《监管政策手册》模块《TM-G-2 业务连续性规划》修订版中文简译
写在前面:越来越多的人们开始关注运营韧性。事实上,虽然该领域还在快速的发展中,但已经凝聚了一些共识。金融行业是最为关注运营韧性的行业之一,近几年来,多个发达国家/地区的金融监管机构和巴塞尔银行监管委员会陆续发布/修订了运营韧性(Operational Resilience)和业务连续性管理方面的正式文件。为让更多的专业人员和爱好者了解国际运营韧性领域的进展,学习并实践运营韧性的良好实践,在过去两年,我组织了两期公益翻译活动,翻译了巴塞尔银行监管委员会和英国金融监管机构的运营韧性相关资料,包括:
《运营韧性原则》中文简译(巴塞尔银行监管委员会)(2021年11月23日)
《操作风险稳健管理原则修订》中文简译(巴塞尔银行监管委员会)(2021年11月29日)
《运营韧性:重要业务服务的影响容忍度》中文简译(英格兰银行、英国审慎监管局(PRA)和英国金融行为监管局(FCA)联合说明文件)(2022年11月26日)
《政策声明|PS6/21 – 运营韧性:重要业务服务的影响容忍度》中文简译(英国审慎监管局(PRA)运营韧性政策声明)(2022年11月27日)
《PRA规则手册:CRR机构,Solvency II机构:运营韧性文书2021》中文简译(英国审慎监管局(PRA)运营韧性政策声明 附件1 — PRA规则手册运营韧性部分)(2022年11月28日)
《PRA监管声明|SS1/21 “运营韧性:重要业务服务的影响容忍度”》中文简译(英国审慎监管局(PRA)运营韧性政策声明 附件2 — PRA监管声明SS1/21)(2022年12月1日)
《PRA“运营韧性”政策说明》中文简译(英国审慎监管局(PRA)运营韧性政策声明 附件3 — 运营韧性政策说明)(2022年12月2日)
今年3月,我再次组织了一个公益翻译小组,对美国、爱尔兰、澳大利亚、新加坡和香港等地金融监管机构的运营韧性相关资料进行翻译。7月份前后,翻译小组成员陆续将翻译文稿发送给我,近期我会将这些资料审校完成,陆续在公众号发布。 以下是参与第三期运营韧性资料公益翻译小组的成员(排名不分前后,按姓氏拼音排序):
高洋(ICBC,william.yang.gao@gmail.com)
江磊(深圳龙华,2014595@qq.com)
刘琪岳(北京)
刘宇(深圳,13316880733@189.cn)
刘元锋(北京农商银行总行,liuyf@bjrcb.com)
林喆(广州,674441632@qq.com)
马骏(埃森哲/大连,patrick.ma2018@outlook.com)
孙宁莉(深圳市韧安咨询服务有限公司,115947186@qq.com)
王舵(大连童安应急管理科技有限公司,prekids@163.com)
徐文静(DNV,wen.jing.xu@dnv.com)
薛春娟(浙江省舟山市,793571689@qq.com)
张锋(北京,zhangfeng76@wo.cn)
周可政(上海,wikikivv@gmail.com)
王曙(新常安科技,kevinwang@vip.sina.com)
感谢公益翻译小组的各位专业人员抽出个人时间进行翻译工作。以下译文由我负责最终统一审校定稿,如译文中有任何不准确或理解错误的地方,都是由于我的原因造成,与诸位翻译人员无关。如对译文有意见或修改建议,请给我留言。
王曙(kevinwang) 2023.10.26
这份文件由香港金融管理局(HKMA)于2022年5月31日发布,阐述了香港金融管理局对业务连续性规划的监管方法,以及香港金融管理局期望认可机构在业务连续性规划时考虑的稳健实践,原文(英文)见:
以下中文简译将先给出(针对英文版)的翻译,再列出英文原文和中文(繁体)原文供参考。《TM-G-2 业务连续性规划》(修订版)取代了2022年12月2日发布的《TM-G-2 业务连续性规划》(V.1)。
关于香港金融管理局监管政策手册(SPM)的新模块OR-2和模块TM-G-2修订版的说明
这两个模块旨在实施巴塞尔银行监管委员会(BCBS)于2021年3月发布的运营韧性原则(POR),具体而言:
- 新模块OR-2作为指导性说明发布,说明了金管局应对运营韧性的总体方法。它阐述了金管局的期望,即每个认可机构都应具备运营韧性,并就认可机构如何制定一个综合和整体的运营韧性框架来支持这一点提供了高水平的指导。
- 模块TM-G-2修订版补充了新模块OR-2,为业务连续性规划提供了增强的指导,这是有效的运营韧性框架的关键组成部分。它包含了与POR中涵盖的业务连续性规划和测试相关的额外要求,还调整了用于业务连续性规划和运营韧性目的的术语,以提高清晰度。 认可机构应当注意,与运营韧性有关的许多概念和要求并非新鲜事物,已在金管局现行指导下广泛涵盖。因此,在执行OR-2的要求时,认可机构应参考相关监管政策手册模块。除了模块TM-G-2修订版之外,还包括关于“外包”的SA-2和关于“操作风险管理”的OR-1。
业务连续性规划 Business Continuity Planning 持續業務運作規劃
本模块应当与《引言》和包含本手册中使用的缩略语和其他术语的《术语表》一起阅读。如果在线阅读,可点击带蓝色下划线的标题以跳转到相关模块的超链接。
This module should be read in conjunction with the Introduction and with the Glossary, which contains an explanation of abbreviations and other terms used in this Manual. If reading on-line, click on blue underlined headings to activate hyperlinks to the relevant module.
本單元應連同引言及收錄本手冊所用縮寫語及其他術語的辭彙一起細閱。若使用本手冊的網上版本,可按動其下面劃有藍線的標題,以接通有關單元。
目的
阐述香港金管局对业务连续性规划的监管方法,以及金管局期望认可机构在业务连续性规划时考虑的稳健实践。
Purpose
To set out the HKMA’s supervisory approach to business continuity planning and the sound practices which the HKMA expects AIs to take into consideration in this regard
目的
說明金管局對持續業務運作規劃的監管方法, 以及金管局預期認可機構在進行持續業務運作規劃時會考慮的穩健做法。
分类
金管局作为指导性说明发布的非法定指引。
Classification
A non-statutory guideline issued by the MA as a guidance note
分类
金融管理專員以建議文件形式發出的非法定指引。
取代的原有指引
TM-G-2 “业务连续性规划”(V.1),2002年12月2日。
Previous guidelines superseded
TM-G-2 “Business Continuity Planning” (V.1) dated 02.12.02
取代舊有指引
於2002年12月2日發出的TM-G-2「持續業務運作規劃」 (V.1)。
适用范围
所有的认可机构。
Application
To all Ais
適用範圍
所有認可機構。
1. 引言
1. Introduction
- 引言
1.1 术语
1.1 Terminology 1.1 詞彙
1.1.1 在本模块中:
- “业务连续性规划”是指为确定紧急情况或灾难造成的潜在损失的影响所必需的预先规划和准备;制定和实施可行的恢复策略;编制恢复计划,确保认可机构在此情况下的运营连续性;以及管理全面的测试和维护计划;
- “业务连续性计划(“BCP”)”是指制定、编写和维护的一套程序和信息,以便在发生紧急情况或灾难时使用;
- “业务影响分析”是指管理层分析以确定和评估认可机构失去各种功能和服务的影响。影响分析试图衡量潜在损失和随着时间推移而不断升级的损失,以便为高级管理层提供可靠的数据确定关键运营。根据分析结果,认可机构应当能够确定所提供的关键运营的范围以及这些运营应当恢复的时间范围;
- “呼叫树”是指为传播信息而预先定义的员工联络人序列;
- “危机管理团队(“CMT”)”是指指导恢复行动,同时负责认可机构的生存和声誉的一批高管;
- “关键运营”是指:(i)认可机构开展的活动、流程和服务,及(ii)交付此类活动和服务所需的支持性资产(包括人员、技术、信息和设施),一旦扰断,可能对认可机构自身的生存能力构成重大风险,或影响认可机构在香港金融体系中的作用。认可机构应当参考“OR-2运营韧性”,了解有关该术语的更多详细信息;
- “危机管理”是指在处理可能威胁认可机构运营、员工、客户或声誉的特定紧急情况时,为CMT提供支持的整体流程;
- “恢复策略”是指恢复业务影响分析中确定的最小集合的关键运营的策略(例如,使用另一个交付渠道提供相同的运营);
- “严重但可能发生的情景”是指虽然不太可能但仍然有可能发生并会导致重大扰断的情况。认可机构应当参考“OR-2运营韧性”,了解该术语的更多详细信息;和
- “扰断容忍度”是指认可机构可接受的关键运营扰断的最大程度。认可机构应当参考“OR-2运营韧性”,了解该术语的更多详细信息。 1.1.1 In this module:
“business continuity planning” refers to the advance planning and preparations which are necessary to identify the impact of potential losses arising from an emergency or a disaster; to formulate and implement viable recovery strategies; to develop recovery plans which ensure continuity of an AI’s operations in that relation; and to administer a comprehensive testing and maintenance programme;
“Business Continuity Plan (“BCP”)” refers to a collection of procedures and information which is developed, compiled and maintained in readiness for use in the event of an emergency or disaster;
“business impact analysis” refers to a management level analysis which identifies and assesses the impact of losing the various functions and services within an AI. The impact analysis tries to measure the potential loss and escalating losses over time in order to provide senior management with reliable data for the identification of critical operations. Based on the results of the analysis, the AI should be able to identify the scope of the critical operations to be provided and the timeframe in which the operations should be resumed;
“call-out tree” refers to a pre-defined sequence of points of contact of staff for dissemination of information;
“crisis management team (“CMT”)” refers to a group of executives who would direct the recovery operations while taking responsibility for the survival and the reputation of the AI;
“critical operations” refers to: (i) activities, processes, and services performed by an AI, as well as (ii) the supporting assets (including people, technology, information and facilities) necessary for the delivery of such activities and services, which if disrupted, could pose material risks to the viability of the AI itself or impact the AI’s role within the Hong Kong financial system1. AIs should refer to “OR-2 Operational Resilience” for more details about this term;
“crisis management” refers to the overall process designed to support the CMT when dealing with a specific emergency situation which might threaten the operations, staff, customers or reputation of an AI;
“recovery strategy” refers to a strategy to resume the minimum set of critical operations identified in the business impact analysis (e.g. use of another delivery channel to provide the same operation);
“severe but plausible scenarios” refers to situations that would result in significant disruptions, and while unlikely to occur, remain probable. Ais should refer to “OR-2 Operational Resilience” for more details about this term; and
“tolerance for disruption” refers to the maximum level of disruption to a critical operation that an AI can accept. AIs should refer to “OR-2 Operational Resilience” for more details about this term.
1.1.1 在本單元內:
- 「持續業務運作規劃」指事先進行的規劃及準備,以識別因緊急或災難事故引起的潛在損失的影響;制定及推行可行的運作復原策略;制定運作復原計劃,以確保在該等情況下認可機構仍能維持運作;以及實施全面的測試及更新計劃;
- 「持續業務運作計劃」或「持續運作計劃」指認可機構制定、編寫及更新的一套程序及資料,以便一旦發生緊急或災難事故時使用;
- 「業務影響分析」指在管理層面進行的分析,以識別及評估認可機構的各項功能與服務在無法運作時所帶來的影響。影響分析嘗試評估有關的潛在損失及隨着事故持續而不斷增加的損失,從而向高級管理層提供可靠數據,以識別關鍵運作。根據分析結果,認可機構應能識別需維持的關鍵運作範疇及恢復提供該服務的時限;
- 「聯絡網」指為傳遞訊息而預先指定聯繫次序的員工通訊程序;
- 「危機管理組」指由行政人員組成的小組,負責領導運作復原程序,並同時負責確保認可機構可繼續經營及保障其信譽;
- 「關鍵運作」指:(i)認可機構執行的活動 、程序及服務,及(ii)為執行上述活動及服務所需的支援資產(包括人員、科技、資訊及設施),而如果上述活動 、服務或所需的支援資產受到干擾,便可能對該認可機構本身能否持續經營構成重大風險,或影響該認可機構在香港金融體系內的角色1。有關此用語的更詳盡說明,認可機構應參考單元OR-2「運作穩健性」;
- 「危機管理」指為協助危機管理組應付可能威脅認可機構的營運、員工、客戶或信譽的特定緊急狀況而設計的整體程序;及
- 「運作復原策略」指恢復在業務影響分析中識別的最低限度關鍵運作的策略(例如使用其他渠道以維持相同運作);
- 「嚴峻但可能發生的情景」指出現機會不大,但仍有可能發生並會導致嚴重干擾的情況。有關此用語的更詳盡說明,認可機構應參考單元OR-2「運作穩健性」;以及
- 「可承受影響上限」指認可機構對某關鍵運作可接受干擾的最高程度。有關此用語的更詳盡說明, 認可機構應參考單元 OR-2「運作穩健性」。
1.2 业务连续性规划的范围
1.2 Scope of business continuity planning 1.2 持續業務運作規劃的範疇
1.2.1 本模块应当与“OR-2运营韧性”一起阅读,以确保关键运营交付的目的,认可机构应当确保其符合其中规定的相关要求。
1.2.1 This module should be read in conjunction with “OR-2 Operational Resilience” with respect to the purposes of ensuring critical operations delivery and AIs should ensure that they are compliant with the relevant requirements specified therein.
1.2.1 本單元應連同單元OR-2「運作穩健性」一併閱讀,以確保維持關鍵運作,認可機構亦應確保遵守其中所訂明的要求。
1.2.2 2001年9月11日发生的(“9/11”)事件造成建筑物损毁、人员伤亡和金融机构运营普遍混乱,促使许多机构审查其业务连续性规划的范围。业务连续性规划的传统范围是短时间无法进入一个建筑物,这显然是不够的。
1.2.2 The destruction of buildings, loss of life, and the widespread dislocations to financial institutions’ operations resulting from the incident of 11 September, 2001 (“9/11”) have prompted many institutions to review their scope of business continuity planning. It is clear that the traditional scope of business continuity planning for inaccessibility of a single building for a short period is not adequate.
1.2.2 2001年9月11日發生的事件(「九一一」事件)引致建築物損毀、人命傷亡,以及金融機構 運作中斷。這次事件促使許多機構檢討其持續業務運作規劃的範疇。傳統的持續業務運作規劃是針對在一段短時間內不能進入一幢建築物而設計,這顯然並不足夠。
1.2.3 金管局认识到BCP涉及成本,而且为所有最坏情况制定和实施全面的计划可能不符合成本效益。然而,考虑到过去的事件,似乎明智的做法是,认可机构的规划是基于它们可能必须应对其关键办公室、设施、交易对手或服务提供商所在的建筑物和周围基础设施的完全毁坏,关键人员的损失,以及备份设施可能需要长期使用的情况。
1.2.3 The HKMA recognises that BCPs involve a cost, and that it may not be cost effective to have a fully developed and implemented plan for all the worst case scenarios. However, having regard to past events, it would seem sensible for AIs to plan on the basis that they may have to cope with the complete destruction of buildings and surrounding infrastructure in which their key offices, installations, counterparties or service providers are located, the loss of key personnel, and the situation that back-up facilities might need to be used for an extended period of time.
1.2.3 金管局明白持續運作計劃涉及成本,而且就所有最壞情況制定及實施全面的持續運作計劃並不符合成本效益。 然而,在參考過去發生的事件後,似乎較合宜的做法是認可機構在制定計劃時,應該考慮到其主要辦事處、設備、對手方或服務供應商所在的建築物及附近的基礎設施被完全摧毀、失去主要員工及可能要依賴備用設施一段較長時間的可能性。
1.2.4 认可机构可能会发现,考虑两个层次的计划是有用的:一个处理近期问题,需进行全面编制,并具有立即实施的物理能力;另一个可以是纸面形式,以应对长期情况(例如,如何租赁额外的场地,以及如何适应可能不是立即至关重要但会随着时间推移会变得重要的流程)。
1.2.4 AIs may find it useful to consider two-tier plans: one to deal with near-term problems, which would be fully developed with the physical capacity to put it into immediate effect and the other, which might be in paper form, to deal with a longer-term scenario (e.g. how to lease additional premises and how to accommodate processes that might not be critical immediately but would become so over time).
1.2.4 認可機構可考慮將計劃分為兩個層面:第一個層面是處理短期的問題,這個層面的計劃需完成所有的制定工作,而且可即時投入運作;另一層面可以屬文件形式,以處理長期的情況(例如有關如何租用額外場地及處理暫時可能並不重要,但在一段時間後可能會變為關鍵的程序)。
1.2.5 根据认可机构的独特情况,较长期计划可能包括如何重建主要场所或搬迁至新的永久工作地点的计划。例如,这可能要求将设计文件、平面图和布线图的副本保存在场外。
1.2.5 Depending on the individual circumstances of AIs, the longer-term plan may include plans on how to reconstruct the primary sites or to move to a new permanent work location. For example, this may require that duplicates of design documents, floor plans and cabling diagrams should be kept off-site.
1.2.5 視乎個別認可機構的情況而定,長期計劃可能包括如何重建主要場地或遷至新的固定工作地 點的計劃。例如有關計劃可能要求在主要場地以外儲存設計文件、樓面平面圖及導線安裝圖等的副本。
1.3 监管方法
1.3 Supervisory approach 1.3 監管方法
1.3.1 金管局的监管目标是协助认可机构制订可行和周密的BCP,以保障其业务的所有关键方面,和应对长时间的扰断。
1.3.1 The HKMA’s supervisory objective is to help ensure that AIs have workable and well thought through BCPs to protect all the critical areas of their business and to cope with prolonged disruptions.
1.3.1 金管局的監管目的是協助確保認可機構有可行及周全的持續運作計劃,以保障其所有關鍵業務範疇及應付業務長期受到干擾的情況。
1.3.2 金管局会在其现场检查、非现场审查以及与认可机构举行审慎会议时,酌情决定认可机构在业务连续性规划方面的工作是否足够。金管局在评估认可机构的BCP是否充分时,会考虑本模块所述的实践。
1.3.2 The HKMA will, in the course of its on-site examinations, off-site reviews and prudential meetings with AIs, determine as appropriate the adequacy of their efforts being put into business continuity planning. In assessing the adequacy of AIs’ BCP, the HKMA will have regard to the practices set out in this module.
1.3.2 金管局在進行現場審查、非現場審查及與認可機構進行審慎監管會議時,會按情況決定認可機構就持續業務運作規劃所做的工作是否足夠。在評估認可機構的持續運作計劃是否足夠時,金管局會參考本單元列載的做法。
1.3.3 认可机构如启用其BCP,应当立即通知金管局。金管局也应当在接获通知后定期收到进度报告,直至危机最终解决为止。
1.3.3 AIs should inform the HKMA promptly if their BCP is activated. The HKMA should also receive periodic progress reports upon being notified until the final resolution of the crisis.
1.3.3 認可機構若啟動持續運作計劃,應迅速通知金管局,並定期向金管局提交進度報告,直至危機最終得到解決。
2. 董事会和高级管理层监督
2. Board and senior management oversight 2. 董事局及高級管理層監察
2.1 制定政策、流程和职责
2.1 Establishment of policy, process and responsibility 2.1 定立政策、程序及責任
2.1.1 认可机构的董事会和高级管理层对业务连续性规划及其BCP的有效性负最终责任。高级管理层应当为业务连续性规划制定政策、标准和程序,并应当由董事会认可。高级管理层应当确保各级员工认真对待业务连续性规划,并投入足够的资源来实施计划。
2.1.1 The Board of Directors2 and senior management of AIs have the ultimate responsibility for business continuity planning and the effectiveness of their BCP. The senior management should establish policies, standards and processes for business continuity planning3, which should be endorsed by the Board. The senior management should ensure that business continuity planning is taken seriously by all levels of staff and that sufficient resources are devoted to implementing the plan.
2.1.1 認可機構的董事局2及高級管理層對持續業務運作規劃及持續運作計劃的成效負有最終責任。高級管理層應定立持續業務運作規劃3的政策、標準及程序,並應獲董事局認可。高級管理層應確保各級員工都對持續業務運作規劃採取認真及嚴謹的態度,並要為實施有關計劃投入足夠資源。
2.1.2在本模块中,建议的业务连续性规划流程由下图所示的几个关键部分组成:
高级管理层应当明确机构中哪个职能部门负责管理业务连续性规划的整个过程(BCP职能)。
2.1.2 In this module, the suggested process for business continuity planning consists of several key components as shown in the following diagram:
The senior management should establish clearly which function in the institution has the responsibility for managing the entire process of business continuity planning (the BCP function).
2.1.2 在本單元內,就持續業務運作規劃建議採納的程序包含以下幾個主要項目(如下圖所示):
高級管理層應清楚確立機構內負責管理整個持續業務運作規劃過程的部門(持續業務運作規劃部門)。
2.2 监控和报告
2.2 Monitoring and reporting 2.2 監察及匯報
2.2.1 BCP职能部门应当定期向董事会和高级管理层提交其BCP测试的报告。BCP的任何重大变更也应当报告给高级管理层。
2.2.1 The BCP function should submit regular reports to the Board and senior management on the testing of its BCP. Any major changes to the BCP should also be reported to the senior management.
2.2.1 持續業務運作規劃部門應就持續運作計劃的測試定期向董事局及高級管理層提交報告,並應向高級管理層匯報對持續運作計劃作出的任何重大改動。
2.2.2 认可机构的内部审计职能部门应当定期审查其BCP,以确定计划是否切合实际并保持相关性,以及是否遵守认可机构制定的政策和标准。
2.2.2 The internal audit function of an AI should conduct periodic review of its BCP to determine whether the plan is realistic and remain relevant, and whether it adheres to the policies and standards established by the AI.
2.2.2 認可機構的內部審計部門應定期檢討持續運作計劃,以決定該計劃是否切實可行及仍然適用, 以及計劃是否符合認可機構所定的政策及標準。
2.2.3 鉴于业务连续性规划的重要性,认可机构的首席执行官应当准备并签署正式的年度声明,并提交给董事会,说明所采用的恢复策略是否仍然有效,以及成文的BCP是否得到适当的测试和维护。年度声明应当纳入BCP,并作为金管局现场检查的一部分进行审查。
2.2.3 Given the importance of business continuity planning, the Chief Executive of AIs should prepare and sign-off a formal annual statement submitted to the Board on whether the recovery strategies adopted are still valid and whether the documented BCPs are properly tested and maintained. The annual statement should be incorporated into the BCP and will be reviewed as part of the HKMA’s on-site examinations.
2.2.3 鑑於持續業務運作規劃的重要性,認可機構的行政總裁應準備及簽署正式的年度聲明,並提交予董事局,說明所採納的運作復原策略是否仍然有效,以及列載的持續運作計劃是否經過妥善測試及更新。該年度聲明應併入持續運作計劃內,金管局進行現場審查時亦會查閱有關聲明。
3. 业务影响分析和恢复策略
3. Business impact analysis and recovery strategy 3. 業務影響分析及運作復原策略
3.1 业务影响分析
3.1 Business impact analysis 3.1 業務影響分析
3.1.1业务影响分析的目的是识别业务连续性面临的各种风险,并量化扰断的影响。业务影响分析有助于确定那些在发生灾难时必须由认可机构一致并有效地交付的关键业务活动、银行服务和内部支持功能。
3.1.1 The objective of the business impact analysis is to identify different kinds of risks to business continuity and to quantify the impact of disruptions. The business impact analysis helps to identify those critical business activities, banking services and internal support functions which, in the event of a disaster, must be consistently and effectively delivered by an AI.
3.1.1 業務影響分析的目的,是識別對持續業務運作構成威脅的各種不同風險,以及量化業務受干擾造成的影響。業務影響分析有助識別在發生事故時,認可機構必須繼續有效提供的關鍵業務活動、銀行服務及內部支援功能。
3.1.2业务影响分析通常包括两个阶段。第一阶段是确定在发生灾难时必须维护和持续的关键运营。这通常需要评估如果不能执行正常功能或服务时对认可机构的整体风险。评估标准包括对客户、人员、声誉和内部服务的影响,以及财务和法律影响。第二阶段是时间范围评估。它旨在确定认可机构需要多快地恢复确定的关键运营,同时考虑到认可机构设定的扰断容忍度。
3.1.2 The business impact analysis normally comprises two stages. The first stage is to identify critical operations that must be maintained and continued in the event of a disaster. This usually entails an assessment of the overall exposure to the AI if the normal functions or services cannot be performed. The criteria for the assessment include the impact on customers, personnel, reputation and internal services as well as the financial and legal implications. The second stage is a time-frame assessment. It aims to determine how quickly the AI needs to resume the critical operations identified, taking into account the tolerance for disruption set by the AI.
3.1.2 業務影響分析通常分為兩個階段。第一階段是識別一旦發生事故時,認可機構必須維持及繼續的關鍵運作。這個階段通常包括評估若認可機構無法執行其正常功能或服務時,認可機構所承受的整 體風險。評估的準則包括對客戶、員工、信譽及內部服務造成的衝擊,以至財政及法律方面所受的影響。第二階段是時限評估,目的是在顧及認可機構所設定的可承受影響上限後,決定認可機構需多快恢復所識別的關鍵運作。
3.1.3 根据业务影响分析,业务和支持职能部门应当能够确定在发生灾难时要交付的关键运营的最低水平。
3.1.3 Based on the business impact analysis, the business and support functions should be able to define the minimum level of critical operations to be delivered in the event of a disaster.
3.1.3 根據業務影響分析的結果,業務及支援部門應能定出在發生事故時需維持的最低限度的關鍵運作。
3.2 恢复策略制定
3.2 Recovery strategy formulation 3.2 制定運作復原策略
3.2.1业务和支持职能部门应当制定自己的恢复策略,说明如何实现恢复时间范围,并交付业务影响分析得出的最低水平的关键运营。这涉及决定备用场所、恢复人员总数和提供此水平运营所需的相关工作空间、应用程序和技术要求、办公设施和重要记录等。作为其中的一部分,认可机构也可以考虑启用在家工作安排、拆分团队安排或其他机制的可能好处,使团队能够在需要时相互替补。认可机构应当注意,他们可能需要应对超出正常情况下的工作量。
3.2.1 Business and support functions should formulate their own recovery strategies on how to achieve the recovery time-frame and to deliver the minimum level of critical operations derived from the business impact analysis. This involves determination of an alternate site, total number of recovery personnel and the related workspace, applications and technology requirements, office facilities and vital records required for the provision of such levels of operations. As part of this, AIs may also consider the possible benefits of activating work-from-home arrangements, split-team arrangements or other mechanisms that enable teams to stand in for each other where needed. AIs should take note that they might need to cater for processing volumes that exceed those under normal circumstances.
3.2.1 業務及支援部門應就如何達到業務影響分析所定立的最低限度關鍵運作及有關復原時限,自行制定運作復原策略。這包括決定備用場地、負責復原行動的人員總數,以及為提供有關水平的運作所需的工作空間、應用程式及科技要求、辦公室設施及重要記錄等。作為有關策略的其中一部分,認可機構亦可考慮啟動在家工作安排、分隔工作安排或其他機制,讓工作團隊在有需要時可互相替補。 認可機構也應留意,它們要處理的工作量可能會比正常情況下大。
3.2.2 业务影响分析中时间范围评估的结果是单个服务恢复优先级的关键决定因素。关键运营之间的相互依赖关系是决定恢复策略和优先顺序时的另一个主要考虑因素。例如,前台运营的恢复高度依赖于中台和后台支持功能的恢复。
3.2.2 The result of the time-frame assessment in the business impact analysis is the key determination factor for the recovery priority of individual services. The interdependency among critical operations is another major consideration in determining the recovery strategies and priority. For example, the recovery of the front office operations is highly dependent on the recovery of the middle office and back office support functions.
3.2.2 業務影響分析的時限評估結果是個別服務復原次序的主要決定因素。此外,關鍵運作之間互倚關係的情況也是決定復原策略及優先次序的另一個主要考慮因素。例如前線部門的運作復原高度倚賴中間部門及後勤支援部門的運作復原。
3.2.3在进行了业务影响分析并制定了恢复策略后,业务和支持职能部门应当建立提供基本业务和技术服务水平的最低BCP要求。为了避免在后期出现任何不必要的争论和不适当的BCP投资,这些BCP要求应当在着手编制BCP之前得到高级管理层的批准。此外,高级管理层还应当确保在新业务产品和服务的规划和开发阶段就已考虑业务连续性要求。
3.2.3 Having performed the business impact analysis and formulated the recovery strategies, business and support functions should have established the minimum BCP requirements for the provision of essential business and technology services levels. To avoid any unnecessary arguments and inappropriate BCP investment at a later stage, these BCP requirements should be approved by the senior management prior to proceeding to the development of the BCP. In addition, senior management should also ensure that the business continuity requirements should be considered at the planning and development stages of new business products and services.
3.2.3 進行業務影響分析及制定運作復原策略後,業務及支援部門應已確立對於持續運作計劃所需的最低要求,以提供必要水平的業務及科技服務。為避免日後出現不必要的爭論及就持續運作計劃作出不適當的投資,這些對持續運作計劃的要求應先行得到高級管理層批准,才進行制定持續運作計劃的工作。此外,高級管理層亦應確保在新產品及服務的策劃及發展階段就已考慮有關持續業務運作的要求。
4. 编制业务连续性计划
4. Development of Business Continuity Plan 4.持續業務運作計劃的制定
4.1 概述
4.1 Overview 4.1 概要
4.1.1 一旦决定了单个业务和支持功能的恢复策略,并最终确定了BCP要求,就应当开始编制BCP。BCP的目标是提供详细的指导和程序,以应对和管理危机,恢复和持续在业务影响分析中确定的关键运营,并最终使业务返回正常。
4.1.1 Once the recovery strategies for individual business and support functions are determined and the BCP requirements are finalised, the development of the BCP should commence. The objective of the BCP is to provide detailed guidance and procedures to respond to and manage a crisis, to resume and continue critical operations identified in business impact analysis, and to ultimately return to business as usual.
4.1.1 一旦決定了個別業務及支援部門的運作復原策略及定出有關持續運作計劃的要求後,認可機構便應展開制定持續運作計劃的工作。持續運作計劃的目的,是要就如何應付及管理危機、恢復及維持在業務影響分析中確定的關鍵運作,以及最終使業務回復正常,提供詳盡指引及列出詳細的程序。
4.1.2 有效的BCP具前瞻性,并应当针对一系列包含扰断事件和事故的严重但可能发生的情景进行验证。BCP应当识别关键运营以及支持这些关键运营的关键内部和外部依赖关系。它应当包含业务影响分析、恢复策略、测试方案、培训和意识方案、沟通策略和危机管理流程。认可机构交付关键运营(包括那些依赖关键第三方服务的)的BCP应当与其运营韧性框架保持一致。同样的一致性要求也适用于认可机构恢复和处置计划中可能包含的BCP。
4.1.2 An effective BCP is forward-looking, and should be validated for a range of severe but plausible scenarios which contain disruptive events and incidents. The BCP should identify critical operations as well as the key internal and external dependencies supporting these critical operations. It should incorporate business impact analysis, recovery strategies, testing programmes, training and awareness programmes, communication strategies and crisis management processes. An AI’s BCP for the delivery of critical operations, including those reliant on critical third-party services, should be consistent with its operational resilience framework. The same consistency requirement also applies to BCPs which may be contained within an AI’s recovery and resolution plans.
4.1.2 有效的持續運作計劃應具前瞻性,並應驗證能應對一系列包含具破壞力事件或事故的嚴峻但可能發生的情景。持續運作計劃應識別關鍵運作及支援該等關鍵運作的主要內部與外部倚賴關係。有關計劃應包含業務影響分析、復原策略、測試方案、培訓及認知方案、通訊策略及危機管理程序。認可機構就維持關鍵運作(包括倚賴關鍵第三方服務的關鍵運作)制定的持續運作計劃應與其運作穩健性架構一致。同樣的一致性要求亦適用於認可機構的恢復與處置計劃內可能包含的持續運作計劃。
4.1.3 认可机构应当在制定恢复组织、程序和安排的同时,编制其BCP文件。BCP文件记录和编制不应当被视为两个不相关且独立的项目。否则,可能很难确保BCP的内容与实际的恢复过程和安排一致。BCP编制过程总结如下。
4.1.3 AIs should perform documentation of their BCP along with the development of the recovery organisation, procedures and arrangements. The BCP documentation and development should not be treated as two unrelated and independent projects. Otherwise, it may be difficult to ensure that the content of the BCP is consistent with the actual recovery processes and arrangements. The BCP development process is summarised below.
4.1.3 認可機構應在制定運作復原架構、程序及安排時,編製持續運作計劃的文件。認可機構不應視持續運作計劃的制定及文件記錄為兩項不相關及獨立的工作,否則便難以確保持續運作計劃的內容與實際的運作復原程序及安排一致。持續運作計劃的制定過程綜合如下。
4.2 危机管理流程
4.2 Crisis management process 4.2 危機管理程序
4.2.1 需要注意的是,灾难发生后会演变。认可机构应当成立CMT,以应对和管理危机的各个阶段。CMT应当由高级管理人员和主要支持功能(例如建筑设施、信息科技、公司传播和人力资源)的负责人组成。
4.2.1 It is important to note that a disaster will evolve after occurrence. AIs should establish a CMT to respond to and manage the various stages of a crisis. The CMT should comprise members of the senior management and heads of major support functions (e.g. building facilities, IT, corporate communications and human resources).
4.2.1 認可機構必須留意,災難事故發生後會出現變化。認可機構應成立危機管理組,以應付及管理危機的各個發展階段。危機管理組的成員應包括高級管理層及主要支援部門(例如建築物設施、資訊科技、公司通訊及人力資源)的負責人。
4.2.2 BCP应当规定危机管理流程,作为书面指导,协助高级管理层处理和应对紧急情况,以避免对整个业务产生溢出效应。高级管理层应当识别潜在的危机情景,并在适用的情况下编制具体的危机管理程序来管理这些情景(例如处理炸弹威胁的程序不同于处理重大电力故障的程序)。整个危机管理过程至少应当包括以下内容:
- 确保及早发现紧急情况或灾难并及时向CMT报告事件的流程;
- 确定管理运营扰断的角色和职责的流程,以及在发生影响关键人员的扰断时权力继任的明确指导;
- CMT评估对认可机构的总体影响的流程,以及就适当的应对行动(即员工安全、事件控制和具体的危机管理程序)做出快速决定;
- 从营业地点安全撤离的安排(例如,在灾难发生后立即引导员工前往预先安排的紧急集结区,核实所有员工和访客名单并通过不同方式追踪失踪人员);
- 明确启用BCP和/或备用场所的内部决策流程和标准;
- 为CMT收集最新状态信息的流程(例如,确保相关业务和支持职能部门的关键人员定期举行电话会议,报告恢复过程的状态);
- 及时内部和外部沟通的流程(见下文第4.7节);和
- 监督受影响设施和业务服务的恢复和复原工作的流程。 4.2.2 BCPs should set out a crisis management process that serves as documented guidance to assist senior management in dealing with and containing an emergency to avoid spillover effects to the business as a whole. Senior management should identify potential crisis scenarios and where applicable develop specific crisis management procedures for managing these scenarios (i.e. a procedure to handle a bomb threat is different from that to handle a major power failure). The overall crisis management process, at a minimum, should contain the following:
the process for ensuring early detection of an emergency or a disaster and prompt notification to the CMT about the incident;
the process for establishing the roles and responsibilities for managing operational disruptions and clear guidance regarding the succession of authority in the event of a disruption that impacts key personnel;
the process for the CMT to assess the overall impact on the AI and to make quick decisions on the appropriate responses for action (i.e. staff safety, incident containment and specific crisis management procedures);
the arrangements for safe evacuation from business locations (e.g. directing staff to prearranged emergency assembly area, taking attendance of all employees and visitors and tracking missing people through different means immediately after the disaster);
clear internal decision-making process and criteria for activation of the BCP and/or alternate sites;
the process for gathering updated status information for the CMT (e.g. ensuring that regular conference calls are held among key staff from relevant business and support functions to report on the status of the recovery process);
the process for timely internal and external communications (see subsection 4.7 below); and
the process for overseeing the recovery and restoration efforts of the affected facilities and the business services.
4.2.2 持續運作計劃應列明危機管理程序,作為指引文件,以協助高級管理層處理及遏止緊急事故繼續惡化,防止事故影響機構的整體業務。高級管理層應識別潛在的危機情況,以及在適用情況下制定相關的危機管理程序以處理這些情況(例如處理炸彈威脅的程序有別於處理大規模電力故障的程序) 。 整個危機管理程序至少應包含以下項目:
- 確保及早發現緊急或災難事故的程序,以及迅速通知危機管理組的方法;
- 確立管理運作受干擾的角色與責任的程序, 以及一旦出現干擾以致影響主要人員時的權力承接安排的清晰指引;
- 危機管理組評估事件對認可機構的整體影響的程序,以及迅速決定適當回應行動的步驟(即員工的安全、遏止事故繼續惡化及有關的危機管理程序);
- 安全撤離辦公地點的安排(例如帶領員工前往預先安排的緊急集合地點、清楚點算全體僱員及訪客、在災難事故後立即透過不同方法追查失蹤人士的下落);
- 啟動持續運作計劃及/或備用場地的清晰內部決策程序及準則;
- 為危機管理組收集最新情況資料的程序(例如確保相關業務及支援部門的主要人員定時進行電話會議,匯報運作復原程序的狀況);
- 及時進行內部及對外通訊的程序(見下文第4.7段);及
- 監察受影響設施與業務服務的復原及恢復工作的程序。 4.2.3 如果CMT成员需要从其主要业务地点撤离,认可机构应当设立指挥中心,为CMT提供必要的工作空间和设施。指挥中心应当与认可机构的主要业务地点保持足够距离,以避免受到同一灾难的影响。
4.2.3 If CMT members need to be evacuated from their primary business locations, AIs should set up command centres to provide the necessary workspace and facilities for the CMT. Command centres should be sufficiently distanced from AIs’ primary business locations to avoid being affected by the same disaster.
4.2.3 若危機管理組成員需要從主要工作地點撤離,認可機構應設立指揮中心,為危機管理組提供所需的工作空間及設施。指揮中心應與認可機構的主要運作地點相隔足夠的距離,以免受到同一災難事故的影響。
4.3 业务重续
4.3 Business resumption 4.3 恢復業務運作
4.3.1 每个相关的业务和支持职能部门都应当成立业务恢复小组,下设业务重续小组执行业务重续流程。应当向小组分派具有所需知识和技能的适当的恢复人员。认可机构应当确保为所有关键过程确定后备恢复人员。应当备有恢复人员和后备人员的联系电话,包括办公时间以外的联系信息,防止紧急情况出现(例如钱包卡)。此外,认可机构还应当考虑员工轮班计划,以涵盖业务恢复所需的延长工作时间。
4.3.1 Each relevant business and support function should establish a business recovery team which may have subteams to carry out the business resumption process. Appropriate recovery personnel with the required knowledge and skills should be assigned to the teams. AIs should ensure that alternate recovery personnel are identified for all critical processes. Contact numbers for recovery and alternate personnel, including contact information after office hours, should be available for an emergency (e.g. as wallet cards). AIs should also consider a staff rotation plan in order to cover extended working hours for business recovery.
4.3.1 每個相關業務及支援部門都應成立業務復原小組,小組下可再設附屬小組,負責執行業務恢復程序。有關部門應指派具備所需知識與技能的適當復原人員加入該等小組。認可機構應確保所有關鍵程序均有後備復原人員,並應備有復原及後備人員的聯絡電話,包括辦公時間以外的聯絡資料,以便在發生緊急事故時可作聯絡之用(例如放在錢包內的聯絡資料卡)。此外,認可機構應考慮編製職 員輪值表,以應付業務復原期間要延長工作時間的情況。
4.3.2 一般来说,业务恢复流程包括三个主要阶段:
- 动员阶段 — 此阶段旨在通知恢复团队(例如,通过呼出树),并确保重续业务服务所需的资源(例如,供应商提供的恢复服务)。如果需要不同于BCP中预先确定的顺序,此阶段可能涉及决定恢复业务服务的顺序;
- 替代处理阶段 — 此阶段强调在备用场所和/或以不同于正常流程的方式重续业务和服务交付。这可能需要重建和验证记录,建立新的控制,替代手工流程,以及与客户和交易对手打交道的不同处理方式;和
- 完全恢复阶段 — 此阶段指灾难后恢复到永久场所的流程。对于业务来说,这与启用BCP的流程同样困难和关键。 4.3.2 Generally, the business resumption process consists of three major phases:
The mobilisation phase – This phase aims to notify the recovery teams (e.g. via a call-out tree) and to secure the resources (e.g. recovery services provided by vendors) required to resume business services. This phase might involve determination of the sequence for restoring business services if it needs to be different from the pre-determined sequence in the BCP;
The alternate processing phase – This phase emphasises the resumption of the business and service delivery at the alternate site and/or in a different way than the normal process. This may entail record reconstruction and verification, establishment of new controls, alternate manual processes, and different ways of dealing with customers and counterparties; and
The full recovery phase – This phase refers to the process for moving back to a permanent site after a disaster. It is as difficult and critical to the business as the process to activate the BCP.
4.3.2 一般來說,業務恢復程序分為三個主要階段:
- 啟動階段 - 這個階段的目標是通知復原小組(例如經聯絡網)及取得恢復業務服務所需資源(例如供應商提供的復原服務)。如果恢復業務服務的次序需要有別於持續運作計劃所預設的次序,便要在這個階段決定有關的次序;
- 後備操作階段 - 這個階段的重點是在備用場地及/或以有別於正常程序的方法恢復業務及提供服務。這可能包括重建及確認記錄、制定新的管控措施、後備人手處理程序,以及用不同方法應對客戶及對手方;及
- 全面復原階段 - 這個階段指在災難事故後遷回固定場地運作的過程。這個階段與啟動持續運作計劃的程序一樣困難,對業務同樣影響重大。 4.3.3 对于前两个阶段,应当明确职责并确定活动的优先次序。应当制定恢复任务清单并将其包含在BCP中。人们认识到,全面恢复阶段涉及的某些任务可能取决于有关灾害的性质,并且可能难以事先制订详细的计划。但是,BCP至少应当确定和计划所有事件中需要的活动,例如,核查永久站点的安全性和准备情况。
4.3.3 For the first two phases, clear responsibilities should be established and activities prioritised. A recovery tasks checklist should be developed and included in the BCP. It is recognised that certain tasks involved in the full recovery phase may depend on the nature of the disaster concerned and that it may be difficult to formulate detailed plans in advance. However, the BCP should at least identify and plan for activities which would be required in any events, for example, the verification of the safety and readiness of the permanent site.
4.3.3 認可機構應就首兩個階段清晰指明各崗位的責任,並列明有關活動的先後次序。認可機構應制定復原工作清單,並列入持續運作計劃內。部分在全面復原階段中的工作可能會因應災難事故的性質不同而有所差異,因此或難以預先定立周詳計劃。然而,持續運作計劃應至少識別在任何情況下也必須進行的工作,例如檢查固定場地是否安全和準備就緒,並就此制定計劃。
4.4 技术恢复
4.4 Technology recovery 4.4 資訊科技系統運作復原
4.4.1 业务重续往往依赖于技术资源(包括应用程序、硬件设备和网络基础设施以及电子记录)的恢复。在决定功能的恢复策略时,应当指定各个业务和支持功能恢复期间所需的技术要求。
4.4.1 Business resumption very often relies on the recovery of technology resources that include applications, hardware equipment and network infrastructure as well as electronic records. The technology requirements that are needed during recovery for individual business and support functions should be specified when the recovery strategies for the functions are determined.
4.4.1 恢復業務運作的程序往往都要倚賴資訊科技資源的復原,包括應用程式、硬件設備及網絡基建以及電子記錄。認可機構在決定個別業務及支援部門的復原策略時應具體列明該等部門在復原過程中對資訊科技的要求。
4.4.2 认可机构应当注意关键技术设备和设施的韧性,如不间断电源(“UPS”)和冷却系统。这些设备和设施应当受到持续监测以及定期维护和测试。这将降低必须启动BCP的可能性,以及对正常业务不可避免的干扰。
4.4.2 AIs should pay attention to the resilience of critical technology equipment and facilities such as the Uninterruptible Power Supply (“UPS”) and the cooling systems. Such equipment and facilities should be subject to continuous monitoring and periodic maintenance and testing. This would reduce the probability of having to activate the BCP and the inevitable disruptions to normal business.
4.4.2 認可機構應留意關鍵科技設備及設施的穩健性,例如不間斷電源供應器及冷卻系統等的性能,並應持續監察及定期維修與測試該等設備及設施。這樣可減低需要啟動持續運作計劃的機會,及減少日常業務受到干擾的可能性。
4.4.3 应当指派适当人员负责技术恢复。需要为关键技术恢复人员确定后备人员,以防他们无法执行恢复过程。
4.4.3 Appropriate personnel should be assigned with the responsibility for technology recovery. Alternate personnel needs to be identified for key technology recovery personnel in case of their unavailability to perform the recovery process.
4.4.3 認可機構應指派適當人員負責資訊科技系統的復原,同時亦要就主要科技復原人員指定後備人員,以應付主要人員未能出現執行復原程序的情況。
4.5 业务连续性模式
4.5 Business continuity models 4.5 持續業務運作的模式
4.5.1 有多种业务连续性模式可让认可机构采用来处理长时间扰断。传统模式是“活动/备份”模式,被许多组织广泛使用。这种传统模式是基于一个“活动的”运营场所和一个相应的后备场所(备份场所),均用于数据处理和业务运营。如果“备份场所”需要配备设备以支持“活动场所”的长时间扰断,则这种模式可能需要大量投资。
4.5.1 There are various business continuity models that could be adopted by AIs to handle prolonged disruptions. The traditional model is an “active/back-up” model, which is widely used by many organisations. This traditional model is based on an “active” operating site with a corresponding alternate site (back-up site), both for data processing and for business operations. This model may require significant investment if the “back-up site” needs to be equipped to support for prolonged disruptions of the “active site”.
4.5.1 認可機構可選用不同的持續業務運作模式,以處理業務長時間受到干擾的情況。傳統模式是「常用/備用」模式,許多機構都選用這種模式。傳統模式是以一個「常用」運作場地為根據,並設有相應的備用場地(後備場地),兩個場地都是用作數據處理及業務運作。若「後備場地」需要有充足設備以便在「常用場地」長時間受到干擾時提供支援,認可機構便可能要就這個模式作出重大投資。
4.5.2 新兴的分离运营模式是一种不同的业务连续性模式,已经被一些机构采用。这种模式是在两个或多个分散的活动场所上运行相同的关键运营,互相提供内在的备份(例如客户服务呼叫中心)。每个场所都有能力在一段较长的时间内承担另一个场所的部分或全部工作。这种策略可以提供几乎立即恢复的能力,并且通常能够处理长时间扰断的问题。
4.5.2 An emerging split operations model, which has already been used by some institutions, is a different business continuity model. This model is to operate with two or more widely separated active sites for the same critical operations, providing inherent back-up for each other (e.g. call centres for customer services). Each site has the capacity to take up some or all of the work of another site for an extended period of time. This strategy can provide nearly immediate resumption capacity and is normally able to handle the issue of prolonged disruptions.
4.5.2 部分機構所採用的是新近出現的「分隔運作」模式,這是一種不同的持續業務運作模式。在這種模式下,相同的關鍵運作在兩個或以上相距很遠的常用場地運作,互相提供後備支援(例如客戶服務熱線中心)。每個場地都有能力在一段長時間內承擔另一個場地的部分或全部工作。這個策略幾乎可以提供即時的恢復能力,而且一般都能應付業務長時間受到干擾的情況。
4.5.3分离运营模式可能会增加运营成本,因为要维护每个场所的过剩容量,并增加了运营复杂性。可能很难维持经过适当培训的员工,多个场所也会造成技术问题。
4.5.3 The split operations model may incur higher operating costs, in terms of maintaining excess capacity at each site and added operating complexity. It may be difficult to maintain appropriately trained staff and pose technological issues at multiple sites.
4.5.3 「 分隔運作」模式的運作成本可能會較高,原因是每個場地都要維持額外的運作能力,運作的複雜程度亦會增加。此外,要維持受過適當訓練的員工可能會有困難,場地數目亦可能會增加資訊科技上的困難。
4.5.4 采用哪种业务连续性模式的问题,由各机构根据其经营环境的风险评估和自身运营特点来判断。
4.5.4 The question of what business continuity model to adopt is for individual institutions’ judgement based on the risk assessment of their business environment and the characteristics of their own operations.
4.5.4 認可機構應根據其對經營環境的風險評估及其本身業務運作的特點,決定選用哪種持續業務 運作模式。
4.6 重要记录管理
4.6 Vital record management 4.6 重要記錄管理
4.6.1 每个BCP应当清楚地识别在发生灾难时被认为对关键业务和支持功能恢复至关重要的信息以及相关的保护措施。重要信息包括存储在电子或非电子介质上(如纸质记录)的信息。
4.6.1 Each BCP should clearly identify information deemed vital for recovery of critical business and support functions in the event of a disaster and the relevant protection measures. Vital information includes that stored on both electronic or non-electronic media (e.g. paper records).
4.6.1 每個持續運作計劃都應清楚識別在發生災難事故時,對關鍵業務及支援部門的復原屬重要的資料,以及相關的保護措施。重要資料包括儲存在電子或非電子媒介(例如書面記錄)的資料。
4.6.2 重要记录的副本在创建后应当尽快异地存储。备份的重要记录必须易于访问,以便紧急检索。应当充分控制对备份重要记录的访问,以确保它们对业务恢复是可靠的。对于某些关键运营,认可机构应当考虑即时备份数据(例如采用实时数据镜像技术)的需要,以确保及时系统和数据恢复。应当有明确的程序,说明在重要记录丢失、损坏或毁坏的情况下,应当如何以及以何种优先顺序检索或重建这些记录。
4.6.2 Copies of vital records should be stored off-site as soon as possible after creation. Back-up vital records must be readily accessible for emergency retrieval. Access to back-up vital records should be adequately controlled to ensure that they are reliable for business resumption purposes. For certain critical operations, AIs should consider the need for instantaneous data back-up (e.g. adopting real-time data mirroring technology) to ensure prompt system and data recovery. There should be clear procedures indicating how and in what priority vital records are to be retrieved or recreated in the event that they are lost, damaged or destroyed.
4.6.2 重要記錄的副本一旦製成後應盡快儲存在運作場地以外的地點。 後備重要記錄必須易於存取,以便在緊急情況下進行檢索。後備重要記錄的存取應有足夠的控制以確保其可靠性,以用作恢復業務。對於部分關鍵運作而言, 認可機構應考慮是否需要即時進行數據備份(例如採用即時數據鏡像技術) , 以確保迅速的系統及數據復原。認可機構應定有清晰程序,列明若遺失重要記錄或重要記錄受損或遭毀壞,應如何檢索或重建該記錄,以及有關的先後次序。
4.7 公共关系和沟通策略
4.7 Public relations and communication strategy 4.7 公共關係及通訊策略
4.7.1 认可机构应当制定与关键外部各方(例如监管机构、投资者、客户、交易对手、业务伙伴、服务提供商、媒体和其他相关方)沟通的正式策略。该策略需要规定在发生灾难时,认可机构应当与哪方进行沟通。这将确保向有关各方传达一致和最新的信息。在灾难期间,持续和清晰的沟通通常可能有助于维护客户和交易对手以及公众的信心。
4.7.1 AIs should formulate a formal strategy for communication with key external parties (e.g. regulators, investors, customers, counterparties, business partners, service providers, the media and other stakeholders). The strategy needs to set out to which parties AIs should communicate in the event of a disaster. This will ensure that consistent and up-to-date messages are conveyed to the relevant parties. During a disaster, ongoing and clear communication is likely to assist in maintaining the confidence of customers and counterparties as well as the public in general.
4.7.1 認可機構應制定與主要的對外各方(例如監管機構、投資者、客戶、對手方、業務夥伴、服務供應商、傳媒及其他持份者)通訊的正式策略。有關策略應列明若發生災難事故,認可機構需要聯絡的各方。此舉確保有關方面能收到一致及最新的信息。在發生災難事故期間,持續及清晰的通訊有助維持客戶及對手方以至公眾人士對機構的信心。
4.7.2 BCP应当明确指出谁可以与媒体对话,并预先安排在灾难期间将外部沟通转给指定的人员。认可机构可能会发现,将准备新闻稿草稿作为其BCP的一部分是有帮助的。这将节省CMT在混乱的情况下决定传送主要信息的时间。与外部各方的重要对话应当妥善记录,以备将来参考。重要外部人士的联络电话和电子邮件地址应当以易于访问的方式保存(例如,保存在钱包卡中或企业内网)。
4.7.2 The BCP should clearly indicate who can speak to the media, and have pre-arrangements for redirecting external communications to designated staff during a disaster. AIs may find it helpful to prepare draft press releases as part of their BCP. This will save the CMTs’ time in determining the main messages to convey in a chaotic situation. Important conversations with external parties should be properly logged for future reference. Important contact numbers and e-mail addresses of key external parties should be kept in a readily accessible manner (e.g. in wallet cards or AIs’ intranet).
4.7.2 持續運作計劃應清楚列明在發生災難事故期間負責向傳媒發言的人員,並預先安排指定人員負責對外通訊。認可機構可以考慮預先擬定新聞稿草稿,作為其持續運作計劃的一部分。此舉可節省危機管理組在混亂情況中決定對外傳遞的主要信息所花的時間。與對外各方的重要對話應妥善記錄,以便日後參考。主要對外各方的重要聯絡電話號碼及電郵地址應妥善保存,並要易於取用(例如記錄在錢包內的聯絡卡上或存放在認可機構的內聯網) 。
4.7.3 在内部沟通方面,BCP应当规定如何在适当的情况下及时、一致地向所有员工、母行、总行、分行和子公司传达恢复状况。这可能需要使用不同的沟通渠道(例如向员工的手机群发信息、认可机构的网站、电子邮件、内联网和即时通讯)。
4.7.3 As regards internal communication, the BCP should set out how the status of recovery can be promptly and consistently communicated to all staff, parent bank, head office, branches and subsidiaries, where appropriate. This may entail the use of various communication channels (e.g. broadcasting of messages to mobile phones of staff, AIs’ websites, e-mails, intranet and instant messaging).
4.7.3 至於內部通訊方面, 持續運作計劃應列明如何可以將復原情況迅速及持續地通知所有員工、總行、總辦事處、分行及附屬公司(如適用)。此舉可能涉及使用各種不同的通訊渠道(例如將信息傳播至員工的流動電話、認可機構的網站、透過電郵、內聯網及即時訊息傳遞) 。
4.8 其它风险缓解措施
4.8 Other risk mitigating measures 4.8 其他減低風險措施
4.8.1 认可机构应当购买适当的保险,以降低他们在灾难期间可能面临的财务风险。认可机构还应当定期审查其保险单的充分性和承保范围,以降低灾害造成的任何可预见风险,例如办公室、关键IT设施和设备的损失以及人员伤亡等。保险单可能还需要解决认可机构未能向客户和交易对手提供服务的法律责任。
4.8.1 AIs should have proper insurance coverage to reduce the financial exposure that they may face during a disaster. AIs should regularly review the adequacy and coverage of their insurance policies in reducing any foreseeable risks caused by disasters, such as loss of offices, critical IT facilities and equipment, and casualty. Insurance policies may also need to address AIs’ legal responsibilities for failing to deliver services to their customers and counterparties.
4.8.1 認可機構應購買承保範圍適當的保險,以減低它們在災難事故期間可能會面對的財務風險。 認可機構應定期檢討其保單以及有關的承保範圍是否足夠,以減低因災難事故引致的任何可預見的風險,例如辦公室、關鍵資訊科技設施及設備的損失及人命傷亡等。保單內容亦可能需要涵蓋認可機構未能向客戶及對手方提供服務所引起的法律責任。
4.8.2 认可机构还应当将可能需要获得额外流动性的情况纳入其BCP。
4.8.2 AIs should also incorporate the possible need to obtain additional liquidity into their BCPs.
4.8.2 認可機構亦應在持續運作計劃內併入可能需要取得額外流動資金的情況。
5. 业务和技术恢复后备场所
5. Alternate sites for business and technology recovery 5. 業務運作及資訊科技系統復原備用場地
5.1 后备场所的选择标准
5.1 Selection criteria for alternate sites 5.1 備用場地的挑選準則
5.1.1 大多数业务连续性工作都依赖于后备场所(即恢复场所)的可用性来成功执行。后备场所可以是通过与商业供应商签订协议获得的外部场所,也可以是认可机构房地产投资组合中的场所。一个可使用、能运转的后备场所是所有BCP中不可或缺的组成部分。
5.1.1 Most business continuity efforts are dependent on the availability of an alternate site (i.e. recovery site) for successful execution. The alternate site may be either an external site available through an agreement with a commercial vendor or a site within the AI’s real estate portfolio. A useable, functional alternate site is an integral component of all BCPs.
5.1.1 大部分持續運作計劃要推行成功,都需要有備用場地(即運作復原場地)。備用場地可以是根據與供應商定立協議而獲得使用權的外部場地,也可以是認可機構的物業組合內的場地。一個合用的備用場地是所有持續運作計劃不可缺少的部分。
5.1.2 认可机构应当检查主要业务功能集中在相同或邻近地点的程度,以及后备场所与主要场所的接近程度。后备场所应当保持足够距离,以避免受到同一灾害的影响(例如,它们应当位于单独或后备的电信网络和电网上)。
5.1.2 AIs should examine the extent to which key business functions are concentrated in the same or adjacent locations and the proximity of the alternate sites to primary sites. Alternate sites should be sufficiently distanced to avoid being affected by the same disaster (e.g. they should be on separate or alternative telecommunication networks and power grids).
5.1.2 認可機構應檢討主要業務部門集中在相同或鄰近地點的程度,以及備用場地與主要場地的距離。備用場地應與主要場地相隔足夠的距離,以免受同一災難事故的影響(例如應使用不同的電訊網絡及電力網)。
5.1.3 认可机构后备场所应在其BCP指明的时间要求内随时可供使用(即每周7天、每天24小时)。 如果BCP有需要,后备场所应当预先安装通风系统、工作站和电源空间。应当根据认可机构的安全策略实施适当的物理访问控制,例如访问控制系统和安全保卫。
5.1.3 AIs’ alternate sites should be readily accessible and available for occupancy (i.e. 24 hours a day, 7 days a week) within the time requirement specified in their BCPs. Should the BCPs so require, the alternate sites should have pre-installed ventilation, workstations, power space. Appropriate physical access controls such as access control systems and security guards should be implemented in accordance with Ais’ security policy.
5.1.3 認可機構的備用場地應易於到達,並於持續運作計劃註明的時限內隨時可供使用(即一星期7日每日24小時)。如果持續運作計劃有所要求,備用場地應預先安裝工作站、電力、電話及通風設備,以及足夠的空間。認可機構應按照其保安政策實施適當的出入場地控制措施,例如出入控制系統及保安員。
5.1.4 除了建立后备场所外,认可机构还应当特别注意将业务转移到后备场所的交通运输。应当考虑到灾害可能对交通系统造成的影响(例如道路或隧道关闭)。有些员工可能在从家中到后备场所的通勤有困难。还应当考虑其他后勤问题,例如如何将内部和外部邮件重新路由到后备场所。此外,应当考虑与电信公司预先作出安排,将自动电话从主要工作地点转移到后备场所。
5.1.4 Other than the establishment of alternate sites, Ais should also pay particular attention to the transportation logistics for relocation of operations to alternate sites. Consideration should be given to the impact a disaster may have on the transportation system (e.g. closures of roads or tunnels). Some staff may have difficulty in commuting from their homes to the alternate sites. Other logistics, such as how to re-route internal and external mail to alternate sites should also be considered. Moreover, pre-arrangement with telecommunication companies for automated telephone call diversion from the primary work locations to the alternate sites should be considered.
5.1.4 除了設立備用場地外,認可機構也應特別留意將業務運作遷至備用場地過程中所需的交通運輸後勤安排,並應考慮災難事故可能會對運輸系統造成的影響(如封閉道路或隧道)。部分員工由住所前往備用場地可能會有困難。其他後勤安排,例如怎樣將內部及對外郵件轉送至備用場地也應在考慮之列。此外,認可機構也應考慮與電訊服務公司預先作出安排,將電話由主要辦公地點自動轉移至備用場地。
5.2 后备技术恢复场所
5.2 Alternate sites for technology recovery 5.2 資訊科技系統運作復原備用場地
5.2.1 技术恢复的后备场所(即备份数据中心)可能与后备业务场所分开,应当配备足够适当型号、大小和容量的技术设备(例如工作站、服务器、打印机等),以满足认可机构BCP中指定的恢复要求。这些场所也应当配备足够的电信设施(包括频宽)并预先安装其BCP中指定的网络连接,以处理预期的话音和数据流量。
5.2.1 Alternate sites for technology recovery (i.e. back-up data centres), which may be separate from the alternate business site, should have sufficient technical equipment (e.g. workstations, servers, printers, etc.) of appropriate model, size and capacity to meet recovery requirements as specified by AIs’ BCPs. The sites should also have adequate telecommunication (including bandwidth) facilities and pre-installed network connections as specified by their BCPs to handle the expected voice and data traffic volume.
5.2.1 資訊科技系統運作復原備用場地(即後備數據中心)可與備用業務運作場地位於不同地點, 並應有足夠的資訊科技設備(如工作站、伺服器、打印機等),有關設備的型號、規模及容量應達到認可機構的持續運作計劃註明的復原要求。資訊科技系統運作復原備用場地也應有足夠的電訊設施(包括網絡頻寬)及預先安裝持續運作計劃指定的網絡連繫,以處理預期的話音及數據流量。
5.2.2 认可机构应当考虑安排从其后备场所到主要客户、交易对手和服务提供商的后备场所的电信连接,因为这些客户、交易对手和服务提供商的主要场所靠近认可机构的主要业务场所,因此可能受到正在处理的同一灾难的影响。应当优先考虑与认可机构关键运营高度依赖的当事方建立电信联系。
5.2.2 AIs should consider arranging telecommunication links from their alternate sites to the alternate sites of major customers, counterparties and service providers whose primary sites are close to AIs’ primary business locations and who may therefore be affected by the same disaster being catered for. Priority should be given to establishing telecommunication links to those parties upon which AIs’ critical operations have a high dependency.
5.2.2 認可機構應考慮由備用場地建立電訊連繫至位於機構主要業務地點附近的主要客戶、對手方及服務供應商的備用場地,因為這些客戶、對手方及服務供應商亦可能會受同一的災難事故影響。認可機構應優先考慮與其關鍵運作所高度倚賴的有關各方建立電訊聯繫。
5.3 供应商或其他机构提供的后备场所
5.3 Alternate sites provided by vendors or other institutions 5.3 供應商或其他機構提供的備用場地
5.3.1 认可机构应当避免过度依赖外部供应商提供BCP支持,特别是当多个机构使用同一供应商的服务时(例如提供备份设施或额外硬件)。认可机构应当确信,这些供应商确实有能力在需要时提供服务,并应明确规定供应商的合同责任。
5.3.1 AIs should avoid placing excessive reliance on external vendors in providing BCP support, particularly where a number of institutions are using the services of the same vendor (e.g. to provide back-up facilities or additional hardware). AIs should satisfy themselves that such vendors do actually have the capacity to provide the services when needed and the contractual responsibilities of the vendors should be clearly specified.
5.3.1 認可機構應避免過度倚賴外部供應商就持續運作計劃提供支援,特別是在幾家機構同時使用同一位供應商服務的情況(例如提供後備設施或額外硬件)。認可機構應清楚確定該等供應商是否有能力在需要時提供有關服務,並應清楚列明供應商的合約責任。
5.3.2 合同条款应当包括供应商在备份设施、技术支持或硬件方面承诺交付的交货时间和能力。在某些情况下,订金协议可能是明智的,以确保供应商在面对其他受影响用户的竞争需求时优先提供服务。供应商应当能够证明其自身的可恢复性,包括在合同场所无法使用的情况下指定另一个恢复场所。
5.3.2 The contractual terms should include the lead-time and capacity that vendors are committed to deliver in terms of back-up facilities, technical support or hardware. In some cases, a retainer agreement may be advisable to ensure priority service from the vendors in the face of competing demands from other affected users. The vendor should be able to demonstrate its own recoverability including the specification of another recovery site in the event that the contracted site becomes unavailable.
5.3.2 合約條款應包括供應商提供後備設施、技術支援或硬件的所需時間及處理量。在若干情況下,認可機構可考慮訂立聘用協議,以確保在其他受影響用戶爭相要求供應商提供服務時,可優先獲得供應商的服務。供應商應能證明其本身的運作復原能力,包括另一個復原場地的規格,以防合約註明的場地無法使用。
5.3.3 某些认可机构可能依赖与另一机构的互惠恢复安排来提供恢复能力。然而,认可机构应当注意到,这种安排往往不适合长时间的扰断和延长的时间。这种安排还可能使认可机构难以充分测试其BCP。因此,任何互惠恢复协议都应当经认可机构进行适当的风险评估和记录,并经董事会正式批准。
5.3.3 Certain AIs may rely on a reciprocal recovery arrangement with another institution to provide recovery capability. AIs should, however, note that such arrangement is often not appropriate for prolonged disruptions and an extended period of time. This arrangement could also make it difficult for AIs to adequately test their BCP. Any reciprocal recovery agreement should therefore be subject to proper risk assessment and documentation by AIs, and formal approval by the Board.
5.3.3 部分認可機構可能會倚賴與另一家機構定立的交互復原安排來提供業務運作復原能力。然而, 認可機構應留意這種安排一般不適宜於應付干擾持續以及要維持一段長時間的情況。同時,這項安排可能會令認可機構難以充分測試其持續運作計劃。因此,認可機構應對任何交互復原協議進行適當的風險評估及記錄,並要經董事局正式批准。
6. 实施业务连续性计划
6. Implementation of Business Continuity Plan 6. 持續業務運作計劃的實施
6.1 测试和排练
6.1 Testing and rehearsal 6.1 測試及演習
6.1.1 如果计划没有经过适当的定期测试,认可机构不应当认为其BCP是完整的。必须进行测试以确保BCP是可操作的。应当针对一系列包括扰断性事件和事故在内的严重但可能发生的情景对BCP进行测试和验证。测试需要验证认可机构人员的意识和准备,以及确定BCP的实际工作情况。
6.1.1 AIs should not consider their BCP as complete if the plans have not been subject to proper periodic testing. Testing is needed to ensure that the BCP is operable. Testing of BCP should be conducted and validated for a range of severe but plausible scenarios that incorporate disruptive events and incidents. Testing entails verifying the awareness and preparedness of AIs’ personnel as well as determining how well the BCP really works.
6.1.1 若持續運作計劃並未經過適當的定期測試, 認可機構不應視該計劃為已完成。測試是為了確保持續運作計劃是可行的。認可機構應以一系列包含具破壞力的事件及事故的嚴峻但可能發生的情景來測試及核實持續運作計劃。測試包括核實認可機構人員的認知及準備程度,以及確定持續運作計劃實際運作時的成效。
6.1.2认可机构应该根据各种因素确定其BCP测试的频率,包括扰断的潜在影响、认可机构有多少关键运营,以及经营环境是否发生了重大变化。高级管理层每次都应当参与测试,并了解在启用BCP时他们个人需要做什么。此外,恢复和后备人员都应当参加计划排练,以熟悉他们的恢复职责。
6.1.2 AIs are expected to determine the frequency of testing of their BCP based on a variety of factors, including the potential impact of a disruption, how many critical operations an AI has, and whether the operating environment has materially changed. Senior management should participate in the testing each time and be aware of what they are personally required to do in the event of their BCP being invoked. In addition, both recovery and alternate personnel should participate in plan rehearsals to familiarise themselves with their recovery responsibilities.
6.1.2 認可機構應根據多項因素來決定持續運作計劃的測試頻率,有關因素包括某干擾的潛在影響、認可機構有多少關鍵運作,以及運作環境是否有發生重大變化。 每次測試高級管理層都應參與,並應清楚知道一旦啟動持續運作計劃,他們本身需要採取的行動。此外,復原及後備人員都應參與演習,以熟習其在復原過程中的責任。
6.1.3 所有与BCP相关的风险和假设必须作为测试计划的一部分进行相关性和适当性审查。测试的范围应当全面,以涵盖BCP的主要组成部分、重要各方之间的协调以及与第三方和集团内部实体的相互依赖关系。根据测试目标和所涉及的各方,BCP测试的类型可能包括桌面结构化走查、BCP特定组件的测试或全面综合测试。特别是:
- 员工疏散和沟通安排(如呼出树)应当得到验证;
- 应当启动业务和技术恢复的后备场所;
- 供应商或交易对手方提供的重要恢复服务应当构成测试范围的一部分;
- 认可机构应当考虑测试其备份IT系统与主要客户、交易对手及服务供应商的主要及备份系统的联系;
- 如果备份设施与其他方(例如机构的附属机构)共享,认可机构需要核实是否可以同时容纳所有各方;和
- 重要记录的恢复应当作为测试的一部分进行认证。 6.1.3 All BCP related risks and assumptions must be reviewed for relevancy and appropriateness as part of the planning of testing. The scope of testing should be comprehensive to cover the major components of the BCP as well as coordination among important parties, and interdependencies with third parties and intragroup entities. Depending on the testing objectives and parties involved, the types of BCP testing may include a desktop structured walkthrough, a testing of particular components of the BCP or a fully integrated testing4. In particular:
staff evacuation and communication arrangements (e.g. call-out trees) should be validated;
the alternate sites for business and technology recovery should be activated;
important recovery services provided by vendors or counterparties should form part of the testing scope;
AIs should consider testing the linkage of their back-up IT systems with the primary and back-up systems of key customers, counterparties and service providers;
if back-up facilities are shared by other parties (e.g. subsidiaries of the institution), the AI needs to verify whether all parties can be accommodated concurrently; and
recovery of vital records should be certified as part of the testing.
6.1.3 在制定測試計劃時,機構必須檢討所有涉及持續運作計劃的風險及假設是否適切。測試的範圍 應全面,以涵蓋持續運作計劃的主要環節,以及主要各方之間的協調,以至與第三方及集團內部實體之間的互倚關係。 視乎測試目的及涉及的各方而定,持續運作計劃測試的類型可包括桌面結構檢查、 針對持續運作計劃特定環節的測試,或全面綜合測試4。特別是:
- 應核實員工撤離及通訊安排(例如聯絡網);
- 應啟動業務及資訊科技系統運作復原備用場地;
- 供應商或對手方提供的重要復原服務應包括在測試範圍內;
- 認可機構應考慮測試後備資訊科技系統與主要客戶、對手方及服務供應商的主要及後備系統的連繫;
- 若與其他方(例如機構的附屬公司)共用後備設施,則認可機構要核實該設施能否同時應付所有相關各方的需要;及
- 測試應驗證重要記錄能否還原。 6.1.4 应当制定正式的测试文件(包括测试计划、测试情景、测试程序和测试结果),以确保测试的全面性和有效性。具体而言,应当在测试完成后准备一份事后审查报告,由认可机构的高级管理层正式签署。如果测试结果表明 BCP存在弱点或差距,则应当更新计划和恢复策略以纠正这种情况。
6.1.4 Formal testing documentation (including testing plan, testing scenarios, testing procedures and testing results) should be produced to ensure thoroughness and effectiveness of testing. Specifically, a post mortem review report should be prepared at the completion of the testing for formal sign-off by AIs’ senior management. If the testing results indicate a weakness or gap in the BCP, the plans and recovery strategies should be updated to remedy the situation.
6.1.4 認可機構應編製正式的測試文件(包括測試計劃、會測試的情況、測試程序及測試結果),以確保測試徹底及有效。尤其認可機構應在測試完成後編製測試後檢討報告,而該報告應由認可機構的高級管理層正式簽署。若測試結果顯示持續運作計劃存在弱點或漏洞,便需更新有關計劃及運作復原策略,以作補救。
6.2 定期维护
6.2 Periodic maintenance 6.2 定期更新
6.2.1 认可机构应当制定正式的变更管理程序,以在适当批准和记录的情况下,就任何相关变更更新其BCP。如果计划已启动,则应在恢复正常运营后进行审查,以确定需要改进的领域。如果需要供应商提供重要的恢复服务,则应当有正式的流程来定期(例如,每年)审查相关服务水平协议的适当性。
6.2.1 AIs should have formal change management procedures to keep their BCPs updated in respect of any relevant changes with proper approval and documentation. In the event that a plan has been activated, a review should be carried out once normal operations are restored to identify areas for improvement. If vendors are needed to provide vital recovery services, there should be formal processes for regular (say, annual) reviews of the appropriateness of the relevant service level agreements.
6.2.1 認可機構應制定正式的變更管理程序,確保持續運作計劃能因應任何相關改變作出更新(須經過適當批准及有文件記錄)。若持續運作計劃被啟動,認可機構應在回復正常運作後隨即進行檢討,以找出需要改進的地方。若需要供應商提供重要復原服務,機構應制定正式程序,以定期(例如每年)檢討有關的服務水平協議是否適當。
6.2.2 各业务和支持职能应当在BCP职能部门的协助下,每年审查其业务影响分析和恢复策略。其目的是确认BCP要求(包括后备场所设备的技术规格)的有效性,或是否需要更新,以适应不断变化的业务和经营环境。
6.2.2 Individual business and support functions, with the assistance of the BCP function, should review their business impact analysis and recovery strategy, on an annual basis. This aims to confirm the validity of, or whether updates are needed to, the BCP requirements (including the technical specifications of equipment of the alternate sites) for the changing business and operating environment.
6.2.2 在持續業務運作規劃部門的協助下,個別業務及支援部門應每年檢討其業務影響分析及復原策略。檢討目的是要確定在不斷轉變的業務及經營環境下,對持續運作計劃的要求(包括備用場地設備的科技規格)仍然有效,或是否需要更新。
6.2.3 当收到变更通知时,应当尽快更新关键员工、交易对手、客户和服务提供商的联系信息。
6.2.3 The contact information for key staff, counterparties, customers and service providers should be updated as soon as possible when notification of changes is received.
6.2.3 主要員工、對手方、客戶及服務供應商的聯絡資料應在收到有關的修改通知後盡快予以更新。
6.2.4 重大的内部变动(例如合并或收购、业务重组或主要人员离职)应当立即反映在计划中,并向高级管理层报告。
6.2.4 Significant internal changes (e.g. merger or acquisitions, business re-organisation or departure of key personnel) should be reflected in the plan immediately and reported to senior management.
6.2.4 重大內部變動(例如合併或收購、業務重組或主要人員離職等)應立即在持續運作計劃中反映,並要向高級管理層匯報。
6.2.5 BCP文件的副本应当储存在与主要场所分开的地点。在紧急情况下应当采取的关键步骤摘要应当提供给高级管理层和其他关键人员,并由他们保存在多个地点(例如办公室、家中、公文包或认可机构的网站)。
6.2.5 Copies of the BCP document should be stored at locations separate from the primary sites. A summary of key steps to take in an emergency should be made available to senior management and other key personnel and kept by them in multiple locations (e.g. office, home, briefcase or AI’s website).
6.2.5 持續運作計劃文件副本應儲存在主要場地以外的地點。在緊急情況下採取的主要步驟概要應提供予高級管理層及其他主要人員,並由他們保存在多個不同地點(例如辦事處、住所、公事包或認可機構的網站)。