View Current

Business Continuity Management Procedure

This is the current version of this document. To view historic versions, click the link in the document's navigation bar.

Section 1 - Purpose

(1) The Business Continuity Management (BCM) Framework is an integral component of the University’s approach to effectively managing disruption-related risks.

(2) This Procedure:

  1. defines the methodology and continuity planning process for mitigating the impact a disruptive events on the University’s critical business functions;
  2. outlines the escalation process for incidents and invocation of Business Continuity Plans; and
  3. establishes resilience and response capabilities to safeguard people, operations, and the University’s reputation during disruption.
Top of Page

Section 2 - Application and Scope

(3) All faculties, divisions, business units and significant University functions, including regional campuses and controlled entities, are required to have Business Continuity Plans (BCPs) for their critical business functions where appropriate documented and stored on the University Enterprise Risk Management (ERM) System.

Top of Page

Section 3 - Principles

(4) This Procedure informs and drives continual, effective, cross-functional, multi-level continuity planning through holistic, integrated risk management practice by:

  1. linking corporate governance, risk management, business continuity planning and creating a resilient and responsive organisation in response to the “Business Disruption” organisational risk;
  2. investing time, capital, tools and techniques to ensure BCM is a fully embedded, auditable process;
  3. ensuring the BCM is sufficiently flexible to meet the challenges of scalability, different University stakeholder profiles and various geographical needs coupled with governance, regulatory and legal regimes;
  4. assisting the management of events that require information and resource coordination across multiple business functions and/or campuses; and
  5. creating a culture of resilience where the business continuity capabilities of the University is reflective of the needs, technology, structure and reputation of its operations.
Top of Page

Section 4 - Business Resilience

(5) Business Resilience can be considered as the state of continued, uninterrupted operation of the University. The resilience of people, assets, processes, technology and third-party providers, as well as the availability and integrity of information, is the key focus of Business Resilience.

(6) The University’s Risk Appetite Statement (RAS) identifies key risks and defines the acceptable level of risk for each category. The University has “No Appetite” for business disruptions affecting critical operations but has a “High Appetite” for change that enhances resources, staff capabilities and organisational structure.

(7) Business disruption, though infrequent, can arise from events such as natural disasters, pandemics, cyber-attacks, significant loss of utilities, financial or political crisis, or accidents affecting reputation of the University.

(8) Business Resilience strengthens the response mechanisms, clarifies escalation criteria and establishes the chain of command during critical incidents or crises, ensuring the University meets legal, regulatory and contractual obligations.

(9) Business Continuity Plans (BCPs) are created for areas with high critical functions, such as faculties, divisions, business units, and significant University functions to address identified vulnerabilities, ensuring continuity and timely recovery of critical functions.

(10) The key elements of Business Resilience include:

  1. Proactive Element:
    1. Risk Recognition – disruption risk identified and transferred to the CPIA;
    2. Risk Reduction – risk treatments/controls introduced to reduce the likelihood of disruption;
  2. Contingent Element:
    1. Response – plans incorporating mitigation of the effects and scale of a disruptive event.
    2. Recovery – identifying recovery strategies, locations, resources, staff and dependencies.

(11) This two-stage approach introduces controls (reducing the frequency and severity of a potential event) and develops responses and recovery strategies (reducing the scale and effects of an actual event).

(12) Business Resilience additionally integrates emergency management, crisis management, business continuity planning, IMTS disaster recovery planning, cybersecurity response and pandemic management, based on the nature of the disruptive event and the required level of response.

Top of Page

Section 5 - Business Continuity Planning

(13) Business Continuity Planning is a core function of Business Resilience. 

(14) Business Continuity Planning includes:

  1. an understanding of the University mission, objectives, critical processes and functional dependencies, prioritisation process, resource requirements and external supply/contract arrangements
  2. performance of a risk assessment to identify, analyse and evaluate the probability, consequences and appetite of the problems that may arise from a disruptive event;
  3. development of a pre-defined, pre-tested, management approved Business Continuity Plan (BCP) that can be executed in response to a disruptive event; and
  4. regularly rehearsing and testing the BCP to ensure designated staff validate its currency, confirm their competence, and test assumptions around resource accessibility.

(15) Business Continuity Planning assures the Risk, Audit and Compliance Committee, University Council, and key stakeholders of the University's capacity to recover quickly, safely, and cost-effectively from disruptions.

Top of Page

Section 6 - Business Continuity Process

(16) The BC Process is illustrated in Figure 2: BC process and relationship between the activities associated with managing disruption-related risk.

Step 1: Business Impact Assessment (BIA)

(17) The purpose of a Business Impact Assessment (BIA) is to identify, evaluate, and prioritise the potential impacts of disruptions on an organisation's critical functions. A BIA is essential for business continuity planning, providing key information to develop impact assessment strategies, prioritise resource allocation, and ensure operational recovery and continuity.

(18) The Business Impact Assessment includes:

  1. Identify Critical Business Functions: determine essential business functions and assets, forming the basis for prioritising recovery efforts;
  2. Assess and Qualify Impacts: Evaluate potential impacts and downtime tolerance in University operations and guidelines recovery time and point objective; 
  3. Quantify Downtime Tolerances: by assessing the potential financial and operational impacts of disruptions, this information guides recovery time objectives (RTOs) and recovery point objectives (RPOs) in the development of recovery strategies;
  4. Prioritise Recovery and Resource Allocation: prioritise recovery efforts and allocate resources effectively based on function criticality and dependencies; and
  5. Develop Strategies and Plans: inform the development of risk mitigation, disaster recovery, and business continuity strategies and plans.
  6. Enhance Awareness and Support Decision Making: increase awareness of vulnerabilities, risks, aiding informed decision making and fostering a culture of resilience.

Step 2: Risk Identification

(19) Risk assessment will be conducted after business impact assessment to analyse any gaps been identified, and mitigations of vulnerabilities exposed by the business impact assessment.

(20) Understand Functions and Vulnerabilities: conduct an initial risk analysis to understand university functions, critical processes, key assets, third-party dependencies, and vulnerabilities, along with the effectiveness of existing controls.

(21) Systematic Risk Evaluation: perform a systematic analysis of the likelihood and potential consequences of disruptive events, applying the consequence ratings in the Risk Management Framework and Guidelines.

(22) Treatment and Mitigation: evaluate disruption-related risks that require treatment, identify available treatments per the University Risk Appetite Statement, and consider improvements to reduce residual risks to acceptable levels.

Step 3: Response Identification and Selection

(23) Determining the strategy to apply to respond to a disruptive event is based on the BIA that has identified the key activities and the people, systems and resources that support them. The BIA will determine for each process the Maximum Acceptable Outage (MAO) and Recovery Time Objectives (RTO).

(24) When selecting response options, consideration should be given to the following:

  1. the nature of the disruptive events that the operations may be exposed to;
  2. available workarounds or alternative procedures for completing the activity to a minimal acceptable level until recovery is possible, note this should include associated costs;
  3. insurance options (replace rather than salvage);
  4. third party arrangements and dependencies, including available supply chains and vendor management;
  5. critical periods or events;
  6. internal resource capabilities, including human resources and assets;
  7. accessibility of data and systems; and
  8. the option to do nothing; if no workaround is available or there is risk appetite for loss in this regard.

Step 4: The Business Continuity Plan

(25) The Business Continuity Plan is set of information on how the process or function can recover from a disruption. The plan describes the processes, procedures and information required to ensure continuity of essential services during a business interruption, and to facilitate a controlled return to normal operations.

(26) The BCP is designed to capture:

  1. management of the immediate consequences of a disruptive event;
  2. recovery strategies and operational options;
  3. communication and command lines, individual welfare;
  4. key tasks and reference information;
  5. plan invocation method;
  6. appointment of business continuity and recovery team members, meeting locations/ communications;
  7. schedules for recording key information, actions taken and tasks that need to be performed; and
  8. up-to-date stakeholder contact details.

Step 5: Communication Strategy

(27) Developing a clear and effective communication and consultation strategy is a key component of managing a disruptive event. The University Crisis & Critical Incident Communication Plan (CCICP) details the protocols for managing communications in the event of a major business disruption.

(28) Faculty, division, business unit or critical process specific communication strategies may be required to be outlined in the requisite BCP. It is important to note that any external communications or internal stakeholder communications must be developed in consultation with the Advancement and Communications Division and approval must follow the requirements as per the CCICP.

Step 6: Training, Testing and Maintaining Plans

(29) Each department or division with business continuity plans is responsible for maintaining them as part of the recovery and response processes.

(30) Testing or rehearsal and evaluation of BCPs should be undertaken on a regular basis, with results documented and improvements implemented. Testing must satisfy management requirements, including:

  1. verification of the effectiveness of the current plans;
  2. provision of training opportunities to key staff;
  3. highlighting any deficiencies in both the plans and staff awareness; and
  4. identification and implementation of remedial actions.

(31) Coordination and development of the annual testing program is the responsibility of the Risk, Compliance and Assurance.

(32) The implementation, monitoring and review of BCPs and associated programs of work is undertaken by the University Executive Board.

(33) The Table below provides a recommended methodology:

Type of Test
Process
Participants
Timeframe
Business Continuity Plan Review
Review of the structure and content of plans and processes in the ERMS.
Local Business Continuity Coordinator and Business Function Owner of the Business Continuity Plans
Annually
Simulation / Scenario Exercise
Use of the plans and processes to simulate a theoretical response to a disruptive event
University Business Continuity Coordinator, Facilitators, Specialist Recovery Teams, Observers (as required)
Those around the organisation or those required to respond to the event based on the impacted processes, products or services or users of interconnected technologies.
Annually

Step 7: BCP Activation Review

(34) When a disruptive event occurs and results in the activation of the BCP’s, senior management and key personnel involved shall undertake a post-event debrief and record the observations and recommendations to inform subsequent action planning.

(35) Records of post-event debriefs must be provided to the Risk, Compliance and Assurance for reporting to the University Executive Board.

Top of Page

Section 7 - Linking Business Resilience Plans

(36) The University has adopted a Prevention, Preparedness, Response and Recovery (PPRR) approach as the process for managing all phases before, during and after a disruptive event. This approach is outlined in Figure 3.

(37) The PPRR approach applies a tiered response structure to a disruptive event to enable an integrated, scalable and consistent response to be initiated.

(38) The approach identifies the following response structure:

  1. Emergency:
    1. local Emergency Teams immediately respond to protect people, assets, infrastructure, operations and/or services;
    2. impact to a small number of people, single building and/or University process;
    3. activated locally through Emergency Management Plan, Campus Emergency Response Procedures, Standard Operating Procedures
  2. Critical Incident:
    1. initial Critical Incident Response activated, as per the Critical Incident Management Plan and coordinated by the Incident Management Coordinator;
    2. critical Incident Management Team convenes as per the Critical Incident Management Plan (CIMP) to assess the severity and level of response required;
    3. impact may be upon multiple operations, buildings and processes and/or requires a controlled and UOW coordinated response;
    4. the Chair of the Critical Incident Management Team will provide updates and a final report outlining the incident response, Business Continuity Plan activations and any ongoing risk treatments to the Risk, Audit and Compliance Committee;
    5. the CIMT(membership includes the Vice-President Operations, and/or Deputy Vice-Chancellor (Education), Chief Communications and Marketing Officer, Director, Risk, Compliance and Assurance; and, affected faculty/division head.
  3. Crisis:
    1. Crisis Management Team (CMT) will be activated by the Chief of Staff at the direction of the Chair of the CIMT, as per the Crisis and Critical Incident Management Plan;
    2. CMT convenes as per the Crisis Management Plan to provide strategic leadership to the CIMT;
    3. the CMT is activated when the disruptive event threatens UOW’s strategic objectives, reputation or viability;
    4. the CMT membership includes: Vice-Chancellor and President (Chair), the Chair of CIMT, Chief Communications and Marketing Officer, Chief of Staff, and Executive Lead(s) for affected areas.
  4. Crisis Governance Group:
    1. when the risk warrants, the Chair of CMT may convene the Crisis Governance Group (CGG), a group that represents the University Council to advise them of the crisis.

(39) The response structure is summarised in figure 4

Top of Page

Section 8 - Delegations

(40) In accordance with the Delegations of Authority Policy, an extraordinary authority is effective from the time the critical incident or crisis is declared and extends for as long as the CIMT is immediately responding to the impacts of a business disruption and will cease upon disbandment of the CIMT.

(41) Any decision made in accordance with this delegation must be recorded by the CIMT secretary and reported to the University Executive Board as soon as practically possible.

(42) On resuming business as usual, a debrief and post incident review will be undertaken and reported to the University Executive by the Director, Risk, Compliance and Assurance.

Top of Page

Section 9 - Storage, Maintenance and Review

(43) Each BCP Owner is responsible for the maintenance of the BCP document and assigned BIAs in the University’s Enterprise Risk Management System, Protecht, with guidance and support available from the RAD.

(44) BCPs and BIAs are to be accessible to all persons nominated by the BCP or BIA Owner and detailed on the Distribution List in the Enterprise Risk Management System, Protecht.

(45) All BCP and BIA documentation is to be stored in accordance with the UOW Privacy Policy.

(46) The Risk, Compliance and Assurance will have access to all BCPs and BIAs in Enterprise Risk Management System, Protecht as well as maintain a copy of the Crisis Management Plan.

(47) To ensure currency and accuracy, BIAs and BCPS must be reviewed and maintained regularly (at least every 1 year) as well as after major organisational changes, the introduction of new business critical systems or after testing or training has identified that updates or improvements are required.

(48) The following information and documentation are required to be reviewed at a minimum as follows:

Document
Review Period
Recovery Team Contact Details
Six (6) monthly
Business Continuity Management and Resilience Policy
Business Continuity Management and Resilience Guidelines
Every two (2) years or if significant business changes
Business Impact Assesment and Business Continuity Plans
Every one (1) year or if significant business changes
Emergency Management Plan
Every one (1) year or if significant business changes
Critical Incident and Crisis Management Plan
Every one (1) year or if significant business changes
Specialist recovery and incident management plans
Every one (1) year or if significant business changes in line with Crisis and Critical Incident Management Plans
Top of Page

Section 10 - Roles and Responsibilities

(49) Ownership of Business Continuity Management sits with the Risk, Audit and Compliance Committee (RACC) as a component of the risk management framework.

(50) The University Executive Board is responsible for the provision of support in the strategic direction of recovery, including resources and infrastructure, during a business interruption and for ensuring senior management understands their BCM responsibilities.

(51) The University Executive Board is responsible for the proactive management of the University’s CMP, Emergency Management Plan, IT Disaster Recovery Plan, Cyber Security Incident Response Plan and BCPs and processes.

(52) The Director, Risk, Compliance and Assurance provides management oversight for all RAD activities and may become involved during a disruptive event as required by the Critical Incident Management Team and after an incident to review the adequacy of the response.

(53) The impacted Senior Executive or Director, Risk, Compliance and Assurance, and if unavailable, the Senior Manager, Risk and Assurance may act as the Incident Management Coordinator for the Critical Incident Management Team.

(54) The Risk, Compliance and Assurance facilitates, implements and manages all aspects of the Business Continuity Management Policy and provides support and guidance to all faculties, divisions, business units and “owners” of significant University functions.

(55) The Risk, Compliance and Assurance will provide high-level support to the CIMT and/or CMT in the event of a disruptive event. Note this support includes the management and record keeping of all documentation relating to any disruptive event.

(56) Faculties, divisions, business units and owners of significant University functions, have a responsibility to:

  1. determine their business continuity priorities and analyse their disruption-related risks by adopting a risk-based assessment (the BIA), consistent with the Enterprise Risk Management Policy;
  2. develop and review BCPs which detail critical processes, response actions, resource requirements and recovery strategies for activation during a disruptive event, to maintain continuity of core business functions within acceptable timeframes;
  3. actively take part in the testing and awareness programs as required;
  4. form a Local Recovery Team who will manage the local response to an incident and will include a Local Business Continuity Coordinator (LBCC) and a Team Leader; and
  5. ensure any documentation completed during a disruptive event, including forms, templates, reports, reviews are provided to the RAD for record keeping.

(57) The LBCC is nominated as the main contact for BC matters relating to a particular BCP and has responsibility for the management and coordination of BCM for their respective business unit, including implementing and maintaining documentation, performing reviews and updates as well as facilitating training and awareness sessions to members of staff within their unit. The LBCC will provide support to the Local Recovery Team (identified in the BCP) and undertake the actions as outlined in the response plan.

(58) Local Recovery Teams are responsible for the assessment of, and decision to, escalate incidents as they occur to effect recovery and restoration of normal business operations and will follow the basic steps as outlined in the BCP and as directed by the Team Leader, to manage the response actions following a disruption to a key business process.

(59) The Local Recovery Team will notify a member of the CIMT and the Risk, Compliance and Assurance about a disruptive event and the decision to activate their BCP. The Local Recovery Team will provide regular status updates to the Risk, Compliance and Assurance throughout and post the disruptive event.

(60) Every staff member is responsible for actively taking part in awareness and training sessions as required and for following directions provided to them by their LBCC and Local Recovery Team in the event of an incident occurring.

(61) It is the responsibility of other UOW support units to ensure that sufficient information is held in the BCPs to enable the recovery of infrastructure and services that are required, within acceptable timeframes.

Top of Page

Section 11 - Definitions

(62) Definitions relating to BCM are detailed in the Business Continuity Management Policy