Orange County NC Website
DocuSign Envelope ID:FCC003D1-05FF-4218-868F-50402CE3790D <br /> The Professional Practices are a body of knowledge designed to assist organization in the <br /> development and implementation of a business continuity management(BCM)program. Use of <br /> the Professional Practice framework can increase the likelihood that no significant gaps will be <br /> present in your program as well as increase the likelihood that the various parts of the program <br /> will work cohesively in an actual event. Furthermore,these Professional Practices are intended to <br /> serve as both a guide for BCM Program development,implementation and maintenance and as a <br /> tool for conducting audits of an existing program. <br /> Project Initiation and Management <br /> Establishes the need for a Business Continuity Plan,including management support at all levels <br /> of the organization. It is important to organize and manage the project to completion within <br /> agreed upon time and budget limits. <br /> Risk Evaluation and Control <br /> This step determines the frequency and severity of natural,man-made, and political perils that can <br /> effect the organization and its facilities. By identifying and quantifying these exposures, controls <br /> can be implemented to mitigate them as well as provide a cost-benefit analysis to justify <br /> investment in these controls. <br /> Business Impact Analysis (BIA) <br /> Identifies the impacts resulting from a disaster by utilizing techniques that identify critical <br /> organization/departmental functions. This helps establish recovery priorities such as the number <br /> of personnel needed, the type of equipment needed, and the organizations inter-dependencies so <br /> recovery time objectives (how quickly functions need to be restored) can be set. <br /> Developing Business Continuity Strategies <br /> Selects recovery-operating strategies for business and information technologies. This includes <br /> such methods as utilization of a commercial hot-site, duplication of key records, contractual <br /> agreements, off-site storage, etc. <br /> Developing and Implementing Business Continuity Plans <br /> Designs, develops and implements the physical document that is formulated as a result of the risk <br /> evaluation and business continuity strategies that were developed/performed. <br /> Maintaining and Exercising Business Continuity Plans <br /> Develops processes to test the plan and procedures to maintain plan currency to continue the <br /> organizations ability to respond to a disaster. <br /> Emergency Response and Operations <br /> Develops and implements procedures for responding to and handling a disaster. This includes <br /> establishing and managing the Emergency Operations Center, designating a person who is in <br /> charge and a framework for dealing with the overall management of the incident. <br /> Awareness and Training Programs <br /> Develops a program to create corporate awareness and enhance the skills required developing, <br /> implementing,maintaining, and utilizing the developed plans. <br /> 12 I :I[" ; <br />