Example: stock market

Continuity Planning Business BCP

Federal Financial Institutions Examination CouncilFFIECIT EXAMINATIONHANDBOOKBCPB usinessContinuity PlanningFEBRUARY 2015 Table of ContentsTable of ContentsTable of ContentsTable of ContentsIntroductionIntroductionIntroduc tionIntroduction1 Board and Senior Management ResponsibilitiesBoard and Senior Management ResponsibilitiesBoard and Senior Management ResponsibilitiesBoard and Senior Management Responsibilities2 Business Continuity Planning ProcessBusiness Continuity Planning ProcessBusiness Continuity Planning ProcessBusiness Continuity Planning Process3 Business Impact AnalysisBusiness Impact AnalysisBusiness Impact AnalysisBusiness Impact Analysis5 Risk AssessmentRisk AssessmentRisk AssessmentRisk Assessment8 Risk ManagementRisk ManagementRisk ManagementRisk Management9 Business Continuity Plan Development9 Assumptions11 Internal

Business continuity planning represents a cyclical, process-oriented approach that includes a business impact analysis (BIA), a risk assessment, risk management, and risk monitoring and testing. The business continuity planning process involves the recovery, resumption, and maintenance of the entire business, not just the technology component.

Tags:

  Business, Planning, Continuity, Business continuity planning, Continuity planning business

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Continuity Planning Business BCP

1 Federal Financial Institutions Examination CouncilFFIECIT EXAMINATIONHANDBOOKBCPB usinessContinuity PlanningFEBRUARY 2015 Table of ContentsTable of ContentsTable of ContentsTable of ContentsIntroductionIntroductionIntroduc tionIntroduction1 Board and Senior Management ResponsibilitiesBoard and Senior Management ResponsibilitiesBoard and Senior Management ResponsibilitiesBoard and Senior Management Responsibilities2 Business Continuity Planning ProcessBusiness Continuity Planning ProcessBusiness Continuity Planning ProcessBusiness Continuity Planning Process3 Business Impact AnalysisBusiness Impact AnalysisBusiness Impact AnalysisBusiness Impact Analysis5 Risk AssessmentRisk AssessmentRisk AssessmentRisk Assessment8 Risk ManagementRisk ManagementRisk ManagementRisk Management9 Business Continuity Plan Development9 Assumptions11 Internal and External Components11 Mitigation Strategies12 Risk Monitoring and TestingRisk Monitoring and TestingRisk Monitoring and TestingRisk Monitoring and Testing12 Principles of the Business Continuity Testing Program13 Roles and Responsibilities14 Testing Policy15 Execution.

2 Evaluation, Independent Assessment, and Reporting of Test Results20 Updating Business Continuity Plan and Test Program22 Other Policies, Standards and ProcessesOther Policies, Standards and ProcessesOther Policies, Standards and ProcessesOther Policies, Standards and Processes22 Security Standards23 Project Management23 Change Control Policies24 Data Synchronization Procedures24 Crisis Management24 Incident Response25 Remote Access25 Employee Training26 Notification Standards26 Insurance26 Business Continuity Planning BookletGovernment and Community27 SummarySummarySummarySummary27 Appendix A: Examination ProceduresAppendix A: Examination ProceduresAppendix A: Examination ProceduresAppendix A: Examination ProceduresA-1 Appendix B: GlossaryAppendix B: GlossaryAppendix B: GlossaryAppendix B.

3 GlossaryB-1 Appendix C: Internal And External ThreatsAppendix C: Internal And External ThreatsAppendix C: Internal And External ThreatsAppendix C: Internal And External ThreatsC-1 Appendix D: Pandemic PlanningAppendix D: Pandemic PlanningAppendix D: Pandemic PlanningAppendix D: Pandemic PlanningD-1 Appendix E: InterdependenciesAppendix E: InterdependenciesAppendix E: InterdependenciesAppendix E: InterdependenciesE-1 Appendix F: Business Impact Analysis ProcessAppendix F: Business Impact Analysis ProcessAppendix F: Business Impact Analysis ProcessAppendix F: Business Impact Analysis ProcessF-1 Appendix G: Business Continuity Plan ComponentsAppendix G: Business Continuity Plan ComponentsAppendix G: Business Continuity Plan ComponentsAppendix G: Business Continuity Plan ComponentsG-1 Appendix H: Testing Program - Governance and AttributesAppendix H: Testing Program - Governance and AttributesAppendix H: Testing Program - Governance and AttributesAppendix H: Testing Program - Governance and AttributesH-1 Appendix I: Laws, Regulations, and GuidanceAppendix I: Laws, Regulations, and GuidanceAppendix I.

4 Laws, Regulations, and GuidanceAppendix I: Laws, Regulations, and GuidanceI-1 Appendix J: Strengthening the Resilience of Outsourced Technology ServicesAppendix J: Strengthening the Resilience of Outsourced Technology ServicesAppendix J: Strengthening the Resilience of Outsourced Technology ServicesAppendix J: Strengthening the Resilience of Outsourced Technology ServicesJ-1 Business Continuity Planning BookletIntroductionIntroductionIntroduct ionIntroductionThis booklet is one in a series of booklets that comprise the Federal Financial InstitutionsExamination Council (FFIEC) Information Technology (IT) Examination Handbook.

5 Thisbooklet provides guidance to assist examiners in evaluating financial institution [1] andservice provider risk management processes to ensure the availability of critical financialservices. This booklet was also designed to provide helpful guidance to financialinstitutions regarding the implementation of their Business Continuity Planning booklet rescinds and replaces the previous " Business Continuity Planning Booklet,"which was issued in March 2003, and has been revised to reflect technological andregulatory changes with a focus on management's responsibilities regarding oversight ofthe Continuity Planning process for Business operations.

6 While significant revisions havebeen made, the focus of this booklet continues to be based on an enterprise-wide,process-oriented approach that considers technology, Business operations, testing, andcommunication strategies that are critical to Business Continuity Planning for the entirebusiness, instead of just the information technology booklet is divided into two parts. The first part, or narrative, describes the businesscontinuity Planning process and addresses the responsibilities of the board of directors(board) and senior management.

7 The second part includes examination procedures, aglossary, detailed appendices supporting the narrative, and a reference list of eachagency's applicable laws, regulations, and guidance. Each section in the narrativebegins with an "Action Summary" that highlights the major points in that section. Whilenot a substitute for reading the entire booklet, the action summaries may be used toquickly assess the most important issues discussed in that section. It is also important toread the detailed appendices, which can serve as a comprehensive reference guide forthe topics discussed in the overall goal of this booklet is to provide guidance to the financial services industryabout the importance of Business Continuity Planning , which establishes the basis forfinancial institutions to recover and resume Business processes when operations havebeen disrupted unexpectedly.

8 Because financial institutions play a crucial role in theoverall economy, disruptions in service should be minimized in order to maintain publictrust and confidence in the financial system. As such, financial institution managementshould incorporate Business Continuity considerations into the overall design of theirbusiness model to proactively mitigate the risk of service institution management should develop a comprehensive Business continuityplan (BCP) as part of the Business Continuity Planning process.

9 The BCP should bebased on the size and complexity of the institution and should be consistent with thefinancial institution's overall Business strategy. The goal of the BCP should be tominimize financial losses to the institution, serve customers and financial markets withminimal disruptions, and mitigate the negative effects of disruptions on businessoperations. Reviewing a financial institution's Business Continuity Planning process,which includes an assessment of the BCP, is an established part of examinationsperformed by the FFIEC member agencies.

10 [2]Changes in Business processes and technology increased terrorism concerns, recentcatastrophic natural disasters, and the threat of a pandemic have focused even greaterattention on the need for effective Business Continuity Planning . Consequently, theseissues should be given greater consideration in the Business Continuity planningBusiness Continuity Planning BookletPage 1process. Financial institution management should consider the potential for area-widedisasters that could affect an entire region and result in significant losses to theinstitution.


Related search queries