Overview
The Incident Response Plan is a key component of the Information Security Program. When unexpected security incidents and disruptions occur, too many organizations discover that their response plans are incomplete or outdated and that their staff are not adequately trained in the roles they are assigned. This leads to prolonged disruptions and expensive recovery efforts. Testing your plan on a regular basis provides the opportunity to:
- Verify the completeness and accuracy of the procedures in the plan
- Identify areas within the plan that should be enhanced or updated to improve effectiveness
- Determine the external resources required for an incident response
- Provide training for response teams to improve efficiency
- Demonstrate the ability to respond and recover from unplanned incidents and disruptions
- Build confidence in the program and the ability of staff
As a credit union, you are required to perform a test of your Incident Response Plan at least annually, and the results of the test are to be reviewed by Senior Management and the Board of Directors (or applicable committee). Performing the same test each year can lead to a false sense of security. Response and recovery tests and exercises should be designed with an increasing scope for continuous program improvement.
The certified Business Continuity and Response professionals at CU*Answers have the knowledge and experience necessary and will work with your team to develop and coordinate a testing schedule that accomplishes the goals listed above.
The Process
A certified CU*Answers Business Continuity professional will work with you and your team from start to finish to:
- Assess the current testing program and develop one that addresses the key areas of the plan
- Develop the testing program playbook that identifies the process and steps for each test or exercise
- Coordinate the necessary support teams throughout the duration of the test to ensure that the desired tasks are performed
- Recommend areas for improvement, both in procedures and continuity and recovery strategies
- Document the results of the test in a final report that can be presented to your Board of Directors and to auditors and examiners
Next Steps
Engagements start at $750.00 and are based on the size and complexity of operations and IT topology.
An initial (free) consultation is offered to assess the needs of your existing Incident Response Testing program and identify an action plan to get to the target state. A custom Statement of Work and proposal will be provided for each project.
Reviews
There are no reviews yet.