(1) The Business Continuity Management (BCM) Framework is an integral component of the University’s approach to effectively managing disruption-related risks. (2) This Procedure: (3) All faculties, divisions, business units and significant University functions, including regional campuses and controlled entities, are required to have Business Continuity Plans (BCPs) for their critical business functions where appropriate documented and stored on the University Enterprise Risk Management (ERM) System. (4) This Procedure informs and drives continual, effective, cross-functional, multi-level continuity planning through holistic, integrated risk management practice by: (5) Business Resilience can be considered as the state of continued, uninterrupted operation of the University. The resilience of people, assets, processes, technology and third-party providers, as well as the availability and integrity of information, is the key focus of Business Resilience. (6) The University’s Risk Appetite Statement (RAS) identifies key risks and defines the acceptable level of risk for each category. The University has “No Appetite” for business disruptions affecting critical operations but has a “High Appetite” for change that enhances resources, staff capabilities and organisational structure. (7) Business disruption, though infrequent, can arise from events such as natural disasters, pandemics, cyber-attacks, significant loss of utilities, financial or political crisis, or accidents affecting reputation of the University. (8) Business Resilience strengthens the response mechanisms, clarifies escalation criteria and establishes the chain of command during critical incidents or crises, ensuring the University meets legal, regulatory and contractual obligations. (9) Business Continuity Plans (BCPs) are created for areas with high critical functions, such as faculties, divisions, business units, and significant University functions to address identified vulnerabilities, ensuring continuity and timely recovery of critical functions. (10) The key elements of Business Resilience include: (11) This two-stage approach introduces controls (reducing the frequency and severity of a potential event) and develops responses and recovery strategies (reducing the scale and effects of an actual event). (12) Business Resilience additionally integrates emergency management, crisis management, business continuity planning, IMTS disaster recovery planning, cybersecurity response and pandemic management, based on the nature of the disruptive event and the required level of response. (13) Business Continuity Planning is a core function of Business Resilience. (14) Business Continuity Planning includes: (15) Business Continuity Planning assures the Risk, Audit and Compliance Committee, University Council, and key stakeholders of the University's capacity to recover quickly, safely, and cost-effectively from disruptions. (16) The BC Process is illustrated in Figure 2: BC process and relationship between the activities associated with managing disruption-related risk. (17) The purpose of a Business Impact Assessment (BIA) is to identify, evaluate, and prioritise the potential impacts of disruptions on an organisation's critical functions. A BIA is essential for business continuity planning, providing key information to develop impact assessment strategies, prioritise resource allocation, and ensure operational recovery and continuity. (18) The Business Impact Assessment includes: (19) Risk assessment will be conducted after business impact assessment to analyse any gaps been identified, and mitigations of vulnerabilities exposed by the business impact assessment. (20) Understand Functions and Vulnerabilities: conduct an initial risk analysis to understand university functions, critical processes, key assets, third-party dependencies, and vulnerabilities, along with the effectiveness of existing controls. (21) Systematic Risk Evaluation: perform a systematic analysis of the likelihood and potential consequences of disruptive events, applying the consequence ratings in the Risk Management Framework and Guidelines. (22) Treatment and Mitigation: evaluate disruption-related risks that require treatment, identify available treatments per the University Risk Appetite Statement, and consider improvements to reduce residual risks to acceptable levels. (23) Determining the strategy to apply to respond to a disruptive event is based on the BIA that has identified the key activities and the people, systems and resources that support them. The BIA will determine for each process the Maximum Acceptable Outage (MAO) and Recovery Time Objectives (RTO). (24) When selecting response options, consideration should be given to the following: (25) The Business Continuity Plan is set of information on how the process or function can recover from a disruption. The plan describes the processes, procedures and information required to ensure continuity of essential services during a business interruption, and to facilitate a controlled return to normal operations. (26) The BCP is designed to capture: (27) Developing a clear and effective communication and consultation strategy is a key component of managing a disruptive event. The University Crisis & Critical Incident Communication Plan (CCICP) details the protocols for managing communications in the event of a major business disruption. (28) Faculty, division, business unit or critical process specific communication strategies may be required to be outlined in the requisite BCP. It is important to note that any external communications or internal stakeholder communications must be developed in consultation with the Advancement and Communications Division and approval must follow the requirements as per the CCICP. (29) Each department or division with business continuity plans is responsible for maintaining them as part of the recovery and response processes. (30) Testing or rehearsal and evaluation of BCPs should be undertaken on a regular basis, with results documented and improvements implemented. Testing must satisfy management requirements, including: (31) Coordination and development of the annual testing program is the responsibility of the Risk, Compliance and Assurance. (32) The implementation, monitoring and review of BCPs and associated programs of work is undertaken by the University Executive Board. (33) The Table below provides a recommended methodology: (34) When a disruptive event occurs and results in the activation of the BCP’s, senior management and key personnel involved shall undertake a post-event debrief and record the observations and recommendations to inform subsequent action planning. (35) Records of post-event debriefs must be provided to the Risk, Compliance and Assurance for reporting to the University Executive Board. (36) The University has adopted a Prevention, Preparedness, Response and Recovery (PPRR) approach as the process for managing all phases before, during and after a disruptive event. This approach is outlined in Figure 3. (37) The PPRR approach applies a tiered response structure to a disruptive event to enable an integrated, scalable and consistent response to be initiated. (38) The approach identifies the following response structure: (39) The response structure is summarised in figure 4 (40) In accordance with the Delegations of Authority Policy, an extraordinary authority is effective from the time the critical incident or crisis is declared and extends for as long as the CIMT is immediately responding to the impacts of a business disruption and will cease upon disbandment of the CIMT. (41) Any decision made in accordance with this delegation must be recorded by the CIMT secretary and reported to the University Executive Board as soon as practically possible. (42) On resuming business as usual, a debrief and post incident review will be undertaken and reported to the University Executive by the Director, Risk, Compliance and Assurance. (43) Each BCP Owner is responsible for the maintenance of the BCP document and assigned BIAs in the University’s Enterprise Risk Management System, Protecht, with guidance and support available from the RAD. (44) BCPs and BIAs are to be accessible to all persons nominated by the BCP or BIA Owner and detailed on the Distribution List in the Enterprise Risk Management System, Protecht. (45) All BCP and BIA documentation is to be stored in accordance with the UOW Privacy Policy. (46) The Risk, Compliance and Assurance will have access to all BCPs and BIAs in Enterprise Risk Management System, Protecht as well as maintain a copy of the Crisis Management Plan. (47) To ensure currency and accuracy, BIAs and BCPS must be reviewed and maintained regularly (at least every 1 year) as well as after major organisational changes, the introduction of new business critical systems or after testing or training has identified that updates or improvements are required. (48) The following information and documentation are required to be reviewed at a minimum as follows: (49) Ownership of Business Continuity Management sits with the Risk, Audit and Compliance Committee (RACC) as a component of the risk management framework. (50) The University Executive Board is responsible for the provision of support in the strategic direction of recovery, including resources and infrastructure, during a business interruption and for ensuring senior management understands their BCM responsibilities. (51) The University Executive Board is responsible for the proactive management of the University’s CMP, Emergency Management Plan, IT Disaster Recovery Plan, Cyber Security Incident Response Plan and BCPs and processes. (52) The Director, Risk, Compliance and Assurance provides management oversight for all RAD activities and may become involved during a disruptive event as required by the Critical Incident Management Team and after an incident to review the adequacy of the response. (53) The impacted Senior Executive or Director, Risk, Compliance and Assurance, and if unavailable, the Senior Manager, Risk and Assurance may act as the Incident Management Coordinator for the Critical Incident Management Team. (54) The Risk, Compliance and Assurance facilitates, implements and manages all aspects of the Business Continuity Management Policy and provides support and guidance to all faculties, divisions, business units and “owners” of significant University functions. (55) The Risk, Compliance and Assurance will provide high-level support to the CIMT and/or CMT in the event of a disruptive event. Note this support includes the management and record keeping of all documentation relating to any disruptive event. (56) Faculties, divisions, business units and owners of significant University functions, have a responsibility to: (57) The LBCC is nominated as the main contact for BC matters relating to a particular BCP and has responsibility for the management and coordination of BCM for their respective business unit, including implementing and maintaining documentation, performing reviews and updates as well as facilitating training and awareness sessions to members of staff within their unit. The LBCC will provide support to the Local Recovery Team (identified in the BCP) and undertake the actions as outlined in the response plan. (58) Local Recovery Teams are responsible for the assessment of, and decision to, escalate incidents as they occur to effect recovery and restoration of normal business operations and will follow the basic steps as outlined in the BCP and as directed by the Team Leader, to manage the response actions following a disruption to a key business process. (59) The Local Recovery Team will notify a member of the CIMT and the Risk, Compliance and Assurance about a disruptive event and the decision to activate their BCP. The Local Recovery Team will provide regular status updates to the Risk, Compliance and Assurance throughout and post the disruptive event. (60) Every staff member is responsible for actively taking part in awareness and training sessions as required and for following directions provided to them by their LBCC and Local Recovery Team in the event of an incident occurring. (61) It is the responsibility of other UOW support units to ensure that sufficient information is held in the BCPs to enable the recovery of infrastructure and services that are required, within acceptable timeframes. (62) Definitions relating to BCM are detailed in the Business Continuity Management Policy. Business Continuity Management Procedure
Section 1 - Purpose
Top of PageSection 2 - Application and Scope
Section 3 - Principles
Top of PageSection 4 - Business Resilience
Section 5 - Business Continuity Planning
Section 6 - Business Continuity Process
Step 1: Business Impact Assessment (BIA)
Step 2: Risk Identification
Step 3: Response Identification and Selection
Step 4: The Business Continuity Plan
Step 5: Communication Strategy
Step 6: Training, Testing and Maintaining Plans
Step 7: BCP Activation Review
Section 7 - Linking Business Resilience Plans
Section 8 - Delegations
Section 9 - Storage, Maintenance and Review
Top of Page
Section 10 - Roles and Responsibilities
Section 11 - Definitions
View Current
This is the current version of this document. To view historic versions, click the link in the document's navigation bar.
Type of Test
Process
Participants
Timeframe
Business Continuity Plan Review
Review of the structure and content of plans and processes in the ERMS.
Local Business Continuity Coordinator and Business Function Owner of the Business Continuity Plans
Annually
Simulation / Scenario Exercise
Use of the plans and processes to simulate a theoretical response to a disruptive event
University Business Continuity Coordinator, Facilitators, Specialist Recovery Teams, Observers (as required)
Those around the organisation or those required to respond to the event based on the impacted processes, products or services or users of interconnected technologies.
Annually
Document
Review Period
Recovery Team Contact Details
Six (6) monthly
Business Continuity Management and Resilience Policy
Business Continuity Management and Resilience Guidelines
Every two (2) years or if significant business changes
Business Impact Assesment and Business Continuity Plans
Every one (1) year or if significant business changes
Emergency Management Plan
Every one (1) year or if significant business changes
Critical Incident and Crisis Management Plan
Every one (1) year or if significant business changes
Specialist recovery and incident management plans
Every one (1) year or if significant business changes in line with Crisis and Critical Incident Management Plans