Business Recover Plan (BRP)--LEVEL 3 (Management & Recovery Team Assessment and Evaluation For Effectiveness) |
Y |
N |
N/A |
- Has the business officer and management team approved the BRP?
|
|
|
|
- Does the business owner maintain:
- The master copy of the BRP?
- An audit trail of the changes made to a BRP?
|
|
|
|
- Do all aspects of physical and logical security at the alternate site conform with your current security procedures?
|
|
|
|
- Are the physical and logical security at the alternate site at least as stringent as the security at the disaster location?
|
|
|
|
- Have all employees and their alternates responsible for executing a manual work-around for a mechanized process been identified in the BRP and properly trained?
|
|
|
|
- Has an independent observer documented the simulation exercise(s) noting all results, discrepancies, exposures, action items, and individual responsible, etc.?
|
|
|
|
- Was a debriefing held within a reasonable period of time (typically two weeks) after the simulation exercise(s) to ensure all activities have been accurately recorded?
|
|
|
|
- Did the exercise coordinator publish a simulation exercise(s) report within a reasonable period of time (typically three weeks) after the completion of the simulation exercise(s)?
|
|
|
|
- Did the exercise report include:
- what worked properly as well as any deficiencies and recommendations for improvement?
- responsiblity and due date for the development of the Corrective Action Plan?
|
|
|
|
- Was a Corrective Action Plan developed by the Exercise Team to address any deficiencies identified by the exercise?
|
|
|
|
- Is there a retention plan for the Exercise Plans and Corrective Action Plans (minimum retention 3 years)?
|
|
|
|
- Has a walk-through element exercise been performed at least quarterly?
|
|
|
|
- Did each walk-through element exercise have a prepared plan which includes:
a) Description
b) Scope
c) Objective
|
|
|
|
- When there is a change in hardware, software, or a process that might impact the Business Recovery Plan, is the BRP reviewed and updated within 30 days of the changes:
Sign-Off By Officer:
by whom? Name:____________________________
When? Date:_____________________________
|
|
|
|
- Based on the Joint Assessment has the Team determined that the BRP is effective?
|
|
|
|