(1) This Procedure was approved by the Vice-Chancellor on 27 August 2014. (2) This Procedure is pursuant to the Business Continuity Policy and includes the following schedule: (3) This Procedure outlines the steps required to comply with the Business Continuity Policy. (4) This Procedure applies across the University. (5) Refer to the Business Continuity Policy. (6) This Procedure outlines the methodology that will be utilised to design, develop, implement and manage business continuity across the University. This methodology aligns with the international standard AS/NZ ISO022301:2012 Societal security - Business continuity management systems and best practice for business continuity. Guidance documents, templates and training materials will be provided by the Business Continuity Advisor for each step outlined in this procedure. (7) A Business Impact Analysis (BIA) will be the primary information collection and assessment tool in the development of Business Continuity Plans (BCP). The BIA process: (8) The information captured and assessed via the BIA process is then used to develop BCPs with ICT requirements provided to Deakin eSolutions for ICT Recovery analysis and planning. (9) Development of BCPs provides a pre-defined and management approved course of action to be initiated in response to an operational disruption. (10) BCPs should document the information required to perform critical activities should the normal operating environment be unavailable and must include: (11) BCPs should: (12) Exercising BCPs provides training and management assurance of continuity capability. No matter how well designed and thought-out the business continuity or ICT Recovery Plan may seem, realistic and robust exercising will reveal areas requiring attention. (13) Exercises can be used for: validating policies, plans, procedures, RTOs, training, equipment, and inter-organisational agreements; clarifying and training personnel in roles and responsibilities; improving inter-organisation coordination and communications; identifying gaps in resources and ICT services; improving individual performance; identifying opportunities for improvement and controlled opportunity to practice improvisation. (14) Exercising of business continuity and ICT Recovery Plans will be scheduled to occur annually. A debrief session will be held following each exercise with results and recommendations to address issues documented for action. (15) A disruption to operations could result in activation of one or multiple plans affecting one or more locations. (16) The Business Continuity System coordinates the activation of the BCP, and directs the communications, response and recovery process required to return to normal business. (17) BCPs could be activated in isolation from other emergency management processes; this will depend on the extent and geographical spread of the incident. (18) The University will utilise emergency and crisis management procedures and protocols for command, coordination and communication of emergencies. (19) ICT Recovery is a component of the University's overall business continuity capability; it provides for the timely recovery and restoration of ICT systems, including applications and data resources that support critical activities should the primary data centre experience a significant disruption. (20) ICT Recovery will utilise the Deakin eSolutions IT Critical Incident Process to manage all critical incidents including escalation to ICT Recovery events. (21) ICT Recovery is managed in accordance with the Business Continuity Policy and Deakin eSolutions ICT Recovery framework and guidelines. The ICT Recovery Framework includes: (22) ICT Recovery Plans must be: (23) In addition to the Accountabilities listed in the Business Continuity Policy, (24) For the purpose of this Procedure:Business Continuity Procedure
Section 1 - Preamble
Top of PageSection 2 - Purpose
Section 3 - Scope
Section 4 - Policy
Section 5 - Procedure
Business Impact Analysis
Business continuity plan development and maintenance
Exercising
Activation
ICT recovery
Accountability and responsibilities
Top of Page
Section 6 - Definitions
View Current
This is not a current document. To view the current version, click the link in the document's navigation bar.