<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.securityprocedure.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Contingency</title>
 <link>http://www.securityprocedure.com/tag/contingency</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>Comparison between ISACA and DRII Business Continuity Plan</title>
 <link>http://www.securityprocedure.com/comparison-between-isaca-and-drii-business-continuity-plan</link>
 <description>&lt;p&gt;DRII vs ISACA Business Continuity Plan Comparison&lt;br /&gt;
&lt;IMG SRC=&quot;http://img187.imageshack.us/img187/5076/bcpzn7.png&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.isaca.org/&quot;&gt;ISACA (Information System Audit and Control Association)&lt;/a&gt; and &lt;a href=&quot;http://www.drii.org/&quot;&gt;DRII (Disaster Recovery Institute International)&lt;/a&gt; are the two organizations that have a competency to release the right procedure and step by step for Business Continuity Management. However, if you see each step from ISACA and DRII, you can find some small differences approach on it. Here is some example:&lt;/p&gt;
&lt;p&gt;ISACA Business Continuity&lt;br /&gt;
1. Project management and initiation&lt;br /&gt;
2. Business impact analysis&lt;br /&gt;
3. Recovery strategy&lt;br /&gt;
4. Plan design and development&lt;br /&gt;
5. Training and awareness&lt;br /&gt;
6. Implementation and testing&lt;br /&gt;
7. Monitoring and maintenance&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/comparison-between-isaca-and-drii-business-continuity-plan&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/comparison-between-isaca-and-drii-business-continuity-plan#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/business-impact-analysis">Business Impact Analysis</category>
 <category domain="http://www.securityprocedure.com/tag/contingency">Contingency</category>
 <category domain="http://www.securityprocedure.com/tag/disaster-recovery">Disaster Recovery</category>
 <pubDate>Fri, 15 Aug 2008 21:51:04 -0500</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">260 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>How many plans should I prepare? BCP, DRP or COOP</title>
 <link>http://www.securityprocedure.com/how-many-plans-should-i-prepare-bcp-drp-or-coop</link>
 <description>&lt;p&gt;I hate the (incompetent) IS auditor, here is the story. One day your external auditor from big 4 audit firm come checking your IT system. This guy, discuss some issue with executive level within your company. This text book auditor then asks you to prepare any document or plan in case of disaster or incident. You, in charge in IT department then asking question to the auditor.&lt;br /&gt;
“Can you explain more detail what type of document? Since I’m little bit confuse with your jargon of BCP, DRP, COOP what is the difference?”&lt;/p&gt;
&lt;p&gt;And here is the explanation, theoretically, according to NIST-SP 800-34 standard, you must prepare:&lt;/p&gt;
&lt;h3&gt;1. Business Continuity Plan (BCP)&lt;/h3&gt;
&lt;p&gt;Purpose: Provide procedures for sustaining essential business operations while recovering from a significant disruption&lt;br /&gt;
Scope: Addresses business processes; IT addressed based only on its support for business process&lt;/p&gt;
&lt;h3&gt;2. Business Recovery (or Resumption) Plan (BRP)&lt;/h3&gt;
&lt;p&gt;Purpose: Provide procedures for recovering business operations immediately following a disaster&lt;br /&gt;
Scope: Addresses business processes; not IT-focused; IT addressed based only on its support for business process&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/how-many-plans-should-i-prepare-bcp-drp-or-coop&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/how-many-plans-should-i-prepare-bcp-drp-or-coop#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/contingency">Contingency</category>
 <category domain="http://www.securityprocedure.com/tag/disaster-recovery">Disaster Recovery</category>
 <pubDate>Thu, 06 Mar 2008 09:25:27 -0600</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">56 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Review of Business Continuity Management Framework</title>
 <link>http://www.securityprocedure.com/review-business-continuity-management-framework</link>
 <description>&lt;p&gt;Recent natural disaster, such as earth quake or tsunami is true evidence that all business operation need appropriate business continuity management.  Today, there are a lot of world standard that could be followed to get the best implementation of business continuity management. From the US standard: NIST SP 800-34 to British Standard 25999. Here is simple comparison between to standard.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/review-business-continuity-management-framework&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/review-business-continuity-management-framework#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/bs25999">BS25999</category>
 <category domain="http://www.securityprocedure.com/tag/business-impact-analysis">Business Impact Analysis</category>
 <category domain="http://www.securityprocedure.com/tag/contingency">Contingency</category>
 <category domain="http://www.securityprocedure.com/tag/nist-sp">NIST-SP</category>
 <pubDate>Wed, 05 Mar 2008 23:47:27 -0600</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">54 at http://www.securityprocedure.com</guid>
</item>
</channel>
</rss>
