SlideShare a Scribd company logo
WELCOME TO SECURE360 2012
 Did you remember to scan your badge for CPE
Credits? Ask your Room Volunteer for
assistance.
 Please complete the Session Survey front and
back (this is Room 4), and leave on your seat.
Note: “Session” is Tuesday or Wednesday
 Are you tweeting? #Sec360
ABOUT ME
• Certified Minnesota Emergency Manager
• Certified Business Continuity Professional
• Full-Time Director of Public Safety for North Hennepin Community
College
• Part-Time Security Consultant and Trainer
The opinions and views expressed in this presentation are my own and do not reflect
those of North Hennepin Community College, the Minnesota State Colleges and
University System, or the State of Minnesota.
I am not a representative of FEMA or the Federal Government. All of the information
presented here is based on my research of open-source FEMA training materials.
THEY’RE FROM THE GOVERNMENT, AND
HERE TO HELP…
• FEMA released new Continuity Of Operations Planning (COOP)
“Guidelines” in 2011.
• FEMA has a full-time Division and staff devoted to COOP
• FEMA has stated their COOP “Guidelines” will be required for companies
doing business with the government
• Historically, “Guidelines” have become “Requirements” over time.
• NIMS example
I THOUGHT WE ALREADY DID THAT?
Disaster Recovery Institute International (DRII)
British Standards Institution
National Fire Protection Agency 1600
International Organization for Standardization
Other regulatory guidance
IS THIS REQUIRED?
YES – if you are a Federal agency
YES – if you are a vendor who does business with the Federal government
PROBABLY – if you are a State or Local government agency that receives
Federal funding
Historically, “Guidelines” usually become “Requirements”
A TALE OF TWO PLANS
Business Continuity Planning (BCP)
VS.
Continuity Of Operations Planning (COOP)
COOP OBJECTIVES:
• Ensure the performance of an agency’s essential functions during a COOP
event.
• Reduce loss of life by minimizing damage and losses.
• Ensure the successful succession to office in the event a disruption renders
agency leadership unavailable to perform their responsibilities.
• Reduce or mitigate disruptions to operations.
• Ensure that agencies have alternate facilities from which to operate.
• Protect essential facilities, equipment, vital records, and other assets.
• Achieve a timely and orderly recovery from a COOP situation.
• Achieve a timely and orderly reconstitution from an emergency and
resume full service to internal and external customers.
ELEMENTS OF A COOP PLAN:
• Plans and Procedures
• Essential Functions
• Delegations of Authority
• Orders of Succession
• Alternate Operating Facilities
• Interoperable Communications
• Vital Files, Records and Databases
• Human Capital
• Test, Training and Exercise Program
• Devolution of Control and Direction
• Reconstitution Operations
• Agency Head Responsibilities
WHAT’S THE SAME?
Both programs stress the necessity of making continuity part of the
organizational culture.
COOP objectives are consistent with model BCP objectives
COMMON ELEMENTS
The foundation of planning -
• Identification of essential functions (COOP)
• Identification of critical functions (BCP)
COOP identifies “PMEFs” = Primary Mission Essential Functions
Government COOPs identify “MEF” = Federal Executive Branch Mission
Essential Functions and “NEF” = National Essential Functions
Both BCP and COOP use a similar Business Impact Analysis method.
BENEFITS AND GOALS ARE THE SAME
 Anticipate events and necessary response actions.
 Adapt to sudden changes in the operational environment.
 Improve their performance through the identification of essential functions, work
processes, and communications methods.
 Improve management controls by establishing measures for performance.
 Improve communication to support essential functions throughout the agency.
 The absolute necessity for personal and family preparedness is stressed in both
COOP and BCP.
WHAT’S DIFFERENT?
Terminology differs in some areas
COOP documents and guidance specifically exclude facility Emergency Plans
• BCP explicitly includes Emergency Response as a major function. This
includes protecting , communicating with and accounting for employees.
• It should be noted that the COOP model assumes these priorities are
addressed in a separate Emergency Operations Plan (EOP)
DISCRETION VS. REGULATION
COOP requirements are clearly standardized, while BCP standards are more
discretionary (except within highly regulated industries)
COOP compliance = regulatory compliance
BCP = best business practices and reduced liability exposure
TEST, TRAINING AND EXERCISE PROGRAM
COOP mandates each plan contain a Test, Training, and Exercise program
(TT&E) to support COOP. Specific requirements are identified for:
• Testing
• Training
• Exercising
• Participation
• After-Action and Compliance Reports
BCP program “best practices” include similar requirements, but are often not
followed through for a variety of reasons (lack of resources, funding, buy-in).
These are not “optional” in COOP.
MORE ALIKE THAN DIFFERENT
Although there are some differences between COOP and BCP programs both are
focused on the continuity of essential/critical functions following a disruptive
event.
BCP includes a more proactive component of mitigation/prevention and the added
emphasis on crisis management which not only comes into play with physical
events, but is also concerned with the risks associated with the protection of an
organization’s reputation and proper governance.
The core competencies for BCP and COOP are very similar and transferable
between the public and private sector.
Both make good business sense and support the strategic goals and objectives of an
organization.
CONSIDERATIONS
Keep following the BCP Industry-Based recommendations
- Could affect business with the Government in the long run
- What you are paying DRII for, FEMA does for free (well, tax dollars
anyway)
Transition to the FEMA COOP “Guidelines”
- Unproven, for the most part
- Unclear impact on underwriting
Is your plan EFFECTIVE?
Is your plan DEFENSIBLE?
Bottom line: who underwrites your risk?
IS COOP FOR YOUR BUSINESS?
What’s the impact on your business?
- Are you receiving Federal Funding?
- Are you in business with the Federal Government?
- Are you in business with State/Local Government?
Conduct a gap analysis between your current BCP-based plan and the Federal
COOP guidelines
Transition your plan’s structure and terminology to meet the COOP guidelines
and format
http://www.fema.gov/about/org/ncp/coop/index.shtm
Or just Google “FEMA COOP NCP”
THANKS FOR ATTENDING!
Any Questions?

More Related Content

Viewers also liked (13)

Sonny
SonnySonny
Sonny
 
Alicia PolíGons
Alicia PolíGonsAlicia PolíGons
Alicia PolíGons
 
2009/09/20 meeting
2009/09/20 meeting2009/09/20 meeting
2009/09/20 meeting
 
Non-stop stappen in Tilburg
Non-stop stappen in TilburgNon-stop stappen in Tilburg
Non-stop stappen in Tilburg
 
Andres
AndresAndres
Andres
 
Romeria
RomeriaRomeria
Romeria
 
IBD-Matanda
IBD-MatandaIBD-Matanda
IBD-Matanda
 
一心藥局來啦!!3
一心藥局來啦!!3一心藥局來啦!!3
一心藥局來啦!!3
 
Intelligence geosolution
Intelligence geosolutionIntelligence geosolution
Intelligence geosolution
 
Como gobiernan las empresas. Lecturas recomendadas. Luis Rico
Como gobiernan las empresas. Lecturas recomendadas. Luis RicoComo gobiernan las empresas. Lecturas recomendadas. Luis Rico
Como gobiernan las empresas. Lecturas recomendadas. Luis Rico
 
Grendene Implementação ERP WEB Based
Grendene Implementação ERP WEB BasedGrendene Implementação ERP WEB Based
Grendene Implementação ERP WEB Based
 
O Modelo SCOR
O Modelo SCORO Modelo SCOR
O Modelo SCOR
 
Sms4 Parking Official Presentation Oct2008
Sms4 Parking Official Presentation Oct2008Sms4 Parking Official Presentation Oct2008
Sms4 Parking Official Presentation Oct2008
 

Similar to Federal COOP

SMU Solved Assignment MB0052
SMU Solved Assignment MB0052SMU Solved Assignment MB0052
SMU Solved Assignment MB0052
Revlon
 
18Analysis of Organizational Behavior Issues i.docx
18Analysis of Organizational Behavior Issues i.docx18Analysis of Organizational Behavior Issues i.docx
18Analysis of Organizational Behavior Issues i.docx
RAJU852744
 
18Analysis of Organizational Behavior Issues i.docx
18Analysis of Organizational Behavior Issues i.docx18Analysis of Organizational Behavior Issues i.docx
18Analysis of Organizational Behavior Issues i.docx
aulasnilda
 
PMO and PPM Best Practices
PMO and PPM Best PracticesPMO and PPM Best Practices
PMO and PPM Best Practices
Jeff McClay
 

Similar to Federal COOP (20)

SMU Solved Assignment MB0052
SMU Solved Assignment MB0052SMU Solved Assignment MB0052
SMU Solved Assignment MB0052
 
Business Continuity as a Career
Business Continuity as a CareerBusiness Continuity as a Career
Business Continuity as a Career
 
Four steps to creating an enterprise Business Continuity program
Four steps to creating an enterprise Business Continuity program Four steps to creating an enterprise Business Continuity program
Four steps to creating an enterprise Business Continuity program
 
Top 4 Reasons to Outsource Non-Employee Workforce
Top 4 Reasons to Outsource Non-Employee WorkforceTop 4 Reasons to Outsource Non-Employee Workforce
Top 4 Reasons to Outsource Non-Employee Workforce
 
18Analysis of Organizational Behavior Issues i.docx
18Analysis of Organizational Behavior Issues i.docx18Analysis of Organizational Behavior Issues i.docx
18Analysis of Organizational Behavior Issues i.docx
 
18Analysis of Organizational Behavior Issues i.docx
18Analysis of Organizational Behavior Issues i.docx18Analysis of Organizational Behavior Issues i.docx
18Analysis of Organizational Behavior Issues i.docx
 
Where and how to start a solid lean transformation
Where and how to start a solid lean transformationWhere and how to start a solid lean transformation
Where and how to start a solid lean transformation
 
User adoption - the change management money shot
User adoption  - the change management money shotUser adoption  - the change management money shot
User adoption - the change management money shot
 
Coop awareness training
Coop awareness trainingCoop awareness training
Coop awareness training
 
Business Case Essentials Final
Business Case Essentials FinalBusiness Case Essentials Final
Business Case Essentials Final
 
Business Continuity Planning Presentation Overview
Business Continuity Planning Presentation OverviewBusiness Continuity Planning Presentation Overview
Business Continuity Planning Presentation Overview
 
ProfPrflNMSC
ProfPrflNMSCProfPrflNMSC
ProfPrflNMSC
 
Steve Sobak Implementing BCM In The Healthcare Industry : Singapore Experience
Steve Sobak Implementing BCM In The Healthcare Industry : Singapore ExperienceSteve Sobak Implementing BCM In The Healthcare Industry : Singapore Experience
Steve Sobak Implementing BCM In The Healthcare Industry : Singapore Experience
 
PMO and PPM Best Practices
PMO and PPM Best PracticesPMO and PPM Best Practices
PMO and PPM Best Practices
 
ThinkGRC Introduction to Business Continuity for Middle Management
ThinkGRC Introduction to Business Continuity for Middle ManagementThinkGRC Introduction to Business Continuity for Middle Management
ThinkGRC Introduction to Business Continuity for Middle Management
 
How to Build a Business Case for Online Employee Training - Webinar 09.04.14
How to Build a Business Case for Online Employee Training - Webinar 09.04.14How to Build a Business Case for Online Employee Training - Webinar 09.04.14
How to Build a Business Case for Online Employee Training - Webinar 09.04.14
 
The Seven Enablers & Constraints Of IT Service Management - Research Update 2011
The Seven Enablers & Constraints Of IT Service Management - Research Update 2011The Seven Enablers & Constraints Of IT Service Management - Research Update 2011
The Seven Enablers & Constraints Of IT Service Management - Research Update 2011
 
The 7 enablers and constraints of itsm 2011 v1 final
The 7 enablers and constraints of itsm 2011 v1 finalThe 7 enablers and constraints of itsm 2011 v1 final
The 7 enablers and constraints of itsm 2011 v1 final
 
Renewed Focus of Businesses and Practitioners on BCM (in Asia)
Renewed Focus of Businesses and Practitioners on BCM (in Asia)Renewed Focus of Businesses and Practitioners on BCM (in Asia)
Renewed Focus of Businesses and Practitioners on BCM (in Asia)
 
Creating an Effective Business Continuity Plan
Creating an Effective Business Continuity PlanCreating an Effective Business Continuity Plan
Creating an Effective Business Continuity Plan
 

Federal COOP

  • 1.
  • 2. WELCOME TO SECURE360 2012  Did you remember to scan your badge for CPE Credits? Ask your Room Volunteer for assistance.  Please complete the Session Survey front and back (this is Room 4), and leave on your seat. Note: “Session” is Tuesday or Wednesday  Are you tweeting? #Sec360
  • 3. ABOUT ME • Certified Minnesota Emergency Manager • Certified Business Continuity Professional • Full-Time Director of Public Safety for North Hennepin Community College • Part-Time Security Consultant and Trainer The opinions and views expressed in this presentation are my own and do not reflect those of North Hennepin Community College, the Minnesota State Colleges and University System, or the State of Minnesota. I am not a representative of FEMA or the Federal Government. All of the information presented here is based on my research of open-source FEMA training materials.
  • 4. THEY’RE FROM THE GOVERNMENT, AND HERE TO HELP… • FEMA released new Continuity Of Operations Planning (COOP) “Guidelines” in 2011. • FEMA has a full-time Division and staff devoted to COOP • FEMA has stated their COOP “Guidelines” will be required for companies doing business with the government • Historically, “Guidelines” have become “Requirements” over time. • NIMS example
  • 5. I THOUGHT WE ALREADY DID THAT? Disaster Recovery Institute International (DRII) British Standards Institution National Fire Protection Agency 1600 International Organization for Standardization Other regulatory guidance
  • 6. IS THIS REQUIRED? YES – if you are a Federal agency YES – if you are a vendor who does business with the Federal government PROBABLY – if you are a State or Local government agency that receives Federal funding Historically, “Guidelines” usually become “Requirements”
  • 7. A TALE OF TWO PLANS Business Continuity Planning (BCP) VS. Continuity Of Operations Planning (COOP)
  • 8. COOP OBJECTIVES: • Ensure the performance of an agency’s essential functions during a COOP event. • Reduce loss of life by minimizing damage and losses. • Ensure the successful succession to office in the event a disruption renders agency leadership unavailable to perform their responsibilities. • Reduce or mitigate disruptions to operations. • Ensure that agencies have alternate facilities from which to operate. • Protect essential facilities, equipment, vital records, and other assets. • Achieve a timely and orderly recovery from a COOP situation. • Achieve a timely and orderly reconstitution from an emergency and resume full service to internal and external customers.
  • 9. ELEMENTS OF A COOP PLAN: • Plans and Procedures • Essential Functions • Delegations of Authority • Orders of Succession • Alternate Operating Facilities • Interoperable Communications • Vital Files, Records and Databases • Human Capital • Test, Training and Exercise Program • Devolution of Control and Direction • Reconstitution Operations • Agency Head Responsibilities
  • 10. WHAT’S THE SAME? Both programs stress the necessity of making continuity part of the organizational culture. COOP objectives are consistent with model BCP objectives
  • 11. COMMON ELEMENTS The foundation of planning - • Identification of essential functions (COOP) • Identification of critical functions (BCP) COOP identifies “PMEFs” = Primary Mission Essential Functions Government COOPs identify “MEF” = Federal Executive Branch Mission Essential Functions and “NEF” = National Essential Functions Both BCP and COOP use a similar Business Impact Analysis method.
  • 12. BENEFITS AND GOALS ARE THE SAME  Anticipate events and necessary response actions.  Adapt to sudden changes in the operational environment.  Improve their performance through the identification of essential functions, work processes, and communications methods.  Improve management controls by establishing measures for performance.  Improve communication to support essential functions throughout the agency.  The absolute necessity for personal and family preparedness is stressed in both COOP and BCP.
  • 13. WHAT’S DIFFERENT? Terminology differs in some areas COOP documents and guidance specifically exclude facility Emergency Plans • BCP explicitly includes Emergency Response as a major function. This includes protecting , communicating with and accounting for employees. • It should be noted that the COOP model assumes these priorities are addressed in a separate Emergency Operations Plan (EOP)
  • 14. DISCRETION VS. REGULATION COOP requirements are clearly standardized, while BCP standards are more discretionary (except within highly regulated industries) COOP compliance = regulatory compliance BCP = best business practices and reduced liability exposure
  • 15. TEST, TRAINING AND EXERCISE PROGRAM COOP mandates each plan contain a Test, Training, and Exercise program (TT&E) to support COOP. Specific requirements are identified for: • Testing • Training • Exercising • Participation • After-Action and Compliance Reports BCP program “best practices” include similar requirements, but are often not followed through for a variety of reasons (lack of resources, funding, buy-in). These are not “optional” in COOP.
  • 16. MORE ALIKE THAN DIFFERENT Although there are some differences between COOP and BCP programs both are focused on the continuity of essential/critical functions following a disruptive event. BCP includes a more proactive component of mitigation/prevention and the added emphasis on crisis management which not only comes into play with physical events, but is also concerned with the risks associated with the protection of an organization’s reputation and proper governance. The core competencies for BCP and COOP are very similar and transferable between the public and private sector. Both make good business sense and support the strategic goals and objectives of an organization.
  • 17. CONSIDERATIONS Keep following the BCP Industry-Based recommendations - Could affect business with the Government in the long run - What you are paying DRII for, FEMA does for free (well, tax dollars anyway) Transition to the FEMA COOP “Guidelines” - Unproven, for the most part - Unclear impact on underwriting Is your plan EFFECTIVE? Is your plan DEFENSIBLE? Bottom line: who underwrites your risk?
  • 18. IS COOP FOR YOUR BUSINESS? What’s the impact on your business? - Are you receiving Federal Funding? - Are you in business with the Federal Government? - Are you in business with State/Local Government? Conduct a gap analysis between your current BCP-based plan and the Federal COOP guidelines Transition your plan’s structure and terminology to meet the COOP guidelines and format
  • 20.