SlideShare a Scribd company logo
1 of 25
BS25999 and Other
Management Systems Standards (MSS)

                     Chris Green, Chair BCM/1
                     This Presentation is an Adaptation of a Siemens-
                       Insight copyright Presentation

                                               Insight Consulting
Agenda

 BS25999 and other standards
 Benefits of the Management Systems approach
 Guidance
 Accreditation
 Other Developments
Why have standards?

 Common understanding
 Common approach
 Common sets of evidence
 Promote quality in a particular subject area
 Reduced risk
 Reduce management overhead
 Greater assurance that the topic is managed effectively
Which standard should we have?

 Broadly speaking there are four tiers of “standards” in the
  UK
    PAS – guidance on best practice
    BS – a standard for the UK in the form of a code of
     practice
    BS – a specification allowing for the achievement of
     certification
    ISO – an international standard superseding BS
Positioning BS25999-1

 Supersedes PAS56
 Not the specification standard which will be BS25999-2
 Related guidance should be compatible with BS25999, for
  instance any future PAS relating to continuity planning
 Could be superseded by an International Standard, so any
  ISO25999 would replace BS25999
Global Vision for ISO 2006 to 2010

 Facilitation of global trade
 Improvement in quality, safety, security, environmental and
  consumer protection, as well as rational use of resources
 Global dissemination of technologies and good practice
Issue of Complexity

   Great potential for synergy between standards
   The synergies are not recognised
   Economies relating to synergies are not realised
Management Systems Standards

                                    ISO TMB




                          MSS-SAG             TC223 Societal
                                                Security




                 RM           Quality          Environment     Food Safety
              ISO 25700      ISO 9001           ISO 14001       ISO22000

                                                      SUPPLY CHAIN
                                                        PAS 28003

    BCM
   BS 25999
                IT DR         Crisis Mgt
               PAS 77          SSM/1
Issue - More reporting and more management time

   Constant stream of people reporting to the Board
   Board room time taken up with reporting not strategy
   No common themes nor messages
   Management want confidence and assurance (this is
    exactly what the standards are aimed at providing)
   Always ask for money
PAS99 – MS Integration



    E      OHS&S     Q         BC




                                      E OH&S Q BC




                    Common   Common
  Common   Common
                                       COMMON
Management Systems

 Generally the approach is:-
    Standard Plan-Do-Check-Act model
   BS describes establishing a Management System, its
    continuing operation and a process of continuing
    improvement
   Subject specific information then fits into this model
PDCA Model
Implications for BS25999-2

 This is the specification that will allow for certification
 Must weigh the benefits of commonality with other
  standards and the current practices in business continuity
 MSS approach will need adapting for our specialism whilst
  retaining the key characteristics of a certification standard
  and consistency with other related MSS
 Scope statements allow application to largest and smallest
  of organisations
 Scope must not be allowed to imply capability where none
  exists – for instance certification can only be achieved by
  addressing all steps and all controls in the standard
25999 Part 2

 BS25999-2 has finished DPC
 250 pages of comments !
 Under review at present and being finalisde for the main
  committee to review in October 2007
 Publication will be late October
 Guidance Documents underway
The Standards Pyramid


                                                  ISO
         BS25999
                                              BSI/CEN
                                                                          FT
                                                                        pl S E
                                         Context;                         c     2
                                     Framework; Scope                       Pu 50
                                        Why do BCM                            bl – S
                                                                                ic      m
                                     (benefits/drivers)?;                          –       a
                                          Options;                                   Na ll




                                                                            Ch
 Relation to Other                 Implementation / Testing                            tio




                                                                              ar
    Risk Areas                       Specialised                                           na




                                                                                iti
                                     Functions                                               l/L




                                                                                   es
                                                                                                   oc




                                                                                      /V
                           HR – IT – OR - Legal – Security                                            al




                                                                                              ol
                                                                                              un
                           – Procurement – Ethics –
Sector Guides




                                                                                                ta
                           Supply



                                                                                   SM


                                                                                                  ry
                                                                                     E
                       Sector/Industry specific guides*
                         Construction,                                            Utilities
           Financial                     Pharmaceutical   Aerospace &    Retail
                          mining, oil
                                                          Engineering
                           and gas
The Standards Pyramid


                                                  ISO
         BS25999
                                              BSI/CEN
                                                                          FT
                                                                        pl S E
                                         Context;                         c     2
                                     Framework; Scope                       Pu 50
                                        Why do BCM                            bl – S
                                                                                ic      m
                                     (benefits/drivers)?;                          –       a
                                          Options;                                   Na ll




                                                                            Ch
 Relation to Other                 Implementation / Testing                            tio




                                                                              ar
    Risk Areas                       Specialised                                           na




                                                                                iti
                                     Functions                                               l/L




                                                                                   es
                                                                                                   oc




                                                                                      /V
                           HR – IT – OR - Legal – Security                                            al




                                                                                              ol
                                                                                              un
                           – Procurement – Ethics –
Sector Guides




                                                                                                ta
                           Supply



                                                                                   SM


                                                                                                  ry
                                                                                     E
                       Sector/Industry specific guides*
                         Construction,                                            Utilities
           Financial                     Pharmaceutical   Aerospace &    Retail
                          mining, oil
                                                          Engineering
                           and gas
The Standards Pyramid


                                                  ISO
         BS25999
                                             BSI/CEN
                                                                          FT
                                                                        pl S E
                                         Context;                         c     2
                                     Framework; Scope                       Pu 50
                                        Why do BCM                            bl – S
                                                                                ic      m
                                     (benefits/drivers)?;                          –       a
                                          Options;                                   Na ll




                                                                            Ch
 Relation to Other                 Implementation / Testing                            tio




                                                                              ar
    Risk Areas                       Specialised                                           na




                                                                                iti
                                     Functions                                               l/L




                                                                                   es
                                                                                                   oc




                                                                                      /V
                           HR – IT – OR - Legal – Security                                            al




                                                                                              ol
                                                                                              un
                           – Procurement – Ethics –
Sector Guides




                                                                                                ta
                           Supply



                                                                                   SM


                                                                                                  ry
                                                                                     E
                       Sector/Industry specific guides*
                         Construction,                                            Utilities
           Financial                     Pharmaceutical   Aerospace &    Retail
                          mining, oil
                                                          Engineering
                           and gas
Accreditation Bodies

 5 accreditation bodies interested


 4 volunteers for pilot – however, concerns that they are “all
  the same”


 Competence Criteria for Auditors being developed
Other emerging standards

 PAS77 – IT Continuity guidance
    Developed in isolation from BS25999
    Does not follow precepts of PAS56 or BS25999
    Does not follow the management systems approach
    Not clear how this fits with other related standards – e.g.
     ISO 20000 (ITIL)
 ISO/IEC 24762 – Recovery Site Provision
    Didn’t ask any recovery site vendors !
Risk Management

 Risk Management standard
    BCM and Risk Management committees have swapped
     glossaries and trying to agree common terms
    Where BS25999 uses risk assessment it has tried to
     reflect developments of risk management standard
ISO IPOCM

 Commencement
     Broadly similar to Programme Management
     Define scope, management commitment, policy
 Planning
     Broadly similar to Understanding Your Business
     Includes risk assessment and Impact Analysis
     Also response as includes Response Management
 Implementation and Operation
     Includes resourcing, competence, education and awareness and
      operational control structure
 Performance Assessment
     Evaluation of effectiveness including testing, maintenance and
      audit
     Broadly similar to BS25999
IPOCM

 This is work in progress and a long way from a finalised
  document
 Terminology slightly different from UK common usage and
  the business continuity industry as most of us have come
  to know it
     For the most part UK practitioners can embrace the
      changes
 Approach slightly different to BS25999/PAS56
    But many common points
Room for more?

 Should there be standards in specific areas of business
  continuity?
    PAS77 could be developed into a standard
    Could there be an Incident Management standard?
    Overall Governance standard?
What happens next?

 Committee continues in operation


 Focus for other related committees (e.g. risk management)


 Review of BS25999 so that subsequent revisions lead to
  improvements in the standard


 Focus for expertise and contribution to ISO deliberations
BS25999 and MSS Guide

More Related Content

Viewers also liked

HOW CAN I SPY ON SOMEONES FACEBOOK
HOW CAN I SPY ON SOMEONES FACEBOOK HOW CAN I SPY ON SOMEONES FACEBOOK
HOW CAN I SPY ON SOMEONES FACEBOOK Jane_Robert
 
Ayudas para la mejora de la producción y comercialización de la miel en la Co...
Ayudas para la mejora de la producción y comercialización de la miel en la Co...Ayudas para la mejora de la producción y comercialización de la miel en la Co...
Ayudas para la mejora de la producción y comercialización de la miel en la Co...CEDER Merindades
 
Catálogo Productos-piscina.com
Catálogo Productos-piscina.comCatálogo Productos-piscina.com
Catálogo Productos-piscina.comProductos piscina
 
Decreto de consagracion del ecuador
Decreto de consagracion del ecuadorDecreto de consagracion del ecuador
Decreto de consagracion del ecuadorMary Cecily
 
OAuth 2.0 und OpenId Connect
OAuth 2.0 und OpenId ConnectOAuth 2.0 und OpenId Connect
OAuth 2.0 und OpenId ConnectManfred Steyer
 
Descartes
DescartesDescartes
DescartesAndeka
 
CommonKADS context models
CommonKADS context modelsCommonKADS context models
CommonKADS context modelsGuus Schreiber
 
GitHub halp app - Minimizing platform-specific code with MVVM - Justin Spahr-...
GitHub halp app - Minimizing platform-specific code with MVVM - Justin Spahr-...GitHub halp app - Minimizing platform-specific code with MVVM - Justin Spahr-...
GitHub halp app - Minimizing platform-specific code with MVVM - Justin Spahr-...Xamarin
 
Que Es Cluf
Que Es ClufQue Es Cluf
Que Es Clufdaisy
 
Archivos de usuarios y grupos
Archivos de usuarios y gruposArchivos de usuarios y grupos
Archivos de usuarios y gruposPablo Macon
 
El Retorno sobre la Inversión en Customer Experience
El Retorno sobre la Inversión en Customer ExperienceEl Retorno sobre la Inversión en Customer Experience
El Retorno sobre la Inversión en Customer ExperienceRainer Uphoff
 
Impugnacion paternidad
Impugnacion paternidadImpugnacion paternidad
Impugnacion paternidadEvan Evans
 
Presentación Felipe Solano - eCommerce Day Bogotá 2016
Presentación Felipe Solano - eCommerce Day Bogotá 2016Presentación Felipe Solano - eCommerce Day Bogotá 2016
Presentación Felipe Solano - eCommerce Day Bogotá 2016eCommerce Institute
 
Planeación didáctica argumentada
Planeación didáctica argumentada Planeación didáctica argumentada
Planeación didáctica argumentada Lucy Galán
 

Viewers also liked (18)

HOW CAN I SPY ON SOMEONES FACEBOOK
HOW CAN I SPY ON SOMEONES FACEBOOK HOW CAN I SPY ON SOMEONES FACEBOOK
HOW CAN I SPY ON SOMEONES FACEBOOK
 
Ayudas para la mejora de la producción y comercialización de la miel en la Co...
Ayudas para la mejora de la producción y comercialización de la miel en la Co...Ayudas para la mejora de la producción y comercialización de la miel en la Co...
Ayudas para la mejora de la producción y comercialización de la miel en la Co...
 
Revista Regio nr.30 iulie 2014
Revista Regio nr.30 iulie 2014Revista Regio nr.30 iulie 2014
Revista Regio nr.30 iulie 2014
 
Catálogo Productos-piscina.com
Catálogo Productos-piscina.comCatálogo Productos-piscina.com
Catálogo Productos-piscina.com
 
Decreto de consagracion del ecuador
Decreto de consagracion del ecuadorDecreto de consagracion del ecuador
Decreto de consagracion del ecuador
 
OAuth 2.0 und OpenId Connect
OAuth 2.0 und OpenId ConnectOAuth 2.0 und OpenId Connect
OAuth 2.0 und OpenId Connect
 
Descartes
DescartesDescartes
Descartes
 
CommonKADS context models
CommonKADS context modelsCommonKADS context models
CommonKADS context models
 
GitHub halp app - Minimizing platform-specific code with MVVM - Justin Spahr-...
GitHub halp app - Minimizing platform-specific code with MVVM - Justin Spahr-...GitHub halp app - Minimizing platform-specific code with MVVM - Justin Spahr-...
GitHub halp app - Minimizing platform-specific code with MVVM - Justin Spahr-...
 
HOSPITAL INFANTA MARGARITA
HOSPITAL INFANTA MARGARITAHOSPITAL INFANTA MARGARITA
HOSPITAL INFANTA MARGARITA
 
Que Es Cluf
Que Es ClufQue Es Cluf
Que Es Cluf
 
Archivos de usuarios y grupos
Archivos de usuarios y gruposArchivos de usuarios y grupos
Archivos de usuarios y grupos
 
zara
zarazara
zara
 
El Retorno sobre la Inversión en Customer Experience
El Retorno sobre la Inversión en Customer ExperienceEl Retorno sobre la Inversión en Customer Experience
El Retorno sobre la Inversión en Customer Experience
 
Impugnacion paternidad
Impugnacion paternidadImpugnacion paternidad
Impugnacion paternidad
 
Crianza de pez carpa
Crianza de pez carpaCrianza de pez carpa
Crianza de pez carpa
 
Presentación Felipe Solano - eCommerce Day Bogotá 2016
Presentación Felipe Solano - eCommerce Day Bogotá 2016Presentación Felipe Solano - eCommerce Day Bogotá 2016
Presentación Felipe Solano - eCommerce Day Bogotá 2016
 
Planeación didáctica argumentada
Planeación didáctica argumentada Planeación didáctica argumentada
Planeación didáctica argumentada
 

Similar to BS25999 and MSS Guide

IT - Enterprise Service Operation Center
IT - Enterprise Service Operation CenterIT - Enterprise Service Operation Center
IT - Enterprise Service Operation CenterSameer Paradia
 
Strengthening CMMI Maturity Levels with a Quantitative Approach to Root-Cause...
Strengthening CMMI Maturity Levels with a Quantitative Approach to Root-Cause...Strengthening CMMI Maturity Levels with a Quantitative Approach to Root-Cause...
Strengthening CMMI Maturity Levels with a Quantitative Approach to Root-Cause...Luigi Buglione
 
Presentation for MEED - Copy
Presentation for MEED - CopyPresentation for MEED - Copy
Presentation for MEED - CopySenthil Kumar, S
 
Global Soc Whitepaper Be
Global Soc Whitepaper BeGlobal Soc Whitepaper Be
Global Soc Whitepaper BePeter Grossen
 
SOC 2/SOC 3 Whitepaper
SOC 2/SOC 3 WhitepaperSOC 2/SOC 3 Whitepaper
SOC 2/SOC 3 WhitepaperDTIMMERMAN
 
Global Soc Whitepaper Be
Global Soc Whitepaper BeGlobal Soc Whitepaper Be
Global Soc Whitepaper BeGilles Dufrane
 
Global Soc Whitepaper Be
Global Soc Whitepaper BeGlobal Soc Whitepaper Be
Global Soc Whitepaper Bealaindhoe
 
G6 independent certification for CSP v3
G6 independent certification for CSP v3G6 independent certification for CSP v3
G6 independent certification for CSP v3Ummey Humayra
 
IADC Sept 2015 -RCM-Print PDF
IADC Sept 2015 -RCM-Print PDFIADC Sept 2015 -RCM-Print PDF
IADC Sept 2015 -RCM-Print PDFPieter van Asten
 
PPTX Corporate Project Presentation FEL in New Energies 2023.ppsx
PPTX Corporate   Project Presentation FEL in  New Energies 2023.ppsxPPTX Corporate   Project Presentation FEL in  New Energies 2023.ppsx
PPTX Corporate Project Presentation FEL in New Energies 2023.ppsxANGUSMACLEOD21
 
Burleson.amer
Burleson.amerBurleson.amer
Burleson.amerNASAPMC
 
itu-t recommendation g671, g703
itu-t recommendation g671, g703itu-t recommendation g671, g703
itu-t recommendation g671, g703FrankNguyen48
 
Regulatory Design Toolkit for Utilities, Stephen Labson slEconomics
 Regulatory Design Toolkit for Utilities, Stephen Labson slEconomics Regulatory Design Toolkit for Utilities, Stephen Labson slEconomics
Regulatory Design Toolkit for Utilities, Stephen Labson slEconomicsStephen Labson
 
Placement Brochure of Aviation Management 2009-10 For University of Petroleum...
Placement Brochure of Aviation Management 2009-10 For University of Petroleum...Placement Brochure of Aviation Management 2009-10 For University of Petroleum...
Placement Brochure of Aviation Management 2009-10 For University of Petroleum...University Of Petroleum And Energy Studies
 
Tiêu chuẩn BSI BS 8536_1_2015
Tiêu chuẩn BSI BS 8536_1_2015Tiêu chuẩn BSI BS 8536_1_2015
Tiêu chuẩn BSI BS 8536_1_2015Huytraining
 
Semiconductor newsletter8 01
Semiconductor newsletter8 01Semiconductor newsletter8 01
Semiconductor newsletter8 01Omnex Inc.
 
Policy Control and Charging 2012 Conference Highlights
Policy Control and Charging 2012 Conference HighlightsPolicy Control and Charging 2012 Conference Highlights
Policy Control and Charging 2012 Conference HighlightsAlan Quayle
 

Similar to BS25999 and MSS Guide (20)

IT - Enterprise Service Operation Center
IT - Enterprise Service Operation CenterIT - Enterprise Service Operation Center
IT - Enterprise Service Operation Center
 
Strengthening CMMI Maturity Levels with a Quantitative Approach to Root-Cause...
Strengthening CMMI Maturity Levels with a Quantitative Approach to Root-Cause...Strengthening CMMI Maturity Levels with a Quantitative Approach to Root-Cause...
Strengthening CMMI Maturity Levels with a Quantitative Approach to Root-Cause...
 
Presentation for MEED - Copy
Presentation for MEED - CopyPresentation for MEED - Copy
Presentation for MEED - Copy
 
Global Soc Whitepaper Be
Global Soc Whitepaper BeGlobal Soc Whitepaper Be
Global Soc Whitepaper Be
 
SOC 2/SOC 3 Whitepaper
SOC 2/SOC 3 WhitepaperSOC 2/SOC 3 Whitepaper
SOC 2/SOC 3 Whitepaper
 
Global Soc Whitepaper Be
Global Soc Whitepaper BeGlobal Soc Whitepaper Be
Global Soc Whitepaper Be
 
Global Soc Whitepaper Be
Global Soc Whitepaper BeGlobal Soc Whitepaper Be
Global Soc Whitepaper Be
 
Sasmos Report
Sasmos ReportSasmos Report
Sasmos Report
 
G6 independent certification for CSP v3
G6 independent certification for CSP v3G6 independent certification for CSP v3
G6 independent certification for CSP v3
 
IADC Sept 2015 -RCM-Print PDF
IADC Sept 2015 -RCM-Print PDFIADC Sept 2015 -RCM-Print PDF
IADC Sept 2015 -RCM-Print PDF
 
PPTX Corporate Project Presentation FEL in New Energies 2023.ppsx
PPTX Corporate   Project Presentation FEL in  New Energies 2023.ppsxPPTX Corporate   Project Presentation FEL in  New Energies 2023.ppsx
PPTX Corporate Project Presentation FEL in New Energies 2023.ppsx
 
Burleson.amer
Burleson.amerBurleson.amer
Burleson.amer
 
itu-t recommendation g671, g703
itu-t recommendation g671, g703itu-t recommendation g671, g703
itu-t recommendation g671, g703
 
Regulatory Design Toolkit for Utilities, Stephen Labson slEconomics
 Regulatory Design Toolkit for Utilities, Stephen Labson slEconomics Regulatory Design Toolkit for Utilities, Stephen Labson slEconomics
Regulatory Design Toolkit for Utilities, Stephen Labson slEconomics
 
Placement Brochure of Aviation Management 2009-10 For University of Petroleum...
Placement Brochure of Aviation Management 2009-10 For University of Petroleum...Placement Brochure of Aviation Management 2009-10 For University of Petroleum...
Placement Brochure of Aviation Management 2009-10 For University of Petroleum...
 
Tiêu chuẩn BSI BS 8536_1_2015
Tiêu chuẩn BSI BS 8536_1_2015Tiêu chuẩn BSI BS 8536_1_2015
Tiêu chuẩn BSI BS 8536_1_2015
 
Semiconductor newsletter8 01
Semiconductor newsletter8 01Semiconductor newsletter8 01
Semiconductor newsletter8 01
 
CMMC 2.0 Explained: Impact for SMBs
CMMC 2.0 Explained:  Impact for SMBsCMMC 2.0 Explained:  Impact for SMBs
CMMC 2.0 Explained: Impact for SMBs
 
Policy Control and Charging 2012 Conference Highlights
Policy Control and Charging 2012 Conference HighlightsPolicy Control and Charging 2012 Conference Highlights
Policy Control and Charging 2012 Conference Highlights
 
mm CGEIT Best Practices and Concepts
mm CGEIT Best Practices and Conceptsmm CGEIT Best Practices and Concepts
mm CGEIT Best Practices and Concepts
 

BS25999 and MSS Guide

  • 1. BS25999 and Other Management Systems Standards (MSS) Chris Green, Chair BCM/1 This Presentation is an Adaptation of a Siemens- Insight copyright Presentation Insight Consulting
  • 2. Agenda  BS25999 and other standards  Benefits of the Management Systems approach  Guidance  Accreditation  Other Developments
  • 3. Why have standards?  Common understanding  Common approach  Common sets of evidence  Promote quality in a particular subject area  Reduced risk  Reduce management overhead  Greater assurance that the topic is managed effectively
  • 4. Which standard should we have?  Broadly speaking there are four tiers of “standards” in the UK  PAS – guidance on best practice  BS – a standard for the UK in the form of a code of practice  BS – a specification allowing for the achievement of certification  ISO – an international standard superseding BS
  • 5. Positioning BS25999-1  Supersedes PAS56  Not the specification standard which will be BS25999-2  Related guidance should be compatible with BS25999, for instance any future PAS relating to continuity planning  Could be superseded by an International Standard, so any ISO25999 would replace BS25999
  • 6. Global Vision for ISO 2006 to 2010  Facilitation of global trade  Improvement in quality, safety, security, environmental and consumer protection, as well as rational use of resources  Global dissemination of technologies and good practice
  • 7. Issue of Complexity  Great potential for synergy between standards  The synergies are not recognised  Economies relating to synergies are not realised
  • 8. Management Systems Standards ISO TMB MSS-SAG TC223 Societal Security RM Quality Environment Food Safety ISO 25700 ISO 9001 ISO 14001 ISO22000 SUPPLY CHAIN PAS 28003 BCM BS 25999 IT DR Crisis Mgt PAS 77 SSM/1
  • 9. Issue - More reporting and more management time  Constant stream of people reporting to the Board  Board room time taken up with reporting not strategy  No common themes nor messages  Management want confidence and assurance (this is exactly what the standards are aimed at providing)  Always ask for money
  • 10. PAS99 – MS Integration E OHS&S Q BC E OH&S Q BC Common Common Common Common COMMON
  • 11. Management Systems  Generally the approach is:-  Standard Plan-Do-Check-Act model  BS describes establishing a Management System, its continuing operation and a process of continuing improvement  Subject specific information then fits into this model
  • 13. Implications for BS25999-2  This is the specification that will allow for certification  Must weigh the benefits of commonality with other standards and the current practices in business continuity  MSS approach will need adapting for our specialism whilst retaining the key characteristics of a certification standard and consistency with other related MSS  Scope statements allow application to largest and smallest of organisations  Scope must not be allowed to imply capability where none exists – for instance certification can only be achieved by addressing all steps and all controls in the standard
  • 14. 25999 Part 2  BS25999-2 has finished DPC  250 pages of comments !  Under review at present and being finalisde for the main committee to review in October 2007  Publication will be late October  Guidance Documents underway
  • 15. The Standards Pyramid ISO BS25999 BSI/CEN FT pl S E Context; c 2 Framework; Scope Pu 50 Why do BCM bl – S ic m (benefits/drivers)?; – a Options; Na ll Ch Relation to Other Implementation / Testing tio ar Risk Areas Specialised na iti Functions l/L es oc /V HR – IT – OR - Legal – Security al ol un – Procurement – Ethics – Sector Guides ta Supply SM ry E Sector/Industry specific guides* Construction, Utilities Financial Pharmaceutical Aerospace & Retail mining, oil Engineering and gas
  • 16. The Standards Pyramid ISO BS25999 BSI/CEN FT pl S E Context; c 2 Framework; Scope Pu 50 Why do BCM bl – S ic m (benefits/drivers)?; – a Options; Na ll Ch Relation to Other Implementation / Testing tio ar Risk Areas Specialised na iti Functions l/L es oc /V HR – IT – OR - Legal – Security al ol un – Procurement – Ethics – Sector Guides ta Supply SM ry E Sector/Industry specific guides* Construction, Utilities Financial Pharmaceutical Aerospace & Retail mining, oil Engineering and gas
  • 17. The Standards Pyramid ISO BS25999 BSI/CEN FT pl S E Context; c 2 Framework; Scope Pu 50 Why do BCM bl – S ic m (benefits/drivers)?; – a Options; Na ll Ch Relation to Other Implementation / Testing tio ar Risk Areas Specialised na iti Functions l/L es oc /V HR – IT – OR - Legal – Security al ol un – Procurement – Ethics – Sector Guides ta Supply SM ry E Sector/Industry specific guides* Construction, Utilities Financial Pharmaceutical Aerospace & Retail mining, oil Engineering and gas
  • 18. Accreditation Bodies  5 accreditation bodies interested  4 volunteers for pilot – however, concerns that they are “all the same”  Competence Criteria for Auditors being developed
  • 19. Other emerging standards  PAS77 – IT Continuity guidance  Developed in isolation from BS25999  Does not follow precepts of PAS56 or BS25999  Does not follow the management systems approach  Not clear how this fits with other related standards – e.g. ISO 20000 (ITIL)  ISO/IEC 24762 – Recovery Site Provision  Didn’t ask any recovery site vendors !
  • 20. Risk Management  Risk Management standard  BCM and Risk Management committees have swapped glossaries and trying to agree common terms  Where BS25999 uses risk assessment it has tried to reflect developments of risk management standard
  • 21. ISO IPOCM  Commencement  Broadly similar to Programme Management  Define scope, management commitment, policy  Planning  Broadly similar to Understanding Your Business  Includes risk assessment and Impact Analysis  Also response as includes Response Management  Implementation and Operation  Includes resourcing, competence, education and awareness and operational control structure  Performance Assessment  Evaluation of effectiveness including testing, maintenance and audit  Broadly similar to BS25999
  • 22. IPOCM  This is work in progress and a long way from a finalised document  Terminology slightly different from UK common usage and the business continuity industry as most of us have come to know it  For the most part UK practitioners can embrace the changes  Approach slightly different to BS25999/PAS56  But many common points
  • 23. Room for more?  Should there be standards in specific areas of business continuity?  PAS77 could be developed into a standard  Could there be an Incident Management standard?  Overall Governance standard?
  • 24. What happens next?  Committee continues in operation  Focus for other related committees (e.g. risk management)  Review of BS25999 so that subsequent revisions lead to improvements in the standard  Focus for expertise and contribution to ISO deliberations