SlideShare a Scribd company logo
Benefiting from BS 25999
Business Continuity Management

Lee Allison CISM CISSP CAS (lee@spiir.net)
Managing Director, Spiir Security Consulting
BSI Certification Auditor & Course Tutor




                                                    “80% of [SME] businesses affected by a
                                                    major incident like a fire either never re-
                                                    open or close within 18 months.”

                                                    Douglas Barnett
                                                    Risk control strategy manager
   Benefiting from BS 25999         IVC Nigeria     AXA Insurance
   Business Continuity Management   27th May 2009
Flexible Framework
•    Process based
•    High-level requirements
•    Applies to any organisation
•    The ‘what’ not the ‘how to’
•    Integration with other standards
       (e.g. ISO 27001, ISO 20000, ISO 9001, etc)

•  Auditable specification

Benefiting from BS 25999         IVC Nigeria
Business Continuity Management   27th May 2009
Management System
                                                               Implement & operate
 BS
 25999
 Part 2
                                  BCMS
                                                  Policy
                                                  Scope
                                                  Objectives
Law                                               Resources
Regs                                              Procedures
Req                                               Plans          Monitor &
                                                  …              review




 Benefiting from BS 25999         IVC Nigeria
 Business Continuity Management   27th May 2009
PDCA

                                                          The PDCA cycle is the
                                                          means of ensuring that
                                                          business continuity is
                                                          effectively managed and
                        Plan       Do                     improved.


                        Act        Check




                              Standardisation

Benefiting from BS 25999           IVC Nigeria
Business Continuity Management     27th May 2009
BCMS Maturity      Continual Improvement



                                                             X

                                                  X


                             X



                                                      Time

 Benefiting from BS 25999         IVC Nigeria
 Business Continuity Management   27th May 2009
BCM Lifecycle

                                                 The Business Continuity
                                                 Lifecycle represents the
                                                 continuous operation of
                                                 the business continuity
                                                 programme within the
                                                 organization.

                                                 The PDCA cycle applies to all
                                                 parts of the BCM Lifecycle.




Benefiting from BS 25999         IVC Nigeria
Business Continuity Management   27th May 2009
BCMS Audits
•  Requirement of the standard
•  Process auditing
•  BCMS effectiveness in achieving defined
   goals and objectives
•  Feedback to management
•  Part of the continual improvement process
•  Corrective actions

Benefiting from BS 25999         IVC Nigeria
Business Continuity Management   27th May 2009
Management Review
•    Requirement of the standard
•    Review of BCMS in achieving objectives
•    Directing improvement and changes
•    Taking action on weak areas
       –  Resources
       –  Budget
       –  etc


Benefiting from BS 25999         IVC Nigeria
Business Continuity Management   27th May 2009
Benefiting from BS 25999

•  Making intelligent decisions based on more than
   ‘gut’ feeling
•  $pend on what is necessary to achieve objectives
   and reduce expenditure in less critical areas
•  Assurance that things are actually as they seem
•  Pro-active in protecting long-term business goals
•  Duty of care to share holders, customers & staff
•  3rd party audit and certification
Benefiting from BS 25999         IVC Nigeria
Business Continuity Management   27th May 2009
Questions?



Benefiting from BS 25999         IVC Nigeria
Business Continuity Management   27th May 2009

More Related Content

Similar to Benefiting From Bs25999 Lee

Bs25999 business continuity implementation
Bs25999 business continuity implementationBs25999 business continuity implementation
Bs25999 business continuity implementationiso27001consulting
 
Establishing BCMS and Certifying Against ISO 22301
Establishing BCMS and Certifying Against ISO 22301Establishing BCMS and Certifying Against ISO 22301
Establishing BCMS and Certifying Against ISO 22301Continuity and Resilience
 
An overview of BCM certification
An overview of BCM certification An overview of BCM certification
An overview of BCM certification BCM Institute
 
27ian2011 silensec
27ian2011   silensec27ian2011   silensec
27ian2011 silensecAgora Group
 
CMI Conference - Change or Die
CMI Conference - Change or DieCMI Conference - Change or Die
CMI Conference - Change or Diecharliemb2
 
Managing and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's FirstManaging and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's FirstBCM Institute
 
Societal Security – the new standard ISO 22301 for Business Continuity Manage...
Societal Security – the new standard ISO 22301 for Business Continuity Manage...Societal Security – the new standard ISO 22301 for Business Continuity Manage...
Societal Security – the new standard ISO 22301 for Business Continuity Manage...Global Risk Forum GRFDavos
 
Understanding The Business Continuity Management Expectations And Good Practices
Understanding The Business Continuity Management Expectations And Good PracticesUnderstanding The Business Continuity Management Expectations And Good Practices
Understanding The Business Continuity Management Expectations And Good PracticesEnterprise Security Risk Management
 
Be Solid & Trusted New Change Management (Ncm) En Linked In
Be Solid & Trusted New Change Management (Ncm) En Linked InBe Solid & Trusted New Change Management (Ncm) En Linked In
Be Solid & Trusted New Change Management (Ncm) En Linked Infsw13169
 
Aufait Technologies - Introduction to BPM
Aufait Technologies - Introduction to BPMAufait Technologies - Introduction to BPM
Aufait Technologies - Introduction to BPMDinesh Kumar P
 
BCM Institute MTE Touw June Wah Singapore Business Federation - The National...
BCM Institute MTE  Touw June Wah Singapore Business Federation - The National...BCM Institute MTE  Touw June Wah Singapore Business Federation - The National...
BCM Institute MTE Touw June Wah Singapore Business Federation - The National...BCM Institute
 
Polarion Conf 2012 - CMMi Constellation and Polarion Integration
Polarion Conf 2012 - CMMi Constellation and Polarion IntegrationPolarion Conf 2012 - CMMi Constellation and Polarion Integration
Polarion Conf 2012 - CMMi Constellation and Polarion IntegrationEmerasoft, solutions to collaborate
 
Benefits tracking gsw
Benefits tracking gswBenefits tracking gsw
Benefits tracking gswwoznite65
 
Balanced Scorecard for CMMI Implementations - Eduardo Espinheira e Paula Gomes
Balanced Scorecard for CMMI Implementations - Eduardo Espinheira e Paula GomesBalanced Scorecard for CMMI Implementations - Eduardo Espinheira e Paula Gomes
Balanced Scorecard for CMMI Implementations - Eduardo Espinheira e Paula GomesPaula Gomes
 
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdfiso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdfVictorNagesparan
 

Similar to Benefiting From Bs25999 Lee (20)

Bs25999 business continuity implementation
Bs25999 business continuity implementationBs25999 business continuity implementation
Bs25999 business continuity implementation
 
Business Continuity Audit
Business Continuity AuditBusiness Continuity Audit
Business Continuity Audit
 
2010 BCM & Risk brochure
2010 BCM & Risk brochure2010 BCM & Risk brochure
2010 BCM & Risk brochure
 
Establishing BCMS and Certifying Against ISO 22301
Establishing BCMS and Certifying Against ISO 22301Establishing BCMS and Certifying Against ISO 22301
Establishing BCMS and Certifying Against ISO 22301
 
SunGard Continuity Programme Management
SunGard Continuity Programme ManagementSunGard Continuity Programme Management
SunGard Continuity Programme Management
 
An overview of BCM certification
An overview of BCM certification An overview of BCM certification
An overview of BCM certification
 
27ian2011 silensec
27ian2011   silensec27ian2011   silensec
27ian2011 silensec
 
CMI Conference - Change or Die
CMI Conference - Change or DieCMI Conference - Change or Die
CMI Conference - Change or Die
 
Managing and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's FirstManaging and Implementing a National BCM Programme: A World's First
Managing and Implementing a National BCM Programme: A World's First
 
Societal Security – the new standard ISO 22301 for Business Continuity Manage...
Societal Security – the new standard ISO 22301 for Business Continuity Manage...Societal Security – the new standard ISO 22301 for Business Continuity Manage...
Societal Security – the new standard ISO 22301 for Business Continuity Manage...
 
Understanding The Business Continuity Management Expectations And Good Practices
Understanding The Business Continuity Management Expectations And Good PracticesUnderstanding The Business Continuity Management Expectations And Good Practices
Understanding The Business Continuity Management Expectations And Good Practices
 
Be Solid & Trusted New Change Management (Ncm) En Linked In
Be Solid & Trusted New Change Management (Ncm) En Linked InBe Solid & Trusted New Change Management (Ncm) En Linked In
Be Solid & Trusted New Change Management (Ncm) En Linked In
 
Iso 22301
Iso 22301Iso 22301
Iso 22301
 
Aufait Technologies - Introduction to BPM
Aufait Technologies - Introduction to BPMAufait Technologies - Introduction to BPM
Aufait Technologies - Introduction to BPM
 
BCM Institute MTE Touw June Wah Singapore Business Federation - The National...
BCM Institute MTE  Touw June Wah Singapore Business Federation - The National...BCM Institute MTE  Touw June Wah Singapore Business Federation - The National...
BCM Institute MTE Touw June Wah Singapore Business Federation - The National...
 
Polarion Conf 2012 - CMMi Constellation and Polarion Integration
Polarion Conf 2012 - CMMi Constellation and Polarion IntegrationPolarion Conf 2012 - CMMi Constellation and Polarion Integration
Polarion Conf 2012 - CMMi Constellation and Polarion Integration
 
Accelerate Time to Business Outcomes through BPM
Accelerate Time to Business Outcomes through BPMAccelerate Time to Business Outcomes through BPM
Accelerate Time to Business Outcomes through BPM
 
Benefits tracking gsw
Benefits tracking gswBenefits tracking gsw
Benefits tracking gsw
 
Balanced Scorecard for CMMI Implementations - Eduardo Espinheira e Paula Gomes
Balanced Scorecard for CMMI Implementations - Eduardo Espinheira e Paula GomesBalanced Scorecard for CMMI Implementations - Eduardo Espinheira e Paula Gomes
Balanced Scorecard for CMMI Implementations - Eduardo Espinheira e Paula Gomes
 
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdfiso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
iso22301businesscontinuitymanagement-140207090550-phpapp01.pdf
 

Recently uploaded

Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111zoyaansari11365
 
Understanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and EmployeesUnderstanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and EmployeesDragon Dream Bar
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdcreerey
 
Equinox Gold Corporate Deck May 24th 2024
Equinox Gold Corporate Deck May 24th 2024Equinox Gold Corporate Deck May 24th 2024
Equinox Gold Corporate Deck May 24th 2024Equinox Gold Corp.
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small businessBen Wann
 
Maximizing Efficiency Migrating AccountEdge Data to QuickBooks.pdf
Maximizing Efficiency Migrating AccountEdge Data to QuickBooks.pdfMaximizing Efficiency Migrating AccountEdge Data to QuickBooks.pdf
Maximizing Efficiency Migrating AccountEdge Data to QuickBooks.pdfPaulBryant58
 
New Product Development.kjiy7ggbfdsddggo9lo
New Product Development.kjiy7ggbfdsddggo9loNew Product Development.kjiy7ggbfdsddggo9lo
New Product Development.kjiy7ggbfdsddggo9logalbokkahewagenitash
 
Lookback Analysis
Lookback AnalysisLookback Analysis
Lookback AnalysisSafe PaaS
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanasabutalha2013
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptseri bangash
 
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case Study
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case StudyTransforming Max Life Insurance with PMaps Job-Fit Assessments- Case Study
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case StudyPMaps Assessments
 
Team-Spandex-Northern University-CS1035.
Team-Spandex-Northern University-CS1035.Team-Spandex-Northern University-CS1035.
Team-Spandex-Northern University-CS1035.smalmahmud11
 
5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographerofm712785
 
20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdf20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdftjcomstrang
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxWorkforce Group
 
Business Valuation Principles for Entrepreneurs
Business Valuation Principles for EntrepreneursBusiness Valuation Principles for Entrepreneurs
Business Valuation Principles for EntrepreneursBen Wann
 
FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134LR1709MUSIC
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxCynthia Clay
 
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptxTaurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptxmy Pandit
 

Recently uploaded (20)

Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111
 
Understanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and EmployeesUnderstanding UAE Labour Law: Key Points for Employers and Employees
Understanding UAE Labour Law: Key Points for Employers and Employees
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
 
Equinox Gold Corporate Deck May 24th 2024
Equinox Gold Corporate Deck May 24th 2024Equinox Gold Corporate Deck May 24th 2024
Equinox Gold Corporate Deck May 24th 2024
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
 
Maximizing Efficiency Migrating AccountEdge Data to QuickBooks.pdf
Maximizing Efficiency Migrating AccountEdge Data to QuickBooks.pdfMaximizing Efficiency Migrating AccountEdge Data to QuickBooks.pdf
Maximizing Efficiency Migrating AccountEdge Data to QuickBooks.pdf
 
New Product Development.kjiy7ggbfdsddggo9lo
New Product Development.kjiy7ggbfdsddggo9loNew Product Development.kjiy7ggbfdsddggo9lo
New Product Development.kjiy7ggbfdsddggo9lo
 
Lookback Analysis
Lookback AnalysisLookback Analysis
Lookback Analysis
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about venice
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.ppt
 
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case Study
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case StudyTransforming Max Life Insurance with PMaps Job-Fit Assessments- Case Study
Transforming Max Life Insurance with PMaps Job-Fit Assessments- Case Study
 
Team-Spandex-Northern University-CS1035.
Team-Spandex-Northern University-CS1035.Team-Spandex-Northern University-CS1035.
Team-Spandex-Northern University-CS1035.
 
5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer5 Things You Need To Know Before Hiring a Videographer
5 Things You Need To Know Before Hiring a Videographer
 
20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdf20240425_ TJ Communications Credentials_compressed.pdf
20240425_ TJ Communications Credentials_compressed.pdf
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
 
Business Valuation Principles for Entrepreneurs
Business Valuation Principles for EntrepreneursBusiness Valuation Principles for Entrepreneurs
Business Valuation Principles for Entrepreneurs
 
Communicative rationality and the evolution of business ethics: corporate soc...
Communicative rationality and the evolution of business ethics: corporate soc...Communicative rationality and the evolution of business ethics: corporate soc...
Communicative rationality and the evolution of business ethics: corporate soc...
 
FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
 
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptxTaurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
Taurus Zodiac Sign_ Personality Traits and Sign Dates.pptx
 

Benefiting From Bs25999 Lee

  • 1. Benefiting from BS 25999 Business Continuity Management Lee Allison CISM CISSP CAS (lee@spiir.net) Managing Director, Spiir Security Consulting BSI Certification Auditor & Course Tutor “80% of [SME] businesses affected by a major incident like a fire either never re- open or close within 18 months.” Douglas Barnett Risk control strategy manager Benefiting from BS 25999 IVC Nigeria AXA Insurance Business Continuity Management 27th May 2009
  • 2. Flexible Framework •  Process based •  High-level requirements •  Applies to any organisation •  The ‘what’ not the ‘how to’ •  Integration with other standards (e.g. ISO 27001, ISO 20000, ISO 9001, etc) •  Auditable specification Benefiting from BS 25999 IVC Nigeria Business Continuity Management 27th May 2009
  • 3. Management System Implement & operate BS 25999 Part 2 BCMS Policy Scope Objectives Law Resources Regs Procedures Req Plans Monitor & … review Benefiting from BS 25999 IVC Nigeria Business Continuity Management 27th May 2009
  • 4. PDCA The PDCA cycle is the means of ensuring that business continuity is effectively managed and Plan Do improved. Act Check Standardisation Benefiting from BS 25999 IVC Nigeria Business Continuity Management 27th May 2009
  • 5. BCMS Maturity Continual Improvement X X X Time Benefiting from BS 25999 IVC Nigeria Business Continuity Management 27th May 2009
  • 6. BCM Lifecycle The Business Continuity Lifecycle represents the continuous operation of the business continuity programme within the organization. The PDCA cycle applies to all parts of the BCM Lifecycle. Benefiting from BS 25999 IVC Nigeria Business Continuity Management 27th May 2009
  • 7. BCMS Audits •  Requirement of the standard •  Process auditing •  BCMS effectiveness in achieving defined goals and objectives •  Feedback to management •  Part of the continual improvement process •  Corrective actions Benefiting from BS 25999 IVC Nigeria Business Continuity Management 27th May 2009
  • 8. Management Review •  Requirement of the standard •  Review of BCMS in achieving objectives •  Directing improvement and changes •  Taking action on weak areas –  Resources –  Budget –  etc Benefiting from BS 25999 IVC Nigeria Business Continuity Management 27th May 2009
  • 9. Benefiting from BS 25999 •  Making intelligent decisions based on more than ‘gut’ feeling •  $pend on what is necessary to achieve objectives and reduce expenditure in less critical areas •  Assurance that things are actually as they seem •  Pro-active in protecting long-term business goals •  Duty of care to share holders, customers & staff •  3rd party audit and certification Benefiting from BS 25999 IVC Nigeria Business Continuity Management 27th May 2009
  • 10. Questions? Benefiting from BS 25999 IVC Nigeria Business Continuity Management 27th May 2009