Incident Management Plan Risk Assessment Reports
Incident Management Plan Risk Assessments
Immediate Concerns
- Is there an immediate risk to personnel?
- Is there an immediate risk to the company's reputation?
- What risks are presented to resources or facilities?
- Is there a risk to third parties?
- How long before any of these risks occur—how much time is there?
Situation
- What is the cause or motive of the risk event?
- Is it likely to get worse?
- Are other (different) threats likely to occur?
- What happened, where, and when?
- What effects are to be expected in the best case, likely case, and worst case?
Complicating Factors
- What legal implications are there?
- What media interest has been shown?
- What environmental factors will hamper the resolution of the problem?
The IMP risk assessment should not be confused with the responsibilities of the crisis response team and specialist responders, who should conduct more comprehensive risk assessments and evaluations during and following the crisis. The IMP risk assessment is a tool designed to provide a local perspective of the problems and impacts likely to occur that might fall outside of normal reporting formats within the IMP. While not a component of the IMP, the company should also link risk assessments to any recovery plans so that when the situation has sufficiently stabilized the company can begin to plan the resumption of normal operations.
Incident Management Plan Policies and Instructions
The IMP's association with other aspects of the Business Continuity Management Plan should be clearly stated within the policies and instructions component. This will ensure that users are guided to the correct supporting policies and procedures that govern the implementation of the IMP (if they are not included within the IMP as stated). The IMP should not seek to duplicate unnecessarily those instructions, policies, plans, or procedures captured within other components of the Business Continuity Management Plan; however, it should briefly articulate how those elements guide the management of the IMP. The core subjects that might be covered for IMP usage are:
- Structure of the crisis management organization.
- Decision‐making and authority matrixes.
- Alert states and response trigger points.
- Organizational interfaces and their part in the IMP.
- Communicating IMP activities through the communications plan.
- Leveraging resources through the resource and procurement plan.
- Reference policies, protocols, and other planning documents associated with the IMP.
- Reporting and record‐keeping guidelines.
- Reference mapping and schematic usage.
As the IMP is designed to be a user‐friendly document, the introductory elements should seek to be succinct and relevant. At most, these elements should introduce supporting policies and plans so that the user can be guided to these elements where required.
Structuring Incident Management Plans
- Instructions
- Management tools
- Education
- Information‐gathering techniques
- Response guidelines
Exhibit 1 illustrates some elements a company may wish to include within the IMP. The IMP should be designed to operate in isolation if necessary, despite working as a functional component of the Business Continuity Management Plan, as some user managers may not have access to supporting policies and plans, and the IMP is engineered to guide an inexperienced manager through a crisis quickly by the use of succinct and simple reference guides and instructions—reducing the need to refer to other documents in order to be effective. Where possible, elements of the Business Continuity Management Plan that are relevant to the IMP should be migrated into the plan to ensure consistency and to avoid unnecessary duplication of effort.
Resourcing the Incident Management Plan
In order to be effective, risk assessments, security surveys and plans, and other components of the Business Continuity Management Plan should be undertaken so that the IMP operates within a supported environment. The resource limitations should also be known to management, as these will determine what parameters the IMP will operate in. Resources should be considered in terms of ensuring that the IMP is applicable and relevant, has the correct level of corporate buy‐in and support, has adequate levels of practitioner education and training, has been correctly dispersed, and has the correct technological and physical materials required to make it work.
The Business Continuity Management Plan should also be resourced in terms of redundancy measures, materials, and protocols. Redundancies may apply to materials, infrastructures, or technologies. Companies may wish to ensure that information technology (IT) servers are located off the main site(s) to ensure that information storage is not directly affected by a facility crisis. Emergency or crisis response centers may also have secondary locations established, should the primary ones be within an affected area, and other crisis management resources may have backup components removed from normal facilities, including multiple‐medium access to crisis and response plans.
Incident Management Plan
Emergency Operations Planning | Disaster Planning
Many healthcare organizations confuse emergency operations planning with preparedness. In fact, developing an emergency operations plan (EOP) is but one component of an effective emergency management program to ensure preparedness. Healthcare organizations must develop plans for two different scenarios: one in which they serve as response agencies and one in which they are also victims of the incident. If one plan alone is developed, it must address both of these circumstances. An EOP can be thought of as an executive-level or leadership guidebook to manage the consequences of a disaster. It is a concept document that describes in general terms what response operations and functions will be performed or accomplished by what department, agency, or organization and under what circumstances. It is not a detailed reference tome to be used as a standard operating procedures manual by all response personnel during actual disaster operations.
In addition to EOPs, many organizations develop adjunctive standard operating procedures or job aids. These are more detailed, job-specific or department-specific checklists that delineate duties and responsibilities of each individual or position that is part of the organization response plan. Many of the details usually seen in EOPs should rightfully be placed in these documents, which provide instructions on how to do what is necessary in support of the EOP.
Of paramount importance in EOP development for incidents involving CBRNE are 15 basic issues. These areas are described in the following sections.
Notification. It is imperative that hospitals and emergency departments be included in a notification system that a disaster event has occurred that may affect healthcare services. In CBRNE events, the risk to the facility multiplies. Less than 20 percent of those contaminated by industrial chemicals are subsequently decontaminated on the scene (Levitin and Siegelson 1996); thus, the potential for arrival of contaminated victims at the healthcare facility must be considered and planned for.
Decontamination. Who will perform decontamination, where it is to be performed, how the disposition of victims and their belongings will be handled, and how contaminated wastewater will be handled should be addressed early in the planning process. If outside resources will be required, their availability and timeliness of response must be verified. Appropriate supplies and equipment, PPE, and a process for patient flow from contaminated to clean areas must be addressed.
Facility physical protection. In addition to actual victims, a large number of asymptomatic, possibly exposed individuals (often referred to as “worried well”) may also present for care, and this additional workload must be anticipated. As was seen in the Tokyo sarin event, these individuals may rapidly overrun the facility and may indeed pose a threat to continued operations (Matsui, Ohbu, and Yamashina 1996).
Evacuation. Released agents may remain airborne for a significant period of time. If the facility is downwind from the site of release, provisions must be established to rapidly decide if evacuation of patients, staff, and visitors is necessary. Transportation assets and receiving facilities must be identified. The establishment of alternate treatment facilities, until such time as environmental surety has been established, should also be included.
Shelter-in-place. When sufficient time to evacuate the facility is not available, expedient shelter-in-place provisions must be developed. Policies concerning securing of ventilation systems, internal movement of patients, and provision of PPE to critical facility personnel must be addressed. Sheltering-in-place can be accomplished horizontally (movement along the same level or floor into an area of the facility away from risk) or vertically (movement to higher or lower floors to escape threats where damage has occurred or where height is an issue, such as in flooding, fire, or high winds).
Detection. Detection is one of the weak links in the chain of emergency management and response. Most biological agents will not produce immediate symptoms, many chemical agents have delayed presentations, and, short of massive radiation doses, weeks may pass before those exposed may feel ill. Detection may occur through trend analysis if done in a near-real-time fashion through syndromic surveillance. Syndromic surveillance is a public health epidemiological process of collecting and analyzing patient data based on predetermined signs and symptoms, referred to as a syndrome. The goal of this analysis is to identify abnormal changes or trends in the numbers of patients presenting at portals of entry to the healthcare system. However, this must occur prior to the diseases that cause these syndromes progressing to the point of fatalities or severe morbidity, so that preventive and treatment measures may be instituted early in the course of the outbreak. Detection may also occur clinically or through laboratory analysis. The EOP should identify detection methods used and the procedures to be followed should an event be suspected.
Identification. Separate from detection, identification of agents that produce similar clinical syndromes or effects but have different treatment and protection regimens is a critical capability. Because most hospital laboratories do not have these sophisticated testing capabilities, methods of linking to CDCs Laboratory Response Network must be included in EOPs.
Triage. Triage of victims of a CBRNE event differs from that for other mass-casualty events because many more victims are likely. In the event of a biological-agent attack, two different victims with identical physiological measurements may have significantly different survival probabilities. Specific life-saving procedures, such as the administration of antidotes, may exist that would alter traditional triage algorithms predicated on the ability of the community healthcare network to absorb all casualties in short order—a situation unlikely to occur if the entire community is affected (Burkle 2002).
Treatment options. Just as triage of CBRNE victims is different, so are treatment concerns. The nature of traumatic disasters is such that the majority of victims who will eventually die do so at the scene or during the first 24 to 48 hours, and most do not require isolation to protect other patients and staff. Victims of chemical, biological, or radiological events may require sophisticated support (including burn therapy, isolation rooms, invasive monitoring, and mechanical ventilation) and may require these modalities for prolonged periods of time.
Surge capacity. The ability to increase facility capacity to accept more victims while facing resource constraints, especially during the initial hours and days after the event, is a huge challenge. Other patients not affected by the disaster may continue to present with emergencies that will require treatment. It is unacceptable to assume that only victims of the disaster will be ministered to during response operations. Early discharges, transfers, and use of home health care services may functionally expand facilities, while cancellation of elective procedures and same-day surgery may free more beds and staff. Extending shift times for staff from 8 hours to 12 hours for a short period (less than one week) effectively increases staff by 50 percent (Schultz, Mothershead, and Field 2002).
Surge capacity also applies to material resources. A facility may elect to increase caches of materials and supplies, but storage capabilities and costs of procurement may be a hindrance. Service-level or backup agreements or even memoranda of understanding with local pharmacies and hospital-supply distributors may provide a functional supply surge capacity at a fraction of the cost. This also obviates the need to dedicate space and personnel to store and maintain these goods.
Prophylaxis. Determining who will receive prophylaxis, and at what priority, in the event of a biological release and methods for distributing and dispensing these pharmaceuticals must be included in an EOP. Keep in mind that unprotected staff will most likely not work, nor will staff who are concerned about their families. The facility’s role in providing or dispensing prophylactic antibiotics to the community must also be ascertained.
Fatality management. A large event may produce a significant number of casualties who die after arrival at a hospital, overwhelming hospital morgues. If surge facilities for temporary interment cannot be identified through traditional services (e.g., city morgues, funeral homes), alternate sites must be established and appropriately equipped, staffed, and secured. It is unwise to presume that other response organizations will assume this responsibility. This issue, as others, should be addressed at the community-planning level, with all providers informed of the plan for mass-fatality management.
Counseling services. As seen after the World Trade Center and Murrah Federal Building attacks, responders may suffer both acute and long-term stress reactions, including delayed development of post-traumatic stress disorder (North et al. 2002). It is the responsibility of the healthcare organization to take care of its employees, and the provision of counseling services cannot be ignored. The healthcare system will also most likely be called on to provide these services for victims, victims’ families, and the community at large. Depending on the nature of the disaster, counseling requirements may far outstrip other medical needs of survivors and the community.
Horizontal and vertical integration. Integrating health services with other local or regional response organizations is essential for successful emergency operations. The prolonged phases of emergency response require that healthcare networks operate together and that various actions by other response organizations be interdependent. Organizations must not plan in a vacuum. Federal law requires the use of an incidentmanagement system in such operations (U.S. Congress 1996). A terrorist event involving CBRNE agents also mandates activation of the Federal Response Plan, which is soon to be replaced with the National Response Plan being developed by the Department of Homeland Security. (See Chapter 7 for more information on organized emergency management systems and the Federal Response Plan.)
Law enforcement and incident forensics. Any terrorist event is a criminal act, and law enforcement investigators will be intimately involved throughout all phases of response. Additional requirements for maintaining a legal chain of custody while handling and transporting samples, patient information sharing, and other cooperative ventures will require new approaches to incident management by all response organizations.
Audit Risk (Incident Management)
inefficiencies, and fraud.
An example of different types of risks associated with different segments of the audit, systems involving handling of cash are very susceptible to theft, where data processing systems are usually susceptible to inefficient resource allocation. In planning to manage audits, the most difficult judgment is the level of acceptable risk relevant to each audit segment. It is for this reason that auditors should be knowledgeable and experienced persons. Auditors must understand the control environment and the associated risks by examining management and application controls already in place. For example, when auditors review system development activities, they are seeking to understand the controls that are associated with these tasks.
They attempt to understand the business processes, including components such as human expertise, information technology, communications, management controls and application controls so they can assess related vulnerabilities and attendant risks. By understanding processes, components, behavior, and intended results, auditors can provide appropriate safeguard recommendations, if any apply.
Planning the Audit
In order to conduct an audit properly, a comprehensive audit management plan must be crafted.
The audit management plan should be action oriented, by listing the primary objectives to be performed. It should be tailored to the specific targeted business unit or division.
In drafting the audit management plan, a thorough review must be made of the organization's policies, with particular attention paid to risk management activities.
In the crafting, development, and implementation of policies, procedures, and standards, the organization is providing a process governing the activities of its employees consistent with the particular organization's goals and objectives. In many cases there are laws, regulations, and requirements affecting how the organization must conduct all or part of their business processes. Risk management is an integral part of the policy and procedure implementation. Auditing is basically an impartial review and investigation into the application of the organization's policies, procedures, and standards.
In crafting the audit management plan, the organization's strategic plan and objectives should be reviewed. This is essentially the basic guiding documentation for the organization. Depending on the business' units that are being audited, their applicable policies, procedures, and standards should be carefully reviewed. Job descriptions, organizational charts, lines of reporting, lines of authority, and chains of command should be made part of the information cache used to form the basis of the audit management plan.
In some business environments, audit management planning requires the auditors to conduct a preliminary survey through questionnaires to establish the appropriate scope addressing relevant business risks, develop the audit management plan, and direct auditor activities within the audit program. Often senior audit managers prepare questionnaires, also known as interrogatories, and send them to appropriate senior managers of the audit target. When completed, these questionnaires will provide the auditors with comprehensive visibility into the processes of the business unit.
These questionnaires may help auditors identify critical areas on which they need to focus their attention rather than taking a scattered, "shotgun" approach. As part of this preliminary questionnaire survey, auditors should review systems and processes to identify key controls already in place.
General questions that should be asked in preparing audit management plan questionnaires include but not limited to:
What are the critical issues regarding this business unit's operation?
What are the critical assets of this business unit?
What are the critical management functions?
What are the critical applications?
Does this business unit process sensitive data?
What are the risks to the business unit?
What substantive steps have been taken to address these risks?
What processes are least tested in the unit's business unit's daily operations? For example, if the business unit suffers from frequent power-outages and uses emergency power sources, including uninterruptible power sources and emergency generators, to restore operations, then power recovery requirements are likely to be well-formulated and tested. However, in the case of a complete disaster recovery plan, it may not be tested, and in fact, may not exist at all. The audit management plan should be the governing document for the "biggest bang for the buck."
Another valuable source in the development of an audit management plan is the review of previously performed audit reports. Many times these documents will identify potential weaknesses that should have been corrected or addressed earlier. The audit management plan is merely that, an activity plan. It should address those areas to be evaluated, and not too much more. Audit programs are different from audit plans in that they are comprehensive documents delving into the audit's "nuts and bolts."
Exhibit 1 is a brief example of an audit management plan.====================================================================
Audit Step
Planning1. Discuss nature and scope of audit with key senior personnel
2. Discuss audit requirements with senior managers
3. Assemble required audit staff and build team
4. Draft comprehensive audit program
Draft initial budget
Reporting1. Hold opening meeting with appropriate personnel at initiation of audit
2. Use standard audit reports format including compilation of audit findings and recommendations
3. Hold closing meeting with key managers to review draft of final audit report
4. Identify key senior managers in the event of reporting irregularities before audit conclusion
Preliminary Audit Steps
1. Identify key employee contacts for audit
2. Obtain appropriate organization and business unit documentation includingA. Strategic business plans
B. Relevant policies, procedures, and standards for firewall administration unit
C. Relevant documentation to gain an understanding of the operations of the firewall administration unit
Audit Procedures
1. Understand unit's business practices and compare with organization's policies, practices, and standards
2. Understand and document business process flows
3. Interview pertinent employees in firewall administration unit to gain an understanding of their functions, risks, and other relevant issues
Testing
1. Testing will be performed to increase auditor's understanding of the firewall administration unit's function and activities
2. Testing will increase the auditor's understanding of managerial and application controls
3. Auditor will test if relevant controls are operating correctly and consistently
4. Auditor will test metrics to manage firewall administration
5. Auditor will test the correct design, development, and implementation of firewall administration
Popular Posts
-
The first step in implementing a strategy for deploying physical scanners is to select a central location to which all scanners will re...
-
Often crisis responders will initiate a crisis notification through a verbal briefing. As such, it is imperative that a clear and accurate ...
-
The composition of the crisis and incident response teams should reflect the personnel required to analyze and deal with any events, fro...
-
Incident and problem management processes are intended to handle problems that are raised through the service desk as well as responses t...
-
Each company will define the composition and structure of its own crisis response group dependent on the nature, size, and scope of the ...
-
There are many ways to deploy a system, and what is needed for the operating environment will possibly affect the solution chosen. In so...
-
Nessus is a popular open-source scanner for organizations that choose not to spend the money on other proprietary products. There are s...
-
Incident Management Guidelines Office block, facility, or hotel fires can present unique risks depending on the operating region in which th...
-
In many descriptions you will see the words "Critical Incident Response Team" associated with critical incidents. Many incident ...
-
Copyright protection is the means by which authors establish their rights of ownership in a fixed tangible medium of expression. Authors...

