Verso ilnuovostandard ISO (BS25999) sullabusiness Continuity Scenari e opportunità

Similar documents
La certificazione ISO27001

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006

Introduction to ISO/IEC 27001:2005

Predstavenie štandardu ISO/IEC 27005

An Overview of ISO/IEC family of Information Security Management System Standards

John Snare Chair Standards Australia Committee IT/12/4

Business Continuity Management

Business continuity management and cyber resiliency

Business Continuity and Disaster Recovery

Driving Global Resilience

Business Continuity Policy

NHS Gloucestershire Clinical Commissioning Group. Business Continuity Strategy

Business Continuity Management: How to get started. Presented by: Tony Drewitt, Managing Director IT Governance Ltd 19 April 2018

New International Health and Safety Standard ISO 45001

SAMPLE REPORT. Business Continuity Gap Analysis Report. Prepared for XYZ Business by CSC Business Continuity Services Date: xx/xx/xxxx

Facilities Management and Business Continuity. 10 May 2017

Global Statement of Business Continuity

How ISO helps organisation to achieve operational readiness Ong Liong Chuan 26 Apr 2016

7 th BICSI Southeast Asia Conference 2009 Building the Next Generation Broadband Network

Information Security Strategy

Risk Management. Continuity Management

What is ISO ISMS? Business Beam

TAN Jenny Partner PwC Singapore

Introduction to Business Continuity Management

Information Security Management Systems Standards ISO/IEC Global Opportunity for the Business Community

TSC Business Continuity & Disaster Recovery Session

What is BS 7799? BS 7799 is the most influential, globally recognised standard for information security management.

Incident Response. Tony Drewitt Head of Consultancy IT Governance Ltd

Business Continuity: How to Keep City Departments in Business after a Disaster

ISO/IEC Information technology Security techniques Code of practice for information security management

Policy. Business Resilience MB2010.P.119

Why you should adopt the NIST Cybersecurity Framework

Leveraging ITIL to improve Business Continuity and Availability. itsmf Conference 2009

SECURING THE UK S DIGITAL PROSPERITY. Enabling the joint delivery of the National Cyber Security Strategy's objectives

Principles for BCM requirements for the Dutch financial sector and its providers.

PECB Change Log Form

C106: DEMO OF THE INFORMATION SECURITY MANAGEMENT SYSTEM - ISO: 27001:2005 AWARENESS TRAINING PRESENTATION KIT

Securing Digital Applications

BUSINESS CONTINUITY MANAGEMENT PROGRAM OVERVIEW

Using International Standards to Implement a Business Continuity Management System (BCMS)

WELCOME ISO/IEC 27001:2017 Information Briefing

ISO 22301: An Overview of BCM Implementation Process. Presenter: Dejan Kosutic

Promoting the Art and Science of Business Continuity Management Worldwide. Partner of the DRJ

HENRY EE, FBCI, CBCP

Building resilience. Delivering assurance.

BCM s Role in Effective Risk Management: A Risk Manager s Point of View

Certified Information Security Manager (CISM) Course Overview

Is your organization ready for ISMS certification?

TEL2813/IS2820 Security Management

zsah Cloud Offering Security FAQ In partnership with Clearswift

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Code of practice for information security management

Disaster Recovery and Business Continuity Planning (Mile2)

Introduction to Standards Development

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security management systems Overview and vocabulary

Global Security Consulting Services, compliancy and risk asessment services

POSITION DESCRIPTION

Policy Title; Business Continuity Management Policy. Date Published/Reviewed; February 2018

Fiscal 2015 Activities Review and Plan for Fiscal 2016

Risk Advisory Academy Training Brochure

Information Security Management System

Information Security Exchange

A View From the Top. Mark Hughes BT Group Security Director

Security Management Models And Practices Feb 5, 2008

Mark Hofman SANS Institute/Shearwater Solutions

When Recognition Matters WHITEPAPER ISO SUPPLY CHAIN SECURITY MANAGEMENT SYSTEMS.

ACCREDITATION COMMISSION FOR CONFORMITY ASSESSMENT BODIES

FACTS AND OPPORTUNITIES IN BRAZIL. Gartner IT Security Summit Washington DC, June 2008

standards and so the text is not to be used for commercial purposes, gain or as a source of profit. Any changes to the slides or incorporation in

BCP At Bangkok Bank, Thailand

Enterprise resilience and the role of Standards

Conformity assessment Requirements for bodies providing audit and certification of management systems. Part 6:

IT Governance ISO/IEC 27001:2013 ISMS Implementation. Service description. Protect Comply Thrive

PREPARE FOR TAKE OFF. Accelerate your organisation s journey to the Cloud.

ISO Professional Services Guide to Implementation and Certification AND

What is ISO/IEC 27001?

,000+ What is the BCI Corporate Partnership? What are the benefits of becoming a Corporate Partner? Levels of Partnership

Session 5: Business Continuity, with Business Impact Analysis

Global Wind Organisation CRITERIA FOR THE CERTIFICATION BODY

Canada Life Cyber Security Statement 2018

What Why Value Methods

UL and Business Continuity

Cyber risk resilience

Course List & Pricing Crest Advisory Africa

TABLE OF CONTENTS ONLY IT Resiliency Benchmarking Report

BPS Suite and the OCEG Capability Model. Mapping the OCEG Capability Model to the BPS Suite s product capability.

BUSINESS CONTINUITY MANAGEMENT. A short guide 2017

The Key Principles of Cyber Security for Connected and Automated Vehicles. Government

ACCREDITATION COMMISSION FOR CONFORMITY ASSESSMENT BODIES

ISO/IEC TR TECHNICAL REPORT. Information technology Security techniques Information security management guidelines for financial services

Cyber Security Incident Response Fighting Fire with Fire

Manchester Metropolitan University Information Security Strategy

New York Department of Financial Services Cybersecurity Regulation Compliance and Certification Deadlines

Business Continuity Planning

Digital Forensics - Global Market Outlook ( )

European Union Agency for Network and Information Security

Heading Text. Manage your Organization s Governance, Risks, and Compliance Requirements and Transform your Business Potential with SAP GRC

ISO 22301: An Overview of BCM Implementation Process. Presenter: Dejan Kosutic

Internet of Things Toolkit for Small and Medium Businesses

Cybersecurity: Considerations for Internal Audit. Gina Gondron Senior Manager Frazier & Deeter Geek Week August 10, 2016

Protecting your data. EY s approach to data privacy and information security

Transcription:

Verso ilnuovostandard ISO 22301 (BS25999) sullabusiness Continuity Scenari e opportunità Massimo Cacciotti Business Services Manager BSI Group Italia

Agenda BSI: Introduction 1. Why we need BCM? 2. Benefits of BCM 3. International Development of BCM 4. Getting started with BCM 5. Related standard to BCM: ISO/IEC 27000 series

BSI s Introduction Founded in 1901 Global independent business services organization No owners/ shareholders all profit reinvested into business Standards, Assessment, testing certification, training, software World s #1 Standards Body #1 certification body in the UK, USA and Korea >2,500 staff and >50% non-uk 53 offices located around the world 70,000 clients in 150 countries 235m revenue in 2010

BSI s Introduction What our customers say about us

Operations in 147 Countries

Global 52 Offices Presence Worldwide Milano, Padova London Washington Beijing Worldwide Offices Mexico City Sao Paulo New Delhi Singapore Sydney

Our services Assurance Services (Assessment and Certification) Training Governance, Risk and Compliance Testing services Healthcare Services Advisory Services

BSI Training We offer various types of training including: Awareness Training Implementation Training Auditor Training Our delivery options: Public training courses In-house training course e-learning courses Customer journey Auditor training Implementation Training Awareness Training Convenzione AIEA BSI

BSI Governance, Risk & Compliance (GRC) Entropy Software A turn-key solution that provides the management system framework for fully functional integrated and auditable management systems including: Environmental Management ISO 14001 Health & Safety Management OHSAS 18001 Quality Management ISO 9001 Information Security Management ISO/IEC 27001 Supplier Compliance Management (C-TPAT & AEO) and other management systems standards

Business Continuity Management (BCM) facts and future trends

1. Why we need BCM Definition Business Continuity Management (BCM) is a framework for identifying potential threats to an organization and building organizational capability to respond to such threats, in order to safeguard the interests of key stakeholders, reputation, brand and value-adding activities (1) (1) Joint statement: BristishStandards Institution, Business ContinuityInstitute, Cabinet office, Chartered Management Institute

Natural disasters Economic disruption and market turbolence Terrorism Physical security disruptions Infrastructure or IT failures Fraud or hacking New regulations Potential consequences: Examplesof Disruption Employee safety jeopardized Reduced customer confidence Loss in image or brand equity Decline in revenues Decline in market share BCM Risks

Are you prepared for disaster? CMI/BSI UK survey March 2011 84% of managers realize the benefits of BCM planning 58% of managers report that their organization has BCM in place (significant YoY growth in SMB sector) Only 50% of organizations with BCM test their BC plan once a year or more 60% of organizations with BCM provide training to relevant staff Only 55% of organizations ensure that their supply chain have BCM plans in place

2. BCM: The Benefits& Business Case Expedite recovery after disruption Understand overall business exposure Prepared to respond should the unexpected occur. Raises awareness in the organization Proxy for good overall management. Demonstrates to customers, partners and other stakeholders that the organization takes a robust approach to risk Reassurance that the business can keep going

Perceivedbenefitsof BCM

Managers viewson BCM effectiveness

3. International development of BCM 25999 PAS 2003 BS 2006 ISO 2012 Started as a PAS (Publicly Available Specification) by BSI (PAS 56) Moved to a BS 25999 in 2006 & 2007 in two parts as Umbrella Standard Scheduled to move to ISO in 2012 (ISO 22301)

BSI International usage of BS25999 BSI translations into French, German and Spanish BS 25999 sold by BSI in over 100 countries Other National Standards Bodies Adoption of BS 25999 outside the UK (Brazil, Spain etc.) Local translation/distribution (Japan, China, Russia, etc.) US As part of the PS-Prep program the US Department for Homeland Security recommended 3 standards for BCM, including BS 25999.

The new ISO 22301 19 The growing success of the BSI developed BS 25999 has prompted ISO (the International Organisation for Standardization) to begin work on publishing an ISO recognised standard which is expected to be released in May 2012 BSI is well placed to assist clients in making a smooth transition to the new ISO standard in 2012 (ISO 22301)

4. GettingStartedwithBCM Recommendations Senior managers must take ultimate responsibility for the quality and robustness of their organizations BCM. Use BCM based on a common framework (such as BS 25999) as part of a wider programmeand train employees Develop a clearly defined approach for responding to the media; BCM is multi-functional not just IT Review which suppliers are critical to your operations and ask whether they have BCM Test your BCM through regular exercises

BCM Standards Code of of Practice Best practice, not auditable Requirements Shall statements, auditable

Management Systems Common components of management systems: Policy Planning Implementation and operation Performance assessment Improvement Management review

Plan Do Check Act (PDCA) Cycle Continual Continual improvement improvement of of the the Business Business Continuity Continuity Management Management System System Interested Interested Parties Parties Plan Establish Interested Interested Parties Parties Act Maintain and improve Do Implement and operate Business Continuity requirements and expectations Check Monitor and review Managed Business Continuity

PLAN: Understanding the Organization Identify critical activities Perform Business Impact Analysis (BIA) Evaluate threats to critical activities Determine continuity requirements Determine choices Understanding the Organization

Business Continuity Policy Requires top management commitment and approval Includes objectives of business continuity and scope of business continuity management system Must be communicated Must be reviewed Should be appropriate to the nature, scale, complexity, geography and criticality of business activities Should reflect culture, dependencies and operating environment

PLAN: Determine Business Continuity Strategy Strategies are arrangements to enable an organization to recover Define and document incident response structure Determine how to recover each critical activity Manage relationships Determining BCM Strategies

DO: Developing and Implementing a BCM Response Incident response structure and Crisis Management Incident management plan Business continuity plan Developing and Implementing BCM Responses

Sequence of Events of an Incident Incident! Overall recovery objective: back-to-normal as quickly as possible Timeline Within minutes to hours: Staff and visitors accounted for Casualties dealt with Damage containment/ limitation Damage assessment Invocation of BCP Incident Response Business continuity Within minutes to days: Contact staff, customers, suppliers, etc. Recovery of critical business processes Rebuild lost work-in-progress Within weeks to months: Damage repair/replacement Relocation to permanent place of work Recovery of costs from insurers Recovery/resumption back to normal

CHECK: Exercising, Maintaining, and Reviewing BC Arrangements Exercise program Exercise arrangements Maintaining BC arrangements Reviewing BC arrangements Exercising, maintaining, and reviewing

ACT: Embedding BCM in Organizational Culture Ensure BCM becomes part of the core values and effective management of the organization BCM education for all employees Evaluate the effectiveness of the BCM awareness delivery

SUMMARY Disruptions experienced by 8 out of 10 organizations -a real threat 8 out of 10 say benefits & business cases are strong for BCM Despite this, many organizations still unprepared for BCM BS 25999 is the leading global standard to help implement BCM BCM should be reviewed with suppliers Media coverage included in BCM strategy(reputational risk) Senior managers must take ultimate responsibility for BCM Manytoolsto assistyourorganisations in BCM

The Early Adopters of BCM ICT Finance Proffessional Services Manufacture Public Services Minerals, Energy, Utilities Built Environment Transport Healthcare Food Aero and Defence Facilities & Retail The ICT and Finance sector are the early adopters of Business Continuity Management Systems

BSI 25999 certification clients

What is ISO 22301 Societal Security Prepardness and Continuity Management System Requirements

What is ISO 22301 Very similar to BS 25999-2 What are the key differences: Monitoring performance: Introduces requirements for BCM/BCMS Metrics e.g. BIA update frequency, number of plans, numbers exercises completed, etc Operational Planning and Control: Enphasis on operational planning and setting controls for BCMS

Certified Organisations - Transition Decided by UKAS at the point of publication Certified Organisations have 12 to 18 months to transition, althought could be up to 3 years Part of Continuous assessment visits Additional visit will be necessary: - differences between ISO 22301 and BS 25999-2 - Organisation size and BCMS scope

ISO/IEC 27000 Series - Published ISO/IEC 27000 - Overview and vocabulary 2009 ISO/IEC 27001 - Information security management systems - Requirements 2005 ISO/IEC 27002 - Code of practice for Information security management 2005 ISO/IEC 27003 - ISMS implementation guidance 2010 ISO/IEC 27004 - Information security management - Measurement 2009 ISO/IEC 27005 - Information security risk management 2011 ISO/IEC 27006 - Guidance to Certification Bodies ISO/IEC 27007 - Guidelines for ISMS auditing ISO/IEC 27008 - Guidelines for auditors on information security controls 2007 2011 2011 ISO/IEC 27010 - Guidance for inter-sector and inter-organizational communications 2012 ISO/IEC 27011 - Guidance to telecommunications 2008 ISO/IEC 27031 - Guidelines for ICT readiness for business continuity 2011 ISO/IEC 27033-1 - Security Techniques, Network Security 2009

Other 27000 standards in development ISO/IEC 27013 ISO/IEC 27014 ISO/IEC 27015 ISO/IEC 27016 ISO/IEC 27017 ISO/IEC 27018 ISO/IEC 27032 ISO/IEC 27034 ISO/IEC 27036 ISO/IEC 27037 ISO/IEC 27038 ISO/IEC 27039 ISO/IEC 27040 Guidelines on the integrated implementation of ISO/IEC 27001 & ISO/IEC 20000-1 Governance of information security Information security management guidelines for financial services Information security management Organizational economics Information Security in Cloud Computing (relevant controls in 27001) Information Security in Cloud Computing (relevant controls in 27001 - DP/Privacy) Guidelines for cyber-security Guidelines for application security (6 part standard) Information security for supplier relationships (4 part standard) Guidelines for identification, collection, acquisition and preservation of digital evidence (possibly a 4 part standard) Specification for digital redaction Selection, deployment and operations of intrusion detection and prevention systems Storage security (2012) (2012) (2013) (2014/15) (2014) (2014) (2012) (2012 ) (2012/13) (2013/14) (2013) (2013/14) (2014)

Evento 24 Maggio 2012 primo in Italia Convegno ISO 22301-Business Continuity Quando: Dove: 24 Maggio 2012 Milano Orario: 9,15 17,00 Iscrizioni: Camera di Commercio Milano Via Meravigli 9b Palazzo TURATI Viviana Rosa Marketing & PR Manager viviana.rosa@bsigroup.com