SlideShare a Scribd company logo
1 of 15
Download to read offline
1
© Copyright 2016 EMC Corporation. All rights reserved. Please write to us if you would like to get in touch with the speaker
BUSINESS RESILIENCY
PITFALLS
M A H A A B U R U M M A N
3
© Copyright 2016 EMC Corporation. All rights reserved.
Growing number of disasters
Multiplying regulatory
requirements
Highly complex supply chains
24/7 delivery requirements
Cyber Breaches
Business Resiliency Drivers
TICKING THE COMPLIANCE
BOX
5
© Copyright 2016 EMC Corporation. All rights reserved.
5
Standards and Regulations
Regulation Summary
Sarbanes-Oxley Auditors are increasing scrutiny of all areas of internal control, including security and business
continuity controls.
ISO 22301:2014 – Societal
Security – Business
Continuity Management
Systems – Requirements
Requirements to plan, establish, implement, operate, monitor, review, maintain and continually
improve a documented management system to protect against, reduce the likelihood of occurrence,
prepare for, respond to, and recover from disruptive incidents when they arise.
ITIL v.3 (international) – IT
Infrastructure Library
Global standard in the area of service management. ITIL® (IT Infrastructure Library®) is the most
widely accepted approach to IT service management in the world. ITIL provides a cohesive set of
best practice, drawn from the public and private sectors internationally.
Business Continuity
Standard and Guide
AE/HSE/NCEMA
7000:2012
Developed to help entities systematically build their business continuity capability during and after an
emergency, disaster or crisis. Initiatives are aimed at ensuring ongoing performance of essential
functions and services in both the public and private sectors, for the purpose of enhancing the UAE’s
national stability.
Source: BCM Legislation and regulations, Jan 2016. BCI
PARALYSIS BY ANALYSIS
7
© Copyright 2016 EMC Corporation. All rights reserved.
Expansive approach to BIA
Undefined and unlimited scope
Excessive analysis of results
What is a BIA?
“A business impact analysis (BIA) is a process that identifies and evaluates the potential effects
(financial, life/safety, regulatory, legal/contractual, reputation and so forth) of natural and man-made
events on business operations.” Gartner IT Glossary
8
© Copyright 2016 EMC Corporation. All rights reserved.
Criticality Assessment Prioritization
The Goals of a BIA
SILOED FUNCTIONS
10
© Copyright 2016 EMC Corporation. All rights reserved.
10
Challenges
The organization does
not fully understand the
criticality of business
processes, risks or
impacts of crises on the
organization
The organization
does not focus on
building resiliency
into processes,
operations, IT, etc.
Executives do not have
an understanding of the
residual risk of being or
not being prepared
Are we prepared
for the next big
disaster?
- CxO
“
”
Business continuity, IT
disaster recovery and
crisis management are
driven by separate,
unconnected groups
Visibility Collaboration AccountabilityAutomationEfficiency
Plan smarter by
integrating BCM, IT DR
and Crisis Management
Leverage technologies
to their full potential with
workflow and controls
Establish
governance and
ownership across the
BCM spectrum
Get IT, Crisis
Management and
the business on the
same page
Understand recovery
priorities and make
better planning
decisions
11
© Copyright 2016 EMC Corporation. All rights reserved.
11
Gaps and Overlaps
Many functions in the organization are repetitive and inefficient. Information is
not being shared across functions resulting in duplicate efforts and fractured
visibility.
CIO
Risk Ownership
Reporting
Business Assets
Issue and Remediation
Ownership
BCM
COO
Risk Identification
Risk Assessment
ERM
Metrics & Reporting
Issue Generation
Risk Assessment
Evaluate Controls
Reporting
Issue Generation
Control Testing
Compliance Checklist
Reporting
Issue Generation
CCO CRO
IT Assets
Security Risk
IT Controls
Issue Generation
EXPAND CONTINUITY TO
RESILIENCY
13
© Copyright 2016 EMC Corporation. All rights reserved.
Common business context
Capture and resolve incidents
Prepare for and exercise business
recovery strategies
Prepare for and recover from IT
system outages
Manage crisis events and
communications
Evaluate 3rd party readiness
What Is Business Resiliency?
Incident
Management
Business
Continuity
IT Disaster
Recovery
Business Operations
Crisis
Management
3rd Party Governance
“A holistic management process that identifies potential threats to an organization and the impacts to
business operations those threats, if realized, might cause.” ISO 22301
14
© Copyright 2016 EMC Corporation. All rights reserved.
Questions Comments
The End
EMC, RSA, the EMC logo and the RSA logo are registered trademarks of EMC Corporation in the U.S. and other countries.

More Related Content

What's hot

Crisis Management Techniques for Cyber Attacks
Crisis Management Techniques for Cyber AttacksCrisis Management Techniques for Cyber Attacks
Crisis Management Techniques for Cyber AttacksPECB
 
Centralized operations – Risk, Control, and Compliance
Centralized operations – Risk, Control, and ComplianceCentralized operations – Risk, Control, and Compliance
Centralized operations – Risk, Control, and CompliancePECB
 
Building Risk Management into Enterprise Architecture
Building Risk Management into Enterprise ArchitectureBuilding Risk Management into Enterprise Architecture
Building Risk Management into Enterprise Architectureiasaglobal
 

What's hot (6)

Crisis Management Techniques for Cyber Attacks
Crisis Management Techniques for Cyber AttacksCrisis Management Techniques for Cyber Attacks
Crisis Management Techniques for Cyber Attacks
 
Tma Insurance Info Paper2012
Tma Insurance Info Paper2012Tma Insurance Info Paper2012
Tma Insurance Info Paper2012
 
Centralized operations – Risk, Control, and Compliance
Centralized operations – Risk, Control, and ComplianceCentralized operations – Risk, Control, and Compliance
Centralized operations – Risk, Control, and Compliance
 
Six simple rules of training
Six simple rules of trainingSix simple rules of training
Six simple rules of training
 
Building Risk Management into Enterprise Architecture
Building Risk Management into Enterprise ArchitectureBuilding Risk Management into Enterprise Architecture
Building Risk Management into Enterprise Architecture
 
#Corpriskforum2016 - Andy Cox
#Corpriskforum2016 - Andy Cox#Corpriskforum2016 - Andy Cox
#Corpriskforum2016 - Andy Cox
 

Viewers also liked

5th ME Business & IT Resilience summit 2016 - Learnings from chennai floods
5th ME Business & IT Resilience summit 2016 - Learnings from chennai floods5th ME Business & IT Resilience summit 2016 - Learnings from chennai floods
5th ME Business & IT Resilience summit 2016 - Learnings from chennai floodsContinuity and Resilience
 
5th ME Business & IT Resilience Summit 2016 - IT Resilience and Service Manag...
5th ME Business & IT Resilience Summit 2016 - IT Resilience and Service Manag...5th ME Business & IT Resilience Summit 2016 - IT Resilience and Service Manag...
5th ME Business & IT Resilience Summit 2016 - IT Resilience and Service Manag...Continuity and Resilience
 
5th ME Business & IT Resilience Summit 2016 - Implementing Business Continuit...
5th ME Business & IT Resilience Summit 2016 - Implementing Business Continuit...5th ME Business & IT Resilience Summit 2016 - Implementing Business Continuit...
5th ME Business & IT Resilience Summit 2016 - Implementing Business Continuit...Continuity and Resilience
 
5th ME Business & IT Resilience Summit 2016 - Project management in bcm why...
5th ME Business & IT Resilience Summit 2016 - Project management in bcm   why...5th ME Business & IT Resilience Summit 2016 - Project management in bcm   why...
5th ME Business & IT Resilience Summit 2016 - Project management in bcm why...Continuity and Resilience
 
5th ME Business & IT Resilience Summit 2016 - BIA - how to derive maximum ben...
5th ME Business & IT Resilience Summit 2016 - BIA - how to derive maximum ben...5th ME Business & IT Resilience Summit 2016 - BIA - how to derive maximum ben...
5th ME Business & IT Resilience Summit 2016 - BIA - how to derive maximum ben...Continuity and Resilience
 
5th ME Business & IT Resilience Summit 2016 - Pandemics in BCM
5th ME Business & IT Resilience Summit 2016 - Pandemics in BCM5th ME Business & IT Resilience Summit 2016 - Pandemics in BCM
5th ME Business & IT Resilience Summit 2016 - Pandemics in BCMContinuity and Resilience
 
5th ME Business & IT Resilience Summit 2016 - Understanding strategy, objecti...
5th ME Business & IT Resilience Summit 2016 - Understanding strategy, objecti...5th ME Business & IT Resilience Summit 2016 - Understanding strategy, objecti...
5th ME Business & IT Resilience Summit 2016 - Understanding strategy, objecti...Continuity and Resilience
 
5th ME Business & IT Resilience Summit 2016 - Reselience vs continuity
5th ME Business & IT Resilience Summit 2016 - Reselience vs  continuity5th ME Business & IT Resilience Summit 2016 - Reselience vs  continuity
5th ME Business & IT Resilience Summit 2016 - Reselience vs continuityContinuity and Resilience
 

Viewers also liked (8)

5th ME Business & IT Resilience summit 2016 - Learnings from chennai floods
5th ME Business & IT Resilience summit 2016 - Learnings from chennai floods5th ME Business & IT Resilience summit 2016 - Learnings from chennai floods
5th ME Business & IT Resilience summit 2016 - Learnings from chennai floods
 
5th ME Business & IT Resilience Summit 2016 - IT Resilience and Service Manag...
5th ME Business & IT Resilience Summit 2016 - IT Resilience and Service Manag...5th ME Business & IT Resilience Summit 2016 - IT Resilience and Service Manag...
5th ME Business & IT Resilience Summit 2016 - IT Resilience and Service Manag...
 
5th ME Business & IT Resilience Summit 2016 - Implementing Business Continuit...
5th ME Business & IT Resilience Summit 2016 - Implementing Business Continuit...5th ME Business & IT Resilience Summit 2016 - Implementing Business Continuit...
5th ME Business & IT Resilience Summit 2016 - Implementing Business Continuit...
 
5th ME Business & IT Resilience Summit 2016 - Project management in bcm why...
5th ME Business & IT Resilience Summit 2016 - Project management in bcm   why...5th ME Business & IT Resilience Summit 2016 - Project management in bcm   why...
5th ME Business & IT Resilience Summit 2016 - Project management in bcm why...
 
5th ME Business & IT Resilience Summit 2016 - BIA - how to derive maximum ben...
5th ME Business & IT Resilience Summit 2016 - BIA - how to derive maximum ben...5th ME Business & IT Resilience Summit 2016 - BIA - how to derive maximum ben...
5th ME Business & IT Resilience Summit 2016 - BIA - how to derive maximum ben...
 
5th ME Business & IT Resilience Summit 2016 - Pandemics in BCM
5th ME Business & IT Resilience Summit 2016 - Pandemics in BCM5th ME Business & IT Resilience Summit 2016 - Pandemics in BCM
5th ME Business & IT Resilience Summit 2016 - Pandemics in BCM
 
5th ME Business & IT Resilience Summit 2016 - Understanding strategy, objecti...
5th ME Business & IT Resilience Summit 2016 - Understanding strategy, objecti...5th ME Business & IT Resilience Summit 2016 - Understanding strategy, objecti...
5th ME Business & IT Resilience Summit 2016 - Understanding strategy, objecti...
 
5th ME Business & IT Resilience Summit 2016 - Reselience vs continuity
5th ME Business & IT Resilience Summit 2016 - Reselience vs  continuity5th ME Business & IT Resilience Summit 2016 - Reselience vs  continuity
5th ME Business & IT Resilience Summit 2016 - Reselience vs continuity
 

Similar to 5th ME Business & IT Resilience Summit 2016 - Business Resiliency Pitfalls

The Revere Group - Making A Case For Disaster Recovery
The Revere Group - Making A Case For Disaster RecoveryThe Revere Group - Making A Case For Disaster Recovery
The Revere Group - Making A Case For Disaster Recoverycadavis22
 
The Challenges Of Multi-cloud Management.pdf
The Challenges Of Multi-cloud Management.pdfThe Challenges Of Multi-cloud Management.pdf
The Challenges Of Multi-cloud Management.pdfaNumak & Company
 
COMMONALITY AND DIVERSITY OF OPERATING SYSTEMS .docx
COMMONALITY AND DIVERSITY OF OPERATING SYSTEMS                .docxCOMMONALITY AND DIVERSITY OF OPERATING SYSTEMS                .docx
COMMONALITY AND DIVERSITY OF OPERATING SYSTEMS .docxmccormicknadine86
 
An Introduction To ICT Continuity Based On BS 25777
An Introduction To ICT Continuity Based On BS 25777An Introduction To ICT Continuity Based On BS 25777
An Introduction To ICT Continuity Based On BS 25777Yasmine Anino
 
Business Continuity Getting Started
Business Continuity Getting StartedBusiness Continuity Getting Started
Business Continuity Getting Startedmxp5714
 
Business Resiliency
Business ResiliencyBusiness Resiliency
Business ResiliencyRackspace
 
Business Risk: Effective Technology Protecting Your Business
Business Risk: Effective Technology Protecting Your BusinessBusiness Risk: Effective Technology Protecting Your Business
Business Risk: Effective Technology Protecting Your Businessat MicroFocus Italy ❖✔
 
Assocham conf grc sept 13
Assocham conf  grc  sept 13Assocham conf  grc  sept 13
Assocham conf grc sept 13subramanian K
 
SecureTech 2014: Risk, Business Continuity and Cybersecurity - A Resiliency ...
SecureTech 2014:  Risk, Business Continuity and Cybersecurity - A Resiliency ...SecureTech 2014:  Risk, Business Continuity and Cybersecurity - A Resiliency ...
SecureTech 2014: Risk, Business Continuity and Cybersecurity - A Resiliency ...poore120
 
Risk & Compliance Outlook 2011
Risk & Compliance Outlook 2011Risk & Compliance Outlook 2011
Risk & Compliance Outlook 2011Hiten Sethi
 
RSM India publication - How Robust is your IT System
RSM India publication - How Robust is your IT SystemRSM India publication - How Robust is your IT System
RSM India publication - How Robust is your IT SystemRSM India
 
Introducing Oracle Advanced Financial Controls Cloud Service
Introducing Oracle Advanced Financial Controls Cloud ServiceIntroducing Oracle Advanced Financial Controls Cloud Service
Introducing Oracle Advanced Financial Controls Cloud ServiceDane Roberts
 
Office 2007 In Business Continuity Whitepaper: Microsoft Corporation
Office 2007 In Business Continuity Whitepaper: Microsoft CorporationOffice 2007 In Business Continuity Whitepaper: Microsoft Corporation
Office 2007 In Business Continuity Whitepaper: Microsoft CorporationMary Marks
 
IBM XIV® Storage System: Engineered for Business Continuity
IBM XIV® Storage System: Engineered for Business ContinuityIBM XIV® Storage System: Engineered for Business Continuity
IBM XIV® Storage System: Engineered for Business ContinuityIBM India Smarter Computing
 
Beyond Predictive and Preventive Maintenance
Beyond Predictive and Preventive MaintenanceBeyond Predictive and Preventive Maintenance
Beyond Predictive and Preventive MaintenanceHarshad Shah
 

Similar to 5th ME Business & IT Resilience Summit 2016 - Business Resiliency Pitfalls (20)

Dit yvol5iss37
Dit yvol5iss37Dit yvol5iss37
Dit yvol5iss37
 
The Revere Group - Making A Case For Disaster Recovery
The Revere Group - Making A Case For Disaster RecoveryThe Revere Group - Making A Case For Disaster Recovery
The Revere Group - Making A Case For Disaster Recovery
 
The Challenges Of Multi-cloud Management.pdf
The Challenges Of Multi-cloud Management.pdfThe Challenges Of Multi-cloud Management.pdf
The Challenges Of Multi-cloud Management.pdf
 
COMMONALITY AND DIVERSITY OF OPERATING SYSTEMS .docx
COMMONALITY AND DIVERSITY OF OPERATING SYSTEMS                .docxCOMMONALITY AND DIVERSITY OF OPERATING SYSTEMS                .docx
COMMONALITY AND DIVERSITY OF OPERATING SYSTEMS .docx
 
Information Governance
Information GovernanceInformation Governance
Information Governance
 
An Introduction To ICT Continuity Based On BS 25777
An Introduction To ICT Continuity Based On BS 25777An Introduction To ICT Continuity Based On BS 25777
An Introduction To ICT Continuity Based On BS 25777
 
Cobit5 and-grc
Cobit5 and-grcCobit5 and-grc
Cobit5 and-grc
 
Systems Resilience
Systems ResilienceSystems Resilience
Systems Resilience
 
Business Continuity Getting Started
Business Continuity Getting StartedBusiness Continuity Getting Started
Business Continuity Getting Started
 
Business Resiliency
Business ResiliencyBusiness Resiliency
Business Resiliency
 
Business Risk: Effective Technology Protecting Your Business
Business Risk: Effective Technology Protecting Your BusinessBusiness Risk: Effective Technology Protecting Your Business
Business Risk: Effective Technology Protecting Your Business
 
Assocham conf grc sept 13
Assocham conf  grc  sept 13Assocham conf  grc  sept 13
Assocham conf grc sept 13
 
SecureTech 2014: Risk, Business Continuity and Cybersecurity - A Resiliency ...
SecureTech 2014:  Risk, Business Continuity and Cybersecurity - A Resiliency ...SecureTech 2014:  Risk, Business Continuity and Cybersecurity - A Resiliency ...
SecureTech 2014: Risk, Business Continuity and Cybersecurity - A Resiliency ...
 
Dit yvol3iss20
Dit yvol3iss20Dit yvol3iss20
Dit yvol3iss20
 
Risk & Compliance Outlook 2011
Risk & Compliance Outlook 2011Risk & Compliance Outlook 2011
Risk & Compliance Outlook 2011
 
RSM India publication - How Robust is your IT System
RSM India publication - How Robust is your IT SystemRSM India publication - How Robust is your IT System
RSM India publication - How Robust is your IT System
 
Introducing Oracle Advanced Financial Controls Cloud Service
Introducing Oracle Advanced Financial Controls Cloud ServiceIntroducing Oracle Advanced Financial Controls Cloud Service
Introducing Oracle Advanced Financial Controls Cloud Service
 
Office 2007 In Business Continuity Whitepaper: Microsoft Corporation
Office 2007 In Business Continuity Whitepaper: Microsoft CorporationOffice 2007 In Business Continuity Whitepaper: Microsoft Corporation
Office 2007 In Business Continuity Whitepaper: Microsoft Corporation
 
IBM XIV® Storage System: Engineered for Business Continuity
IBM XIV® Storage System: Engineered for Business ContinuityIBM XIV® Storage System: Engineered for Business Continuity
IBM XIV® Storage System: Engineered for Business Continuity
 
Beyond Predictive and Preventive Maintenance
Beyond Predictive and Preventive MaintenanceBeyond Predictive and Preventive Maintenance
Beyond Predictive and Preventive Maintenance
 

More from Continuity and Resilience

The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq BajwaThe Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq BajwaContinuity and Resilience
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha EltinayThe Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha EltinayContinuity and Resilience
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Paul Gant
The Business Continuity Conference, 25th October 2023 in Riyadh -  Paul GantThe Business Continuity Conference, 25th October 2023 in Riyadh -  Paul Gant
The Business Continuity Conference, 25th October 2023 in Riyadh - Paul GantContinuity and Resilience
 
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...Continuity and Resilience
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...Continuity and Resilience
 
Advancing the Enterprise Towards Enterprise Resilience
Advancing the Enterprise Towards Enterprise ResilienceAdvancing the Enterprise Towards Enterprise Resilience
Advancing the Enterprise Towards Enterprise ResilienceContinuity and Resilience
 
Value of Work Place Services in the Middle East
Value of Work Place Services in the Middle EastValue of Work Place Services in the Middle East
Value of Work Place Services in the Middle EastContinuity and Resilience
 
Social Media Influence in the field of Crisis Management– Case Studies
Social Media Influence in the field of Crisis Management– Case StudiesSocial Media Influence in the field of Crisis Management– Case Studies
Social Media Influence in the field of Crisis Management– Case StudiesContinuity and Resilience
 
Cyber Resilience Tips and Techniques For Protection & Response
Cyber ResilienceTips and Techniques For Protection & Response Cyber ResilienceTips and Techniques For Protection & Response
Cyber Resilience Tips and Techniques For Protection & Response Continuity and Resilience
 
Business Continuity and Information Security- An Excellent Fit!
Business Continuity and Information Security- An Excellent Fit!Business Continuity and Information Security- An Excellent Fit!
Business Continuity and Information Security- An Excellent Fit!Continuity and Resilience
 
Crisis Communication & BCM in Aviation Sector
Crisis Communication & BCM in Aviation SectorCrisis Communication & BCM in Aviation Sector
Crisis Communication & BCM in Aviation SectorContinuity and Resilience
 
Effectiveness of Disaster Management Ground Reality and Potential.
Effectiveness of Disaster Management Ground Reality and Potential.Effectiveness of Disaster Management Ground Reality and Potential.
Effectiveness of Disaster Management Ground Reality and Potential.Continuity and Resilience
 

More from Continuity and Resilience (20)

The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq BajwaThe Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha EltinayThe Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Paul Gant
The Business Continuity Conference, 25th October 2023 in Riyadh -  Paul GantThe Business Continuity Conference, 25th October 2023 in Riyadh -  Paul Gant
The Business Continuity Conference, 25th October 2023 in Riyadh - Paul Gant
 
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
 
DEFLUFFING RESILIENCE
DEFLUFFING RESILIENCEDEFLUFFING RESILIENCE
DEFLUFFING RESILIENCE
 
CREATING AND MAINTAINING A BCM PROGRAM
CREATING AND MAINTAINING A BCM PROGRAMCREATING AND MAINTAINING A BCM PROGRAM
CREATING AND MAINTAINING A BCM PROGRAM
 
BCM Challenges and Compliance
BCM Challenges and Compliance BCM Challenges and Compliance
BCM Challenges and Compliance
 
Thriving in the Crisis Situation
Thriving in the Crisis SituationThriving in the Crisis Situation
Thriving in the Crisis Situation
 
Cyber Security & IT Resilience
Cyber Security & IT Resilience Cyber Security & IT Resilience
Cyber Security & IT Resilience
 
Enterprise Resilience
Enterprise ResilienceEnterprise Resilience
Enterprise Resilience
 
Advancing the Enterprise Towards Enterprise Resilience
Advancing the Enterprise Towards Enterprise ResilienceAdvancing the Enterprise Towards Enterprise Resilience
Advancing the Enterprise Towards Enterprise Resilience
 
Bcm is all about people!
Bcm   is all about people!Bcm   is all about people!
Bcm is all about people!
 
SAMA BCM Framework
SAMA BCM Framework SAMA BCM Framework
SAMA BCM Framework
 
Value of Work Place Services in the Middle East
Value of Work Place Services in the Middle EastValue of Work Place Services in the Middle East
Value of Work Place Services in the Middle East
 
Social Media Influence in the field of Crisis Management– Case Studies
Social Media Influence in the field of Crisis Management– Case StudiesSocial Media Influence in the field of Crisis Management– Case Studies
Social Media Influence in the field of Crisis Management– Case Studies
 
Cyber Resilience Tips and Techniques For Protection & Response
Cyber ResilienceTips and Techniques For Protection & Response Cyber ResilienceTips and Techniques For Protection & Response
Cyber Resilience Tips and Techniques For Protection & Response
 
Business Continuity and Information Security- An Excellent Fit!
Business Continuity and Information Security- An Excellent Fit!Business Continuity and Information Security- An Excellent Fit!
Business Continuity and Information Security- An Excellent Fit!
 
Crisis Communication & BCM in Aviation Sector
Crisis Communication & BCM in Aviation SectorCrisis Communication & BCM in Aviation Sector
Crisis Communication & BCM in Aviation Sector
 
Effectiveness of Disaster Management Ground Reality and Potential.
Effectiveness of Disaster Management Ground Reality and Potential.Effectiveness of Disaster Management Ground Reality and Potential.
Effectiveness of Disaster Management Ground Reality and Potential.
 

Recently uploaded

Call Us🔝⇛+91-97111🔝47426 Call In girls Munirka (DELHI)
Call Us🔝⇛+91-97111🔝47426 Call In girls Munirka (DELHI)Call Us🔝⇛+91-97111🔝47426 Call In girls Munirka (DELHI)
Call Us🔝⇛+91-97111🔝47426 Call In girls Munirka (DELHI)jennyeacort
 
Farmer Representative Organization in Lucknow | Rashtriya Kisan Manch
Farmer Representative Organization in Lucknow | Rashtriya Kisan ManchFarmer Representative Organization in Lucknow | Rashtriya Kisan Manch
Farmer Representative Organization in Lucknow | Rashtriya Kisan ManchRashtriya Kisan Manch
 
LPC Warehouse Management System For Clients In The Business Sector
LPC Warehouse Management System For Clients In The Business SectorLPC Warehouse Management System For Clients In The Business Sector
LPC Warehouse Management System For Clients In The Business Sectorthomas851723
 
Simplifying Complexity: How the Four-Field Matrix Reshapes Thinking
Simplifying Complexity: How the Four-Field Matrix Reshapes ThinkingSimplifying Complexity: How the Four-Field Matrix Reshapes Thinking
Simplifying Complexity: How the Four-Field Matrix Reshapes ThinkingCIToolkit
 
LPC Operations Review PowerPoint | Operations Review
LPC Operations Review PowerPoint | Operations ReviewLPC Operations Review PowerPoint | Operations Review
LPC Operations Review PowerPoint | Operations Reviewthomas851723
 
原版1:1复刻密西西比大学毕业证Mississippi毕业证留信学历认证
原版1:1复刻密西西比大学毕业证Mississippi毕业证留信学历认证原版1:1复刻密西西比大学毕业证Mississippi毕业证留信学历认证
原版1:1复刻密西西比大学毕业证Mississippi毕业证留信学历认证jdkhjh
 
ANIn Gurugram April 2024 |Can Agile and AI work together? by Pramodkumar Shri...
ANIn Gurugram April 2024 |Can Agile and AI work together? by Pramodkumar Shri...ANIn Gurugram April 2024 |Can Agile and AI work together? by Pramodkumar Shri...
ANIn Gurugram April 2024 |Can Agile and AI work together? by Pramodkumar Shri...AgileNetwork
 
Fifteenth Finance Commission Presentation
Fifteenth Finance Commission PresentationFifteenth Finance Commission Presentation
Fifteenth Finance Commission Presentationmintusiprd
 
Reflecting, turning experience into insight
Reflecting, turning experience into insightReflecting, turning experience into insight
Reflecting, turning experience into insightWayne Abrahams
 
self respect is very important in this crual word where everyone in just thin...
self respect is very important in this crual word where everyone in just thin...self respect is very important in this crual word where everyone in just thin...
self respect is very important in this crual word where everyone in just thin...afaqsaeed463
 
Unlocking Productivity and Personal Growth through the Importance-Urgency Matrix
Unlocking Productivity and Personal Growth through the Importance-Urgency MatrixUnlocking Productivity and Personal Growth through the Importance-Urgency Matrix
Unlocking Productivity and Personal Growth through the Importance-Urgency MatrixCIToolkit
 
Pooja Mehta 9167673311, Trusted Call Girls In NAVI MUMBAI Cash On Payment , V...
Pooja Mehta 9167673311, Trusted Call Girls In NAVI MUMBAI Cash On Payment , V...Pooja Mehta 9167673311, Trusted Call Girls In NAVI MUMBAI Cash On Payment , V...
Pooja Mehta 9167673311, Trusted Call Girls In NAVI MUMBAI Cash On Payment , V...Pooja Nehwal
 
VIP Kolkata Call Girl Rajarhat 👉 8250192130 Available With Room
VIP Kolkata Call Girl Rajarhat 👉 8250192130  Available With RoomVIP Kolkata Call Girl Rajarhat 👉 8250192130  Available With Room
VIP Kolkata Call Girl Rajarhat 👉 8250192130 Available With Roomdivyansh0kumar0
 
Measuring True Process Yield using Robust Yield Metrics
Measuring True Process Yield using Robust Yield MetricsMeasuring True Process Yield using Robust Yield Metrics
Measuring True Process Yield using Robust Yield MetricsCIToolkit
 
Introduction to LPC - Facility Design And Re-Engineering
Introduction to LPC - Facility Design And Re-EngineeringIntroduction to LPC - Facility Design And Re-Engineering
Introduction to LPC - Facility Design And Re-Engineeringthomas851723
 
Board Diversity Initiaive Launch Presentation
Board Diversity Initiaive Launch PresentationBoard Diversity Initiaive Launch Presentation
Board Diversity Initiaive Launch Presentationcraig524401
 

Recently uploaded (17)

Call Us🔝⇛+91-97111🔝47426 Call In girls Munirka (DELHI)
Call Us🔝⇛+91-97111🔝47426 Call In girls Munirka (DELHI)Call Us🔝⇛+91-97111🔝47426 Call In girls Munirka (DELHI)
Call Us🔝⇛+91-97111🔝47426 Call In girls Munirka (DELHI)
 
Farmer Representative Organization in Lucknow | Rashtriya Kisan Manch
Farmer Representative Organization in Lucknow | Rashtriya Kisan ManchFarmer Representative Organization in Lucknow | Rashtriya Kisan Manch
Farmer Representative Organization in Lucknow | Rashtriya Kisan Manch
 
LPC Warehouse Management System For Clients In The Business Sector
LPC Warehouse Management System For Clients In The Business SectorLPC Warehouse Management System For Clients In The Business Sector
LPC Warehouse Management System For Clients In The Business Sector
 
Simplifying Complexity: How the Four-Field Matrix Reshapes Thinking
Simplifying Complexity: How the Four-Field Matrix Reshapes ThinkingSimplifying Complexity: How the Four-Field Matrix Reshapes Thinking
Simplifying Complexity: How the Four-Field Matrix Reshapes Thinking
 
LPC Operations Review PowerPoint | Operations Review
LPC Operations Review PowerPoint | Operations ReviewLPC Operations Review PowerPoint | Operations Review
LPC Operations Review PowerPoint | Operations Review
 
sauth delhi call girls in Defence Colony🔝 9953056974 🔝 escort Service
sauth delhi call girls in Defence Colony🔝 9953056974 🔝 escort Servicesauth delhi call girls in Defence Colony🔝 9953056974 🔝 escort Service
sauth delhi call girls in Defence Colony🔝 9953056974 🔝 escort Service
 
原版1:1复刻密西西比大学毕业证Mississippi毕业证留信学历认证
原版1:1复刻密西西比大学毕业证Mississippi毕业证留信学历认证原版1:1复刻密西西比大学毕业证Mississippi毕业证留信学历认证
原版1:1复刻密西西比大学毕业证Mississippi毕业证留信学历认证
 
ANIn Gurugram April 2024 |Can Agile and AI work together? by Pramodkumar Shri...
ANIn Gurugram April 2024 |Can Agile and AI work together? by Pramodkumar Shri...ANIn Gurugram April 2024 |Can Agile and AI work together? by Pramodkumar Shri...
ANIn Gurugram April 2024 |Can Agile and AI work together? by Pramodkumar Shri...
 
Fifteenth Finance Commission Presentation
Fifteenth Finance Commission PresentationFifteenth Finance Commission Presentation
Fifteenth Finance Commission Presentation
 
Reflecting, turning experience into insight
Reflecting, turning experience into insightReflecting, turning experience into insight
Reflecting, turning experience into insight
 
self respect is very important in this crual word where everyone in just thin...
self respect is very important in this crual word where everyone in just thin...self respect is very important in this crual word where everyone in just thin...
self respect is very important in this crual word where everyone in just thin...
 
Unlocking Productivity and Personal Growth through the Importance-Urgency Matrix
Unlocking Productivity and Personal Growth through the Importance-Urgency MatrixUnlocking Productivity and Personal Growth through the Importance-Urgency Matrix
Unlocking Productivity and Personal Growth through the Importance-Urgency Matrix
 
Pooja Mehta 9167673311, Trusted Call Girls In NAVI MUMBAI Cash On Payment , V...
Pooja Mehta 9167673311, Trusted Call Girls In NAVI MUMBAI Cash On Payment , V...Pooja Mehta 9167673311, Trusted Call Girls In NAVI MUMBAI Cash On Payment , V...
Pooja Mehta 9167673311, Trusted Call Girls In NAVI MUMBAI Cash On Payment , V...
 
VIP Kolkata Call Girl Rajarhat 👉 8250192130 Available With Room
VIP Kolkata Call Girl Rajarhat 👉 8250192130  Available With RoomVIP Kolkata Call Girl Rajarhat 👉 8250192130  Available With Room
VIP Kolkata Call Girl Rajarhat 👉 8250192130 Available With Room
 
Measuring True Process Yield using Robust Yield Metrics
Measuring True Process Yield using Robust Yield MetricsMeasuring True Process Yield using Robust Yield Metrics
Measuring True Process Yield using Robust Yield Metrics
 
Introduction to LPC - Facility Design And Re-Engineering
Introduction to LPC - Facility Design And Re-EngineeringIntroduction to LPC - Facility Design And Re-Engineering
Introduction to LPC - Facility Design And Re-Engineering
 
Board Diversity Initiaive Launch Presentation
Board Diversity Initiaive Launch PresentationBoard Diversity Initiaive Launch Presentation
Board Diversity Initiaive Launch Presentation
 

5th ME Business & IT Resilience Summit 2016 - Business Resiliency Pitfalls

  • 1. 1 © Copyright 2016 EMC Corporation. All rights reserved. Please write to us if you would like to get in touch with the speaker
  • 2. BUSINESS RESILIENCY PITFALLS M A H A A B U R U M M A N
  • 3. 3 © Copyright 2016 EMC Corporation. All rights reserved. Growing number of disasters Multiplying regulatory requirements Highly complex supply chains 24/7 delivery requirements Cyber Breaches Business Resiliency Drivers
  • 5. 5 © Copyright 2016 EMC Corporation. All rights reserved. 5 Standards and Regulations Regulation Summary Sarbanes-Oxley Auditors are increasing scrutiny of all areas of internal control, including security and business continuity controls. ISO 22301:2014 – Societal Security – Business Continuity Management Systems – Requirements Requirements to plan, establish, implement, operate, monitor, review, maintain and continually improve a documented management system to protect against, reduce the likelihood of occurrence, prepare for, respond to, and recover from disruptive incidents when they arise. ITIL v.3 (international) – IT Infrastructure Library Global standard in the area of service management. ITIL® (IT Infrastructure Library®) is the most widely accepted approach to IT service management in the world. ITIL provides a cohesive set of best practice, drawn from the public and private sectors internationally. Business Continuity Standard and Guide AE/HSE/NCEMA 7000:2012 Developed to help entities systematically build their business continuity capability during and after an emergency, disaster or crisis. Initiatives are aimed at ensuring ongoing performance of essential functions and services in both the public and private sectors, for the purpose of enhancing the UAE’s national stability. Source: BCM Legislation and regulations, Jan 2016. BCI
  • 7. 7 © Copyright 2016 EMC Corporation. All rights reserved. Expansive approach to BIA Undefined and unlimited scope Excessive analysis of results What is a BIA? “A business impact analysis (BIA) is a process that identifies and evaluates the potential effects (financial, life/safety, regulatory, legal/contractual, reputation and so forth) of natural and man-made events on business operations.” Gartner IT Glossary
  • 8. 8 © Copyright 2016 EMC Corporation. All rights reserved. Criticality Assessment Prioritization The Goals of a BIA
  • 10. 10 © Copyright 2016 EMC Corporation. All rights reserved. 10 Challenges The organization does not fully understand the criticality of business processes, risks or impacts of crises on the organization The organization does not focus on building resiliency into processes, operations, IT, etc. Executives do not have an understanding of the residual risk of being or not being prepared Are we prepared for the next big disaster? - CxO “ ” Business continuity, IT disaster recovery and crisis management are driven by separate, unconnected groups Visibility Collaboration AccountabilityAutomationEfficiency Plan smarter by integrating BCM, IT DR and Crisis Management Leverage technologies to their full potential with workflow and controls Establish governance and ownership across the BCM spectrum Get IT, Crisis Management and the business on the same page Understand recovery priorities and make better planning decisions
  • 11. 11 © Copyright 2016 EMC Corporation. All rights reserved. 11 Gaps and Overlaps Many functions in the organization are repetitive and inefficient. Information is not being shared across functions resulting in duplicate efforts and fractured visibility. CIO Risk Ownership Reporting Business Assets Issue and Remediation Ownership BCM COO Risk Identification Risk Assessment ERM Metrics & Reporting Issue Generation Risk Assessment Evaluate Controls Reporting Issue Generation Control Testing Compliance Checklist Reporting Issue Generation CCO CRO IT Assets Security Risk IT Controls Issue Generation
  • 13. 13 © Copyright 2016 EMC Corporation. All rights reserved. Common business context Capture and resolve incidents Prepare for and exercise business recovery strategies Prepare for and recover from IT system outages Manage crisis events and communications Evaluate 3rd party readiness What Is Business Resiliency? Incident Management Business Continuity IT Disaster Recovery Business Operations Crisis Management 3rd Party Governance “A holistic management process that identifies potential threats to an organization and the impacts to business operations those threats, if realized, might cause.” ISO 22301
  • 14. 14 © Copyright 2016 EMC Corporation. All rights reserved. Questions Comments The End
  • 15. EMC, RSA, the EMC logo and the RSA logo are registered trademarks of EMC Corporation in the U.S. and other countries.