Free Essay

Jit2 Risk Management Task 1

In:

Submitted By traffic225
Words 1943
Pages 8
a business continuity plan
Total facility lost due to a hurricane.

XYZ Bakery Supply is a global company with a full range of innovative products and application expertise in the bakery, and patisserie sectors. Products and services are available in more than 100 countries around the world, and in many cases actually produced there by our subsidiaries. Clients are artisans, industry, retailers and food service. XZY Bakery Supply aim to be "reliable partners in innovation" wherever we are in the world, and so help our customers deliver nutritious, tasty food for the communities they live in
Business Contingency plan as be simply defined as identification and protection of critical business processes and resources and preparing a process to ensure to survival of the organization during a times of business disruption (Hiles, A., 2007). In any well formulated Business contingency plan (BCP) there will be five integral parts which is layout in Business contingency plan of XYZ Bakery Supply for total facility lost due to a hurricane.
B1: Pre-Incident Preparedness
In a Pre-incident strategies, we will implement procures that help us mitigate the impact of downtime during the total loss of facility.
In this Pre-incident strategy the company will mandate a Business Contingency policy following in case of imminent approach of a powerful hurricane. * CEO, COO and CFO will monitor the hurricane and will make recommendation to close the faculty for safety. * All the department managers will have contact information for everyone in their department. When CEO gives notice to close the facility, COO will contact each of the faculty managers in turn contact the employees under that department. * COO will have a list of all vendors and customers and will contact then that that the facility will be closed. * Computer system containing vendor, customer, inventory and formula information will be back up to the remote site and backup and restore process will tested regularly. * CFO will have list of all bank account information, Vendor information and Payroll information. CFO will responsible for “paying the bills” such as paying vendor and direct deposit of employees.
B2: Ethical use and protection of sensitive data
It is imperative that our company protects our sensitive data which includes our bread formulas, Employee/Payroll , vendor information, customer information and accounting information and to always use them ethically. The objective to use our sensitive data ethically and reasonably, there are three components for the mythology. First, How are we going to protect the data to make sure it is being used appropriately users. Second, what is our backup procedure? Lastly, after a major business disruption, how do you recover our sensitive data?
First, the company uses an Enterprise resource planning (ERP) system to centralize the information and have a permission level based access. ERP system is a business management suite that uses a common database system that share data across the various departments (Hossein.B., 2004). ERP system will allow access to the sensitive data information by departmental needs. Also, the company will have confidentiality and ethic training for all employees and will be asked to sign a confidentiality agreement before starting employment. The user interface (UI) can be anything from think client, think client like Telnet or secure web browser based. The company will go with secure web Brower to access data.
The proactively backup your data is to backbone of protection your company’s data. Your data is only good as your last successful backup. The company will back up their ERP system just like any other system, either to a tape drive or some kind of hard disk system such in a RAID 5 or RAID 6 system using incremental backups. Moreover, the core database will backup daily to ERP system vendor. This will give redundant backup of the core database, remote backup of core database, and if local system becomes unavailable the ERP system vendor can host the database which will give access to our database via secure web browser connection via HTTPS.
After a major business interruption and the data because unavailable for any length of time, the ERP system vendor can host the database and give limited access to the database such as employee payroll, supplier information, Customer information and company accounting information via secure web browser connection until he local system can come back online and the changed information can be appended to the local system.
B3: Ethical use and protection of customer data
The company’s customers are bakery artisans, industry, retailers and food service providers who purchase baking ingredients and supplies from the company. The customer data includes: Company, Address, phone number, Fax number, Email Address, Balance, past order invoices, Current Invoice, and Payment info, just to name a handful and protection of the customer data and being use ethically and properly is a paramount.
First, to protect the customer data and to ensure that data is used ethically and appropriately by the employees all of the employees will be trained in proper use of customer information, and be asked to sign a confidentiality agreement before starting employment. Furthermore, ERP system will allow access to the sensitive data information by departmental needs and limiting access to information they the sales team needs. The customers database in the local ERP system will be backup on the daily using incremental backups, also the database will be backup to the daily to the ERP system vendor for redundant backup and during the local system outage the database can be hosted by the ERP system vendor were the customer data can be access remotely and securely by the sales team.
After a major business interruption and the data because unavailable for any length of time, the ERP system vendor can host the database and give limited access to the database such as employee payroll, supplier information, Customer information and company accounting information via secure web browser connection until he local system can come back online and the changed information can be appended to the local database system.

B4: Communication plan to be used during and following the disruption.
Communication during a crisis like massive hurricane, during and after is imperative to surviving any impending business disruption. The stake holders who will be affected by business disruption are customers, suppliers and the company’s employees.
During impending hurricane, the CEO, COO and the CFO will monitor the storm from TV, Radio and internet. CEO will have many conference calls but will have at least one with both COO and CFO at least 12 hours before landfall of the storm to determine if the facility will need to be closed. After taking recommendation from the COO and CFO into consideration, if the CEO decides to close the facility the following active of communication will take place.
If the decision to closes the facility is made during business hours:
CEO, will send out companywide mass email stating that the “facility will closed the next day and please check ether email and/or check on the company’s website for update of when will the facility will be back open.” Also, CEO will be responsible for contacting the customers that the facility will be closed and their delivery of their goods will need to be rescheduled either by phone, email or both.
COO, will be responsible for contacting each of the different departments by LAN line phone instructing them to contact each of the people in their department that the facility will be closed the next day and please have them check their email or check the company’s website for more information. Also COO will update the company’s website regarding the closing of the facility due to the storm. Lastly, COO will contact the suppliers that the facility will be closed the next day and all shipments to the facility will need to be rescheduled.
CFO, will be responsible to if there is any payments to suppliers, utility or payroll/direct deposit that CFO can ran before closing of the facility the next day.
If the decision to closes the facility is made after business hours:
CEO, will send out companywide mass email stating that the “facility will closed the next day and please check ether email and/or check on the company’s website for update of when will the facility will be back open.” Also, CEO will be responsible for contacting the customers that the facility will be closed and their delivery of their goods will need to be rescheduled either by phone, email or both the next morning.
COO, will be responsible for contacting each of the different departments by cell phone instructing them to contact each of the people in their department at home by home phone or cell phone that the facility will be closed the next day and please have them check their email or check the company’s website for more information. Also COO will update the company’s website regarding the closing of the facility due to the storm. Lastly, COO will contact the suppliers that the facility will be closed the next day and all shipments to the facility will need to be rescheduled either by email, phone or both.
CFO, responsibility will be to VPN to the company’s network were he or she will have access to the company’s ERP system where he/she can process any payments to suppliers, utility or payroll/direct deposit that CFO can be ran before the storm hit.
B5. Restoration of Operations
The goal of this BCP is to restore the business to normal operation as quick as possible. The best case scenario is the hurricane did not do any damage to the facility and the open back up the next day without any interruption. The worst case scenario is the totally loss of facility due to hurricane winds, water damage, and even fire.
In the case of total loss of facility or a long time closure of facility, the following action will take place:
CEO, will email out the company wide email updating the issue regarding the facility and when it will be back in operation. Also, CEO will be contacting the customers that facility as lost and will update the customers when it will be back in operation either by phone, email or both.
COO, will contact each of the different departments by cell phone instructing them to contact each of the people in their department at home by home phone or cell phone that the facility was lost and update then when it might back in operation and please have them check their email or check the company’s website for more information. Also COO will update the company’s website regarding the facility. Lastly, COO will contact the suppliers that the facility was lost and either to ship the supply to be canceled or to be ship to another location.
If the information system containing the company data is to be destroyed or becomes unavailable for a long period of time, the CFO will contact the ERP system vendor to host the company remote backup database form the vendor’s datacenter which will give the XYZ Bakery Supply access to their company core data of suppliers, accounting, and customer data so they may continue to pay their suppliers, run payroll deposits and service their customers best they can until the facility is back in normal operations.
The facility will rebuilt with help of outside building contractors and/ or consultants. In the mean time the company will seek temporary locations were they may start receiving supplies from suppliers and inventory to delivery to their customers.

http://en.wikipedia.org/wiki/Enterprise_resource_planning
Bidgoli, Hossein, (2004). The Internet Encyclopedia, Volume 1, John Wiley & Sons, Inc. p. 707.

Similar Documents

Premium Essay

Risk Management Task 1a

...Running head: JIT2 (RISK MANAGEMENT): TASK 1A 1 JIT2 (Risk Management): Task 1A It has been stated that, "Denial is a common tactic that substitutes deliberate ignorance for thoughtful planning," Charles Tremper (n.d.) who authored various risk management books. We have been hired, as a consultant in our first task is to create and present to management of business contingency plan combined with risk management to our new client. There has been some concern from both the IT department and legal departments about personal identifiable information sensitive information, client records, and other sensitive information regarding the ethical use and protection of this information. Our goal is to have client confidence along with some sense of job satisfaction; therefore, our boss has informed us that we get to choose our very first client. Our selection can be the place we actually work, any local business, or even a Fortune 500 company. One requirement is that our client must operate globally throughout its business. We will exclude any proprietary information, confidential information, or anything that can be considered sensitive. No names of real people involved with the business, any suppliers, or anything else that could be identifiable will be used. Instead we will only use made-up or fictional names for this task. No actual financial data will be used but rather be addressed using vague or generic terms when appropriate. Due to concerns in the global marketplace...

Words: 3310 - Pages: 14

Premium Essay

Risk Management

...JIT2 (Risk Management): Task 1A Our firm has been hired as a consultant, the first task my team and I have been assigned is to create and present to management both a risk management and a business contingency plan for our client. Both the legal and IT departments have expressed their concerns regarding the ethical use and protection of sensitive data, customer records, and other information systems content of both the firm and the client. In an effort to follow the company’s goal of each project building employee confidence and job satisfaction, the team has been allowed to select our first client. The client we choose can be a former or current employer, any local business, any nationally or internationally held publicly traded or privately held company. The one prerequisite is that the client operate globally in at least one aspect of it business. To help ensure anonymity and security any information that could be considered confidential, proprietary, or personal in nature will be excluded. No actual names of people, suppliers, the company, or other identifiable information will be included. In addition every effort will be made to ensure fictional names used will be obscure as possible. Company-specific data, including financial information, will be addressed in the most general and generic means possible when appropriate. Per the client’s request will address the following items: A. Generate a risk register that includes eight valid risks faced by the client. The...

Words: 2097 - Pages: 9

Premium Essay

Risk Mgmt

...Task 1 (C) – JIT2 Risk Management C. Recommendations Create an implementation plan in which you recommend ways of implementing, monitoring and adjusting the BCP. For the task of creating a Business Continuity Plan (BCP), I will follow a logical and systematic formula for implementation, monitoring and reviewing the plan for United Health Group. The goal is to minimize the impact of any disruption by containing it within a predictable and predetermined period of time. To do this, I recommend that this plan be developed and implemented with as many preventative controls, contingency resources, and procedures designed to allow the organization to quicky bounce back from any long-term business interruption. With this document I’ll present a workable DR plan that focuses not only on safeguarding critical data but also on the restoration of all normal business functions. The process for developing a sound Disaster Recovery plan will involve many layers of detail from the obvious to the not so obvious. Since disasters are by their nature unpredictable, this DR plan must be thorough enough to provide a certain amount of relief to know that if one does occur, the affects on the business will not be catastrophic. Disaster Recovery Topics: 1. Secure executive-level leadership commitment Senior leadership buy-in and support is critical to the long-term success of any enterprise level initiative. Disaster Recovery and Business Continuity Plans are no different. Further...

Words: 2044 - Pages: 9

Premium Essay

Jit2 Task

...JIT2 Task (A) Risk Management Register: Risk | Description | Owner | Source | Likelihood of Occurrence* | Severity of Impact* | Controllability* | Macroeconomics Risks | Economic downturn could pose risk to sales development. | Accounting Team/Sales Team | Poor economy, not enough jobs, people not purchasing as much | High | High | Low | Consumer Demand Risks | Not being able to respond to consumer wants/demands quickly enough, leading to short-term revenue loss | Marketing Team | Consumer interests change, other companies offer newer/better product | Medium | Medium | Medium | Industry Consolidation Risks (bargaining power) | Decreased bargaining power, price wars, inflated discounts, limited space within retailers | Sourcing, Pricing, Marketing and General Counsel Legal Teams | Market consolidation and strategic alliances | High | Medium | Medium | Political and Regulatory Risks | Trade policies | Government Relations Team/General Counsel Legal Team | Restrictions on importing and tariffs that disrupt free flow of goods | Medium | Medium | Low | Legal Risks | Patents and third-party trademark infringement- must be careful not to raise concern for risk when creating and marketing new products | General Counsel Legal Team | Many competitors in same business marketing similar products | Low | Medium | High | Product Counterfeiting and Imitation Risks | Other vendors stealing logos and designs and portraying their imitation products as original | Product Branding...

Words: 1606 - Pages: 7

Premium Essay

Risk

...JIT2 Task 1 Part B ManIT, LLC Business Continuity Plan The information below is a Business Continuity Plan for ManIT, LLC to follow in the possible aftermath of a disaster causing major disruptions to the business. Preparation, response, and recovery from a disaster affecting the operations of ManIT, LLC, requires the full efforts of multiple personnel in many different departments. If such of an event does happen, this plan could be followed and monitored by the Continuity Management Team within ManIT, LLC. The Business Continuity Plan gives the responsibilities of the Continuity Management Team, where their goal is to make procedures that will help with the ManIT, LLC business functions. If such an event or disaster that does affect any functional area of the business, the Continuity Management Team would be there to facilitate all of the areas affected by the event or disaster and personnel involved. This team should include other smaller groups that would entail operations and communication, and damage assessment with each role of the groups to be defined whenever a major business disruption occurs. The leader of the Continuity Management Team will be a Coordinator and would be the central point of contact for all execution of plans. B1. Strategic Changes There are many changes that ManIT, LLC should implement to ensure that operations should continue should a disruption occur. In recent year, the Department of Homeland Security recommended...

Words: 2086 - Pages: 9