Continuity Essential Records Management
Total Page:16
File Type:pdf, Size:1020Kb
Regulations and Guidance Contact Information For more information, please contact FEMA NCP. 36 CFR 1223 Managing Vital Records For FEMA Region-specific information, contact the Federal Continuity Federal Executive Branch National appropriate Regional Continuity Manager from the Directive (FCD) 1 Continuity Program and Requirements list below. Continuity Guidance Continuity Guidance Circular Circular (CGC) FEMA Region Location FEMA HQ National Capital Region Other Sources of Information Region I CT, MA, ME, NH, RI, VT • The National Archives and Records Administration: Resources-Vital Records and Region II NJ, NY, PR, VI Records Disaster Mitigation and Recovery: Region III DC, DE, MD, PA, VA, WV www.archives.gov/records-mgmt/vital-records/. • Your state archives are a good source of Region IV AL, FL, GA, KY, MS, NC, SC, TN information and assistance. To locate your state archives, visit: www.statearchivists.org/connect/ Region V IL, IN, MI, MN, OH, WI resources-state/. Region VI AR, LA, NM, OK, TX About FEMA’s National Region VII IA, KS, MO, NE Continuity Programs Region VIII CO, MT, ND, SD, UT, WY Serving as the Nation’s center of excellence for continuity planning, guidance, and operations, Region IX AZ, CA, HI, NV, Pacific Territories FEMA National Continuity Programs (NCP) Continuity Essential Region X AK, ID, OR, WA executes its vision to ensure essential functions of government continue at all levels. Our mission is to Records Management Regional offices may be contacted via: safeguard the implementation of Executive Branch [email protected] continuity and assist the continuity planning efforts of federal, state, local, tribal, and territorial Website National Continuity government and non-governmental stakeholders Continuity news, tools, guidance, and other to sustain the continuous performance of essential useful resources can be found on our website at: Programs functions and critical services under all conditions. www.fema.gov/national-continuity-programs. To accomplish this, NCP provides guidance, technical assistance, planning, training, and workshop support to other Department of Homeland July 2018 Security (DHS) and FEMA components, federal departments and agencies, state, local, territorial, and tribal (SLTT) governments, and other members of the whole community, to include private sector owners and operators of critical infrastructure. What is Essential Records Management? What are Essential Records? How Do I Protect my Essential Records? The identification, protection, and ready availability of Information systems and applications, electronic and Through a Risk Assessment and a BIA, organizations information systems and applications, electronic and hardcopy documents, references, and records needed can determine the outcome resulting from an incident, hardcopy documents, references, and records needed to support essential functions during a continuity event. event, or occurrence, as determined by its likelihood to support essential functions during a continuity event. Essential Records include: and the associated consequences for both primary Critical supporting activities include: • Emergency/Continuity Plan; and alternate facilities. Consider the vulnerability of • Appointing an Essential Records Manager. • Standard Operating Procedures (SOP); those records deemed essential and take necessary • Identifying and protecting records necessary for • Staff contact and assignment information, such as steps to protect them, such as: the organization to continue continuity operations names, addresses, and phone numbers; • Using backup servers, regularly backing up including performance of essential functions and • Orders of succession and delegations of authority; essential electronic files, and storing backup reconstitution of normal operations. • Policies, procedures, directives, and systems copies in a secure off-site location. • Conducting a Risk Assessment and a Business manuals; • Pre-positioning hard copy records to ensure an Impact Analysis (BIA) to identify the most • List of credit card holders to purchase supplies; organization is not reliant on electronic equipment vulnerable records and how to protect them. • Maps and building plans; to access records. • Ensuring continuity personnel have appropriate • Personnel and payroll records; • Leverage cloud computing, which disperses risk access at alternate locations to required media • Customer records; to an organization since data is not hosted on (e.g., paper, photographic film, microform, and/ • Social Security and retirement records; local servers. or electronic forms), equipment, and instructions • Contracts and vendor agreements; and • Raising computers above the flood level and for retrieval of essential records including, but • Licenses and long-term permits. moving them away from large windows. not limited to, records stored in cloud-based • Securing equipment that could move or fall applications and accessed via the Internet or a What is an Essential Records Packet? during an earthquake. Virtual Private Network. An electronic or hard copy compilation of • Considering off-site protection plans such as • Developing procedures to routinely update essential key information, instructions, and supporting planned dispersal, E-vaulting, or duplication of records to ensure they always contain the most documentation needed to access essential records in an records. current information. emergency situation. • Moving heavy/ or fragile objects to low shelves; • Purchasing fire-resistant cabinets and vaults. Major Categories of Essential Records The packet should include: • A hard or soft copy of Emergency Relocation Additional Suggestions • Emergency Operating Records: Records essential Group (ERG) members with up-to-date telephone • Develop procedures to ensure staff at continuity to the continued functioning or reconstitution of an numbers; facilities have access to appropriate media for organization during and after an emergency. • An inventory of essential records with their precise accessing essential records as soon as possible • Legal and Financial Rights Records: Records locations; after activation of continuity plans. essential to protect the legal and financial rights of • Necessary access mechanisms; • Maintaining inventories at a number of different the Government and individuals directly affected • Alternate location information; sites with sufficient distance away to avoid by its activities. Examples include: accounts • Access requirements and lists of sources of being subject to the same emergency to support receivable, social security, payroll, retirement, and equipment necessary to access the records (e.g., continuity operations. insurance records. These records were formerly hardware and software, microform/microfilm • Develop instructions on moving essential records defined as ‘‘rights-and-interests’’ records. readers, internet access, dedicated telephone lines); (that have not been prepositioned) from the • Lists of records recovery experts/vendors; and primary operating facility to the alternate site and • A copy of the organization’s continuity plans. include these instructions in the continuity plan..