
While there is a governance structure in place for business continuity planning, HC and PHAC would be better served by integrating IT continuity planning for MCAs into the business continuity planning governance structure. Sufficient and appropriate procedures were performed and evidence gathered to support the accuracy of the audit conclusion. The audit was conducted in accordance with the Internal Auditing Standards for the Government of Canada and the International Standards for the Professional Practice of Internal Audit.

The objective of the audit was to assess the management control framework in place to enable IT continuity planning at HC and PHAC for MCAs supporting the delivery of critical services to Canadians. IT continuity plans (commonly known as disaster recovery plans) and business continuity plans are vital to the delivery of critical services for HC and PHAC. The delivery of critical services could be seriously compromised or may not be performed if MCAs are not available during a business disruption or a disaster. Information technology (IT) continuity planning is a key part of business continuity planning. All critical services delivered by HC and PHAC depend on one or more MCA being available during a disruption in operations. The audit focused on mission critical systems/applications (MCA) in Health Canada (HC) and the Public Health Agency of Canada (PHAC).


3.1 Identification of mission critical systems/applications.1.3 IT continuity planning alignment with business continuity planning.B - Findings, recommendations and management responses.
