Preface |
|
xi | |
Acknowledgments |
|
xiii | |
Digital Assets |
|
xv | |
Introduction |
|
xvii | |
Chapter 1 Business Continuity-A Definition And A Brief History |
|
1 | (18) |
|
|
1 | (1) |
|
|
2 | (11) |
|
1.2.1 Emergency Management |
|
|
2 | (2) |
|
1.2.2 Community Disaster Services |
|
|
4 | (1) |
|
|
4 | (1) |
|
|
5 | (1) |
|
|
6 | (1) |
|
1.2.6 Insurance and Risk Management |
|
|
7 | (1) |
|
|
8 | (1) |
|
1.2.8 Millennium Bug (Y2K) |
|
|
8 | (1) |
|
1.2.9 Business Continuity Organizations and Certification |
|
|
8 | (1) |
|
1.2.10 Effect of September 11, 2001 |
|
|
9 | (1) |
|
|
10 | (2) |
|
|
12 | (1) |
|
1.2.13 Private Sector Preparedness Accreditation and Certification Program |
|
|
12 | (1) |
|
1.2.14 Emergency Management Accreditation Program |
|
|
12 | (1) |
|
|
12 | (1) |
|
|
13 | (3) |
|
|
16 | (1) |
|
|
17 | (2) |
Chapter 2 Understanding The Standards |
|
19 | (14) |
|
|
19 | (1) |
|
|
20 | (1) |
|
|
21 | (3) |
|
2.3.1 Plan (Establish, or in the ASIS Version: Establish the Management System) |
|
|
22 | (1) |
|
2.3.2 Do (Implement and Operate) |
|
|
22 | (1) |
|
2.3.3 Check (Monitor and Review) |
|
|
22 | (1) |
|
2.3.4 Act (Maintain and Improve) |
|
|
23 | (1) |
|
2.4 Organization of Standards |
|
|
24 | (6) |
|
|
30 | (2) |
|
|
32 | (1) |
Chapter 3 Building A Business Continuity Capability |
|
33 | (18) |
|
|
34 | (1) |
|
|
34 | (1) |
|
3.3 Business Continuity Manager |
|
|
35 | (2) |
|
3.3.1 Understanding the Context of the Organization |
|
|
36 | (1) |
|
|
37 | (2) |
|
3.4.1 Statement of Applicability |
|
|
38 | (1) |
|
|
39 | (1) |
|
3.6 Business Continuity Objectives and Project Planning |
|
|
40 | (2) |
|
3.7 Competence and Awareness |
|
|
42 | (1) |
|
|
43 | (3) |
|
|
46 | (1) |
|
3.9.1 Business Continuity Working Group |
|
|
47 | (1) |
|
|
47 | (2) |
|
|
49 | (2) |
Chapter 4 Emergency Management-Preparedness And Response |
|
51 | (18) |
|
|
52 | (1) |
|
|
52 | (3) |
|
|
55 | (12) |
|
4.3.1 Emergency Response Program and Plan |
|
|
56 | (3) |
|
4.3.2 Emergency Response Team |
|
|
59 | (3) |
|
4.3.3 Incident Command System |
|
|
62 | (5) |
|
|
67 | (2) |
Chapter 5 Business Impact Analysis |
|
69 | (22) |
|
|
70 | (2) |
|
5.1.1 Recovery Time Objective and Recovery Point Objective |
|
|
71 | (1) |
|
5.2 Business Impact Analysis Process |
|
|
72 | (16) |
|
5.2.1 BIA Project Planning |
|
|
73 | (2) |
|
|
75 | (3) |
|
|
78 | (1) |
|
5.2.4 Documentation and Communication of Analysis |
|
|
79 | (9) |
|
|
88 | (1) |
|
|
88 | (1) |
|
|
88 | (3) |
Chapter 6 Risk Assessment |
|
91 | (16) |
|
|
92 | (1) |
|
|
93 | (1) |
|
|
94 | (9) |
|
6.3.1 Hazard Identification |
|
|
96 | (3) |
|
|
99 | (1) |
|
|
100 | (3) |
|
|
103 | (1) |
|
6.5 Risk Assessment Report |
|
|
104 | (1) |
|
|
105 | (1) |
|
|
106 | (1) |
Chapter 7 Mitigation And Business Continuity Strategy |
|
107 | (22) |
|
|
108 | (1) |
|
|
108 | (4) |
|
|
111 | (1) |
|
7.3 Business Continuity Strategy |
|
|
112 | (16) |
|
|
113 | (2) |
|
7.3.2 Accounting, Finance, and Payroll |
|
|
115 | (1) |
|
7.3.3 Customer Service/Technical Support |
|
|
115 | (1) |
|
|
116 | (1) |
|
|
117 | (2) |
|
7.3.6 Information Technology |
|
|
119 | (3) |
|
7.3.7 Insurance and Risk Management |
|
|
122 | (1) |
|
|
122 | (1) |
|
|
122 | (1) |
|
|
123 | (2) |
|
7.3.11 Purchasing/Procurement |
|
|
125 | (1) |
|
7.3.12 Sales and Marketing |
|
|
126 | (1) |
|
7.3.13 Telecommunications |
|
|
126 | (1) |
|
7.3.14 Alternate Location |
|
|
127 | (1) |
|
|
128 | (1) |
|
|
128 | (1) |
Chapter 8 Business Continuity Plans And Procedures |
|
129 | (32) |
|
|
130 | (1) |
|
8.2 Fundamental Attributes of the Plan |
|
|
130 | (1) |
|
8.3 Plan Organization and Structure |
|
|
131 | (13) |
|
|
132 | (1) |
|
8.3.2 Statement of Policy |
|
|
132 | (1) |
|
|
133 | (1) |
|
|
133 | (1) |
|
|
133 | (1) |
|
|
133 | (1) |
|
|
134 | (1) |
|
8.3.8 Invocation (Activation) Criteria, Procedures, and Authority |
|
|
134 | (1) |
|
8.3.9 Order of Succession and Delegation of Authority |
|
|
135 | (1) |
|
8.3.10 Continuity Organizational Structure |
|
|
135 | (1) |
|
8.3.11 Communication of Information |
|
|
136 | (3) |
|
8.3.12 Emergency Operations Center |
|
|
139 | (1) |
|
8.3.13 Alternative Locations and Space Allocations |
|
|
139 | (1) |
|
8.3.14 Recovery Priorities or RTOs |
|
|
140 | (1) |
|
8.3.15 Internal and External Dependencies |
|
|
140 | (1) |
|
8.3.16 Documentation of Expense and Activities |
|
|
140 | (2) |
|
8.3.17 Additional Information |
|
|
142 | (1) |
|
|
142 | (1) |
|
8.3.19 Orientation and Training |
|
|
142 | (1) |
|
8.3.20 Exercising and Testing |
|
|
143 | (1) |
|
|
143 | (1) |
|
|
143 | (1) |
|
|
143 | (1) |
|
|
144 | (13) |
|
8.4.1 Team Member Call List |
|
|
145 | (1) |
|
8.4.2 Team Task Instructions |
|
|
146 | (2) |
|
8.4.3 Internal/External Contact List |
|
|
148 | (1) |
|
|
149 | (1) |
|
8.4.5 Other Pertinent Information/Appendix |
|
|
149 | (1) |
|
8.4.6 Management or Crisis Management Team |
|
|
149 | (2) |
|
8.4.7 Emergency Operations Center |
|
|
151 | (6) |
|
8.5 Putting the Plan Together |
|
|
157 | (1) |
|
|
158 | (3) |
Chapter 9 Orientation, Exercising, And Testing |
|
161 | (28) |
|
|
162 | (1) |
|
|
163 | (5) |
|
|
168 | (1) |
|
|
169 | (1) |
|
|
170 | (2) |
|
|
172 | (14) |
|
|
172 | (1) |
|
|
172 | (1) |
|
|
173 | (1) |
|
9.6.4 Exercise Objectives |
|
|
174 | (1) |
|
9.6.5 Scenario Development |
|
|
175 | (1) |
|
9.6.6 Timeline and Master Scenario Event List |
|
|
176 | (1) |
|
|
177 | (2) |
|
|
179 | (2) |
|
|
181 | (2) |
|
9.6.10 After-Action Meetings and Report |
|
|
183 | (3) |
|
|
186 | (1) |
|
|
187 | (2) |
Chapter 10 Continuous Improvement |
|
189 | (34) |
|
|
190 | (1) |
|
|
190 | (7) |
|
|
192 | (5) |
|
10.3 Performance Evaluation and Metrics |
|
|
197 | (5) |
|
10.3.1 Balanced Scorecard |
|
|
198 | (1) |
|
|
199 | (1) |
|
|
199 | (1) |
|
|
199 | (1) |
|
|
199 | (1) |
|
10.3.6 Cascading Functions |
|
|
200 | (1) |
|
|
200 | (2) |
|
10.4 Evaluations and Internal Audit |
|
|
202 | (4) |
|
|
205 | (1) |
|
|
206 | (1) |
|
10.6 Nonconformity and Corrective Action |
|
|
207 | (11) |
|
10.6.1 Root Cause Analysis |
|
|
208 | (3) |
|
10.6.2 Extent of Condition |
|
|
211 | (1) |
|
10.6.3 Five Whys Analysis |
|
|
211 | (2) |
|
10.6.4 Corrective Action Plan |
|
|
213 | (1) |
|
10.6.5 Corrective Action Database Management |
|
|
213 | (3) |
|
10.6.6 Responsibility Assignment Matrix |
|
|
216 | (2) |
|
10.6.7 Effectiveness Review |
|
|
218 | (1) |
|
|
218 | (3) |
|
|
221 | (2) |
Appendix A Sample Competencies Suggested for Business Continuity Manager |
|
223 | (2) |
Appendix B Required Documents under ISO 22301 |
|
225 | (2) |
Appendix C Emergency Plan Table of Contents |
|
227 | (4) |
Appendix D Sample Business Impact Analysis Questions |
|
231 | (26) |
Appendix E Sample Continuity Team Resource Tool Kit |
|
257 | (8) |
Appendix F Websites That Contain Hazard Information |
|
265 | (2) |
Appendix G Examples of Natural, Technological, and Man-made Hazards |
|
267 | (4) |
Appendix H Excerpt from Risk Assessment Report—Hazards |
|
271 | (4) |
Appendix I Full Scale Exercise Example |
|
275 | (18) |
Index |
|
293 | |