SlideShare una empresa de Scribd logo
1 de 7
Example Business Continuity Plan
        Based upon DS4.2 from COBIT (Control Objectives for Information Technology)

                              Prepared by: Micheal Axelsen FCPA1
                                Director, Applied Insight Pty Ltd

Provided as is, without warranty, for businesses to consider as a very early starting point in
the preparation of a business continuity plan. This work is based upon material delivered to
University business students.

Question One: Research Issue – Personal Data Protection

Assume a fire has destroyed your bedroom. Identify the items in your room that would be
irreplaceable if this scenario eventuated. Draw up a business continuity plan for your
bedroom and yourself.

Identify what you would need to do to ensure that irreplaceable items are better protected in
the future. Identify the steps you would need to take immediately after the fire to recover
from this disaster.

Worked Solution

Note that in COBIT 4.1, regarding the IT aspects we would need to identify an IT continuity
plan. Firstly, we need to understand our business requirements – what our key business
functions and processes are (DS4.2).

So, the business continuity plan draws upon our risk management framework (for argument’s
sake, AS/NZS 4360:2004):

•     Identify key business functions and processes.




1
    Micheal may be contacted on 0412 526 375 or micheal.axelsen@appliedinsight.com.au.


                                                                                                 1
•   Identify ‘major’ disruption by reference to risk appetite




    Consider what the definitions of economic loss might be that are insignificant, minor,
    moderate, major, or catastrophic (e.g. catastrophic might be $1,000,000 whilst
    insignificant might be $500).
•   Identify potential business impacts
•   What actions can be taken to address requirements for:
        • Resilience (reduce likelihood or consequence of the risk)
        • Alternative processing (work-arounds in the event access is denied)
        • Recovery capability of critical IT services (recovery of critical IT services)
•   Identify usage guidelines, roles and responsibilities, procedures, communication
    processes, and the testing approach




                                                                                             2
A rough approach might look like this:
                                                                    Business Continuity Plan

Risk Appetite: The business has determined that it can withstand a $3,000 level of disruption.

Assumptions: Catastrophic events (e.g. fire, flood) would result in similar business impacts. Actions to reduce impact will work equally as well
for low-impact events (e.g. localised flooding, loss of internet connection).

Note: Some things are deliberately missing – who can spot something?

        Key business functions            Business impact if                      Resilience                                    Actions                   Procedures &
                                            unavailable                                                                                                  Responsibilities
 Client Acquisition:
     • Marketing website material     Clients unable to discover    Host with reliable ISP with strong       Take XML download of posts/content          MSA
         (two websites,               business and identify         financial background (Yahoo)             monthly. Add to backup processes.
         www.michealaxelsen.com and   services. Large business
         www.appliedinsight.com.au)   impact.                       Host on a common ISP platform.
         and supporting collateral
                                      If content lost, would take
                                      months to re-create, if at
                                      all possible.
    •   Current marketing plan        Marketing stages with         Incorporate into Exchange Server         None identified.                            MSA
                                      clients lost. Moderate        with email – reduce points of failure.
                                      business impact.
                                                                    Reputable provider with SLA
                                                                    (WebCentral)

                                                                    Enables sync across devices and
                                                                    internet access.
 Service Delivery
     • Methodologies and client       Affects ability to convince   Store in a single place and protect      Backup process:                             MSA
         outputs                      clients of capability.        that well (i.e. hard drive) and
                                                                    incorporate into backup processes.       1.   Use SyncBack for each laptop daily –




                                                                                                                                                                 3
Key business functions        Business impact if                     Resilience                                Actions                      Procedures &
                                        unavailable                                                                                               Responsibilities
                                Affects efficiency and                                                   files are stored in three places (PMD,
                                effectiveness as these are                                               Dell, HP).
                                all key to service delivery.                                         2. Daily backup from Dell to external
                                                                                                         USB using MS Backup & Sync
                                                                                                         (monthly resets to keep disk space
                                                                                                         low).
                                                                                                     3. Monthly backup of entire system to a
                                                                                                         third 500gb pocket media drive kept at
                                                                                                         separate office 5 km away.
   •   Precedents and models    Affects ability to convince    Store in a single place and protect   See backup process                           MSA
                                clients of capability.         that well (i.e. hard drive) and
                                                               incorporate into backup processes.
                                Affects efficiency and
                                effectiveness as these are
                                all key to service delivery.
   •   Templates                Affects ability to convince    Store in a single place and protect   See backup process                           MSA
                                clients of capability.         that well (i.e. hard drive) and
                                                               incorporate into backup processes.
                                Affects efficiency and
                                effectiveness as these are
                                all key to service delivery.
   •   Research Notes           Affects ability to convince    Store in a single place and protect   None required – rely upon Evernote SLA.      MSA
                                clients of capability.         that well (i.e. hard drive) and
                                                               incorporate into backup processes.
                                Affects efficiency and
                                effectiveness as these are     Store research notes in Evernote
                                all key to service delivery.   software (paid subscription) –
                                                               enables sync across devices and
                                                               mobile access.

                                                               Maintained in three places (Dell,
                                                               online, and HP Mini-Note).
Administrative Support




                                                                                                                                                          4
Key business functions           Business impact if                      Resilience                                  Actions                     Procedures &
                                         unavailable                                                                                                Responsibilities
•   MYOB Accounting System       Unable to invoice and         Store in a single place and protect      See backup process                          MSA
                                 meet external compliance      that well (i.e. hard drive) and
                                 requirements.                 incorporate into backup processes.
•   Access to email              Unable to communicate         Incorporate into Exchange Server         None.                                       MSA
                                 with clients.                 with email – reduce points of failure.

                                                               Reputable provider with SLA
                                                               (WebCentral)


•   Task list                    Current workload would        Incorporate into Exchange Server         None.                                       MSA
                                 be lost.                      with email – reduce points of failure.

                                                               Reputable provider with SLA
                                                               (WebCentral)

                                                               Enables sync across devices and
                                                               internet access with only an internet
                                                               connection.
•   Mobile telephone             Major contact point with      Insurance policy                         None.                                       MSA
                                 clients lost; $1,200 phone
                                 to replace if purchased.
•   VOIP phone                   Major contact point with      None – wear this as an expense.          Identify provider (Engin telephone).        MSA
                                 clients lost; $100 phone to
                                 replace if needs to be                                                 Divert VOIP phone to mobile in
                                 repurchased.                                                           emergency using password details noted in
                                                                                                        Evernote.
•   Accounting records (Paper)   Unable to invoice and         Monthly scan to electronic format.       See backup process.                         MSA
                                 meet external compliance
                                 requirements.
•   Bookmarks                    Lose record of access to      Place bookmarks online in webspace       None.                                       MSA
                                 many required online          (start.michealaxelsen.com) using
                                 services (e.g. online         Google start page.




                                                                                                                                                             5
Key business functions              Business impact if                      Resilience                                   Actions                    Procedures &
                                               unavailable                                                                                                Responsibilities
                                       banking, blog,
   •   Critical passwords              Unable to access many          Store passwords in Evernote             None.                                       MSA
                                       websites crucial to            (encrypted using common super-
                                       operating business             duper secret password).

                                                                      Will be able to regain access with PC
                                                                      and internet connection.
   •   Suncorp Token Key               Without this, I lose access    In event of catastrophe, Suncorp        None.                                       MSA
                                       to online banking full stop.   provides a temporary security code
                                                                      until a new key is issued.
IT Infrastructure
    • Dell Laptop (15”) (approximately $3K)             Unable to provide           Insurance policy;         In event of loss, identify with insurance   MSA
                                                        services                    backup processes          provider and order replacement.

                                                                                                              Preferred Vendor: Dell

   •   HP Laptop Mini-Note 2133 (approximately $1K)     Unable to provide           Insurance policy;         In event of loss, identify with insurance   MSA
                                                        services                    backup processes          provider and order replacement.

                                                                                                              Preferred Vendor: HT

   •   HP Scanjet bubblejet printer                     Unable to provide           Insurance policy;         In event of loss, identify with insurance   MSA
                                                        services                    backup processes.         provider and order replacement.

                                                                                    Order three year on-      Preferred Vendor: HT
                                                                                    site warranty.
   •   Pocketmedia Drive                                Unable to provide           Insurance policy;         In event of loss, identify with insurance   MSA
                                                        services                    backup processes          provider and order replacement.

                                                                                                              Preferred Vendor: HT

   •   External USB HDD (WD)                            Unable to provide           Insurance policy;         In event of loss, identify with insurance   MSA
                                                        services                    backup processes          provider and order replacement.




                                                                                                                                                                  6
Key business functions             Business impact if                       Resilience                                 Actions                    Procedures &
                                         unavailable                                                                                                 Responsibilities

                                                                                                          Preferred Vendor: HT

•   Broadband connection                           Unable to perform             Identify a secondary     Use alternative provider (suggested: $10   MSA
                                                   online banking, pay           alternative provider     per GB wireless connection at UQ,
                                                   bills, and deliver                                     available quickly from office).
                                                   services.
                                                                                                          Or just wifi surf someone else’s open
                                                                                                          wireless connection .
•   CD Media (to reinstall software)               If lost, would require re-    Backup CD media and      Restore from separate DVDs.                MSA
                                                   purchase of $5,000            store in a separate
                                                   worth of Microsoft            location (office)
                                                   goodies without proof-        together with software
                                                   of-purchase.                  keys.




                                                                                                                                                             7

Más contenido relacionado

La actualidad más candente

Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planingHanaysha
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity ManagementDiane Christina
 
Disaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesDisaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesSlideTeam
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity PlanningDipankar Ghosh
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcpAdv Prashant Mali
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planninggcleary
 
Disaster Recovery Plan
Disaster Recovery Plan Disaster Recovery Plan
Disaster Recovery Plan Emilie Gray
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery PlanningKathy Pelletier
 
Business Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationBusiness Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationPECB
 
Business Continuity & Disaster Recovery
Business Continuity & Disaster RecoveryBusiness Continuity & Disaster Recovery
Business Continuity & Disaster RecoveryEC-Council
 
What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP) What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP) CBIZ, Inc.
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery PlanningJohn Wilson
 
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptxBUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptxJayLloyd8
 
Bcm Roadmap
Bcm RoadmapBcm Roadmap
Bcm Roadmapbtrmuray
 
Business Continuity Detailed Plan
Business Continuity Detailed PlanBusiness Continuity Detailed Plan
Business Continuity Detailed PlanWissam Abdel Baki
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Planmhdpaknejad
 
What is dr and bc 12-2017
What is dr and bc 12-2017What is dr and bc 12-2017
What is dr and bc 12-2017Atef Yassin
 

La actualidad más candente (20)

Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planing
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
Disaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesDisaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation Slides
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcp
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Disaster Recovery Plan
Disaster Recovery Plan Disaster Recovery Plan
Disaster Recovery Plan
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery Planning
 
Integrated GRC
Integrated GRCIntegrated GRC
Integrated GRC
 
Business Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationBusiness Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS Implementation
 
Business Continuity & Disaster Recovery
Business Continuity & Disaster RecoveryBusiness Continuity & Disaster Recovery
Business Continuity & Disaster Recovery
 
What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP) What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP)
 
Introduction to Business Continuity Management
Introduction to Business Continuity ManagementIntroduction to Business Continuity Management
Introduction to Business Continuity Management
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery Planning
 
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptxBUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
 
Bcm Roadmap
Bcm RoadmapBcm Roadmap
Bcm Roadmap
 
Business Continuity Detailed Plan
Business Continuity Detailed PlanBusiness Continuity Detailed Plan
Business Continuity Detailed Plan
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
 
What is dr and bc 12-2017
What is dr and bc 12-2017What is dr and bc 12-2017
What is dr and bc 12-2017
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 

Similar a Business Continuity Plan Template

Business Continuity Knowledge Share
Business Continuity Knowledge ShareBusiness Continuity Knowledge Share
Business Continuity Knowledge Share.Gastón. .Bx.
 
Mesabi Group paper: Rethink Data Protection and Retention Now Merchandising
Mesabi Group paper: Rethink Data Protection and Retention Now Merchandising Mesabi Group paper: Rethink Data Protection and Retention Now Merchandising
Mesabi Group paper: Rethink Data Protection and Retention Now Merchandising IBM India Smarter Computing
 
Maximizing Business Continuity Success
Maximizing Business Continuity SuccessMaximizing Business Continuity Success
Maximizing Business Continuity SuccessSymantec
 
Map r whitepaper_zeta_architecture
Map r whitepaper_zeta_architectureMap r whitepaper_zeta_architecture
Map r whitepaper_zeta_architectureNarender Kumar
 
S-CUBE LP: Techniques for design for adaptation
S-CUBE LP: Techniques for design for adaptationS-CUBE LP: Techniques for design for adaptation
S-CUBE LP: Techniques for design for adaptationvirtual-campus
 
Destroying Perf Bottlenecks
Destroying Perf BottlenecksDestroying Perf Bottlenecks
Destroying Perf Bottlenecksbenscheerer
 
Driving Business Value on Power Systems with Solid-state Drives
Driving Business Value on Power Systems with Solid-state DrivesDriving Business Value on Power Systems with Solid-state Drives
Driving Business Value on Power Systems with Solid-state DrivesIBM India Smarter Computing
 
A Cost-Effective Integrated Solution for Backup and Disaster Recovery
A Cost-Effective Integrated Solution for Backup and Disaster RecoveryA Cost-Effective Integrated Solution for Backup and Disaster Recovery
A Cost-Effective Integrated Solution for Backup and Disaster Recoveryxmeteorite
 
PCTY 2012, Overvågning af forretningssystemer i et virtuelt miljø v. Hans Ped...
PCTY 2012, Overvågning af forretningssystemer i et virtuelt miljø v. Hans Ped...PCTY 2012, Overvågning af forretningssystemer i et virtuelt miljø v. Hans Ped...
PCTY 2012, Overvågning af forretningssystemer i et virtuelt miljø v. Hans Ped...IBM Danmark
 
Building a Business Continuity Capability
Building a Business Continuity CapabilityBuilding a Business Continuity Capability
Building a Business Continuity CapabilityRod Davis
 
Introduction to Modern Data Virtualization 2021 (APAC)
Introduction to Modern Data Virtualization 2021 (APAC)Introduction to Modern Data Virtualization 2021 (APAC)
Introduction to Modern Data Virtualization 2021 (APAC)Denodo
 
Business Continuity for Mission Critical Applications
Business Continuity for Mission Critical ApplicationsBusiness Continuity for Mission Critical Applications
Business Continuity for Mission Critical ApplicationsDataCore Software
 
Cut Costs - Fight Recession
Cut Costs - Fight RecessionCut Costs - Fight Recession
Cut Costs - Fight RecessionMomir Boskovic
 
Mission critical linux white paper
Mission critical linux white paperMission critical linux white paper
Mission critical linux white paperFas (Feisal) Mosleh
 
Whose View is it Anyway: Addressing Multiple Stakeholder Concerns
Whose View is it Anyway: Addressing Multiple Stakeholder ConcernsWhose View is it Anyway: Addressing Multiple Stakeholder Concerns
Whose View is it Anyway: Addressing Multiple Stakeholder Concernssferoz
 
Sas Predictive Asset Maintenance
Sas   Predictive Asset MaintenanceSas   Predictive Asset Maintenance
Sas Predictive Asset Maintenancepierrecochard
 

Similar a Business Continuity Plan Template (20)

Business Continuity Knowledge Share
Business Continuity Knowledge ShareBusiness Continuity Knowledge Share
Business Continuity Knowledge Share
 
Mesabi Group paper: Rethink Data Protection and Retention Now Merchandising
Mesabi Group paper: Rethink Data Protection and Retention Now Merchandising Mesabi Group paper: Rethink Data Protection and Retention Now Merchandising
Mesabi Group paper: Rethink Data Protection and Retention Now Merchandising
 
Maximizing Business Continuity Success
Maximizing Business Continuity SuccessMaximizing Business Continuity Success
Maximizing Business Continuity Success
 
Map r whitepaper_zeta_architecture
Map r whitepaper_zeta_architectureMap r whitepaper_zeta_architecture
Map r whitepaper_zeta_architecture
 
S-CUBE LP: Techniques for design for adaptation
S-CUBE LP: Techniques for design for adaptationS-CUBE LP: Techniques for design for adaptation
S-CUBE LP: Techniques for design for adaptation
 
DS Auditor Datasheet
DS Auditor DatasheetDS Auditor Datasheet
DS Auditor Datasheet
 
Destroying Perf Bottlenecks
Destroying Perf BottlenecksDestroying Perf Bottlenecks
Destroying Perf Bottlenecks
 
Driving Business Value on Power Systems with Solid-state Drives
Driving Business Value on Power Systems with Solid-state DrivesDriving Business Value on Power Systems with Solid-state Drives
Driving Business Value on Power Systems with Solid-state Drives
 
A Cost-Effective Integrated Solution for Backup and Disaster Recovery
A Cost-Effective Integrated Solution for Backup and Disaster RecoveryA Cost-Effective Integrated Solution for Backup and Disaster Recovery
A Cost-Effective Integrated Solution for Backup and Disaster Recovery
 
PCTY 2012, Overvågning af forretningssystemer i et virtuelt miljø v. Hans Ped...
PCTY 2012, Overvågning af forretningssystemer i et virtuelt miljø v. Hans Ped...PCTY 2012, Overvågning af forretningssystemer i et virtuelt miljø v. Hans Ped...
PCTY 2012, Overvågning af forretningssystemer i et virtuelt miljø v. Hans Ped...
 
Managing multi-site teams on Agile Projects
Managing multi-site teams on Agile ProjectsManaging multi-site teams on Agile Projects
Managing multi-site teams on Agile Projects
 
Building a Business Continuity Capability
Building a Business Continuity CapabilityBuilding a Business Continuity Capability
Building a Business Continuity Capability
 
Introduction to Modern Data Virtualization 2021 (APAC)
Introduction to Modern Data Virtualization 2021 (APAC)Introduction to Modern Data Virtualization 2021 (APAC)
Introduction to Modern Data Virtualization 2021 (APAC)
 
Business Continuity for Mission Critical Applications
Business Continuity for Mission Critical ApplicationsBusiness Continuity for Mission Critical Applications
Business Continuity for Mission Critical Applications
 
Cut Costs - Fight Recession
Cut Costs - Fight RecessionCut Costs - Fight Recession
Cut Costs - Fight Recession
 
Mission critical linux white paper
Mission critical linux white paperMission critical linux white paper
Mission critical linux white paper
 
Whose View is it Anyway: Addressing Multiple Stakeholder Concerns
Whose View is it Anyway: Addressing Multiple Stakeholder ConcernsWhose View is it Anyway: Addressing Multiple Stakeholder Concerns
Whose View is it Anyway: Addressing Multiple Stakeholder Concerns
 
Resume
ResumeResume
Resume
 
GIS POV
GIS POVGIS POV
GIS POV
 
Sas Predictive Asset Maintenance
Sas   Predictive Asset MaintenanceSas   Predictive Asset Maintenance
Sas Predictive Asset Maintenance
 

Más de Micheal Axelsen

20220114 Typecasting on the lettera 22
20220114 Typecasting on the lettera 2220220114 Typecasting on the lettera 22
20220114 Typecasting on the lettera 22Micheal Axelsen
 
20210214 Adventures in Typewriting - In Australia
20210214 Adventures in Typewriting - In Australia20210214 Adventures in Typewriting - In Australia
20210214 Adventures in Typewriting - In AustraliaMicheal Axelsen
 
Cyber Security and the CEO
Cyber Security and the CEOCyber Security and the CEO
Cyber Security and the CEOMicheal Axelsen
 
Speakers at MNCs in Emerging Markets: International Human Resource Management...
Speakers at MNCs in Emerging Markets: International Human Resource Management...Speakers at MNCs in Emerging Markets: International Human Resource Management...
Speakers at MNCs in Emerging Markets: International Human Resource Management...Micheal Axelsen
 
Seminar Invitation to UQ BS Event: MNCs in Emerging Markets: International H...
Seminar Invitation to UQ BS Event:  MNCs in Emerging Markets: International H...Seminar Invitation to UQ BS Event:  MNCs in Emerging Markets: International H...
Seminar Invitation to UQ BS Event: MNCs in Emerging Markets: International H...Micheal Axelsen
 
Review tversky & kahnemann (1974) judgment under uncertainty
Review   tversky & kahnemann (1974) judgment under uncertaintyReview   tversky & kahnemann (1974) judgment under uncertainty
Review tversky & kahnemann (1974) judgment under uncertaintyMicheal Axelsen
 
What if I told you you doing insane hours is not the same as doing your phd?
What if I told you you doing insane hours is not the same as doing your phd?What if I told you you doing insane hours is not the same as doing your phd?
What if I told you you doing insane hours is not the same as doing your phd?Micheal Axelsen
 
Workshop: Processes and practices for effective information governance
Workshop:  Processes and practices for effective information governanceWorkshop:  Processes and practices for effective information governance
Workshop: Processes and practices for effective information governanceMicheal Axelsen
 
Sergeant Major Eats Sugar Cookies
Sergeant Major Eats Sugar CookiesSergeant Major Eats Sugar Cookies
Sergeant Major Eats Sugar CookiesMicheal Axelsen
 
IDAS and the Accounting Professional
IDAS and the Accounting ProfessionalIDAS and the Accounting Professional
IDAS and the Accounting ProfessionalMicheal Axelsen
 
Online Social Networking and the Workplace draft #3 final
Online Social Networking and the Workplace draft #3 finalOnline Social Networking and the Workplace draft #3 final
Online Social Networking and the Workplace draft #3 finalMicheal Axelsen
 
Judgment Under Uncertainty: Anchoring and Adjustment Bias
Judgment Under Uncertainty:  Anchoring and Adjustment BiasJudgment Under Uncertainty:  Anchoring and Adjustment Bias
Judgment Under Uncertainty: Anchoring and Adjustment BiasMicheal Axelsen
 
NGERS and Data Capture Systems: Reporting Requirements
NGERS and Data Capture Systems:  Reporting RequirementsNGERS and Data Capture Systems:  Reporting Requirements
NGERS and Data Capture Systems: Reporting RequirementsMicheal Axelsen
 
Overview of Key Performance Indicators
Overview of Key Performance IndicatorsOverview of Key Performance Indicators
Overview of Key Performance IndicatorsMicheal Axelsen
 
Data Management Strategies - Speakers Notes
Data Management Strategies - Speakers NotesData Management Strategies - Speakers Notes
Data Management Strategies - Speakers NotesMicheal Axelsen
 
Data Management Strategies
Data Management StrategiesData Management Strategies
Data Management StrategiesMicheal Axelsen
 
Research in an e-enabled world
Research in an e-enabled worldResearch in an e-enabled world
Research in an e-enabled worldMicheal Axelsen
 
Continued Use Of IDAs And Knowledge Acquisition
Continued Use Of IDAs And Knowledge AcquisitionContinued Use Of IDAs And Knowledge Acquisition
Continued Use Of IDAs And Knowledge AcquisitionMicheal Axelsen
 

Más de Micheal Axelsen (20)

20220114 Typecasting on the lettera 22
20220114 Typecasting on the lettera 2220220114 Typecasting on the lettera 22
20220114 Typecasting on the lettera 22
 
20210214 Adventures in Typewriting - In Australia
20210214 Adventures in Typewriting - In Australia20210214 Adventures in Typewriting - In Australia
20210214 Adventures in Typewriting - In Australia
 
Cyber Security and the CEO
Cyber Security and the CEOCyber Security and the CEO
Cyber Security and the CEO
 
Speakers at MNCs in Emerging Markets: International Human Resource Management...
Speakers at MNCs in Emerging Markets: International Human Resource Management...Speakers at MNCs in Emerging Markets: International Human Resource Management...
Speakers at MNCs in Emerging Markets: International Human Resource Management...
 
Seminar Invitation to UQ BS Event: MNCs in Emerging Markets: International H...
Seminar Invitation to UQ BS Event:  MNCs in Emerging Markets: International H...Seminar Invitation to UQ BS Event:  MNCs in Emerging Markets: International H...
Seminar Invitation to UQ BS Event: MNCs in Emerging Markets: International H...
 
Review tversky & kahnemann (1974) judgment under uncertainty
Review   tversky & kahnemann (1974) judgment under uncertaintyReview   tversky & kahnemann (1974) judgment under uncertainty
Review tversky & kahnemann (1974) judgment under uncertainty
 
What if I told you you doing insane hours is not the same as doing your phd?
What if I told you you doing insane hours is not the same as doing your phd?What if I told you you doing insane hours is not the same as doing your phd?
What if I told you you doing insane hours is not the same as doing your phd?
 
Workshop: Processes and practices for effective information governance
Workshop:  Processes and practices for effective information governanceWorkshop:  Processes and practices for effective information governance
Workshop: Processes and practices for effective information governance
 
Sergeant Major Eats Sugar Cookies
Sergeant Major Eats Sugar CookiesSergeant Major Eats Sugar Cookies
Sergeant Major Eats Sugar Cookies
 
IDAS and the Accounting Professional
IDAS and the Accounting ProfessionalIDAS and the Accounting Professional
IDAS and the Accounting Professional
 
Academic paper template
Academic paper templateAcademic paper template
Academic paper template
 
Online Social Networking and the Workplace draft #3 final
Online Social Networking and the Workplace draft #3 finalOnline Social Networking and the Workplace draft #3 final
Online Social Networking and the Workplace draft #3 final
 
Judgment Under Uncertainty: Anchoring and Adjustment Bias
Judgment Under Uncertainty:  Anchoring and Adjustment BiasJudgment Under Uncertainty:  Anchoring and Adjustment Bias
Judgment Under Uncertainty: Anchoring and Adjustment Bias
 
The Data Dynamic
The Data DynamicThe Data Dynamic
The Data Dynamic
 
NGERS and Data Capture Systems: Reporting Requirements
NGERS and Data Capture Systems:  Reporting RequirementsNGERS and Data Capture Systems:  Reporting Requirements
NGERS and Data Capture Systems: Reporting Requirements
 
Overview of Key Performance Indicators
Overview of Key Performance IndicatorsOverview of Key Performance Indicators
Overview of Key Performance Indicators
 
Data Management Strategies - Speakers Notes
Data Management Strategies - Speakers NotesData Management Strategies - Speakers Notes
Data Management Strategies - Speakers Notes
 
Data Management Strategies
Data Management StrategiesData Management Strategies
Data Management Strategies
 
Research in an e-enabled world
Research in an e-enabled worldResearch in an e-enabled world
Research in an e-enabled world
 
Continued Use Of IDAs And Knowledge Acquisition
Continued Use Of IDAs And Knowledge AcquisitionContinued Use Of IDAs And Knowledge Acquisition
Continued Use Of IDAs And Knowledge Acquisition
 

Último

Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxGo for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxRakhi Bazaar
 
business environment micro environment macro environment.pptx
business environment micro environment macro environment.pptxbusiness environment micro environment macro environment.pptx
business environment micro environment macro environment.pptxShruti Mittal
 
Excvation Safety for safety officers reference
Excvation Safety for safety officers referenceExcvation Safety for safety officers reference
Excvation Safety for safety officers referencessuser2c065e
 
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...SOFTTECHHUB
 
Lucia Ferretti, Lead Business Designer; Matteo Meschini, Business Designer @T...
Lucia Ferretti, Lead Business Designer; Matteo Meschini, Business Designer @T...Lucia Ferretti, Lead Business Designer; Matteo Meschini, Business Designer @T...
Lucia Ferretti, Lead Business Designer; Matteo Meschini, Business Designer @T...Associazione Digital Days
 
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...ssuserf63bd7
 
Send Files | Sendbig.comSend Files | Sendbig.com
Send Files | Sendbig.comSend Files | Sendbig.comSend Files | Sendbig.comSend Files | Sendbig.com
Send Files | Sendbig.comSend Files | Sendbig.comSendBig4
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxmbikashkanyari
 
trending-flavors-and-ingredients-in-salty-snacks-us-2024_Redacted-V2.pdf
trending-flavors-and-ingredients-in-salty-snacks-us-2024_Redacted-V2.pdftrending-flavors-and-ingredients-in-salty-snacks-us-2024_Redacted-V2.pdf
trending-flavors-and-ingredients-in-salty-snacks-us-2024_Redacted-V2.pdfMintel Group
 
PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationAnamaria Contreras
 
Driving Business Impact for PMs with Jon Harmer
Driving Business Impact for PMs with Jon HarmerDriving Business Impact for PMs with Jon Harmer
Driving Business Impact for PMs with Jon HarmerAggregage
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfRbc Rbcua
 
NAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataNAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataExhibitors Data
 
EUDR Info Meeting Ethiopian coffee exporters
EUDR Info Meeting Ethiopian coffee exportersEUDR Info Meeting Ethiopian coffee exporters
EUDR Info Meeting Ethiopian coffee exportersPeter Horsten
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMVoces Mineras
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdfShaun Heinrichs
 
Unveiling the Soundscape Music for Psychedelic Experiences
Unveiling the Soundscape Music for Psychedelic ExperiencesUnveiling the Soundscape Music for Psychedelic Experiences
Unveiling the Soundscape Music for Psychedelic ExperiencesDoe Paoro
 
BAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptxBAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptxran17april2001
 
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdfChris Skinner
 

Último (20)

Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptxGo for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
Go for Rakhi Bazaar and Pick the Latest Bhaiya Bhabhi Rakhi.pptx
 
business environment micro environment macro environment.pptx
business environment micro environment macro environment.pptxbusiness environment micro environment macro environment.pptx
business environment micro environment macro environment.pptx
 
Excvation Safety for safety officers reference
Excvation Safety for safety officers referenceExcvation Safety for safety officers reference
Excvation Safety for safety officers reference
 
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
How To Simplify Your Scheduling with AI Calendarfly The Hassle-Free Online Bo...
 
Lucia Ferretti, Lead Business Designer; Matteo Meschini, Business Designer @T...
Lucia Ferretti, Lead Business Designer; Matteo Meschini, Business Designer @T...Lucia Ferretti, Lead Business Designer; Matteo Meschini, Business Designer @T...
Lucia Ferretti, Lead Business Designer; Matteo Meschini, Business Designer @T...
 
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
Horngren’s Financial & Managerial Accounting, 7th edition by Miller-Nobles so...
 
Send Files | Sendbig.comSend Files | Sendbig.com
Send Files | Sendbig.comSend Files | Sendbig.comSend Files | Sendbig.comSend Files | Sendbig.com
Send Files | Sendbig.comSend Files | Sendbig.com
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
 
trending-flavors-and-ingredients-in-salty-snacks-us-2024_Redacted-V2.pdf
trending-flavors-and-ingredients-in-salty-snacks-us-2024_Redacted-V2.pdftrending-flavors-and-ingredients-in-salty-snacks-us-2024_Redacted-V2.pdf
trending-flavors-and-ingredients-in-salty-snacks-us-2024_Redacted-V2.pdf
 
PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement Presentation
 
Driving Business Impact for PMs with Jon Harmer
Driving Business Impact for PMs with Jon HarmerDriving Business Impact for PMs with Jon Harmer
Driving Business Impact for PMs with Jon Harmer
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdf
 
NAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataNAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors Data
 
EUDR Info Meeting Ethiopian coffee exporters
EUDR Info Meeting Ethiopian coffee exportersEUDR Info Meeting Ethiopian coffee exporters
EUDR Info Meeting Ethiopian coffee exporters
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQM
 
WAM Corporate Presentation April 12 2024.pdf
WAM Corporate Presentation April 12 2024.pdfWAM Corporate Presentation April 12 2024.pdf
WAM Corporate Presentation April 12 2024.pdf
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf
 
Unveiling the Soundscape Music for Psychedelic Experiences
Unveiling the Soundscape Music for Psychedelic ExperiencesUnveiling the Soundscape Music for Psychedelic Experiences
Unveiling the Soundscape Music for Psychedelic Experiences
 
BAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptxBAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptx
 
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
 

Business Continuity Plan Template

  • 1. Example Business Continuity Plan Based upon DS4.2 from COBIT (Control Objectives for Information Technology) Prepared by: Micheal Axelsen FCPA1 Director, Applied Insight Pty Ltd Provided as is, without warranty, for businesses to consider as a very early starting point in the preparation of a business continuity plan. This work is based upon material delivered to University business students. Question One: Research Issue – Personal Data Protection Assume a fire has destroyed your bedroom. Identify the items in your room that would be irreplaceable if this scenario eventuated. Draw up a business continuity plan for your bedroom and yourself. Identify what you would need to do to ensure that irreplaceable items are better protected in the future. Identify the steps you would need to take immediately after the fire to recover from this disaster. Worked Solution Note that in COBIT 4.1, regarding the IT aspects we would need to identify an IT continuity plan. Firstly, we need to understand our business requirements – what our key business functions and processes are (DS4.2). So, the business continuity plan draws upon our risk management framework (for argument’s sake, AS/NZS 4360:2004): • Identify key business functions and processes. 1 Micheal may be contacted on 0412 526 375 or micheal.axelsen@appliedinsight.com.au. 1
  • 2. Identify ‘major’ disruption by reference to risk appetite Consider what the definitions of economic loss might be that are insignificant, minor, moderate, major, or catastrophic (e.g. catastrophic might be $1,000,000 whilst insignificant might be $500). • Identify potential business impacts • What actions can be taken to address requirements for: • Resilience (reduce likelihood or consequence of the risk) • Alternative processing (work-arounds in the event access is denied) • Recovery capability of critical IT services (recovery of critical IT services) • Identify usage guidelines, roles and responsibilities, procedures, communication processes, and the testing approach 2
  • 3. A rough approach might look like this: Business Continuity Plan Risk Appetite: The business has determined that it can withstand a $3,000 level of disruption. Assumptions: Catastrophic events (e.g. fire, flood) would result in similar business impacts. Actions to reduce impact will work equally as well for low-impact events (e.g. localised flooding, loss of internet connection). Note: Some things are deliberately missing – who can spot something? Key business functions Business impact if Resilience Actions Procedures & unavailable Responsibilities Client Acquisition: • Marketing website material Clients unable to discover Host with reliable ISP with strong Take XML download of posts/content MSA (two websites, business and identify financial background (Yahoo) monthly. Add to backup processes. www.michealaxelsen.com and services. Large business www.appliedinsight.com.au) impact. Host on a common ISP platform. and supporting collateral If content lost, would take months to re-create, if at all possible. • Current marketing plan Marketing stages with Incorporate into Exchange Server None identified. MSA clients lost. Moderate with email – reduce points of failure. business impact. Reputable provider with SLA (WebCentral) Enables sync across devices and internet access. Service Delivery • Methodologies and client Affects ability to convince Store in a single place and protect Backup process: MSA outputs clients of capability. that well (i.e. hard drive) and incorporate into backup processes. 1. Use SyncBack for each laptop daily – 3
  • 4. Key business functions Business impact if Resilience Actions Procedures & unavailable Responsibilities Affects efficiency and files are stored in three places (PMD, effectiveness as these are Dell, HP). all key to service delivery. 2. Daily backup from Dell to external USB using MS Backup & Sync (monthly resets to keep disk space low). 3. Monthly backup of entire system to a third 500gb pocket media drive kept at separate office 5 km away. • Precedents and models Affects ability to convince Store in a single place and protect See backup process MSA clients of capability. that well (i.e. hard drive) and incorporate into backup processes. Affects efficiency and effectiveness as these are all key to service delivery. • Templates Affects ability to convince Store in a single place and protect See backup process MSA clients of capability. that well (i.e. hard drive) and incorporate into backup processes. Affects efficiency and effectiveness as these are all key to service delivery. • Research Notes Affects ability to convince Store in a single place and protect None required – rely upon Evernote SLA. MSA clients of capability. that well (i.e. hard drive) and incorporate into backup processes. Affects efficiency and effectiveness as these are Store research notes in Evernote all key to service delivery. software (paid subscription) – enables sync across devices and mobile access. Maintained in three places (Dell, online, and HP Mini-Note). Administrative Support 4
  • 5. Key business functions Business impact if Resilience Actions Procedures & unavailable Responsibilities • MYOB Accounting System Unable to invoice and Store in a single place and protect See backup process MSA meet external compliance that well (i.e. hard drive) and requirements. incorporate into backup processes. • Access to email Unable to communicate Incorporate into Exchange Server None. MSA with clients. with email – reduce points of failure. Reputable provider with SLA (WebCentral) • Task list Current workload would Incorporate into Exchange Server None. MSA be lost. with email – reduce points of failure. Reputable provider with SLA (WebCentral) Enables sync across devices and internet access with only an internet connection. • Mobile telephone Major contact point with Insurance policy None. MSA clients lost; $1,200 phone to replace if purchased. • VOIP phone Major contact point with None – wear this as an expense. Identify provider (Engin telephone). MSA clients lost; $100 phone to replace if needs to be Divert VOIP phone to mobile in repurchased. emergency using password details noted in Evernote. • Accounting records (Paper) Unable to invoice and Monthly scan to electronic format. See backup process. MSA meet external compliance requirements. • Bookmarks Lose record of access to Place bookmarks online in webspace None. MSA many required online (start.michealaxelsen.com) using services (e.g. online Google start page. 5
  • 6. Key business functions Business impact if Resilience Actions Procedures & unavailable Responsibilities banking, blog, • Critical passwords Unable to access many Store passwords in Evernote None. MSA websites crucial to (encrypted using common super- operating business duper secret password). Will be able to regain access with PC and internet connection. • Suncorp Token Key Without this, I lose access In event of catastrophe, Suncorp None. MSA to online banking full stop. provides a temporary security code until a new key is issued. IT Infrastructure • Dell Laptop (15”) (approximately $3K) Unable to provide Insurance policy; In event of loss, identify with insurance MSA services backup processes provider and order replacement. Preferred Vendor: Dell • HP Laptop Mini-Note 2133 (approximately $1K) Unable to provide Insurance policy; In event of loss, identify with insurance MSA services backup processes provider and order replacement. Preferred Vendor: HT • HP Scanjet bubblejet printer Unable to provide Insurance policy; In event of loss, identify with insurance MSA services backup processes. provider and order replacement. Order three year on- Preferred Vendor: HT site warranty. • Pocketmedia Drive Unable to provide Insurance policy; In event of loss, identify with insurance MSA services backup processes provider and order replacement. Preferred Vendor: HT • External USB HDD (WD) Unable to provide Insurance policy; In event of loss, identify with insurance MSA services backup processes provider and order replacement. 6
  • 7. Key business functions Business impact if Resilience Actions Procedures & unavailable Responsibilities Preferred Vendor: HT • Broadband connection Unable to perform Identify a secondary Use alternative provider (suggested: $10 MSA online banking, pay alternative provider per GB wireless connection at UQ, bills, and deliver available quickly from office). services. Or just wifi surf someone else’s open wireless connection . • CD Media (to reinstall software) If lost, would require re- Backup CD media and Restore from separate DVDs. MSA purchase of $5,000 store in a separate worth of Microsoft location (office) goodies without proof- together with software of-purchase. keys. 7