Operational Resilience Standard - Section 1: Operational Resilience Flashcards
What is operational resilience?
The ability to resist operational stresses and failures, and support fast restoration and recovery.
The Operational Resilience Framework aims to standardise resilience requirements for which 5 key resources?
- Technology
- Data
- Suppliers
- People
- Property.
How does the Operational Resilience Standard define critical processes?
NAB processes “that must work” (as per Process Management Standard) and are those identified to have a significant impact to Customers, our Financial Resources, and Business Resiliency via Business Continuity and C3 Tiering.
Why does NAB prioritise its critical processes under C3 tiering?
To ensure critical processes are resilient by design.
How does NAB ensure critical processes are resilient by design?
By prioritising its critical processes under C3 Tiering
What benefit does C3 Tiering provide in a major disruption?
It provides direction on which critical processes need to be prioritised for recovery (related services/resource dependencies are tiered accordingly)
What are two key benefits of C3 Tiering for critical processes?
- Ensures they are resilient by design.
- Provides direction on prioritisation for recovery.
What is the priority order of the 5 tiers under C3 Tiering
- Country
- Company Critical
- Customer Time-Critical
- Customer Non-Time Critical
- Company Supporting
Under C3 Tiering, what is the definition of Country?
The stability of market, economy, or payments ecosystem would be threatened.
Under C3 Tiering, what is the definition of Company Critical?
The existence of the organisation could be at risk (e.g., Liquidity)
Under C3 Tiering, what is the definition of Customer Time-Critical?
There would be considerable detriment to end users of the process/
Under C3 Tiering, what is the definition of Customer Non-Time Critical?
Continuing to process existing customers and taking on new business whilst returning to business as usual operations.
Under C3 Tiering, what is the definition of Company Supporting?
Maintain back office functions that support the delivery of other operations of the firm.
Under C3 Tiering, what are three considerations for disruptions?
- Could damage financial industry.
- Could threaten company’s viability e.g., financial loss, legal, or reputational damage.
- Could cause intolerable harm to customers.
Are BNZ and International branches required to localise the critical business services within their region to the C3 Tiering?
Yes
What are the 5 key resources identified and mapped to support the delivery of NAB Critical Processes?
- Technology
- Data
- Property
- People
- Suppliers
What are 3 reasons to identify the resources in end-to-end NAB Critical Processes?
- Understand linkages and single points of failure between operational assets.
- Improve awareness of availability of substitute during disruptions.
- Increase robustness of business continuity planning and incident management.
What are the 6 key Operational Resilience activities (used to describe role expectations)?
- NAB Critical Process Prioritisation and Mapping.
- Process Resilience Assessment.
- Identification of Emerging Risks and Threats.
- Defining Impact Tolerance Statement
- Treatment and Remediation Plan
- Reporting and Monitoring
What is the purpose of Operational Resilience activity number 1. NAB Critical Process Prioritisation and Mapping?
- Prioritisation - in relation to the 3Cs.
- Mapping - ensure resource dependencies identified and linked to the end-to-end NAB Critical Process, and identify any vulnerabilities in the process.
What is the purpose of Operational Resilience activity number 2. Process Resilience Assessment?
Measure the end-to-end resilience of the NAB Critical Processes and their resources.
What are 5 disciplines involved in a resilience response?
- Business Continuity Management
- Service Continuity
- Enterprise Security
- Incident Management
- Crisis Management
Why does the bank adopt a horizontal end-to-end approach to resilience?
To help break down silos from each division and focus on consistent identification of what is important to the country, company, and customer.
What is Maximum Acceptable Outage (MAO)?
The maximum amount of time a system can be unavailable before its loss will compromise the organisation’s objectives or survival.
How does Maximum Acceptable Outage (MAO) operate alongside C3 tiering?
Each business process has a defined MAO rating include C3 classification. For example, payment processes have a 30min MAO and Country C3 Classification.
What are the Maximum Acceptable Outage (MAO) times for Critical and Non-Critical Processes?
- Critical -24hr MAO
- Non-Critical >24hr MAO