41
WHAT IT IS? GlobalCONTINUITY® explained from a practical point of view

GlobalCONTINUITY described from a practical point of view

  • Upload
    audisec

  • View
    300

  • Download
    0

Embed Size (px)

DESCRIPTION

GlobalCONTINUITY is software for the implementation, deployment and maintenance of business continuity management systems (Business Continuity Plans) based on ISO 22301. GlobalCONTINUITY only implements the standard ISO 22301? No, GlobalCONTINUITY is much more valuable because it can be used for any aspect related with Business Continuity and Disaster Recovery, Risks, BIAs, Continuity Control Panels, Crisis Management, etc. What we understand by business continuity? Those activities are taken in preparation a company for surviving disasters and for preventing them. What type of disasters? - Natural Disasters (floods, earthquakes, fire…) - Industrial Disasters. - Strikes and pandemic diseases. - Cyberattacks. - Falls of Information systems. - Internal attacks by employees. - Etc… OVERVIEW: 1. Main characteristics: Continuity objectives Meeting minutes Document Management Control Panel Users management Project Management Tasks and obligations Employees management 2.Business Impact Analysis Guided questionnaires for BIAs Automatic BIAs Consolidation of BIAs Calculation of MTPD, RTO and RPO 3.Risk Analysis & Risk Management Asset inventory Risk analysis Risk management Historical versions and reports Catalogs of risks High return on investment Risk simulation 4. Continuity Plans & Disaster Recovery Disaster scenarios Continuity plans and disaster recovery Crisis management in real time Automatic deployment of the plans Planning and implementation of tests of the plans Control Panel and follow-up of the deployment In summary: We have a platform which covers the complete cycle of the standard ISO 22301, but it can implement Continuity Plans and Disaster Recovery Plans without following requirements specified by the standard It’s flexible in methodologies. It reduces time for performing the impact analysis and risk analysis. It allows you to add the entire structure of the BCP and DRP with a high level of detail (or easier). It manages the crisis in the event of a real incident. Control panels for knowing how the system works. User-friendly software and very quick putting into operation. Additionally, the software has more options such as: Project management Document management system Management by roles of the users. Reports management. Etc. Therefore, it’s not only a platform for business continuity and disaster recovery, GlobalCONTINUITY® gives an added value.

Citation preview

  • 1. WHAT IT IS? GlobalCONTINUITY explained from apractical point of view

2. AUDISEC is a consultant company with huge experience in more than 300 companies and public administrations worldwide: Information Security, Continuity, Risks, Control PanelsGlobalSUITE: software developed according to the experience for theimplementation of risk management systems, business continuity plans, information security, etc. Moreover, it allows you to implement other standards such as ISO 27001, ISO 31000, ISO 20000, 3. GlobalSUITE: Integral Solution of Management Systems GlobalSUITE is the unique software worldwide that manages INTEGRALLY the implementation, maintenance, automation & monitoring of any management system.GlobalSUITE allows the integrated management of the entire certifications & management systems that the company have implemented previously. 4. GlobalSUITE: Integral Solution of Management SystemsGlobalSUITE is an application which encloses multiple solutions for managing and maintaining Management Systems in an integrated way.GlobalSGSI Information Security Management Systems (ISMS) (ISO/IEC 27001)GlobalCONTINUITY Business Continuity Plans (BS25999/ISO 22301 )Global20000 IT Service Management (ITSM) (ISO/IEC 20000)GlobalSGPIC Systems for the Critical Infrastructures ProtectionGlobalRISK Advanced Risks Analysis & Management (ISO31000)GlobalENS National Security Framework. (ENS in Spain)GlobalBSC Integral Control Panel Balanced ScoreCard (BSC)GlobalCOMPLIANCE Legal ComplianceGlobalLOPD Personal Data protection systemsGlobalSG Quality Management Systems (ISO 9001)GlobalSG Environmental management systems (ISO 14001)GlobalSG Occupational health and Safety Management (OSHAS 18001)Etc. 5. Large Banks in Spain and LATAM. Several public administrations and ministries departments Utilities companies and Tech companies Industrial organizations: Power, pharmaceuticals, logistics, etc. 6. Its software for the implementation, deployment and maintenance of business continuity management systems (Business Continuity Plans) based on ISO 22301. 7. GlobalCONTINUITY only implements the standard ISO 22301? 8. GlobalCONTINUITY only implements thestandard ISO 22301? No, GlobalCONTINUITY is much more valuable because it can be used for any aspect related with Business Continuity and Disaster Recovery, Risks, BIAs, Continuity Control Panels, Crisis Management, etc. 9. What we understand by business continuity? Those activities are taken in preparation a company for surviving disasters and for preventing them.What type of disasters? Natural Disasters (floods, earthquakes, fire) Industrial Disasters. Strikes and pandemic diseases. Cyberattacks. Falls of Information systems. Internal attacks by employees. Etc 10. Overview Main Characteristics Users management Project Management Tasks and obligations Employees managementGuided questionnaires for BIAs Automatic BIAs Consolidation of BIAs Calculation of MTPD, RTO and RPORisk Analysis & Risk Management Business Impact Analysis Continuity objectives Meeting minutes Document Management Control PanelAsset inventory Risk analysis Risk management Historical versions and reports Catalogs of risks High return on investment Risk simulationContinuity Plans & Disaster Recovery Disaster scenarios Continuity plans and disaster recovery Crisis management in real time Automatic deployment of the plans Planning and implementation of tests of the plans Control Panel and follow-up of the deployment 11. Im implementing a business continuity project How GlobalCONTINUITY may help me? 12. It solves common problems of this type of projects In the initial phase, it allows you to define perfectly the scope and objectives, committees and people involved, to carry out the first GAP for viewing the levels of maturity in continuity, etc. 13. It solves common problems of this type of projects. BIA (Business Impact Analysis). How develop the BIA; surveys which must be provided to several departments and people; consolidate that information, all the information must be implementedaccording to a reliable methodology, it must be performed in a reasonable time. 14. BIA in GlobalCONTINUITY Configuration of impacts, valuation levels, time scales andcriteria by each impact. Its possible to send customizable surveys to the user from the own platform or by e-mail. Consolidation of BIA for obtaining data of each process according to multiple answers. Calculation of MTPD/MAO, RTO, RPO, MBCO 15. BIA in GlobalCONTINUITYBIAs BIAsBIAsBIAsBIAsConsolidated BIABIAsBIAsBIAs 16. And the risk analysis. May I implement it in GlobalCONTINUITY? We can perform the risk analysis; customize the definition of its methodologies, identify threats, elaborate action plans, carry out the follow-up, relate them with BCP orDRP, etc. 17. How manage the risks in GlobalCONTINUITY Qualitative and quantitative methodologies or mixed.Customized definition of calculation methods. Libraries of threats which can be customized by the user.LevelsFormulasTypologies 18. Moreover, there are additional functionalities for better management of the risks: Analyze the cost of the risks through different types of cost. Perform simulations of how will be the new scenario of risks in the event of implementing the treatment plan. Carrying out a study of the return on investment of the risk treatment plans. 19. Here ends the phase of analysis and planning, Which type of value provides GlobalCONTINUITY? Process optimization in time, costs and results Way of work contrasted in hundred of companies and organizations Methodological flexibility 20. We have already completed the first phase of the project 21. DO phase, the implementation 22. DO phase: the implementation. Mainly it focuses in the implementation activities of the businesscontinuity plans (BCP), disaster recovery plans (DRP) and crisis management plans or incident management. 23. DO phase: In which contributes GlobalCONTINUITY? It divides the project in a flexible way: One BCP and several DRP One BCP One BCP y one DRPBCMS Several BCP and several DRPBCP1 Several DRPBCP2 Several BCP DRP1DRP2DRP3There is not imposed any specific structure, but its possible to follow the recommendations of the platform.DRP1 24. What level of detail has? The level of detail of GlobalCONTINUITY runs from the definition ofhigh level of the disaster scenarios and the BCP objectives to the last technical instruction. 25. It can only be used for IT continuity? No, the BCP and DRP can be focused to any area of the organizationand they includes every aspect of the business continuity.Human Resources Organizational Technical/Systems Logistics Back to normality etc 26. GlobalCONTINUITY supports continuity plans for several facilities or countries? Yes, thanks to its structure of entities and subentities, GlobalCONTINUITY can define different levels, from a corporal level to other specific facility and having a global vision of the group. 27. The continuity plans can be tested? There is a specific module for planning and implementing the test; carrying out a deep control to view how the test is evolving in real time. 28. What will happen if a real incident occur? GlobalCONTINUITY supports the crisis management and gives a visionof how the real deployment is evolving. And moreover: o Convene and coordinate the table of the crisis. o Deploy the crisis management plan. o Send automatically all the tasks inside the BCP and DRP to each person who has any responsibility, manuals, technical instructions, dependent tasks, etc. o See the remaining time according to our RTO, RPO and MTDP. 29. How can I review or improve the system? GlobalCONTINUITY provides the necessary functionality for: o Carry out Business Continuity Audits. o Manage corrective, preventive actions and non-conformities. o Manage day-to-day incidents. o Establish a control panel with objectives, metrics and indicators. 30. BUSINESS OBJECTIVES CSFINDICATORSMETRICSObj. Cont. Obj. Plan1 Indicator Cont.1Indicator Cont.2Obj. Plan2 Indicator Cont.3MetricAMetricB 31. In summary: o We have a platform which covers the complete cycle of the standard ISO 22301, but it can implement Continuity Plans and Disaster Recovery Plans without following requirements specified by the standard. 32. In summary: o We have a platform which covers the complete cycle of the standard ISO 22301, but it can implement Continuity Plans and Disaster Recovery Plans without following requirements specified by the standard o Its flexible in methodologies. 33. In summary: o We have a platform which covers the complete cycle of the standard ISO 22301, but it can implement Continuity Plans and Disaster Recovery Plans without following requirements specified by the standard o Its flexible in methodologies. o It reduces time for performing the impact analysis and risk analysis. 34. In summary: o We have a platform which covers the complete cycle of the standard ISO 22301, but it can implement Continuity Plans and Disaster Recovery Plans without following requirements specified by the standard o Its flexible in methodologies. o It reduces time for performing the impact analysis and risk analysis. o It allows you to add the entire structure of the BCP and DRP with a high level of detail (or easier). 35. In summary: o We have a platform which covers the complete cycle of the standard ISO 22301, but it can implement Continuity Plans and Disaster Recovery Plans without following requirements specified by the standard o Its flexible in methodologies. o It reduces time for performing the impact analysis and risk analysis. o It allows you to add the entire structure of the BCP and DRP with a high level of detail (or easier).o It manages the crisis in the event of a real incident. 36. In summary: o We have a platform which covers the complete cycle of the standard ISO 22301, but it can implement Continuity Plans and Disaster Recovery Plans without following requirements specified by the standard o Its flexible in methodologies. o It reduces time for performing the impact analysis and risk analysis. o It allows you to add the entire structure of the BCP and DRP with a high level of detail (or easier).o It manages the crisis in the event of a real incident. o Control panels for knowing how the system works. 37. In summary: o We have a platform which covers the complete cycle of the standard ISO 22301, but it can implement Continuity Plans and Disaster Recovery Plans without following requirements specified by the standard o Its flexible in methodologies. o It reduces time for performing the impact analysis and risk analysis.o It allows you to add the entire structure of the BCP and DRP with a high level of detail (or easier). o It manages the crisis in the event of a real incident. o Control panels for knowing how the system works. o User-friendly software and very quick putting into operation. 38. Additionally, the software has more options such as: o Project management o Document management system o Management by roles of the users. o Reports management. o Etc. Therefore, its not only a platform for business continuity and disaster recovery, GlobalCONTINUITY gives an added value. 39. Integration with other systems: o Ticketing tools. o Active directory. o Alarm Centers. o Communication tools. o Knowledge base. o Document managers. o Etc. 40. Thank you for your attention!