Level 3
Category: Project and Work Management
SG 1 Identify Essential Service Dependencies
SP 1.1 Identify and Prioritize Essential Functions
SP 1.2 Identify and Prioritize Essential Resources
SG 2 Prepare for Service Continuity
SP 2.1 Establish Service Continuity Plans
SP 2.2 Establish Service Continuity Training
SP 2.3 Provide and Evaluate Service Continuity Training
SG 3 Verify and Validate the Service Continuity Plan
SP 3.1 Prepare for the Verification and Validation of the Service Continuity Plan
SP 3.2 Verify and Validate the Service Continuity Plan
SP 3.3 Analyze Results of Verification and Validation of the Service Continuity Plan
Identify and prioritize the essential functions that must be performed to ensure service continuity.
A business impact analysis
Identify and prioritize the essential services of the organization.
Identify the essential functions on which services rely.
Analyze the criticality of providing those functions and the impact to services if the essential functions cannot be performed.
Prioritize the list of essential functions that must be provided despite a significant disruption.
Orders of succession
Delegations of authority
Directory of critical staff with contact information
Data and systems required to support identified essential service functions
Records of service agreements and contracts
Records of legal operating charters (e.g., articles of incorporation, authorization by local, state, national government agencies)
Staff benefit balances, payroll, and insurance records
List of internal and external resources required
List of dependencies and interdependencies of resources
Identify and document internal and external dependencies.
Identify and document key staff and their roles in relation to service delivery.
Identify and document organizational and relevant stakeholder responsibilities.
Identify and document resources required by essential functions to ensure continuity.
Prioritize resources based on an evaluation of impact from their loss or from lack of access.
Ensure that safety provisions are made for staff, both internal and external, within the delivery environment and for organizational supporting functions.
Ensure that records and databases are protected, accessible, and usable in an emergency.
Formal statement of who has the authority to initiate and execute the service continuity plan
List of communication mechanisms needed to initiate the execution of the service continuity plan
List of threats and vulnerabilities that could impede the ability of the organization to deliver services
List of alternate resources and locations that support the organization’s essential functions
Documentation of the recovery sequence
List of key staff roles and responsibilities
List of stakeholders and the methods used for communicating with them
Documented methods for handling security related material as appropriate
Identify and document threats and vulnerabilities to ongoing service delivery
Document the service continuity plan.
Review the service continuity plan with relevant stakeholders.
Ensure that secure storage and access methods exist for the service continuity plan and critical information and functions needed to implement the plan.
Ensure that vital data and systems are adequately protected.
Document the acceptable service level agreed to by the customer for when a shift between the normal delivery environment and the recovery environment (e.g., site affected by disruption, alternate site) is necessary.
Plan for returning to normal working conditions.
Develop procedures for implementing the service continuity plan.
Revise the service continuity plan as necessary.
1. Service continuity training material
Develop a strategy for conducting service continuity training.
Develop and document service continuity training for each category of threat and vulnerability to service delivery.
Review service continuity training material with relevant stakeholders.
Revise the training material as needed to reflect changes in the service continuity plan and feedback on training effectiveness.
Training records
Evaluations of training effectiveness by students and training specialists
Suggested improvements to the service continuity plan
Deliver training that covers the execution of the service continuity plan to appropriate staff.
Maintain records of those who successfully complete service continuity training.
Solicit feedback on how well service continuity training prepared those who will execute the service continuity plan.
Analyze training feedback and document suggested improvements to the service continuity plan and service continuity training.
Verification and validation plan for assuring service continuity
Evaluation methods used for verification and validation
Description of environments necessary to conduct verification and validation
Verification and validation procedures
Criteria for what constitutes successful verification and validation
Develop a plan for conducting service continuity verification and validation.
Review with relevant stakeholders the verification and validation plan, including evaluation methods and the environments and other resources that will be needed.
Determine the procedures and criteria for verification and validation of the service continuity plan.
Identify changes to the service continuity plan from the preparation for verification and validation.
Roster of staff and relevant stakeholders involved in service continuity verification and validation
Results of service continuity plan verification and validation
Prepare the environment to conduct verification and validation.
Conduct verification and validation of the service continuity plan.
Record the results of verification and validation activities.
Verification and validation analysis reports
Improvement recommendations for the service continuity plan
Verification and validation improvement recommendations
Compare actual to expected results of service continuity plan verification and validation.
Evaluate whether restoration to agreed service levels or some other planned state was achieved or not.
Document recommendations for improving the service continuity plan.
Document recommended improvements to the verification and validation of the service continuity plan.
Collect improvement proposals for services or service system components as appropriate based on the analyses of results.
Provide information on how defects can be resolved (including verification methods, criteria, and the verification environment) and initiate corrective action.