BCM With PWC 27 April v3 PDF
BCM With PWC 27 April v3 PDF
BCM With PWC 27 April v3 PDF
Business Continuity
Management
By. Mr. Chomnaphas Tangsook
Business Director
BSI Group ( Thailand) Co., Ltd
1
Contents slide
3
6
BS 25999
Not just about managing the high profile disasters but also the day
to day business disruptions
6
Defining Business
Continuity Management
BS 25999-2:2007, 2.4
7
8
Publication dates
BS25999-1 Code of Practice
December 2006
BS25999-2 Specification
Mid November 2007
Certification process
BSI develops certification process
8
9
9
10
Committee Profile:
33 members
10
11
Institute of Directors
11
12
Metropolitan Police
12
13
Continuity Forum
13
14
Suppliers
Clients /
Customers
Your
Subcontractors
Organization
Conduit
Organizations
Vendors
14
15
16
Sequence of Events of an Incident
17
Timeline
Act Do
Maintain Implement
and and
improve operate
Business
continuity Check
requirements Managed
Monitor
and and business
expectations review continuity
Scoping of BCM
Policy agreement & sign
off
Identification &
engagement of
stakeholders
Approach agreed
Roles & responsibilities
Understanding the organisation
20
Understanding the organization
Identify critical
Establish MTPD for Identify impacts from
activities according to
each activity disruption to activities
priority for recovery
Service Level
MTPD and RTO
Normal level of service
MTPD
OK!
RTO
Time
Incident management plan
MTPD Disaster!
RTO
Time
Incident management plan
response
Aligned to the objectives of the
organisations BCM strategy
Development of plans to
effectively manage a business
disruption to the point it is
contained
Creation of business continuity
plans designed to facilitate the
resumption of critical activities
Detailed plans covering people,
communication, roles &
responsibilities, locations,
resources etc
Incident Management Plan
Contents of an incident management plan include:
27
Business Continuity Plan
Contents of a business continuity plan include:
28
Exercising, reviewing and maintaining
29
Validates effectiveness of
plans
Ensures understanding of
plans, roles &
responsibilities
Identifies improvement
opportunities
Maintains relevance of
plans as result of business
changes
30
Exercising plans
Different types of exercise
Desk check
Walk through
Simulation
Component/activity
Full test
Exercising supports
awareness programme
competency development
BS 25999-2:2007, 4.4.2
Structure of BS 25999-2
31
1 Scope
2 Terms and definitions
3 Planning the BCMS
General requirements, establishing and managing, embedding
BCM in the organisations culture, documentation and records
4 Implementing and operating the BCMS
Understanding the organisation, determining strategy, developing
and implementing a response, exercising, maintaining and
reviewing
5 Monitoring and reviewing the BCMS
Internal audit, management review
6 Maintaining and improving the BCMS
Continual Improvement, preventive and corrective actions
Implementing and operating the
32
BCMS
4.1 Understanding the organisation
4.2 Determining business continuity strategy
4.3 Developing and implementing a BCM
response
4.4 Exercising, maintaining and reviewing BCM
arrangements
Monitoring and reviewing the
33
BCMS
5.1 Internal audit
5.2 Management review of the BCMS
Maintaining and improving the
34
BCMS
6.1 Preventive and corrective actions
6.2 Continual improvement
35
35
36
BS 25999 Clients
36