Business Continuity Management Standard Operating Procedure (Sop)
Business Continuity Management Standard Operating Procedure (Sop)
CONTENTS
1. INTRODUCTION 3
2. KNOWLEDGE 4
12. APPENDICES 14
1 INTRODUCTION
1.1 This procedure enforces and is subject to the conditions of the Business Continuity
Management Policy (Policy/192/09).
1.5 The Civil Contingencies Act 2004 defines BTP as a Category 1 Responder; an agency
at the core of the response to emergencies. Under the 2004 Act, Category 1
responders are required to undertake the civil protection duties. BTP is therefore
required to:
Assess the risk of emergencies occurring and use this to inform contingency
planning;
Put in place emergency plans;
Put in place Business Continuity Management arrangements;
Put in place arrangements to make information available to the public about civil
protection matters and maintain arrangements to warn, inform and advise the public
in the event of an emergency;
Share information with other local responders to enhance co-ordination;
Co-operate with other local responders to enhance co-ordination and efficiency.
1.6 The purpose of the BCMP is to provide a framework through which BTP can develop,
exercise and maintain business continuity plans in alignment with BS25999 and the
Business Continuity Institute (BCI) ‘Good Practice Guidelines 2008’
1.7 All plans will be securely held within a central repository system (eSecurus)
independent of BTP’s IT infrastructure. To comply with the BTP Records Management
Policy, any plan printed as back-up must be dated then destroyed as soon as it is
superseded.
1.8 Authorised users will gain access to their plans through a unique ID and password,
issued by the Force Business Continuity Manager (FBCM) or the system.
1.9 Level of access/privileges are linked to the BCMP role and set within the parameters
outlined below:
1.10 The BTP BCMP is fully endorsed by the British Transport Police Authority BTPA,
Strategic Command Team (SCT) and the Force Management Team (FMT).
2. KNOWLEDGE
2.1 Terms and Definitions
2.1.1 A full glossary of business continuity terms and definitions can be found in Appendix A.
3.1.3 BCMP will be reviewed by FMT through quarterly reports from the FBCM and on a
monthly basis by Corporate Assurance Group (CAG) on an Area/FHQ Department
basis in the course of the year.
3.1.4 Area/FHQ Department will review BC progress monthly as a standing item on their
AMT/SMT meeting agenda.
5.2 The BIA tool is integrated within the BCM system (e-Securus) termed “What If
Analysis?” This forms the basis of BC plan creation process.
5.3 Completion of the BIA for a department or location is the responsibility of the identified
Plan Owner, who is accountable to the Area Commander and/or Portfolio/Departmental
Head for compliance.
5.4 The BIA requires Plan Owners to detail information such as:
Business Processes.
Prioritisation of processes using objective assessment criteria – which allows
priorities and Recovery Time Objectives (RTO) to be calculated for each process.
Determining Critical Working Periods.
Application usage in support of business processes.
Staff skills assessment and priority in recovery mode.
Number of workstations required at recovery site over set timeframes
Special Considerations under the Disability Discrimination Act (DDA)
5.5 Risk Assessment: Risks should be assessed according to BTP’s agreed Risk
Management Policy and SOP.
6.2 Appendix C contains some of the options that could be used in plans to protect
resources and to maintain business continuity. This should not be seen as an
exhaustive list.
7.1.2 FHQ functions delivered out-based on Areas will be included in FHQ Plan Owner’s
arrangements, unless specific local Area-based arrangements are put in place by Area
plan owners.
8.1.2 A schedule of testing and exercises will be maintained by the BCCos for each Area and
the FBCM for FHQ Departments. The BCCos and the FBCM will work with their
respective Plan Owners to facilitate testing and exercising of plans.
8.1.3 Post exercise debriefs will be carried out to ensure lessons identified are incorporated
and improvements made to plans.
8.1.4 Exercise and Testing Guidance for Business Continuity Plan Owners can be found in
Appendix E.
8.2.2 A schedule of Maintenance will be overseen by the Area BCCo for their respective
Area. The FBCM will oversee the FHQ Departments. Plan Owners are responsible for
maintenance of their plan(s) and related documents. Where necessary they will consult
with the Area BCCo. The following types of maintenance and frequency of updates are
set within the programme:
Cascade Lists – update quarterly.
Business Impact Analysis – annually.
Risk Assessment – annually.
Business Recovery Strategy – revisited annually, following update of BIA.
Post exercise / invocation plan update - following an exercise and/or invocation.
9.1.2 The FBCM will work in partnership with the Area BCCos to ensure appropriate training
has been given to those who have a key role within the BTP’s BCMP.
9.2 Awareness
9.2.1 Raising business continuity awareness amongst BTP staff is essential to the
embedding process. Levels of awareness will range from knowledge of BTP’s BC
Policy and Procedures, to individual roles during normal business and in a disruption.
9.2.2 The SCT lead for BC will review BC preparedness formally, quarterly at the FMT.
Each Area AMT/SMT will review BC as a statutory item at each meeting.
9.2.3 Raising levels of awareness will be joint effort between the FBCM, Area BCCo’s, Area
BC Champions and Plan Owners.
9.2.4 The following methods to raise BC awareness should be considered and implemented:
One-to-one briefing
Briefing at local team meetings
Briefing at local AMT/SMT meetings
Internal publications (e.g. Intranet/eweeklies)
Use of Leaflets and Wallet Cards.
Workshops and/or PowerPoint presentations.
9.2.5 Details of awareness methods used will be maintained by the Area BCCo and the
FBCM.
9.3.2 The tools and templates will be used by Plan Owners to meet the minimum
requirements of the BCMP.
9.4.2 The FBCM will report to CAG on ‘State-of-Readiness’ for particular Area(s)/ FHQ
Department(s) as requested by the Head of Risk Management and Insurance on a
monthly basis.
9.5.2 This internal audit will measure four key areas of compliance:
Format – ensure all documentation is held in the correct location and in the
appropriate format.
Content – quality assure the content of the plan to ensure all required elements are
present and fit for purpose.
Testing – review recent testing approach, results, scope and lessons learnt.
Staff Awareness – interview with members of staff to ascertain understanding of
the local plan and arrangements.
9.5.3 Periodically the Civil Contingencies Unit will undertake internal reviews, to support local
planning, ensure continuous improvement and share good practice across BTP. Area
BCCo’s will assist with peer group reviews as appropriate as part of this process.
9.5.4 As a minimum, the FBCM will perform two audits per annum, reporting findings to Plan
Owners, Area Commanders and Department Head and ACC Operations.
10.4.2 Where the scope of the disruptive event has a lower potential for impact, or is solely
confined to a single Area/Department of BTP, an A/DBSG will be convened by the Area
Commander/Head of Department and supported by other Area/Departmental staff (see
Appendix I).
10.5.2 In the event that Plan owners/Deputies are unavailable, the Force Control Room Duty
officer will assess the situation, in accordance with the Command and Control guide
and where appropriate will contact and inform: The Duty “On Call” Chief Officer and/or
the following:
The senior “On Call” officer for the Area.
The relevant Area Commander, Head of Department and Plan Owner.
Force Business Continuity Manager.
Chief Inspector Civil Contingencies Unit.
10.5.3 With the approval of the Duty “On Call” Chief Officer, the BCGG will be activated and
coordinated by the FBCM or a nominated member of the Civil Contingencies Unit to
determine the appropriate response for BTP.
10.5.4 Depending on the nature of the disruptive event, some or all of the stakeholders listed
in Appendix I will participate in the response, as directed by the “On Call” Chief Officer.
10.5.5 Where appropriate, BCGG will require Areas or FHQ Departments to establish a
structure to cascade instructions, actions and policy decisions through a corresponding
A/DBCSG for the affected Area(s) or Department(s) to manage the tactical response to
the disruptive event and recovery.
12. APPENDICES
The documents listed below are available on the Intranet and the BC Planning Software
(eSecurus) to those with access rights.
Appendix A – Glossary of Terms
Appendix B – BC Roles and Responsibility
Appendix C – Response and Recovery Strategies