Share these talks and lectures with your colleagues
Invite colleaguesPost-event reviews: Using a quantitative approach for analysing incident response to demonstrate the value of business continuity programmes and increase planning efficiency
Abstract
Business continuity management is often thought of as a proactive planning process for minimising impact from large-scale incidents and disasters. While this is true, and it is critical to plan for the worst, consistently validating plan effectiveness against smaller disruptions can enable an organisation to gain key insights about its business continuity readiness, drive programme improvements, reduce costs and provide an opportunity to quantitatively demonstrate the value of the programme to management. This paper describes a post mortem framework which is used as a continuous improvement mechanism for tracking, reviewing and learning from real-world events at Microsoft Customer Service & Support. This approach was developed and adopted because conducting regular business continuity exercises proved difficult and expensive in a complex and distributed operations environment with high availability requirements. Using a quantitative approach to measure response to incidents, and categorising outcomes based on such responses, enables business continuity teams to provide data-driven insights to leadership, change perceptions of incident root cause, and instil a higher level of confidence towards disaster response readiness and incident management. The scope of the framework discussed here is specific to reviewing and driving improvements from operational incidents. However, the concept can be extended to learning and evolving readiness plans for other types of incidents.
The full article is available to subscribers to the journal.
Author's Biography
Karthik Vaidyanathan is a senior risk manager at Microsoft Corporation. He is responsible for business continuity planning for the Microsoft Services Division, including Enterprise Services and Customer Service & Support. In this role, he is responsible for implementing its business continuity programme globally, to include operational resilience, recovery of critical systems and infrastructure and incident response. He has a master of science degree in electrical and computer engineering from Rutgers University. He is an ISO 22301 Lead Auditor, and a speaker at business continuity conferences.
Citation
Vaidyanathan, Karthik (2017, December 1). Post-event reviews: Using a quantitative approach for analysing incident response to demonstrate the value of business continuity programmes and increase planning efficiency. In the Journal of Business Continuity & Emergency Planning, Volume 11, Issue 2. https://doi.org/10.69554/YOBG9431.Publications LLP