Re: [discussbusinesscontinuity] Standards for Business Continuity
Maybe the broad BCM should include a class to qualify auditors. Perhaps the leading certifying organisations could develop (if they have not already) an "auditor" certification that certifies that the auditor can do more than simply spell "BC." Auditors can be very beneficial to our efforts.
John Glenn, MBCI
Enterprise Risk Management/Business Continuity
--- On Mon, 1/19/09, Howard Kenny <howard@...> wrote:
From: Howard Kenny <howard@...> Subject: [discussbusinesscontinuity] Standards for Business Continuity To: discussbusinesscontinuity@yahoogroups.com Date: Monday, January 19, 2009, 3:11 PM
Thanks to everyone who took the time to provide their views and input into this discussion.
Obviously there are 3 sides - yes, standards are always a good thing; no, standards provide little practical benefit; and maybe, depending what they say and how good the content is and the ability for benefits to be achieved for the business.
Let's hope those developing the current set of proposed standards are experienced, competent and pragmatic enough to know the difference!
We must never lose sight of the fact that BCM is all about the Business. It is never about making an auditors job easier, comparing capabilities or satisfying pride through competition and nefarious comparisons.
If, on the day of need, the Plan does not deliver what the Plan needs to deliver, we have failed.
Howard ____________ _____ Howard Kenny MBCI Australia
Our company has just merged with another larger company of the same type. We are a chain of retail/wholesale auto parts stores. I have been asked to determine...
Good Morning Bill That is a difficult problem. First, I suggest conducting a BIA to determine which applications directly impact/generate revenue, to include...
I agree with Bob Cohen on where to start, but you may want to have the requestor of the downtime figures explain more about what they are looking for. Being...
You need to do a Business Impact Analysis for the systems at that location. Â First you need to determine what applications run from there, then find out from...
Thank you all for your responses to my request for help on this. Your responses were great and extremely helpful. Is anyone else in disbelief that we are...
I read BSI 25999-1 and BSI 25999-2. I found them both lacking in everything but price. For my money, NFPA 1600 (and variations on that theme) do a better...
John I completely agree with you. If ASIS is going through this (in my opinion) unnecessary effort because they feel NFPA isn't auditable, seems to me their...
What is it with this "one size fits all" mentality we are developing? Like the organisations, and sub sections within these organisations, that we service,...
A few questions I'd like to pose to the forum based on what others think about the flurry of Standards being developed. 1 .. Will BCM become a better value...
Rather than a point by point response, I'd like to share my 2 cents on the subject of BCP standards both as an auditor and as a practitioner. First of all,...
Thanks to everyone who took the time to provide their views and input into this discussion. Obviously there are 3 sides - yes, standards are always a good...
 Maybe the broad BCM should include a class to qualify auditors. Perhaps the leading certifying organisations could develop (if they have not already) an...
Hi Howard. Comments below. A few questions I'd like to pose to the forum based on what others think about the flurry of Standards being developed. 1 .. Will...
... Not necessarily. If the standard is a good one, then it will improve overall BCP efforts. However, just because something is a standard doesn't make it a...