Bulletin Board - Review and Comment
Step 1 of 4: Comment on Document
How to make a comment?
1. Use this
to open a comment box for your chosen Section, Part, Heading or clause.
2. Type your feedback into the comments box and then click "save comment" button located in the lower-right of the comment box.
3. Do not open more than one comment box at the same time.
4. When you have finished making comments proceed to the next stage by clicking on the "Continue to Step 2" button at the very bottom of this page.
Important Information
During the comment process you are connected to a database. The session that connects you to the database may time-out due to inactivity. The following tips will help you to avoid losing your comments or corrupting your entries:
- Do not jump between web pages/applications while logging comments.
- Do not log comments for more than one document at a time. Complete and submit comments from one document before commenting on another.
- Do not leave your submission part way through the comment process. If you are part way through and need to take a break, submit your current set of comments. The system will email you a copy of your comments, so you will be able to identify where you were up to so you can add to them later.
- Do not exit the process until you have completed all three stages.
(1) This Procedure sets out the operational requirements for implementing Victoria University’s (VU’s) business resilience arrangements, including Business Impact Assessments, Business Continuity Plans, activation, escalation, exercising, review and continuous improvement. (2) This Procedure supports the Business Resilience Policy and should be read in conjunction with the Business Resilience Program, Critical Incident Management Procedure, Emergency Management Procedure (pending) and Student Crisis Response Procedure. (3) This Procedure applies to: (4) Business Resilience Policy (5) Business units must complete and maintain Business Impact Assessments (BIAs) for the functions they perform in accordance with the Business Resilience Policy. (6) Business Unit Managers are responsible for ensuring BIA’s are completed, reviewed and maintained for their area of responsibility. (7) BIA’s identify critical functions, activities and services, dependencies, vulnerabilities, impacts that may arise if those functions are disrupted, and recovery priorities and timeframes. (8) Business Impact Assessments are completed within VU’s business reliance tools and processes and must consider, as relevant: (9) Business Impact Assessments must be reviewed: (10) The BIA process will identify vulnerabilities that may affect the continuity or recovery of critical functions. The assessment will assign an overall BIA rating to each business function. Ratings will be used to group functions into priority cohorts, which will then be used by the Critical Incident Management Team (when activated), to direct and prioritise response and recovery activities. (11) The Office of the Chief Risk Officer will consolidate Business Impact Assessment outcomes to produce support the Vice-Chancellor’s Group annual prioritisation of critical functions and recovery activities in accordance with the Business Resilience Program. (12) Business Continuity Plans (BCP) must be developed and maintained following completion of the Business Impact Assessment process. (13) The level of detail required within a BCP will be proportionate to the criticality and risk of the function it supports. Where a function is deemed high priority through the BIA process, the business area will be required to prepare a more detailed and comprehensive BCP, and its testing regime will be more frequent. (14) BCPs consist of two separate components: (15) The relevant member of the Vice-Chancellor's Group is responsible for approving BCPs within their portfolio. (17) A Business Continuity Plan may be activated where a disruption: (18) Activation of a BCP may be authorised by: (19) Following activation, the responsible manager shall: (21) Business units must implement continuity and recovery arrangements in accordance with their approved Business Continuity Plans. (22) Response and recovery activities must be prioritised based on operational criticality, available resources and the nature of the disruption, in accordance with the Business Resilience Policy. (23) Recovery activities must commence as soon as reasonably practicable following stabilisation of the disruption. (24) Business continuity plans must be exercised and reviewed in accordance with the Business Resilience Policy. (25) Business resilience capability shall be supported through: (26) Business units responsible for critical functions must participate in training, exercising and review activities as required by the Office of the Chief Risk Officer. (27) Outcomes of exercises and reviews will be used to improve Business Impact Assessments, Business Continuity Plans and resilience capability. (28) The Office of the Chief Risk Officer will monitor implementation of business resilience arrangements across the University. (29) Business units must participate in monitoring, assurance, review and reporting activities relating to business resilience arrangements when required. (30) Following a significant disruption, activation or exercise, a structured review must be conducted to identify lessons learned and improvement actions. Improvement actions shall be monitored until completed. (31) Business units must maintain records relating to Business Impact Assessments, Business Continuity Plans, activations, exercises, reviews and improvement actions. (32) Records created under this Procedure must be managed in accordance with the University's Records Management Policy, Privacy Policy and Information Security Policy. (33) HESF: Standards 2.3 Wellbeing and Safety; 5.3 Monitoring, Review and Improvement; 6.1 Corporate Governance; 6.2 Corporate Monitoring and Accountability; 7.3 Information Management. (34) Outcome Standards for NVR Registered Training Organisations 2025: Standards 2.6 Wellbeing; 4.1 - 4.2 Leadership and Accountability, 4.3 Risk Management, 4.4 Continuous Improvement. (35) Compliance Standards for NVR Registered Training Organisations and FPP Requirements 2025: Standards 16 Notification of Material Changes; 17 Third Party Arrangements; 20 Compliance with Laws. (36) National Code of Practice for Providers of Education and Training to Overseas Students 2018: Standards 6 Overseas Student Support Services; 5 Younger Overseas Students. (37) Business Impact Assessment (BIA): A structured assessment used to identify critical functions, dependencies, vulnerabilities, impacts and recovery priorities associated with a disruption. (38) Business Continuity: The capability of the University to continue delivery of critical functions during a disruption. (39) Business Continuity Plan: A documented plan that outlines how critical functions will be maintained and recovered during and following a disruptive event. (40) Business Resilience: The capability of the University to anticipate, prepare for, respond to and recover from disruptions while continuing to deliver its critical functions and strategic objectives. (41) Critical Function: A function, activity or service that is essential to the University's ongoing operations or ability to meet its obligations. (42) Crisis or Critical Incident: An event that has the potential to cause significant harm to people, disrupt critical University operations, impact the University's reputation, or require a coordinated response involving senior leadership and multiple functions. (43) Disruptive Event: Any event that adversely impacts or has the potential to adversely impact the University's people, operations, systems, facilities, services or reputation. (44) Emergency: An actual or imminent event that poses a risk to life, health, property, the environment or University operations and requires immediate action. (45) Leadership Cabinet: Direct reports to the Vice-Chancellor’s Group members. (46) Recovery: Activities undertaken to restore operations and services following a disruptive event. Business Resilience Procedure
Section 1 - Summary
Section 2 - Scope
Top of PageSection 3 - Policy/Regulation
Section 4 - Procedures
Part A - Summary of Roles and Responsibilities
Roles
Responsibilities
Council and relevant Sub-Committees (Audit & Risk Committee)
Provides oversight of organisational resilience through governance, risk and assurance processes.
Vice-Chancellor
Accountable for the University's overall business resilience capability and may authorise University-wide activation of business continuity arrangements.
Vice-Chancellor’s Group/ Leadership Cabinet
Office of the Chief Risk Officer
Business Resilience Manager
College/Research Centre/Department Lead or equivalent
Staff
Part B - Business Impact Assessments
Part C - Business Continuity Plans
Part D - Activation and Escalation
Part E - Response and Recovery
Part F - Training, Exercising and Review
Part G - Monitoring and Continuous Improvement
Part H - Records
Section 5 - HESF/ASQA/ESOS Alignment
Section 6 - Definitions