Showing posts with label business continuity. Show all posts
Showing posts with label business continuity. Show all posts

Tuesday, 24 May 2016

IX Business Continuity International Conference

by Jorge García Carnicero


As every year, BSI has been the promotor of the Business Continiuty International Conference, in its IX edition. The place that has been chosen this year was the Gran Melia Fénix Hotel, in Madrid, where the conference took place at first hour of the morning. In a room almost full, with 50 or 60 people, BSI shows that their ability for calling business continuity professional is healthy.

The first speech was driven by Jose Luis Miguel, Country Manager at BSI, that was exposing the BSI capabilities in both generating standards and auditing and in training. Then, he presented the results of the Horizon Scan Report 2016, led by the BCI and promoted by BSI, highlighting aspects such as the top ten threats of continuity, which can be seen in the image or the percentage of companies seeking to increase its budget business continuity for the coming months / years .


The second speech was done by Julio San Jose, from EY, in tandem with Cristina Pereira, continuity responsable at Abanca. Julio emphasize about the key aspects related with continuity:

  • Need of deploying tests and drills.
  • The importance of crisis communication.

He comment aspects as the different estrategias of communications that existe (in a good or a bad way): Silence, Negation, Responsability transference, Confession and controlled discretion, been Confession the best communication strategy.
(I would call it Transparency)

Cristina Pereira exposed the case of Abanca, commenting the different problems with which she has been to deal with when deploying the Business Continuity Plan in the organization. In the same direction than Julio’s speech, she also emphasized the importance of drills.

Before the break, took place the third speech carried out by Agustin Lopez, as representative of DRI in Spain. Agustin exposed the different contingency scenarios in the datacenter with an original presentation, using classical films as a thread (back to the future, Groundhog Day, etc)

When the Confee Break and Networking moment finish, we come back to the room, in which GMV was responsible for the fourth speech in the morning. It was based on the business continuity management system (ISO 22301) and the possibility of integration with other management systems standards, like security (27000), IT Management (20000), quality (9000), etc, with an orientation to certification.

The fifth speech was performed by Uxía Fernandez, from Grupo Ozona. Uxia expose the concept of IRBC (ICT Readiness for Business Continuity) that is used in the standard 27031. Uxia expose the content of the standard with the 5 mainstays as a elements to protect: Facilities, technology, people, data, providers and process. Since usually only technology and data was taken into account, Uxia would like to make special consideration about the other elements. It was a long speech.

Finally, the sixth speech was done by Ricardo Mesias, Risk Management Director at EDP. Ricardo made a speech showing the main problems that he had to deal with in developing the business continuity plan in EDP. He talk about the team, about achieve the complicity of all departments of the company, about the importance of test, about the metrics and about the external support, which is always important.

Conclusion

As a conclusion, I think that the role of BSI maintaining this event year after year is laudable and all the business continuity professional should be thankful about that. This event is a meeting point and is also a way to measure the state of the art of business continuity in spain.

However,  I think that messages has to be improve, since many of them are not showing the actual situation of customers. Recently I was reading an article of Amy DeMartine, senior analyst research in Forrester research for Devops, for Computer World that I think is applicable in Business Continuity. She said: “I think the reason why a lot of companies start with DevOps activities and forget the security staff is that there is a cultural gap. Security people speak a language almost different - incidents, vulnerabilities, risks - , so everybody put them at the end of the development life cycle”. This could be applicant also to business Continuity, that should be included in all the processes of the company but, however, it’s not, at least in Spain. If we focus on the management system and we forget that continuity should be practical it will drive us to see Business Continuity as a waste instead of an investment.  

Recently has took place the Business Continuity Awareness Week, led by the BCI, with a main objective: to show the ROI of the continuity and I think we should learn about int.
Although obviously, BIS as a promotor of the event has to focus speech on management systems, is urgent and essential to update the messages to a market reality different, mainly in the IT area.  It makes no sense to talk about take a tape out of the datacenter when all companies are talking about backup in the cloud, making a third copy in a public cloud, for example.

Monday, 24 February 2014

Auditing Providers, Intrusion or need?

By Moises Lopez Soto

During the last years, there has been a diversification in the way the services are being delivered, increasing the number of providers that conform the supply chain and, therefore, the complexity in the control of all components to provide success in the final result. Trends as Outsourcing some time ago and recently Cloud are clear examples.


We find ourself everyday facing the challenge of ensuring business continuity of our organization with a high number of external agents and, in some cases, this external agent could be absolutely essential to the future of our company. That's why we must take action and act proactively to strengthen the links in the whole chain, minimizing risks and cushioning the impact that could suppose to our business the break of a weak link. This is a complex task when we have to control process and resources internally so it's easy to assume that it would be much more complicated with external agents which have full freedom to be independent in their process and way to deliver their services.

SLA is not enough

Establishing Service Level Agreements are completely valid and necessary on areas of service such as capability and availability but when we are talking about continuity it become insufficient. Among other things, this is because we are not referring to both the supplier's ability to give service but to their ability to keep delivering it after suffer a contingency.

The most common solution is diversification is relying on a model of "duplicity" in a provider-service base, with a relation of N to 1 and with a minimum of two, just as if it were a load balancing in a data network. In some cases this is the usual way to deliver the service,  in other scenarios suppose an increase in the resources required for service management with a greater workload for staff but, nevertheless, is NOT a valid solution for all services. For example, it is usually to stablish this kind of countermeasures when we are talking about business critical services like providers of essential services (electricity , water, etc. . ), when the solution is too complex or too expensive, when there is a monopoly or when there is a single infrastructure common to different suppliers, etc. Any way, it seems absolutely clear that a relationship model in which provider and the company has to be strength enough to carry out all contingency scenarios just as if they were the same company.

Audit process, an interesting weapon

It could be close the day in which the ISO 22301 (or similar) would be required to provide some kind of services, just like there is required the ISO 28000, the ISO 9000 or, even, the ISO 20000, but until that day arrives, audit processes becomes an interesting weapon. On the one hand it would bring a very significantly strengthen in the customer-provider relationship and on the other it will help to raise awareness, work and improving business continuity in both companies.
It is true that providers can refuse, just as we can see in the event that was supported by SIA last year, but it must be the customers which would has to assign some weight to the Business Continuity countermeasures that could be included by their provider in the proposals of service delivery.

Providers should consider the audit processes just like turning point in their business continuity activities, or if they have not done anything before a staring point, to provide resilience to their own business, having the opportunity to strengthen and enhance the relationship with their customers and, at the same time, get a business-marketing revenue on their actions in this field. On the other side, customers should approach them in a constructively way, focusing on growth and providing support and advice to the audited provider. Definitively, a Win-Win relation.

Now a days, audit processes are called to be the main element in order to ensure the strength of business continuity management system and so, the resilience of the company, so it seem to be more a need than an intrusion....

Monday, 21 October 2013

Spanish Critial Infrastructure Protection Law and Business Continuity

By Daniel Blanco Real


The Spanish Law 8/2011 or Ley  de Protección de Infraestructuras Críticas (LPIC) its related to grant essential services that support specific infrastructures considered critical mainly because of two properties:
  1. because its required and there are not other alternative solutions that could replace it and/or
  2. because a disruption or destruction should have very important impacts in essential services
But What is considered a essential service in the law? LPIC identify essential service as those services required to maintain social basic functions (health, security, social welfare and economics, Public administration, etc), although there is difficult to identify it based on the definition above.

Looking for activities and definitions carried out by other countries, we can take a look to the information published by Swedish Civil Contingencies Agency, (MSB in Swedish), that in 2007 established a set of criteria to identify Social critical functions, very close to what is described in LPIC as essential services.

Sector
Functions
Energy supply
Production and distribution of electricity, district heating, fossil fuels and vehicle fuels.
 
Information and communication
 
Telephone services, Internet, radio and TV broadcasts, postal services, production and distribution of newspapers, radio and TV.
 
Financial services
Money transmission, cash access, private insurance and securities trading.
 
Social insurances
Payment of sickness and unemployment benefits and the national pension system.
 
Public health and medical services, and special social
services
 
Emergency hospitals, primary care, psychiatry, pharmaceutical supplies, infectious disease control, and special social services for children, disabled persons and the elderly.
 
Protection, security and safety
 
Rescue services, police, courts, correctional institutions and SOS Alarm, military, coast guard, and customs, border and immigration control.
 
Transport
Road, rail, sea and air transport, and transport infrastructure management.
 
Municipal services
Drinking water, sewage treatment, streetcleaning, public meeting places, refuse collection and roads.
 
Food Agriculture and the production, distribution and control of food.º
 
Trade and industry Retail, IT operations and service, construction and contract work, guard and security services and the manufacturing industry.
 
Public administration
governance
support functions
service sector
 
 
National management, regional management and local management, diplomatic and consular services, inspection and permit services, expert and analytical services, detection and laboratory services, collection and provision of population data, meteorological services, training services and burial services.

It can be seen in the original document.

In order to clarify what is considered as a essential service, the document offers some questions that have to be answered for those who think that can be critical operators, grouped by two different blocks: preventive measures and respond measures

From a preventive measures perspective:
  • What is the potential scope of a shutdown?
  • How many people would be affected?
  • What levels of society would be affected by a shutdown?
  • To what degree would people’s lives and health be affected?
  • What financial, environmental, societal and cultural values could be lost?
  • How would public trust be affected?
  • How long would it take to repair the damage?
 From a response measures perspective:
  • Is the function essential for Leading and coordinating society’s response?
  • Is the function essential for Providing the public with enough information about the situation?
  • Is the function essential for Responding operatively to the emergency?
  • Is the function essential for Minimising the consequences?
  • Is the function essential for Restoring functions?
Once essential services are clearly defined, all organizations (obviously critical operator, but also if not)  must focus on:
  • How products and services that are delivering can affect to those essential services (This is clear in critical operators)
  • How lack of this essential services could affect to products and services delivered.
As a conclusion, Business Continuity in an organization has not only focus in how to recover products and service delivery, but also to take into account how the lack of this products and services affect to the society and the essential services. Without support of those essential services it's probably that organizations will not be able to recover their business and this is something that a lot of organizations don't take into account in their plans and business continuity management systems.

Thursday, 3 October 2013

When Goverment shutdowns

By Jorge García Carnicero

The decision taken by the Congress of United States of not to finance the Government is a continuity scenario that is going to bring multiples inconveniences to citizens and that it would provoke the activation of different contingency plans in organization, and people.

But first of all, what is a Government shutdown? It’s a situation in which Government stops to deliver public services that are not basic because of lack of money to pay it. This situation is due to the separation in the decisions groups established by the USA law in which the federal budget depends on Congress (composed by Senate and House of representatives) and have to be countersigned by President. In some circumstances, like President and parliaments groups that control the Congress, are different in political terms it could be that there would be divergences between them and not to approve the budgets, and consequently, the lack of financial for the public activity.

Last 30th of September, House of Representatives, controlled by Republicans, and Democart-controlled Government didn’t agree about deadline of health assistance law, which provoke the government shutdown. This brought along with sending 800.000 public servant to their homes and the activity of all the agencies in United State which are considered not critical stopped. Moreover, and due to the government has reached the top of approved budget, if new budget is not approved, United States will declare suspension of payments next 17th of October.

Government Shutdown consequences are a lot, as it can be imaged. Following we are going to analyses this situation from different perspectives:

 For agencies in United States:

Agencies are stopping their activities and carrying out the different contingency plans associated to each one. Those plans will be published in the following link of the White House

For Government agencies providers

It’s clear that the Government activity generate business for a lot of providers. These providers will be affected, because activity is going to decrease and so the ingress. Depending on the time that takes the shutdown, the looses in the providers will be growing. It’s difficult to thin on a contingency plan covering this situation, but assurance.

For companies depending on services of Government

There are a lot of companies which have dependencing on the government activity. Apart from the administrative activities, we are talking about, for example, public transport, needed to take people to their workplaces or custom services, needed to imports.

For Public servants

As said before, the shutdown is going to send close to 800.000 public servants to their homes, without salary, until the Congress approve the new budget. This situation can carry some finantial problems to their families, and each public servant will have to manage with measures that will anticipate, if they have done before.

There are other agents afected, like those ecompanies with a very high dependency on retail trade or al thouse business denpending on agencies actions. As an example, the validation of mobile phones.

From a the perspectgive of administration as a provider of business continuity services, companies and continuity responsables in United States has to take into account that the following services are affected:
  • FEMA: the disaster recovery information is not beeing up to date, although it has been asking for help trough disasterassistanc.gov
  • Ready.gov, the website information is not up to date.
  • The NOAA (National  Oceanic and Atmospheric Administration) is not operative, and the NHC(National Hurricane Center) is operative and working properly.

Friday, 27 September 2013

Conference AENOR-Continuam: Business Continuity Management

By Moises Lopez Soto


Last Friday, 27th of September, has taken place a conference about Business Continuity Management: ISO22301, promoted and organized by AENOR and Continuam with a high success of attendance and a great level of lectures. There has been perhaps for the first time that there were people of a great variety of industries, like Telcom such as Telefonica, energy companies like Iberdrola, or transport, represented by the Municipal Transport Company of Madrid (EMT).


Although this pot is not intended to be a wide summary of the session and there will probably be a lot of details not covered, I’d like to make widely known the event and some points that were covered by the different experts invited.

The session started with the exposition of the content and scope by Mr. José Luis Tejera, business development director of AENOR, who made a review about the different security standards and who made the first reference to an issue that was emphasized in the lectures after him: it’s really necessary to collaborate with supply chain, that is providers, because of the dependences on them.

After that, a round table was established about Regulation and Certification, in which there were reviewed different contents of ISO 22301 by Mr. Tomas Marín Iñurrieta, chief of Regultations service and Coordination of CNPIC, and Mr. Carlos Manuel Fernández Sánchez, Business Development TIC manager of AENOR, who emphasizes about the importance of deploying business continuity system instead of certificate it, although certification requires you to keep your deployment up to date.

Mr Juan José Miguez Iglesias, technology risks associate of PwC, contribute with the experience of PwC in Business Continuity consultancy, defining a four phases methodology (Document review, BCMS gap analysis, verification and tests and support to audit process) with which they intend to cover most of their customer requirements for deployment of BCMS. PwC metohodology also can include fast track actions, with which they will test in a first approach through a role play the knowledge and maturity of the company take this test as a starting point and developing the plans and procedures in a second approach. This combines Latin character (based in improvisation) with Anglo-Saxon character (based in procedures).

Closing this first round table, Cristo Perez, Busines Continuity Manager of Sanitas, made a presentation of the pocess follow by Sanitas for deployment and certification of BCMS, showing an example of a DRP evolution since it was not enough to cover the varity of scenarios typically included as Business Continuity scope. He used two examples: thread of terrosit attack in Campo de las Naciones, that caused a unavailability scenario and Aviar flu. As a resasault their have a global management system in which they include the business decision makers and, over all, that put People as cornerstone of all system.

In the second part of the session, Mr. Cesar Perez Chirions, President of Continuam, and Ms Maria Parga, general director assessor of BME-INNOVA and vicepresident of Cotinuam, made a presentation about the “Instituto de continuidad de negocio” and about their objective of connect professionals who want to share their knowledge and try to to make widely known and promote Business Continuity activities.
Closing the session, there toke place a second round table with the following professionals:
  • Mr. Manuel Carpio Cámara, Information Security and Fraud Prevention director in Telefonica, who apart from giving information about specific cases and present the global BCM structure of such a big company, made his particular vision of BCM, with two dimensions: a vertical dimension with BCMS and a horizontal dimension which put together particular requirments). He also expose the way they support the different BCM plans of each telco belonging  to Telefonica Group through SUNGARD BCM tool in DRASS model. I would like make two highlights of his lecture: The phrase “Continuity is NOT an option” and Event Correlation, which can bring information about where is anybody at any time during an incident.
  • Mr. Ángel Robles Rodríguez, Deputy lawyerd at EMT, presented how from his organization they have to think on buses as if they was an employee.
  • Mr. Pedro Pablo, Security, privacy and Global Continiuty Manager of RSI, talk about necessity of reinforce supply chain and make emphasis in problem trying to grant the service level agreed with providers, especially with big ones.
  • Mr. Javier García Carmona, responable of information security and communications in Iberdrola, was the autor of an other phrase that I consider it a great phrase: “In Spain there is not Business Continuity Culture”. Apart from that he sent a calming message about Spanish electric infrastructure, considered one of the critical infrastructures.
  • Mr Roberto Rodriguez, Business Continuity Director in Grupo Santander, made an exposition remarking the  value of test as a way establish automatism responses to a contingency and serving as a catalyst that avoid the potential shock of personal selected to answer the incident because of the type of crises that could be close to their environment, or because of their own character and their ability to answer to a contingency, being critical to the success to the Business Contintuity program the election of this people and we do not usually pay to much attention to this.
  • Mr Victor Llorente, bussiness consultor at Grupo SIA, go into detail about the need of support Business Continuity programs in tools that allow the automation of BCMS processes.
The closing lecture was carrying out by Mr Avelino Brito, general director at AENOR, who toured the organization and put into relevance the meaning of AENOR as a unifying knowledge organization.

In general terms, I feel has been an interesting event, which highlights the progress in Business Continuity industry. Business Continuity professionals begin to look for strengths and obtain resilience, ensuring not only our internal capabilities but also the dependencies by third parties. This requires focus much more towards people, towards their responsiveness, to heard and given the capacity of business decision makers as opposed to the old IT disposal. And all this is done under a global international framework, which is ISO22301 in which to look and be bound to improve.

Wednesday, 28 March 2012

BCAW webminars

This are the webminars deployed regarding the Business Continuity Awareness Week, sponsored by BCI.

Adopting Cloud In Your Backup Strategy
BCM Frameworks: From Best Practices to Standards to Overarching Models
Burst out of you own personal silo, Find out who else is interested in disasters
Business Continuity Awareness for Senior Management
Business Continuity in the Supply Chain
Business Continuity Management Systems
CM² Maturity Model
Conscientisation pour la continuité des affaires auprès de la direction
Contact Centre Continuity
Continuity as a Service (CaaS)
Corporate Business Impact Analysis-Why Bother?
Cyber Preparedness-Time is Not on Your Side
Establishing a Governance framework for an effective BCM
Getting Started with BCM
Horizon Scanning - What could Business Continuity look like in 2040
Horizon Scanning, new threats, new skills, new challenges the next 5 years
How to check your Business Continuity Management System?
How to Effectively Use Social Media Before and During Disasters
How to Successfully Implement a Business Continuity Management Program..
Identifying Key Suppliers
Infrastructure Impact Analysis
Integrating Cyber Threat Protection and Business Continuity Planning
ISO 22301 Business Continuity Management Systems
Learning from Earthquakes, Non-Structural Retrofitting and Other Mitigation Meas
Preparing for the 2012 Games- What should you do in the time left?
Preparing for the 2012 Release of ISO 22301
Preparing your Communications Strategies for London 2012
Puzzle Pieces: Are You Seeing the Entire Planning Landscape
Risk Management Strategies for Protecting Enterprise Supply Chains
Why a formal certified BCMS? “Due Diligence”-Talking the Language Management

Thursday, 28 July 2011

Where to begin.

There are a lot of types of organizations: government or public, bigs or smalls, SOHO, etc, and all of them has their own objectives. This heterogeneity of organizations makes that each one has their own motivation when establishing their Business Continuity program.
A key element used to be news: when a disruptive event, a natural disaster or a unexpected event occurs it could wake up some kind of awareness in directors that can say what about if it happens to me? Thereafter, the direction used to identify internally the business continuity manager, in order to carry out the program and, if there are enough budget, ask for external hep form consultants.

The next step is looking for a reference that  can show the better way to achieve the program. Both, BC guides and standards (GPG from BCI, ISO 22301, etc) and consultancy methodologies develop a inventory of business process, resources inventory, risk assessment, business impact analysis, ....

But what I' going to put forward is a different way to begin in Business Continuity, that, from my  personal experience, could be the best way. The main aspect of any initiative is the awareness so is the first thing we have to promote and this grant us the success in the others phases of the program. And, of course, the best way for awareness is with TEST. So, my recommendation: carry out a drill without a lot of preparedness but, of course, always with the complicity of direction.

An example that I have experienced in this way was a drill in an European organization  at which arrived a new director, who had been working in the military. He decided to conduit a drill based on a bomb in the main entrance of the building. Surprisingly, the results of the drill were better than expected, mainly because of the leadership of this director, but a lot of lesson could be learned and there were a lot of conclusions that were drawn and actions lines in which to work.

But be careful, because this formula perhaps is not valid for some scopes. For example, if our scope is only IT Service Continuity, we cannot conduit a drill: we can cause just the opposite of what we were looking for.