Skip to content
BOL Conferences
Learn More - Click Here!

Thread Options
#1630655 - 11/18/11 10:27 PM Disaster Recovery Training
Lilly1234 Offline
Member
Joined: Dec 2010
Posts: 50
Hello!
Does anyone know what reg or law talks about Disaster Recovery training and what the requirements of this training are? How often, who must complete, content, etc?
Thanks!

Return to Top
Disaster Recovery
#1630700 - 11/20/11 01:01 AM Re: Disaster Recovery Training Lilly1234
Russ Horn Offline
100 Club
Russ Horn
Joined: May 2008
Posts: 139
You might check out the FFIEC IT Examination Handbook, Business Continuity Planning Booklet.

Within the booklet, they have a section called Employee Training that states:
"Financial institutions should provide business continuity training for personnel to ensure that all parties are aware of their primary and back-up responsibilities should a disaster occur. Key employees should be involved in the business continuity development process as well as periodic tests and training exercises. The training program should incorporate enterprise-wide training as well as specific training for individual business units. Employees should be aware of which conditions call for implementing all or parts of the BCP, who is responsible for implementing the BCP for business units and the institution, and what to do if these key employees are not available at the time of a disaster. Cross training should be used to anticipate restoring operations in the absence of key employees. Employee training should be regularly scheduled and updated to address changes to the BCP." - you can find it here.

In addition, Appendix G states "A comprehensive training program should be developed for all employees, conducted at least annually, and kept up-to-date to ensure that everyone understands their current role in the overall recovery process." regarding training - you can find it here.

Hope this helps some.

Thanks,
Russ
_________________________
Russ Horn, CISA, CISSP, CRISC
CoNetrix
rhorn@conetrix.com

Return to Top
#1651298 - 01/16/12 04:32 PM Re: Disaster Recovery Training Lilly1234
DCS Planning Offline
Member
Joined: Jun 2009
Posts: 74
OK
Russ is correct, that's the FFIEC reg for it. However, if you need more best practice information I'd encourage you to develop your own iterative and incremental model (road map, if you will) that moves from awareness to basic participation, then into specific training per response qualifications. Everyone must receive annual basic training but those who are essential employees (and backups) or who have specific response requirements require training and exercise experience specific to the actions that are expected of them.
_________________________
Eryn Tribble
(888) 297 - PLAN
Of course, there are some things you just can't ever see coming so always plan ahead!

Return to Top

Moderator:  Dana Turner