Draft Details
- Emergency and continuity management program (N...
- DRAFT STANDARD
- Legal Notice for Draft Standards
- Preface
- + 0.1 General
- 0.2 Using this Standard
- + 1 Scope, purpose, and application
- 1.1 Scope
- + 1.2 Purpose
- 1.2.1 General
- 1.2.2 Continual improvement process
- 1.3 Application
- 1.4 Terminology
- 2 Reference publications
- 3 Definitions
- + 4 Program management
- 4.1 Senior management commitment
- 4.2 Program coordinator
- + 4.3 Program committee
- 4.3.1 Establishment
- 4.3.2 Strategic direction and input
- 4.3.3 Membership
- + 4.4 Program administration
- 4.4.1 Program
- 4.4.2 Policy
- 4.4.3 Goals, objectives, and performance measur...
- 4.4.4 Integration
- 4.4.5 Budget and schedule
- 4.4.6 Records management
- 4.4.7 Review
- 4.5 Compliance
- + 4.6 Financial management
- 4.6.1 Controls
- 4.6.2 Decisions
- 4.7 Resources
- + 5 Planning
- + 5.1 Planning process
- 5.1.1 Program development process
- 5.1.2 Planning process
- 5.1.3 Review and assess
- 5.1.4 Involvement of interested parties
- + 5.2 Common plan requirements
- 5.2.1 Plan purpose and objectives
- 5.2.2 Internal organization roles and responsib...
- 5.2.3 External organization roles and responsib...
- 5.2.4 Logistics support and resource requiremen...
- 5.2.5 Communication and information management
- 5.2.6 Plan dissemination and communication
- 5.2.7 Plan maintenance
- + 5.3 Risk assessment
- 5.3.1 Risk assessment process
- 5.3.2 Hazard and threat identification
- 5.3.3 Risk analysis considerations
- 5.3.4 Risk evaluation
- 5.3.5 Risk treatment options
- 5.3.6 Risk monitoring
- + 5.4 Impact analysis
- 5.4.1 Impact analysis
- 5.4.2 Identification of dependencies
- 5.4.3 Critical activity identification and prio...
- 5.4.4 Supporting resources for critical activit...
- 5.4.5 Impact analysis review schedule
- + 5.5 Strategy development
- 5.5.1 Prevention
- 5.5.2 Mitigation
- 5.5.3 Preparedness
- 5.5.4 Response
- 5.5.5 Continuity
- 5.5.6 Recovery
- 5.5.7 Communications
- 5.5.8 Education and training
- 5.5.9 Continual improvement
- + 6 Implementation
- + 6.1 Prevention
- 6.1.1 Prevention measures
- 6.1.2 Evaluate prevention measures
- + 6.2 Mitigation
- 6.2.1 Mitigation measures
- 6.2.2 Evaluate mitigation measures
- + 6.3 Preparedness
- + 6.3.1 Incident management system
- 6.3.1.1 Incident management system
- 6.3.1.2 Roles and responsibilities
- 6.3.2 Response plan
- + 6.3.3 Communications
- 6.3.3.1 Communication strategy
- 6.3.3.2 Emergency communication and warning cap...
- 6.3.3.3 Communication procedures
- 6.3.3.4 Pre-scripted information
- 6.3.3.5 Public awareness and education
- + 6.3.4 Continuity
- 6.3.4.1 Continuity plan
- 6.3.4.2 Technology recovery plan
- + 6.3.5 Resource management
- 6.3.5.1 Resource management procedures
- 6.3.5.2 Locations
- 6.3.5.3 Mutual aid/mutual assistance
- + 6.3.6 Education and training
- 6.3.6.1 Education and training strategy
- 6.3.6.2 Training evaluation and improvement
- 6.3.6.3 Training records
- + 6.4 Response
- 6.4.1 Operational procedures
- 6.4.2 Situational awareness
- 6.4.3 Incident management
- 6.4.4 Communications
- 6.4.5 Incident information
- 6.4.6 Public education and awareness
- + 6.5 Recovery
- 6.5.1 Recovery procedures
- 6.5.2 Recovery assessment
- 6.5.3 Restoration
- 6.5.4 Communications
- 6.5.5 Incident information
- + 7 Program evaluation
- 7.1 Evaluation
- + 7.2 Exercises and tests
- 7.2.1 Exercises
- 7.2.2 Tests
- 7.2.3 Results
- 7.3 Audit and review
- 7.4 Corrective measures
- + 8 Program review
- 8.1 Continual improvement
- 8.2 Corrective measures
- 8.3 Senior management review
- 8.4 Senior management commitment
- + Annex A (informative)
- A.0.1
- Figure 1
- + A.4 Program management
- A.4.1 Senior management commitment
- + A.4.2 Program coordinator
- A.4.3.1 Establishment
- A.4.3.2 Strategic direction and input
- A.4.3.3 Membership
- + A.4.4 Program administration
- A.4.4.2 Policy
- A.4.4.3 Goals, objectives, and performance meas...
- A.4.4.6 Records management
- A.4.5 Compliance
- + A.4.6 Financial management
- A.4.6.1 Controls
- + A.5 Planning
- A.5.1.1 Program development process
- A.5.1.2 Planning process
- A.5.1.3 Review and assess
- A.5.1.4 Involvement of interested parties
- A.5.2.1 Plan purpose and objectives
- A.5.2.2 Internal organization roles and respons...
- A.5.2.3 External organization(s) roles and resp...
- A.5.2.4 Logistics support and resource requirem...
- A.5.2.5 Communication and information managemen...
- A.5.2.6 Plan dissemination and communication
- A.5.3.1 Risk assessment process
- A.5.3.2 Hazard and threat identification
- A.5.3.3 Risk analysis
- A.5.3.4 Risk evaluation
- A.5.3.6 Risk monitoring
- + A.5.4 Impact analysis
- A.5.4.1 Impact analysis
- A.5.4.2 Identification of dependencies
- A.5.4.3 Critical activity identification and pr...
- A.5.4.4 Supporting resources for recovery and c...
- + A.5.5 Strategy development
- A.5.5.1 Prevention
- A.5.5.2 Mitigation
- A.5.5.3 Preparedness
- A.5.5.4 Response
- A.5.5.5 Continuity
- A.5.5.6 Recovery
- A.5.5.7 Communications
- + A.5.5.8 Education and Training
- A.5.5.8.1 Education
- A.5.5.8.2 Training
- A.5.5.9 Continual Improvement
- + A.6 Implementation
- + A.6.1 Prevention
- A.6.1.1 Prevention measures
- A.6.1.2 Hazard assessment and prevention measur...
- + A.6.2 Mitigation
- A.6.2.1 Mitigation measures
- A.6.2.2 Hazard evaluation and mitigation measur...
- + A.6.3 Preparedness
- A.6.3.1.1 Incident management system
- A.6.3.1.2 Roles and responsibilities
- + A.6.3.2 Response plan
- A.6.3.3.1 Communication systems and strategy
- A.6.3.3.2 Emergency communication and warning c...
- A.6.3.3.3 Communication procedures
- A.6.3.3.4 Pre-scripted incident information
- A.6.3.3.5 Public awareness and education
- A.6.3.4.1 Plan for disruption management and re...
- A.6.3.4.2 Technology recovery plan
- A.6.3.5.1 Resource management
- A.6.3.5.2 Mutual aid/mutual assistance
- A.6.3.5.3 Facilities
- A.6.3.6.1 Education and training strategy
- A.6.3.6.2 Training evaluation and improvement
- A.6.4.1 Operational procedures
- A.6.4.2 Situational awareness
- A.6.4.3 Incident management
- A.6.5.1 Recovery procedures
- A.6.5.2 Recovery assessment
- A.6.5.4 Communications
- + A.7 Program evaluation
- + A.7.1 Evaluation
- A.7.2.1 Exercises
- A.7.2.2 Tests
- A.7.2.3 Results
- A.7.3 Audit and review
- A.7.4 Corrective measures
- + A.8 Program review
- A.8.1 Continual improvement
- A.8.3 Senior management review
1.1 Scope
This Standard establishes criteria for an emergency and continuity management program.
1.2 Purpose
1.2.1 General
This Standard provides the requirements to develop, implement, evaluate, maintain, and continually improve an emergency and continuity management program for prevention and mitigation, preparedness, response, and recovery of an incident.
1.2.2 Continual improvement process
The elements of a continual improvement process included in this Standard are
a) program management;
b) planning;
c) implementation;
d) program evaluation; and
e) management review.
1.3 Application
This Standard applies to all organizations.
1.4 Terminology
In this Standard, “shall” is used to express a requirement, i.e., a provision that the user is obliged to satisfy in order to comply with the standard; “should” is used to express a recommendation or that which is advised but not required; and “may” is used to express an option or that which is permissible within the limits of the standard.
Notes accompanying clauses do not include requirements or alternative requirements; the purpose of a note accompanying a clause is to separate from the text explanatory or informative material.
Notes to tables and figures are considered part of the table or figure and may be written as requirements.
Annexes are designated normative (mandatory) or informative (nonmandatory) to define their application.
You may comment on any section of this document by clicking the “Submit Comment” link at the bottom of the relevant section.