Business Continuity Management Case Study
- Country :
Australia
BioNextGen is a company specialized in vaccine manufacturing. The company has three production plants, located in France, Luxembourg and Belgium.
BioNextGen has 80 employees, including :
- The Chief Executive Officer
- The Chief Health and Quality Officer
- The Chief Information Security Officer
- The Chief Financial Officer
- The Operations Manager, who is responsible for business continuity
- The Research team
- The Production team
- The HR and administration team
- The IT team
- The Finance and accounting team
BioNextGen has two rooms rented for its IT environment from a service provider offering infrastructure services within these data centers. Internal standard IT equipment (workstations, etc.) are managed internally by the IT department, while the complex machines (for research and production) are directly managed and maintained by a specialized service provider. BioNextGen has a contractual commitment to provide vaccination kits within 72 hours to its customers.
You will be responsible for implementing BioNextGen's business continuity management system.
Exercise 1 (1.5 points)
- Propose three advantages to the Management Board to initiate a project for implementing a business continuity management system.
Exercice 2 (1.5 points)
- Propose three interested parties that have to be considered by BioNextGen for the establishment of the Business Continuity Management System.
Exercise 3 (1.5 points)
- Identify three applicable requirements (law, regulatory, standard, contractual) that have to be considered by BioNextGen for the establishment of the Business Continuity Management System.
Exercise 4 (1 point)
- Propose a scope description for the BCMS of BioNextGen.
Exercise 5 (1.5 points)
- Propose three business continuity objectives for BioNextGen.
Exercise 6 (3 points)
- Propose a RACI matrix to help BioNextGen on the definition of roles and responsibilities with regard to the BCMS.
The RACI matrix should include the following tasks:
- Definition of the business continuity strategy
- Establishment of the business continuity policy
- Definition of the methodology for performing the business impact analysis
- Performing the business impact analysis
- Identification of scenarios for the business continuity plans
- Management of the testing plan
Exercise 7 (10 points)
Perform a business impact analysis for BioNextGen:
- Propose three key activities.
- For one activity identified in 7.1, propose five key supporting assets.
- Identify one dependency and explain why.
- Identify a critical period and explain why.
- Propose a MAO, RTO, RPO for the activity and explain why.
- Identify required assets (staff, IT asset, critical documentation) and propose a RTO/RPO for IT assets.
- Propose a workaround for the activity