13.07.2015 Views

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

RFP MED-12-001 | Technical Proposal<strong>Iowa</strong> <strong>Medicaid</strong> <strong>Enterprise</strong> System Service Procurement | MMIS and Core MMIS Operationsprotection for that ePHI during emergency operations. Plans for access and securing ePHI will becontained within the BCP as a supplement to the contingency plans.Having a BCP with contingency plans is an important aspect of operating any business. However, merelycreating the plans and having them on file is not enough. It is critical to keep the plans updated. TeamNoridian's cyclical planning methodology establishes a formal process to maintain the BCP. Business andsystems management are responsible for developing and maintaining the plan for their respectiveoperations based on information in the BIA. Business continuity plans must be reviewed and updated atleast annually, as well as upon major changes such as changes in business processes, business unit orteam member responsibilities. Management is also responsible for conducting BCP training to their staffannually. Team Noridian will submit the updated BCP to the IME for approval on an annual basis. Withinthe BCP, Team Noridian will address the required maintenance of updating disaster recovery plans andprocedures as a subset of business continuity planning.As part of the development of the BCP for this contract, Team Noridian will develop plans for thereplacement of personnel by working with our human resources department. The plans will include:• Replacement in the event of loss of personnel before or after signing this contract• Replacement in the event of inability by personnel to meet performance standards• Allocation of additional resources in the event of Team Noridian's inability to meet performancestandards• Replacement and addition of personnel with specific qualifications• The time frames necessary for replacement• Team Noridian's capability of providing replacements and additions with comparable experience• Methods for ensuring timely productivity from replacements and additions• How established tasks will continue to be performed by staff when disaster strikes - focusing on theuse of our contingency plans.8.3.1.2.7 Disaster Recovery PlanRFP Section 6.3.1.2, Requirements x and yTeam Noridian's Disaster Recovery Plan (DRP) will enable Team Noridian to survive a disaster andreestablish normal business operations. To accomplish this purpose, Team Noridian must be able toassure that critical operations can resume within a reasonable timeframe.If there is a disaster, our first priority is to prevent loss of life and safeguard personnel during anydisruption. Our second priority is to safeguard the assets with which we are entrusted and maintain theintegrity of the systems involved. Team Noridian uses guidance from industry-standard references indeveloping our DRP, as shown in Figure 8-60, coupled with our own experience and our customer'srequirements.National Institute of Standards andTechnology (NIST)• Special Publication (SP) 800-34,Contingency Planning Guide forInformation Technology Systems• SP 800-37, Guide for the SecurityCertification and Accreditation of FederalInformation Systems• SP 800-53, Recommended SecurityControls for Federal Information SystemsHomeland Security PresidentialDirective (HSPD)• HSPD 7, Critical InfrastructureIdentification, Prioritization, andProtection• HSPD 20, National ContinuityPolicy, May 2007• HSPD 21, Public Health andMedical Preparedness, October2007Federal Acts and Directives• The Computer Security Act of 1987• Office of Management and Budget (OMB) Circular A-130,Management of Federal Information Resources, Appendix III,November 2000• Federal Continuity Directive 1, Federal Executive Branch NationalContinuity Program and Requirements, February 2008• Federal Continuity Directive 2, Federal Executive Branch MissionEssential Function and Primary Mission Essential FunctionIdentification and Submission Process, February 2008• Federal Emergency Management Agency (FEMA) NationalResponse Framework, January 2008Figure 8-60. Industry-Standard References for DRP. Team Noridian follows multiple federal directives,acts, and NIST requirements when defining our DRP.8 | 98

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!