AN APPROACH TO BUSINESS CONTINUITY MANAGEMENT(FOR THE PEOPLE WHO WORK FOR THE PEOPLE)PREPARED BYSHIBASURJYA &TRIDEEP
What is BCM ?
 WHAT ARE DISASTERS ?
IMPACT OF DISASTERTSUNAMITERRORIST ATTACKFIREEARTHQUAKETORNADOFLOOD
Project Initiation and PlanningBusiness impact analysis and risk analysisBusiness Continuity PlanningPreparing for possible emergencyDisaster recoveryBusiness recoveryTraining and awarenessTestingMaintenance and managing to keep it up to date.STEPS IN BCM
PROJECT INITIATION & PLANNING
In this phase an agreement is arrived upon by the senior management on the need of Business recovery and continuity planning.Development of BCP should be driven from the board level and a proper budget and an assurance of cooperation is of prime importance.Then this is followed by organization of planning team comprising of individuals of various departments and consultants to undertake detailed technical analysis and business recovery planning.Then the scope and the aim of Business recovery plan is identified and an brief over view of the recovery program is defined.
BUSINESS IMPACT ANALYSIS & RISK ANALYSIS
It involves understanding the business and identifying the key business functions.Data from the middle management is very helpful for the understanding the criticality of the functions of the various departments.Impacts on the business can be divided into qualitative and quantitative aspects.Quantitative aspects include the financial impacts.Qualitative aspects is the operational impacts.
Risk analysis starts by documenting the threats to these processes, their internal vulnerabilities and the consequences of various failure scenarios.At the end we estimate how to control the impact of the most serious ones.Risk analysis can also b done by using software packages with the database of historical threats and vulnerabilities relevant to the organization’s environment and business.CONT….
Business continuity planning
Preparing for possible emergencies
Identifying ways to prevent an emergency from turning into a disaster.Primary focus should be on key business practices.
BACK-UP AND RECOVERY STRATEGIESOrganizations should be prepared for possible emergency situations with back-up and preventive strategies.Alternative business process handing strategy.IT system backup and recovery strategy. Premises and essential equipment back-up  and recovery strategy.Customer service back-up and recovery strategy.Administration and operation back-up and recovery strategy.Information and documentation back-up and recovery strategy.Insurance coverage.
There are some key members of management and staff who will provide the technical and management skills necessary to achieve a smooth business recovery process.These key members should be picked according to the situation to avoid a chaos and will be responsible for implementation of BCP.Functional organization chart.BCP project coordinator and deputy for each key functional area.Key personnel, suppliers, vendors and emergency contact information.Manpower recovery strategy.The disaster recovery team.KEY BCP PERSONNEL AND SUPPLIES.
All organizations have documents, records and procedures, which are, considered vital part of their operation.Documents and records vital to business processes.Emergency stationary and office supplies.Media handling procedures.Emergency authorization procedures.Budget for back-up and recovery phase.KEY DOCUMENT AND PROCEDURES
The priority of during the disaster recovery phase are the safety and well being of the employees and other involved persons, Completion of Damage Assessment Form,the minimization of emergency itself,The minimization of the threat of further damage,Reestablishment of external services such as power, communication, water etc.
Assessment of initial emergency situation.Mobilizing the disaster recovery team and assessing the scale of emergency.Identification of potential disaster status.Involvement of emergency services.Assessing the potential business impact of the emergency.HANDLING TE EMERGENCY SITUATION
Communication is one of the most important ingredients.It is necessary to keep various groups informed like: disaster recovery team, business recovery team, senior &middle management, families of affected employees, media etc.Mobilizing the disaster recovery team.Disaster recovery phase report.NOTIFICATION AND REPORTING DURING DISASTER RECOVERY PHASE.
Business recovery
The business recovery involves the restoration of normal business operation after an unexpected event.The efficiency and the effectiveness of the procedures could have a direct bearing on organization’s ability to survive the emergency.
MANAGING THE BUSINESS RECOVERYMobilizing the business recovery team.Assessing extent of damage and business impact.Preparing specific recovery plan.Monitoring progress.Keeping everyone informed.Handing business operation back to regular management.Preparing business recovery phase report.
TRAINING & AWARENESSPDCA CYCLEPLANDOCHECKACT
A documented BCP awarenessAwareness program should embrace the culture & language of the enterpriseTrain-the-Trainer sessions should be providedKey aspect
Objective & scope of testsSimulating & setting the Test EnvironmentPreparation of Test DataIdentifying who is to conduct the TestsIdentifying who is to control & Monitor the TestsPreparing Feedback QuestionnairesPreparing Budget For Testing PhaseTraining the core Testing team for each Business unitPreparing the testing Policy & GuidelinesTEST PLANNING
Test Each part of Business Recovery ProcessTest Accuracy of Employee & Vendor Emergency Contact NumbersAssess test resultsCONDUCTING THE TESTS
PLAN MAINTENANCE & KEEPING IT UP-TO-DATE
Maintaining  & keeping the BCP up-to-date ensuring its effectiveness is a continuous processMaintenance procedures & schedules should be establishedA schedule for regular, systematic review of the content of the disaster recovery/business resumption plan should also be provided along with defining a procedure for making appropriate changes to plan
Getting management buy-in & commitment evidenced by the provision of adequate resources & budget with the responsibility of BCP resting with top executivesClearly spelling out management’s objectiveBCF should be designed from start as a business requirement“Whole-System” continuity should be plannedPlans should be continuously testedIt should be ensured that continuity plans are accessibleKey Success factors
85% of large organization have some sort of disaster recovery plan, a broader business recovery plan, & only 10% to 15 % of those are up to date2 of 5 business experiencing a disaster are likely to be gone in 5 years  GARTNER ESTIMATES
There is an Old Saying…No one plans to fail,       they just fail to plan.
Buisness contingency plan

Buisness contingency plan

  • 1.
    AN APPROACH TOBUSINESS CONTINUITY MANAGEMENT(FOR THE PEOPLE WHO WORK FOR THE PEOPLE)PREPARED BYSHIBASURJYA &TRIDEEP
  • 3.
  • 4.
    WHAT AREDISASTERS ?
  • 5.
    IMPACT OF DISASTERTSUNAMITERRORISTATTACKFIREEARTHQUAKETORNADOFLOOD
  • 6.
    Project Initiation andPlanningBusiness impact analysis and risk analysisBusiness Continuity PlanningPreparing for possible emergencyDisaster recoveryBusiness recoveryTraining and awarenessTestingMaintenance and managing to keep it up to date.STEPS IN BCM
  • 8.
  • 9.
    In this phasean agreement is arrived upon by the senior management on the need of Business recovery and continuity planning.Development of BCP should be driven from the board level and a proper budget and an assurance of cooperation is of prime importance.Then this is followed by organization of planning team comprising of individuals of various departments and consultants to undertake detailed technical analysis and business recovery planning.Then the scope and the aim of Business recovery plan is identified and an brief over view of the recovery program is defined.
  • 11.
  • 12.
    It involves understandingthe business and identifying the key business functions.Data from the middle management is very helpful for the understanding the criticality of the functions of the various departments.Impacts on the business can be divided into qualitative and quantitative aspects.Quantitative aspects include the financial impacts.Qualitative aspects is the operational impacts.
  • 13.
    Risk analysis startsby documenting the threats to these processes, their internal vulnerabilities and the consequences of various failure scenarios.At the end we estimate how to control the impact of the most serious ones.Risk analysis can also b done by using software packages with the database of historical threats and vulnerabilities relevant to the organization’s environment and business.CONT….
  • 14.
  • 16.
  • 17.
    Identifying ways toprevent an emergency from turning into a disaster.Primary focus should be on key business practices.
  • 18.
    BACK-UP AND RECOVERYSTRATEGIESOrganizations should be prepared for possible emergency situations with back-up and preventive strategies.Alternative business process handing strategy.IT system backup and recovery strategy. Premises and essential equipment back-up and recovery strategy.Customer service back-up and recovery strategy.Administration and operation back-up and recovery strategy.Information and documentation back-up and recovery strategy.Insurance coverage.
  • 19.
    There are somekey members of management and staff who will provide the technical and management skills necessary to achieve a smooth business recovery process.These key members should be picked according to the situation to avoid a chaos and will be responsible for implementation of BCP.Functional organization chart.BCP project coordinator and deputy for each key functional area.Key personnel, suppliers, vendors and emergency contact information.Manpower recovery strategy.The disaster recovery team.KEY BCP PERSONNEL AND SUPPLIES.
  • 20.
    All organizations havedocuments, records and procedures, which are, considered vital part of their operation.Documents and records vital to business processes.Emergency stationary and office supplies.Media handling procedures.Emergency authorization procedures.Budget for back-up and recovery phase.KEY DOCUMENT AND PROCEDURES
  • 22.
    The priority ofduring the disaster recovery phase are the safety and well being of the employees and other involved persons, Completion of Damage Assessment Form,the minimization of emergency itself,The minimization of the threat of further damage,Reestablishment of external services such as power, communication, water etc.
  • 23.
    Assessment of initialemergency situation.Mobilizing the disaster recovery team and assessing the scale of emergency.Identification of potential disaster status.Involvement of emergency services.Assessing the potential business impact of the emergency.HANDLING TE EMERGENCY SITUATION
  • 24.
    Communication is oneof the most important ingredients.It is necessary to keep various groups informed like: disaster recovery team, business recovery team, senior &middle management, families of affected employees, media etc.Mobilizing the disaster recovery team.Disaster recovery phase report.NOTIFICATION AND REPORTING DURING DISASTER RECOVERY PHASE.
  • 25.
  • 26.
    The business recoveryinvolves the restoration of normal business operation after an unexpected event.The efficiency and the effectiveness of the procedures could have a direct bearing on organization’s ability to survive the emergency.
  • 27.
    MANAGING THE BUSINESSRECOVERYMobilizing the business recovery team.Assessing extent of damage and business impact.Preparing specific recovery plan.Monitoring progress.Keeping everyone informed.Handing business operation back to regular management.Preparing business recovery phase report.
  • 28.
    TRAINING & AWARENESSPDCACYCLEPLANDOCHECKACT
  • 29.
    A documented BCPawarenessAwareness program should embrace the culture & language of the enterpriseTrain-the-Trainer sessions should be providedKey aspect
  • 32.
    Objective & scopeof testsSimulating & setting the Test EnvironmentPreparation of Test DataIdentifying who is to conduct the TestsIdentifying who is to control & Monitor the TestsPreparing Feedback QuestionnairesPreparing Budget For Testing PhaseTraining the core Testing team for each Business unitPreparing the testing Policy & GuidelinesTEST PLANNING
  • 33.
    Test Each partof Business Recovery ProcessTest Accuracy of Employee & Vendor Emergency Contact NumbersAssess test resultsCONDUCTING THE TESTS
  • 34.
    PLAN MAINTENANCE &KEEPING IT UP-TO-DATE
  • 35.
    Maintaining &keeping the BCP up-to-date ensuring its effectiveness is a continuous processMaintenance procedures & schedules should be establishedA schedule for regular, systematic review of the content of the disaster recovery/business resumption plan should also be provided along with defining a procedure for making appropriate changes to plan
  • 37.
    Getting management buy-in& commitment evidenced by the provision of adequate resources & budget with the responsibility of BCP resting with top executivesClearly spelling out management’s objectiveBCF should be designed from start as a business requirement“Whole-System” continuity should be plannedPlans should be continuously testedIt should be ensured that continuity plans are accessibleKey Success factors
  • 38.
    85% of largeorganization have some sort of disaster recovery plan, a broader business recovery plan, & only 10% to 15 % of those are up to date2 of 5 business experiencing a disaster are likely to be gone in 5 years GARTNER ESTIMATES
  • 39.
    There is anOld Saying…No one plans to fail, they just fail to plan.