Business Continuity Policy
Purpose and Scope
a. The purpose of this policy is to ensure that the organization establishes objectives, plans and, procedures such that a major disruption to the organization’s key business activities is minimized.
b. This policy applies to all infrastructure and data within the organization’s information security program.
c. This policy applies to all management, employees, and suppliers that are involved in decisions and processes affecting the organization’s business continuity. This policy must be made readily available to all whom it applies to.
Background
a. The success of the organization is reliant upon the preservation of critical business operations and essential functions used to deliver key products and services. The purpose of this policy is to define the criteria for continuing business operations for the organization in the event of a disruption. Specifically, this document defines:
i. The structure and authority to ensure business resilience of key processes and systems.
ii. The requirements for efforts to manage through a disaster or other disruptive event when the need arises.
iii. The criteria to efficiently and effectively resume normal business operations after a disruption.b. Within this document, the following definitions apply:
i. Business impact analysis/assessment - an exercise that determines the impact of losing the support of any resource to an enterprise, establishes the escalation of that loss over time, identifies the minimum resources needed to return to a normal level of operation, and prioritizes recovery of processes and the supporting system.
ii. Disaster recovery plan - a set of human, physical, technical, and procedural resources to return to a normal level of operation, within a defined time and cost, when an activity is interrupted by an emergency or disaster.
iii. Recovery time objective - the amount of time allowed for the recovery of a business function or resource to a normal level after a disaster or disruption occurs.
iv. Recovery point objective - determined based on the acceptable data loss in the case of disruption of operations. Policy
a. Business Risk Assessment and Business Impact Analysis
b. Disaster Recovery Plan
c. Data Backup and Restoration Plans
Last updated