Example Coop Continuity of Operations Program
Example Coop Continuity of Operations Program
(COOP)
1
National Institute of Standards and Technology - http://csrc.nist.gov/publications/PubsSPs.html
2
International Organization for Standardization - https://www.iso.org
3
Federal Emergency Management Agency - https://training.fema.gov/EMIWeb/IS/ICSResource/index.htm
4
FEMA NDRF - https://www.fema.gov/national-disaster-recovery-framework
5
FEMA NRF - https://www.fema.gov/media-library-data/1466014682982-9bcf8245ba4c60c120aa915abe74e15d/National_Response_Framework3rd.pdf
6
Cloud Security Alliance - https://cloudsecurityalliance.org/
7
Center for Internet Security - https://www.cisecurity.org/
8
COBIT - http://www.isaca.org/COBIT/Pages/default.aspx
9
EU General Data Protection Regulation - http://ec.europa.eu/justice/data-protection/reform/files/regulation_oj_en.pdf
INTRODUCTION
The Continuity of Operations Plan (COOP) provides authoritative guidance on the prescribed measures used to establish and
maintain Business Continuity and Disaster Recovery (BC/DR) capabilities at [Company Name].
Protecting [Company Name] data and the systems that collect, process and store this information is of critical importance.
Consequently, the security of systems must include controls and safeguards to offset possible threats, as well as controls to ensure
accountability, availability, integrity, confidentiality and safety of the data:
Confidentiality – Confidentiality addresses preserving restrictions on information access and disclosure so that access is
restricted to only authorized users and services.
Integrity – Integrity addresses the concern that sensitive data has not been modified or deleted in an unauthorized and
undetected manner.
Availability – Availability addresses ensuring timely and reliable access to and use of information.
Safety – Safety addresses reducing risk associated with embedded technologies that could fail or be manipulated by
nefarious actors.
PURPOSE
The purpose of the Continuity of Operations Plan (COOP) is to prescribe a comprehensive framework for:
Creating a Business Continuity Management System (BCMS);
Protecting the Confidentiality, Integrity, Availability and Safety (CIAS) of [Company Name]’s systems, applications, services
and data;
Recognizing the highly-networked nature of the current computing environment and provide effective company-wide
management and oversight of those related cybersecurity risks; and
Providing for the development, review and maintenance of security controls required to ensure the continuity of business
processes.
Commensurate with assessed risk, security measures must be implemented to provide cost-effective and sustainable ways to
protect [Company Name] assets against reasonably-foreseeable natural and man-made disasters.
The concept of the Continuity of Operations Plan (COOP) is to establish Business Continuity & Disaster Recovery (BC/DR) processes
that will enable [Company Name] to recover from adverse situations with a minimal negative impact on operations.
Phase 1 – Prepare
Phase 2 – React
Phase 3 – Recover
Phase 4 – Transition
Phase 5 – Review & Improve
This phased approach incorporates several different incident response and BC/DR components to create a centralized and strategic
approach to emergency management that can scale to deal with the size and scope of disasters and recovery efforts.
These phases overlap from incident response at a tactical level (IRPs and DRPs) to intermediate and long-term recovery efforts at a
strategic level (BCPs):
Incident Response Plans (IRPs)
Disaster Recovery Plans (DRPs)
Business Continuity Plans (BCPs)
It is important to keep in mind that most disasters start off with incident response that require IRPs. As events escalate, DRPs are
activated and then transition into BCPs. The COOP covers this spectrum of response, but there are important distinctions:
Disaster Recovery (DR) is data-centric.
Business Continuity (BC) is business-centric.
COOP MISSION
To ensure the appropriate People, Processes and Technology (PPT) exist, are properly prepared, and are able to execute BC/DR
operations in less-than-optimal conditions with little or no advanced notice.
OPERATIONAL LOCATIONS
The following physical locations are within scope for [Company Name]’s COOP:
CRL Description
1 One (1) production site with onsite storage.
2 One (1) production site with offsite storage.
3 One (1) production site with cloud-based processing and storage.
4 Two (2) production sites in close proximity with localized processing and storage.
5 Two (2) production sites in close proximity with cloud-based processing and storage.
6 Three (3) or more geographically-dispersed production sites with localized processing and storage.
7 Three (3) or more geographically-dispersed production sites with cloud-based processing and storage.
MTD Target
Function Description
(s/m/h/d/w/m)
[example] 3 days Email communications Corporate email
x
x
x
x
x
RPO Target
Function Description
(s/m/h/d/w/m)
[example] 8 hours Database X Employee Resource Management (ERM) database
x
x
x
x
x
This phase addresses the preparation aspect of the COOP, since a failure to plan is tantamount to a plan to fail.
Appendix A (Baseline Security Categorization Guidelines) provides guidance on categorizing systems for criticality.
Appendix B (MEF Recovery Prioritization) provides a tiered list of assets, based on recovery prioritization.
These three (3) typical steps are typically involved in accomplishing the BIA:
1) Determining mission/business processes and recovery criticality.
a. Mission/business processes supported by the system are identified and the impact of a system disruption to those
processes is determined along with outage impacts and estimated downtime.
b. The downtime should reflect the maximum time that [Company Name] can tolerate while still maintaining the
mission.
2) Identifying resource requirements.
a. Realistic recovery efforts require a thorough evaluation of the resources required to resume mission/business
processes and related interdependencies as quickly as possible.
b. Examples of resources that should be identified include facilities, personnel, equipment, software, data files,
system components, and vital records.
3) Identifying recovery priorities for system resources.
a. Based upon the results from the previous activities, system resources can be linked more clearly to critical
mission/business processes and functions.
b. Priority levels can be established for sequencing recovery activities and resources.
PEOPLE
Staff listed within the Key Staff Roles must have the appropriate Knowledge, Skills, and Abilities (KSAs) to perform their assigned
duties. To ensure KSA are current, these individuals requires annual capability development that at a minimum includes:
Participating in at least one (1) simulated exercise (e.g., tabletop exercise, failover exercise, etc.); and
Reading the COOP to maintain familiarity with the content and their expected roles.
TRAINING
Members of the BCT are expected to take the Federal Emergency Management Agency (FEMA) Introduction to Incident Command
System (ICS-100) course.12
On an annual basis, [Company Name] will conduct at least one scenario-based exercise, which may be a tabletop discussion or a full
live exercise. It is imperative that members of the following teams perform an annual review of the COOP, prior to the exercise:
Senior Management;
Integrated Security Incident Response Team (ISIRT);
Business Continuity Team (BCT);
Damage Assessment Team (DAT);
Infrastructure Team;
End User Computing (EUC) Team; and
Procurement Team.
PROCESSES
The BCT Leader is responsible for managing the process of maintaining the accuracy of systems, applications and processes that are
needed for the successful execution of the COOP.
Appendix C (Critical Records & Files) a directory and location of critical records and files that are important for the COOP.
TECHNOLOGY
The BCT Leader is responsible for managing the process of maintaining the accuracy of systems, applications and services that are
needed for the successful execution of the COOP.
Appendix B (MEF Recovery Prioritization) provides a tiered list of systems, applications and processes, based on recovery
prioritization.
12
FEMA Emergency Management Institute - https://training.fema.gov/nims/
IT IS PROHIBITED TO DISCLOSE THIS DOCUMENT TO THIRD-PARTIES
Page 24 of 59
WITHOUT AN EXECUTED NON-DISCLOSURE AGREEMENT (NDA)