t rin rR ep fo ot N lia er at M pl e
Sa
m
ISO 22301 Business Continuity Management Foundation release 1.0.0 PARTICIPANT HANDBOOK
e Portfolio
rR ep
Classroom course, release 1.0.0
rin
ISO 22301 Business Continuity Management Foundation,
t
Copyright
Copyright and Trademark Information for Partners/Stakeholders.
ot
fo
Copyright Š 2013 ITpreneurs. All rights reserved.
l-
N
Please note that the information contained in this material is subject to change without notice. Furthermore, this material contains proprietary information that is protected by copyright. No part of this material may be photocopied, reproduced, or translated to another language without the prior consent of ITpreneurs Nederland B.V.
Sa
m
pl e
M
at
er
ia
The language used in this course is US English. Our sources of reference for grammar, syntax, and mechanics are from The Chicago Manual of Style, The American Heritage Dictionary, and the Microsoft Manual of Style for Technical Publications.
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
t
Follow Us
rin
Before you start the course, please take a moment to:
rR ep
“Like us” on Facebook http://www.facebook.com/ITpreneurs
fo
“Follow us” on Twitter
ot
http://twitter.com/ITpreneurs
l-
http://gplus.to/ITpreneurs
N
"Add us in your circle" on Google Plus
ia
"Link with us" on Linkedin
at
er
http://www.linkedin.com/company/ITpreneurs
"Watch us" on YouTube
Sa
m
pl e
M
http://www.youtube.com/user/ITpreneurs
Copyright © 2013, ITpreneurs Nederland B.V. All rights reserved.
1
rin
t
his pl pae geM haa steb reiea nl l -efNt b loan t fk int or ent i R ona ep lly
m T
Sa
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
rR ep
rin
t
Contents
Day 1
-------------------------------------------------------------
5
Day 2
-------------------------------------------------------------
67
-------------------------------------
N/A
----------------------------------
125
ot
Appendix B: Exercises List
fo
Appendix A: Case Study
139
Appendix D: Release Notes ---------------------------------
149
Participant Feedback Form ----------------------------------
151
Sa
m
pl e
M
at
er
ia
l-
N
Appendix C: Correction Key for Exercises ---------------
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
3
rin
t
his pl pae geM haa steb reiea nl l -efNt b loan t fk int or ent i R ona ep lly
m T
Sa
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
Sa
m
pl e
M
at
er
ia
l-
N
ot
fo
rR ep
rin
ISO 22301 Business Continuity Management Foundation
t
Day 1
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
5
rR ep
1
rin
t
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
fo
DAY
l-
N
ot
Certified ISO 22301 Foundation
er
Section 1
ia
Certified ISO 22301 Foundation Training
at
Course objectives and structure
M
a. Meet and greet
b. General Information
pl e
c. Training objectives d. Educational approach
Sa
m
e. Examination and certification f. PECB g. Schedule for the training
2
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
6
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
Activity
N
ot
fo
rR ep
rin
t
Meet and greet
l-
3
M
at
er
ia
General Information
Use of a computer and access to the Internet
Smoking area
Sa
m
pl e
Use of mobile phones and recording devices
Timetable and breaks
Meals
Absences 4
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
7
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
Training Objectives
Explain the components and the operation of a Business Continuity Management System based on ISO 22301 and its principal processes
rR ep
1
rin
t
Acquiring knowledge
Understand the goal, content and correlation between ISO 22301 and ISO 22313 as well as with other standards and regulatory frameworks
fo
2
Understand the concepts, approaches, standards, methods and techniques for the implementation and effective management of a BCMS 5
l-
N
ot
3
ia
Educational Approach
Sa
m
pl e
M
at
er
Students at the center
6
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
8
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
7
l-
N
ot
fo
rR ep
z Candidates who met all the prerequisites for certification will receive a certificate:
rin
z The exam only contains essay questions. The duration of the exam is one hour. The minimum passing score is 70%
t
Exam and Certificate
ia
ISO 22301 Foundation
1 2 3 4
Pass the exam Adhere to the PECB Code of Ethics No professional experience required No business continuity experience required
Sa
m
pl e
M
at
er
Prerequisites for certification
ISO 22301 Foundation 8
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
9
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
What is PECB?
Main services:
N
ot
fo
rR ep
1. Certification of personnel (Auditor and Implementer) 2. Certification of training organizations 3. Certification of trainers
rin
t
Professional Evaluation and Certification Board
l-
9
ia
Customer Service
1. Submit a complaint
M
at
er
Comments, questions and complaints
Training Provider
Participant
Sa
m
pl e
2. Answer in writing
4. Final arbitration
3. Appeal PECB
10
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
10
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
Sa
m
pl e
M
at
er
ia
QUESTIONS?
11
l-
N
ot
fo
rR ep
rin
t
Schedule for the Training
12
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
11
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
Certified ISO 22301 Foundation Training
t
Section 2
rin
Standard and regulatory framework
rR ep
a. What is ISO? b. Fundamental ISO principles c. Management system standards d. Business Continuity standards e. ISO 22301 and ISO 27001
fo
f. Certification schema and process
er
ia
What is ISO?
13
l-
N
ot
g. ISO 22301 advantages
ISO is a network of national standardization bodies from over 160 countries
z
The final results of ISO works are published as international standards
pl e
M
at
z
Over 19 000 standards have been published since 1947
Sa
m
z
14
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
12
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
Management System Standards
ISO 22000
ISO 20000 IT Service
ISO 22301
ISO 27001
Business continuity
Information Security
rin
OHSAS 18001 Health and Safety at work
ISO 28000
Supply Chain Security
15
Sa
m
pl e
M
at
er
ia
l-
N
ot
Food Safety
ISO 14001 Environment
rR ep
Quality
fo
ISO 9001
t
Primary standards against which an organization can be certified
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
13
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
Sa
m
pl e
M
at
er
ia
l-
N
ot
fo
rR ep
rin
ISO 22301 Business Continuity Management Foundation
t
Day 2
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
67
rR ep
2
rin
t
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
fo
DAY
l-
N
ot
Certified ISO 22301 Foundation
er
Section 9
ia
Certified ISO 22301 Foundation Training
at
Business continuity strategy
M
a. Strategy model for business continuity b. Analysis and selection of the Strategy
pl e
c. Constraints affecting the Strategy choice
Sa
m
d. Comparaison of the main BC strategy options
2
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
68
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
Requirements
rin
rR ep
8.3 Business continuity strategy 8.3.1 Determination and selection Determination and selection of strategy shall be based on the outputs from the business impact analysis and risk assessment.
t
ISO 22301, clause 8.3.1
fo
The organization shall determine an appropriate business continuity strategy for: a) protecting prioritized activities; b) stabilizing, continuing, resuming and recovering prioritized activities and their dependencies and supporting resources; and c) mitigating, responding to and managing impacts.
The determination of strategy shall include approving prioritized time frames for the resumption of activities.
3
l-
N
ot
The organization shall conduct evaluations of the business continuity capabilities of suppliers.
The objective of Strategy Selection is to assist in defining the action items needed to protect the organization and to select the most appropriate recovery solutions for critical business functions and supporting resources
M
at
z
er
ia
Definition of the Strategy Model
In the selection of a strategy, you must weigh the cost of being without the service at various points in time (the duration of the outage) against the cost of the solution. The objective is to minimize the total cost of the impact and the solution
Sa
m
pl e
z
4
Copyright Š 2013, ITpreneurs Nederland B.V. All rights reserved.
69
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
Strategic Business Continuity Models
t
3 basic models This traditional BC model is based on an ‘active’ operating site with a corresponding backup site. This includes both data processing and operations. The model relies on relocating staff from the active to the backup site and maintaining backup copies of technology and data.
rR ep
1
rin
Active/Backup Model
Active/Active (Split Operations) Model
2
This emerging BC model relies upon two or more widely separated (geographically) ‘active’ operational sites for Mission Critical Activities that inherently backup for one another.
This BC model provides a variation of the ‘Active/Backup’ and ‘Active/Active’ models where a backup site periodically functions as the primary site for a period of time.
N
ot
3
fo
Alternate Site Model
l-
5
ia
Analysis of the BC Strategy Options
X. Mirror site
M
C O S T
at
er
Available BC strategies and the RTO they satisfy
IX. Hot site
Sa
m
pl e
O F S T R A T E G Y
VIII. Relocation in other group cilities facilities VII. ote Remote ng working VI. Warm rm site
V. Reciprocall agreementt
IV. Mobile e site
III. Cold d site
II. Rebuilt and restoration
I. No S Strategy
TIME OF RECOVERY 6
Copyright © 2013, ITpreneurs Nederland B.V. All rights reserved.
70
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
t
No strategy defined
rin
No documentation for business recovery and continuity Data are not sent off-site, and there is no alternate site identified ¾ Strategy used by organizations with high risk appetite or for a site with low criticallity; also, can be seen where a product has a limited life span
rR ep
Caracteristics
I. No Strategy
Advantages
Disadvantages
The most expensive strategy after a disaster…
N
ot
fo
The least expensive strategy to implement
l-
7
er
at
Strategy focus mainly on insurance Documentation of the material assets and facilities Data are not sent off-site, and there is no alternate site identified ¾ Strategy used by organizations with moderate risk appetite or for a site with low critically
Sa
m
pl e
M
Caracteristics
ia
II. Rebuild and Restoration
Advantages
Disadvantages
Low cost strategy and easy to implement Protection against the financial loss for physical assets
Strategy usually does not take in consideration the business processes and immaterial assets Strategy does not include a plan to ensure continuity of operation during a disaster
8
Copyright © 2013, ITpreneurs Nederland B.V. All rights reserved.
71
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
Ready for equipment but no computer hardware on site Communications links may or may not be ready ¾ Strategy used by organizations with moderate risk appetite or for a site with low critically
rin
t
Facility with electrical power, Heating Ventilation and Air Conditioning (HVAC)
rR ep
Caracteristics
III. Cold Site
Advantages
Disadvantages False sense of security
Fast to implement
Length of time for recovery can be long depending of the complexity of the technology and equipment used by the organization
fo
Low cost Easy to maintain
N
ot
Service provider may oversell processing capabilities
l-
er
at
Trailer that can be quickly transported to an alternate site Can be preconfigured with servers, desktop computers, communications equipment, microwave and satellite data links ¾ Useful alternative when there are no recovery facilities in the geographic area
pl e
M
Caracteristics
ia
IV. Mobile Site
9
Advantages
Sa
m
Low cost Fast to implement
Disadvantages Capacity of the equipment can be insufficient for the need
Easy to maintain Flexibility
10
Copyright © 2013, ITpreneurs Nederland B.V. All rights reserved.
72
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
Agreement by both parties, assumes sufficient capacity in time of need (Big Assumption) ¾ Should only be considered if no other options, or perfect partner with compatible technology environment
t rin
Arrangement with another company with similar hardware or software configurations
rR ep
Caracteristics
V. Reciprocal Agreement
Advantages
Disadvantages
Highly unlikely the capacity will exist
If processing requirements are similar it may be workable
Severely limits responsiveness and support
N
ot
fo
Low or no cost
l-
er
at
Facility with electrical power, Heating Ventilation and Air Conditioning (HVAC) and communication link Workstations and printers are available but software may not be installed
M
Caracteristics
ia
VI. Warm Site
11
pl e
¾ Strategy used by organizations with moderate or low risk appetite or for a site with low or medium critically Advantages
Disadvantages
Location – since less control required sites can be more flexible
Service provider may oversell processing capabilities
Sa
m
Cost – much less than hot
12
Copyright © 2013, ITpreneurs Nederland B.V. All rights reserved.
73
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
¾ Strategy used by small organizations or for some business units
t rin
Includes the concept of “working from home” and working from other noncorporate locations e.g. hotels
rR ep
Caracteristics
VII. Remote Working
Advantages
Disadvantages
No cost
Due to security and confidentiality issues this option is not always suitable
fo
Flexible solution
N
ot
Difficult to coordinate for large organizations
l-
13
er
at
In case of a disruptive incident of an organizational division, the relocation will be done in another facillity of the same organization
M
Caracteristics
ia
VIII. Relocation in other group facilities
pl e
¾ Strategy used by large organizations with several facillities
Advantages
Disadvantages
Sa
m
Cost can be low to medium
Does not have an assurance that the capacity will exist when needed
Easy to implement In most case, compatibility of the technology
Resource contention during disaster
Quick response to activate
14
Copyright © 2013, ITpreneurs Nederland B.V. All rights reserved.
74
ISO 22301 Business Continuity Management | Foundation | Participant Handbook
¾ Strategy used by organizations with very low risk appetite or for a site with high critically
rin
Workstations and servers are kept up to date
t
Applications are installed on the servers and workstations
rR ep
Caracteristics
IX. Hot Site
Advantages
Disadvantages
24/7 availability, exclusivity of use
Expensive Requires constant maintenance of hardware, software, data and applications Security of hot site, primary site security must be duplicated
fo
Immediately available
15
Sa
m
pl e
M
at
er
ia
l-
N
ot
Supports short and long term outages
Copyright © 2013, ITpreneurs Nederland B.V. All rights reserved.
75