PP1 Policy & Program Management Flashcards

1
Q

What is a business continuity policy?

A

Key document that sets out purpose, context, scope, and governance of the BC programme.

The policy “provides intentions and direction of an
organization as formally expressed by its top management.” (Source: ISO 22301:2012)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When to use an interim structure and plan?

A

In large or complex organisation, where fully scoped BC programme may take months to complete, an interim response structure and plan may be sensible temporary measure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

General principles to be considered when

creating or revising BC policy (7):

A
  1. Provide STRATEGIC DIRECTION for BC programme
  2. Define way organisation will APPROACH BC and how programme will be structured and resourced.
  3. Supported, approved and owned by TOP MANAGEMENT.
  4. State how supports strategic objectives of organisation.
  5. Appropriate to size, complexity and type of organisation.
  6. Identify standards or guidelines used as benchmark
  7. COMMUNICATED and made available to all interested parties.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Steps required to develop effective BC policy are (10):

A
  1. Agree definition and objectives
  2. Agree scope of BC programme.
  3. Identify and agree on standards or guidelines
  4. Review and conduct gap analysis
  5. Draft new or revised policy.
  6. Review draft policy
  7. Circulate draft policy for consultation
  8. Amend draft policy
  9. Facilitate approval and signoff of policy
  10. Ensure approved policy is communicated
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The business continuity policy should include (8):

A
  1. Definition of BC for use in organisation.
  2. Statement of governance and leadership commitment
  3. Defined objectives and scope for BC programme.
  4. Roles and responsibilities for BC programme including an incident response capability.
  5. References to relevant policies, standards,and legal and regulatory requirements.
  6. Identification of interested parties.
  7. Agreed methods and frequency for measurement and review of all stages of BC lifecycle.
  8. Agree methods for sign-off and communication of policy and all programme activities.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

BC policy should be regularly reviewed at pre-agreed intervals or following significant changes, including (5):

A
  1. Change in organisation’s approach to risk
  2. Change in market conditions.
  3. An acquisition, merger, or disposal.
  4. Changes to products or services
  5. Changes to legal or regulatory requirements.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Reviewing or auditing BC policy, following should be demonstrated (6):

A
  1. Top management ensured policy is communicated
  2. Policy is effective.
  3. Policy clearly states what measurable deliverables of the BC programme are.
  4. Clear TOP MANAGEMENT commitment
  5. Clear and documented ongoing commitment to BC and continual improvement.
  6. Opportunities for adapting to change can be identified.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

General principles to consider when determining scope of the BC programme (4):

A
  1. Definition of scope of programme ensures clear
    understanding of which areas of organization are
    included and excluded.
  2. Understanding of organization’s strategy, objectives,culture, operating environment, and approach to risk.
  3. Understanding of outsourced activities and suppliers of products and services.
  4. Understanding of BC programme as ongoing process.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Process to determine scope of business continuity programme (4):

A
  1. Establish steering group
  2. Define and document relevant products and services
  3. Consider requirements for delivery
  4. Consider requirements of other related policies
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Definition of Products and Services:

A

Beneficial outcomes provided by organization to

its customers, recipients and interested parties…” (Source: ISO 22301:2012)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Decisions on products and services to include in scope may be prompted by (4):

A
  1. Products which make significant contribution to the
    organization’s reputation, income, or success.
  2. Customer contractual requirement.
  3. Legal or regulatory requirement.
  4. Physical threats, eg. proximity to other industrial
    premises such as a chemical manufacturing plant or hazards such as flooding.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Reasons product or service may be excluded from scope include (2):

A
  1. Nearing end of life (and would be terminated if disrupted).
  2. Low margins or low volumes (could be terminated or externally sourced if disrupted).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Deciding whether to exclude product or service, following issues should be considered (5):

A
  1. Financial loss.
  2. Interested parties who may be impacted by loss
  3. Reputational damage
  4. Impact on legal or regulatory requirements.
  5. Needs and expectations of customers and other interested parties.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Methods and techniques used to define scope of BC programme include (5):

A
  1. Cost beneft analysis.
  2. Strengths, Weaknesses, Opportunities and Threats (SWOT) analysis.
  3. Benchmarking against appropriate standards or guidelines.
  4. Market analysis techniques.
  5. Business impact analysis (BIA) and risk assessment (if already been conducted).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Governance for business continuity primarily focuses on (5):

A
  1. Providing oversight and support
  2. Ensuring BC programme aligns with organization’s objectives.
  3. Ensuring BC programme complies with policy and related legal and regulatory requirements.
  4. Monitoring and reviewing BC programme regularly to ensure requirements are being met.
  5. Supporting continual improvement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Establishing governance for BC requires the

following (6):

A
  1. Understanding of organizational structure,
  2. Clear definition of authority and accountabilities relating to BC
  3. Identification of key performance indicators
  4. Defined BC information to report
  5. Outline of type and frequency of reporting and communication.
  6. Alignment of governance of BC programme with
    overall governance framework of organization.
17
Q

Leadership and commitment to BC policy and programme can be achieved using the following methods (8):

A
  1. Recognising and communicating requirement for BC as key management discipline
  2. Ensuring that BC policy and programme is aligned to objectives of organization.
  3. Ensuring that BC programme delivers expected outcomes
  4. Maintaining support for BC policy and programme.
  5. Ensuring individuals undertake activities.
  6. Providing resources required to implement policy
  7. Directing and supporting continual improvement of BC
  8. Providing direction and guidance to embed BC
    into business as usual routines.
18
Q

In defining governance, organization’s top management should agree (5):

A
  1. What needs to be measured and monitored.
  2. How this should be achieved.
  3. Methods for monitoring, measuring, analysing,and
    evaluating.
  4. When monitoring and measuring should be performed
  5. When monitoring and measuring results should be analysed and evaluated

To do this, top management should:

  1. Act to address areas of weakness or gaps in BC programme objectives.
  2. Monitor effectiveness of programme.
  3. Ensure that relevant information is retained as evidence of results.
19
Q

Purpose of assigning roles and responsibilities

A

Ensure tasks required to implement and maintain BC programme allocated to specific, competent
individuals whose performance can be evaluated and where further training requirements can be identified.

20
Q

By assigning member top management overall

accountability for BC and effectiveness, organisation ensures that (3):

A
  1. BC recognised as key activity in organisation.
    2 Implementation will be achieved through collaboration with other related disciplines.
  2. Appropriate response roles and responsibilities will be defined based on competency
21
Q

Skills and competencies required in roles identified as part of BC programme:

Top management

A

Provide leadership, commitment and resources as part of governance.

22
Q

Skills and competencies required in roles identified as part of BC programme:

Steering group

A

Oversee, advise, and manage BC programme, making recommendations,and reporting to top management

23
Q

Skills and competencies required in roles identified as part of BC programme:

Business continuity plan owner

A

Ensure BC plan adequately reflects organization’s BC

capability.

24
Q

Skills and competencies required in roles identified as part of BC programme:

Business continuity professional

A

Develop and deliver effective BC programme. This includes facilitation and coordination of plans throughout the organisation.

25
Q

Skills and competencies required in roles identified as part of BC programme:

Incident response personnel

A

Respond to incident or crisis

26
Q

Skills and competencies required in roles identified as part of BC programme:

Departmental representative

A

Communicate implications of departmental changes that may impact BC programme.
Collect information for BIA.
Develop, implement, and maintain departmental plans on behalf of the plan owner.
Conduct and participate in exercises.

27
Q

Skills and competencies required in roles identified as part of BC programme:

All personnel (7)

A
  1. Acknowledge roles and responsibilities during incident
  2. Recognise incident or crisis.
  3. Alert incident or crisis responders
  4. Escalate action to incident or crisis management team.
  5. Respond appropriately to specific threats.
  6. Respond appropriately when evacuated from site.
  7. Understand relevant plans and associated roles and responsibilities.
28
Q

Skills and competencies required in roles identified as part of BC programme:

Interested parties

A

Act where relevant within the BC programme or in response to incident.

29
Q

Outcome of assigning roles and responsibilities as part of

BC policy and programme management are:

A
  1. Clearly defend roles and responsibilities assigned to
    competent individuals and teams.
  2. Appropriate authority assigned as relevant to the role.
  3. Roles and responsibilities, and authorities documented in BC policy.
  4. Alternates for each role identified.
  5. Responsibilities included in individuals’ job descriptions and communicated to interested parties
30
Q

BC programme definition

A

BC programme is ongoing management and governance process supported by top management and
appropriately resourced to implement and maintain BC
continuity management.” (Source: ISO 22301:2012)

31
Q

Documentation in BC programme has three purposes (3):

A
  1. Help manage BC programme effectively.
  2. Demonstrate effective management of programme.
  3. Enable prompt and effective response to incident
32
Q

To implement and manage BC programme, the BC

professional or team, in consultation with top management should (9):

A
  1. Develop BC management programme
  2. Identify appropriate activities
  3. Coordinate appropriate activities within organization
  4. Manage change and coordinate with other areas of
    organization
  5. Promote benefits of programme through communication
  6. Manage programme budget.
  7. Maintain and manage programme documentation.
  8. Ensure relevant legal and regulatory requirements identified and considered
  9. Report to top management
33
Q
Examples of projects included as part of BC
programme are (3):
A
  1. Developing and managing exercise programme.
  2. Developing and delivering training and awareness activities.
  3. Selecting suppliers to deliver defined product or service
34
Q

Following should also be considered when managing BC programme (6):

A
  1. Relevant industry sector specific good practice
  2. Self-assessment against relevant standard/legislation
  3. Relationships with suppliers or providers of outsourced activities
  4. Financial management and budgetary requirements.
  5. Legal and regulatory advice.
  6. Internal and external audits (where appropriate).
  7. Reviews and change management requirements
35
Q

A BC management programme consists of (8):

A
  1. BC policy.
  2. Definition of objectives of BC for the organization.
  3. Clearly defend scope.
  4. Definition of governance and leadership commitment.
  5. Roles and responsibilities.
  6. References to relevant policies, standards, and regulatory requirements.
  7. Identification of interested parties, including outsourced service providers.
  8. Method for review, measurement, sign-off and
    communication.
  9. Ongoing budget commitment and financial support.
36
Q

BC programme documentation should include the following (17)

A
  1. BC policy.
  2. BC programme of activities.
  3. Project management documentation.
  4. BC team meeting agendas, minutes, action trackers.
  5. Skills and competency requirements and records.
  6. Training and awareness activities.
  7. BIA questionnaires and information.
  8. Risk assessment.
  9. Papers supporting choice of BC solutions.
  10. Response structure.
  11. BC plans.
  12. Crisis management plans.
  13. Exercise programme.
  14. Exercise reports.
  15. Service level agreements with customers and suppliers.
  16. Contracts for outsourced service provider recovery services, including workspace and salvage.
  17. Maintenance and review programme and reports.
37
Q

Sections in PP1 Policy and Programme Management (5):

A
  1. BC POLICY
  2. Scope BC PROGRAMME
  3. Establishing GOVERNANCE
  4. Assigning ROLES AND RESPONSIBILITIES
  5. The BC PROGRAMME
38
Q

PP1 Policy and Programme Management Professional Practice Definition (3):

A
  1. Establishes policy relating to BC.
  2. Defines policy should be implemented through ongoing cycle of activities within BC programme.
  3. Governance is established, roles and responsibilities are assigned and programme is developed, implemented and maintained.