SlideShare uma empresa Scribd logo
1 de 19
Baixar para ler offline
Business Impact Analysis – Understanding
     what is required for BS 25999:2

               Hilary Estall
              28th April 2010
Contents
•   Introduction
•   Key elements of the BIA development process
•   Important terminology
•   Do’s and don’ts for certification to BS 25999:2
•   Lessons learnt from certified organisations
Straw Poll
• Hands up if you are seeking to align your BCM
  arrangements to BS 25999
• Hands up if you are planning to become
  certified to BS 25999
• Hands up if you have already achieved
  certification to BS 25999
• What are the drivers for your company to
  consider working with BS 25999?
Introduction
• 12 years experience in Management Systems
• In 2007 established BSI Business Continuity
  scheme for certifying companies to BS 25999
• Taken part in > 20 BS 25999 audits (at BSI)
• CBCI and AMBCI
• BCM/1 Committee Member
What to expect
• This presentation WILL    • This presentation WILL
  provide insight into        NOT tell you how to
  what BS 25999 Part 2        conduct a BIA for
  expects you to do to be     business continuity
  compliant (and to keep      management purposes
  the auditors happy)
• It will give you some
  tips on what to do and
  what to avoid
The BIA process
• Different ways (ie methodologies) to conduct
  a BIA. Questionnaires, workshops, 1 to 1’s.
• Choose wisely – what suits your business?
• The broader the involvement the better
• Ensure Top Management support (that means
  manpower and time!) to get best results
• The more time spent on the BIA the better
Key elements of the BIA development
process                                     Identify
                                         activities that
                   Critical activity      support the
                                                               Identify
                      resource           key products
                                                             impacts over
                    requirements          and services
                                                                 time




    RTO for the                                                              Establish the
  resumption of                             BIA                              MTPD for each
 critical activities                     Elements                               activity




                Determine what
                      BCM                                    Recovery priority
               arrangements are                               for all activities
                  in place for            Identify all       and identify the
               suppliers/Partners       dependencies         critical activities
                                          relevant to
                                       critical activities
BIA elements
• Ensure that BCMS scope includes the same
  key products and services as the BIA does
• Consider ALL activities that are performed to
  support its key products and services (not just
  critical ones). This will support the
  prioritisation process later
                    Audit Aware
  Auditors will expect to see a clear focus on the
  products and services that have been selected
BIA elements cont..
• Identify the impact to these activities if
  disrupted and how these would vary over time
                   Audit aware
  Be able to discuss what the business considers
  to be the biggest impacts and why
  Be able to discuss what timeframes were
  selected and why. (eg. Peak work periods).
  What is the link back to business priorities?
BIA elements cont..
• Establish the Maximum Tolerable Period of
  Disruption (MTPD) for each activity
• Prioritise activities for recovery and identify
  the critical activities

• Remember that activities not considered
  critical now may become so during a
  disruption
BIA elements cont..
• Identify all dependencies on critical activities
  including suppliers and outsource partners
• Determine BCM arrangements for the
  suppliers/outsourced partners on whom
  critical activities depend
                     Audit Aware
• This goes beyond asking if they have a BC
  Policy. Demonstrate a deeper understanding
  of their arrangements for the relevant
  products and services that they provide to you
Important terminology
• Maximum Tolerable Period of Disruption
  “Duration after which an organisation’s viability will
    be irrevocably threatened if product and service
    delivery cannot be resumed” BS 25999:1

• Recovery Time Objective
  “Target time set for resumption of product, service
    or activity delivery after an incident” BS 25999:1
Maximum Tolerable Period of
                     Disruption
               • Overall BCMS entity (based on chosen scope)
Organisation




               • Corporate level definition or
 Product or
  Service      • Deliverable outputs

               • Operational relationship with Product/Services or
  Activity     • Support/Strategic relationship


               • Resources, suppliers, outsource partners etc
Dependencies
Recovery Time Objective
• Use the same approach as for MTPD (4 levels)

• Expand the application of RTO’s to beyond
  critical activities to include product/service
  and dependencies
Clarification provided by BCM/1
• BCM/1 approved a clarification note in June
  2009 to help BCM practitioners
• Published on Continuity Central website
http://www.continuitycentral.com/feature0677.
  html
• Article on MTPD by Jacque Rupert
http://www.continuitycentral.com/feature0675.
  html
Do’s and don’ts for certification to
       BS 25999:2 (BIA only)
• DO make sure that Top     • DON’T adopt a
  Management are fully        template mentality and
  aware of BIA findings       copy someone else’s
  and are able to discuss     BIA format for the sake
  them                        of it
• DO be able to justify the • DON’T over complicate
  methodology & content       the BIA so that it
  of your BIA                 becomes a monster
• DO adhere to every
  clause requirement
Lessons learnt from certified
            organisations
• “Seek contributions from a wide range of staff”
• “Take sufficient time to get it right. If you do your
  BIA properly, writing plans becomes very easy”
• “Engage key customers and suppliers”
• “Make sure you have evidence that you have covered
  every element of the standard.”
• “the template in particular has evolved through
  multiple iterations based on user feedback.”
Thanks for listening

       Hilary Estall

Hilary.estall@pslinfo.co.uk
    www.pslinfo.co.uk

Mais conteúdo relacionado

Mais procurados

Compliance Identification Risk Monitoring Risk Mitigation Risk Assessment Reg...
Compliance Identification Risk Monitoring Risk Mitigation Risk Assessment Reg...Compliance Identification Risk Monitoring Risk Mitigation Risk Assessment Reg...
Compliance Identification Risk Monitoring Risk Mitigation Risk Assessment Reg...SlideTeam
 
Commercial Banking Trends book 2022
Commercial Banking Trends book 2022Commercial Banking Trends book 2022
Commercial Banking Trends book 2022Capgemini
 
Erp governance methodology and case studies v rjt
Erp governance methodology and case studies  v rjtErp governance methodology and case studies  v rjt
Erp governance methodology and case studies v rjtJames Sutter
 
Building a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintBuilding a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintluweinet
 
GRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveGRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveMax Neira Schliemann
 
Master Data Management - Aligning Data, Process, and Governance
Master Data Management - Aligning Data, Process, and GovernanceMaster Data Management - Aligning Data, Process, and Governance
Master Data Management - Aligning Data, Process, and GovernanceDATAVERSITY
 
BCMS Presentation1
BCMS Presentation1BCMS Presentation1
BCMS Presentation1barbytee
 
Business analysis Fundamentals | Fundamentals of business analysis
Business analysis Fundamentals | Fundamentals of business analysisBusiness analysis Fundamentals | Fundamentals of business analysis
Business analysis Fundamentals | Fundamentals of business analysisTechcanvass
 
BUSINESS IMPACT ‎ANALYSIS- DRM
BUSINESS IMPACT ‎ANALYSIS- DRMBUSINESS IMPACT ‎ANALYSIS- DRM
BUSINESS IMPACT ‎ANALYSIS- DRMLibcorpio
 
Data Center Consolidation and Optimization By Magnus Manders, CTO of Infrastr...
Data Center Consolidation and Optimization By Magnus Manders, CTO of Infrastr...Data Center Consolidation and Optimization By Magnus Manders, CTO of Infrastr...
Data Center Consolidation and Optimization By Magnus Manders, CTO of Infrastr...Capgemini
 
Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management systemsubbusai82
 
Introduction to Data Governance
Introduction to Data GovernanceIntroduction to Data Governance
Introduction to Data GovernanceJohn Bao Vuu
 
How to Strengthen Enterprise Data Governance with Data Quality
How to Strengthen Enterprise Data Governance with Data QualityHow to Strengthen Enterprise Data Governance with Data Quality
How to Strengthen Enterprise Data Governance with Data QualityDATAVERSITY
 
The Non-Invasive Data Governance Framework
The Non-Invasive Data Governance FrameworkThe Non-Invasive Data Governance Framework
The Non-Invasive Data Governance FrameworkDATAVERSITY
 
Top 7 Capabilities for Next-Gen Master Data Management
Top 7 Capabilities for Next-Gen Master Data ManagementTop 7 Capabilities for Next-Gen Master Data Management
Top 7 Capabilities for Next-Gen Master Data ManagementDATAVERSITY
 
Requirements for a Master Data Management (MDM) Solution - Presentation
Requirements for a Master Data Management (MDM) Solution - PresentationRequirements for a Master Data Management (MDM) Solution - Presentation
Requirements for a Master Data Management (MDM) Solution - PresentationVicki McCracken
 
Business Relationship Management Executive Brief
Business Relationship Management Executive BriefBusiness Relationship Management Executive Brief
Business Relationship Management Executive BriefSvetlana Sidenko
 

Mais procurados (20)

Compliance Identification Risk Monitoring Risk Mitigation Risk Assessment Reg...
Compliance Identification Risk Monitoring Risk Mitigation Risk Assessment Reg...Compliance Identification Risk Monitoring Risk Mitigation Risk Assessment Reg...
Compliance Identification Risk Monitoring Risk Mitigation Risk Assessment Reg...
 
Commercial Banking Trends book 2022
Commercial Banking Trends book 2022Commercial Banking Trends book 2022
Commercial Banking Trends book 2022
 
Erp governance methodology and case studies v rjt
Erp governance methodology and case studies  v rjtErp governance methodology and case studies  v rjt
Erp governance methodology and case studies v rjt
 
Business Continuity Planning Presentation
Business Continuity Planning PresentationBusiness Continuity Planning Presentation
Business Continuity Planning Presentation
 
Building a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprintBuilding a business impact analysis (bia) process a hands on blueprint
Building a business impact analysis (bia) process a hands on blueprint
 
GRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveGRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance Executive
 
Master Data Management - Aligning Data, Process, and Governance
Master Data Management - Aligning Data, Process, and GovernanceMaster Data Management - Aligning Data, Process, and Governance
Master Data Management - Aligning Data, Process, and Governance
 
Integrated GRC
Integrated GRCIntegrated GRC
Integrated GRC
 
BCMS Presentation1
BCMS Presentation1BCMS Presentation1
BCMS Presentation1
 
Business analysis Fundamentals | Fundamentals of business analysis
Business analysis Fundamentals | Fundamentals of business analysisBusiness analysis Fundamentals | Fundamentals of business analysis
Business analysis Fundamentals | Fundamentals of business analysis
 
BUSINESS IMPACT ‎ANALYSIS- DRM
BUSINESS IMPACT ‎ANALYSIS- DRMBUSINESS IMPACT ‎ANALYSIS- DRM
BUSINESS IMPACT ‎ANALYSIS- DRM
 
Master Data Management
Master Data ManagementMaster Data Management
Master Data Management
 
Data Center Consolidation and Optimization By Magnus Manders, CTO of Infrastr...
Data Center Consolidation and Optimization By Magnus Manders, CTO of Infrastr...Data Center Consolidation and Optimization By Magnus Manders, CTO of Infrastr...
Data Center Consolidation and Optimization By Magnus Manders, CTO of Infrastr...
 
Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management system
 
Introduction to Data Governance
Introduction to Data GovernanceIntroduction to Data Governance
Introduction to Data Governance
 
How to Strengthen Enterprise Data Governance with Data Quality
How to Strengthen Enterprise Data Governance with Data QualityHow to Strengthen Enterprise Data Governance with Data Quality
How to Strengthen Enterprise Data Governance with Data Quality
 
The Non-Invasive Data Governance Framework
The Non-Invasive Data Governance FrameworkThe Non-Invasive Data Governance Framework
The Non-Invasive Data Governance Framework
 
Top 7 Capabilities for Next-Gen Master Data Management
Top 7 Capabilities for Next-Gen Master Data ManagementTop 7 Capabilities for Next-Gen Master Data Management
Top 7 Capabilities for Next-Gen Master Data Management
 
Requirements for a Master Data Management (MDM) Solution - Presentation
Requirements for a Master Data Management (MDM) Solution - PresentationRequirements for a Master Data Management (MDM) Solution - Presentation
Requirements for a Master Data Management (MDM) Solution - Presentation
 
Business Relationship Management Executive Brief
Business Relationship Management Executive BriefBusiness Relationship Management Executive Brief
Business Relationship Management Executive Brief
 

Destaque

Bs25999 business continuity implementation
Bs25999 business continuity implementationBs25999 business continuity implementation
Bs25999 business continuity implementationiso27001consulting
 
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015Digital Queensland
 
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...Digital Queensland
 
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...Digital Queensland
 
Business Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In PracticeBusiness Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In PracticeDipankar Ghosh
 

Destaque (6)

Bs25999 business continuity implementation
Bs25999 business continuity implementationBs25999 business continuity implementation
Bs25999 business continuity implementation
 
Business Continuity.Bs25999
Business Continuity.Bs25999Business Continuity.Bs25999
Business Continuity.Bs25999
 
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015
Partners in Technology (PiT) - SME Perspective - Bay Technologies - 21 July 2015
 
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...
Partners in Technology (PiT) - Innovations in Council Service Delivery - 27 M...
 
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...
Partners in Technology (PiT) - A Qeensland SME perspective - Solute Consultin...
 
Business Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In PracticeBusiness Impact Analysis - Clause 4 Of BS25999 In Practice
Business Impact Analysis - Clause 4 Of BS25999 In Practice
 

Semelhante a Technical Briefing: Business Impact Analysis: understanding what is required for BS 25999

How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?Abdul Naseer
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...PECB
 
Business Continuity Management: How to get started
Business Continuity Management: How to get startedBusiness Continuity Management: How to get started
Business Continuity Management: How to get startedIT Governance Ltd
 
02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIABCM Institute
 
The project manager and business analyst partnership - ensuring project success
The project manager and business analyst partnership - ensuring project successThe project manager and business analyst partnership - ensuring project success
The project manager and business analyst partnership - ensuring project successMark Troncone MBA, PMP, CBAP, ITILv3, CSM
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity ManagementECC International
 
Business continuity management system overveiw
Business continuity management system  overveiwBusiness continuity management system  overveiw
Business continuity management system overveiwNaresh Rao
 
EBR's: prepping, producing, and presenting
EBR's: prepping, producing, and presentingEBR's: prepping, producing, and presenting
EBR's: prepping, producing, and presentingGainsight
 
BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...BCM Institute
 
Sami Tayara BI Presentation ATT Jan07B
Sami Tayara BI Presentation ATT Jan07BSami Tayara BI Presentation ATT Jan07B
Sami Tayara BI Presentation ATT Jan07BSami Tayara
 
Business continuity management www.reconglobal.in
Business continuity management   www.reconglobal.inBusiness continuity management   www.reconglobal.in
Business continuity management www.reconglobal.inSatya Yadav
 
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...TheBCI
 
NQA ISO 22301 Business Continuity Checklist
NQA ISO 22301 Business Continuity ChecklistNQA ISO 22301 Business Continuity Checklist
NQA ISO 22301 Business Continuity ChecklistNQA
 
How Business Process Assurance Can Enhance Quality When Applying Agile Method...
How Business Process Assurance Can Enhance Quality When Applying Agile Method...How Business Process Assurance Can Enhance Quality When Applying Agile Method...
How Business Process Assurance Can Enhance Quality When Applying Agile Method...Cognizant
 
Bpr training v 2.0 4.1.2012
Bpr training   v 2.0 4.1.2012Bpr training   v 2.0 4.1.2012
Bpr training v 2.0 4.1.2012Mohammad Saleh
 
90 days to make a difference - approach
90 days to make a difference - approach90 days to make a difference - approach
90 days to make a difference - approachStuart Creasey
 

Semelhante a Technical Briefing: Business Impact Analysis: understanding what is required for BS 25999 (20)

How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?How to integrate BCMS with Organization's culture?
How to integrate BCMS with Organization's culture?
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
 
Business Continuity Management: How to get started
Business Continuity Management: How to get startedBusiness Continuity Management: How to get started
Business Continuity Management: How to get started
 
02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA
 
The project manager and business analyst partnership - ensuring project success
The project manager and business analyst partnership - ensuring project successThe project manager and business analyst partnership - ensuring project success
The project manager and business analyst partnership - ensuring project success
 
Cisco Data Sheet SORM
Cisco Data Sheet SORM Cisco Data Sheet SORM
Cisco Data Sheet SORM
 
CISSP Chapter 1 BCP
CISSP Chapter 1 BCPCISSP Chapter 1 BCP
CISSP Chapter 1 BCP
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
Business continuity management system overveiw
Business continuity management system  overveiwBusiness continuity management system  overveiw
Business continuity management system overveiw
 
Business Continuity Audit
Business Continuity AuditBusiness Continuity Audit
Business Continuity Audit
 
SAMA BCM Framework
SAMA BCM Framework SAMA BCM Framework
SAMA BCM Framework
 
EBR's: prepping, producing, and presenting
EBR's: prepping, producing, and presentingEBR's: prepping, producing, and presenting
EBR's: prepping, producing, and presenting
 
BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...BCM Institute MTE  Jeremy Wong - Business Continuty Management Benchmarking i...
BCM Institute MTE Jeremy Wong - Business Continuty Management Benchmarking i...
 
Sami Tayara BI Presentation ATT Jan07B
Sami Tayara BI Presentation ATT Jan07BSami Tayara BI Presentation ATT Jan07B
Sami Tayara BI Presentation ATT Jan07B
 
Business continuity management www.reconglobal.in
Business continuity management   www.reconglobal.inBusiness continuity management   www.reconglobal.in
Business continuity management www.reconglobal.in
 
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...Bci NeBe conf 2017   thought provoking - challenging the maturity of bcm v2 -...
Bci NeBe conf 2017 thought provoking - challenging the maturity of bcm v2 -...
 
NQA ISO 22301 Business Continuity Checklist
NQA ISO 22301 Business Continuity ChecklistNQA ISO 22301 Business Continuity Checklist
NQA ISO 22301 Business Continuity Checklist
 
How Business Process Assurance Can Enhance Quality When Applying Agile Method...
How Business Process Assurance Can Enhance Quality When Applying Agile Method...How Business Process Assurance Can Enhance Quality When Applying Agile Method...
How Business Process Assurance Can Enhance Quality When Applying Agile Method...
 
Bpr training v 2.0 4.1.2012
Bpr training   v 2.0 4.1.2012Bpr training   v 2.0 4.1.2012
Bpr training v 2.0 4.1.2012
 
90 days to make a difference - approach
90 days to make a difference - approach90 days to make a difference - approach
90 days to make a difference - approach
 

Mais de BSI British Standards Institution

BSI Brochure: Customer Contact Association Global Standard - Your partner for...
BSI Brochure: Customer Contact Association Global Standard - Your partner for...BSI Brochure: Customer Contact Association Global Standard - Your partner for...
BSI Brochure: Customer Contact Association Global Standard - Your partner for...BSI British Standards Institution
 
Guide to making a new standard - Standards & Standardization - Making a New W...
Guide to making a new standard - Standards & Standardization - Making a New W...Guide to making a new standard - Standards & Standardization - Making a New W...
Guide to making a new standard - Standards & Standardization - Making a New W...BSI British Standards Institution
 
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE Direc...
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE  Direc...PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE  Direc...
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE Direc...BSI British Standards Institution
 
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...BSI British Standards Institution
 
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?BSI British Standards Institution
 
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...BSI British Standards Institution
 

Mais de BSI British Standards Institution (20)

BSI Brochure: Customer Contact Association Global Standard - Your partner for...
BSI Brochure: Customer Contact Association Global Standard - Your partner for...BSI Brochure: Customer Contact Association Global Standard - Your partner for...
BSI Brochure: Customer Contact Association Global Standard - Your partner for...
 
BSI's Top 10 standards that matter to consumers
BSI's Top 10 standards that matter to consumersBSI's Top 10 standards that matter to consumers
BSI's Top 10 standards that matter to consumers
 
BSI leaflet on easy-to-open packaging
BSI leaflet on easy-to-open packagingBSI leaflet on easy-to-open packaging
BSI leaflet on easy-to-open packaging
 
Defining social responsibility with BS ISO 26000
Defining social responsibility with BS ISO 26000Defining social responsibility with BS ISO 26000
Defining social responsibility with BS ISO 26000
 
Guide to making a new standard - Standards & Standardization - Making a New W...
Guide to making a new standard - Standards & Standardization - Making a New W...Guide to making a new standard - Standards & Standardization - Making a New W...
Guide to making a new standard - Standards & Standardization - Making a New W...
 
Standards & standardization handout
Standards & standardization handoutStandards & standardization handout
Standards & standardization handout
 
A proposal for working with higher education
A proposal for working with higher educationA proposal for working with higher education
A proposal for working with higher education
 
Standards and standardization
Standards and standardization Standards and standardization
Standards and standardization
 
Standards and standardization
Standards and standardizationStandards and standardization
Standards and standardization
 
The perfect business continuity manager
The perfect business continuity managerThe perfect business continuity manager
The perfect business continuity manager
 
Nano website presentation bsi template december 2010
Nano website presentation bsi template december 2010Nano website presentation bsi template december 2010
Nano website presentation bsi template december 2010
 
Nano website presentation bsi template december 2010
Nano website presentation bsi template december 2010Nano website presentation bsi template december 2010
Nano website presentation bsi template december 2010
 
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE Direc...
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE  Direc...PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE  Direc...
PAS 2015: The Disruptive Challenges facing the NHS, Dr Penny Bevan CBE Direc...
 
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...
PAS 2015: NHS Resilience Next Steps, Phil Storr Head of NHS Resilience Projec...
 
Fire safety brochure
Fire safety brochureFire safety brochure
Fire safety brochure
 
BSI Presentation: Working with Higher Education
BSI Presentation: Working with Higher EducationBSI Presentation: Working with Higher Education
BSI Presentation: Working with Higher Education
 
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?
Case Study: The BS25999 Experience: how BS25999 is delivering for HDNL?
 
Case Study: BS25999 in a multi-site enterprise
Case Study: BS25999 in a multi-site enterpriseCase Study: BS25999 in a multi-site enterprise
Case Study: BS25999 in a multi-site enterprise
 
PD25888: Recovery Planning
PD25888: Recovery PlanningPD25888: Recovery Planning
PD25888: Recovery Planning
 
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...
PAS 150 The Clinical Viewpoint - Diane Playford - VRSIG Chair, British Societ...
 

Último

Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environmentelijahj01012
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMintel Group
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03DallasHaselhorst
 
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City GurgaonCall Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaoncallgirls2057
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesKeppelCorporation
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607dollysharma2066
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCRashishs7044
 
Appkodes Tinder Clone Script with Customisable Solutions.pptx
Appkodes Tinder Clone Script with Customisable Solutions.pptxAppkodes Tinder Clone Script with Customisable Solutions.pptx
Appkodes Tinder Clone Script with Customisable Solutions.pptxappkodes
 
Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...Peter Ward
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFChandresh Chudasama
 
PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationAnamaria Contreras
 
PB Project 1: Exploring Your Personal Brand
PB Project 1: Exploring Your Personal BrandPB Project 1: Exploring Your Personal Brand
PB Project 1: Exploring Your Personal BrandSharisaBethune
 
MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?Olivia Kresic
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckHajeJanKamps
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Riya Pathan
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCRashishs7044
 
Call Girls Contact Number Andheri 9920874524
Call Girls Contact Number Andheri 9920874524Call Girls Contact Number Andheri 9920874524
Call Girls Contact Number Andheri 9920874524najka9823
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Americas Got Grants
 

Último (20)

Cyber Security Training in Office Environment
Cyber Security Training in Office EnvironmentCyber Security Training in Office Environment
Cyber Security Training in Office Environment
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 Edition
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03
 
Call Us ➥9319373153▻Call Girls In North Goa
Call Us ➥9319373153▻Call Girls In North GoaCall Us ➥9319373153▻Call Girls In North Goa
Call Us ➥9319373153▻Call Girls In North Goa
 
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City GurgaonCall Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation Slides
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR
 
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
 
Appkodes Tinder Clone Script with Customisable Solutions.pptx
Appkodes Tinder Clone Script with Customisable Solutions.pptxAppkodes Tinder Clone Script with Customisable Solutions.pptx
Appkodes Tinder Clone Script with Customisable Solutions.pptx
 
Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDF
 
PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement Presentation
 
PB Project 1: Exploring Your Personal Brand
PB Project 1: Exploring Your Personal BrandPB Project 1: Exploring Your Personal Brand
PB Project 1: Exploring Your Personal Brand
 
MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?MAHA Global and IPR: Do Actions Speak Louder Than Words?
MAHA Global and IPR: Do Actions Speak Louder Than Words?
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
 
Call Girls Contact Number Andheri 9920874524
Call Girls Contact Number Andheri 9920874524Call Girls Contact Number Andheri 9920874524
Call Girls Contact Number Andheri 9920874524
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...
 

Technical Briefing: Business Impact Analysis: understanding what is required for BS 25999

  • 1. Business Impact Analysis – Understanding what is required for BS 25999:2 Hilary Estall 28th April 2010
  • 2. Contents • Introduction • Key elements of the BIA development process • Important terminology • Do’s and don’ts for certification to BS 25999:2 • Lessons learnt from certified organisations
  • 3. Straw Poll • Hands up if you are seeking to align your BCM arrangements to BS 25999 • Hands up if you are planning to become certified to BS 25999 • Hands up if you have already achieved certification to BS 25999 • What are the drivers for your company to consider working with BS 25999?
  • 4. Introduction • 12 years experience in Management Systems • In 2007 established BSI Business Continuity scheme for certifying companies to BS 25999 • Taken part in > 20 BS 25999 audits (at BSI) • CBCI and AMBCI • BCM/1 Committee Member
  • 5. What to expect • This presentation WILL • This presentation WILL provide insight into NOT tell you how to what BS 25999 Part 2 conduct a BIA for expects you to do to be business continuity compliant (and to keep management purposes the auditors happy) • It will give you some tips on what to do and what to avoid
  • 6.
  • 7. The BIA process • Different ways (ie methodologies) to conduct a BIA. Questionnaires, workshops, 1 to 1’s. • Choose wisely – what suits your business? • The broader the involvement the better • Ensure Top Management support (that means manpower and time!) to get best results • The more time spent on the BIA the better
  • 8. Key elements of the BIA development process Identify activities that Critical activity support the Identify resource key products impacts over requirements and services time RTO for the Establish the resumption of BIA MTPD for each critical activities Elements activity Determine what BCM Recovery priority arrangements are for all activities in place for Identify all and identify the suppliers/Partners dependencies critical activities relevant to critical activities
  • 9. BIA elements • Ensure that BCMS scope includes the same key products and services as the BIA does • Consider ALL activities that are performed to support its key products and services (not just critical ones). This will support the prioritisation process later Audit Aware Auditors will expect to see a clear focus on the products and services that have been selected
  • 10. BIA elements cont.. • Identify the impact to these activities if disrupted and how these would vary over time Audit aware Be able to discuss what the business considers to be the biggest impacts and why Be able to discuss what timeframes were selected and why. (eg. Peak work periods). What is the link back to business priorities?
  • 11. BIA elements cont.. • Establish the Maximum Tolerable Period of Disruption (MTPD) for each activity • Prioritise activities for recovery and identify the critical activities • Remember that activities not considered critical now may become so during a disruption
  • 12. BIA elements cont.. • Identify all dependencies on critical activities including suppliers and outsource partners • Determine BCM arrangements for the suppliers/outsourced partners on whom critical activities depend Audit Aware • This goes beyond asking if they have a BC Policy. Demonstrate a deeper understanding of their arrangements for the relevant products and services that they provide to you
  • 13. Important terminology • Maximum Tolerable Period of Disruption “Duration after which an organisation’s viability will be irrevocably threatened if product and service delivery cannot be resumed” BS 25999:1 • Recovery Time Objective “Target time set for resumption of product, service or activity delivery after an incident” BS 25999:1
  • 14. Maximum Tolerable Period of Disruption • Overall BCMS entity (based on chosen scope) Organisation • Corporate level definition or Product or Service • Deliverable outputs • Operational relationship with Product/Services or Activity • Support/Strategic relationship • Resources, suppliers, outsource partners etc Dependencies
  • 15. Recovery Time Objective • Use the same approach as for MTPD (4 levels) • Expand the application of RTO’s to beyond critical activities to include product/service and dependencies
  • 16. Clarification provided by BCM/1 • BCM/1 approved a clarification note in June 2009 to help BCM practitioners • Published on Continuity Central website http://www.continuitycentral.com/feature0677. html • Article on MTPD by Jacque Rupert http://www.continuitycentral.com/feature0675. html
  • 17. Do’s and don’ts for certification to BS 25999:2 (BIA only) • DO make sure that Top • DON’T adopt a Management are fully template mentality and aware of BIA findings copy someone else’s and are able to discuss BIA format for the sake them of it • DO be able to justify the • DON’T over complicate methodology & content the BIA so that it of your BIA becomes a monster • DO adhere to every clause requirement
  • 18. Lessons learnt from certified organisations • “Seek contributions from a wide range of staff” • “Take sufficient time to get it right. If you do your BIA properly, writing plans becomes very easy” • “Engage key customers and suppliers” • “Make sure you have evidence that you have covered every element of the standard.” • “the template in particular has evolved through multiple iterations based on user feedback.”
  • 19. Thanks for listening Hilary Estall Hilary.estall@pslinfo.co.uk www.pslinfo.co.uk