SlideShare a Scribd company logo
1 of 20
Business Continuity Management
Paul Marsden – Group Business Continuity Manager
Business Continuity - Planning
► BCM Definition (BS ISO 22301)
– “holistic management process that identifies potential
threats to an organization and the impacts to business
operations those threats, if realized, might cause, and
which provides a framework for building organizational
resilience with the capability of an effective response
that safeguards the interests of its key stakeholders,
reputation, brand and value-creating activities”
Business Continuity - Planning
► Best practice from ISO 22301 – Business Continuity
Management systems
– Keepmoat BCM Policy, Procedures, Plans, Business Impact Analysis
cover critical business functions including supply chain reviewed
through internal audits, desktop tests and live exercises.
– Project Business Continuity Plans set out how continuity of business
will be achieved under various business disruption events including
the Disruption of the Supply of Materials. The Plan will include an
indicative schedule of test and review dates.
– All BCPs are reviewed as part of the Annual Management Review.
Business Continuity - Planning
► Business Continuity Planning
Business Continuity - Planning
► Business Continuity Planning
Business Continuity - Process
► All Hazards Approach to Disruption Events
– Keepmoat adopt an ‘all hazards’ approach addressing the
consequences rather than purely the causes
– BCP linked to Clients’ Civil Emergency Plans to support the plans
for Major Disaster and Civil Emergency.
– Key threat categories include;
 Loss of access to Buildings
 Environmental inc. external threats
 People – key staff and health epidemics
 IT – data, network and communications
 Combinations of the above
Business Continuity - Process
► All Hazards Approach to Disruption Events
Risk Assessment (RA)
Business Impact Analysis (BIA)
Business Continuity Plan (BCP)
Train, Test and Live Exercises
Review&Improve
Business Continuity - Process
► Risk Assessment (RA)
Business Continuity - Process
► Risk Assessment (RA) - IT
Business Continuity - Process
► Risk Assessment (RA) - People
Business Continuity - Process
► Business Impact Analysis (BIA)
Business Continuity
► Business Continuity Plan
(BCP)
– BCP Objectives
– Roles & Responsibilities
– Key Risks
– Contacts
– Invocation and BC processes
– Tests and exercises’ schedule
– Client Emergency Support
Business Continuity - Process
► Test & Exercises’ schedule
– Carried out in accordance with BS
ISO 22398
– Tests verify recovery time
objectives within BCP and test out
crisis scenarios.
– Tests and exercise programmes
based on risk assessment but as
a minimum within:-
 3 months desk top tests and
 12 months ‘live’ exercises
Business Continuity
► Go Bags
Business Continuity – 4 key threats
► Disruption to IT & Data
► Systems redundancy inherent
in Keepmoat approach
– Co-location of IT infrastructure
– Distributed office locations
► Data security maintenance
► Regular systems testing and
resilience proving
Business Continuity – 4 key threats
► Disruption of Time essential Staff
– Succession planning
– Trained deputies
– Temporary delegation of authority
– Prioritised BC support for designated staff
Business Continuity – 4 key threats
► Denial of access to office
– Staff work from home using secure IT
– Pre-allocated locations in alternative Keepmoat
offices
– Ability to rapidly move
to serviced offices
Business Continuity – 4 key threats
► Disruption of the Supply of Materials
– All Suppliers and Subcontractors are formally approved using stringent, due
diligence processes.
– Alternative suppliers and Subcontractors available
– Robust specifications for supplier materials ensure that client
requirements are met for each project.
– Keepmoat carry out quality audits on supply chain processes and
individual companies to test robustness of supply including assessing
their business continuity plans.
– Supply Chain will be analysed and assessed in accordance with
standard PD 25222 using tests and live exercises
Business Continuity
► Thank you
► Questions?

More Related Content

What's hot

Risk register
Risk registerRisk register
Risk registerAlexAfuya
 
BUSINESS IMPACT ‎ANALYSIS- DRM
BUSINESS IMPACT ‎ANALYSIS- DRMBUSINESS IMPACT ‎ANALYSIS- DRM
BUSINESS IMPACT ‎ANALYSIS- DRMLibcorpio
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery PlanningJohn Wilson
 
Business Continuity - Business Risk & Management
Business Continuity - Business Risk & ManagementBusiness Continuity - Business Risk & Management
Business Continuity - Business Risk & ManagementAndrew Styles
 
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...Alexander Larsen
 
Business Continuity Detailed Plan
Business Continuity Detailed PlanBusiness Continuity Detailed Plan
Business Continuity Detailed PlanWissam Abdel Baki
 
What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP) What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP) CBIZ, Inc.
 
BUSINESS CONTINUITY PLANNING AND RISK MANAGEMENT
BUSINESS CONTINUITY PLANNING AND RISK MANAGEMENTBUSINESS CONTINUITY PLANNING AND RISK MANAGEMENT
BUSINESS CONTINUITY PLANNING AND RISK MANAGEMENTContinuity and Resilience
 
PECB Webinar: The importance of business impact analysis
PECB Webinar: The importance of business impact analysisPECB Webinar: The importance of business impact analysis
PECB Webinar: The importance of business impact analysisPECB
 
Building a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintBuilding a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintluweinet
 
A Top Down Business Impact Analyses Method V5
A Top Down Business Impact Analyses Method V5A Top Down Business Impact Analyses Method V5
A Top Down Business Impact Analyses Method V5Gewurtz
 
Guía plan de continuidad y recuperación de negocio
Guía plan de continuidad y recuperación de negocioGuía plan de continuidad y recuperación de negocio
Guía plan de continuidad y recuperación de negociomiguel911
 
Business continuity management www.reconglobal.in
Business continuity management   www.reconglobal.inBusiness continuity management   www.reconglobal.in
Business continuity management www.reconglobal.inSatya Yadav
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Narudom Roongsiriwong, CISSP
 
Business Impact Analysis
Business Impact AnalysisBusiness Impact Analysis
Business Impact Analysisdlfrench
 
Bcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation SlidesBcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation SlidesSlideTeam
 
Business Continuity, Data Privacy, and Information Security: How do they link?
Business Continuity, Data Privacy, and Information Security: How do they link?Business Continuity, Data Privacy, and Information Security: How do they link?
Business Continuity, Data Privacy, and Information Security: How do they link?PECB
 

What's hot (20)

Risk register
Risk registerRisk register
Risk register
 
Business Continuity Planning Presentation
Business Continuity Planning PresentationBusiness Continuity Planning Presentation
Business Continuity Planning Presentation
 
BUSINESS IMPACT ‎ANALYSIS- DRM
BUSINESS IMPACT ‎ANALYSIS- DRMBUSINESS IMPACT ‎ANALYSIS- DRM
BUSINESS IMPACT ‎ANALYSIS- DRM
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery Planning
 
Business Continuity - Business Risk & Management
Business Continuity - Business Risk & ManagementBusiness Continuity - Business Risk & Management
Business Continuity - Business Risk & Management
 
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
Business Continuity Management (BCM, BCP) Smaple (Animations don't work in Sl...
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
Business Continuity Detailed Plan
Business Continuity Detailed PlanBusiness Continuity Detailed Plan
Business Continuity Detailed Plan
 
Awareness iso 22301 danang suryo
Awareness iso 22301 danang suryoAwareness iso 22301 danang suryo
Awareness iso 22301 danang suryo
 
What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP) What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP)
 
BUSINESS CONTINUITY PLANNING AND RISK MANAGEMENT
BUSINESS CONTINUITY PLANNING AND RISK MANAGEMENTBUSINESS CONTINUITY PLANNING AND RISK MANAGEMENT
BUSINESS CONTINUITY PLANNING AND RISK MANAGEMENT
 
PECB Webinar: The importance of business impact analysis
PECB Webinar: The importance of business impact analysisPECB Webinar: The importance of business impact analysis
PECB Webinar: The importance of business impact analysis
 
Building a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintBuilding a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprint
 
A Top Down Business Impact Analyses Method V5
A Top Down Business Impact Analyses Method V5A Top Down Business Impact Analyses Method V5
A Top Down Business Impact Analyses Method V5
 
Guía plan de continuidad y recuperación de negocio
Guía plan de continuidad y recuperación de negocioGuía plan de continuidad y recuperación de negocio
Guía plan de continuidad y recuperación de negocio
 
Business continuity management www.reconglobal.in
Business continuity management   www.reconglobal.inBusiness continuity management   www.reconglobal.in
Business continuity management www.reconglobal.in
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
Business Impact Analysis
Business Impact AnalysisBusiness Impact Analysis
Business Impact Analysis
 
Bcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation SlidesBcm Framework PowerPoint Presentation Slides
Bcm Framework PowerPoint Presentation Slides
 
Business Continuity, Data Privacy, and Information Security: How do they link?
Business Continuity, Data Privacy, and Information Security: How do they link?Business Continuity, Data Privacy, and Information Security: How do they link?
Business Continuity, Data Privacy, and Information Security: How do they link?
 

Similar to BCM Presentation - March 2015

BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...BCM Institute
 
Business continuity overview slideshare
Business continuity overview slideshareBusiness continuity overview slideshare
Business continuity overview slideshareChris Greenhill
 
BCMS Presentation1
BCMS Presentation1BCMS Presentation1
BCMS Presentation1barbytee
 
Rob kloots auditingforscyandbcm
Rob kloots auditingforscyandbcmRob kloots auditingforscyandbcm
Rob kloots auditingforscyandbcmRobert Kloots
 
Business continuity management system overveiw
Business continuity management system  overveiwBusiness continuity management system  overveiw
Business continuity management system overveiwNaresh Rao
 
Business Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewBusiness Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewAhmed Riad .
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...PECB
 
Operational risk & business continuity management
Operational risk & business continuity managementOperational risk & business continuity management
Operational risk & business continuity managementUjjwal 'Shanu'
 
Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301PECB
 
Operational risk management (2)
Operational risk management (2)Operational risk management (2)
Operational risk management (2)Ujjwal 'Shanu'
 
AMIT_YADAV_-CV-IT
AMIT_YADAV_-CV-ITAMIT_YADAV_-CV-IT
AMIT_YADAV_-CV-ITAmit Yadav
 
Business Continuity & Disaster Recovery
Business Continuity & Disaster RecoveryBusiness Continuity & Disaster Recovery
Business Continuity & Disaster RecoveryEC-Council
 
ArvindMahuli_EHS 2016
ArvindMahuli_EHS 2016ArvindMahuli_EHS 2016
ArvindMahuli_EHS 2016Arvind Mahuli
 

Similar to BCM Presentation - March 2015 (20)

BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...
 
Business continuity overview slideshare
Business continuity overview slideshareBusiness continuity overview slideshare
Business continuity overview slideshare
 
Business Continuity Audit
Business Continuity AuditBusiness Continuity Audit
Business Continuity Audit
 
BCMS Presentation1
BCMS Presentation1BCMS Presentation1
BCMS Presentation1
 
Rob kloots auditingforscyandbcm
Rob kloots auditingforscyandbcmRob kloots auditingforscyandbcm
Rob kloots auditingforscyandbcm
 
Business continuity management system overveiw
Business continuity management system  overveiwBusiness continuity management system  overveiw
Business continuity management system overveiw
 
Business Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An OverviewBusiness Continuity Management System ISO 22301:2012 An Overview
Business Continuity Management System ISO 22301:2012 An Overview
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
 
bimal bedi-2
bimal bedi-2bimal bedi-2
bimal bedi-2
 
Operational risk & business continuity management
Operational risk & business continuity managementOperational risk & business continuity management
Operational risk & business continuity management
 
Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301
 
Operational risk management (2)
Operational risk management (2)Operational risk management (2)
Operational risk management (2)
 
AMIT_YADAV_-CV-IT
AMIT_YADAV_-CV-ITAMIT_YADAV_-CV-IT
AMIT_YADAV_-CV-IT
 
Business Continuity & Disaster Recovery
Business Continuity & Disaster RecoveryBusiness Continuity & Disaster Recovery
Business Continuity & Disaster Recovery
 
Professional Profile
Professional ProfileProfessional Profile
Professional Profile
 
Six sigma
Six sigmaSix sigma
Six sigma
 
ArvindMahuli_EHS 2016
ArvindMahuli_EHS 2016ArvindMahuli_EHS 2016
ArvindMahuli_EHS 2016
 
Cmmi (2)
Cmmi (2)Cmmi (2)
Cmmi (2)
 
Cmmi
CmmiCmmi
Cmmi
 
Qsys Profile
Qsys ProfileQsys Profile
Qsys Profile
 

BCM Presentation - March 2015

  • 1. Business Continuity Management Paul Marsden – Group Business Continuity Manager
  • 2. Business Continuity - Planning ► BCM Definition (BS ISO 22301) – “holistic management process that identifies potential threats to an organization and the impacts to business operations those threats, if realized, might cause, and which provides a framework for building organizational resilience with the capability of an effective response that safeguards the interests of its key stakeholders, reputation, brand and value-creating activities”
  • 3. Business Continuity - Planning ► Best practice from ISO 22301 – Business Continuity Management systems – Keepmoat BCM Policy, Procedures, Plans, Business Impact Analysis cover critical business functions including supply chain reviewed through internal audits, desktop tests and live exercises. – Project Business Continuity Plans set out how continuity of business will be achieved under various business disruption events including the Disruption of the Supply of Materials. The Plan will include an indicative schedule of test and review dates. – All BCPs are reviewed as part of the Annual Management Review.
  • 4. Business Continuity - Planning ► Business Continuity Planning
  • 5. Business Continuity - Planning ► Business Continuity Planning
  • 6. Business Continuity - Process ► All Hazards Approach to Disruption Events – Keepmoat adopt an ‘all hazards’ approach addressing the consequences rather than purely the causes – BCP linked to Clients’ Civil Emergency Plans to support the plans for Major Disaster and Civil Emergency. – Key threat categories include;  Loss of access to Buildings  Environmental inc. external threats  People – key staff and health epidemics  IT – data, network and communications  Combinations of the above
  • 7. Business Continuity - Process ► All Hazards Approach to Disruption Events Risk Assessment (RA) Business Impact Analysis (BIA) Business Continuity Plan (BCP) Train, Test and Live Exercises Review&Improve
  • 8. Business Continuity - Process ► Risk Assessment (RA)
  • 9. Business Continuity - Process ► Risk Assessment (RA) - IT
  • 10. Business Continuity - Process ► Risk Assessment (RA) - People
  • 11. Business Continuity - Process ► Business Impact Analysis (BIA)
  • 12. Business Continuity ► Business Continuity Plan (BCP) – BCP Objectives – Roles & Responsibilities – Key Risks – Contacts – Invocation and BC processes – Tests and exercises’ schedule – Client Emergency Support
  • 13.
  • 14. Business Continuity - Process ► Test & Exercises’ schedule – Carried out in accordance with BS ISO 22398 – Tests verify recovery time objectives within BCP and test out crisis scenarios. – Tests and exercise programmes based on risk assessment but as a minimum within:-  3 months desk top tests and  12 months ‘live’ exercises
  • 16. Business Continuity – 4 key threats ► Disruption to IT & Data ► Systems redundancy inherent in Keepmoat approach – Co-location of IT infrastructure – Distributed office locations ► Data security maintenance ► Regular systems testing and resilience proving
  • 17. Business Continuity – 4 key threats ► Disruption of Time essential Staff – Succession planning – Trained deputies – Temporary delegation of authority – Prioritised BC support for designated staff
  • 18. Business Continuity – 4 key threats ► Denial of access to office – Staff work from home using secure IT – Pre-allocated locations in alternative Keepmoat offices – Ability to rapidly move to serviced offices
  • 19. Business Continuity – 4 key threats ► Disruption of the Supply of Materials – All Suppliers and Subcontractors are formally approved using stringent, due diligence processes. – Alternative suppliers and Subcontractors available – Robust specifications for supplier materials ensure that client requirements are met for each project. – Keepmoat carry out quality audits on supply chain processes and individual companies to test robustness of supply including assessing their business continuity plans. – Supply Chain will be analysed and assessed in accordance with standard PD 25222 using tests and live exercises
  • 20. Business Continuity ► Thank you ► Questions?