Posts Tagged ‘BS 25999-2’

Organizational Resilience & Voluntary Preparedness

Thursday, May 1st, 2008

On August 3, 2007, Public Law 110-53 (”Implementing Recommendations of the 9/11 Commission Act of 2007″) called for the development and identification of ‘all-hazards emergency preparedness’ standards and best practices, fostering a voluntary preparedness program that would specifically include small business concerns (see Title IX.) In January of 2008, an interdisciplinary team of representatives from professional organizations including security, business continuity, emergency, and enterprise risk management issued a report titled “Framework for Voluntary Preparedness“, highlighting the significance of ‘core elements’ shared by regulations, standards, and best practices across these resilience-related sectors. This represents another exciting validation of our business model and a great opportunity for growth. Securitydirector, LLC has been advocating the convergence of tools, workflows, and applications related to the wide spectrum of security, compliance, and resilience practices within the enterprise since 2001, with the first release of the Enterprise Resilience Portal (ERESP), where ‘core features’ are a process-engineering translation of ‘core elements’.
High costs and the absence of clear and direct economic incentives are recognized as key challenges in the movement of any organization toward the adoption of security, emergency, and continuity management practices, particularly for Small and Mid-size Enterprises (SME). However, resistance is also caused the highly fragmented, inconsistent, or often redundant nature of processes and applications that each initiative or management practice demands for adoption and implementation. The “siloed” approach that characterizes many of today’s resilience-related management initiatives such as IT security, RM, BCP, WVP, Assets Protection, etc., is often the primary cause of their cost, ineffectiveness, and weak adoption rates. ERESP was designed from ground up as a dedicated platform featuring the tools and workflows that support the entire lifecycle of such management programs, dramatically reducing both time and costs traditionally associated with creating and sustaining risk mitigation programs. ERESP represents not only the new platform for the exchange of knowledge, products, and services between selected security providers and corporate leaders, but also an innovative, measurable effort in support of risk-management-related economic incentives.