Sie sind auf Seite 1von 65

Introduction to

Risk Assessment and


Business Impact Analysis
A series of Business Continuity
Management System BCM25999

Global Partner for Business Success

Presented by :
Introduction to Risk Assessment and Business Impact Analysis CD1

Introducing

Please interview your neighbour for 5 minutes


Find out
Who he/she is
What dept
What he/she hopes to get out of the Course
What he/she understands about business continuity
Anything else of interest - Sports, Hobbies, Family,
(claim to fame), etc.
Be ready to briefly introduce them to the rest of the Course

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Timetable : Day 1
Time Session
09:00 09:15 Section 0 : Introduction & Timetable
09:15 10:15 Section 1 : Introduction to Business Continuity Management
System
10:15 10:30 Tea & Coffee Break
10.30 12:30 Section 2 : Business Impact Analysis

12:30 13:30 Lunch Break


13:30 15:30 Section 3 : Continuity Recovery Requirement Analysis
15:30 15:45 Tea & Coffee Break
15:45 17:00 Section 4 : Risk Assessment

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Timetable : Day 2
Time Session
09:00 10:15 Section 4 : Risk Assesment
10:15 10:30 Tea & Coffee Break
10:30 12:30 Section 4 : Risk Assement exercise

12:30 13:30 Lunch Break


13:30 15:30 Section 5 : BIA and Risk Assessment Management
Section 5 : Company BIA and RARC exercise
15:30 15:45 Tea & Coffee Break
15:45 16:45 Section 5 :Company BIA and RARC exercise
16:45 17:00 Course Summary & Close for the day

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Course objectives

Understand the purpose of business impact analysis and


risk assessment
Understand the methodology of Business Impact Analysis
and Risk Assessment
Manage and measures the risk

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Introduction to
1 Business Continuity
Management System

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

What is BCM ?

holistic management process that identifies potential


threats to an organization and the impacts to business
operations that those threats, if realized, might cause, and
which provides a framework for building organizational
resilience with the capability for an effective response that
safeguards the interests of its key stakeholders, reputation,
brand and value-creating activities
Clause 2.4

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

What is BCM ?

Business continuity management involves managing the


recovery or continuation of business activities in the event
of a business disruption, and management of the overall
programme through training, exercises and reviews, to
ensure the business continuity plan(s) stays current and
up-to-date.

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Standards for Business Continuity Management

BS 25999-1:2006 Part 1: Code of Practice


BS 25999-2:2007 Part 2: Specification
NFPA 1600:2007
MS 1970:2007
SS 540:2008
ANZ 5050
HB 221:2004 Australia
HB 292:2006
HB 293:2006

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

BCM Lifecycle

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

PDCA cycle applied to BCMS processes

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

BCM Documentation Requirement

BCM Policy including scope and principles


Business Impact Analysis
Risk and Threat assessment
BCM Strategies including papers supporting the choice of the strategies adopted
Response plans
Incident Management Plans
Business Continuity Plans
Departmental Business Resumption Plans
Exercise Schedule and reports
Awareness and training programme
Service level agreements with customers and suppliers
Contracts for third party recovery services such as workspace and salvage

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Exercise 1.1

Working in a group, discuss the


difference:
Emergency Response vs Disaster
Recovery vs. Business continuity

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Business Impact
2 Analsyis

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

BS 25999-1 Business Impact Analysis and Risk


Assessment

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Comparison between Business Impact Analysis


and Risk Assessment

The Business Continuity Institute 2007

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Business Impact Analysis (BIA) (Cl. 4.1.1)

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Criticallity

Level of criticallity of process-product-services


Impact Classification
Time

8 hr Vital
24 hr Critical
3 day Essential
5 day Important
10 day Non Critical
30 day Deferrable

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Impact vs Time

The service level versus time when the incident occurs

Incident

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

MTPoD vs RTO
Invocation Lead Time
Investigatio
Incidient n process Decision Recovery Process
Normal Catch up Normal
reporting (Damage making (RTO)
process assessment process
)
Disruption
Maximum Tolerable Period of Disruption (MTPoD)

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Case Study 2.1

Understanding Impact over the


time

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Exercise 2.2

Impact over the time


Recovery Time Objectives
MTPD

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Data collection Questionaries


Basic Information
Timeframe for resuming operation
Location
Peak and valley period
Impact
Organization resistance
Factors to consider
Volume of jobs
Contractual, legal
Key Tools
Peoples , skills set
Equipment, IT , Telco,
Data
Dependencies internal external

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Case study 2.3

Sample of Interview check list


Sample of BIA report

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Continuity Recovery
3 Requirement
Analysis

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Continuity Recovery Requirement Analysis

Collect information on the numbers of the resources required


to resume and continue the business activities at a level
required to satisfy the organization obligations

This is the phase on MTPD, while the service level is not on


the normal stages but still acceptable by the organization

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Continuity Recovery Requirement Analysis

to estimate the resources and facilities and


services that each activity will require at resumption

Invocation Lead Time


Investigatio
Incidient n process Decision Recovery Process
Normal Catch up Normal
reporting (Damage making (RTO)
process assessment process
)
Disruption
Maximum Tolerable Period of Disruption (MTPoD)

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Purpose of Continuity Requirement

Provide the resources information from which an


appropriate recovery strategy can be
determine/recommended
Identify resources requirement resulting from activity
dependencies that exist both internally and externally

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Necessary Resources

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Factors that affecting the Recovery


Requirement

Quantity of the resources required over the time to


maintain the business function at an acceptance level and
within the max torelable period of disruption
Extra activities might occurs out of normal period

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Exercise 3.1

Continuity Recovery Requirement


Analysis

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

4 Risk Assessment

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Risk assessment (Cl. 4.1.2, 4.1.3)

Establishing the context

Risk assessment

Risk identification
Communication Monitor
and and
Consultation Risk analysis Review

Risk evaluation

Risk treatment

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Risk assessment

Risk identification
all significant threats potentially affecting the critical
activities are identified
understand the vulnerabilities of critical activities and
supporting resources
the risks are owned

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Are critical asset something that is something to


you?

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Poor Threat Assessment ?

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

T T

T R RR
Ctrl
T

V V

Asset

T V V
Ctrl Ctrl
RR RR T

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Vulnerability Profiling (T and V pairings)

Vulnerabilities Threats Assets

Lack of communication between Malicious destruction of Physical


HR and IT group in respect of data & facilities Software
terminated employees leading to Information
terminated employees still having
access to system.

Lack of identification and Masquerade Data


authentication mechanisms

Lack of physical security over Eavesdropping Data


data communications closets or hubs

Lack of policy restricting the Social Engineering Software


provision of information by staff Data
over the phone

No business continuity plan Earthquake, fire,


flood, Information storm, vermin,
power Software People fluctuations,
etc. Global Partner for Business Success
Introduction to Risk Assessment and Business Impact Analysis CD1

Exercise 4.1

Identify Asset Process


Identify Threat And Vulnerability

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Likelihood

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Case study 4.2

Evaluation of Threat, Vulnerability,


and Likelihood

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Risk assessment

Risk analysis
with varying degrees of detail depending upon the risk,
the purpose of the analysis, and the information, data
and resources available
qualitative or quantitative, or a combination of these.
an iterative process, being repeated as more data
become available.
reviewed and revised risk could be split or aggregated

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Poor Risk Management ?

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Risk assessment

Risk evaluation
categorized and prioritized
compare levels of risk with the risk appetite
Risk Control
Manage and reducing the Risk by controlling the threat
and vulnerability
Substitute object which harmless
Eliminate risk
Engineering control Security System, Back up, Gen Set
Procedural control

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Risk treatment
Avoid risk
Cannot influence and/or manage
Too costly
Seek risk
Desirable potential consequence
Pursue an opportunity
Modify risk
Optimize potential opportunities
Minimize threats
Changing likelihood and consequences
Transfer risk
Risk sharing insurance, partnership
Outsource
Retain risk
Acceptable residual risk
Exceed threshold but too costly

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Exercise 4.3

Risk Analysis and Risk Control

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Exercise 4.4

Risk Analysis and Risk Control 2

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Manage the BIA and


5 Risk Assesment

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Manage BIA and Risk Assesment

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Exercise 5.1

Business Risk Analysis and


Business Impact Analysis

Global Partner for Business Success


Introduction to Risk Assessment and Business Impact Analysis CD1

Q&A

Global Partner for Business Success

Das könnte Ihnen auch gefallen