Operational Resilience Standard - Section 1: Operational Resilience Flashcards

1
Q

What is operational resilience?

A

The ability to resist operational stresses and failures, and support fast restoration and recovery.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The Operational Resilience Framework aims to standardise resilience requirements for which 5 key resources?

A
  1. Technology
  2. Data
  3. Suppliers
  4. People
  5. Property.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does the Operational Resilience Standard define critical processes?

A

NAB processes “that must work” (as per Process Management Standard) and are those identified to have a significant impact to Customers, our Financial Resources, and Business Resiliency via Business Continuity and C3 Tiering.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why does NAB prioritise its critical processes under C3 tiering?

A

To ensure critical processes are resilient by design.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How does NAB ensure critical processes are resilient by design?

A

By prioritising its critical processes under C3 Tiering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What benefit does C3 Tiering provide in a major disruption?

A

It provides direction on which critical processes need to be prioritised for recovery (related services/resource dependencies are tiered accordingly)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are two key benefits of C3 Tiering for critical processes?

A
  1. Ensures they are resilient by design.
  2. Provides direction on prioritisation for recovery.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the priority order of the 5 tiers under C3 Tiering

A
  1. Country
  2. Company Critical
  3. Customer Time-Critical
  4. Customer Non-Time Critical
  5. Company Supporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Under C3 Tiering, what is the definition of Country?

A

The stability of market, economy, or payments ecosystem would be threatened.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Under C3 Tiering, what is the definition of Company Critical?

A

The existence of the organisation could be at risk (e.g., Liquidity)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Under C3 Tiering, what is the definition of Customer Time-Critical?

A

There would be considerable detriment to end users of the process/

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Under C3 Tiering, what is the definition of Customer Non-Time Critical?

A

Continuing to process existing customers and taking on new business whilst returning to business as usual operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Under C3 Tiering, what is the definition of Company Supporting?

A

Maintain back office functions that support the delivery of other operations of the firm.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Under C3 Tiering, what are three considerations for disruptions?

A
  1. Could damage financial industry.
  2. Could threaten company’s viability e.g., financial loss, legal, or reputational damage.
  3. Could cause intolerable harm to customers.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Are BNZ and International branches required to localise the critical business services within their region to the C3 Tiering?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the 5 key resources identified and mapped to support the delivery of NAB Critical Processes?

A
  1. Technology
  2. Data
  3. Property
  4. People
  5. Suppliers
17
Q

What are 3 reasons to identify the resources in end-to-end NAB Critical Processes?

A
  1. Understand linkages and single points of failure between operational assets.
  2. Improve awareness of availability of substitute during disruptions.
  3. Increase robustness of business continuity planning and incident management.
18
Q

What are the 6 key Operational Resilience activities (used to describe role expectations)?

A
  1. NAB Critical Process Prioritisation and Mapping.
  2. Process Resilience Assessment.
  3. Identification of Emerging Risks and Threats.
  4. Defining Impact Tolerance Statement
  5. Treatment and Remediation Plan
  6. Reporting and Monitoring
19
Q

What is the purpose of Operational Resilience activity number 1. NAB Critical Process Prioritisation and Mapping?

A
  • Prioritisation - in relation to the 3Cs.
  • Mapping - ensure resource dependencies identified and linked to the end-to-end NAB Critical Process, and identify any vulnerabilities in the process.
20
Q

What is the purpose of Operational Resilience activity number 2. Process Resilience Assessment?

A

Measure the end-to-end resilience of the NAB Critical Processes and their resources.

21
Q

What are 5 disciplines involved in a resilience response?

A
  1. Business Continuity Management
  2. Service Continuity
  3. Enterprise Security
  4. Incident Management
  5. Crisis Management
22
Q

Why does the bank adopt a horizontal end-to-end approach to resilience?

A

To help break down silos from each division and focus on consistent identification of what is important to the country, company, and customer.

23
Q

What is Maximum Acceptable Outage (MAO)?

A

The maximum amount of time a system can be unavailable before its loss will compromise the organisation’s objectives or survival.

24
Q

How does Maximum Acceptable Outage (MAO) operate alongside C3 tiering?

A

Each business process has a defined MAO rating include C3 classification. For example, payment processes have a 30min MAO and Country C3 Classification.

25
Q

What are the Maximum Acceptable Outage (MAO) times for Critical and Non-Critical Processes?

A
  • Critical -24hr MAO
  • Non-Critical >24hr MAO