Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Title: Business Continuity Management Policy
Subject: Information Security 
Policy No: ISO:2013:08 
Applies: University-wide 
Issuing Authority: Information Security Office - Chief Information Security Officer
Responsible Officer: Vice President for Information Resources and Chief Information Officer
Adopted: 07/01/2013
Last Revision: 08/01/2014
Last Reviewed: 12/29/2014

I. PURPOSE

A.This policy describes the Rowan University Business Continuity Management program, which is proactive and iterative in its approach to assess potential threats and ensure appropriate and resilient arrangements are in place. The Program is required to support the safety of our employees and secure critical resources (people, systems and locations) required to continue key business processes and minimize impacts in a timely, structured, and cost-effective manner, in the event of a business interruption incident. 

B. Business Continuity Management's primary objective is to enable the executive and senior management to continue to manage and operate their business under adverse conditions, by leveraging appropriate resilience strategies, recovery objectives, and business continuity and crisis management plans.

II. ACCOUNTABILITY

Under the direction of the President, the Chief Information Officer, Chief Information Security Officer, schools and business units, the Information Security Office (ISO) shall implement and ensure compliance with this policy.

III. APPLICABILITY

This policy applies specifically to all employees, deans, officers and directors of the University. Furthermore, management's accountability extends to ensuring all aspects of its Business Continuity Management's activity incorporate third party service providers and vendors.

IV. DEFINITIONS

Business Interruption - an event, whether anticipated or unanticipated, which disrupts the normal course of business operations within the university.

V. POLICY

A. Business Continuity Management Framework

...

The Information Security Office (ISO) will monitor and report on the status of University-wide business continuity management activities, plans, protocols and testing to each Dean and the Executive for each business unit on a periodic basis. Additionally, the ISO will provide regular reporting to the Board Risk Committee regarding the state of the University's Business Continuity Management Program and preparedness.

VI. ATTACHMENTS

A. Attachment 1, Roles and Responsibilities

...


By Direction of the CIO:

_________________________________
Mira Lalovic-Hand,
VP and Chief Information Officer

ATTACHMENT 1

ROLES and RESPONSIBILITIES

  1. A. Board of Directors
     The Board Risk Committee will: 
    1. Annually review and approve this any substantial changes to this policy.
    2. Maintain a general understanding of the scope of the policy and make inquiries of a responsible senior officer with respect to this policy.
    3. Review reports, as and when presented to the Board Risk Committee by executive management of the University, with respect to the outcome of significant business continuity events and the resulting action plans for mitigating recurrence.
  2. Deans and Business Units
    All areas are to ensure that faculty, staff, and management are familiar with incident protocols for emergencies and business disruptions. Deans and Executive management is to ensure compliance to this Business Continuity Management Policy and its supporting standards and guidelines.
  3. Information Resources and Technology (IRT)
    IRT is responsible for supporting the information systems and technology requirements of business management's Business Continuity Management activities. This includes supporting the development and implementation of appropriate strategies to recover infrastructure platforms and restore critical applications consistent with business management's continuity and recovery objectives. 
    IRT is also responsible for overseeing the creation, execution, and testing of a formal Disaster Recovery (DR) Plan and activities related to the systems and infrastructure it supports on behalf of the businesses.  
  4. Information Security Office (ISO)
    The ISO is responsible for the oversight of university-wide Business Continuity Management and for making appropriate recommendations to the Board Risk Committee regarding BCP and DR strategies and activities. 
  5. Legal
    Upon engagement by the sponsoring business, legal supports the risk management objectives of this policy by providing advice and support with contracts impacted by this policy 

 

ATTACHMENT 2

NON-COMPLIANCE AND SANCTIONS

...