implementations



         Muhammad Ghazali
MBCI, CBCI, ISMS ISO 27001LA, BS25999 LA
   Associate Director – Head of BCM Service
       Protiviti Member firm Middle East
The Good Practice Guidelines

Why Good Practice Guidelines

The value of the GPG:

    Not Just What, but “Why” and
    “how”

    Baseline and common language

    Used for Entry examination

    Professional Reference document

    Stage-wise
The Good Practice Guidelines


1. BCM Program Management

2. Understanding the Organization

3. Determining BCM Strategies

4. Developing and Implementing

   BCM Response

5. Exercising Maintaining and

   Reviewing

6. Embedding BCM into Organization

   Culture
BCM Program Management


                        What                                            Why
1.   Develop the BCM Program
                                                        Objectives, Mission, Vision, Key
2.   Identification of owner/member and
                                                        Service, Product, future strategy,
     participants of Program
                                                        acquisitions, geographical scale,
3.   Development of BCM Policy of the organization
                                                        competitor strategy, regulatory
4.   Identification of inclusion and exclusion of the
                                                        obligation etc. etc..
     BCM Program
                                                                        How
5. Define and approve the scope of the program
                                                        Involve the Top Management
Examples:
                                                        team
         BCM Head – That’s probably you…
                                                        Review documents produced by
         BCM Steering Committee -Management
                                                        the organization
         BCM Roles – Strategic, Tactical and
                                                        • Business plans
         Operational
                                                        • Strategic plans
         BCM Forum – Selected team members
                                                        • Annual report
                                                        • Marketing report
A “Program” Not a “Project”

                 •   Set Objectives
                 •   See Obligations
Program Scope
                 •   Acceptable level of risk
                 •   Statutory, regulatory and contractual issues

                 • Top management commitment and approval
                 • Objectives of the business continuity and scope
                 • Communicated and reviewed
Organizational
    Policy       • Appropriate by nature, scale, complexity, geography
                   and criticality of business activities
                 • Reflect culture, dependencies and operating
                   environment

                 • Defined roles and responsibilities
Resources and
                 • Top management nominees / appointees
 Competence
                 • BCM competency
Understanding the Organization


                       What                                            Why
Know your                                                     Your Business depends on
         Process                                        •   Operations Staff/skills
                                                        •   Records/Data Assets
         People                                         •   Voice/Data Communications
         Infrastructures                                •   Facilities & Infrastructure
                                                        •   Equipment
         Environment
         Internal and external Suppliers
                                                                       How
         Threats to all requirement
                                                        There are three main activities to
         Impact of those threats
                                                        “Understanding the Organization”
{if you know your enemies and know yourself, you        • Business Impact Analysis (BIA)
will not be imperiled in a hundred battles} Sun Tzu     • Continuity Requirements
                                                          Analysis (CRA)
                                                        • Risk Assessment (RA)
Knowing Your Organization - Impact Analysis


Business Objectives      Key BIA Inputs                       Recovery Requirements as Output

                         Financial Impact
Key Business Areas       •   Lost sales revenue
                         •   Productivity loss
                         •   Permanent customer loss
                                                                  Recovery Time
                         •   Loss of interest income              Objective (RTO)
                         Operational Impacts
                         •   Brand image
 Critical Processes      •   Competitive advantage
                         •   Customer satisfaction
      - Business Lines   •   Increased regulatory oversight                             MTPOD
                         •   Employee Morale
      - Support Lines                                            Recovery Point
                         Management Tolerances                   Objective (RPO)
                         • Intolerable/acceptable downtime
                         • Intolerable/acceptable data loss


                         Resource Dependencies
                         •   Operations Staff                     Minimum
                         •   Records/Data Assets                  Operation
                         •   Voice/Data Communications
                         •   Facilities & Infrastructure
                                                                  Requirements
                         •   Equipment
Knowing Your Risks – Risk Assessment (RA)


 Business               Interviews
 Objectives           Questionnaires
                       Workshops

                                                  BIA
                        BIA of Critical
Critical Processes                            Dependency
                          Processes
                                            Impact over time



                                                                Business     Business
                                                               Continuity   Continuity
                                                                Strategy      Plans



                                             Risk Register
Key Risks / threats    Risk Assessment       Vulnerability
                                            Threats, Impact,
                                               Likelihood
Determining BCM Strategies


                        What                                          Why
                                                      Your Business requires to select
On the basis of your RTO (Recovery Time Objective),
                                                      Appropriate continuity options for
Recovery Point Objective (RPO) and Maximum
                                                      each activity that supports the
tolerable period of disruption (MTPOD), identify
                                                      delivery
strategies
• The faster you want it – the more it will cost!
Separation distance                                                     How
                                                      Asses Continuity options for each
• How far away do you need to be                      critical activity to following levels:
• Accessible yet recoverable                          1. Initial Continuity – to an initial
                                                           acceptable level
                                                      2. Recovery – to a sustainable
                                                           level
                                                      3. Resumption – back to the
                                                           normal level
Determining BCM Strategies – Considerations


Continuity Strategy    Continuity Strategy     Continuity Strategy
        for                    for                     for
  Key Processes            Technology               Facilities


                                                    Physical
Alternate processes        IT Systems
                                                 Location/Space

   Options to              Core / Main         Office Equipments/
   Customers               Application              Stationary


Alternate Channels      User/Branch Data
                           Processing             Power Supply
    of Delivery


Alternate methods       Data Center/Voice
                       and Communication        Communication
of communication


   Support to          Info. security / Data
                              Transfer           Transportation
   Customers
Developing & Implementing BCM Response


                        What                                            Why
The GPG identifies the following stages of response:
                                                        To identify and document
                                                        • Individual and Teams roles
• Emergency response – immediate actions
                                                        Actions required for
• Incident management – management of the
                                                            Invocation, Crisis, Incident,
  response to the incident
                                                                    Internal and
• Business/ IT Continuity – the initial business
                                                          External, Communication, call
  response to the
                                                                   lists, etc. etc.
  incident (essential activities at acceptable level)
                                                                         How
• Recovery – recovery of activities to sustainable        The Plan(s) developement include
  level                                                            Appoint an owner
• Resumption – resuming operations to ‘normal’               Define the objectives and scope
                                                           Create Teams for planning, response
                                                                Agree the responsibilities
                                                               Document actionable steps
                                                                    Populate the plan
                                                              Circulate and gather feedback
                                                                    Agree and validate
                                                                     Agree a program
Continuity Plans - Considerations

•   Simple language

•   Action Oriented – (Check list…)

•   Easy to access, maintain and

    Navigate

•   Plans are tools / guidelines to
use or follow in case required, do
not allow them to restrict your
thoughts and responses.
Exercising Maintaining and Reviewing


                          What                                         Why
Exercise                                                To Highlight doubtful assumptions
Verifies your assumptions about IT / Buss.              Provides Hidden information
Continuity                                              about
                                                        Gain confidence in exercice
Validates                                               participants
            Effectiveness of your plan                  Raise awareness of BCM
            Response of your teams                      Verify BCP/ IT Continuity Plans(s)
            Effectiveness of your strategies

Results offers Opportunities for improvement in                        How
                                                        Agree the Scope– what are your BCM
          Plans                                         priorities?
          Responses                                     Engage senior stakeholders
          Strategies                                    Communicate thoroughly –particularly
                                                        for senior staff
                                                        Plan frequently - Normal Business is
                                                        always Busy
                                                        Make sure the exercise type fits the
                                                        need
Embedding BCM into Organization Culture


                       What                                       Why
Let the organization know about BCM                Management Understanding of
Just like                                          Risk/ Impact/ Threat/Response
          Human Resource Management (HRM)
          Management Information System (MIS)      Transformation of understanding
          Financial Management System (FMS)        across the organizations
          Material / Supply Chain Management
          Procurement

Involve all members of the organization, because
                                                                 How
 Continuity is everyone Business                   •   Employee Handbook - Guidelines
                                                   •   BCM Business Cases
                                                   •   Email messages
                                                   •   Intranet BCP Web Site
                                                   •   New Employee Induction Program
                                                   •   Interactive Presentations with
                                                       Staff
                                                   •   Organize in-house Coaching
                                                       Sessions
The BCI GPG Presentation @ The BCI

More Related Content

What's hot

Business continuity planning
Business continuity planningBusiness continuity planning
Business continuity planning
Sandeep Kashyap
 

What's hot (20)

What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP) What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP)
 
Bcm Roadmap
Bcm RoadmapBcm Roadmap
Bcm Roadmap
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
 
Building a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintBuilding a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprint
 
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Third-Party Risk Management (TPRM) | Risk Assessment QuestionnairesThird-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
 
Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management system
 
Business Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationBusiness Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS Implementation
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Business Continuity Planning Seminar
Business Continuity Planning SeminarBusiness Continuity Planning Seminar
Business Continuity Planning Seminar
 
BUSINESS CONTINUITY MANAGEMENT system
BUSINESS CONTINUITY MANAGEMENT systemBUSINESS CONTINUITY MANAGEMENT system
BUSINESS CONTINUITY MANAGEMENT system
 
Business Continuity Planning Presentation
Business Continuity Planning PresentationBusiness Continuity Planning Presentation
Business Continuity Planning Presentation
 
Nist cybersecurity framework isc2 quantico
Nist cybersecurity framework  isc2 quanticoNist cybersecurity framework  isc2 quantico
Nist cybersecurity framework isc2 quantico
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Business continuity planning
Business continuity planningBusiness continuity planning
Business continuity planning
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
Business Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesBusiness Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation Slides
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
Business Continuity Planning Presentation Overview
Business Continuity Planning Presentation OverviewBusiness Continuity Planning Presentation Overview
Business Continuity Planning Presentation Overview
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 

Viewers also liked

Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery Presentation
TimSchaefer
 
An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery Planning
NEBizRecovery
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
hhuihhui
 
Crisis Management
Crisis ManagementCrisis Management
Crisis Management
euweben01
 
Crisis management - Types and Examples
Crisis management - Types and ExamplesCrisis management - Types and Examples
Crisis management - Types and Examples
Nupur Bhardwaj
 

Viewers also liked (11)

Crisis Communications_Plans and Exercises
Crisis Communications_Plans and ExercisesCrisis Communications_Plans and Exercises
Crisis Communications_Plans and Exercises
 
Comparison of ISO 22301 with BS 25999
Comparison of ISO 22301 with BS 25999Comparison of ISO 22301 with BS 25999
Comparison of ISO 22301 with BS 25999
 
Krizių komunikacija: trumpa apžvalga
Krizių komunikacija: trumpa apžvalgaKrizių komunikacija: trumpa apžvalga
Krizių komunikacija: trumpa apžvalga
 
Crisis Communication Simulation Exercise [Freberg]
Crisis Communication Simulation Exercise [Freberg]Crisis Communication Simulation Exercise [Freberg]
Crisis Communication Simulation Exercise [Freberg]
 
ISO 22301 Business Continuity Management
ISO 22301 Business Continuity ManagementISO 22301 Business Continuity Management
ISO 22301 Business Continuity Management
 
Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery Presentation
 
An Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery Planning
 
The A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoveryThe A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster Recovery
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
 
Crisis Management
Crisis ManagementCrisis Management
Crisis Management
 
Crisis management - Types and Examples
Crisis management - Types and ExamplesCrisis management - Types and Examples
Crisis management - Types and Examples
 

Similar to The BCI GPG Presentation @ The BCI

Krzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpiKrzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpi
banqUP
 
Condensed Itu Workshop Report
Condensed Itu Workshop ReportCondensed Itu Workshop Report
Condensed Itu Workshop Report
jalilmaraicar
 
Project design and management
Project design and managementProject design and management
Project design and management
Andrew Zolnai
 
Syllabus capability maturity model
Syllabus capability maturity modelSyllabus capability maturity model
Syllabus capability maturity model
D&D Consulting
 

Similar to The BCI GPG Presentation @ The BCI (20)

Business continuity management fundamentals update
Business continuity management fundamentals updateBusiness continuity management fundamentals update
Business continuity management fundamentals update
 
AdvisorAssist Compliance ROI
AdvisorAssist Compliance ROIAdvisorAssist Compliance ROI
AdvisorAssist Compliance ROI
 
Killing the Myth: Agile & CMMI
Killing the Myth: Agile & CMMIKilling the Myth: Agile & CMMI
Killing the Myth: Agile & CMMI
 
Krzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpiKrzysztof pulkiewicz kpi
Krzysztof pulkiewicz kpi
 
Condensed Itu Workshop Report
Condensed Itu Workshop ReportCondensed Itu Workshop Report
Condensed Itu Workshop Report
 
Bpo risk management
Bpo risk managementBpo risk management
Bpo risk management
 
Bcp Dr Grant Thornton Llp(Danny Miller) Vfinal
Bcp Dr Grant Thornton Llp(Danny Miller) VfinalBcp Dr Grant Thornton Llp(Danny Miller) Vfinal
Bcp Dr Grant Thornton Llp(Danny Miller) Vfinal
 
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy Modeler
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy ModelerRole Discovery and RBAC Design: A Case Study with IBM Role and Policy Modeler
Role Discovery and RBAC Design: A Case Study with IBM Role and Policy Modeler
 
S&OP Leadership Exchange: Tailoring S&OP to Fit your Business
S&OP Leadership Exchange: Tailoring S&OP to Fit your BusinessS&OP Leadership Exchange: Tailoring S&OP to Fit your Business
S&OP Leadership Exchange: Tailoring S&OP to Fit your Business
 
NFP Strategic Initiatives Process 2012
NFP Strategic Initiatives Process  2012NFP Strategic Initiatives Process  2012
NFP Strategic Initiatives Process 2012
 
Project design and management
Project design and managementProject design and management
Project design and management
 
Project Management in an Agency Environment
Project Management in an Agency Environment Project Management in an Agency Environment
Project Management in an Agency Environment
 
Ospmi Chapter Presentation
Ospmi Chapter PresentationOspmi Chapter Presentation
Ospmi Chapter Presentation
 
Business Healthcheck Service By John Capper & Co
Business Healthcheck Service By John Capper & CoBusiness Healthcheck Service By John Capper & Co
Business Healthcheck Service By John Capper & Co
 
Measuring the Results of your Agile Adoption
Measuring the Results of your Agile AdoptionMeasuring the Results of your Agile Adoption
Measuring the Results of your Agile Adoption
 
Crm for iit k
Crm for iit kCrm for iit k
Crm for iit k
 
How to Organize and Prioritize Requirements
How to Organize and Prioritize RequirementsHow to Organize and Prioritize Requirements
How to Organize and Prioritize Requirements
 
Syllabus capability maturity model
Syllabus capability maturity modelSyllabus capability maturity model
Syllabus capability maturity model
 
Managing cost and realising benefits from your SAP HCM or other HR system
Managing cost and realising benefits from your SAP HCM or other HR systemManaging cost and realising benefits from your SAP HCM or other HR system
Managing cost and realising benefits from your SAP HCM or other HR system
 
Bpr training v 2.0 4.1.2012
Bpr training   v 2.0 4.1.2012Bpr training   v 2.0 4.1.2012
Bpr training v 2.0 4.1.2012
 

Recently uploaded

FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
dollysharma2066
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
lizamodels9
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
dlhescort
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
dlhescort
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
daisycvs
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
amitlee9823
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Sheetaleventcompany
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
amitlee9823
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
daisycvs
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
Abortion pills in Kuwait Cytotec pills in Kuwait
 

Recently uploaded (20)

It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation Final
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 

The BCI GPG Presentation @ The BCI

  • 1. The Business Continuity Institute The Good Practice Guidelines – Real life Implementations Muhammad Ghazali MBCI, CBCI, ISMS ISO 27001LA, BS25999 LA Associate Director – Head of BCM Service Protiviti Member firm Middle East
  • 2. The Good Practice Guidelines Why Good Practice Guidelines The value of the GPG: Not Just What, but “Why” and “how” Baseline and common language Used for Entry examination Professional Reference document Stage-wise
  • 3. The Good Practice Guidelines 1. BCM Program Management 2. Understanding the Organization 3. Determining BCM Strategies 4. Developing and Implementing BCM Response 5. Exercising Maintaining and Reviewing 6. Embedding BCM into Organization Culture
  • 4. BCM Program Management What Why 1. Develop the BCM Program Objectives, Mission, Vision, Key 2. Identification of owner/member and Service, Product, future strategy, participants of Program acquisitions, geographical scale, 3. Development of BCM Policy of the organization competitor strategy, regulatory 4. Identification of inclusion and exclusion of the obligation etc. etc.. BCM Program How 5. Define and approve the scope of the program Involve the Top Management Examples: team BCM Head – That’s probably you… Review documents produced by BCM Steering Committee -Management the organization BCM Roles – Strategic, Tactical and • Business plans Operational • Strategic plans BCM Forum – Selected team members • Annual report • Marketing report
  • 5. A “Program” Not a “Project” • Set Objectives • See Obligations Program Scope • Acceptable level of risk • Statutory, regulatory and contractual issues • Top management commitment and approval • Objectives of the business continuity and scope • Communicated and reviewed Organizational Policy • Appropriate by nature, scale, complexity, geography and criticality of business activities • Reflect culture, dependencies and operating environment • Defined roles and responsibilities Resources and • Top management nominees / appointees Competence • BCM competency
  • 6. Understanding the Organization What Why Know your Your Business depends on Process • Operations Staff/skills • Records/Data Assets People • Voice/Data Communications Infrastructures • Facilities & Infrastructure • Equipment Environment Internal and external Suppliers How Threats to all requirement There are three main activities to Impact of those threats “Understanding the Organization” {if you know your enemies and know yourself, you • Business Impact Analysis (BIA) will not be imperiled in a hundred battles} Sun Tzu • Continuity Requirements Analysis (CRA) • Risk Assessment (RA)
  • 7. Knowing Your Organization - Impact Analysis Business Objectives Key BIA Inputs Recovery Requirements as Output Financial Impact Key Business Areas • Lost sales revenue • Productivity loss • Permanent customer loss Recovery Time • Loss of interest income Objective (RTO) Operational Impacts • Brand image Critical Processes • Competitive advantage • Customer satisfaction - Business Lines • Increased regulatory oversight MTPOD • Employee Morale - Support Lines Recovery Point Management Tolerances Objective (RPO) • Intolerable/acceptable downtime • Intolerable/acceptable data loss Resource Dependencies • Operations Staff Minimum • Records/Data Assets Operation • Voice/Data Communications • Facilities & Infrastructure Requirements • Equipment
  • 8. Knowing Your Risks – Risk Assessment (RA) Business Interviews Objectives Questionnaires Workshops BIA BIA of Critical Critical Processes Dependency Processes Impact over time Business Business Continuity Continuity Strategy Plans Risk Register Key Risks / threats Risk Assessment Vulnerability Threats, Impact, Likelihood
  • 9. Determining BCM Strategies What Why Your Business requires to select On the basis of your RTO (Recovery Time Objective), Appropriate continuity options for Recovery Point Objective (RPO) and Maximum each activity that supports the tolerable period of disruption (MTPOD), identify delivery strategies • The faster you want it – the more it will cost! Separation distance How Asses Continuity options for each • How far away do you need to be critical activity to following levels: • Accessible yet recoverable 1. Initial Continuity – to an initial acceptable level 2. Recovery – to a sustainable level 3. Resumption – back to the normal level
  • 10. Determining BCM Strategies – Considerations Continuity Strategy Continuity Strategy Continuity Strategy for for for Key Processes Technology Facilities Physical Alternate processes IT Systems Location/Space Options to Core / Main Office Equipments/ Customers Application Stationary Alternate Channels User/Branch Data Processing Power Supply of Delivery Alternate methods Data Center/Voice and Communication Communication of communication Support to Info. security / Data Transfer Transportation Customers
  • 11. Developing & Implementing BCM Response What Why The GPG identifies the following stages of response: To identify and document • Individual and Teams roles • Emergency response – immediate actions Actions required for • Incident management – management of the Invocation, Crisis, Incident, response to the incident Internal and • Business/ IT Continuity – the initial business External, Communication, call response to the lists, etc. etc. incident (essential activities at acceptable level) How • Recovery – recovery of activities to sustainable The Plan(s) developement include level Appoint an owner • Resumption – resuming operations to ‘normal’ Define the objectives and scope Create Teams for planning, response Agree the responsibilities Document actionable steps Populate the plan Circulate and gather feedback Agree and validate Agree a program
  • 12. Continuity Plans - Considerations • Simple language • Action Oriented – (Check list…) • Easy to access, maintain and Navigate • Plans are tools / guidelines to use or follow in case required, do not allow them to restrict your thoughts and responses.
  • 13. Exercising Maintaining and Reviewing What Why Exercise To Highlight doubtful assumptions Verifies your assumptions about IT / Buss. Provides Hidden information Continuity about Gain confidence in exercice Validates participants Effectiveness of your plan Raise awareness of BCM Response of your teams Verify BCP/ IT Continuity Plans(s) Effectiveness of your strategies Results offers Opportunities for improvement in How Agree the Scope– what are your BCM Plans priorities? Responses Engage senior stakeholders Strategies Communicate thoroughly –particularly for senior staff Plan frequently - Normal Business is always Busy Make sure the exercise type fits the need
  • 14. Embedding BCM into Organization Culture What Why Let the organization know about BCM Management Understanding of Just like Risk/ Impact/ Threat/Response Human Resource Management (HRM) Management Information System (MIS) Transformation of understanding Financial Management System (FMS) across the organizations Material / Supply Chain Management Procurement Involve all members of the organization, because How Continuity is everyone Business • Employee Handbook - Guidelines • BCM Business Cases • Email messages • Intranet BCP Web Site • New Employee Induction Program • Interactive Presentations with Staff • Organize in-house Coaching Sessions