You are on page 1of 43

RSA Business Continuity

Management & Operations


Patrick Potter – Solution Manager
Patty Cutter – Product Manager

January 24th, 2013

© Copyright 2011 EMC Corporation. All rights reserved. 1


Business Continuity Management Defined

“A holistic management process that identifies potential


threats to an organization and the impacts to business
operations those threats, if realized, might cause.
BCM provides a framework for building organizational
resilience with the capability of an effective response that
safeguards the interests of key stakeholders, reputation,
brand and value-creating activities”

BSI - ISO 22301:2012

© Copyright 2011 EMC Corporation. All rights reserved. 2


Heightened Need for Effective BCM Programs
• Growing number of crisis
events and natural disasters
• Regulatory requirements for
BCM are increasing
• 24/7 service delivery
requirements
• Globalization and highly
complex supply chains
• Operational risks due to
more frequent disruptive
events

© Copyright 2011 EMC Corporation. All rights reserved. 3


Business Continuity Management Lifecycle
Align BCM Program with
Business Strategies and Perform Risk Assessments
Objectives and Business Impact
Self-Audit and Comply
with Authoritative Analyses to determine
Sources recovery priorities

Manage Crisis
Events, Activate Document BC/DR
Plans and Notify Recovery Plans,
Key Parties Test BC/DR and Crisis Strategies and Tasks
Management Plans,
Automate Plan Maintenance
and Train Key Resources

© Copyright 2011 EMC Corporation. All rights reserved. 4


RSA BCM Improves Current BCM Approach
Uncoordinated, ad hoc
Inability to prioritize Poor coordination processes Static plan Difficult to report to
recovery of processes among BC, DR and documentation by senior management
and assets based on crisis teams multiple tools that current BC/DR
criticality plans will work

Accountability Efficiency Collaboration Automation Visibility


Alignment with Crisis personnel Consistent Automated, up-to- Insight into
business priorities can efficiently processes, enabling date BC/DR plans, continuity risks and
and establishment of respond to crisis collaboration across easily accessible required budget
ownership events BC, DR and crisis during a crisis
teams event

© Copyright 2011 EMC Corporation. All rights reserved. 5


RSA Approach to BCM & Operations

How we solve Business


Problems
RSA Business
Continuity Management
& Operations

Foundation for RSA GRC Modules


any GRC Use RSA Business Continuity Management
Case RSA Enterprise Management

RSA Archer Platform featuring Mobile

© Copyright 2011 EMC Corporation. All rights reserved. 6


BCM & Operations: A Holistic Approach
Business
Crisis Management and IT Context
• Communications • Business Assets
• Activation • IT Assets
• Event Management • Prioritization, Criticality,
Operations Recovery Objectives
• Program Monitoring
• Enterprise
Management
BC/DR Planning • Visibility Risk and Impact
• Recovery Plans
Analysis
• Resources
• Business Impact Analysis
• Plan Testing
• BC Risk Assessment
• Plan Maintenance

© Copyright 2011 EMC Corporation. All rights reserved. 7


Risk and Business Impact Analysis
• BCM Risk Register helps
identify, evaluate and mitigate
risks
• Business Impact Analysis
enables evaluation of criticality
of processes and assets and
determine RPOs and RTOs
• Prioritize business processes
based on:
– Financial Impact
– Operational Impact
– Regulatory Impact
– Reputation Impact

© Copyright 2011 EMC Corporation. All rights reserved. 8


Business Continuity/Disaster Recovery
Planning
• Centrally manage BC and DR
plans
• Link plans to BCM risk
register, BIAs, IT assets and
business processes
• Link plans to call trees and
specific recovery strategies
and tasks
• Document results of BC/DR
plan tests, ownership, and
workflow

© Copyright 2011 EMC Corporation. All rights reserved. 9


Crisis Management
• Report crisis events that
occur anywhere you do
business
• Quickly capture the details of
a crisis, including the time of
occurrence, event location,
type and severity
• Communicate crisis
information and leverage
emergency notifications and
call trees
• Manage activated BC/DR
plans

© Copyright 2011 EMC Corporation. All rights reserved. 10


Operations
• Integrate with Enterprise
Management to relate BCM
components such as risks,
BIAs, recovery plans, crises
to repository of business
hierarchy and infrastructure
• Align recovery objectives with
organizational priorities by
integrating with other GRC
processes:
– Enterprise Risk Management
– Incident Management
– Third Party Management

© Copyright 2011 EMC Corporation. All rights reserved. 11


Why Our Customers Choose RSA for BCM
Centralized Platform for BCM & GRC Flexibility
All core processes required for enterprise Business users can adapt processes
governance, risk and compliance integrated to their requirements through point-
with BCM&O through one central platform and-click configuration

Comprehensive eGRC Library GRC Community site


Library of policies, controls, procedures and 8,000+ eGRC experts collaborating
assessments mapped to global regulations on challenges and trends
and industry standards (e.g. BS25999, NIMS
and ISO 22301)

Out-of-the-Box Expertise Integration


Regulations, risks, controls, best Code-free integration with
practices without the need for costly databases, spreadsheets, point
professional services solutions (e.g. Everbridge)

© Copyright 2011 EMC Corporation. All rights reserved. 12


© Copyright 2011 EMC Corporation. All rights reserved. 13
Business Continuity
Management 4 Demo

© Copyright 2011 EMC Corporation. All rights reserved. 14


RSA Archer Business Continuity Mobile
Application
• BCM Mobile Application for iPhone and iPad
enables users to view business continuity or
disaster recovery plans and associated
strategies, tasks, calling trees, and
requirements
• Key technical features:
– Secure authentication
– Off-line availability of encrypted data
– Click to call, email, and text functionality from
the app
– Regular data synchronization
– URI convenience

© Copyright 2011 EMC Corporation. All rights reserved. 15


BCM Mobile App Quote
“As a major wireless telecommunications provider, having a mobile application is
high on our list of required features for our Business Continuity and Disaster
Recovery Planning solution.

The Archer BCM mobile app gives us one more option for quickly accessing
contact and plan data while we are away from our computers.”

Business Continuity Officer


Fortune 500 Telecommunications Company

EMC CONFIDENTIAL—INTERNAL USE ONLY 16


Upcoming RSA Events

• RSA Archer GRC Roadshow – Philadelphia, Jan. 29


• Register Now: https://community.emc.com/docs/DOC-19114

• RSA Conference 2013 – San Francisco, Feb. 25 –


March 1 @ Moscone Center
• Register Now: https://community.emc.com/events/1745

EMC CONFIDENTIAL—INTERNAL USE ONLY 39


Free Friday Tech Huddle

• Join the ‘customer only’ weekly Free Friday Tech


Huddle live webcasts @ 12 ET
• Customer Support team addresses how to
troubleshoot common issues & utilize new
functionality delivered by the RSA Archer products
• Join us! https://community.emc.com/docs/DOC-18975

EMC CONFIDENTIAL—INTERNAL USE ONLY 40


RSA Archer Public Webcast – every
Thursday
 Jan 31 at 2ET: Using FedRAMP to Enable
Secure Cloud Computing
 Feb 7 at 2ET: PCI Compliance

Register on the RSA public website


http://www.emc.com/campaign/global/rsa/rsa-webcast.htm

EMC CONFIDENTIAL—INTERNAL USE ONLY 41


Where will your BCM program begin?
Learn More At…

Review BCM Case Gain Insight about


Studies BCM Regulatory
Learn more about
Requirements
Business Continuity
Management &
Operations
www.rsa.com/grc

EMC CONFIDENTIAL—INTERNAL USE ONLY 42


THANK YOU

© Copyright 2011 EMC Corporation. All rights reserved. 43

You might also like