23
Sanjay Verma establishing relationship RISK Management and DISASTER Recovery source: Microsoft templates

A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

Embed Size (px)

Citation preview

Page 1: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

Sanjay Verma

establishing relationship

RISK Management and

DISASTER Recovery

source: Microsoft templates

Page 2: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

DRIVERS

REGULATORY

LEGISLATIVE

BUSINESS

Good business practices source: Google images

Page 3: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

OUTCOME

source: Google images

Page 4: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

the FIVE

PRINCIPLES

Page 5: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

BUSINESS IS

KING

1

Page 6: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

source: Google images

Page 7: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

YOUR

BUSINESS

Financial Reporting

Page 8: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

RELATIONSHIP

2

Page 9: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

BUSINESS

IT

source: Google images

Page 10: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

BUSINESS PROCESS

CONTROLS

IT CONTROLS

Financial Reporting

source: Google images

Page 11: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

Risk Management Business Continuity

Management

Key Method ………….. …………..

Key Parameters ………….. …………..

Type of Incident ………….. …………..

Size of events ………….. …………..

Scope ………….. …………..

Intensity ………….. …………..

OPERATIONAL RISK

Page 12: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

Risk Management Business Continuity

Management

Key Method Risk Analysis Business Impact Analysis

Key Parameters Impact & Probability Impact & Time

Type of Incident ………….. …………..

Size of events ………….. …………..

Scope ………….. …………..

Intensity ………….. …………..

OPERATIONAL RISK

Page 13: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

3 SINGLE INTEGRATED

FRAMEWORK

Page 14: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

CRISIS MANAGEMENT

(Corporate issues)

BUSINESS CONTINUITY

(Process contingencies)

DISASTER RECOVERY

(IT system availability)

BUSINESS CONTINUITY MANAGEMENT INTEGRATION OF 3 DISCIPLINES

Page 15: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

4 ENABLING

HOLISTIC

APPROACH

Page 16: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

Business Process

Controls

IT Environment

Financial Reporting

Inte

rnal / E

xte

rnal A

ud

it

IT R

isk

& S

ecu

rity

Pro

fes

sio

nals

source: Google images

Page 17: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

Threats

Vulnerabilities

Incidents

Assets

Business Impact

exploit

causing

affecting

producing

Deterrent Controls

Preventive Controls

Detective Controls

Corrective Controls

reduces

reduces

discovers

reduces

Risk Assessment Selection of Controls

Leads to

triggers

triggers

source: http://sabsa.org

Page 18: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

SEPARATING

GOVERNANCE

& MANAGEMENT

5

Page 19: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

Department

Process #2 Process #1

Work-

station

Builds

IT

Applicat-

ions

IT

Special

Needs

Network

Drives

Special

Require-

ments

Vital

Records

Internal

Depen-

dencies

Suppliers Roles

All-Hazards Approach to “Loss of Resource Type”

People, Seats, Cost Centre, Plan Owner

Process Workflow State Worst Time,

Frequency, Criticality

source: BCM Ina Box

Page 20: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

THE INFORMATION ‘BRIDGE’

PROCESS-BY-IT SERVICES VIEW

RP

OR

TO

Ow

ner

BNZ BNZ BNZ BNZ BNZ BNZ NAB Cert NAB

LOC Auk Auk Auk Auk BNZ BNZ BNZ BNZ BNZ BNZ Mel Mel Mel Mel Mel Mel Mel Mel Mel Mel Mel Mel

Process / IT Services matrix IT S

ervi

ce N

ame

Ana

lytic

al M

arke

ting

Dat

abas

e

Enc

oder

TD

P

TR

IAD

Alp

ha O

rang

e A

lpha

FT

P/X

CO

M

Gen

esys

Ove

r10

data

base

SD

R ta

gs

SIG

dat

abas

e

AP

AQ

Pac

k

B2K

BIS

BR

AIN

S

BT

Z

CD

S

CIF

CLS

ser

ver

Con

nect

ivity

Con

nex

CP

S

Name of Critical Process Name of Sub-Process MAO

Payments / Clearing and Settlement

Obligations

Cards Settlements Credit Card Issuing 24g g g g

Cards Settlements Merchant Acquiring 24g g g

Cards Settlements EFTPOS Debit Cards 24g g

Cards Settlements ATM Settlement 24g g

Retail Interchange

Inward & Outwards

Interchange positions 24g

Retail Interchange

Same day Cleared

Payments (Assured Value

Payments) 24g g g

Retail Interchange

Cheque and Lodgement

Processing 24g

Retail Interchange Direct Debit Processing 24g g g

Retail Interchange Direct Credit / Bill Payment 24g g

Retail Interchange Automatic Payments 24g g

Retail Interchange Foreign Cash 24g

Retail Interchange Dishonours 24g g g g g

BRIDGING

GAPS

Process #2

Process #1

“CORE” of RISK MANAGEMENT

source: BCM Ina Box

Page 21: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

source: Google images

Page 22: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

No COMPANY can make a profit

without taking risk

Taking RISKS without consciously managing it can

lead to the downfall of organisations

Risk PROFESSIONALS

are divided as to how to determine

risk appetite

Page 23: A CIO’s Perspective: Reconciling Risk Management with Disaster Recovery Tactics by Sanjay Verma

Thank You