SlideShare uma empresa Scribd logo
1 de 22
Baixar para ler offline
Continuity and Resilience (CORE)
ISO 22301 BCM Consulting Firm
Presentations by speakers at the
8th ME Business & IT Resilience Summit
March 10, 2019 at The Address Hotel, Duabi Mall, Dubai, UAE
Our Contact Details:
UAE INDIA
Continuity and Resilience
Website: www.coreconsulting.ae
Tel: +971 2 6594006
PO Box: 25722, Abu Dhabi, United Arab Emirates
Email: info@continuityandresilience.com
Continuity and Resilience
Tel: +91 11 41055534 | Direct: +91 11 6467 9380
Email: info@continuityandresilience.com
Website: www.coreconsulting.ae
Level 15, Eros Corporate Towers, Nehru Place, New Delhi
– 110019, India
Business
Continuity and
Information
Security- An
Excellent Fit!
Ramesh Ramani
Agenda
• Introduction-BCMS and ISMS
• International Standards, UAE Regulations (NCEMA, ADSIC, NESA, ISR, GDPR). Dubai Data Law
• PDCA Cycle
• Common Factors-BCMS and ISMS
• Organisational Considerations
• Joint Project Management
• Where this will work?
• Where this will not work
• Q&A
Standards, Regulations
• ISO 27001:2013-Information Security
• ISO 22301:2012-Business Continuity
• UAE Regulations
✓ NCEMA 7001:2015 (National Emergency Crisis and Disasters Management Authority)
✓ ADSIC –(Abu Dhabi Systems and Information Centre)
✓ NESA Standards (National Electronic Security Authority)
✓ ISR (Information Security Regulation)
✓ Regulating Data Dissemination and Exchange (Dubai Data Law)
✓ ADSIC- (ABU DHABI GOVERNMENT DATA MANAGEMENT STANDARDS)
PDCA Cycle
Business Continuity
(ISO 22301)
Information Security
(ISO 27001)
Plan (Establish)
Gap Analysis, Information Risk
Assessment, BIA,Risk Mitigation
Plan
Gap Analysis, Information Risk
Assessment, Risk Mitigation Plan
Do (Implement)
Implementing BCM response,
Risk Mitigation
Risk Mitigation
Check (Monitor)
Internal Audit/Management
reviews
Internal Audit/Management
reviews
Act (Improve)
Exercising and maintaining BC
Arrangements and embedding
BC culture
Continual Improvement
Program Management Program Management Program Management
PDCA Cycle
Organisational Considerations
• Risk Management
• ISO 31000
• Risk management in your organization
• Cl 4 of 27001 and 22301
• ERM and Relation with Other Functions
• International best practices-Risk management
• RA Methodology-Specific to ADSIC/NESA
Start
With
Organisational Considerations
• Scope of ISMS/BCMS
• Scope Document (Common)
• Exclusions
• Scope Statement
• ISR/NESA-Scope Requirements
• Cl 4 of 27001/22301
Finish
With
Organisational Considerations
BCMS/ISMS-Objectives-Next Step
• Measurable-Measured
• Monitorable-Monitored
• Balance Score Card
• COBIT
BCMS Common Factors - Framework
Testing DRP/BCP
Establishment of DR site
Drawing of RFP for DR site
Disaster Recovery Strategy Plan
Drawing of IT Continuity Plan
Business Continuity Plan
RTO / RPO / Max Outage
Business Impact Analysis
Risk Assessment (Critical Assets) Vulnerability
Value
Threat
ISO 22301
ISO 27031
Existing setup /
Redundancy / New
Technologies
ISMS Common Factors - Framework
Plan Risk Assessment
Risk Mitigation Plan
Vulnerability
Threat
People
Processes.
Procedures
Technical
Asset Value
Do Risk Mitigation Products, Processes or People Controls
Audit Internal AuditCheck
Continual Improvement Closing of Audit Gaps/Raising the BarAct
Continue with PDCA Cycle-ISO 27001 Certification
Joint Project Management - Plan
Lloyd's Register 11
PLAN
PLAN
BC & IS
Joint Project Management - Plan
Lloyd's Register 12
PLAN
PLAN
BC & IS
Joint Project Management - Do
Lloyd's Register 13
DO
DO
BC & IS
Joint Project Management - Check
Lloyd's Register 14
BC & IS
Check
Check
BC (Availability) IS (CIA) Activity
Internal Audit, Management Review, BC
Tests/DR Tests
Internal Audit, Management Review,
BC
Internal Audit, Management Review,
BC Tests/DR Tests (Common)
Joint Project Management - Act
Lloyd's Register 15
ACT
ACT
BC & IS
Lloyd's Register 16
Aim-Provide initial
planning and
preparation for the
assignment.
1.Scope and
Service
Acceptance
Document C
2.ISMS/BCMS
Scope definition
3.BC/IS Policy
Statement C
4.BCM/Information
Security Steering
Committee Charter
C
Aim to collect all
relevant data
pertaining to the
scope
- develop BIA/Risk
Assessment
methodology
- perform asset
enumeration/valuat
ion
1.BIA/Risk
Assessment
Methodology
2.Information Asset
Valuation/Critical
Asset Valuation-
C,I,A-C
3.Critical/
information assets
register-C
Aim-Perform BIA/
Risk Assessment
on the identified
critical/Informatio
n assets and
develop BCP/Risk
Treatment Plan.
Develop
mandatory
policies and
controls
1.Vulnerability
Assessment-C
2.Threat
Assessment-C
3.Risk
Assessment
Report (IS)
4.BIA (RTO/RPO)
5.BCP/DRP
6.Risk Mitigation &
Treatment Plan C
7.Statement of
Applicability (ISO
27001)
8.BCP/DR Policies
and Procedures C
Aim-Implement
BCP/Risk
Mitigation
Controls based
on the
BCP/control
implementation
road map
1.Implement
controls
identified
2.People
(Training/Duties)
C
3.Implementing
products C?
4.Implementing
Processes
Aim
- To Test the
BCP/DRP
-To audit the ISMS
Prepare for ISO
27001/22301
Certification
1.BC/DR Test
Results
2.ISO 27001 Audit
Reports
Aim-Continual
Improvement of
BCMS/ISMS
Certification
against ISO
22301/ISO 27001
Initial Plan
Acquire/
Analyze Data
Develop
BCMS/ISMS
Implement
BCMS/ISMS
Test
BCM/S/ISMS
Continual
Improvement
Where this WILL work?
Software
Industry
BPO / ITESGovernment Organizations
Banking and
Financial Services
Oil Industry
What Do Auditors Look for?
✓ Scope of Certification/BCMS
✓ BCMS Objectives
✓ RA and BIA
✓ BCP Strategy/BCP
✓ DR ( IT) and BCP Coordination
✓ PDCA Cycle
✓ Documentation Requirements
✓ BC Testing Evidences
✓ Senior Management Commitments-Evidences
Our Information Security & Business Continuity Assessment and Training Services
Lloyd's Register 19
Our range of online and face-to-face assessment services is suitable for organisations of all sizes and locations, and can help you
make the most of the standards.
TrainingCertifications
Integrated
management
system
assessment
Gap Analysis
Surveillance
Certification journey
Lloyd's Register 20
Stage 1 Stage 2 Themed
surveillance
Focused
visits
Renewal
Risk-based
methodology
Our experts tailor the assessment
according to the maturity of your
systems to ensure they are
appropriate to the real risks you
face.
Reporting
Our aim is to leave a report with
you at the end of your visit, or as
soon as possible afterwards. Rapid
feedback is important, because
once a risk has been identified, it
needs to be addressed promptly
Non-conformity
Taking notice of the non-
conformities can help prevent
costly mistakes and even legal
action by the regulators.
Improvement log
Details your progress and the
effective implementation of the
improvements. A mechanism for
tracking the progress of strategic
improvements around the key
issues.
SurveillanceInitial assessment Certificate
Thank You
W: LRQAMEA.COM
T: +971 (4) 701 4150
E: LRQA-MEA@LR.org
Lloyd's Register 21
Lloyd's Register 22
Continuity and Resilience (CORE)
ISO 22301 BCM Consulting Firm
Presentations by speakers at the
8th ME Business & IT Resilience Summit
March 10, 2019 at The Address Hotel, Duabi Mall, Dubai, UAE
Our Contact Details:
UAE INDIA
Continuity and Resilience
Website: www.coreconsulting.ae
Tel: +971 2 6594006
PO Box: 25722, Abu Dhabi, United Arab Emirates
Email: info@continuityandresilience.com
Continuity and Resilience
Tel: +91 11 41055534 | Direct: +91 11 6467 9380
Email: info@continuityandresilience.com
Website: www.coreconsulting.ae
Level 15, Eros Corporate Towers, Nehru Place, New Delhi
– 110019, India

Mais conteúdo relacionado

Mais procurados

Cobit 5 for Information Security
Cobit 5 for Information SecurityCobit 5 for Information Security
Cobit 5 for Information SecuritySeto Joseles
 
Yhcg - IT security and risk management
Yhcg  - IT security and risk managementYhcg  - IT security and risk management
Yhcg - IT security and risk managementWilfred Barretto
 
Cobit 5 for information security
Cobit 5 for information securityCobit 5 for information security
Cobit 5 for information securityElkanouni Mohamed
 
Using COBIT PO9 to perform Project Risk Analysis
Using COBIT PO9 to perform Project Risk AnalysisUsing COBIT PO9 to perform Project Risk Analysis
Using COBIT PO9 to perform Project Risk Analysiswebmentorman
 
Rapid Risk Assessment: A New Approach to Risk Management
Rapid Risk Assessment: A New Approach to Risk ManagementRapid Risk Assessment: A New Approach to Risk Management
Rapid Risk Assessment: A New Approach to Risk ManagementEnergySec
 
Creating an effective cyber security awareness programme
Creating an effective cyber security awareness programmeCreating an effective cyber security awareness programme
Creating an effective cyber security awareness programmeIT Governance Ltd
 
BCM Institute MTE Richard Stuart - IPS Securex: Journey to be Resilient
BCM Institute MTE Richard Stuart - IPS Securex: Journey to be ResilientBCM Institute MTE Richard Stuart - IPS Securex: Journey to be Resilient
BCM Institute MTE Richard Stuart - IPS Securex: Journey to be ResilientBCM Institute
 
IT Risk Management & Compliance
IT Risk Management & ComplianceIT Risk Management & Compliance
IT Risk Management & Compliancerhanna11
 
NESCO Town Hall Workforce Development Presentation
NESCO Town Hall Workforce Development PresentationNESCO Town Hall Workforce Development Presentation
NESCO Town Hall Workforce Development PresentationEnergySec
 
Energy Industry Organizational Strategies to Increase Cyber Resiliency
Energy Industry Organizational Strategies to Increase Cyber ResiliencyEnergy Industry Organizational Strategies to Increase Cyber Resiliency
Energy Industry Organizational Strategies to Increase Cyber ResiliencyEnergySec
 
Eyad Sallam International IFSEC and OSH Arabia conference presentation
Eyad Sallam International IFSEC and OSH Arabia conference presentationEyad Sallam International IFSEC and OSH Arabia conference presentation
Eyad Sallam International IFSEC and OSH Arabia conference presentationEyad Sallam
 
BPMN -The Very First Step in Business Continuity
BPMN -The Very First Step in Business ContinuityBPMN -The Very First Step in Business Continuity
BPMN -The Very First Step in Business ContinuityPECB
 
IT frameworks
IT frameworksIT frameworks
IT frameworkscyouss
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...PECB
 
Introduction to COBIT 5 and IT management
Introduction to COBIT 5 and IT managementIntroduction to COBIT 5 and IT management
Introduction to COBIT 5 and IT managementChristian F. Nissen
 
Cv bevan lane january 2014 oil and gas
Cv bevan lane january 2014 oil and gasCv bevan lane january 2014 oil and gas
Cv bevan lane january 2014 oil and gasBevan Lane
 
Dynamic Cyber Defense
Dynamic Cyber DefenseDynamic Cyber Defense
Dynamic Cyber DefenseEnergySec
 

Mais procurados (20)

Cobit 5 for Information Security
Cobit 5 for Information SecurityCobit 5 for Information Security
Cobit 5 for Information Security
 
Yhcg - IT security and risk management
Yhcg  - IT security and risk managementYhcg  - IT security and risk management
Yhcg - IT security and risk management
 
Cobit 5 for information security
Cobit 5 for information securityCobit 5 for information security
Cobit 5 for information security
 
CobiT Foundation Free Training
CobiT Foundation Free TrainingCobiT Foundation Free Training
CobiT Foundation Free Training
 
Using COBIT PO9 to perform Project Risk Analysis
Using COBIT PO9 to perform Project Risk AnalysisUsing COBIT PO9 to perform Project Risk Analysis
Using COBIT PO9 to perform Project Risk Analysis
 
Rapid Risk Assessment: A New Approach to Risk Management
Rapid Risk Assessment: A New Approach to Risk ManagementRapid Risk Assessment: A New Approach to Risk Management
Rapid Risk Assessment: A New Approach to Risk Management
 
Creating an effective cyber security awareness programme
Creating an effective cyber security awareness programmeCreating an effective cyber security awareness programme
Creating an effective cyber security awareness programme
 
BCM Institute MTE Richard Stuart - IPS Securex: Journey to be Resilient
BCM Institute MTE Richard Stuart - IPS Securex: Journey to be ResilientBCM Institute MTE Richard Stuart - IPS Securex: Journey to be Resilient
BCM Institute MTE Richard Stuart - IPS Securex: Journey to be Resilient
 
IT Risk Management & Compliance
IT Risk Management & ComplianceIT Risk Management & Compliance
IT Risk Management & Compliance
 
NESCO Town Hall Workforce Development Presentation
NESCO Town Hall Workforce Development PresentationNESCO Town Hall Workforce Development Presentation
NESCO Town Hall Workforce Development Presentation
 
Energy Industry Organizational Strategies to Increase Cyber Resiliency
Energy Industry Organizational Strategies to Increase Cyber ResiliencyEnergy Industry Organizational Strategies to Increase Cyber Resiliency
Energy Industry Organizational Strategies to Increase Cyber Resiliency
 
Confidis-Briefing-Web
Confidis-Briefing-WebConfidis-Briefing-Web
Confidis-Briefing-Web
 
Eyad Sallam International IFSEC and OSH Arabia conference presentation
Eyad Sallam International IFSEC and OSH Arabia conference presentationEyad Sallam International IFSEC and OSH Arabia conference presentation
Eyad Sallam International IFSEC and OSH Arabia conference presentation
 
BPMN -The Very First Step in Business Continuity
BPMN -The Very First Step in Business ContinuityBPMN -The Very First Step in Business Continuity
BPMN -The Very First Step in Business Continuity
 
IT frameworks
IT frameworksIT frameworks
IT frameworks
 
Cobit 5 Business Framework -Governance and Management of Enterprise IT
Cobit 5  Business Framework -Governance and Management of Enterprise ITCobit 5  Business Framework -Governance and Management of Enterprise IT
Cobit 5 Business Framework -Governance and Management of Enterprise IT
 
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...Assessing the Impact of a Disruption: Building an Effective Business Impact A...
Assessing the Impact of a Disruption: Building an Effective Business Impact A...
 
Introduction to COBIT 5 and IT management
Introduction to COBIT 5 and IT managementIntroduction to COBIT 5 and IT management
Introduction to COBIT 5 and IT management
 
Cv bevan lane january 2014 oil and gas
Cv bevan lane january 2014 oil and gasCv bevan lane january 2014 oil and gas
Cv bevan lane january 2014 oil and gas
 
Dynamic Cyber Defense
Dynamic Cyber DefenseDynamic Cyber Defense
Dynamic Cyber Defense
 

Semelhante a Business Continuity and Information Security- An Excellent Fit!

ISO 27001 In The Age Of Privacy
ISO 27001 In The Age Of PrivacyISO 27001 In The Age Of Privacy
ISO 27001 In The Age Of PrivacyControlCase
 
How to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectHow to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectCORE Consulting
 
J. LaCagnina CV 5-2016
J. LaCagnina CV 5-2016J. LaCagnina CV 5-2016
J. LaCagnina CV 5-2016John LaCagnina
 
Abidance Cip Presentation
Abidance Cip PresentationAbidance Cip Presentation
Abidance Cip Presentationjamesholler
 
How to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectHow to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectContinuity and Resilience
 
Pmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment OverviewPmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment OverviewAlan McSweeney
 
Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsOracle
 
Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Oracle
 
Whos role is it anyway
Whos role is it anywayWhos role is it anyway
Whos role is it anywayIRIS
 
OneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to ManyOneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to ManyControlCase
 
Business continuity planning guide
Business continuity planning guideBusiness continuity planning guide
Business continuity planning guideAstalapulosListestos
 
Business continuity planning guide
Business continuity planning guideBusiness continuity planning guide
Business continuity planning guideCenapSerdarolu
 
20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution
20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution
20200429 PMI NYC Meetup Agile Governance Ariel Partners for DistributionCraeg Strong
 
AdvisorAssist Presentation: Cloud Computing and Compliance For RIAs
AdvisorAssist Presentation:  Cloud Computing and Compliance For RIAsAdvisorAssist Presentation:  Cloud Computing and Compliance For RIAs
AdvisorAssist Presentation: Cloud Computing and Compliance For RIAsAdvisorAssist, LLC
 
Resume-Ishita_Kundu_2015
Resume-Ishita_Kundu_2015Resume-Ishita_Kundu_2015
Resume-Ishita_Kundu_2015Ishita Kundu
 

Semelhante a Business Continuity and Information Security- An Excellent Fit! (20)

Testing BC Plans
Testing BC PlansTesting BC Plans
Testing BC Plans
 
ISO 27001 In The Age Of Privacy
ISO 27001 In The Age Of PrivacyISO 27001 In The Age Of Privacy
ISO 27001 In The Age Of Privacy
 
How to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR projectHow to plan and manage a BCM and IT DR project
How to plan and manage a BCM and IT DR project
 
J. LaCagnina CV 5-2016
J. LaCagnina CV 5-2016J. LaCagnina CV 5-2016
J. LaCagnina CV 5-2016
 
Abidance Cip Presentation
Abidance Cip PresentationAbidance Cip Presentation
Abidance Cip Presentation
 
How to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR ProjectHow to Plan and Manage a BCM and IT DR Project
How to Plan and Manage a BCM and IT DR Project
 
Pmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment OverviewPmi, Opm3 And Cmmi Assessment Overview
Pmi, Opm3 And Cmmi Assessment Overview
 
CORE MANAGEMENT CONSULTING
CORE MANAGEMENT CONSULTINGCORE MANAGEMENT CONSULTING
CORE MANAGEMENT CONSULTING
 
Con8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controlsCon8154 controlling for multiple erp systems with oracle advanced controls
Con8154 controlling for multiple erp systems with oracle advanced controls
 
Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...Customers talk about controlling access for multiple erp systems with oracle ...
Customers talk about controlling access for multiple erp systems with oracle ...
 
Whos role is it anyway
Whos role is it anywayWhos role is it anyway
Whos role is it anyway
 
OneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to ManyOneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to Many
 
Business continuity planning guide
Business continuity planning guideBusiness continuity planning guide
Business continuity planning guide
 
Business continuity planning guide
Business continuity planning guideBusiness continuity planning guide
Business continuity planning guide
 
CV jagroop jagpal
CV jagroop jagpalCV jagroop jagpal
CV jagroop jagpal
 
20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution
20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution
20200429 PMI NYC Meetup Agile Governance Ariel Partners for Distribution
 
AdvisorAssist Presentation: Cloud Computing and Compliance For RIAs
AdvisorAssist Presentation:  Cloud Computing and Compliance For RIAsAdvisorAssist Presentation:  Cloud Computing and Compliance For RIAs
AdvisorAssist Presentation: Cloud Computing and Compliance For RIAs
 
Government and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP SystemsGovernment and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP Systems
 
COBIT®5 - Foundation
COBIT®5 - FoundationCOBIT®5 - Foundation
COBIT®5 - Foundation
 
Resume-Ishita_Kundu_2015
Resume-Ishita_Kundu_2015Resume-Ishita_Kundu_2015
Resume-Ishita_Kundu_2015
 

Mais de Continuity and Resilience

The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq BajwaThe Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq BajwaContinuity and Resilience
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha EltinayThe Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha EltinayContinuity and Resilience
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Paul Gant
The Business Continuity Conference, 25th October 2023 in Riyadh -  Paul GantThe Business Continuity Conference, 25th October 2023 in Riyadh -  Paul Gant
The Business Continuity Conference, 25th October 2023 in Riyadh - Paul GantContinuity and Resilience
 
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...Continuity and Resilience
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...Continuity and Resilience
 
Advancing the Enterprise Towards Enterprise Resilience
Advancing the Enterprise Towards Enterprise ResilienceAdvancing the Enterprise Towards Enterprise Resilience
Advancing the Enterprise Towards Enterprise ResilienceContinuity and Resilience
 
Social Media Influence in the field of Crisis Management– Case Studies
Social Media Influence in the field of Crisis Management– Case StudiesSocial Media Influence in the field of Crisis Management– Case Studies
Social Media Influence in the field of Crisis Management– Case StudiesContinuity and Resilience
 
Crisis Communication & BCM in Aviation Sector
Crisis Communication & BCM in Aviation SectorCrisis Communication & BCM in Aviation Sector
Crisis Communication & BCM in Aviation SectorContinuity and Resilience
 
Effectiveness of Disaster Management Ground Reality and Potential.
Effectiveness of Disaster Management Ground Reality and Potential.Effectiveness of Disaster Management Ground Reality and Potential.
Effectiveness of Disaster Management Ground Reality and Potential.Continuity and Resilience
 
Kerala floods case study automated two-way crisis communication
Kerala floods case study   automated two-way crisis communicationKerala floods case study   automated two-way crisis communication
Kerala floods case study automated two-way crisis communicationContinuity and Resilience
 
Renewed focus of Business and Practitioners on BCM (in Asia)
Renewed focus of Business and Practitioners on BCM (in Asia)Renewed focus of Business and Practitioners on BCM (in Asia)
Renewed focus of Business and Practitioners on BCM (in Asia)Continuity and Resilience
 
Cyber Security Developments for BCM Practitioners
Cyber Security Developments for BCM PractitionersCyber Security Developments for BCM Practitioners
Cyber Security Developments for BCM PractitionersContinuity and Resilience
 

Mais de Continuity and Resilience (20)

The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq BajwaThe Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
The Business Continuity Conference, 25th October 2023 in Riyadh - Mr. Atiq Bajwa
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha EltinayThe Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
The Business Continuity Conference, 25th October 2023 in Riyadh - Nuha Eltinay
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Paul Gant
The Business Continuity Conference, 25th October 2023 in Riyadh -  Paul GantThe Business Continuity Conference, 25th October 2023 in Riyadh -  Paul Gant
The Business Continuity Conference, 25th October 2023 in Riyadh - Paul Gant
 
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
The Business Continuity Conference, 25th October 2023 in Riyadh - David Boll...
 
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
The Business Continuity Conference, 25th October 2023 in Riyadh - Abdulrahma...
 
DEFLUFFING RESILIENCE
DEFLUFFING RESILIENCEDEFLUFFING RESILIENCE
DEFLUFFING RESILIENCE
 
CREATING AND MAINTAINING A BCM PROGRAM
CREATING AND MAINTAINING A BCM PROGRAMCREATING AND MAINTAINING A BCM PROGRAM
CREATING AND MAINTAINING A BCM PROGRAM
 
BCM Challenges and Compliance
BCM Challenges and Compliance BCM Challenges and Compliance
BCM Challenges and Compliance
 
Thriving in the Crisis Situation
Thriving in the Crisis SituationThriving in the Crisis Situation
Thriving in the Crisis Situation
 
Cyber Security & IT Resilience
Cyber Security & IT Resilience Cyber Security & IT Resilience
Cyber Security & IT Resilience
 
Enterprise Resilience
Enterprise ResilienceEnterprise Resilience
Enterprise Resilience
 
Advancing the Enterprise Towards Enterprise Resilience
Advancing the Enterprise Towards Enterprise ResilienceAdvancing the Enterprise Towards Enterprise Resilience
Advancing the Enterprise Towards Enterprise Resilience
 
Bcm is all about people!
Bcm   is all about people!Bcm   is all about people!
Bcm is all about people!
 
Social Media Influence in the field of Crisis Management– Case Studies
Social Media Influence in the field of Crisis Management– Case StudiesSocial Media Influence in the field of Crisis Management– Case Studies
Social Media Influence in the field of Crisis Management– Case Studies
 
Crisis Communication & BCM in Aviation Sector
Crisis Communication & BCM in Aviation SectorCrisis Communication & BCM in Aviation Sector
Crisis Communication & BCM in Aviation Sector
 
Effectiveness of Disaster Management Ground Reality and Potential.
Effectiveness of Disaster Management Ground Reality and Potential.Effectiveness of Disaster Management Ground Reality and Potential.
Effectiveness of Disaster Management Ground Reality and Potential.
 
Kerala floods case study automated two-way crisis communication
Kerala floods case study   automated two-way crisis communicationKerala floods case study   automated two-way crisis communication
Kerala floods case study automated two-way crisis communication
 
Social media influence in the field of bcm
Social media influence in the field of bcmSocial media influence in the field of bcm
Social media influence in the field of bcm
 
Renewed focus of Business and Practitioners on BCM (in Asia)
Renewed focus of Business and Practitioners on BCM (in Asia)Renewed focus of Business and Practitioners on BCM (in Asia)
Renewed focus of Business and Practitioners on BCM (in Asia)
 
Cyber Security Developments for BCM Practitioners
Cyber Security Developments for BCM PractitionersCyber Security Developments for BCM Practitioners
Cyber Security Developments for BCM Practitioners
 

Último

SURAT CALL GIRL 92628/71154 SURAT CALL G
SURAT CALL GIRL 92628/71154 SURAT CALL GSURAT CALL GIRL 92628/71154 SURAT CALL G
SURAT CALL GIRL 92628/71154 SURAT CALL GNiteshKumar82226
 
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls AgencyHire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls AgencyJia Oberoi
 
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7Sana Rajpoot
 
Kolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book now
Kolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book nowKolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book now
Kolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book nowapshanarani255
 
Udupi Call girl service 6289102337 Udupi escort service
Udupi Call girl service 6289102337 Udupi escort serviceUdupi Call girl service 6289102337 Udupi escort service
Udupi Call girl service 6289102337 Udupi escort servicemaheshsingh64440
 
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579Best VIP Call Girl Noida Sector 48 Call Me: 8700611579
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579diyaspanoida
 
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7soniya singh
 
Girls For Night in Islamabad | 03274100048 🔞
Girls For Night in Islamabad | 03274100048 🔞Girls For Night in Islamabad | 03274100048 🔞
Girls For Night in Islamabad | 03274100048 🔞Ifra Zohaib
 
Indore ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book now
Indore  ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book nowIndore  ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book now
Indore ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book nowapshanarani255
 
+91-9899900591 Russian Call Girls In New Delhi Independent Russian Call Girls...
+91-9899900591 Russian Call Girls In New Delhi Independent Russian Call Girls...+91-9899900591 Russian Call Girls In New Delhi Independent Russian Call Girls...
+91-9899900591 Russian Call Girls In New Delhi Independent Russian Call Girls...kauryashika82
 
Call Girls In {{Laxmi Nagar Delhi}} 9667938988 Indian Russian High Profile Es...
Call Girls In {{Laxmi Nagar Delhi}} 9667938988 Indian Russian High Profile Es...Call Girls In {{Laxmi Nagar Delhi}} 9667938988 Indian Russian High Profile Es...
Call Girls In {{Laxmi Nagar Delhi}} 9667938988 Indian Russian High Profile Es...aakahthapa70
 
Bhopal Call girl service 6289102337 bhopal escort service
Bhopal Call girl service 6289102337 bhopal escort serviceBhopal Call girl service 6289102337 bhopal escort service
Bhopal Call girl service 6289102337 bhopal escort servicemaheshsingh64440
 
VAPI CALL GIRL 92628/71154 VAPI CALL GIR
VAPI CALL GIRL 92628/71154 VAPI CALL GIRVAPI CALL GIRL 92628/71154 VAPI CALL GIR
VAPI CALL GIRL 92628/71154 VAPI CALL GIRNiteshKumar82226
 
CALL GIRLS 9999288940 women seeking men Locanto No Advance North Goa
CALL GIRLS 9999288940 women seeking men Locanto No Advance North GoaCALL GIRLS 9999288940 women seeking men Locanto No Advance North Goa
CALL GIRLS 9999288940 women seeking men Locanto No Advance North Goadelhincr993
 
Call Girls In {{Connaught Place Delhi}}96679@38988 Indian Russian High Profil...
Call Girls In {{Connaught Place Delhi}}96679@38988 Indian Russian High Profil...Call Girls In {{Connaught Place Delhi}}96679@38988 Indian Russian High Profil...
Call Girls In {{Connaught Place Delhi}}96679@38988 Indian Russian High Profil...aakahthapa70
 
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGARJAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGARNiteshKumar82226
 
Call Girls | 😏💦 03274100048 | Call Girls Near Me
Call Girls | 😏💦 03274100048 | Call Girls Near MeCall Girls | 😏💦 03274100048 | Call Girls Near Me
Call Girls | 😏💦 03274100048 | Call Girls Near MeIfra Zohaib
 
Lucknow ❣️ Call Girl 97487*63073 Call Girls in Lucknow Escort service book now
Lucknow ❣️  Call Girl 97487*63073 Call Girls in Lucknow Escort service book nowLucknow ❣️  Call Girl 97487*63073 Call Girls in Lucknow Escort service book now
Lucknow ❣️ Call Girl 97487*63073 Call Girls in Lucknow Escort service book nowapshanarani255
 
Call Now ☎9870417354|| Call Girls in Gurgaon Sector 13 Escort Service Gurgaon...
Call Now ☎9870417354|| Call Girls in Gurgaon Sector 13 Escort Service Gurgaon...Call Now ☎9870417354|| Call Girls in Gurgaon Sector 13 Escort Service Gurgaon...
Call Now ☎9870417354|| Call Girls in Gurgaon Sector 13 Escort Service Gurgaon...riyadelhic riyadelhic
 

Último (20)

SURAT CALL GIRL 92628/71154 SURAT CALL G
SURAT CALL GIRL 92628/71154 SURAT CALL GSURAT CALL GIRL 92628/71154 SURAT CALL G
SURAT CALL GIRL 92628/71154 SURAT CALL G
 
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls AgencyHire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
Hire 💕 8617370543 Uttara Kannada Call Girls Service Call Girls Agency
 
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7
Call Girls in Karachi || 03274100048 || 50+ Hot Sexy Girls Available 24/7
 
Kolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book now
Kolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book nowKolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book now
Kolkata 💋 Call Girl 9748763073 Call Girls in Kolkata Escort service book now
 
Udupi Call girl service 6289102337 Udupi escort service
Udupi Call girl service 6289102337 Udupi escort serviceUdupi Call girl service 6289102337 Udupi escort service
Udupi Call girl service 6289102337 Udupi escort service
 
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579Best VIP Call Girl Noida Sector 48 Call Me: 8700611579
Best VIP Call Girl Noida Sector 48 Call Me: 8700611579
 
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7
Call Girls in Saket (delhi) call me [8264348440 ] escort service 24X7
 
9953056974 Call Girls In Ashok Nagar, Escorts (Delhi) NCR.
9953056974 Call Girls In Ashok Nagar, Escorts (Delhi) NCR.9953056974 Call Girls In Ashok Nagar, Escorts (Delhi) NCR.
9953056974 Call Girls In Ashok Nagar, Escorts (Delhi) NCR.
 
Girls For Night in Islamabad | 03274100048 🔞
Girls For Night in Islamabad | 03274100048 🔞Girls For Night in Islamabad | 03274100048 🔞
Girls For Night in Islamabad | 03274100048 🔞
 
Indore ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book now
Indore  ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book nowIndore  ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book now
Indore ❣️Call Girl 97487*63073 Call Girls in Indore Escort service book now
 
+91-9899900591 Russian Call Girls In New Delhi Independent Russian Call Girls...
+91-9899900591 Russian Call Girls In New Delhi Independent Russian Call Girls...+91-9899900591 Russian Call Girls In New Delhi Independent Russian Call Girls...
+91-9899900591 Russian Call Girls In New Delhi Independent Russian Call Girls...
 
Call Girls In {{Laxmi Nagar Delhi}} 9667938988 Indian Russian High Profile Es...
Call Girls In {{Laxmi Nagar Delhi}} 9667938988 Indian Russian High Profile Es...Call Girls In {{Laxmi Nagar Delhi}} 9667938988 Indian Russian High Profile Es...
Call Girls In {{Laxmi Nagar Delhi}} 9667938988 Indian Russian High Profile Es...
 
Bhopal Call girl service 6289102337 bhopal escort service
Bhopal Call girl service 6289102337 bhopal escort serviceBhopal Call girl service 6289102337 bhopal escort service
Bhopal Call girl service 6289102337 bhopal escort service
 
VAPI CALL GIRL 92628/71154 VAPI CALL GIR
VAPI CALL GIRL 92628/71154 VAPI CALL GIRVAPI CALL GIRL 92628/71154 VAPI CALL GIR
VAPI CALL GIRL 92628/71154 VAPI CALL GIR
 
CALL GIRLS 9999288940 women seeking men Locanto No Advance North Goa
CALL GIRLS 9999288940 women seeking men Locanto No Advance North GoaCALL GIRLS 9999288940 women seeking men Locanto No Advance North Goa
CALL GIRLS 9999288940 women seeking men Locanto No Advance North Goa
 
Call Girls In {{Connaught Place Delhi}}96679@38988 Indian Russian High Profil...
Call Girls In {{Connaught Place Delhi}}96679@38988 Indian Russian High Profil...Call Girls In {{Connaught Place Delhi}}96679@38988 Indian Russian High Profil...
Call Girls In {{Connaught Place Delhi}}96679@38988 Indian Russian High Profil...
 
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGARJAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
JAMNAGAR CALL GIRLS 92628/71154 JAMNAGAR
 
Call Girls | 😏💦 03274100048 | Call Girls Near Me
Call Girls | 😏💦 03274100048 | Call Girls Near MeCall Girls | 😏💦 03274100048 | Call Girls Near Me
Call Girls | 😏💦 03274100048 | Call Girls Near Me
 
Lucknow ❣️ Call Girl 97487*63073 Call Girls in Lucknow Escort service book now
Lucknow ❣️  Call Girl 97487*63073 Call Girls in Lucknow Escort service book nowLucknow ❣️  Call Girl 97487*63073 Call Girls in Lucknow Escort service book now
Lucknow ❣️ Call Girl 97487*63073 Call Girls in Lucknow Escort service book now
 
Call Now ☎9870417354|| Call Girls in Gurgaon Sector 13 Escort Service Gurgaon...
Call Now ☎9870417354|| Call Girls in Gurgaon Sector 13 Escort Service Gurgaon...Call Now ☎9870417354|| Call Girls in Gurgaon Sector 13 Escort Service Gurgaon...
Call Now ☎9870417354|| Call Girls in Gurgaon Sector 13 Escort Service Gurgaon...
 

Business Continuity and Information Security- An Excellent Fit!

  • 1. Continuity and Resilience (CORE) ISO 22301 BCM Consulting Firm Presentations by speakers at the 8th ME Business & IT Resilience Summit March 10, 2019 at The Address Hotel, Duabi Mall, Dubai, UAE Our Contact Details: UAE INDIA Continuity and Resilience Website: www.coreconsulting.ae Tel: +971 2 6594006 PO Box: 25722, Abu Dhabi, United Arab Emirates Email: info@continuityandresilience.com Continuity and Resilience Tel: +91 11 41055534 | Direct: +91 11 6467 9380 Email: info@continuityandresilience.com Website: www.coreconsulting.ae Level 15, Eros Corporate Towers, Nehru Place, New Delhi – 110019, India
  • 3. Agenda • Introduction-BCMS and ISMS • International Standards, UAE Regulations (NCEMA, ADSIC, NESA, ISR, GDPR). Dubai Data Law • PDCA Cycle • Common Factors-BCMS and ISMS • Organisational Considerations • Joint Project Management • Where this will work? • Where this will not work • Q&A
  • 4. Standards, Regulations • ISO 27001:2013-Information Security • ISO 22301:2012-Business Continuity • UAE Regulations ✓ NCEMA 7001:2015 (National Emergency Crisis and Disasters Management Authority) ✓ ADSIC –(Abu Dhabi Systems and Information Centre) ✓ NESA Standards (National Electronic Security Authority) ✓ ISR (Information Security Regulation) ✓ Regulating Data Dissemination and Exchange (Dubai Data Law) ✓ ADSIC- (ABU DHABI GOVERNMENT DATA MANAGEMENT STANDARDS)
  • 5. PDCA Cycle Business Continuity (ISO 22301) Information Security (ISO 27001) Plan (Establish) Gap Analysis, Information Risk Assessment, BIA,Risk Mitigation Plan Gap Analysis, Information Risk Assessment, Risk Mitigation Plan Do (Implement) Implementing BCM response, Risk Mitigation Risk Mitigation Check (Monitor) Internal Audit/Management reviews Internal Audit/Management reviews Act (Improve) Exercising and maintaining BC Arrangements and embedding BC culture Continual Improvement Program Management Program Management Program Management PDCA Cycle
  • 6. Organisational Considerations • Risk Management • ISO 31000 • Risk management in your organization • Cl 4 of 27001 and 22301 • ERM and Relation with Other Functions • International best practices-Risk management • RA Methodology-Specific to ADSIC/NESA Start With
  • 7. Organisational Considerations • Scope of ISMS/BCMS • Scope Document (Common) • Exclusions • Scope Statement • ISR/NESA-Scope Requirements • Cl 4 of 27001/22301 Finish With
  • 8. Organisational Considerations BCMS/ISMS-Objectives-Next Step • Measurable-Measured • Monitorable-Monitored • Balance Score Card • COBIT
  • 9. BCMS Common Factors - Framework Testing DRP/BCP Establishment of DR site Drawing of RFP for DR site Disaster Recovery Strategy Plan Drawing of IT Continuity Plan Business Continuity Plan RTO / RPO / Max Outage Business Impact Analysis Risk Assessment (Critical Assets) Vulnerability Value Threat ISO 22301 ISO 27031 Existing setup / Redundancy / New Technologies
  • 10. ISMS Common Factors - Framework Plan Risk Assessment Risk Mitigation Plan Vulnerability Threat People Processes. Procedures Technical Asset Value Do Risk Mitigation Products, Processes or People Controls Audit Internal AuditCheck Continual Improvement Closing of Audit Gaps/Raising the BarAct Continue with PDCA Cycle-ISO 27001 Certification
  • 11. Joint Project Management - Plan Lloyd's Register 11 PLAN PLAN BC & IS
  • 12. Joint Project Management - Plan Lloyd's Register 12 PLAN PLAN BC & IS
  • 13. Joint Project Management - Do Lloyd's Register 13 DO DO BC & IS
  • 14. Joint Project Management - Check Lloyd's Register 14 BC & IS Check Check BC (Availability) IS (CIA) Activity Internal Audit, Management Review, BC Tests/DR Tests Internal Audit, Management Review, BC Internal Audit, Management Review, BC Tests/DR Tests (Common)
  • 15. Joint Project Management - Act Lloyd's Register 15 ACT ACT BC & IS
  • 16. Lloyd's Register 16 Aim-Provide initial planning and preparation for the assignment. 1.Scope and Service Acceptance Document C 2.ISMS/BCMS Scope definition 3.BC/IS Policy Statement C 4.BCM/Information Security Steering Committee Charter C Aim to collect all relevant data pertaining to the scope - develop BIA/Risk Assessment methodology - perform asset enumeration/valuat ion 1.BIA/Risk Assessment Methodology 2.Information Asset Valuation/Critical Asset Valuation- C,I,A-C 3.Critical/ information assets register-C Aim-Perform BIA/ Risk Assessment on the identified critical/Informatio n assets and develop BCP/Risk Treatment Plan. Develop mandatory policies and controls 1.Vulnerability Assessment-C 2.Threat Assessment-C 3.Risk Assessment Report (IS) 4.BIA (RTO/RPO) 5.BCP/DRP 6.Risk Mitigation & Treatment Plan C 7.Statement of Applicability (ISO 27001) 8.BCP/DR Policies and Procedures C Aim-Implement BCP/Risk Mitigation Controls based on the BCP/control implementation road map 1.Implement controls identified 2.People (Training/Duties) C 3.Implementing products C? 4.Implementing Processes Aim - To Test the BCP/DRP -To audit the ISMS Prepare for ISO 27001/22301 Certification 1.BC/DR Test Results 2.ISO 27001 Audit Reports Aim-Continual Improvement of BCMS/ISMS Certification against ISO 22301/ISO 27001 Initial Plan Acquire/ Analyze Data Develop BCMS/ISMS Implement BCMS/ISMS Test BCM/S/ISMS Continual Improvement
  • 17. Where this WILL work? Software Industry BPO / ITESGovernment Organizations Banking and Financial Services Oil Industry
  • 18. What Do Auditors Look for? ✓ Scope of Certification/BCMS ✓ BCMS Objectives ✓ RA and BIA ✓ BCP Strategy/BCP ✓ DR ( IT) and BCP Coordination ✓ PDCA Cycle ✓ Documentation Requirements ✓ BC Testing Evidences ✓ Senior Management Commitments-Evidences
  • 19. Our Information Security & Business Continuity Assessment and Training Services Lloyd's Register 19 Our range of online and face-to-face assessment services is suitable for organisations of all sizes and locations, and can help you make the most of the standards. TrainingCertifications Integrated management system assessment Gap Analysis Surveillance
  • 20. Certification journey Lloyd's Register 20 Stage 1 Stage 2 Themed surveillance Focused visits Renewal Risk-based methodology Our experts tailor the assessment according to the maturity of your systems to ensure they are appropriate to the real risks you face. Reporting Our aim is to leave a report with you at the end of your visit, or as soon as possible afterwards. Rapid feedback is important, because once a risk has been identified, it needs to be addressed promptly Non-conformity Taking notice of the non- conformities can help prevent costly mistakes and even legal action by the regulators. Improvement log Details your progress and the effective implementation of the improvements. A mechanism for tracking the progress of strategic improvements around the key issues. SurveillanceInitial assessment Certificate
  • 21. Thank You W: LRQAMEA.COM T: +971 (4) 701 4150 E: LRQA-MEA@LR.org Lloyd's Register 21
  • 22. Lloyd's Register 22 Continuity and Resilience (CORE) ISO 22301 BCM Consulting Firm Presentations by speakers at the 8th ME Business & IT Resilience Summit March 10, 2019 at The Address Hotel, Duabi Mall, Dubai, UAE Our Contact Details: UAE INDIA Continuity and Resilience Website: www.coreconsulting.ae Tel: +971 2 6594006 PO Box: 25722, Abu Dhabi, United Arab Emirates Email: info@continuityandresilience.com Continuity and Resilience Tel: +91 11 41055534 | Direct: +91 11 6467 9380 Email: info@continuityandresilience.com Website: www.coreconsulting.ae Level 15, Eros Corporate Towers, Nehru Place, New Delhi – 110019, India