Example Business continuity plan

advertisement
October 7, 2012 EXAMPLE BUSINESS CONTINUITY PLAN
Business
Process
Loss or
theft of
internal
electronic
data
Failure to
respond to
accreditati
on
deficiencie
s
Loss of
teaching
laboratori
es
Likelihood
Loss of
research
samples
Consequence
Rare
Catastrophic
Inherent
Risk Rating
High 14
Business Process
Responsibility
Dean, Faculty of “Example”
1
Rare
Catastrophic
High 14
Dean, Faculty of “Example”
N/A
N/A
N/A
N/A
On-going
Rare
Catastrophic
High 14
Dean, Faculty of “Example”
1
2 laboratories
(80 and 50
seats)
80
Microscopes
N/A
See body of
document
During semesters
Rare
Catastrophic
High 14
Dean, Faculty of “Example”
N/A
-80oC freezers
Cool Room
Liquid
nitrogen
storage
N/A
See body of
document
On-going
Staff
Minimum #
Infrastructure
File Storage
Software
Applications
SuperSecure
Recovery Location
“Example” Backup
and Recovery
Processing Periods
Critical
All year round
University of Tasmania | 1
October 7, 2012 EXAMPLE BUSINESS CONTINUITY PLAN
Staff Member (Title)
Dean, Faculty of “Example”
Manager, Information Systems
Associate Dean (Learning & Teaching)
Head of School, School of Fun
Technical Manager
Head of School, School of Excitement
Supplier Name (if
applicable)
N/A
Supplier Contact
Contact Details
03) 6226 1111
Sally.Citizen@utas.edu.au
(03) 6226 4444 | 0400 1122 3344
John.Citizen@utas.edu.au
03) 6226 9999
Jane.Citizen@utas.edu.au
03) 6324 5555 | 0455 1122 3344
Jeff.Citizen@utas.edu.au
03) 6324 7777 | 0499 1122 3344
Simon.Citizen@utas.edu.au
03) 6430 5555
Justine.Citizen@utas.edu.au
Alternate Contact (Name and Title)
Ms Susan Person
General Manager, Faculty of “Example”
Mr Ben Person
Assistance Manager, Information Systems
Professor Sally Citizen
Dean, Faculty of “Example”
Mr Peter Person
Deputy Head of School, School of Fun
Mrs Sandra Person
Laboratory Technician (Newnham,
Inveresk)
Mr Fred Person
Laboratory Technician (Cradle Coast)
Dr Polly Person
Deputy Head of School, School of
Excitement
Phone
Contact Details
(03) 6226 3333
Susan.Person@utas.edu.au
(03) 6226 2222
Ben.Person@utas.edu.au
03) 6226 1111
Sally.Citizen@utas.edu.au
(03) 6324 6666
Peter.Person@utas.edu.au
(03) 6324 8888
Sandra.Person@utas.edu.au
(03) 6430 8888
Fred.Person@utas.edu.au
(03) 6430 6666
Polly.Person@utas.edu.au
Email
University of Tasmania | 2
October 7, 2012 EXAMPLE BUSINESS CONTINUITY PLAN
Risk: Loss or theft of internal
electronic data
Maximum Allowable Outage: 4 weeks
Business Site: Sandy Bay
Short-term Risk/Normal Processing Periods
Inherent
Likelihood Consequence
Response Strategy – Actions and Activities
Risk Rating
Category: Teaching/Research/Systems
Crisis Event Responsibility
Communication Plan
1.
2.
Back-up
1. Data backed-up daily to tape.
Unlikely
Moderate
Moderate
9
1.
2.
3.
4.
5.
6.
Long-term Risk/Critical Processing Periods
Inherent
Likelihood Consequence
Risk Rating
Rare
Catastrophic
High 14
Determine loss or cause of data loss
Immediately instigate service agreement with ITR to
divert all helpdesk calls to ITR helpdesk.
If theft, consult ICT security and police
Limit Access to data on a needs identified basis
Audit of access rights
Recover data from best possible source
Response Strategy – Actions and Activities
1.
As above
Dean, Faculty of
“Example”
Manager, Information
Systems
3.
4.
5.
6.
7.
Crisis Event Responsibility
Dean, Faculty of
“Example”
Manager, Information
Systems
Head of “Example”
Notify ICT Security
officer
Notify all staff
Notify all students
Liaise with
Governance &
Legal Office
regarding
breaches of
legislation
SMT
External
stakeholders, as
required
Communication Plan
1.
2.
As above
Accreditation body
Supporting Documentation
University Security
Framework
Facilities Use Agreement
Supporting Documentation
As Above
University of Tasmania | 3
October 7, 2012 EXAMPLE BUSINESS CONTINUITY PLAN
Risk: Failure to respond to
accreditation deficiencies
Maximum Allowable Outage: 13 weeks
Business Site: All campuses
Short-term Risk/Normal Processing Periods
Inherent
Likelihood Consequence
Response Strategy – Actions and Activities
Risk Rating
1. Coordinate with accreditation body to achieve course
accreditation.
Moderate
Rare
Major
2. Implement recommendations
10
3. Advocate to University for support in implementing
recommendations
Long-term Risk/Critical Processing Periods
Inherent
Likelihood Consequence
Response Strategy – Actions and Activities
Risk Rating
Rare
Catastrophic
High 14
1.
2.
As above
Transfer students to other Universities
Category: Teaching/Systems
Crisis Event Responsibility
Dean, Faculty of
“Example”
Associate Dean (Learning
& Teaching)
Crisis Event Responsibility
Dean, Faculty of
“Example”
Associate Dean (Learning
& Teaching)
Communication Plan
1.
Supporting Documentation
Notify DVC
(Students &
Education)
Notify Provost
Notify SMT
Link to accreditation body
guidlines
Communication Plan
Supporting Documentation
2.
3.
1.
As above
As above
University of Tasmania | 4
October 7, 2012 EXAMPLE BUSINESS CONTINUITY PLAN
Risk: Loss of teaching laboratories
Maximum Allowable Outage: 13 weeks
Business Site: Newnham, Inveresk
Short-term Risk/Normal Processing Periods
Inherent
Likelihood Consequence
Response Strategy – Actions and Activities
Risk Rating
Key Equipment/Infrastructure:
2 laboratories (80 and 50 seats) – large open space with
wet facilities
140 Microscopes (minimum required 80 to meet ongoing
teaching requirements).
Rare
Moderate
Moderate
6
1.
2.
3.
Long-term Risk/Critical Processing Periods
Inherent
Likelihood Consequence
Risk Rating
Rare
Catastrophic
High 14
Determine outage
Notify students and staff of alternative plans:
a. Relocate to other teaching laboratories
within Science building
b. Where possible, alter practical classes to run
in the field
c. Relocate to research laboratories –
negotiate with researchers
Liaise with staff and external stakeholders for
rescheduling of tutorials and meetings.
Response Strategy – Actions and Activities
1.
2.
3.
As above
Rebuild facility
Purchase specialised equipment (minimum 12 weeks
replacement)
Category: Teaching/Infrastructure
Crisis Event Responsibility
Communication Plan
1.
2.
Dean, Faculty of
“Example”
Head of School, School of
Fun
Technical Manager
3.
4.
5.
Crisis Event Responsibility
Dean, Faculty of
“Example”
Head of School, School of
Fun
Technical Manager
Notify students
Staff (including
researchers where
required)
Notify external
stakeholders –
PASS, timetabling
School executive
Faculty executive
Communication Plan
1.
As above
Supporting Documentation
N/A
Supporting Documentation
N/A
University of Tasmania | 5
October 7, 2012 EXAMPLE BUSINESS CONTINUITY PLAN
Risk: Loss of samples
Maximum Allowable Outage:
-80oC freezers – 12 hours
Cool Room – 24 hours
Liquid nitrogen storage – 2 hours
Business Site: Cradle Coast
Short-term Risk/Normal Processing Periods
Inherent
Likelihood Consequence
Response Strategy – Actions and Activities
Risk Rating
-80oC freezers
1. Determine outage
2. Sign all freezers to not open under any
circumstances.
3. Move samples when nearing 12 hours of outage to
other -80oC freezers
4. Determine relocation:
a. Storage within Cradle Coast campus
b. Off-site storage options – SuperCool facility
Unlikely
Moderate
Moderate
9
Cool Room
1. Determine outage
2. Sign all freezers to not open under any
circumstances.
3. Move samples when nearing 24 hours of outage to
hired refrigerated container.
Liquid nitrogen storage
1. Determine outage
2. Relocate samples within 2 hours to alternate storage
on Cradle Coast campus.
Category: Research/Infrastructure
Crisis Event Responsibility
Communication Plan
1.
Dean, Faculty of
“Example”
Head of School
Technical Manager
2.
3.
4.
5.
6.
Notify all staff and
students to not
open cold/freezer
storage, through
signage, word of
mouth.
Property Services
School executive
Faculty executive
Institutional
research ethics
committees,
where applicable
Research office
Supporting Documentation
Link to sample register
University of Tasmania | 6
October 7, 2012 EXAMPLE BUSINESS CONTINUITY PLAN
Long-term Risk/Critical Processing Periods
Inherent
Likelihood Consequence
Risk Rating
Response Strategy – Actions and Activities
1.
2.
3.
Rare
Catastrophic
As above
Evaluate loss
Where no replicate samples exist determine whether
to replicate research or abandon project.
High 14
o
-80 C freezers – replacement minimum 2 months
Cool Room – replacement minimum 3 months
Liquid nitrogen storage – replacement minimum 3 months
Crisis Event Responsibility
Dean, Faculty of
“Example”
Head of School
Technical Manager
Communication Plan
1.
2.
As above
External
stakeholders,
where applicable
Supporting Documentation
As above
University of Tasmania | 7
Download