Denise Fortner, MBCP

Denise Fortner, MBCP
Showing posts with label Toolbox. Show all posts
Showing posts with label Toolbox. Show all posts

Tuesday, February 17, 2015

What's in an IT Disaster Recovery plan template?

SunGard Availability Services has an article that might be useful if you're working on IT DR plans:

Whats in an IT DR plan template

This is a good article and very helpful. It's also a perfect example of what a "plan template" means: it shows you the headings for the plan, the questions you need to answer, and what type of data needs to be included. It's not a file you download and fill in the blanks. 

Any guide that purports to be a quick fill-in-the-blanks template is a fraud: it's either so high level that it's worth nothing, or it's a sales pitch in disguise. SunGard Availability Services' template is exactly the kind of thing you want when you're looking for a template: some key pointers, a list of the things you must include (which is incomplete because it can't address every business in every situation), and some advice on the headings you want to use and in what order.


Monday, February 16, 2015

4 ways to make a project a success despite reluctant users


Insurance Networking News has a fantastic article on one of the most common barriers to any project:

Making a project succeed despite reluctant users

Regardless what business you're in, you will have people who don't share your vision. This article is geared specifically toward software/system users who are less than supportive or completely against change, but the ideas in the article can be applied to a wide range of situations.






Saturday, February 14, 2015

Creating a Culture of Preparedness

Emergency Management Magazine has a wonderful article about embedding the business continuity process into the culture of an organization:

Tips for Creating a Culture of Preparedness

So often, this is the hardest thing to achieve in your awareness program. There are some great insights in this article.

Business Continuity Awareness Week is coming up in March, incorporate some of this advice into your plan!

Monday, February 9, 2015

The CEO's knowledge of business continuity


Check out this great article from Continuity Central:

CEO? Here are three key business continuity questions you need to ask

So often, the CEO believes they have an understanding of business continuity that is greater than their true understanding. 

Business continuity professionals need to regularly communicate with the CEO to assure they understand the risk level the company was willing to take (as identified in the last Risk Analysis), what business functions were identified as critical to the survival of the company (and what business functions weren't deemed critical), and the resources required to either maintain critical functions without interruption, or recover critical functions in the in the Recovery Time Objective (RTO) as documented in the last Business Impact Analysis - including systems, data, sites, personnel, hardware including workstations

A CEO that understood these things 2 years ago when a Risk Analysis and Business Impact Analysis were completed may not recall everything, if they aren't involved in Business Continuity on a very regular basis (such as weekly, not yearly).

Can your CEO explain what is recoverable and in what time frame? Can they explain how many people would be working from home (if able) or waiting for facilities to secure a new site that can accommodate all employees and functions? 

Check out Continuity Central's article, and I'd love to know what you think.

And keep in mind that Business Continuity Awareness week is coming up in March and could be a great time to work on awareness with your CEO and upper management.

A common theme you may notice in my blogs is that I campaign hard against the idea that disaster recovery is dead (long live business resilience). Unless your RTOs for every function are zero downtime, and you have a perfect mirroring of all systems (which doesn't mean you're immune to disaster), you have work-space recovery for 100% of employees, disaster recovery is still relevant. Even if you have all of those things, you still have to deal with Crisis Communication, Emergency Response and Emergency Management, and Disaster Recovery. 

There is no getting around it. Business Continuity and Business Resilience plans enhance the Disaster Recovery plan, not replace. You can't disaster-proof your business. If you could, well, a lot of us would be out of a job!

Check out my Toolbox page for some resources you may want to incorporate for Business Continuity Awareness week.

Tuesday, February 3, 2015

More Dynamic Tabletop Exercises for Emergency Response and Crisis Management

One of the challenges of tabletop exercises is that they don't become a predictable reading of the plan. Tabletop exercises are very cost effective, but they aren't known for being creative or exciting  (in general).

One of the benefits of tabletop exercises is that they're very cost effective. And they are a great tool to use with upper management since travel can be minimized. But in order to keep upper management in your organization interested in tabletop exercises, you've got to lead dynamic tabletop exercises that stay fresh and non-repetitive.

FEMA has developed tabletop scripts for organizations to use for three scenarios: a critical power failure to multiple communities, a chemical accident, and an impending hurricane. The chemical accident and hurricane scenarios both have "video inject scripts" that you can use as the exercise progresses:

Emergency Planning Exercises (FEMA)

If you've never presented a tabletop exercise, or would like some new ideas to incorporate, check out the FEMA site and put this in your toolbox!

Friday, January 30, 2015

The Old Elevator Speech

Many professionals are familiar with the concept of the elevator speech: a rehearsed, persuasive, short statement that sells you, your company or your products and services, that you can use if you unexpectedly see a contact or potential customer (or employer) and only have a very brief amount of time to talk to them - like the length of time an elevator ride might take.

MindTools.com has developed guidelines for crafting an elevator speech, if you've never created one before:

http://www.mindtools.com/pages/article/elevator-pitch.htm

The elevator speech is a fantastic tool, one you should definitely utilize. But . . . how long has it been since you revisited your elevator speech and updated it? 

Is it covered in dust? 

Why not take the time this week to make it a priority to revise your elevator speech?

Got your elevator speech updated? 

Ready to take it to the next level?

Many business continuity professionals have worked in their current company for years. They know all of the members of upper management, and the members of upper management have at least an average understanding of your company's business continuity program. 

But you may have limited face-time with members of upper management: perhaps you see them in a weekly staff meeting where you're expected to very briefly give an update. Unless you schedule time with them, which can be challenging, you don't have a lot of opportunities to:
  • sell yourself: your skills, your initiative, your ideas;
  • sell your business continuity program: not just update them on the latest development, but tout the progress that has been made in the program in the last year(s) or remind them of challenges that have been overcome; and
  • sell your vision: 
    • what area(s) do you feel needs to be a focal point of the business continuity program this year?
    • what ideas do you have about changing the status quo?
    • what do you need management support to do this year?
The Alec Baldwin movie "Glengarry Glen Ross" utilizes a sales saying: ABC = Always Be Closing. It means everything should ideally be done with one goal in mind: taking you a step closer to making a sale or closing the deal.  

Always Be Closing

Be prepared to use even a brief period of time (like an elevator ride) when you have the captive attention of someone in your organization crucial to your success or the success of one of you initiatives. Here's a sample elevator speech crafted to highlight a problem in the organization, what is already being done about the problem, and an idea that requires the buy-in of executive management:
"Did you know that at the last fire drill, it took 45 minutes to clear the building? I spoke with the fire chief and she said a building this size should be able to evacuate in half that time. One of the lunch-and-learns I've scheduled for Business Continuity Awareness Week in March, is for her to come in and stress exactly how quickly a fire can spread through a training video they use. I'm especially concerned that employees who require assistance aren't being evacuated fast enough.
"I'd like to increase the frequency of our fire drills until we improve the evacuation time, of course working around critical business periods. Combined with my awareness initiatives, I know we can do better on employee safety. Can I book some time with you next Monday to discuss the fire drill scheduling?"
Look at the sentence in red: it ends on a positive note that shows confidence.

Note that last sentence asking for a commitment to meet and discuss scheduling on a specific day. Without that sentence, you haven't asked for the "sale", you haven't necessarily made progress to closing the deal. You could go back to your office and hope he considers what you said . . . or you can Always Be Closing and ask for a commitment before he steps out of that elevator.

If those two paragraphs look long, consider this: with no practice (and a little bit of a slow southern drawl) I read it out loud in 47 seconds.

Experiment with developing several elevator speeches for different situations to accomplish different goals. Practice them so you are always ready. 

As business continuity professionals, it's what we do: always be ready! 

Never get caught not knowing what to say again.

Thursday, January 29, 2015

Ready.gov - Testing & Exercises

Ready.gov Testing and Exercises

Ready.gov has put together a list of the benefits of testing. They also did a fantastic job of discussing the use of the term 'exercising' vs. 'testing':

Testing the Plan

When you hear the word “testing,” you probably think about a pass/fail evaluation. You may find that there are parts of your preparedness program that will not work in practice. Consider a recovery strategy that requires relocating to another facility and configuring equipment at that facility. Can equipment at the alternate facility be configured in time to meet the planned recovery time objective? Can alarm systems be heard and understood throughout the building to warn all employees to take protective action? Can members of emergency response or business continuity teams be alerted to respond in the middle of the night? Testing is necessary to determine whether or not the various parts of the preparedness program will work.

Exercises

When you think about exercises, physical fitness to improve strength, flexibility and overall health comes to mind. Exercising the preparedness program helps to improve the overall strength of the preparedness program and the ability of team members to perform their roles and to carry out their responsibilities. There are several different types of exercises that can help you to evaluate your program and its capability to protect your employees, facilities, business operations, and the environment

I know some people have become adverse to the word 'testing', feeling that if the test isn't 100% successful, it reflects poorly, like a failure. Personally, I use the words interchangeably. I think one key to a successful exercise program is setting the expectation with management that it is designed to find the areas that need improvement, and there will always be areas that need improvement.

In my opinion, if an organization is testing year after year and they're finding no weaknesses in the continuity plan, then they need to look at changing the testing scenario. Recovering the IT environment isn't proof of business continuity, it's one component. Some  organizations may over-focus on IT recovery/resilience, at the expense of other plan components such as:

  • Command and control procedures
  • Communications with employees, shareholders and the media (employees may have been told not to speak to the media if an event occurs, but have you updated that direction to include not posting to any social media or taking unauthorized pictures during a recovery?)
  • Alternate facility for employees to work in, both locally and farther away in the case of a large incident
  • Staffing, cross-training and the need for alternate staff
  • Managing customer communications and expectations
Testing is such an important component to the business continuity program. Once it's become an integrated part of the program, it's important to continuously reevaluate the scope and scenario of your exercises.

Tuesday, January 27, 2015

Notification Wallet Card Template and Awareness Training

Business Continuity Contact Card (Wallet Card) Template

This PowerPoint presentation was shared on www.slideshare.net: Best Practices in Business Planning for Pandemic Influenza, by Jim Goble, CBCP, at National City Corporation. It's from 2006 but a lot of it is still relevant, including the Wallet Card template on slide 12. 

If you've never created a Wallet Card for your organization, they're very useful. Team members may have a lot of that information on their phones, but it could be outdated. By developing and distributing a Wallet Card, they can refer to it and updates contact information in their phones. This is Crisis Communication, something a team would access during the Notification Phase of an event as well as the Assessment Phase.

Make sure you date your Wallet Cards, so employees can easily tell if they're looking at the most recent version. I recommend updating the card quarterly, or more often if important information changes.



If your organization isn't used to the idea of a Wallet Card, this can be something you introduce during Business Continuity Awareness Week, March 16 - 20, 2015.

http://bcaw.groupsite.com/main/summary

BCAW also has a lot of information you may want to add to your toolbox. You can also sign up for the group so that you'll get reminders about Business Continuity Awareness Week. 

If you know that Business Continuity Awareness is an area your organization needs to work on, make this the year that you introduce Business Continuity Awareness Week!

Tuesday, September 2, 2014

Proposal Writing: Reviewing the Request for Proposal (Part 2)

In yesterday's blog, I discussed the first steps to evaluating a RFP. Today I'll wrap up the best practices for completing that initial assessment.

Just to recap, in yesterday's post I discussed:

  • Your initial read-through of the proposal, noting the submission requirements
  • You've assembled your team and assigned every line-item in the RFP
  • You've set and internal deadline for your team members to prepare their questions
  • A designated person has been identified to submit the questions and distribute the answers
Before You Submit the First Question

Submitting questions can be the first impression your organization makes on a potential customer. Before a single question is submitted, someone has to review each question and ensure it's in the form of a question (not just "CPU"). You want to present a professional appearance. 

All questions should be in the same font and the same style of bullets (or no bullets at all). And you must get the customer's name right. If ABC Corp. goes by "ABCC" in their RFP, that's what you have to refer to them as. Not ABC Corp., ABC, not the Awesome Blue Caterpillar Corp., and, please, not ABCD, ABCB or anything else that mangles their name.

When you read the RFP, you'll need to take special note of two things in regards to questions:
  1. What is the policy on contacting the customer? Do all communications go through the same person? Is there a notice that contacting other employees is grounds for your proposal to be dismissed?
  2. Are Q&A going to be distributed to all vendors?
You'll need to inform your entire team if there are restrictions on who can be contacted at the customer's organization. This means your network guru can't pick up the phone and call their network guru, even if they know each other. If this RFP is from a customer you're currently doing business with, you need to assure that anyone already working with the customer understands the new RFP can't be discussed outside of the RFP instructions. If possible, use employees from your organization that aren't already working with the customer to complete the RFP.

Don't run afoul of the customer's policies before you've even submitted a proposal. You don't want to be disqualified.

If the Q&A are going to be distributed to all vendors, you may need to discuss a "question strategy" with your team. You may want to word your questions carefully. For example, instead of asking "will your accept proposals for 17 inch monitors instead of 15 inch monitors," you may want to be generic and ask "will you accept proposals for items that exceed the specifications requested". You may want to conceal your strategy from competitors, or you may not want them to even know you're responding to the RFP. So don't show all your cards if the questions will be shared, and assure that no question you submit identifies your company by name or product or service.

I've noticed a lot of RFPs don't specify if Q&A will be shared among vendors. Some don't specify a date the customer commits to having all questions answered. In this case, I highly recommend you call the RFP contact (following the RFP instructions) and ask for the answers to both.

Th Clock is Ticking

Because RFP's often have a short turn-around-time, and the Q&A can make the difference in how your team responds, or if they chose to not respond. Your team may also need to submit follow-up questions, so time is a big factor in the Q&A:
  • Get line-item owners to commit to submitting questions by an internal deadline
  • Submit questions to the customer as soon as possible
  • Assure that answers to the questions are distributed to the entire team, and as quickly as possible
  • Let team members know to submit follow-up questions by an internal deadline that assures you meet the customer's question deadline
Did you have any idea that there could be so many steps just to get through the Q&A process? I promise if you follow these best practices, you won't regret it. This will give your organization an edge when you begin crafting the proposal.


Monday, September 1, 2014

Proposal Writing: Reviewing the Request for Proposal (Part 1)

I've been asked before if I had a proposal format that someone could use to respond to a Request for Proposal (RFP). The answer is no, and you shouldn't look for someone else's proposal as a formatting guide. The only thing that determines the proposal's format.

For this discussion, I'm using the term RFP, but the same advice holds true for:

  • Request for Information (RFI)
  • Request for Quote (RFQ)
  • Request for Bid (RFB)
  • or any other type of request you receive as a vendor that is an opportunity to demonstrate your qualifications, services and/or products to a current or potential customer.
The same advice can be applied to a proposal from the public or private sector.

I've seen RFPs run upwards of 100 pages, contain a dozen spreadsheets to be completed, and require as many as 30 forms and attachments. The first thing you need to do when considering a RFP is to read the whole thing, highlighting (either physically or online) all of the items that pertain to the response format, including the media the customer wants the proposal in, how many copies, due date and time, mandatory forms and spreadsheets, restrictions on page length or attaching marketing material, etc. This should give you a good idea about the effort it will require to respond to the RFP.

It may seem like that is all that is involved in an initial assessment of a RFP, but I can share some additional best practices here to completing an assessment that will give you an edge when responding to the RFP.

The Online RFP

Increasingly, companies, government organizations and other public entities are using online RFP process. Typically this will require the vendor to register and receive a log in to the customer's RFP website. This website may have the RFP files for download, it may also have relevant policy documents available, or it could be an online tool (program) that requires you to complete the individual questions or requirements directly online.

Most of the time, the customer will also have a file that contains all of the online questions that vendors can download and use as a working document. Sometimes this is in the form of a spreadsheet, and the vendor can upload his answers to the online tool.

It;s extremely important in this case to understand what restrictions are on each item in the online tool. This can include the number of characters allowed in an answer, if an answer can only be a number, if the answer must be selected from a drop-down list (such as Yes/No), or if the vendor can insert an attachment to go with the answer.

This holds true for any spreadsheets you must complete whether or not the proposal is to be entered online.

Sometimes the customer will ask that the final proposal files be uploaded to a website, without requiring input to each item. Either way, you need to get instructions on who you can call if there are technical problems. I've had more proposals than I want to remember that encountered problems at the final stage of online submitting. I could write a book on the online proposal process and how it differs from a more conventional proposal process (and I just might do that), but for now I'll proceed with the steps to complete an initial assessment of a RFP.

Assessing the Work Required

Once you understand the format the proposal has to adhere to, the deadline, and the media the proposal is to be delivered on, you need to have one other item before you can proceed in developing initial assessment on the proposal: the customer's deadline for questions to be submitted and the process involved.

Depending on the size and structure of the organization you work for, you may have a proposal manager or a project manager to assist in the process. I'm assuming in this example that you don't have any help like that and have to do the proposal/project management yourself. If a proposal/project manager is working with you, the same steps would be involved but you'd be able to divide the labor involved.

Next, you need to assign every item in the proposal to a person. That's important because a person can be held accountable but it can be much harder if a task is assigned to a group or department. This also assures that at the beginning of the process yo're identifying everyone who would need to be involved. You don't want to find out later that a key person or group was left out.

Distribute the proposal and a summary of the basic information you've gathered to the team you've assembled. Explain when questions are due, and set an internal deadline for all team members to have their assigned sections reviewed and any questions documented.

I've found it's much more efficient if one person is responsible for assimilating the questions and presenting them to the customer (in whatever format is required), and then distributing the answers received to the whole team. I've learned from doing hundreds of proposals that all of the questions and answers (Q&A) need to be distributed to the entire team. The answer to one question may impact items assigned to other team members.

That's all for today, but tomorrow I will outline best practices for the remaining steps for completing the initial RFP review.