ROWAN UNIVERSITY POLICY
...
The Business Continuity Management Policy
...
A.This policy describes the Rowan University Business Continuity Management program, which is proactive and iterative in its approach to assess potential threats and ensure appropriate and resilient arrangements are in place. The Program is required to support the safety of our employees and secure critical resources (people, systems and locations) required to continue key business processes and minimize impacts in a timely, structured, and cost-effective manner, in the event of a business interruption incident.
B. Business Continuity Management's primary objective is to enable the executive and senior management to continue to manage and operate their business under adverse conditions, by leveraging appropriate resilience strategies, recovery objectives, and business continuity and crisis management plans.
II. ACCOUNTABILITY
Under the direction of the President, the Chief Information Officer, Director of Information Security, schools and business units, the Information Security Office (ISO) shall implement and ensure compliance with this policy.
III. APPLICABILITY
This policy applies specifically to all employees, deans, officers and directors of the University. Furthermore, management's accountability extends to ensuring all aspects of its Business Continuity Management's activity incorporate third party service providers and vendors.
IV. DEFINITIONS
Business Interruption - an event, whether anticipated or unanticipated, which disrupts the normal course of business operations within the university.
V. POLICY
A. Business Continuity Management Framework
Management will apply a consistent, University-wide approach to business continuity management through:
- Governance
- Education and Awareness
- Analysis
- Recovery Strategy and Plan
- Maintenance
- Outsourcing and Third Party Service Providers
- Testing and Quality Assurance
- Monitoring and Control
...
Analysis
On an annual basis, each school and all business unit must assess their risk tolerance and sensitivity to an interruption by completing the Business Impact Analysis ("BIA") process to establish a University-wide criticality ranking. This criticality ranking must be submitted to the Information Security Office for independent validation and approval. The criticality ranking establishes recovery targets and the rigor of business continuity activities. The following criteria (high, medium, low) are used for criticality ranking:
...
Ranking
...
Criteria
...
High
...
• Business functions are critical and must be recovered quickly (0-
6hrs Maximum Downtime Tolerance).
• Failure of business functions would have a significant operational,
financial and/or reputational impact on The University.
• Business functions are sensitive to interruptions and contain
intricate and complex procedures and processes with multiple
points of failure.
• Heavy reliance on systems and/or external service providers.
...
Medium
...
• Business functions are moderately critical and recovery
requirements are less demanding (7-48hrs Maximum Downtime
Tolerance).
• Failure of business functions would have a moderate operational,
financial and/or reputational impact on The University.
• Business functions are less sensitive to interruptions and experience changes less frequently.
• Moderate reliance on systems and/or external service providers.
...
Low
• Business functions are of low complexity and recovery timeframes
could be lengthy (>48hrs Maximum Downtime Tolerance).
• Outages would have a minimal operational, financial and/or
reputational impact on The University.
• Business functions have minimal dependency on systems and/or
external service providers.
...
The Information Security Office (ISO) will monitor and report on the status of University-wide business continuity management activities, plans, protocols and testing to each Dean and the Executive for each business unit on a periodic basis. Additionally, the ISO will provide regular reporting to the Board Risk Committee regarding the state of the University's Business Continuity Management Program and preparedness.
VI. ATTACHMENTS
A. Attachment 1, Roles and Responsibilities
B. Attachment 2, Non-Compliance and Sanctions
...
Mira Lalovic-Hand,
SVP and Chief Information Officer
ATTACHMENT 1
ROLES and RESPONSIBILITIES
- A. Board of Directors
The Board Risk Committee will:- Annually review and approve this any substantial changes to this policy.
- Maintain a general understanding of the scope of the policy and make inquiries of a responsible senior officer with respect to this policy.
- Review reports, as and when presented to the Board Risk Committee by executive management of the University, with respect to the outcome of significant business continuity events and the resulting action plans for mitigating recurrence.
- Deans and Business Units
All areas are to ensure that faculty, staff, and management are familiar with incident protocols for emergencies and business disruptions. Deans and Executive management is to ensure compliance to this Business Continuity Management Policy and its supporting standards and guidelines. - Information Resources and Technology (IRT)
IRT is responsible for supporting the information systems and technology requirements of business management's Business Continuity Management activities. This includes supporting the development and implementation of appropriate strategies to recover infrastructure platforms and restore critical applications consistent with business management's continuity and recovery objectives.
IRT is also responsible for overseeing the creation, execution, and testing of a formal Disaster Recovery (DR) Plan and activities related to the systems and infrastructure it supports on behalf of the businesses. - Information Security Office (ISO)
The ISO is responsible for the oversight of university-wide Business Continuity Management and for making appropriate recommendations to the Board Risk Committee regarding BCP and DR strategies and activities. - Legal
Upon engagement by the sponsoring business, legal supports the risk management objectives of this policy by providing advice and support with contracts impacted by this policy
ATTACHMENT 2
NON-COMPLIANCE AND SANCTIONS
...
, or ISO:2013:09, was removed from this site on September 4, 2024. If you believe you require access to this content, please contact the Technology Support Center at 856-256-4400.