Business Continuity Management and CSDM! Recorded Jan26th 2023
foreign thank you foreign John I don't know if you're gonna kick this thing up if you want I could do the first couple slides for you just to set the uh the tone for the group you have those Horseshoe in here right yep okay yeah I'll go through those first and then hand it off to you all right sounds good let me know when you're ready all right yeah go ahead we'll go to the next one welcome everybody to our Digital Services Forum today we're going to have Scott hattaway run in the meeting and if today's your first time on the meeting I know a lot of times depending on the topics we'll get new people in or people that may may bring you along that have been attending for a while so if it is your first time can you just go into the the chat and post your name and the company you're from and then a little bit about what you do this way the group members confuse on and maybe have a little chat a lot of what this group brings to some people is establishing those connections so you can have those ongoing conversations with people who are doing similar things to what you're doing oh we'll get to Scott in a minute we go to the next slide I'll tell you a little bit about the group so the Digital Services Forum we've had it going on since 2018. and we started with with two people but our vision has evolved over that time and we first focused exclusively on Digital Services and the model for Digital Services inside of the cmdb but we since we went further and we said what are we actually building these services for and it mostly came down to digital transformation so our vision is really around that digital transformation and helping model build the models out for that so our mission is to enable the members so that they can participate in that those efforts that are in their companies and we want to share as much work as we can that's the idea here is to not let everybody stumble over the same things so if there's a presentation you have there's a little bit of code you have that you can put towards the group that's what we want to do all of that work will be out on our share drive and I'll give you a little more information on that on the next slide the Enterprise architecture team and you'll you'll hear from one of our our teammates today Scott will be speaking but we're the ones that host the content but as much as we can we try to get people that are actually doing this people in the field customers like yourselves and co-present with them so if there are topics that you have that you think will be relevant to this group of people we definitely want to hear from you and we do have a meeting every other week we stay pretty consistent with those meetings except for the holidays get a little bit tricky but we do uh try to keep it bi-weekly so that there's a consistency there and we keep them at hour-long meetings except for special events we might have a workshop or we might do something at knowledge that is outside that hour let me go to the next slide Scott so I got a feeling uh I may have taken out your next slide straight to the agenda all years you can take it from here then all right um so one of the things that we'll do is we'll make sure that you get the links to the share um and to the YouTube channel Etc that John was referring to uh good morning everyone my name is Scott hattaway um a little bit about myself I joined servicenow in 2013 um prior to that I was a remedy person going back to the mid 90s for those that know there was a couple of Acquisitions we moved from Peregrine to servicenow R2 BMC and then I left BMC in 2013 to join servicenow um I have been a senior advisory solution consultant for the bulk of my tenure at servicenow and took on the Enterprise architect role in November of 2022. um my manager Peter Caldwell is on the phone he also runs uh the Enterprise architecture team that I'm a member of um one of he's waving um a couple of things about me I'm not an expert in anything except I who to go to when I need help right so the number one skill set I bring to the table is that um I know who's doing uh what on the platform I am fairly well versed on the platform um and as a result I will sometimes make statements that are um related to my time in the field right some of my customers have been Intel Safeway Boeing Disney Etc and as a result of that I've kind of been in many different areas and into different aspects of the platform um and as a result sometimes I'll make declarative statements um I want to say right off the bat that if I say something that is not 100 in line with documentation from servicenow I will do my best to call out that I'm giving you my opinion um but generally if I'm making a statement it's because I truly believe it not because it necessarily 100 right um so you'll notice on this agenda there's a dash group on each item of this that is my invitation to you if you have a question if you have some input this is a group effort please do not hesitate to um reach out I believe we have a couple of uh surveys that are going to come up and if not there is a couple of places where I'm going to ask questions for the group and I'll ask you to put your answers in chat we're going to go through a quick overview of business continuity management we're going to go through a a refresher of the csdm mainly because the next section is where we talk about how business continuity management and common service data model interact with one another I'm going to give you some technical considerations again these are based in experiences I've had my most recent interaction was with Hawaii Medical Services Association two-year process to deploy their cstm and business continuity management and one of the things you'll find is that it's continuing to ongo and I'm hoping that this today's presentation is a jumping off point because I want to bring that customer on the phone and let you guys all learn from the path that they've been on and then finally some best practices at the end neither of those last two lists are inclusive or exclusive um so there's going to be more and a little bit of that's on purpose so that we can uh start a good conversation so if there's no questions yet let's drive in to business continuity management um I'm going to jump to the bottom right because I want to set the stage right off the bat a lot of people hear business continuity management but they think disaster recovery right and I talk about Disaster Recovery as part of business continuity management just as an emergency break as part of a car you don't run around using your emergency brake every time you want to stop right it is a key aspect recovery is a key aspect of it but overall uh business continuity management it outlines the planning process more than anything else and it's meant to develop prior arrangements and those procedures that everybody is aware of and agrees on that allows you to respond to an event in such a matter that all of your business functions continue within the plan levels um during A disruption and it includes the following things your policies and strategies the business impact assessment the risk assessment ongoing validation and testing resilience management Disaster Recovery communication management and almost as importantly especially if you're a servicing external customer to reputation management I want to leave you with one more point on this business continuity management is about continuing business providing Business Services that's in the normal day-to-day activities again I don't want anybody to leave today thinking that business continuity management is just for when things go bad it's the whole point of it is to keep things from going bad so I'm going to talk about the BCM framework and then we're going to drill into one area of this which is the assessment but here's the pro uh the um framework and you notice it's split down the middle into two areas strategy and mitigation right the strategy is making sure that we keep things running right mitigation is when strategy failed right so it's a two-prong approach so you have the plan planning is ongoing and it includes just about everybody um that it includes the same groups of people that are involved in common service data model right or cmdb so the program maturity assessment and annual roadmap sometimes annual is too long to wait um from personal experience and initially you might be doing these things quarterly you have risk assessment and service prioritization so I actually stole one of uh John's slides from last from two weeks ago and I'm going to use it as an example um of this but at each area of the service data model we're going to look at the business impact we're going to look at the technical dependencies including any third-party dependencies we're going to look at the business processes and mapping those two it applications and capabilities we'll look at the recovery Gap analysis and then from that we'll generate a site risk assessment and then the design making sure that all of these components are brought into our design decisions continuity strategy and recovery options as an example if I'm bringing something into the environment that I cannot build a recovery or a return to normal service plan against maybe I shouldn't bring it in then we're going to implement it and once we've implemented it we're going to exercise and test it routinely and then we're going to go into that sustain and maintain area so when we start talking about program maintenance that's the plan that's making sure that we have done proper enablement and training that's testing all of the things you know for example our communication plan one of the biggest errors or the most common errors I see organizations make is that they create a Communications plan that's dependent on the very technology that they are building mitigation plans against so um sort of tongue-in-cheek but if you consider email went down and I send an email out to everybody letting them know that email is back up right sounds funny sounds like it would never happen it is actually very common that that exact use case um then we're looking uh in that plan exercise and test we're going to pre-test the planning we're going to conduct those tests and then we'll pre-test the evaluation and Reporting so you're doing the making sure that the plan is in place to keep things from breaking making sure that there's a plan in place that is tested that returns to service after an outage and then making sure that you've tested your post incident process right and the reporting because that third step making sure that you've done a post uh incident review um is I won't say it's the most critical but it is extremely critical for your ongoing success then the part everybody's most familiar with that's the recovery strategy and implementation right initially this is going to be very reactive but you'll have resiliency plans uh business continuity Disaster Recovery change management emergency response or crisis management emergency response Etc um this is the part where everybody generally thinks about right but you'll notice it's just one aspect of it so I'm going to touch on what I think is the most important aspect um and that's the assessment domains hey Scott so yes before we go on Jeremy did uh did he hit your question there in the end or was it still unclear I didn't see the question not I mean it's it's it's kind of an interesting I mean I understand what a business continuity plan looks like um but at the end of the day we're we're talking about an ordered system that is highly constrained and so therefore what could a strategy failure really look like I mean in a vuca world that we live in how can we say this you know like strategy fails well did we get too specific in the street or the document got it got it so let me uh draw a brick wall line between strategy and the plan so let's say initially unless you're building this out your strategy might be a very manual process and it might be like having hot backups in place right or fast switch over uh options in place so your strategy would be manual it would be reactive and it would only kick off in the event of a failure right the plan is how you would step through turning it back on transitioning over so while there's overlap between strategy and plan the strategy is highlighting the fact that as we and and I think this and your answer is going to become more clear towards the end of the deck um but specifically automation versus manual processes right so you may have a manual strategy I will tell you initially um I get most nervous when customers say hey we're going to have an automation strategy on day one right we're just kicking off and our goal is to have an automation strategy not necessarily the greatest idea because automation allows you to make errors at a really fast pace right um whereas having a manual strategy where we're going to have a crisis management team we're going to contact everybody they're going to come into the building they're everybody's going to have their own uh piece of the pie that they're responsible for and then you build out the plan based on the strategy that you've chosen to go down okay and we'll we're going to touch on that again it's a great question actually thank you and now I've opened up the chat so I should be able to see these things as they scroll by foreign I'll keep an eye out for you too Scott in case thank you sir thank you thank you all right the business uh BCM assessment domains right um and I chose this one because personal feeling not sure that others would agree with me but I think it's the most important aspect um of the entire process um because this is where you're going to learn everything you'll notice by the way the recovery strategy and Recovery plans separate pieces here in fact I can't build a recovery plan without a recovery strategy but Gartner says BCM supports the recovery of essential business processes and includes the planning the business resumption recovering work area and building Workforce resilience the most important part of that statement is the building Workforce resilience highlighting the fact that we don't want things to go down it doesn't matter how fast you recover if you go down every day you've got a bad plan right um so and according to the Gartner data most organizations do not have a formal framework or they choose to develop their own internally and they'll follow things like ISO nifa and those standards that are in place feeling that that's going to give them the protection they need so this is where I make one of those declarative statements okay the only process that's going to work is one that has been built inside your organization by members of your organization and has been tested within your organization two identical companies they both make fuzzy widgets and they both make fuzzy widgets using the same hardware and the same software will have different business continuity uh plans right and it's because so much more is involved than the technology and the logistics and the buildings and the hardware it has a lot to do with the culture and the experience level of the people that are involved I will make another declarative statement the most successful business continuity management implementation I have seen to date was people who were not I.T specialists in the areas that they were doing it and it forced them to have a much broader imagination of what could potentially go wrong so during the assessment domains these are numbered because they go down in that order the BCM governments this is a formal structure to manage and govern the business continuity program these are your policies your Scopes your objectives all of the decisions who has the rights the steering committee uh budget and investment um I will tell you that the areas here that folks Miss is the public sector government related uh requirements that are put in place the business impact analysis this is where we try to Define and categorize the recovery requirements based on downtime impacts to the business over predefined periods of time so the simple one here is if hawaiianairlines.com goes down for 60 minutes what is the financial impact of that one hour outage that gives you how much money that you should it should go back to the first one where we're giving you a budget that you're going to apply um to this process but that's the simple one right when we're later we're going to start talking about reputation and that becomes almost immeasurable then you have your recovery strategy this is the approaches for work Area recovery or work around procedures there is a linkage to it for Disaster Recovery strategies and for integration and again as we get towards the end of this deck where I'm going to give you some examples of how servicenow does this um this strategy has to be on your maturity model and I've got I'm going to provide that for you here and it's something that you can take away and find out where you live on that uh maturity model then the plans there's this recovery and continuity plans these are the procedures for the workarounds and or to recover critical functions again this is the what order we're going to do it who's going to do it and in what order the strategy is what specifically is going to be done and then the exercises this is where we're going to actually exercise this Management program we're going to validate continuity we're going to break stuff we're going to flip Breakers we're going to deliberately cause situations where we're testing the process by the way I'm not testing that a database was able to fail over really quickly I'm testing that failover I'm testing the communication plan I'm testing the reputation management I'm testing the data loss I'm testing all of those things and I'm testing the team at the end of that how well they gathered that data and then use it to improve the process going forward which takes us to program management so this is the process to monitor manage the program including the metrics the scorecards the training the awareness so that we're continually getting better I'm going to go back one slide this whole conversation that we just had is this step it's half of this step actually right so this is why I'm saying I think we're going to want to have this as a jumping off point um for future things now I'm making an assumption so feel free to put in the chat um if it's an incorrect assumption but I believe that most of us know what csdm is so leave this description up on the page there for a moment and I'm going to step through a couple of things that just highlight the relationship between BCM and csdm but for those that is there anybody on the call that does not have experience with cstm at least been exposed to it foreign I will point out something csdm leverages all servicenow products and the platform and it's all about supporting true service level reporting okay um if we see this you guys have all seen this slide before in fact the next slide is one I stole from Joe or John um but this is the csdm uh 4.0 um you'll notice I've added these little blue circles over here this has been this continuity management it's the call out one point I have every aspect so you've gone down your CSD empath you're very mature you've identified your services you've gone down that um The Innovation pipeline you're building it out right let's say you're 100 perfect in this area you need to know that at each area you need to have the BCM involvement and when I say BCM involvement I mean this entire framework becomes part of every of the four sections of csdm it is also very dependent on your foundational data so the locations is where we're going to talk about here in a minute because that's the one people forget about um but when we come over here this is the Innovation pipeline right um this is where we're going to do plan run and build and taking things from ideation through demand we're going to build out that Innovation portal we're going to have the customers interacting with us we're going to have the internal service portal we're going to have all these things out business continuity plays a part in nearly every aspect of this process in fact as I've dug through it there's only a couple that I see that vcm doesn't necessarily have to play a role ideation being one of them um but other than that you're going to have a BCM aspect of everything that we do um okay I thought that was a new question but there's not so let's talk a little bit I think I've hammered the point home BCM is part of everything that we do from csdm perspective in fact there's a inextricable relationship between the two once you've gone down the BCM path so how's servicenow done it again we're going to focus on one portion of this and this is the crisis management team now up until this point I've been hammering the point and it's not just about having emergency brakes right but I want to talk about this because the crisis management team is not just there when things are broken they're also the team that you're going to identify because they're the ones that are going to make sure that you are considering all of the potential uh impacts to your BCM process so we have the crisis management team and they are supported by a business continuity management which is supported by BCM support um they're responsible for managing the crisis they're responsible for keeping the crisis from happening they're responsible for any events that might impact our people our operations our customers our brand and almost most importantly our reputation so of those five things that I just listed only one of them was post failure everything else was at least initially pre-failure one other thing I want to point out here is you build the green teams these are the core members of this process right these are the ones that you're going to be dealing with on a regular basis but you may need to bring other people in so let's say your BCM strategy was a hot failover and you were going to have an AWS environment that was kept up to speed you're going to involve Cloud operations in that portion of the conversation that doesn't mean that cloud is going to be involved in every aspect of it or that they have to be formal ongoing members of the team but at least for their particular areas of focus they will have that another is you'll notice there are certain things that are not necessary by the way this is not my slide and so I'm going to call something up this is actually a servicenow BCM slide but I'm going to call something out here because the other piece of this is that there is a consideration that these things are not necessarily Mission critical right and I disagree especially around finance and Global Technical Support um Finance is also who pays our paychecks and if on December 16th you didn't get your December 15th payment uh I think your reputation and impact to your people is going to be massive right so a little bit of a disagreement there but understand that the point being made here is that internally servicenow's crisis management team has the core members which is HR legal communication I.T physical security and workplace Services by the way remember this this is going to become critical here in just a moment and then we also have ad hoc members that come in on a fairly detailed scheduled Global Technical Cloud operations product operations Innovation strategy sales marketing and finance any questions about servicenow CMT all right so let's go back to BCM framework okay everything we're going to talk about now from this point forward into this morning's presentation I want you asking yourself do we are ready or how can we create a communication strategy and plan and in reputation management strategy and plan Target had an outage or had a breach that they knew about for six months before they notified the public I personally believe and all of the analysts that reviewed that breach will tell you that the length of time from their knowledge of it to notifying the public was far and above the worst aspect of that breach people were more upset about that than they were that their information had been shared communication reputation are part of everything that we could do so if we look at by the way the impact is going to the people the workspaces technology or vendors um people includes customers by the way business as usual we're at an acceptable operating level with this is where we're we're not going to send folks uh communication saying hey look things are going as they should we're going to know that the communication here is we're going to be notified if things start to trickle down performance starts to take a hit outside of normal standards when they do we're going to do a response this doesn't necessarily have to be that it's already down for it to be an emergency response if my drives start filling up or suddenly I'm you know I'm in a Taylor Swift ticket sales situation I'm going to respond to that hopefully before that there's a uh a major problem and you'll notice level of performance is trickled down to a point where we're saying it's below the acceptable it's not necessarily down this is when you activate your crisis management team you do not wait for it to be down to activate your crisis management team how do I know which aspect of the air the business to respond to and that takes us back to csdm and the relationship between the two ncsdm you have identified your critical Services you know which ones you can't live without right every component of the csdm has a BCM relationship so when I come back over here let's say I got 20 things that are being impacted I know which one's to Target because I've done my homework during the csdn process we're going to recover all critical business functions and sometimes generally that means we're going to recover the critical infrastructure and systems that support those critical business functions and how do we know that technical managed the technical services this is where the infrastructure lives if we've got an issue going on down here we got a the blue Smoke's coming out of a server we know which uh business services are going to be uh impacted we know which business capabilities are going to go down and let's say my hawaiianairlines.com if in a piece of infrastructure is gonna is starting to fail and I know that it's directly related to hawaiianairlines.com I know that I need to respond immediately and what do I do first off it's the business continuity plan activation this means there hasn't been a failure yet but this is the plan that I put in place to keep that failure from happening below that this is disaster recovery this is when the the barn is already on fire right and it's the difference between the fire department and a fire extinguisher I have a small fire put it out with the fire extinguisher if the whole building is on fire I have to call the fire department the fire extinguisher in the hoses are my strategy the person that's been taught to use a fire extinguisher and the firefighters themselves are the uh plan so again we have our disruption or pre-disruption we start the beginning recovery and then we go through the restoring process business as usual is where we want to live we're going to respond to that and hopefully before there's a failure we're going to recover as quickly as possible with the least amount of impact to our reputation and then we're going to restore those operations a part that's missing from this slide is what we do with the end of restore and we'll get into that in a moment but before we do this is my first poll question and this is where are you on your BCM Journey or where are you starting on your BCM Journey um you would be surprised at how many people use Excel and they're on that fingers crossed some of the biggest companies in the world that's where they're at not because of arrogance but because they don't think it's going to happen to them reactive this is the manual operations by the way it is not a inappropriate plan right again initially I was saying that there is benefit to doing this uh from the beginning but you have manual operations they're reactively responding to those BCM activities they have limited identification of responsible parties limited program visibility and disconnected from systems of record not whoop not bad right not a bad place to start this is where we can make mistakes that are slow rate and learn from them and move on basic is repeatable basic operations again we've standardized our functions we've got our gaps identified we know what the program status is we've got multiple connections to system of record this is where we start flying so crawl walk run run really fast and then fly ultimately this is where you want to be we want to automatically respond to these things by the way that does not mean that we do not still do our post incident review and it also doesn't mean that we're not constantly testing it so where's everybody at this BCM Journey for the folks that are on the phone and you can put numbers or just type in the manual reactive basic managed or orchestrated into the chat if we don't have the survey and uh let's have a conversation about this because this is where we're getting to the point where this is supposed to definitely be a give and take so I'm interested in where folks are at anybody you can come up mute as well is is anybody using their csdm to support this as well that'd be interesting here as well yeah all right well maybe everybody I mean can somebody other than John say something so I know that I'm not talking to myself laughs anybody Bueller we're here Scott awesome okay cool got nervous there for a second all right so wherever you're starting um on your journey this is where like I said I want to bring uh my friends from hmsa and on one of these calls because they'll take you through this process um it's not an overnight process um don't be embarrassed if you're here you'll notice that increased as we go up uh efficiency and Effectiveness improve and they improve and uh line with the maturity of your BCM process um a lot of customers after about a year two years maybe you're basically swirling right around here okay um and this is I think the most important difference between basic and manage is the continuous monitoring of the processes you know people people hear me say that they think event management that's part of it right but Hardware Asset Management what is my overall utilization of my servers compute power if I'm consistently running above 90 percent there's a BCM impact to that just like there's a PCM impact if I'm currently uh consistently running it below 20 percent there's no reason to be setting 100 bills on fire just so that we can say there's no chance that we'll go down all right some key considerations this is supposed to be a discussion point so there's some things there that are missing um hopefully to drive the conversation but off the gate establish a cover a culture of resilience notice that didn't say of recovery right resilience means that we're not going to go down and a solid BCM plan can be measured by the fact that it in and of itself reduces outages but number one way that it does that is it keeps us from uh or it expands our imagination by the way I see some answers one with spreadsheets Tina thank you for that and uh Sean is at level two appreciate those responses uh Tina you are not the Lone Ranger even though two of 39 responded believe me there's a lot of focus on this call that are likely at level one as well step two obtain executive sponsorship this is another one of those declarative statements that I make if you do not have executive sponsorship you are wasting your time and here's why you're going to be asking people to do more than they're currently doing you're going to be asking for dollars in order to make that happen and ultimately you're going to be putting rules or guard rails in place that a lot of folks are not going to want to follow also to have an effective BCM or csdm process you're going to be asking people to provide data on areas that they are not interested in providing the data on right you need an executive bulldozer in those situations so obtain executive sponsorship you're going to form if you don't already have one you're going to engage if you do your bus CM or crisis response teams your csdm and your csdm teams and by the way I say teams because you have the business side of csdm and you have the technical infrastructure side of cstm so at least there's going to be three legs on that stool most important at this point is clearly Define the roles lots of stuff available servicenow provides it it'll be part of that follow-up deeper dive section highly recommend that you engage expert help that could be partners it could be BCM practitioners I don't want to make this a sales call but service now offers a BCM solution and practitioners and we have Partners um at this stage we're going to confirm and test our executive sponsorship right it's real easy to get somebody to say yeah I'll sponsor that and then when it gets thick and it gets uncomfortable their sponsorship or their support wanes so you're going to confirm that you're going to create and or review organizational change management plans there are two separate viewpoints to this right one is to support business continuity long term this is the ongoing this is when BCM is done we're going to have an organization change management plan in place but also for the initial build out of those plans and the ongoing maintenance of those plans some people disagree with me when I say your BC implants are configuration items they should not be changed without going through organizational change management and this is one of those Evangelical arguments that I sometimes get in and you know everybody's uh entitled to their own opinion but if those plans can change without oversight they're not plans they're just notes right um identify any in-flight projects that this process could impact so example csdm is an in-flight process and BCM is going to impact that but also deployments of service now if you're going to use servicenow as your system of record for this you're going to that's going to there's going to be BCM impact on that it there's also going to be let's say uh technology refreshes things like that where we're going to be you know uh impacting that over maybe by impact I mean slow down um you need to identify those um some of the examples additional stories additional testing may be required associated with that you're going to plan for resourcing three separate work streams csdm service csdm technical and business continuity management again clearly Define the roles and clearly Define the relationships between all the areas I'm going to ask a tongue-in-cheek question which one is the most important while I'm waiting on those answers we're going to once again reconfirm executive sponsorship right by the way that is an ongoing process uh you're going to continue to engage and test they don't have to be in every meeting but you have to engage and test your executive sponsorship and then finally our ultimate goal the first one was to establish a culture of resilience and it's tied to digitizing this program for the sole purpose of moving from reactive to proactive and this is again going back to stop the outage stop the failure once it happens things are already bad and you need to have a very fast uh process for returning to Services normal but your goal of business continuity management is the continuity part not the disaster recovery part some other things and again I did not include everything on here but these are um I might be graphic but I say these are Written in Blood um meaning much like rules are sometimes Written in Blood these were things that were learned in the field and as a result they are on here it is not an exclusively uh this guy is still there I think we lost them cereal and nature for about 10 20 seconds okay am I back what was the last thing I heard uh you were reading about about 30 seconds I forget what the last thing you were saying is but uh all right let me come back over here because I want to I want to talk about the last end here um the the how does the Bia fit into these considerations meaning the person or the business impact analysis impact assessment process yeah or the assessment analysis assessment yeah yeah so um and this list that really doesn't because it either I can say it doesn't or it applies to every aspect of it because each portion of this has a Bia role if I come back to uh if I don't have to go all the way back this side's here right every aspect of what we're talking about is going to play here in the Assassin prioritize role so when I start coming back to here right your business con or your business crisis response teams your csdm teams or whatever they're all going to have a Bia um activities but primarily it's going to come from the business side of csdn okay all right I want to end on digitizing the program to move from reactive to proactive the first step is to establish a culture of resilience the whole idea there is to make sure that you don't go down because once you go down the damage has been done and then you're just in a you know minimize the damage perspective what we want to do is be proactive and keep those outages from happening um now this might be graphic but uh the next page is not an exclusive list that's only a few things then I I call them I state that they've been written in blood meaning that they were uh they're on this screen because I've personally been involved in situations where these things were not done okay um Communications communicating to large groups and you have to be prepared for that now I'll give you an example of why that's so critical if you're using service now and you're using email you need to understand that those notifications is going to go out in serial right so the last person notified might be the most critical person that needed to be notified but they're going to be notified last because for whatever reason maybe their last name starts with z who knows but um you need to have a plan that allows you to communicate to large groups of people in parallel meaning right now normal communication paths might be inaccessible I gave you the tongue-in-cheek example of you know notifying people via email that email had responded but also the speed and scale of communication if you're BCM plan requires you to notify all of your customers of an outage that could literally be thousands of notifications that are going out and you need to manage things like how they want to be notified maybe I don't want to be notified via email maybe I only want to be notified Via Mobile and I only want to be notified Via Mobile if it's a really big deal alternate work locations believe it or not this is a problem that a lot of folks will Overlook right if the reason for your outage was a flooded Data Center depending on hot backups in that flooded data center not going to help you so you need to look at infrastructure and access we learned this during covid it was a very painful lesson and that was because one of my customers their BCM plan was that they were all going to move to a different building to work if their primary building came uh unavailable and they all showed up and that secondary building on the first outage was just closed so they went hey that's not going to happen we're going to we're going to make sure that we have access to it and on the second outage about 30 days later they showed up and they weren't allowed in the building because none of them are vaccinated it was a failure of imagination it was not a failure of the plan of the strategy they just didn't consider what was possible there alternate data sources I put hard copy and quotes here because people think that that's just insane but you might need to have in some form even if it's electronic format you might need to have a portable copy of data that you're not depending on anything including the internet or network infrastructure um to get in place uh primary you and that's just recognizing that primary sources of uh data may be inaccessible now I got two examples one of them was a customer that created a static version of their business Maps their service Maps some of them were very large um this is where you really start prioritizing what's critical um I'm not saying that you paint the hole inside your building with your service Maps or have them in such a way that you can uh navigate them without infrastructure in place but if it is what it's going to be required to get you up and running it's something to consider um and then finally at the end a BCM solution or extensions to existing Solutions and I'll give you two examples of that there are business continuity Management Solutions that basically are the overlays to csdm cmdb all of your foundational data and it'll put in place the documentation process the strategy process all of your communication plans and the testing methodology for that spend a few dollars you get one or you can extend your existing and this is where some customers have just a few additional fields that are on their business services literally on the csdm classes or seem to be classes so that they're able to have these things in place neither is wrong right one's going to get you towards that automation uh process sooner uh than the other but it's more important to have something um I'll tell you if I had to pick one thing it's at the top it's the communications side of this thing it is the most critical aspect of BCM communicating to the people that are going to fix it and compete and communicating to the people that were depending on it and can no longer access it all right key takeaways the only uh animation in the whole deck establish a culture of resilience to move from crisis response mode to strategy mode the underlying message there is BCM is the continuity aspect not the disaster recovery aspect provide Assurance to customers vendors and employees through regular transparent communication communicate with me that you have a BCM practice in place and maybe even communicate what that plan is because guess what I'm gonna do I'm probably not going to call and tell you how cool your idea is right I might feel that it's cool that's great but if I think there's something wrong and if I think you've missed something I'm gonna tell you about it right so make sure that you're providing Assurance to your customers vendors and employees through regular transparent communication and then Holy Grail digitize your program to move from reactive to proactive and scaled with growth do not make this your initial Target it's more important that you have a plan even if it's in Excel spreadsheets maybe it's just a phone list of people to call um but your goal is to digitize that program to move from reactive to proactive and the ability to scale with growth and with that I thank you for your time and attention and I don't know how much time we have left but if we do I'm happy to have conversations we've got about 10 minutes perfect I'm going through let's see if I can open up the chat yes Angela you are 100 correct um yeah again just having the communication with your uh uh even employees and vendors and customers uh just that process will have huge returns [Music] um I want to steal your share for a minute too so we can open that conversation there you go oh there's a lot of people here [Music] anybody else have anything the the thing that I've been thinking about the whole time too is uh we talked a lot last year about where that person that owns the csdm actually sits and when we come down to all the things the CSM can do we're looking at what actually gets done and this is a list that we surveyed the group we had about I think 95 people on a workshop we built out some csdm models we're like what are you doing this for right so we had I think the technical value I think the the BCM part sits more here on the business value side right um so it'd be interesting to see kind of where that sits and are the people that are actually like if people are a lot of times are working on csdm for this stuff right to do change impact assessment and reduce mean time to recovery do they actually have access like are they I don't want to say selling their data right but basically making sure that they know the BCM team um so I'm wondering if it's the csdm team going to the BCM team or is it the BCM team coming to the csdm team like in the situations you've seen I I haven't run into a lot of BCM use cases in my customers like people asking about it and I know bcm's there I just don't know if it's a matter of if the people aren't connected enough to share that data or you know kind of chicken and egg thing right so interest interestingly enough John the um and again declarative statement bstm is the reason for csdm afraid it's it's the literally the reason it exists and if you go back to your blue slide uh slide 10 each one of these it's all about making sure that this stuff keeps working yeah that's why it's there um but it's but connectivity of the groups right the organization yeah but sometimes customers will think they again this is why I I wanted to hammer the point they hear business continuing management and they just think outage immediately go to outage it's not about outage it's about making sure that the service is continually available um it's a good slides yeah the thing up here like if we go all the way back to one of your base slide right we have like the EA and the app owner owns this and the business so we talk about like consumers of each of the sets of data but we don't talk about the consumers as a whole like who's consuming the whole model and that would be the BCM team right would be so they don't own this little chunk or that little chunk and they don't really they're not consuming the services themselves but they're consuming they're consumers of the model right so it's really interesting to think we always cut a lot of this stuff falls in the No Man's Land that's what we've been struggling with like hey the EAS on this where they're putting their capabilities and apps in the Ops Team owns this and they all want to own their own chunks but the holistic ownership of the csdm models a lot of times that falls on like the service the the you know like Angela like the person that owns the whole servicenow platform because it's kind of in no man's land the EAS are like we don't want to own it and then they're like oh yeah I want to own the apps that I support but there's nobody that you know the overall modeling itself kind of falls into no man's land and if it was owned by somebody the the csdm itself would be a product that that has consumers of it like the BCM team or like the financial team right if we get it down to all these so I still think people haven't arrived there yet where this model to run the business and to to give people access information like the BCM team needs access to see you know who do I need who are all my stakeholders who do I call when it's broke too or who do I call to keep it from breaking yeah you have a lot of this data Folks by the way you have a lot of this already in place um look at your uh change to against Business Service your approval list right you you know who these people are yeah um yeah so your service owners your technology owners your EAS your Bas all of these people that are in place um my favorite person to contact is whoever's managing your stories like that they know everyone right they're a really good uh resource for you to go to is whoever's managing your stories for your software development they're gonna know who to call yeah cool awesome interesting use case yeah good stuff Scott appreciate you sharing I wanted to say thank you this is my first one for this uh program I don't think it'll be my last I hope it's not my last I guess I'll find out later um but I look forward to working with all of you and uh hopefully meeting some of you at knowledge um and if you haven't signed up for knowledge go sign up for knowledge good deal all right I want to go through uh spend a little bit of the last few minutes just on some some content so we don't have anything scheduled right now for our next two meetings and we do want to get um our February schedule out there so if there is anything you're working on anything you're teeing up for the beginning of the year um get it my way and then we'll we'll try to line up some speakers for you uh the the stuff that we want to over today uh so we do have our YouTube playlist and there was if you this topic is of special interest to you uh we did have another session on BCM I want to go back a while I was right here I'm back about eight months ago so this is another session where we had our our um project our product manager in speaking about this and then also so if you want to get another take on it or basically another use case uh for for BCM that would be a good one to watch and uh I'll link that in there just so you guys have it I feel like you guys like to say hello and um and we'll put that in there and then if you guys like I said if for Content does anybody have anything they're looking to get out of this forum any any type of thing you're like itching to have come up we could have Mark on to talk about cstm again we can invite Scott we can have Caitlin on to talk about BPM anybody using BPM any of those things are we can revisit stuff that we've done like a couple years ago some of it and not if there are things and everybody's a little shy on the call but if there are things you can send in my way and we'll get that teed up on the itinerary so there are things uh Integrations with apis okay SPM is another one okay SPM in the alignment with so Gerald what do you mean specifically on apis there's a lot of ways I can read into that one are you talking about the modeling of that part or okay Gerald has mic problems I don't know like a lot of times with apis we get into are they defined as microservices in the models and um how do we support those from a model perspective I don't know if that's what you're looking for that's what my assumption would be if okay good deal some complex use cases a csdm modeling okay we did have um so we did have trials and tribulations of csdm implementers and we went through some pretty complex cstm models do we want to go through more of those is that the type was was that on the right lines because that was the impetus for that those calls was to get people that have actually done some pretty pretty deep models on the call okay it's not the best practices okay all right thanks for all the the feedback in the chat I'll take that out and we'll we'll get some topics around those lines and have those sent out now if you haven't noticed the way that we're doing this is we're sending out once a month we're sending you notifications we're trying to limit the notifications we're sending you for this group so once a month we're going to give you a an email and that's going to tell you that these are the the next two meetings for so you'll get an email saying here's the two February meetings and it's up to you to register for those so we'll get those out to you and um and we'll see on the next few meetings so Scott thanks again for presenting really appreciate it and uh we'll talk to you all in a few weeks all right thanks for having me have a great week guys
https://www.youtube.com/watch?v=bzyhc91_DxE