Thank you all for your responses to my request for help on this. Your responses were great and extremely helpful. Is anyone else in disbelief that we are...
Michael - I hope you adding content to the thread and not my comment. You are corrent, the best idea is to keep it off site and i believe John was relying...
I read BSI 25999-1 and BSI 25999-2. I found them both lacking in everything but price. For my money, NFPA 1600 (and variations on that theme) do a better...
John I completely agree with you. If ASIS is going through this (in my opinion) unnecessary effort because they feel NFPA isn't auditable, seems to me their...
What is it with this "one size fits all" mentality we are developing? Like the organisations, and sub sections within these organisations, that we service,...
A few questions I'd like to pose to the forum based on what others think about the flurry of Standards being developed. 1 .. Will BCM become a better value...
Hi Howard. Comments below. A few questions I'd like to pose to the forum based on what others think about the flurry of Standards being developed. 1 .. Will...
Rather than a point by point response, I'd like to share my 2 cents on the subject of BCP standards both as an auditor and as a practitioner. First of all,...
Hi Peter, I was the only one copied, so I'm forwarding it with your good comments and some of my own of course. I think there's a difference of opinion on what...
I wanted to pose a basic but important question to the group. What is the best way to arrive at an RPO (recovery point Objective) for an application. Based on...
The businesses must determine the maximum amout of data loss they can accept. In a shared data environment, the "worst case" drives the rest. Having written...
John: Isn't the real job to collect all the data, understand the issues and then present to Sr Management? SR management may have started out with a set of...
Its a usual problem with most users where they think they can't afford to loose any data (even if all they work on is management report/ MI related work).. I...
I'm in agreement with both John and Howard. I think they are saying similar things in different ways (the ever present difficulty interpreting the written...
Most business managers first think that they must have an RPO of point-of- interruption, but quickly change their minds when they see the associated costs. In...
Agreed. Â Normal SOP is for the planner to present the planner's opinion with options for mgt. Â I got the impression this was not acceptable in this...
... Not necessarily. If the standard is a good one, then it will improve overall BCP efforts. However, just because something is a standard doesn't make it a...
In addition to what others have opined, Pradeep, my bit is
Include 'the Business' into 'the Senior Management'
(its just by the way you have written, I am...
I think the answer to the question "What is the best way to arrive at an RPO (recovery point Objective) for an application" lies in a correct BIA. The cost of...
This information, as well as the RTO, should come out of a Business Impact Analysis. Â In the process of conducting the BIA, the Business Management of...
Thanks to everyone who took the time to provide their views and input into this discussion. Obviously there are 3 sides - yes, standards are always a good...
G'day Pradeep The key questions I use to help the business pragmatically determine this is "Can the data/transaction be recreated?"(if no then RPO=0; If so,...
Hi I too agree with many of you here. 1. The first aspect is that IT always supports the business, so ultimately business objectives are most important....
Dear Members The debate on RTO and in particular RPO have raised some very interesting issues. With a huge variation of interpretation and understanding across...
Wow - this is what I get for not checking email in a few days. Anyway, here's my two cents' worth: Calculating RPOs and RTOs points directly to the BIA. ...
 Maybe the broad BCM should include a class to qualify auditors. Perhaps the leading certifying organisations could develop (if they have not already) an...
Some thoughts: First, make sure they understand data loss and RPO. In many cases, people don't understand the concept of data loss. My experience is that...
Hi, I am currently undertaking a dissertation in the final year of my degree which focuses on poor implementation rates of business continuity (BC)in SME's and...
Dear Paul, Here are the barriers to BC implementation in SMEs that I have observed: 1. Complete lack of awareness of what BC is about, coupled with a ...