Document Comments

Bulletin Board - Review and Comment

Step 1 of 4: Comment on Document

How to make a comment?

1. Use this Comment Icon to open a comment box for your chosen Section, Part, Heading or clause.

2. Type your feedback into the comments box and then click "save comment" button located in the lower-right of the comment box.

3. Do not open more than one comment box at the same time.

4. When you have finished making comments proceed to the next stage by clicking on the "Continue to Step 2" button at the very bottom of this page.

 

Important Information

During the comment process you are connected to a database. Like internet banking, the session that connects you to the database may time-out due to inactivity. If you do not have JavaScript running you will recieve a message to advise you of the length of time before the time-out. If you have JavaScript enabled, the time-out is lengthy and should not cause difficulty, however you should note the following tips to avoid losing your comments or corrupting your entries:

  1. DO NOT jump between web pages/applications while logging comments.

  2. DO NOT log comments for more than one document at a time. Complete and submit all comments for one document before commenting on another.

  3. DO NOT leave your submission half way through. If you need to take a break, submit your current set of comments. The system will email you a copy of your comments so you can identify where you were up to and add to them later.

  4. DO NOT exit from the interface until you have completed all three stages of the submission process.

 

Business Continuity Management Policy

Section 1 - Audience

(1) This policy should be read by all staff of the University of Newcastle (University) and staff of the University's controlled entities.

Top of Page

Section 2 - Executive Summary

(2) Business continuity management (BCM) is a core component of the University's organisational resilience capability and risk management program. BCM comprises the development, implementation and maintenance of processes, policies, procedures, plans and strategies that enable the University to sustain delivery of critical services during and following a disruption.

(3) Effective BCM builds organisational resilience and provides assurance to the University Council, Risk Committee and Vice-Chancellor that disruption-related risks are understood and that appropriate continuity arrangements are in place to support the University's teaching, research and operational activities.

Top of Page

Section 3 - Purpose

(4) The University is committed to maintaining effective BCM capability that supports the ongoing delivery of critical services during disruption. 

(5) This Policy establishes a consistent approach to BCM across the University, including responsibility for the identification of critical services, assessment of disruption impacts, and development of continuity arrangements aligned to the University's Incident Management Framework and Crisis Management Plan.

(6) This Policy is supported by and should be read in conjunction with the Risk Management Policy, Business Continuity Management Framework and associated procedures, which provide guidance for the development, implementation and continuous improvement of continuity capability across the University.

Top of Page

Section 4 - Scope

(7) This Policy applies to all areas and locations of the University and its controlled entities and to all activities that support the continuity of critical services in the event of disruption, including dependencies on people, systems, facilities and third parties and services provided by Digital Technology Solutions and external partners.

Top of Page

Section 5 - Principles

(8) Business Continuity Management at the University is underpinned by the following principles:

  1. continuity planning focuses on the University's critical services and the impacts of disruption to those services;
  2. disruption impacts, dependencies, recovery priorities and disruption tolerances are informed through Business Impact Assessments (BIA);
  3. BCM is integrated with the University's Incident Management Framework, Crisis Management Plan and Information and Communications Technology (ICT) Disaster Recovery arrangements to support a coordinated approach to disruption management and recovery;
  4. responsibility for continuity of services resides within Colleges, Divisions and controlled entities, supported by the Risk Services; and
  5. business continuity capability is subject to ongoing review, testing and continuous improvement.
Top of Page

Section 6 - Responsibilities

(9) The Council's responsibilities for risk are set out in the University of Newcastle Act 1989 and in the statement of primary responsibilities adopted by Council. BCM forms an integral component of the University's approach to managing risk to its operations.

(10) The Risk Committee,in accordance with their Charter, are responsible for monitoring the University's system of risk management, and assuring that risk exposures are being managed appropriately. This includes evaluating the effectiveness of risk management processes, such as BCM, and assessing and determining risk appetite.

(11) In accordance with the Governance Rule and the Vice-Chancellor's functions, the Vice-Chancellor is responsible for ensuring that a BCM program is established, maintained and appropriately supported to meet the University's strategic and operational objectives.

(12) The Chief Operating Officer, as Critical Incident Director, is responsible for leading the University's response to critical incidents in accordance with the Crisis Management Plan, including decisions relating to the prioritisation and recovery of critical services.

(13) Members of the Executive Leadership Team provide leadership within their respective portfolios and are each responsible for ensuring that continuity of critical services is considered within their planning and operational activities.

(14) Risk Services is responsible for facilitating the development, implementation and continuous improvement of the Business Continuity Management Framework, including coordination of Business Impact Assessments, development of guidance and tools, and reporting on organisational resilience capability, including reporting requirements of Risk Committee.

(15) The Emergency Planning Committee is responsible for providing oversight of emergency management, crisis management and business continuity capability, including exercising, testing and post incident review (PIR) activities.

(16) Leaders of Colleges, Divisions, business units and controlled entities are responsible for identifying their critical services, participating in Business Impact Assessments, and developing and maintaining Business Continuity Plans, and implementing continuity arrangements in accordance with this Policy and the Business Continuity Management Framework, including dependencies on people, facilities, technology, information and third-party providers.

(17) The Critical Incident Team (CIT) is responsible for coordinating the University's response to a disruptive event in accordance with the Crisis Management Plan. The CIT operate under the Critical Incident Director's delegated authority to ensure decision making, resources allocation, communication with stakeholders and approval of necessary expenditure to manage the incident and support continuity of critical services occurs.

Top of Page

Section 7 - Related Documents

(18) Business Continuity Management Framework

(19) Incident Management Framework

(20) Crisis Management Plan

(21) Risk Management Policy

(22) Risk Management Framework

Top of Page

Section 8 - Review Process

(23) Risk Services is responsible for reviewing this policy at least annually and following significant organisational or operational change.