Showing posts with label standards. Show all posts
Showing posts with label standards. Show all posts

Monday, 21 October 2013

Spanish Critial Infrastructure Protection Law and Business Continuity

By Daniel Blanco Real


The Spanish Law 8/2011 or Ley  de Protección de Infraestructuras Críticas (LPIC) its related to grant essential services that support specific infrastructures considered critical mainly because of two properties:
  1. because its required and there are not other alternative solutions that could replace it and/or
  2. because a disruption or destruction should have very important impacts in essential services
But What is considered a essential service in the law? LPIC identify essential service as those services required to maintain social basic functions (health, security, social welfare and economics, Public administration, etc), although there is difficult to identify it based on the definition above.

Looking for activities and definitions carried out by other countries, we can take a look to the information published by Swedish Civil Contingencies Agency, (MSB in Swedish), that in 2007 established a set of criteria to identify Social critical functions, very close to what is described in LPIC as essential services.

Sector
Functions
Energy supply
Production and distribution of electricity, district heating, fossil fuels and vehicle fuels.
 
Information and communication
 
Telephone services, Internet, radio and TV broadcasts, postal services, production and distribution of newspapers, radio and TV.
 
Financial services
Money transmission, cash access, private insurance and securities trading.
 
Social insurances
Payment of sickness and unemployment benefits and the national pension system.
 
Public health and medical services, and special social
services
 
Emergency hospitals, primary care, psychiatry, pharmaceutical supplies, infectious disease control, and special social services for children, disabled persons and the elderly.
 
Protection, security and safety
 
Rescue services, police, courts, correctional institutions and SOS Alarm, military, coast guard, and customs, border and immigration control.
 
Transport
Road, rail, sea and air transport, and transport infrastructure management.
 
Municipal services
Drinking water, sewage treatment, streetcleaning, public meeting places, refuse collection and roads.
 
Food Agriculture and the production, distribution and control of food.º
 
Trade and industry Retail, IT operations and service, construction and contract work, guard and security services and the manufacturing industry.
 
Public administration
governance
support functions
service sector
 
 
National management, regional management and local management, diplomatic and consular services, inspection and permit services, expert and analytical services, detection and laboratory services, collection and provision of population data, meteorological services, training services and burial services.

It can be seen in the original document.

In order to clarify what is considered as a essential service, the document offers some questions that have to be answered for those who think that can be critical operators, grouped by two different blocks: preventive measures and respond measures

From a preventive measures perspective:
  • What is the potential scope of a shutdown?
  • How many people would be affected?
  • What levels of society would be affected by a shutdown?
  • To what degree would people’s lives and health be affected?
  • What financial, environmental, societal and cultural values could be lost?
  • How would public trust be affected?
  • How long would it take to repair the damage?
 From a response measures perspective:
  • Is the function essential for Leading and coordinating society’s response?
  • Is the function essential for Providing the public with enough information about the situation?
  • Is the function essential for Responding operatively to the emergency?
  • Is the function essential for Minimising the consequences?
  • Is the function essential for Restoring functions?
Once essential services are clearly defined, all organizations (obviously critical operator, but also if not)  must focus on:
  • How products and services that are delivering can affect to those essential services (This is clear in critical operators)
  • How lack of this essential services could affect to products and services delivered.
As a conclusion, Business Continuity in an organization has not only focus in how to recover products and service delivery, but also to take into account how the lack of this products and services affect to the society and the essential services. Without support of those essential services it's probably that organizations will not be able to recover their business and this is something that a lot of organizations don't take into account in their plans and business continuity management systems.

Monday, 22 October 2012

Healthcare service continuity

Blackout taken place in Fundación Jimenez Diaz hospital , last 16th of October in Madrid is a good example to realize that there is not necessary great disasters or disruption  to activate Business Continuity Plans.
Although we have not too much information about this incident, it can be clearely indenfied two tradicional continuity measures:
  • Power generators activation, to support critical systems
  • Redirection of new admissions to other hospitals, in this case the Hospital Clínico.
When we are talking about a hospital, such as I discuss in my previous post components supporting business, this service is so critical that  availability of all components supporting the service has to be granted, that is, facilities, suppliers, medical staff or information technology. Impact caused by lack of service is simply unaffordable because the life of patients is in play.

However, the incident occurred in Jimenez Diaz Hospital must make us think about if our health system is really prepared for emergency situation or disasters when hospitals are affected. 2004 terrorist attacks in Madrid realized that the emergency agency are prepared to deal with such a great disaster, but What would happen if the own hospitals were affected by the disaster?

In a hospital there are a lot of diverse healthcare services, with different criticalities: emergencies, maternity, hospitalization, operating rooms, doctor appointments, radiology,.... Strategies must be different depending on this criticality. For example, a pediatric appointment could be delayed or redirected to other hospital, but a serious patient that has to go through surgery or with dependation of ventilation can no be unattended and any delay can be fatal.

Having a look abroad, for example to United States, hospitals has a global framework since lasts 80s, called HICS (Hospital Incident Command System). This framework identifies different issues to be taken into account to assure healthcare service. HICS was born as a emergency specific framework (HEICS), but it nowadays is a system for use in both emergency and non-emergency situations. George W Bush govern created in 2003 a global framework to manage incidentes (NICS) and this caused a new revision or HICS which is the last version (version V).

About content, HICS identifies five management functions hat has to be defined in the hospital to manage incidentes:
  • Incident Command, set by different responsibles of safety, liaison and public information officers and the global responsible
  • Operations section concuct ths tactical operations.
  • Logistics Section: provides required resources to achived operational objectives.
  • Planning Section: Collects information about the incident, maintain resource status and infomration for reports and prepares documents, such as incident plan.
  • Finance and Administration Section: Monitors costs related to the incident and provides accounting, procurement, time recording, and cost analyses
The most important advantange of HICS is provides a common terminology and position titles to enhance standardization among agencies and responders

In Spain, with healthcare service tranferred to Autonomous Comunities and with the actual economic crisis it seems that this kind of initiatives are not a priority, altough from my point of view is an interesting tasks for CNPIC. At the end of the day hospitals should be considered critical infrastructure.

Wednesday, 3 August 2011

Historical evolution of norms, standards and legislation in BCM

Before the expected ISO 22301 will be published and, probably, will be the reference standard world wide, its convenient to make a revision of the set of guides and standards that nowadays shows the way in Business Continuity.

The first standards that can be remembered is the  NIST 800-34 "Contingency Planning Guide for IT" from US government. This is the standard in which some terms and definitions begins to be used, and this terms had endured over time. This are DRP, COOP, BCP, etc. This standard were published in 2002 and, without any doubt, were the first statement of intent in the IT Service continuity.

At the same time, the Business Continuity Institute (BCI) published the first version of the Good Practice Guide (GPG) which would be later become the seed of the BS25999 standard. It was more focused in Business continuity that the 800-34. BSi decided in 2003 used as a base to develop the standard, publishing the PAS-56 (Publicly Available Specification). This PAS was in force until the publication of BS-25999-1 that repeal the PAS in 2006. At the same time, the standard BS-25999-2 was launched, with the description of the management system and the certification schema.
Standards developers organizations from Singapore and Australia has been traditionally aware about business continuity and had published different norms and standards, that complete the "occidental" standards. Singapore, for example, published the SS507 BC/DR Service Providers that looks for define the characteristics that providers has to met in other to be certificated as a BC provider. During a while, this standard was considered as a rival of BS-25999 in their fight to establish the base of the new ISO standard, but it was not very used in other countries.

In 2006 was published the PAS-77 standard by BSi. It was focused in covering the IT Service that in  was not taken into account in BS-25999 and was primarily motivated by the criticism. In 2008 this standard become BS-25777 IT Service Continuity Management and in 2011 was became in ISO 27031, although it's not expected that this standard would had a certification schema in in the future. It's important to advice that the committee in charge of the development of this standard is 27 (IT) and not 22 (Social Security).
In the following picture it can be seen a timeline that could clarify this scenarios of norms and standards:
Hope the 22301 will become in the definitely standard that give a boost to the business continuity sector from a certification perspective.