Business Continuity Plan Sample
Business Continuity Plan Sample
Purpose
The purpose of this business continuity plan is to prepare <Client> and <Client> in the event of extended service
outages caused by factors beyond our control (e.g., natural disasters, man-made events), and to restore services to
the widest extent possible in a minimum time frame. All <Client> sites are expected to implement preventive
measures whenever possible to minimize network failure and to recover as rapidly as possible when a failure occurs.
The plan identifies vulnerabilities and recommends necessary measures to prevent extended service outages. It is a
plan that encompasses all <Client> system sites and operations facilities.
1.1 Scope
The scope of this plan is limited to <describe>. This is a business continuity plan, not a daily problem resolution
procedures document.
1.3 Assumptions
Any loss of utility service (power, water), connectivity (system sites), or catastrophic event (weather, natural disaster,
vandalism) that causes an interruption in the service provided by <Client> operations. The plan identifies
vulnerabilities and recommends measures to prevent extended service outages.
See Appendix A for details on the roles and responsibilities of each team.
This plan becomes effective when a disaster occurs. Normal problem management procedures will initiate the plan,
and remain in effect until operations are resumed at the original location, or a replacement location and control is
returned to the appropriate functional management.
The Emergency Management Team and Location Response Coordinator are responsible for declaring a disaster for
Technical Services and activating the various recovery teams as outlined in this plan.
In a major disaster situation affecting multiple business units, the decision to declare a disaster will be determined by
<Client> Corporate. The Emergency Management Team/Location Response Coordinator will respond based on the
directives specified by Corporate.
1.7.3 Notification
Regardless of the disaster circumstances, or the identity of the person(s) first made aware of the disaster, the
Emergency Management Team (EMT) must be activated immediately in the following cases:
Two (2) or more systems and/or sites are down concurrently for five (5) or more hours
Five (5) or more systems and/or sites are down concurrently for five (5) or more hours
Any problem at any system or network facility that would cause either of the above conditions to be present or
there is certain indication that either of the conditions are about to occur
Corporate Public Relations personnel are designated as the principal contacts with the media (radio, television, and
print), regulatory agency, government agencies and other external organizations following a formal disaster
declaration.
Department specific data and document retention policies specify what records must be retained and for how long. All
organizations are accountable for carrying out the provisions of the instruction for records in their organization.
Technical Services follows these standards for its data backup and archiving:
Backup media is stored at locations that are secure, isolated from environmental hazards, and geographically
separate from the location housing the system.
Billing tapes
Tapes greater than three years old are destroyed every six months.
Tapes less than three years old must be stored locally offsite.
The system supervisor is responsible for the transition cycle of tapes.
To Be Determined
1.7.6 Emergency management procedures
The following procedures are to be followed by system operations personnel and other designated <Client>
personnel in the event of an emergency. Where uncertainty exists, the more reactive action should be followed
to provide maximum protection and personnel safety.
Note: Anyone not recognized by the Technical Services staff as normally having business in the area
must be challenged by the staff who should then notify security personnel.
These procedures are furnished to <Client> management personnel to take home for reference. Several pages
have been included to supply emergency contacts.
In the event of any situation where access to a building housing a system is denied, personnel should report to
alternate locations. Primary and secondary locations are listed below.
Workplace: <Name>
Workplace:<Name>
Workplace: <Name>
Workplace: <Name>
Workplace: <Name>
In the event of a major catastrophe affecting a <Client> facility, immediately notify the < Name or Title of Person>.
In the event of a fire or smoke in any of the facilities, the guidelines and procedures in this section are to be
followed.
If fire or smoke is present in the facility, evaluate the situation and determine the severity, categorize the fire
as Major or Minor and take the appropriate action as defined in this section. Call 911 as soon as possible if the
situation warrants it.
Personnel are to attempt to extinguish minor fires (e.g., single hardware component or paper fires) using
hand-held fire extinguishers located throughout the facility. Any other fire or smoke situation will be
handled by qualified building personnel until the local fire department arrives.
In the event of a major fire, call 911 and immediately evacuate the area.
In the event of any emergency situation, system site security and personal safety are the major concern.
If possible, the operations supervisor should remain present at the facility until the fire department has
arrived.
In the event of a major catastrophe affecting the facility, immediately notify the Regional Technical
Manager.
Provide them with your name, extension where you can be reached, building and room
number, and the nature of the emergency. Follow all instructions given.
Note: During non-staffed hours, security personnel will notify the Regional Technical
Manager responsible for the location directly.
Local security personnel will establish security at the location and not allow access to the site
unless notified by the Regional Technical Manager or his designated representative
6 Contact appropriate vendor personnel to aid in the decision regarding the protection of
equipment if time and circumstance permit
7 All personnel evacuating the facilities will meet at their assigned outside location (assembly
point) and follow instructions given by the designed authority. Under no circumstances
may any personnel leave without the consent of supervision.
1.7.9 In the event of a network services provider outage
In the event of a network service provider outage to any facility, the guidelines and procedures in this section
are to be followed.
2 If outage will be greater than 1 hour, route all calls via microwave or other service to
alternate location.
If it is a major outage and all carriers are down and downtime will be greater than 12 hours,
deploy satellite equipment, if available.
In the event of a flood or broken water pipe within any computing facilities, the guidelines and procedures in this
section are to be followed.
STEP ACTION
Procedure
Assess the situation and determine if outside assistance is needed; if this is the case, dial
1
911 immediately.
Immediately notify all other personnel in the facility of the situation and to be prepared to
2
cease operations accordingly.
If water is originating from above the equipment, power down the individual devices and
3
cover with protective shrouds located in the facility.
4 Water detected below the raised floor may have different causes:
— If water is slowly dripping from an air conditioning unit and not endangering
equipment, contact repair personnel immediately.
— If water is of a major quantity and flooding beneath the floor (water main break),
immediately implement power-down procedures. While power-down procedures are
in progress, evacuate the area and follow supervisor’s instructions.
This plan is intended to be a living document and as such must be reviewed on a regular basis. The plan will be
reviewed semi-annually and exercised on an annual basis. The test may be in the form of a walk-through, mock
disaster or component testing. Additionally, with the dynamic environment present within <Client>, it is important to
review the listing of personnel and phone numbers contained within the plan regularly.
The plan will be stored in a common location where it can be viewed by system site personnel and the Emergency
Management Team. Each recovery team will have its own directory with change management limited to the recovery
plan coordinator.
The Recovery Plan Coordinator will be responsible for the plan. A recovery plan coordinator will be assigned for each
company location. Their specific responsibilities are as follows:
Provide hard copy of plan to all team members. Team members must store copy at home, in a personal
car, or electronically via a hand-held device or laptop computer.
Regularly review and update information in the disaster recovery plan (e.g., contact lists, equipment
inventories). Communicate with the Emergency Management Coordinator to get up-to-date information
periodically.
Hold initial team meeting to get team members acquainted with the plan and hold annual/semi-annual
meetings to review the plan on an ongoing basis
Maintain an accurate record of the locations of alternate sites, equipment suppliers, data storage
locations, portable power generators and implementation plans.
Response and recovery checklists and plan flow diagrams are presented in the following (2) sections. The checklists
and flow diagrams may be used by Technical Services members as "quick references" when implementing the plan
or for training purposes.
If in-hours:
Upon observation or notification of a potentially serious situation during working hours at a system/facility, ensure that
personnel on site have enacted standard emergency and evacuation procedures if appropriate and notify the
Location Response Coordinator.
If out of hours:
Technical Services personnel should contact the Location Response Coordinator.
1. The Location Response Coordinator (LRC) will contact the Emergency Management Team (EMT) and
provide the following information when any of the following conditions exist: (See Appendix B for contact list)
Five or more facilities are down concurrently for five or more hours.
Any problem at any system or location that would cause the above condition to be present or there is certain
indication that the above condition is about to occur.
Location of disaster
Type of disaster (e.g., fire, hurricane, flood)
Summarize the damage (e.g., minimal, heavy, total destruction)
Emergency Command Center location and phone contact number; a meeting
location that is close to the situation, but away from the disaster scene
An estimated timeframe of when a damage assessment group can enter the
facility (if possible)
The EMT will contact the respective market team leader and report that a disaster has taken place.
Based on the information obtained, the EMT decides (with the LRC) how to respond to the event: mobilize IRT,
repair/rebuild existing site (s) with location staff, or relocate to a new facility.
If a disaster is not declared, the location response team will continue to address and manage the situation through
its resolution and provide periodic status updates to the EMT.
If a disaster is declared, the Location Response Coordinator will notify the Incident Response Team members
immediately for deployment.
Declare a disaster if the situation is not likely to be resolved within predefined time frames. The person who is
authorized to declare a disaster must also have at least one (1) backup who is also authorized to declare a disaster
in the event the primary person is unavailable.
Using the call list in (Appendix D), EMT members contact team members to inform them of the situation. If known,
advise as to when operations will be restored or what actions will be taken to restore operations.
Once a disaster is declared, the Incident Response Team (IRT) is mobilized. This recovery team will initiate and
coordinate the appropriate recovery actions. IRT members assemble at the Command Center as quickly as possible.
See Appendix E for Regional Command Center Locations.
The LRT remains at the affected site to perform a preliminary damage assessment (if permitted) and gather
information until the IRT arrives.
3.1 Conduct detailed damage assessment (This may also be performed prior to
declaring a disaster)
1. Under the direction of local authorities and/or LRC/IRT assess the damage to the affected
location and/or assets. Include vendors/providers of installed equipment to ensure that their
expert opinion regarding the condition of the equipment is determined ASAP.
NOTE: Access to the facility following a fire or potential chemical contamination will
likely be denied for 24 hours or longer.
2. Develop a Restoration Priority List, identifying facilities, vital records and equipment needed
for resumption activities that could be operationally restored and retrieved quickly
3. Develop a Salvage Priority List identifying sites and records which could eventually be
salvaged
4. Recommendations for required resources
5. Contact the EMT and decide whether the situation requires the initiation of business recovery
plans (long-term disaster months) or if work can return to the primary location (short-term
week or so).
The LRC gathers information from the IRT and other sources; contacts the EMT and provides the EMT with detailed
damage assessment information.
Based on the information obtained from the LRC, the EMT decides whether to continue to the business recovery
phase of this plan. If the situation does not warrant this action, continue to address the situation at the affected site
(s). Provide periodic status updates to the EMT Leader.
The business recovery phase of this plan will be implemented when resources are required to support full restoration
of system and/or facility functionality at an alternate recovery site (e.g., another company office, vendor hot site, cold
site) that would be used for an extended period of time.
NOTE: During the Initial Response Phase, service may be shifted to alternate sites to allow operations to begin
functioning and provide service to its customers. Initially reduced service may be provided until sites can be fully
restored. Within XX hours/xx days the system and facilities should be functional at 100%.
This section documents the steps necessary to activate business recovery plans to support full restoration of
systems or facility functionality at an alternate/recovery site that would be used for an extended period of time.
Coordinate resources to reconstruct business operations at the temporary/permanent system location, and to
deactivate recovery teams upon return to normal business operations.
The system and facility configurations for each location are important to re-establish normal operations. A list for
each location will be included in Appendix F.
4.2 Notify technical engineering staff/coordinate relocation to new facility/location
See Appendix A for Technical Engineering staff contacts associated with a new location being set up as a permanent
location (replacement for site).
Make arrangements in advance with suitable backup location resources. Make arrangements in advance with local
banks, credit card companies, hotels, office suppliers, food suppliers and others for emergency support. Depending
on the incident, its severity and alternate location option selected, contact the appropriate alternate site organization,
the local bank office and other relevant firms.
Using the call list in Appendix B, notify the appropriate company personnel. Inform them of any changes to processes
or procedures, contact information, hours of operation, etc. (may be used for media information)
Assuming all relevant operations have been recovered to an alternate site, and employees are in place to support
operations, the company can declare that it is functioning in a normal manner at the recovery location.
5. Appendixes
Note: See Appendix B for contact list. Suggested members to include: Senior management, Human
Resources, Corporate Public Relations, Legal, Information Systems, Risk Management and Operations
Charter:
Responsible for overall coordination of the disaster recovery effort, evaluation and determining disaster declaration,
and communications with senior management
Support activities:
The Emergency Management Team:
Evaluate which recovery actions should be invoked and activate the corresponding recovery teams.
Evaluate and assess damage assessment findings
Set restoration priority based on the damage assessment reports
Provide senior management with ongoing status information
Acts as a communication channel to corporate teams and major customers
Work with vendors and IRT to develop a rebuild/repair schedule
Note: See Appendix B for contact list. Recommend that the Regional Technical Managers assume this role.
Charter:
Responsible for overall coordination of the disaster recovery effort for their region, establishment of the command
center, and communications with Emergency Management Team
Support activities:
Notify the Incident Recovery Team
Gather damage assessment information and report it to EMT
Determine recovery needs.
Establish command center and related operations. The command center is a prearranged meeting facility
where EMT/LRT/IRT members meet to coordinate damage assessment and business recovery tasks for the
affected operations.
Notify all Team Leaders and advise them to activate their plan (s) if applicable, based upon the disaster
situation
If no disaster is declared, then take appropriate action to return to normal operation using regular staff.
Determine if vendors or other teams are needed to assist with detailed damage assessment.
Prepare post-disaster debriefing report
Coordinate the development of site specific recovery plans and ensure they are updated semi-annually.
Note: See Appendix B for contact list. Recommend that technicians and other suitably trained staff located
at the affected location assume this role.
Charter:
The Location Response Team (LRT) is responsible for the initial alerting/notification of the problem to the LRC during
normal business hours. During off hours, the LRT will be notified along with the LRC. In the event of a disaster
declaration, this team will become a part of the Incident Response Team.
Support activities:
Provide the following information to the LRC in the event of an outage:
a. Type of event
b. Location of occurrence
c. Time of occurrence
Note: See Appendix B for contact list. Recommend that Facility Supervisors and other suitably trained staff
assume this role. Also included in this team should be members of IT’s System Deployment group.
Charter:
The Incident Response Team (IRT) is formed to deploy to the disaster location when a disaster is declared.
Support Activities
Provide recovery support to the affected location and operations
Coordinate resumption of voice and data communications:
a. Work with management to re-route voice and data lines, especially when alternate
site (s) or alternate work locations are predefined
b. Recover voice mail and electronic mail systems when requested by EMT.
c. Verify voice mail and electronic mail are operational at the alternate site.
d. Review the <Client> Minimum Acceptable Operational Requirements checklist to
determine if sufficient resources are in place to support operations
Charter
IT Technical Support will facilitate technology restoration activities.
Support activities:
Upon notification of disaster declaration, review and provide support as follows:
1. Facilitate technology recovery and restoration activities, providing guidance
on replacement equipment and systems, as required.
2. Coordinate removal of salvageable equipment at disaster site that may be used for alternate site
operations.
Primary: Address
Room XXXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Alternate: Address
Room XXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Primary: Address
Room XXXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Alternate: Address
Room XXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Primary: Address
Room XXXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Alternate: Address
Room XXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Primary: Address
Room XXXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Alternate: Address
Room XXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
5.5.5 Emergency Command Center - <Location Name>
Primary: Address
Room XXXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Alternate: Address
Room XXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Primary: Address
Room XXXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Alternate: Address
Room XXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Primary: Address
Room XXXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Alternate: Address
Room XXX
City, State
Contact: “coordinator of rooms/space - (xxx) xxx-xxxx
Upon notification of a incident/disaster situation the On-Duty Personnel will make the initial entries into this form. It
will then be forwarded to the ECC, where it will be continually updated. This document will be the running log until the
incident/disaster has ended and “normal business” has resumed.
________________________________________________________________________
TYPE OF EVENT
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
LOCATION
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
PROJECTED IMPACT TO OPERATIONS
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
________________________________________________________________________
5.7.2 Critical equipment status form
[----------STATUS---------]
Equipment Condition Salvage Comments
Legend
Condition: OK - Undamaged
DBU - Damaged, but usable
DS - Damaged, requires salvage before use
D - Destroyed, requires reconstruction
5.8 Appendix H: Building Evacuation Information
5.11.8 Plumbing
Company Name Contact Work Mobile/Cell Phone
5.11.9 Site Security Services
Company Name Contact Work Mobile/Cell Phone