GuidetoBusinessContinuityManagementFrequentlyAskedQuestionsThirdEditioniGuidetoBusinessContinuityManagement,ThirdEditionConTEnTsIntroduction....................................................................vBusinessContinuityBasics........................................................11.Whatisbusinesscontinuitymanagement(BCM)?........................................12.BCMseemstoincludemanydifferentterms,someofwhichappeartobeverysimilar.Howaretheysimilarordifferent?.....................................................13.Isthereabestpracticeapproachtobusinesscontinuityplanning(BCP)?......................24.WhatBCMelementsareincludedinITIL–specifically,ITservicecontinuitymanagement?.......25.Whatistherelationshipbetweenbusinesscontinuityandenterpriseriskmanagement(ERM)?.....3OverviewoftheRegulationsandStandardsLandscape..................................46.HowshouldregulationsandstandardsshapethedevelopmentofaBCMprogram?.............47.WhatareISO22301andISO22313?..................................................48.WhatisNFPA1600?...............................................................59.ThereisaBCPrequirementpublishedbytheU.S.SecuritiesandExchangeCommission(SEC)regardingNewYorkStockExchange(NYSE)members.AreallNYSE-listedcompaniesrequiredtofollowtheseBCPguidelines?...............................................510.DoestheHealthInsurancePortabilityandAccountabilityAct(HIPAA)includearequirementtoimplementBCMprocesses?........................................................611.DoesTheJointCommissionrequireBCMforhospitals?..................................712.WhatguidancedoestheFederalFinancialInstitutionsExaminationCouncil(FFIEC)providespecifictoBCP?.............................................................713.WhatBCMstandardsexistintheCOBITstandard?......................................814.ArethesetheonlyBCMmandatesanorganizationshouldconsider?.........................8ExecutiveManagementSupportandSponsorship.....................................1015.WhoistherightpersonintheorganizationtoowntheBCMprocess?......................1016.HowcanaBCMteamgainmanagementbuy-in?........................................1017.Howcanexecutivemanagementbe“sold”onbusinesscontinuity?..........................1118.WhatisthevaluetoanorganizationindesigninganddeployingBCMprograms?.............1219.Whatarethecriticalelementsofabusinesscontinuitypolicy?.............................1320.Howshouldaninternalbusinesscontinuityfunction/planningteambestructured?............14RiskAssessmentandBusinessImpactAnalysis(BIA)..................................1521.Whatarethemostcommonapproachestoexecutingariskassessment?......................1522.WhatarethemostcommonapproachestoexecutingaBIA?...............................1523.ShouldkeyvendorsbeincludedintheBIA?............................................1624.Whatisarecoverytimeobjective(RTO)?.............................................1625.Whatisarecoverypointobjective(RPO)?.............................................1626.Arequestionnairesnecessarywhenplanningforbusinesscontinuity?........................1727.AretherewaysaroundcompletingaformalBIAandriskassessment?........................18iiGuidetoBusinessContinuityManagement,ThirdEditionBusinessContinuityStrategyDesign...............................................1928.Whatarethekeyconsideration...