Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... ·...

21
Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP, MBCI, CCSP Malcolm B. Reid, CPP, FBCI, CBCP, CFE

Transcript of Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... ·...

Page 1: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Implementing a Successful Business Continuity ProgramJamie Sanderson-Reid, CPP, CISSP, MBCI, CCSP

Malcolm B. Reid, CPP, FBCI, CBCP, CFE

Page 2: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Today’s agenda

• Introduction

• Situation

• Challenge

• Solution

• Outcomes

• Discussion

Page 3: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

ABOUT YOUR SPEAKER

Page 4: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

ABOUT YOUR SPEAKER, CONT’D

Page 5: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

ABOUT YOUR CO-SPEAKER

Page 6: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

ABOUT YOUR CO-SPEAKER, CONT’D

Page 7: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Situation

• Global financial services organization

• Operations in AMERS, APAC,EMEA

• BC policy out of date and not clear on requirements

• Existing plans out of date and built around a tool which is now obsolete

• Audit requirements to have BC Program and Plans approved and validated

Page 8: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Challenge

• Multiple time zones and different cultures and priority for each business unit.

• “Fear” of transparency/sharing information openly across organization.

• Lack of understanding of relationship between crisis management, business continuity, and disaster recovery.

• Lack of accountability for updating business continuity documentation.

• Tool selection and cloud requirements for SaaS providers

Page 9: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Solution

• 7 Steps to BC Program

• PDCA Approach

• Project Management Techniques

• New Tool to manage all CM, BC, and DR plans and procedures

Page 10: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

PDCA Cycle

Plan

Do

Check

Act

Page 11: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

7 STEPS TO A WORLD-CLASS BUSINESS CONTINUITY PROGRAM

Page 12: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Initiation

Top Management Support

Business Driven Requirements in Policy

Page 13: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Awareness Value Add to Organization

Current Trends

Horizon Scanning

Competency TrainingPolicy Requirements

How to Use Tools

Relationship BuildingSeek Feedback

Understanding Group Needs

Simplify/Improve Processes

Injection

Page 14: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Assessment

Page 15: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Options to achieve RTO

Feasibility

Cost/Benefit

Strategy

Page 16: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Planning

ACTIONABLE PROCEDURES TAGGED TO NAMED TEAMS AND INDIVIDUALS

UNDERSTOOD THRESHOLDS FOR ACTIVATION &

ESCALATION

APPROPRIATE TOOLS

Page 17: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Testing

Key Threats/Hazards & Areas for

Improvement

Exercise Program Priorities

Exercise Objectives Core Capabilities

Page 18: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Auditing

Align with ISO22301 & Best Practices

Crosswalk/Gap Analysis against ISO22301

Policy Requirements Evidence

Page 19: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Outcome

• Program in place with path for maturity.

• Greater awareness of resilience requirements including alignment between crisis management, business continuity and disaster recovery.

• Actionable plans and procedures for recovery.

• Greater confidence in ability of the org to respond to any disruption.

• Completed all audit requirements.

Page 20: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,
Page 21: Implementing a Successful Business ... - Map Your Show › mys_shared › GSX19 › ... · Implementing a Successful Business Continuity Program Jamie Sanderson-Reid, CPP, CISSP,

Discussions & Questions

• Email: [email protected]

• Linkedin: