Showing posts with label Plan. Show all posts
Showing posts with label Plan. Show all posts

Incident Management Plan Risk Assessment Reports


While typically a function of the crisis response team (CRT), an IMP risk assessment report can in some instances be useful for the incident response team (IRT) to indicate how a crisis event may impact the company from a grassroots perspective, as well as any recommendations on how both the IRT and CRT should counter or mitigate these risks. This will feed immediate concerns and information from the source of the event in order to supplement the data response materials forwarded during the initial stages of a crisis. A basic IMP risk assessment of how the event may affect the company can prove useful to support risk mitigation at all levels in the early stages of an emergency.
The IMP risk assessment should not be confused with the responsibilities of the crisis response team and specialist responders, who should conduct more comprehensive risk assessments and evaluations during and following the crisis. The IMP risk assessment is a tool designed to provide an immediate and local perspective of the problems and impacts likely to occur that might fall outside of normal reporting formats within the IMP. The following provides an example of a simple IMP risk assessment report:

IMP Risk Assessment Report Incident Management Data Call

Incident Management Plan Risk Assessments

While typically a function of the crisis response team (CRT), it can in some instances be useful for the incident response team (IRT) to indicate how a crisis event may impact the company from a grassroots perspective. This will feed immediate concerns and information from the source of the event, to supplement the data response materials forwarded during the initial stages of a crisis event. A basic IMP risk assessment of how the event may affect the company can prove useful to support risk mitigation at all levels at the early stages of a crisis. Such assessments may include:

Immediate Concerns

  • Is there an immediate risk to personnel?
  • Is there an immediate risk to the company's reputation?
  • What risks are presented to resources or facilities?
  • Is there a risk to third parties?
  • How long before any of these risks occur—how much time is there?


Situation

  • What is the cause or motive of the risk event?
  • Is it likely to get worse?
  • Are other (different) threats likely to occur?
  • What happened, where, and when?
  • What effects are to be expected in the best case, likely case, and worst case?


Complicating Factors

  • What legal implications are there?
  • What media interest has been shown?
  • What environmental factors will hamper the resolution of the problem?


The IMP risk assessment should not be confused with the responsibilities of the crisis response team and specialist responders, who should conduct more comprehensive risk assessments and evaluations during and following the crisis. The IMP risk assessment is a tool designed to provide a local perspective of the problems and impacts likely to occur that might fall outside of normal reporting formats within the IMP. While not a component of the IMP, the company should also link risk assessments to any recovery plans so that when the situation has sufficiently stabilized the company can begin to plan the resumption of normal operations.

Incident Management Plan Policies and Instructions


The IMP's association with other aspects of the Business Continuity Management Plan should be clearly stated within the policies and instructions component. This will ensure that users are guided to the correct supporting policies and procedures that govern the implementation of the IMP (if they are not included within the IMP as stated). The IMP should not seek to duplicate unnecessarily those instructions, policies, plans, or procedures captured within other components of the Business Continuity Management Plan; however, it should briefly articulate how those elements guide the management of the IMP. The core subjects that might be covered for IMP usage are:


  • Structure of the crisis management organization.
  • Decision‐making and authority matrixes.
  • Alert states and response trigger points.
  • Organizational interfaces and their part in the IMP.
  • Communicating IMP activities through the communications plan.
  • Leveraging resources through the resource and procurement plan.
  • Reference policies, protocols, and other planning documents associated with the IMP.
  • Reporting and record‐keeping guidelines.
  • Reference mapping and schematic usage.


As the IMP is designed to be a user‐friendly document, the introductory elements should seek to be succinct and relevant. At most, these elements should introduce supporting policies and plans so that the user can be guided to these elements where required.

Structuring Incident Management Plans

The IMP is designed to allow both first responders and managers within corporate offices, as well as field project locations to understand the risk natures and response measures appropriate to their company and its operations. The IMP provides logical and user‐friendly response guidelines and information capture formats to support pragmatic incident management. The design of the IMP is an aspect of contingency planning; its implementation is a functional element of crisis management. The structure of the IMP will reflect the level of detail required by the company, as well as the complexity of the operating conditions a business activity is working under. In addition, the level of experience, capability, and reliability of those implementing the IMP should be considered, as clearer instructions and more comprehensive details may be required for a management element with limited experience in crisis management—especially for complex crisis natures. Where possible, the company should seek to retain a level of consistency in IMP structuring and approach methodologies across the group (where appropriate in terms of unique projects and environmental conditions), so that personnel moving between projects become familiar with how the plan is laid out and how it works—and that consistency of approach is maintained. The structuring of the IMP should consider five main elements:


  1. Instructions
  2. Management tools
  3. Education
  4. Information‐gathering techniques
  5. Response guidelines


Exhibit 1 illustrates some elements a company may wish to include within the IMP. The IMP should be designed to operate in isolation if necessary, despite working as a functional component of the Business Continuity Management Plan, as some user managers may not have access to supporting policies and plans, and the IMP is engineered to guide an inexperienced manager through a crisis quickly by the use of succinct and simple reference guides and instructions—reducing the need to refer to other documents in order to be effective. Where possible, elements of the Business Continuity Management Plan that are relevant to the IMP should be migrated into the plan to ensure consistency and to avoid unnecessary duplication of effort.



Exhibit 1: Structuring the Incident Management Plan

The policies, instructions, and threat overviews provide the user some instruction on how the IMP should be used, and the nature and aspects of the risks the company might face—placing the IMP into an understandable context. The data call templates guide responders as to what information they would be seeking and passing through the crisis management structure, and the response guidelines illustrate what practical measures should be taken to bring control to the situation.

Resourcing the Incident Management Plan

The IMP should be resourced with the appropriate policies and plans that guide and support the implementation of responses, as well as the technology required to effectively operate the IMP. The IMP is largely a human resource—driven activity, so the correct selection of response managers, with associated training and education, is required to ensure that the IMP can be adequately managed during a crisis. The IMP will also rely on technology, and the company should consider whether the IMP has sufficient resources to be effective in the event of a crisis—notably through the use of varied communication mediums, which will form a core component of the success of the IMP. The company should ensure that sufficient communication mediums and redundancies are available to flow information, guidance, and decisions throughout the organization. Connectivity and compatibility to supporting agencies are also important. The IMP itself may be posted within the company intranet, or hard copies may be held at office locations for use.

In order to be effective, risk assessments, security surveys and plans, and other components of the Business Continuity Management Plan should be undertaken so that the IMP operates within a supported environment. The resource limitations should also be known to management, as these will determine what parameters the IMP will operate in. Resources should be considered in terms of ensuring that the IMP is applicable and relevant, has the correct level of corporate buy‐in and support, has adequate levels of practitioner education and training, has been correctly dispersed, and has the correct technological and physical materials required to make it work.

The Business Continuity Management Plan should also be resourced in terms of redundancy measures, materials, and protocols. Redundancies may apply to materials, infrastructures, or technologies. Companies may wish to ensure that information technology (IT) servers are located off the main site(s) to ensure that information storage is not directly affected by a facility crisis. Emergency or crisis response centers may also have secondary locations established, should the primary ones be within an affected area, and other crisis management resources may have backup components removed from normal facilities, including multiple‐medium access to crisis and response plans.

Incident Management Plan

The incident management plan (IMP) is a generic and tactical component of the Business Continuity Management (BCM) Plan, offering pragmatic guidelines and responses to support immediate crisis events across a wide spectrum of risk issues as more mature and comprehensive measures are brought into play—typically meeting the needs of the first 24 to 72 hours of a crisis event. The IMP might cover a broad array of subjects—for example, registering information from a threatening phone call, dealing with a road traffic accident, or responding to an explosion or natural disaster. The IMP is effectively the first line of defense for companies managing a crisis situation, while concurrently seeking accurate and timely information to support both strategic and longer term tactical decisionmaking requirements. The IMP works to support the risk management policies, procedures, and plans, taking guidance from such elements as the organizational interface, resource management, and communication plans, while operating under the principles of corporate policies and any security instructions, such as guard orders, travel management policies, and standard operating procedures (SOPs). Therefore, the IMP should be considered another cog within the machinery of a broader Business Continuity Management Plan.
Add a Note HereThe IMP should be integrated within the Business Continuity Management Plan, while being sufficiently detailed to provide an autonomous set of instructions to first line responders who will neither have the time, nor possibly the access, to the entire Business Continuity Management Plan. In order to provide a standalone policy and guidelines document that can act independently of the Business Continuity Management Plan (while still being integrated where desired or appropriate), a company should consider dividing its IMP into a series of components:

§  Add a Note HereInstructions.: Providing corporate policies and instructions as an overall guideline on how the IMP should be managed and conducted, as well as pertinent reference documents and policies within the Business Continuity Management Plan.
§  Add a Note HereManagement Tools.: Providing integration and instructional components linking the IMP to the Business Continuity Management Plan, as well as providing higherlevel management tools. Placing response guidelines into a management framework such as decision making authorities and communication plans.
§  Add a Note HereEducation.: Introducing managers to the nature of the risks they might have to deal with, providing sufficient knowledge and understanding to set the scene for implementing response plans within a context understandable to a wide user audience. Effectively providing a risk register.
§  Add a Note HereResponse Guidelines.: Comprising the actual response instructions and guidelines—walking managers through a series of simple and pragmatic steps to enable local and incident managers to bring control to a crisis as more mature plans and expertise are brought into play.
§  Add a Note HereData Collection.: Comprising data calls, indicating and structuring the critical information local managers will need to collate, consolidate, and distribute within the crisis management plan to ensure effective organizational decision making and resource management.
Add a Note HereThe IMP should be designed to be userfriendly, supporting managers who might not be versed in crisis management or security services to effectively bring the initial event under control—as more experienced risk and security professionals are mobilized to form a qualified and experienced crisis response team (CRT). The plan should therefore be written with a broad user audience in mind, rather than engineered to suit a particular division or industry sector.
Add a Note HereWhile many aspects of an IMP will be generic and will suit a range of operating environments based on the typical risk natures and impact effects a company may face, the IMP should (where appropriate) be tailored locally to reflect any unique risks and challenges that a specific operating environment may present. Considerations to local laws, customs, risk natures, and social factors should be considered and incorporated within the IMP to ensure that responses reflect those factors that will affect them—without disrupting the structure or format of the plan. These unique influences—whether local laws, social infrastructures, political and religious considerations, or topographical and climatic conditions—should be addressed within both the management guidelines section of the IMP and the individual data call and response guidelines. The composition of both the incident management team and the crisis management team should also reflect these influences so that the IMP can be most effectively implemented and sustained.
Add a Note HereThe IMP should be considered a tactical element of the contingency planning process, as well as a functional aspect of a crisis response, providing sensible and practical considerations, guidelines, and response measures for both corporate and project management and allowing first responders, incident managers, and crisis response teams to respond quickly and effectively to a range of problems—in synchronization with each other. An effective IMP reflects the level of effort a company invests in the safety and welfare of its employees, its protection of investment capital and interests, its brand image, as well as its desire to maximize the profitability of business operations. An IMP should not be viewed in isolation, but will be supported with a range of complementary products, policies, procedures, and activities.

Emergency Operations Planning | Disaster Planning

Many healthcare organizations confuse emergency operations planning with preparedness. In fact, developing an emergency operations plan (EOP) is but one component of an effective emergency management program to ensure preparedness. Healthcare organizations must develop plans for two different scenarios: one in which they serve as response agencies and one in which they are also victims of the incident. If one plan alone is developed, it must address both of these circumstances. An EOP can be thought of as an executive-level or leadership guidebook to manage the consequences of a disaster. It is a concept document that describes in general terms what response operations and functions will be performed or accomplished by what department, agency, or organization and under what circumstances. It is not a detailed reference tome to be used as a standard operating procedures manual by all response personnel during actual disaster operations.

In addition to EOPs, many organizations develop adjunctive standard operating procedures or job aids. These are more detailed, job-specific or department-specific checklists that delineate duties and responsibilities of each individual or position that is part of the organization response plan. Many of the details usually seen in EOPs should rightfully be placed in these documents, which provide instructions on how to do what is necessary in support of the EOP.

Of paramount importance in EOP development for incidents involving CBRNE are 15 basic issues. These areas are described in the following sections.

Notification. It is imperative that hospitals and emergency departments be included in a notification system that a disaster event has occurred that may affect healthcare services. In CBRNE events, the risk to the facility multiplies. Less than 20 percent of those contaminated by industrial chemicals are subsequently decontaminated on the scene (Levitin and Siegelson 1996); thus, the potential for arrival of contaminated victims at the healthcare facility must be considered and planned for.

Decontamination. Who will perform decontamination, where it is to be performed, how the disposition of victims and their belongings will be handled, and how contaminated wastewater will be handled should be addressed early in the planning process. If outside resources will be required, their availability and timeliness of response must be verified. Appropriate supplies and equipment, PPE, and a process for patient flow from contaminated to clean areas must be addressed.

Facility physical protection. In addition to actual victims, a large number of asymptomatic, possibly exposed individuals (often referred to as “worried well”) may also present for care, and this additional workload must be anticipated. As was seen in the Tokyo sarin event, these individuals may rapidly overrun the facility and may indeed pose a threat to continued operations (Matsui, Ohbu, and Yamashina 1996).

Evacuation. Released agents may remain airborne for a significant period of time. If the facility is downwind from the site of release, provisions must be established to rapidly decide if evacuation of patients, staff, and visitors is necessary. Transportation assets and receiving facilities must be identified. The establishment of alternate treatment facilities, until such time as environmental surety has been established, should also be included.

Shelter-in-place. When sufficient time to evacuate the facility is not available, expedient shelter-in-place provisions must be developed. Policies concerning securing of ventilation systems, internal movement of patients, and provision of PPE to critical facility personnel must be addressed. Sheltering-in-place can be accomplished horizontally (movement along the same level or floor into an area of the facility away from risk) or vertically (movement to higher or lower floors to escape threats where damage has occurred or where height is an issue, such as in flooding, fire, or high winds).

Detection. Detection is one of the weak links in the chain of emergency management and response. Most biological agents will not produce immediate symptoms, many chemical agents have delayed presentations, and, short of massive radiation doses, weeks may pass before those exposed may feel ill. Detection may occur through trend analysis if done in a near-real-time fashion through syndromic surveillance. Syndromic surveillance is a public health epidemiological process of collecting and analyzing patient data based on predetermined signs and symptoms, referred to as a syndrome. The goal of this analysis is to identify abnormal changes or trends in the numbers of patients presenting at portals of entry to the healthcare system. However, this must occur prior to the diseases that cause these syndromes progressing to the point of fatalities or severe morbidity, so that preventive and treatment measures may be instituted early in the course of the outbreak. Detection may also occur clinically or through laboratory analysis. The EOP should identify detection methods used and the procedures to be followed should an event be suspected.

Identification. Separate from detection, identification of agents that produce similar clinical syndromes or effects but have different treatment and protection regimens is a critical capability. Because most hospital laboratories do not have these sophisticated testing capabilities, methods of linking to CDCs Laboratory Response Network must be included in EOPs.

Triage. Triage of victims of a CBRNE event differs from that for other mass-casualty events because many more victims are likely. In the event of a biological-agent attack, two different victims with identical physiological measurements may have significantly different survival probabilities. Specific life-saving procedures, such as the administration of antidotes, may exist that would alter traditional triage algorithms predicated on the ability of the community healthcare network to absorb all casualties in short order—a situation unlikely to occur if the entire community is affected (Burkle 2002).

Treatment options. Just as triage of CBRNE victims is different, so are treatment concerns. The nature of traumatic disasters is such that the majority of victims who will eventually die do so at the scene or during the first 24 to 48 hours, and most do not require isolation to protect other patients and staff. Victims of chemical, biological, or radiological events may require sophisticated support (including burn therapy, isolation rooms, invasive monitoring, and mechanical ventilation) and may require these modalities for prolonged periods of time.

Surge capacity. The ability to increase facility capacity to accept more victims while facing resource constraints, especially during the initial hours and days after the event, is a huge challenge. Other patients not affected by the disaster may continue to present with emergencies that will require treatment. It is unacceptable to assume that only victims of the disaster will be ministered to during response operations. Early discharges, transfers, and use of home health care services may functionally expand facilities, while cancellation of elective procedures and same-day surgery may free more beds and staff. Extending shift times for staff from 8 hours to 12 hours for a short period (less than one week) effectively increases staff by 50 percent (Schultz, Mothershead, and Field 2002).

Surge capacity also applies to material resources. A facility may elect to increase caches of materials and supplies, but storage capabilities and costs of procurement may be a hindrance. Service-level or backup agreements or even memoranda of understanding with local pharmacies and hospital-supply distributors may provide a functional supply surge capacity at a fraction of the cost. This also obviates the need to dedicate space and personnel to store and maintain these goods.

Prophylaxis. Determining who will receive prophylaxis, and at what priority, in the event of a biological release and methods for distributing and dispensing these pharmaceuticals must be included in an EOP. Keep in mind that unprotected staff will most likely not work, nor will staff who are concerned about their families. The facility’s role in providing or dispensing prophylactic antibiotics to the community must also be ascertained.

Fatality management. A large event may produce a significant number of casualties who die after arrival at a hospital, overwhelming hospital morgues. If surge facilities for temporary interment cannot be identified through traditional services (e.g., city morgues, funeral homes), alternate sites must be established and appropriately equipped, staffed, and secured. It is unwise to presume that other response organizations will assume this responsibility. This issue, as others, should be addressed at the community-planning level, with all providers informed of the plan for mass-fatality management.

Counseling services. As seen after the World Trade Center and Murrah Federal Building attacks, responders may suffer both acute and long-term stress reactions, including delayed development of post-traumatic stress disorder (North et al. 2002). It is the responsibility of the healthcare organization to take care of its employees, and the provision of counseling services cannot be ignored. The healthcare system will also most likely be called on to provide these services for victims, victims’ families, and the community at large. Depending on the nature of the disaster, counseling requirements may far outstrip other medical needs of survivors and the community.

Horizontal and vertical integration. Integrating health services with other local or regional response organizations is essential for successful emergency operations. The prolonged phases of emergency response require that healthcare networks operate together and that various actions by other response organizations be interdependent. Organizations must not plan in a vacuum. Federal law requires the use of an incidentmanagement system in such operations (U.S. Congress 1996). A terrorist event involving CBRNE agents also mandates activation of the Federal Response Plan, which is soon to be replaced with the National Response Plan being developed by the Department of Homeland Security. (See Chapter 7 for more information on organized emergency management systems and the Federal Response Plan.)

Law enforcement and incident forensics. Any terrorist event is a criminal act, and law enforcement investigators will be intimately involved throughout all phases of response. Additional requirements for maintaining a legal chain of custody while handling and transporting samples, patient information sharing, and other cooperative ventures will require new approaches to incident management by all response organizations.

Audit Risk (Incident Management)

Auditors must make judgments on the acceptable levels of audit risk. It is important to remember that the levels of risk will vary across the different segments of the audit, as there are systems that are more susceptible to errors, ineffectiveness,
inefficiencies, and fraud.

An example of different types of risks associated with different segments of the audit, systems involving handling of cash are very susceptible to theft, where data processing systems are usually susceptible to inefficient resource allocation. In planning to manage audits, the most difficult judgment is the level of acceptable risk relevant to each audit segment. It is for this reason that auditors should be knowledgeable and experienced persons. Auditors must understand the control environment and the associated risks by examining management and application controls already in place. For example, when auditors review system development activities, they are seeking to understand the controls that are associated with these tasks.

They attempt to understand the business processes, including components such as human expertise, information technology, communications, management controls and application controls so they can assess related vulnerabilities and attendant risks. By understanding processes, components, behavior, and intended results, auditors can provide appropriate safeguard recommendations, if any apply.

Planning the Audit
In order to conduct an audit properly, a comprehensive audit management plan must be crafted.

The audit management plan should be action oriented, by listing the primary objectives to be performed. It should be tailored to the specific targeted business unit or division.

In drafting the audit management plan, a thorough review must be made of the organization's policies, with particular attention paid to risk management activities.

In the crafting, development, and implementation of policies, procedures, and standards, the organization is providing a process governing the activities of its employees consistent with the particular organization's goals and objectives. In many cases there are laws, regulations, and requirements affecting how the organization must conduct all or part of their business processes. Risk management is an integral part of the policy and procedure implementation. Auditing is basically an impartial review and investigation into the application of the organization's policies, procedures, and standards.

In crafting the audit management plan, the organization's strategic plan and objectives should be reviewed. This is essentially the basic guiding documentation for the organization. Depending on the business' units that are being audited, their applicable policies, procedures, and standards should be carefully reviewed. Job descriptions, organizational charts, lines of reporting, lines of authority, and chains of command should be made part of the information cache used to form the basis of the audit management plan.

In some business environments, audit management planning requires the auditors to conduct a preliminary survey through questionnaires to establish the appropriate scope addressing relevant business risks, develop the audit management plan, and direct auditor activities within the audit program. Often senior audit managers prepare questionnaires, also known as interrogatories, and send them to appropriate senior managers of the audit target. When completed, these questionnaires will provide the auditors with comprehensive visibility into the processes of the business unit.

These questionnaires may help auditors identify critical areas on which they need to focus their attention rather than taking a scattered, "shotgun" approach. As part of this preliminary questionnaire survey, auditors should review systems and processes to identify key controls already in place.

General questions that should be asked in preparing audit management plan questionnaires include but not limited to:

What are the critical issues regarding this business unit's operation?

What are the critical assets of this business unit?

What are the critical management functions?

What are the critical applications?

Does this business unit process sensitive data?

What are the risks to the business unit?

What substantive steps have been taken to address these risks?

What processes are least tested in the unit's business unit's daily operations? For example, if the business unit suffers from frequent power-outages and uses emergency power sources, including uninterruptible power sources and emergency generators, to restore operations, then power recovery requirements are likely to be well-formulated and tested. However, in the case of a complete disaster recovery plan, it may not be tested, and in fact, may not exist at all. The audit management plan should be the governing document for the "biggest bang for the buck."

Another valuable source in the development of an audit management plan is the review of previously performed audit reports. Many times these documents will identify potential weaknesses that should have been corrected or addressed earlier. The audit management plan is merely that, an activity plan. It should address those areas to be evaluated, and not too much more. Audit programs are different from audit plans in that they are comprehensive documents delving into the audit's "nuts and bolts."

Exhibit 1 is a brief example of an audit management plan.

====================================================================


Audit Step

Planning

1. Discuss nature and scope of audit with key senior personnel

2. Discuss audit requirements with senior managers

3. Assemble required audit staff and build team

4. Draft comprehensive audit program

Draft initial budget


Reporting

1. Hold opening meeting with appropriate personnel at initiation of audit

2. Use standard audit reports format including compilation of audit findings and recommendations

3. Hold closing meeting with key managers to review draft of final audit report

4. Identify key senior managers in the event of reporting irregularities before audit conclusion


Preliminary Audit Steps

1. Identify key employee contacts for audit

2. Obtain appropriate organization and business unit documentation including

A. Strategic business plans

B. Relevant policies, procedures, and standards for firewall administration unit

C. Relevant documentation to gain an understanding of the operations of the firewall administration unit


Audit Procedures

1. Understand unit's business practices and compare with organization's policies, practices, and standards

2. Understand and document business process flows

3. Interview pertinent employees in firewall administration unit to gain an understanding of their functions, risks, and other relevant issues


Testing

1. Testing will be performed to increase auditor's understanding of the firewall administration unit's function and activities

2. Testing will increase the auditor's understanding of managerial and application controls

3. Auditor will test if relevant controls are operating correctly and consistently

4. Auditor will test metrics to manage firewall administration

5. Auditor will test the correct design, development, and implementation of firewall administration

Popular Posts