Business Continuity and Disaster Recovery
CRA-6.5.5
Licensees must establish and maintain a written business continuity and disaster recovery plan reasonably designed to ensure the availability and functionality of theLicensee 's services in the event of an emergency or other disruption to theLicensee 's normal business activities. The business continuity and disaster recovery plan, at minimum, must:(a) Identify documents, data, facilities, infrastructure, personnel, and competencies essential to the continued operations of theLicensee 's business;(b) Identify the supervisory personnel responsible for implementing each aspect of the business continuity and disaster recovery plan; include a plan to communicate with essential Persons in the event of an emergency or other disruption to the operations of theLicensee , including employees, counterparties, regulatory authorities, data and communication providers, disaster recovery specialists, and any other Persons essential to the recovery of documentation and data and the resumption of operations;(c) Include procedures for the maintenance of back-up facilities, systems, and infrastructure as well as alternative staffing and other resources to enable the timely recovery of data and documentation and to resume operations as soon as reasonably possible following a disruption to normal business activities;(d) Include procedures for the back-up or copying, with sufficient frequency, of documents and data essential to the operations of theLicensee and storing of the information off site; and(e) Identify third parties that are necessary to the continued operations of theLicensee 's business.Amended: April 2023
Added: April 2019CRA-6.5.6
Licensees must distribute a copy of the business continuity and disaster recovery plan, and any revisions thereto, to all relevant employees and must maintain copies of the business continuity and disaster recovery plan at one or more accessible off-site locations.Amended: April 2023
Added: April 2019CRA-6.5.7
Licensees must provide relevant training to all employees responsible for implementing the business continuity and disaster recovery plan regarding their roles and responsibilities.Amended: April 2023
Added: April 2019CRA-6.5.8
Licensees must immediately notify the CBB of any emergency or other disruption to its operations that may affect its ability to fulfil regulatory obligations or that may have a significant adverse effect on theLicensee , its counterparties, or the market.Amended: April 2023
Added: April 2019CRA-6.5.9
The business continuity and disaster recovery plan must be tested at least annually by qualified, independent internal personnel or a qualified third party, and revised accordingly.
Amended: April 2023
Added: April 2019