Operational Resilience Standard - Section 2 - Role Expectations Flashcards
Who holds BEAR accountability for Resilience following delegation from the Board?
The Group Executive T&EO
Who is accountable for the ownership and operationalisation of this Standard and the execution of activities set out under this Standard?
The Executive Chief Controls Officer
What is the Process Owner accountable for?
The resilience of the end-to-end NAB Critical Process.
- Document process
- Identify risks and threats
- Define impact tolerance
- Identify remediation actions
- Maintain workaround strategies
What is the Resource Owner accountable for?
The resilience of resources that support the end-to-end NAB Critical Process.
- Resource mapping to process
- Identify substitutes
- Manage single points of failure, vulnerabilities, and concentration risks
- Set resource resilience thresholds
- Resilience assessments/ratings
- Execute remediation and TPs
What are the 5 key related resilience disciplines?
- Business Continuity Management
- Service Continuity
- Enterprise Security
- Incident Management
- Crisis Management
What are 3 things Enterprise Controls and Processes (EC&P) conduct for all Operational Resilience activities?
Includes Enterprise Resilience Team
- Allocate sufficient resources to support Line 1’s management of NAB’s resilience.
- Support development, implementation, and testing of controls and processes related to management of resilience risks.
- The Enterprise Resilience Team is responsible for developing, supporting, and advising the operationalisation of the business owned Operational Resilience standard and its supporting artefacts e.g., procedural documents and playbooks.
What 3 things do Second Line of Accountability (Risk) conduct for all Operational Resilience activities?
- Maintain BCM and other Risk policies, standards, and systems (e.g., GRACE).
- Establish risk appetite relating to resilience risks.
- Provide independent review and challenge of the management of resilience risks.
Under the Operational Resilience Standard, do Resilience Disciplines have any actual accountability?
No, but they are responsible for scenario exercises and are consulted on nearly everything else.
Under the Operational Resilience Standard, do Risk have any actual accountabilities or responsibilities?
No, but they are consulted on identification of risks/threats, defining impact tolerance statements, treatment plans and remediation, reporting, and playbooks.
What are EC&P Accountable for?
- C3 Tier categorisation
- Reporting
- Conducting scenario exercises
- Maintaining list of ‘severe but plausible’ scenarios
- Responsible for more