isaca singapore seminar and networking dinner sg... · •iso/iec 24762 guidelines for bc-dr ......

30
ISACA Singapore Seminar and Networking Dinner December 20, 2011 National Library Board Building Level 5, Possibility Room

Upload: phamdiep

Post on 25-Jun-2018

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

ISACA Singapore

Seminar and Networking Dinner

December 20, 2011

National Library Board Building

Level 5, Possibility Room

Page 2: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Auditing the Business Continuity Management Programme:

Challenges, Preparation and Competency

Dr Goh Moh Heng

President

Page 3: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Dr Goh Moh Heng

• President – Business Continuity Management (BCM)

Institute – www.bcm-institute.org

• Managing Director – GMH Continuity Architects – Asia Pacific BCM Consulting Firm – www.GMHasia.com

• Professional BCM Appointments – Technical Advisor for TR19:2005 &

SS540:2008 BCM Standard (Management Council and Technical Committee) www.ss540.org

– Project Director, Technical Working Group for SS507:2004 • ISO/IEC 24762 Guidelines for BC-DR

Services

http://www.bcmpedia.org/wiki/Dr_Goh_Moh_Heng

Page 4: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Dr Goh Moh Heng

Prior Appointments

• Government of Singapore Investment Corporation (GIC)

• Standard Chartered Bank

– Global Head for BCM

• PriceWaterhouseCoopers

• Past Certification Broad Member for DRI International’s Certification Board

• Past Executive Director for DRI Asia

• Senior Technical Advisor, China Business Continuity Management Forum

http://www.bcmpedia.org/wiki/Dr_Goh_Moh_Heng

Page 5: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Agenda

• Back to Basic

• Update on Global BCM Development

• Mandate BCM Competency

• Audit and Review Key BCM Components

• Learn from Recent Disaster

Page 6: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Business Continuity Management Fundamentals

Page 7: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

CRISIS IT

RECOVERY SECURITY

BUSINESS CONTINUITY

Plan

SPECIFIC CRISIS MANAGEMENT

PLAN IT DR PLAN

SPECIFIC PLANS

SECURITY PLAN BC PLAN

Incidents, Emergencies,

Events, Disasters

Page 8: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Common Planning Methodology

http://www.bcmpedia.org/wiki/ BCM_Planning_Process_or_Methodology

Page 9: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Global BCM Development

BCM Standards and Regulations

Page 10: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

National Standards for BCM

• UK

– BS25999 Pt 1 & 2

• Singapore

– SS:507:2008

– SS:540:2008

• Australia/ New Zealand

– ANZ 5050

– HB Series 221, 292, 293

• US

– NFPA 1600: 2011

– ASIS SPC.1-2010 Organizational Resilience

Page 11: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Standards and Guidelines

• Regulations and guidelines to organization

– Sarbanes-Oxley Act

– Basel III Capital Accord

– Central Bank’s BCM guidelines

– COSO; COBIT; SAS70

– OSHA

• New BCM Standards

– ISO 22301

• Societal security - Business continuity management systems

– ISO 22399

• Societal security - Guideline for incident preparedness and operational continuity management

Page 12: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

BCM Planning Methodology and S540 for BCM

Page 13: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

BCM Planning Methodology & BS25999

Page 14: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

International BCM Standards

BS 25999

NFPA 1600 ANZ 5050

SS 540

ISO 22301 (2012)

Page 15: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Organizational BCM Competency

Page 17: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Auditable Components of BCM Programme

Page 18: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Audit Requirement for BCM

Key: Controls: BCM Competency

Key Controls: Approved Reports

Page 19: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Common Language (Online Dictionary)

www.bcmpedia.org

Page 20: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Audit Skillset and Upgrading

Page 21: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

BCM Audit Process Compare with ISO 19011:2002

Audit Planning and Preparation

Audit Fieldwork

Audit Review and Reporting

Audit Follow-up Conducting Audit Follow-up

Completing the Audit

Preparing, Approving, Distributing Audit Report

Conducting On-site Activities

Preparing for On-site Activities

Conducting Document Review

Initiating the Audit

Page 23: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Recent Disasters

Page 24: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Thailand Flooding

Page 25: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Japan Tsunami

Page 26: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Lessons from Recent Disasters

• Lack of understanding of what exactly is BCM?

• Review of key planning scenario (KPS)

– Single site, regional and multiple disasters

• Focus on:

– Low probability High Impact to

– High probability High Impact

• Definition of “BCP”

– Crisis management

– Business continuity

– Emergency response

• Supply chain considerations

• Coordination with public authority

• Welfare of staff and family members

Page 27: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

BCM Framework

• Policy

– Strong governance

– Alignment with business mission

– Consistency in communication

• People

– Senior Management

– Key executive assign to the project or programme

– Involved by business heads and units

– BCM competency

• Process

– Common methodology for BCM, DR, CM, ER, etc

– Integration of plans within organization

0

People

Process

Policy

Page 28: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

BCM Institute Forum Building a Community

80% Asian and Middle Eastern BCM

and DR Professionals

www.bcmi.groupsite.com

Page 29: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

Web-based Activities

• Exchange of information and experiences

Page 30: ISACA Singapore Seminar and Networking Dinner SG... · •ISO/IEC 24762 Guidelines for BC-DR ... –Strong governance ... ISACA Singapore Seminar and Networking Dinner Presentation

THANK YOU

Dr Goh Moh Heng President Mobile: +65 96711022 Tel: +65 63231500 Email: [email protected]