Page 18 - Nov/Dec 2020 Vol 38 No 5
P. 18
CYBER SECURITY by Heather Phillips
A Business Continuity Plan –
Your Best Shot in the Event of Disaster
A BCP (Business Continuity Plan) service or product. The inability to and should give guidelines with
gives an organization the best shot in fulfill obligations to provide services or requirements specifically defined. Rules
the event a disaster strikes. Whether it products may result in legal liabilities. and regulations provide a standard
is a fire, a building collapse, a malicious of guidelines from a regulating body
attack, sabotage, a power outage, or To ensure potential liabilities are to form guidance under which good
a natural disaster like a tornado or addressed in the BCP, an attorney practices should be observed.
earthquake, a catastrophe can hit at any should participate as a project team
moment without warning. member. Having an attorney involved Issued by third-parties, standards
as part of the BCP planning process are worldwide and relate to Business
The lack of a BCP does not mean can help define exposure to legal Continuity as a whole as part of
that the organization will not recover; liabilities if a responsibility was not compliance. Standards are adopted
it merely means the organization fulfilled. and put into practice to provide
will take longer to recover in an Force Majeure organizations with an outline for
unorganized fashion and may face legal business integrity.
ramifications. The organization’s goal Force majeure is a legal notion
is to maintain business functionality that excuses a party under contract An organization’s BCP needs to
or resume business functionality as for unforeseen situations of disaster. follow 15 different regulations to be
quickly as possible after a disaster. Force majeure refers to unforeseeable compliant with the United States
A BCP outlines procedures and circumstances that prevent a party Standards of regulation for compliance.
instructions the organization must from fulfilling a contract. Common An overview of the worldwide
follow to make the organization’s goal force majeure provisions may cover regulations can be found at www.BCI.
a success. several categories of events that could org.
Business Impact Analysis and Continuity impact the supply chain. ISO Compliance
Plans
The provision may cover risks that The BCP must meeting three
One part of composing a BCP is are reasonably beyond the control of additional regulations if the
the BIA (Business Impact Analysis). the party claiming force majeure. Legal organization is to be International
The BIA identifies the organization’s implications in BCP disaster planning Organization for Standardization
critical services or products as well as go far beyond force majeure clauses. (ISO) compliant. If the organization
the internal or external disruptions Contracts are a major part in BCP is a financial institution, a health
and legal impacts of disruptions. development. care facility, a government agency, a
Information can be obtained to utility distributer, or involved with
determine the disruptions and legal With the assistance of legal manufacturing, numerous other
requirements for delivering specific representation, contract requirements regulations must be in compliance.
services or products. such as labor contracts, insurance These additional regulations can be
agreements, and mortgages should found at www.BCI.org.
Once these variables are identified, be addressed in the BIA. An attorney
they must be prioritized. The impacts should also assist in contract review for Staffing plans during a disaster
of disruptions are identified along recovery services. require evaluating current employees
with potential revenue loss and Legal Representation and the resources in the departments.
additional expenses and losses. With During a disaster, establishing a labor
a major disaster, organizations are Legal representation is pool is essential. The BCP should
usually not able to pay the full cost recommended for Human Resources answer: What minimal employees are
of recovery, so they have insurance (HR) to ensure labor contracts are needed to maintain essential services?
to aid financially. It is important for not going to be invalidated upon BCP Will alternate employees such as
the BIA to appropriately decide what deployment. Legal representation also contractors be an option? Will work
needs insurance coverage and the is recommended to assure insurance options such as telecommuting be an
corresponding insurance coverage. agreements, especially Business option?
Interruption Insurance which covers
Continuity plans should be made loss of income suffered by a disaster, The BCP establishes flexible leave
for each of the organization’s internal are in compliance. options for employees who are
and external critical asset and critical unable to perform work duties due to
The BIA should define what attending to family needs. The BCP
insurance claims can be filed
18 TPW November/December 2020