Search the web
Sign In
New User? Sign Up
discussbusinesscontinuity · Business continuity management
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Hear how Yahoo! Groups has changed the lives of others. Take me there.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Downtime Costs   Message List  
Reply | Forward Message #6076 of 6519 |
Re: American Standard Body to produce Standard for Business Continuity

Rather than a point by point response, I'd like to share my 2 cents
on the subject of BCP standards both as an auditor and as a
practitioner.
First of all, I've never met an external auditor I couldn't
bamboozle. I've always worked for small or small-end medium sized
companies. The big accounting firms send out their trainees to
conduct the audit. It's not hard to pass an audit with or without
standards.
Second, each industry and/or country has its own regulatory agencies
and set of rules and laws. They bear scant resemblance to each other
beyond the spelling of BCP. They are not going to give up their turf
any time soon. Some (maybe most) companies are not under BCP
regulations at all.
Third, these are very difficult economic times. Most companies want
to know what they need to do to be in compliance with their
individual regulatory agency (if any). There are industry regulators
that require a BC Plan, but don't know what that is. Question: do
you have a plan? Answer: yes. Next question.
I have had my best success selling a solid mitigation and
preparedness plan including exercises not because a regulator said we
had to or because a standard said we had to, but because it makes
good business sense. Standards may assist the BCP practitioner in
making good choices, but they will never lead to management
commitment. For that, you have to know what you are talking about
and present a solid business case for spending the resources. It has
to make sense.




Mon Jan 12, 2009 7:20 pm

rcrossjr
Offline Offline
Send Email Send Email

Forward
Message #6076 of 6519 |
Expand Messages Author Sort by Date

Our company has just merged with another larger company of the same type. We are a chain of retail/wholesale auto parts stores. I have been asked to determine...
Perschke, Bill
cskdrman
Offline Send Email
Dec 18, 2008
4:46 pm

Good Morning Bill That is a difficult problem.  First, I suggest conducting a BIA to determine which applications directly impact/generate revenue, to include...
B C
bobc1512004
Offline Send Email
Dec 18, 2008
5:24 pm

I agree with Bob Cohen on where to start, but you may want to have the requestor of the downtime figures explain more about what they are looking for. Being...
Bill Lang
wrlang1977
Offline Send Email
Dec 21, 2008
8:30 am

You need to do a Business Impact Analysis for the systems at that location.   First you need to determine what applications run from there, then find out from...
Phil
pstottmfc
Online Now Send Email
Dec 23, 2008
11:23 am

Thank you all for your responses to my request for help on this. Your responses were great and extremely helpful. Is anyone else in disbelief that we are...
Perschke, Bill
cskdrman
Offline Send Email
Jan 5, 2009
11:19 am

Source : http://www.continuityforum.org/news/0906/ASIS American Standard Body to produce Standard for Business Continuity ASIS Online...
john_fernandes@...
john_s_ferna...
Online Now Send Email
Jan 7, 2009
6:54 am

I read BSI 25999-1 and BSI 25999-2.   I found them both lacking in everything but price. For my money, NFPA 1600 (and variations on that theme) do a better...
John Glenn, CRP
jglenncrp
Offline Send Email
Jan 7, 2009
10:45 am

John I completely agree with you.  If ASIS is going through this (in my opinion) unnecessary effort because they feel NFPA isn't auditable, seems to me their...
B C
bobc1512004
Offline Send Email
Jan 7, 2009
8:54 pm

What is it with this "one size fits all" mentality we are developing? Like the organisations, and sub sections within these organisations, that we service,...
Howard Kenny
howardkenny
Offline Send Email
Jan 7, 2009
8:54 pm

A few questions I'd like to pose to the forum based on what others think about the flurry of Standards being developed. 1 .. Will BCM become a better value...
Howard Kenny
howardkenny
Offline Send Email
Jan 11, 2009
2:18 pm

Rather than a point by point response, I'd like to share my 2 cents on the subject of BCP standards both as an auditor and as a practitioner. First of all,...
rcrossjr
Offline Send Email
Jan 12, 2009
9:10 pm

Thanks to everyone who took the time to provide their views and input into this discussion. Obviously there are 3 sides - yes, standards are always a good...
Howard Kenny
howardkenny
Offline Send Email
Jan 20, 2009
7:42 am

  Maybe the broad BCM should include a class to qualify auditors. Perhaps the leading certifying organisations could develop (if they have not already) an...
John Glenn, CRP
jglenncrp
Offline Send Email
Jan 20, 2009
7:29 pm

Hi Howard. Comments below. A few questions I'd like to pose to the forum based on what others think about the flurry of Standards being developed. 1 .. Will...
Bill Lang
wrlang1977
Offline Send Email
Jan 11, 2009
6:28 pm

... Not necessarily. If the standard is a good one, then it will improve overall BCP efforts. However, just because something is a standard doesn't make it a...
aj4ad
Offline Send Email
Jan 19, 2009
2:12 pm
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help