business continuity dcv chile april 2013. vision evolution vision objectives main definitions sgcn...
TRANSCRIPT
Business ContinuityDCV ChileApril 2013
2
3
4
Business Continuity Management. Vision
→ The Operational Continuity is a strategic axis for DCV development.
→ DCV’s goal is to “be the last component of the financial system to stop operating and the first to recover”, regardless of the incident or disaster.
→ To protect the life and physical integrity of the Company’s Collaborators and of the people who are in our premises at the moment of an incident.
Business Continuity Management System
Business Continuity Plan
Crisis and Disaster Management Plan
5
Business Continuity Management. Progress
Start of efforts toward operational continuity
Start of efforts toward operational continuity
Contingency procedural tests
Contingency procedural tests
Contingency plan for all resources and
critical services
Contingency plan for all resources and
critical services
Y2K Plan
Y2K Plan
Business Continuity Plan (BCP) New
Methodology. The function is created
Business Continuity Plan (BCP) New
Methodology. The function is created
Reformulation toward a SGCNReformulation toward a SGCN
Incorporation of DRP+CMP
Incorporation of DRP+CMP
BCP Updating and Maintenance
BCP Updating and Maintenance
Establishment of DCV
Establishment of DCV
Establishment of DCV Registros
Establishment of DCV Registros
BS 25999 Standard is issued
BS 25999 Standard is issued
Production sites are moved to TIER III
Production sites are moved to TIER IIICustody and
registry of IRF transactions
Custody and registry of IRF
transactions
Custody and Registry of IIF
transactions
Custody and Registry of IIF
transactions
Custody and Registry of IRV
transactions
Custody and Registry of IRV
transactions
Intraday Clearing House
Intraday Clearing House
DVP, FLI Operations
DVP, FLI Operations
DematerializationDematerialization
DCV Progress SGCN Progress
Distribution of offices in two buildings
Work Plan according to BS25999 standard
Work Plan according to BS25999 standard
ForwardForward
Site in USASite in USA
EuroclearEuroclear
MilaMila
SADE WebSADE Web
Agreement with DTCC
Agreement with DTCC
Electronic Position Certificate
Electronic Position Certificate
ACSDA Leadership Forum (ALF)
ACSDA Leadership Forum (ALF)
6
7
Business Continuity Management. Policy
→ To ensure the availability of critical processes and compliance with the regulations.
→ To provide guidelines on the roles and obligations of the business continuity management.
→ To recover the critical services, safeguarding the people’s protection and security.
→ To ensure the availability of critical processes and compliance with the regulations.
→ To provide guidelines on the roles and obligations of the business continuity management.
→ To recover the critical services, safeguarding the people’s protection and security.
Objectives
→ Safeguard the security of all the people who are in DCV premises.
→ Align the governing law requirements as per the guidelines of the BS 25999 standard.
→ Continuity issues must be incorporated to DCV’s culture.
→ Safeguard the security of all the people who are in DCV premises.
→ Align the governing law requirements as per the guidelines of the BS 25999 standard.
→ Continuity issues must be incorporated to DCV’s culture.
Main Definitions
8
9
Business Continuity Management. Corporate Governance
Board
Disaster Recovery and Crisis Management
IT Committee Audit and Risk Committee
Risk Management
Information Security
Operational Risk
Business Continuity
Continuity Plans Activation
Processes Owners Emergency Committees
Spokesman Crisis Management Committee (CMC)
Premises Recovery Committee
People Support Committee
Technology Recovery Committee
Communications (internal and external)
Committee
Organizational and Functional Structure
10
11
Business Continuity Management. Strategies
12
Business Continuity Management. BS25999 Certification Project
13
Shows the interested parties that our business is performed efficiently.Meets the expectations of organizational resilience.Shows that we have set the best continuity practices on the leading edge of our business.Helps manage risks for the proper functioning of the business, ensuring its survival.
Benefits
JULJUL OCTOCT NOVNOV
BSI Audit BSI Audit
2012DECDEC JANJAN
BSI Audit
KPMG Internal
Audit
Deloitte Internal
Audit
2013AUGAUG
Management Committee
Revision
Audits and revisions timeline
MAYMAY
BSI Audit
NOVNOV
BSI Audit
JANJAN2014
MAYMAYMARMAR JUNJUN
ISO 22301 becomes effective
Management Committee
Revision
Management Committee
Revision
Management Committee
Revision
14
Saturday 27-02 Sunday 28-02 Monday 01-03
T02/27/2010 03:34 hrs.
03:45 Business Continuity Official gets in touch with Security personnel within the premises.
07:00 Contact with the Office Recovery Committee.
09:00 Office Recovery Committee visits DCV.There are no structural damages, detecting only damages in partition walls, wall covering and detachment of external glass.
10:00 Telework IT Service Verification
14:00 Technology Recovery Committee visits CIENTEC Production Site.Services are reduced as precaution.
Ongoing Report to Management. Situation status.
12:00 Technology Recovery Committee verifies Services and activates SARA and SADE.
13:00 Connectivity tests with interested parties. BCCH – BVS – COMBANC.
17:00 Technology Recovery Committee visits ENTEL Production Site.
17:45 Services checkup.
19:00 IT Services activated in both Production sites.
20:00 Situation Status reported to Board Members.
Assessment and Analysis of the Situation
Activation and Communication
09:00 Registry of collaborators and critical personnel distribution in alternate building.
09:30 Critical personnel shifts activation.
11:00 DCV situation status reported to interested parties.
17:00 Registry of personnel available at their work posts and contact with absent personnel. (15 people absent, 4 of them out of Santiago).
17:00 Internal publication of list of critical personnel and work stations assigned.
Terremoto Cronología
Activated Continuity Plan
Business Continuity Management. T27F Chronology
Difficulties in communication through mobile phones and landlines 15
Plan de MejorasCorto plazo
Monitoring improvement. More coverage through automatic tools and generation of manual commands.
3rd Site. From being an information backup site (Concepción, CHILE) to being a fully operational Production Site (USA).
Independent Electric Power. Keep the power unit in continuous operation and independent autonomy capacity.
Anti-explosion pad implementation. In meeting rooms and offices.
Security. Improve exit way signage and autonomous emergency lights. Anchoring of the false ceiling, air conditioning and lights.
Premises
IT Infrastructure
Business Continuity Management. Learnt lessons
Training. Implementation of a training and awareness program (psychologists, experts, best practices, competences, role playing modeling exercises).
Contact Information. Registry of collaborators’ contact information, as well as of special medical requirements.
Communication Plan. Strengthening of the strategy of communication to interested parties.
Alternate communication equipment. Acquisition of alternative equipment to mobile telephony. NEXTEL.
Civil Protection. Floor leaders program and strengthening of basic security kit.
Human Resources
16
Plan de MejorasCorto plazoBusiness Continuity Management. Learnt lessons.
Disaster Recovery Site (SRAD)
17
Phase I Phase II
Business ContinuityDCV ChileApril 2013
Thanks!!