32
1 Boston ACP – September 8, 2010

1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Embed Size (px)

Citation preview

Page 1: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

1

Boston ACP – September 8, 2010

Page 2: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

A Non-Profit Organization Committed to:

◦ Promoting a base of common knowledge for the continuity management industry

◦ Certifying qualified individuals in the discipline of Business Continuity

◦ Promoting the credibility and professionalism of certified individuals

Founded in 1988.

The Industry’s Premier Education and Certification Program Body

Page 3: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

DRII has Certified INDIVIDUALS in over 95 Countries.

DRII conducts training courses in over 45 countries.

More individuals choose to maintain their certification through us than all other organizations in our industry combined (Over 7,500 active individuals as of 2009)

DRII Certifies individuals in English, Spanish, French, Japanese, Mandarin and Russian

DRI International teaches in English, French, Spanish, Portuguese, Mandarin, Japanese, Italian and Russian

In 2009 DRII taught more classes outside the US than within the US.

Page 4: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Government Organizations •Chaired the Alfred P. Sloan Committee that drafted the Framework for Preparedness that has been the foundation for the Title IX Implementation.

•Member U.S. Chamber of Commerce Homeland Security Task Force

•Member of the Council of Experts for ANSI-ANAB who will set the credentialing standard for certifying bodies for PS-Prep

•Member of FEMA National Advisory Council Private Sector Subcommittee

•Member of Advisory Committee for Congressionally funded Project for National Security Reform

•Meeting with Special Assistant to The President for Homeland Security Standards Policy

Page 5: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Non-Government Organization •Member of the NFPA 1600 Technical Committee

•Member of the BS25999 – ASIS Technical Committee

•Participant RIMS (Risk Insurance Managers Society) PERK (Professional Exchange of Risk Knowledge) Program

•Cooperative Education Credit Sharing with ISACA (Information Systems Audit and Control Association)

•Cooperative Education Credit Sharing with IC2

•Audit Course Development and Training for Auditors with NFPA (National Fire Prevention Association)

•Developing Joint Program with Red Cross

Page 6: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Greater Marketplace Recognition◦Job Pre-Requisites◦Distinguishes Candidate◦HR Key Words CBCP, ABCP

Financial Gain – certification is correlated with higher wages

6

Page 7: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

7

Page 8: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

8Courtesy – BC Management – 2008 Survey

Page 9: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Employer Benefit – ◦ confirms for the employer, the employee has a

high level of knowledge of standard industry practices and processes – AND CONTINUES TO MAINTAIN CURRENT KINOWLEDGE

◦ Provides consistency of knowledge for multi-nationals

9

Page 10: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

10

Page 11: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

What Are We Trying to Accomplish?◦ PREPAREDNESS

Emergency Management Disaster management Business Continuity

Is this New?◦ Regulations◦ Standards◦ Guidances

11

Page 12: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Recommendation: We endorse the American National StandardsInstitute’s recommended standard for private preparedness. We wereencouraged by Secretary Tom Ridge’s praise of the standard, and urgethe Department of Homeland Security to promote its adoption. Wealso encourage the insurance and credit-rating industries to lookclosely at a company’s compliance with the ANSI standard in assessingits insurability and creditworthiness. We believe that compliancewith the standard should define the standard of care owed by a company to its employees and the public for legal purposes. Private-sector preparedness is not a luxury; it is a cost of doing business in the post-9/11 world.

12

Page 13: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

13

Consumer Credit Protection ActConsumer Credit Protection ActOMB Circular A-130OMB Circular A-130FEMA Guidance DocumentFEMA Guidance DocumentPaperwork Reduction ActPaperwork Reduction ActISO 27002 (Previously ISO17799)ISO 27002 (Previously ISO17799)FFIEC BCP HandbookFFIEC BCP HandbookComputer Security ActComputer Security Act12 CFR Part 1812 CFR Part 18Presidential Decision Directive 67Presidential Decision Directive 67FDA Guidance on Computerized SystemsFDA Guidance on Computerized Systems used in Clinical Trialsused in Clinical TrialsANSI/NFPA Standard 1600ANSI/NFPA Standard 1600Turnbull Report (UK)Turnbull Report (UK)ANAO Best Practice Guide (Australia)ANAO Best Practice Guide (Australia)SEC Rule 17 a-4SEC Rule 17 a-4FEMA FPC 65FEMA FPC 65CARCARJHACOJHACO

Sarbanes-Oxley Act of 2002Sarbanes-Oxley Act of 2002HIPAA, Final Security RuleHIPAA, Final Security RuleFFIEC BCP Handbook -2003/ 2008FFIEC BCP Handbook -2003/ 2008Fair Credit Reporting ActFair Credit Reporting ActNASD Rule 3510NASD Rule 3510NERC Security GuidelinesNERC Security GuidelinesFERC Security StandardsFERC Security StandardsNAIC Standard on BCPNAIC Standard on BCPNIST Contingency Planning GuideNIST Contingency Planning GuideFRB-OCC-SEC Guidelines for FRB-OCC-SEC Guidelines for Strengthening the Resilience of Strengthening the Resilience of USUS Financial SystemFinancial SystemNYSE Rule 446NYSE Rule 446California SB 1386California SB 1386Australia Standards BCM HandbookAustralia Standards BCM HandbookGAO Potential Terrorist AttacksGAO Potential Terrorist Attacks GuidelineGuidelineFederal and Legislative BC Federal and Legislative BC Requirements for IRSRequirements for IRSBasel Capital AccordBasel Capital AccordMAS Proposed BCP Guidelines MAS Proposed BCP Guidelines (Singapore)(Singapore)NFA Compliance Rule 2-38NFA Compliance Rule 2-38FSA Handbook (UK)FSA Handbook (UK)BCI Standard, PAS 56 (UK)BCI Standard, PAS 56 (UK)Civil Contingencies Bill (UK)Civil Contingencies Bill (UK)

Post-9/11Post-9/11

Pre-9/11Pre-9/11

1991 - 2001 2002 -------------------------------------------------------2010

2002 Safety Act2002 Safety ActFCD-1/2FCD-1/2

NYS Circular Letter 7NYS Circular Letter 7ASISASIS

State of NY FIRM White Paper on CPState of NY FIRM White Paper on CPNISCC Good Practices (Telecomm)NISCC Good Practices (Telecomm)

Australian Prudential Standard on BCMAustralian Prudential Standard on BCMHB221HB221HB292HB292

BS25999BS25999SS507 – SS540SS507 – SS540

TR19TR19CA Z1600CA Z1600

ISO/PAS 22399ISO/PAS 22399HiTech Act of 2009HiTech Act of 2009

DRIIDRII

Title IX – 110-53 Title IX – 110-53

Business Continuity Regulations and Standards

Page 14: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

14

 a. Goal of the new program is to provide a method to independently certify the emergency preparedness of private sector organizations, including their disaster / emergency management and business continuity programs.  The program focuses on certifying the preparedness of businesses and other private sector entities, and does not involve any individual professional certification.  b.  The program will be voluntary.c.  Key stakeholders are invited to participate in the development of the program.  Consultation with a variety of organizations and various sectors is required by the legislation.  Program development will likely include involvement by a diversity of private sector advisory groups and others.d.  The program will be administered outside of government by 3rd party organizations with experience / expertise in managing and implementing voluntary accreditation and certification programs.e.  One or more preparedness standards can be designated.  NFPA 1600 is reference by example.f.  Existing industry efforts, certifications and reporting in this area will not be duplicated or displaced, but rather recognized and integrated.g.  Special consideration will be made for small business.h.  Proprietary and confidential information is to be protected.

Page 15: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

A list of Recommended Standards Against Which a Company May Certify:

ASIS International SPC.1-2009 Organizational Resilience: Security Preparedness, and Continuity Management System – Requirements with Guidance for use (2009 Edition).

British Standards Institution 25999 (2007 Edition) - Business Continuity Management.(BS 25999:2006-1 Code of practice for business continuity management and BS 25999: 2007-2 Specification for business continuity management)

National Fire Protection Association 1600-Standard on Disaster / Emergency Management and Business Continuity Programs, 2007 and 2010 editions. 

15

Page 16: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

16

ANSI-ANAB

In progress - ANSI

DHS

Page 17: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

DRI/NFPA Course is proceeding with ANSI-CAP Accreditation for the Course

ANSI-CAP follows the accreditation process outlined in the international standard ISO/IEC 17011, General Requirements for Accreditation Bodies Accrediting Conformity Assessment Bodies and recognized by ANSI-ANAB

Passing the Exam will Provide a Certificate of Completion (Because training is a requirement there can be no examination only)

This Certificate will Be Required to Seek CBCA/CBCLAs

DRI International will maintain recertification through continuing education (RSBSQA requirement)

17

Page 18: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Created by Government/Industry Regulatory Bodies

Punitive◦ Fines◦ Shutdown

Subject to Annual (Operational/Financial) Audit Audit Conducted by Third Party Results are Board Issues May Create Vendor Requirements

◦ FFIEC◦ HIPPA

Page 19: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Voluntary Non-Punitive Auditable Through First, Second or Third

Parties State of Flux

◦ NFPA 1600 is the ANSI National Standard is in Revised Every 3 years

◦ ASIS/BS25999 are Currently in the Early Stages of Seeking ANSI Accreditation not Due until at Least End of 2009

◦ ISO 22399/PAS (Publicly Available Specifications) Interim State

◦ New Australian Standard◦ New Singapore Standard

Page 20: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

A Certification by an Approved Certification Body

◦ No Endorsement by DHS/FEMA or Federal Government A Distancing by DHS from the Process Private Sector Certification Bodies

◦ Available Before PS-Prep NFPA 1600 BS 25999 SS507 – SS540 Private Companies

20

Page 21: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

No Get Out of Jail Free (Safe Harbor)◦ Safety Act of 2002

No Reduction in Insurance Premiums

Does Not Exempt Regulatory Compliance

DHS Cannot Make It Mandatory – Only Legislative Action Can◦ Highly Unlikely◦ Consider Sarbanes-Oxley

21

Page 22: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Rewards

◦ May Satisfy Customer Inquiries Supply Chain RFPs

◦ Create Uniformity Multi-Nationals

◦ Increase Preparedness PS-Prep Raised Awareness of Need to Prepare

Page 23: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Risks

◦ May Not Provide Legal Protection Judge and Jury Decision No Known NFPA1600 Defense

◦ Quality of Auditors Proper Training No Control

Precludes “Any organization that provides preparedness consulting services to private sector entities”

Page 24: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Potential Conflict Financial – Operational Audit Corporate Governance Regulation

Expensive Think Sarbanes-Oxley Initial Expense Annual or bi-Annual Review REMEDIATION

Discoverable (Corrective Action Plan)

Page 25: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Focus on the Regs *

Broaden Your Viewpoint *

Keep Your Eyes on Transition *

Hold Off On (the Actual) Certification *

Walk Don’t Run *

Talk to Your General Counsel (DHS Does)

* The Standards RaceAuthor: Mark Carroll

Page 26: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

Let’s Work On Preparedness◦ Small Steps – Easily Accomplished

Page 27: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

27

•The Greater Tampa Bay Chapter would act as the organizing administrator for the training class, and the participants would pay $1745.50 to ACP – GTB.

•At the conclusion of the DRI 501 class and exam, ACP – GTB will file the appropriate paperwork with the State of Florida for an education reimbursement, and the State of Florida would pay ACP – GTB for 50% of the cost of this training / exam program – or $872.50 per participant.

•GTB – ACP would then cut a check back to each participant for $872.50. The education grant only covers the cost of training, exams, and administrative fees associated with the class. •That would bring the net cost to each participant down to $872.50 which is SIGNIFICANTLY lower than you’d pay for the program at any of the major BCP / DR conferences

•Travel, lodging, and meals would be the responsibility of each participant, and we are working with our event coordinator to find a venue which would guarantee a block room rate.

Page 28: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

28

Page 29: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

29

(1) consistent with keeping PS-Prep a voluntary program, as directed by Congress, FEMA should expressly and strongly emphasize that neither program participation nor the accreditation or certification standards establish an enforceable duty, a standard of care or any other basis for imposing civil liability;

(2) entities that are already subject to comprehensive emergency preparedness regulation under the Pipeline Safety Act, the Chemical Facility Anti-Terrorism Act, the Marine Transportation Security Act, etc., should be able to obtain PS-Prep certification solely by documenting their compliance (INGAA added that FEMA should do this accrediting the regulating agencies and instructing them to grant certification once an entity demonstrates its compliance with the emergency preparedness regulations);

(3) entities with PS-Prep certification should be considered pre-qualified for protection under the Supporting Ant-terrorism by Fostering Effective Technologies (“SAFETY”) Act of 2002, or their SAFETY Act applications should at least be accorded priority processing; and

(4) FEMA should examine and address the economic feasibility and cost considerations associated with approving the proposed PS-Prep standards and allowing PS-Prep certification through compliance with current emergency preparedness regulations.

The Interstate Natural Gas Association of America (“INGAA”)

Page 30: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

30

Page 31: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

31

• Legal

o Common law precedent would substantiate certification as a way to mitigate potential liability

o Development of statutory guidelines would provide additional legal motivation to pursue certification

o Some corporations are concerned about possible disincentives associated with certification (e.g. identification of shortfalls)

o Allowing multiple standards for certification could be legally problematic

o Using a maturity model (levels of preparedness) may make certification more compelling from a legal perspective

Page 32: 1 Boston ACP – September 8, 2010. A Non-Profit Organization Committed to: Promoting a base of common knowledge for the continuity management industry

32

Some corporations are concerned about possible disincentives associated with certification.

o There is a potential disincentive pertaining to undertaking preparedness certification and the related documentation of preparedness actions undertaken by a company, especially with respect to the identification of risks to the company and its current vulnerabilities.

o Absent some legal privilege such as attorney-client privilege or work product privilege, documents generated during the certification process could become discoverable and could be used against the company in any future litigation or investigations. That scenario functions as a disincentive to undertaking and documenting preparedness actions.

International Center for Enterprise Preparedness th The Legal Working Group On the Voluntary Business Preparedness Accreditation and Certification Program

International Center for Enterprise Preparedness (InterCEP) New York University Initial Meeting March 7, 2008