260 likes | 511 Views
Business Continuity Planning. MIKE FAITHFULL MBCI Corporate Continuity Manager Information Management Division. yeah, very funny Dave. a-choo!. Service Delivery. Strategic Objectives. Emergency Response. Business Continuity. Risk Management. Emergency Planning. The overlap.
E N D
Business Continuity Planning MIKE FAITHFULLMBCI Corporate Continuity Manager Information Management Division
yeah, very funny Dave. a-choo!
Service Delivery Strategic Objectives Emergency Response Business Continuity Risk Management Emergency Planning The overlap Martin Barnard – Hammersmith & Fulham
Business Continuity HUMAN RESOURCES KNOWLEDGE MANAGEMENT ETC … SECURITY EMERGENCY MANAGEMENT IT DISASTER RECOVERY FACILITIES MANAGEMENT SUPPLY CHAIN MANAGEMENT ENVIRONMENTAL MANAGEMENT HEALTH & SAFETY RISK MANAGEMENT QUALITY MANAGEMENT
What is (a) risk? • How do we measure it? • How do we manage it?
the chance of something happening that will have an impact upon objectives. AS/NZS 4360 sensitivity to things you cannot control Prof.John Gordon – University of Hertfordshire the combination of the probability of an event and its consequences uncertainty of outcome, whether positive opportunity or negative threat, of actions and events a function of probability and impact BCI et al AIRMIC/ALARM Risk Management Standard HM Treasury “Orange Book” RISK is … the possibility of more than one outcome occurring HM Treasury “Green Book”
(hint: go here and hope it works) Pragmatic definition for BC planning …
THREAT “At Risk” VULNERABILITY EXPOSURE
Assets Threats Vulnerabilities Riskanalysis Risks Riskmanagement Countermeasures
What is (a) risk? • How do we measure it? • How do we manage it?
Impact Risk Assessment Matrix Critical Significant Noticeable Low Medium High Likelihood of Occurrence Assessing risk Assessing risks
(have another go) Pragmatic way to measure, with signposts to mitigation …
Flood 1,10 Fire 6,6 Errors 10,1 Seriousness 10 INSURE (Contingent) PREVENT ? Probability 1 10 ACCEPT THE RISK CONTROL AND CONTAIN 1
Impact / Seriousness Probability
Not ‘black and white’, but many shades of gr.. er Impact / Seriousness Probability
Seriousness 10 Probability 1 10 1 CONTINGENT ACTION PREVENTIVE ACTION ACCEPT THE RISK CONTROL AND CONTAIN Impact / Seriousness Probability
Time ! What could a ‘disaster’ cost me …? Cost of protection £ Loss of business
£ Time-related costs Incident cost Time What could a ‘disaster’ cost me …?
“An ounce of prevention …” Likely cause Preventive action Contingent action Install alarms Provide extinguishers Provide emergency exits Call Fire Service Purchase insurance ... Smoking Electrical faults Arson Ban it Regular maintenance Effective security measures