Business Continuity Best Practices
|
|
|
- Lawrence Bradford
- 10 years ago
- Views:
Transcription
1 BusinessContinuityBestPractices MBAOperations&TechnologyConference April2008 Presenter: RajPatel,Partner Plante&MoranPLLC
2 BusinessContinuityBestPractices SessionObjectives KeyLearningConcepts: IntroductiontoDRP/BCP What swrongwithcurrentplans? ProcessforDevelopinganEffectivePlan RegulatoryAuthority&Guidance Howlongcanyourorganizationcopewiththelossofitskeyresources(People, Technology,Facilities,Suppliers&Customers)? Whatwouldbethebusinessimpactifcriticalinformationwasunavailabledueto disasterorsystemfailure? Doyouhaveproceduresinplaceformaintainingyourbusinessoperationsduringan unexpecteddisruption? Todownloadthispresentation,pleasegoto: 2
3 BusinessContinuityBestPractices Terminology DisasterRecoveryPlan Traditional1990sterminology Includedplansfordisastersandemergencies Moreeventfocusedthanprocessfocused OftentheITmanagerorVPOperations Responsibility Typicallytesting,wasdoneonlyatthe EDPHotsite BusinessContinuityPlan TerminologyofficiallyadoptedbyFFIEC Businesscontinuityplanningistheprocesswhereby financialinstitutionsensurethemaintenanceor recoveryofoperations,includingservicestocustomers, whenconfrontedwithadverseeventssuchasnatural disasters,technologicalfailures,humanerror,or terrorism FFIECInformationTechnologyExamination Handbook BusinessContinuityPlanning FFIECDefinition Contingency planning is the process of identifying critical information systemsandbusinessfunctions,and developing plans to enable those systems and functions to be resumedintheeventofadisruption. The process includes testing the recovery plans to ensure they are effective.duringthetestingprocess managementshouldalsoverifythat businessunitplans complement the informationsystemplans. 3
4 BusinessContinuityBestPractices Relevance BusinesscontinuityplanningisrequiredbytheregulatoryagenciesoftheFFIEC andguidelinesforplandevelopmentandmaintenanceareprovided intheffiec InformationTechnologyExaminationHandbook,BusinessContinuity Planning Businesscontinuityplanningisasoundbusinesspracticeinany organization regardlessofregulatoryrequirements Eventsofthepastsixyearshavesignificantlyincreasedtheneedforconcise attentiontoemergencypreparedness: Increaseddependencyondistributedtechnology,vendors,etc. Increasedbusinessdisasters(poweroutage,connectivityissues, InternetBankingsite down,etc.) Increasednumberofnaturaldisasters(Katrina,tornados,floods,etc.) Heightenednationalalertlevels terroristthreat 4
5 BusinessContinuityBestPractices What swrongwithcurrentplans? Outdatedorgatheringdustontheshelves Readslikeapolicyvs.aprocesstorestore Recoveryteamnotawareofplancontentsortrained OnlyaddressesrestoringITsystems Lacksaneffectiveplanto Restoreconnectivitybetweenlocations Managecommunicationstocustomers,localmedia,employees Neverbeentested Writtenlikea planfordummies Alargesingledocument Savedonlyonthenetwork Doesnotaddresssecurityincidents Toomuchfocusoncatastrophicdisastersornaturaldisasters Doesnotaddressavailabilityofcriticalvendors Oneplanfitsalldisruptions 5
6 BusinessContinuityBestPractices MaturityModel FUNDAMENTAL Responsibilitiesforcontinuousserviceareinformal,withlimitedauthority.Managementisbecomingawareoftherisksrelatedto andtheneedforcontinuousservice.thefocusisontheitfunction,ratherthanonthebusinessfunction.usersareimplementing workarounds.theresponsetomajordisruptionsisreactiveandlargelyunprepared.plannedoutagesarescheduledtomeetit needs,ratherthantoaccommodatebusinessrequirements. TRANSITIONAL Responsibilityforcontinuousserviceisassigned.Theapproachestocontinuousservicearefragmented.Reportingonsystem availabilityisincompleteanddoesnottakebusinessimpactintoaccount.therearenodocumenteduserorcontinuityplans, althoughthereiscommitmenttocontinuousserviceavailability, anditsmajorprinciplesareknown.areasonablyreliableinventoryof criticalsystemsandcomponentsexists.standardizationofcontinuousservicepracticesandmonitoringoftheprocessisemerging, butsuccessreliesonindividuals. ENHANCED INTEGRATED Accountabilityisunambiguousandresponsibilitiesforcontinuousserviceplanningandtestingareclearlydefinedandassigned. Plans aredocumentedandbasedonsystemcriticalityandbusinessimpact.thereisperiodicreportingofcontinuousservicetesting. Individualstaketheinitiativeforfollowingstandardsandreceivingtraining.Managementcommunicatesconsistentlytheneedfor continuousservice.highavailabilitycomponentsandsystemredundancyarebeingappliedpiecemeal.aninventoryofcritical systemsandcomponentsisrigorouslymaintained. Responsibilitiesandstandardsforcontinuousserviceareenforced.Responsibilityformaintainingthecontinuousserviceplanis assigned.maintenanceactivitiestakeintoaccountthechangingbusinessenvironment,theresultsofcontinuousservicetestingand bestinternalpractices.structureddataaboutcontinuousserviceisbeinggathered,analyzed,reportedandactedupon.trainingis providedforcontinuousserviceprocesses.systemredundancypractices,includinguseofhighavailabilitycomponents,arebeing consistentlydeployed.redundancypracticesandcontinuousserviceplanninginfluenceeachother.discontinuityincidentsare classifiedandtheincreasingescalationpathforeachiswellknowntoallinvolved. OPTIMIZED Integratedcontinuousserviceprocessesareproactive,selfadjusting,automatedandselfanalyticalandtakeintoaccount benchmarkingandbestexternalpractices.continuousserviceplansandbusinesscontinuityplansareintegrated,alignedand routinelymaintained.buyinforcontinuousserviceneedsissecuredfromvendorsandmajorsuppliers.bankwidetestingoccursand testresultsarefedbackaspartofthemaintenanceprocess.continuousservicecosteffectivenessisoptimizedthroughinnovation andintegration.gatheringandanalysisofdataisusedtoidentifyopportunitiesforimprovement.redundancypracticesand continuousserviceplanningarefullyaligned.managementdoesnotallowsinglepointsoffailureandprovidessupportfortheir remedies.escalationpracticesareunderstoodandthoroughlyenforced. 6
7 BusinessContinuityBestPractices TheBasics 7
8 BusinessContinuityBestPractices TheProcess 8
9 BusinessContinuityBestPractices 1.Mission,Objectives,Scope&Assumptions Mission&Objective Examples Themostimportantobjectiveofbusinesscontinuityplanningistoprotectthe Bank ifallorpartsofits operationsorcomputerservicesaredisruptedbyadisaster.the planningprocessshouldreducetoa minimum,thedisruptionofoperationsandensuresomeleveloforganizationalstabilityduringanorderly recoveryafteradisaster. Otherpossibleobjectivesare:Managesuccessfullythroughadisaster,meetregulatoryandcontractual requirements,ensurecontinuationofbranchoperations. Assumptions Examples Theplanisdesignedtorecoverfromthe"worstcase"destructionofthe Bank operatingenvironment.the worstcaseincludesanynondataprocessingfunctionthatmaybeincloseproximitytothedatacenteror workstations. Thisplanisnotdesignedforthe worstcase destruction,butfocusesonthelossofrecoveryofkey componentssuchaslocalapplication,network,etc. Fiserve isresponsiblefortheavailabilityofcoreapplications(suchasiti)andthusnotaddressedinthisplan. Theplanisbaseuponasufficientnumberofstaffnotbeingincapacitatedtoimplementandaffectrecovery. Therefore,thelevelofdetailoftheplaniswrittentoastaff experiencedinthe Bank s computerservices. Development,testingandimplementationofnewtechnologiesandapplicationsaresuspendedsothatall resourcesareavailabletorecoverexistingcriticalproductionprocessing. Analternatesite(backupcomputerfacility)inwhichtoestablishrecoveryofcomputerprocessingmaybe necessary.timeframerequirementstorecovercomputerprocessingaresignificantlylessthanestimated timestorepair/reconstructadatacenteronanemergencybasis. Thecomputerfacilitiesofthealternativesiteisnotwithinthescopeofthisplanandisassumednottobe impactedbyanydisasterwhichmayinterruptcomputeroperations at Bank offices. 9
10 BusinessContinuityBestPractices 2.PlanCoordinator&DevelopmentTeam CharacteristicsofBCPCoordinator: Shouldhaveauthority Shouldhaveavailabletime/resources Shouldbeabletocommunicatewithtechnicalstaffandnontechnicalstaff Shouldbeorganized,detailorientedandacompetentwriter Fluentinprojectmanagementprinciplesandtechniques Willneedhighlydevelopedqualitiesofpatience,perseveranceanddiplomacy Coordinatorsneedtocultivateenthusiasmandconstantlyreinforcethebuyinofplanparticipants ThemakeupofyourteamwillvarydependingonthesizeofyouITorganization,business unitandthenumberofdepartmentsinvolved Determineactiveteammembersandadvisoryteammembers fromfunctionalareas suchas: Security(data&physical) SeniorManagement BranchOperations CustomerService HumanResources RiskManagement IT Lending Trust Facilities etc. 10
11 BusinessContinuityBestPractices 3.ProjectPlan FormalprojectplantodevelopyourBCPplan Treatitlikeyouwouldanyotherprojectwithformalplan,team,responsibilities,timelines,budget,etc. Don tletitbeapassiveproject Assignastrongprojectmanager Developkeytimelinesandmilestones Involveateamthatrepresentsyourorganization Sponsorshipattheexecutiveleveliscritical Allocateappropriateresources Don tletsoftwaredrivetheproject Hireoutsidehelp(projectmanagers,consultants,etc.) Facilitatetheprocess¬writetheplanforyou Strongtools&methodologies Experiencewithfinancialinstitutions Bewaryofconsultantsthatpushtowardsaproductorrecoverysite(dowhat srightforyou) Bringstrongprojectmanagementskills(willkeeptheprojecton course) 11
12 BusinessContinuityBestPractices 3.ProjectPlan(cont.) PriortodevelopingPlan ReviewexistingDRPplan Reviewinternalplansandpolicies: Evacuationplans Fireprotectionplan Safety&healthprogram Securityprocedures Insuranceprogram Riskmanagementplans Meetwithoutsidegroups Askaboutpotentialemergenciesandavailableresourcesforresponding tothem.forexample,onefacilitydiscoveredthatadam50milesawayposedathreat.familiarizethe localemergencyagencieswithyourfacilityandanyspecificneeds Localemergencymanagementoffice Firedepartment Policedepartment Emergencymedicalservices Utilitycompanies communicationlines,water,electric,etc. OtherlocalorganizationsthatcouldpresentpotentialthreatstoBank Identifyyourinternalresources&capabilities: Personnel facilitiesmanager,electrician,networkadministrator,etc. Equipment fireprotection,communications,emergencypower,etc. Facilities emergencyoperatingcenter,etc. Backupprocesses arrangementswithotherfacilitiesororganizationstoprovideforcriticaloperationssuchaspayroll, communications,etc. Reviewinsurancepolicyforadequatecoverageforinfrastructure andrecoverycosts Conductdatacenter/facilityassessment 12
13 BusinessContinuityBestPractices 13 4.ThreatAssessment Riskevaluationinvolvesdeterminingtheeventsthatcanadverselyaffectthe Bank soperations,thedamagesucheventscancauseandthemeasuresneeded topreventorminimizetheeffectsofpotentialloss Riskevaluationwouldinclude: Threatidentification Determineprobability/occurrence Determineseverity/impact Identifypreventivemeasuresinplace Identifypreventivemeasuresimprovementopportunities CommonNaturalDisasters Earthquakes Hurricanes Floods/MudSlides Tornados Lightning ExtremeWeather CommonBusinessDisasters Communications/NetworkFailure HardwareFailure PowerFailure SoftwareFailureorCorruption VirusorHackAttack ChemicalSpills Fire HumanErrors ArmedRobbery Terrorism
14 BusinessContinuityBestPractices 4.ThreatAssessment(cont.) Thefollowingchartpresentsthetypesofeventswhichhaveforcedcompaniestodeclarea disaster: 14
15 BusinessContinuityBestPractices 5.ImpactAnalysis Recoveryproceduresarestagedaroundthemostcriticalresource (withthe shortestmad)totheapplicationwiththelongestmad Department Name: Operations Interviewee: John Doe Date: 7/26/2007 MN MD CT Minimal Impact Moderate Impact Critical Impact Application Name # of users Usability Daily/ Weekly/ Monthly/ Qtrly/ Annually < 8 Hours Essential 8-24 Hours Hours 2-3 Days 4-7 Days ChexSystems ~900 Daily MD MD MD MD MD MD MD CT Suspended 60 days pull credit report or alter process for validation Deluxe Checks ~900 Daily MN MN MN MN MN MN MN MN MN Suspended n/a mail check orders Digital Insight ~3500 Daily MN MD CT Essential 48hrs Use phone banking or come to branch MCIF 1 Daily MN MN MN MN MN MN MN MN MN Suspended N/A use other report writers Bill Payment 3,000 Daily MN MN MN MD CT Delayed 4 days customers can pay their bills other ways Core Banking System ~200 Daily MD CT Essential 12hrs???? Trust Metavante Watchdog OFAC WirePro Delayed 8-15 Days Days Suspended Days > 60 Days Recovery Strategy (Essential, Delayed, Suspended) Maximum Allowable Downtime What would you do if the system was not available? 15
16 BusinessContinuityBestPractices 6.StrategyAnalysis CURRENT STRATEGY Buy-and-Build Cold Site Warm Site Hot Site Hot-Mirrored Site Recovery Strategy Identify an alternate site, buy or lease equipment, re-build servers Designate a fully operational data center as alternate site in advance of disaster. Recovery similar to Buy-and-Build at designated site Establish alternate site with stand-by hardware and operating systems. Load applications and restore data from tape after a disaster Establish alternate site with stand-by hardware, operating system, and applications. Load data on a daily basis from tape Operate two remote data centers both for production processing. Traffic is dynamically routed between sites Recovery Time 5 days or more More than two days, exact time depends upon hardware availability 24 to 36 hours 3 to 12 hours Instantaneous Technical Architecture None Data center with environmental controls and telecommunications Load applications and restore data from tape during a disaster Restore data from tape on a daily basis before a disaster Mirroring Load Balancing Key Benefits Inexpensive Accommodates webbased systems Inexpensive Can use as alternate site for development and lab Good compromise between recovery time and cost Reliable recovery method Rapid recovery of critical applications Instantaneous recovery Risk of data loss limited to last few uncommitted transactions Operational efficiencies Key Weaknesses Potentially unreliable Can not accommodate web-based systems May take up to a week to recover Potentially unreliable May take up to a week to recover Loss of data since most recent back-up If servers are used for development recovery may be hindered by configuration changes Loss of data since most recent back-up Can t use alternate site for test or lab purposes Expensive Loss of data since most recent back-up Expensive Potentially complex to operate 16
17 BusinessContinuityBestPractices 6.StrategyAnalysis Selectingyouroffsitevendor: Reputation Howlonghasthefacilitybeeninexistence?Haveyoucheckedthier financialstatements? SiteSecurity Securityatstoragefacilityshouldbenolessstringentthanyourownfacility.Somequestionsto consider: Whataretheaccesscontrolsinthefacility? Isvisitoraccessrestricted? Areclientnamesconcealed,evenfromoneanother? Securitymeasuresduringtransportationofmedia?(unmarkedcars,securityinvehicles,employeemonitoring,etc.?) Howareemployeesscreened? Arecamerasorotherdevicesusedtomonitorfacilitytraffic? Howareemergencycallshandled? MediaManagement Averyimportantfactor,howthefacilitymanagesclientrecords,maypresentthefollowing questions: Howismediaofseveralclientssegregated? Ismediatransportedinplasticcontainersorcardboardboxes? Whatkindofinventorymanagementsystemisused? Areemployeestrainedinpropermediahandling? Whatcontrolsexisttomonitorflowofmediainandoutofthefacility? EnvironmentalFactors detection,preventionandsuppressioncontrolsforsmoke,fire, water,humidity,etc. Whatcapabilitiesareinstalledtodetectsmoke,heat,flame,water,andintrusion? Whatsuppressionsystemsexist? Isthealarmsystemtieddirectlytofire,police,andsecurityservices? Howaretemperature,heat,humidityandcontaminationcontrolled? Howoftenareenvironmentalcontrolstested? Transportation Tapesandrecordsareathigherriskoflossordamagewhileridinginthebackofavan Ismediatransportedbyvendoremployeesorindependentcontractors? Ismediasubjectedtoambientclimateconditions? Arevehiclesequiped withantitheftdevices? 17
18 BusinessContinuityBestPractices 7.DocumentPlan Finallytimetodocumentplan: ItisimperativetocommittheBusinessContinuityPlantowriting,otherwise: Planningwillbeforgottenwhenanincidentoccurs Therewillbenoconsistencytoactionsandresponsestaken Therewillnotbeabaselinetoupdateandimproveovertimeand aschangesoccur Manysitesaredependentuponothersitesforproductionandnetworkfunction thereneedstobeacommon understandingofwhatwillbedoneatthevariousbanksitestopreservebusinesscontinuity Regulatorycompliance PlanStructure Logicallysegregatedsections o Administrativesections:Team,roster,responsibilities,whento declareadisaster,incidentresponsepolicy,etc. o Policies:Incidentresponsepolicy,planmaintenancepolicy,plantestingpolicy,etc. o AssetInventory:Applicationlisting,vendorinformation,networkdiagrams,etc. o Analysis:ThreatAssessment,BusinessImpactAnalysis,etc. o RecoverySteps:Systemsrecovery/restoration,etc. o ContinuityofOperations:Branchoperations,lending,etc. o Attachments:Damageassessment,samplepressrelease,phoneredirectphonegreeting,etc. Planscanbesegregatedby: Durationofdisruption:24hrs,72hrs,5days Typeofdisruption:Systems,neighborhood,branchlevel,etc. Typeofdisaster:Fire,communicationbreak,etc. 18
19 BusinessContinuityBestPractices 8.Implementation/Maintenance Security Becauseofthesensitivenatureoftheinformationyourplanwillcontain,it ssuggestedthatonlythosepersonswhohave beendesignatedasmembersoftherecoveryteamshouldbegivencopiesofyourplan Planstorage Singledocumentvs.fragmented Physicalcopyvs.electroniccopy OnCDsvs.Internet Copiesoftheplanshouldbeeasilyaccessible Severalcopiesoftheplanshouldbestoredoffsiteinasecurelocation Ifplanisdistributedonline,makesurethathostingisseparatefromtheproductionenvironment Keyemployeesmayneedaccesstotheplanduringnonworkinghours Eachplanshouldbekeptcurrent,datedandversioncontrolled Ifsoftwareprogramhasbeenusedtoassistwithplandevelopment,copiesoftheplanningdisksandprogramshouldbe storedoffsite Maintainingtheplanisasimportantaswritingtheplanitself Mostrecoveryplansarenotmaintained.Withinayearorless,theplanbecomesoutdated,asstaffhavechanged,the infrastructurehaschanged,thevendorshavechanged,etc. Presentpartsoftheplantothosewhoassistedincreatingtheplaninitiallyforupdates Instituteamaintenanceplanthatincludesautomaticreminderswhereeachsectionisdesignatedwiththefrequency (quarterly,annually,etc.) Theboardisrequiredtoreviewandapprovetheplanannually 19
20 BusinessContinuityBestPractices 9.TestingthePlan Checklisttesting(alsoknownaswalkthru) Determineswhethertheplanisadequate,i.e.,therecoveryteam reviewstheplanandidentifieskeyelementsthatshouldbe uptodateandavailable,thetelephonenumberlistingsarecurrent,copiesofplanarestoredatalltherightlocations,the inventoryofsystemsisaccurate,theriskassessmentiscurrent,etc. Advantages:Itischeap,involvesminimalinterruptiontobusiness,canusuallybearrangedwithshortnotice,itisagentleway toexploreandtesttheplan Disadvantage:Ithaslimitedtrainingvalue,thetestlacksrealism Nonbusinessinterruptiontest(alsoknownasroleplay) Adisasterissimulatedsothatnormaloperationsarenotinterrupted.Thefollowingareasareadequatelytested:hardware, software,telecommunications,supplies,etc. Advantages:Goodtrainingvalue,challengestheparticipantsand plan Disadvantages:Theroleplaycanmovetowardsextreme ParallelTesting Underthisscenariothesystems(withprecedingday sbackupdata)arerestoredatalternatesiteandcurrentdays transactionsprocessed Allreportsnormallyproducedatthealternatelocationforthecurrentdayshouldagreewiththosereportsatyournormal businesslocation Advantages:excellenttrainingvalue,teststherecoveryofkeysystems Disadvantages:Itwillbecostly BusinessInterruptionTesting(pulltheplug) Thisteststhetotalbusinesscontinuityplan Thistestiscostlyandcoulddisruptyournormalbusinessoperations,soproceedwithcaution Adequatetimemustbeallocatedforthistest Youmaywanttotestonlycertainportionsoftheplaninitially toidentifytheworkabilityofeachpartpriortoattemptingthe fulltest 20
21 BusinessContinuityBestPractices RegulatoryAuthority&Guidance FFIECBusinessContinuityPlanning(BCP)Booklet FDICFinancialInstitutionLetter FIL (newguidanceonbcp&supervisionoftechnologyserviceproviders) FDICFinancialInstitutionLetter FIL (BoardofDirectors&SeniorManagementresponsibilityoverBC) OCCBulletin (BCPBooklet) OCCBulletin200314(LargeNationalBanks) (stepstoprotectu.s.financialsystems) FDICFinancialInstitutionLetterFIL (InfluenzaPandemicPreparedness) 21
22 BusinessContinuityBestPractices RegulatoryAuthority&Guidance GLBA501(b) SecurityGuidelines Asstatedinsection501,thesesafeguardsareto: (1) Insurethesecurityandconfidentialityofcustomerrecordsandinformation; (2) Protectagainstanyanticipatedthreatsorhazardstothesecurityorintegrityof suchrecords;and (3) Protectagainstunauthorizedaccessto,oruseof,suchrecordsorinformationthat wouldresultinsubstantialharmorinconveniencetoanycustomer TheseGuidelinesaddressstandardsfordevelopingandimplementingadministrative, technical,andphysicalsafeguardstoprotectthesecurity,confidentiality,andintegrity ofcustomerinformation Therefore: SecurityStandardsdonotspecificallystatethattheBank sinformation SecurityProgramneedaddressthreatstoinformationavailability However, management sriskassessment(s)shouldconsiderthreatstosecurity, IntegrityandAvailability 22
23 BusinessContinuityBestPractices BeInformed 23
24 BusinessContinuityBestPractices BeInformed Hazards Assessment is intended to provide emergency managers, planners,forecastersandthepublic advancenoticeofpotentialhazards related to climate, weather and hydrological events. It integrates existing National Weather Service official medium (35 day), extended (610 day) and longrange (monthly and seasonal) forecasts and outlooks, and hydrological analyses and forecasts, which use stateof theart science and technology in theirformulation. 24
25 BusinessContinuityBestPractices ThankYou Todownloadthispresentation,pleasegoto: Presenter: RajPatel,Partner Plante&MoranPLLC
Business Continuity Best Practices
Presenters: Jesse Galindo Technology Security Consultant t [email protected] 312 602 3537 Cathy Judge Consultant [email protected] 248 223 3595 Session Objectives Key Learning Concepts:
Disaster Recovery Planning Procedures and Guidelines
Disaster Recovery Planning Procedures and Guidelines A Mandatory Reference for ADS Chapter 545 New Reference: 06/01/2006 Responsible Office: M/DCIO File Name: 545mal_060106_cd44 Information System Security
IT Service Management
IT Service Management Service Continuity Methods (Disaster Recovery Planning) White Paper Prepared by: Rick Leopoldi May 25, 2002 Copyright 2001. All rights reserved. Duplication of this document or extraction
Disaster Recovery Remote off-site Storage for single server environment
. White Paper Disaster Recovery Remote off-site Storage for single server environment When it comes to protecting your data there is no second chance January 1, 200 Prepared by: Bill Schmidley CompassPoint
Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP)
Preface Computer systems are the core tool of today s business and are vital to every business from the smallest to giant organizations. Money transactions, customer service are just simple examples. Despite
Disaster Recovery (DR) Planning with the Cloud Desktop
with the Cloud Desktop [email protected] (866) 796-0310 www.os33.com In preparing for the unexpected, most companies put specific disaster recovery plans in place. Without planning, recovering from a disaster
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP). Ed Fortin President Fortin Consulting Paul Godden Consultant & Quotation Author Friday 24 th February 2012 Business Continuity Planning
Security+ Guide to Network Security Fundamentals, Fourth Edition. Chapter 13 Business Continuity
Security+ Guide to Network Security Fundamentals, Fourth Edition Chapter 13 Business Continuity Objectives Define environmental controls Describe the components of redundancy planning List disaster recovery
The Shift Cloud Computing Brings to Disaster Recovery
The Shift Cloud Computing Brings to Disaster Recovery Mike Klein President, Online Tech June 21, 2010 Disasters Happen WHY DISASTER RECOVERY? How Do You Recover All of Your Electronic Assets? Recover Your
Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM
Business Continuity Planning and Disaster Recovery Planning Ed Crowley IAM/IEM 1 Goals Compare and contrast aspects of business continuity Execute disaster recovery plans and procedures 2 Topics Business
Protecting your SQL database with Hybrid Cloud Backup and Recovery. Session Code CL02
Protecting your SQL database with Hybrid Cloud Backup and Recovery Session Code CL02 ARCserve True Hybrid Data Protection ARCserve Backup Data protection for complex environments Disk to Disk to-tape Disk
Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain
1. What is the most common planned performance duration for a continuity of operations plan (COOP)? A. 30 days B. 60 days C. 90 days D. It depends on the severity of a disaster. 2. What is the business
Availability and Disaster Recovery: Basic Principles
Availability and Disaster Recovery: Basic Principles by Chuck Petch, WVS Senior Technical Writer At first glance availability and recovery may seem like opposites. Availability involves designing computer
INSIDE. Preventing Data Loss. > Disaster Recovery Types and Categories. > Disaster Recovery Site Types. > Disaster Recovery Procedure Lists
Preventing Data Loss INSIDE > Disaster Recovery Types and Categories > Disaster Recovery Site Types > Disaster Recovery Procedure Lists > Business Continuity Plan 1 Preventing Data Loss White Paper Overview
How Cloud Computing Can Help. Mark Parrish
How Cloud Computing Can Help Your Business Operations Mark Parrish Ajasent Inc. About Us Mark Parrish Bryan Cordill Joey Cordill Ajasent has been serving clients with highly managed application hosting
CONTINGENCY PLANNING -- THE AUDIT PROCESS Leslie A. Virgilio OFF-SITE, Inc. 32 Ellicott Street Batavia, New York 14020
CONTINGENCY PLANNING -- THE AUDIT PROCESS Leslie A. Virgilio OFF-SITE, Inc. 32 Ellicott Street Batavia, New York 14020 Di~aster Recovery is the ability to continue your information processing when your
Business Continuity and the Cloud. Aaron Shaver US Signal, Solution Architect
Business Continuity and the Cloud Aaron Shaver US Signal, Solution Architect Overview What is BC/DR? Why should businesses have a strategy? Why do many business choose not to? How does the cloud change
Disaster Recovery & Business Continuity Dell IT Executive Learning Series
Disaster Recovery & Business Continuity Dell IT Executive Learning Series Presented by Rich Armour, Debi Higdon & Mitchell McGovern THIS PRESENTATION SUMMARY IS FOR INFORMATIONAL PURPOSES ONLY AND MAY
PAPER-6 PART-4 OF 5 CA A.RAFEQ, FCA
1 Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-4 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand
ITMF Disaster Recovery and Business Continuity Committee Report for the UGA IT Master Plan
ITMF Disaster Recovery and Business Continuity Committee Report for the UGA IT Master Plan I. Executive Summary Planning for continued operation during unforeseen catastrophic events, and for returning
HARVARD RESEARCH GROUP, Inc.
HARVARD RESEARCH GROUP,Inc. 1740 MASSACHUSETTS AVENUE BOXBOROUGH, MASSACHUSETTS 01719 Tel (978) 263-3399 Vol1 The High-Availability Challenge 1999 Recently Harvard Research Group (HRG) completed the analysis
Toronto Public Library Disaster Recovery recommended safeguards and controls
BCE Security Solutions Restricted Attachment 1 Toronto Public Library Disaster Recovery recommended safeguards and controls Final Prepared by: Bell Security Solutions Inc. Professional Services 333 Preston
Disaster Recovery. Hendry Taylor Tayori Limited
Disaster Recovery Hendry Taylor Tayori Limited Agenda What is Business Continuity planning (BCP) What is Disaster Recovery (DR) and Disaster Recovery Planning (DRP) Overview Lifecycle Analysis Plan design
Business Continuity Planning and Disaster Recovery Planning
Business Continuity Planning and Disaster Recovery Planning Ed Crowley IAM/IEM 1 ISC 2 Key Areas of Knowledge Understand business continuity requirements 1. Develop and document project scope and plan
Disaster Recovery Disaster Recovery Planning for Business Continuity Session Name :
Disaster Recovery Planning for Business Continuity Session Name : Title Introducing Jason Ouimette Product Manager, Noble Systems John Simpson CIO, Noble Systems Mike Mahfouz Director of Collection Operations,
Domain 3 Business Continuity and Disaster Recovery Planning
Domain 3 Business Continuity and Disaster Recovery Planning Steps (ISC) 2 steps [Har10] Project initiation Business Impact Analysis (BIA) Recovery strategy Plan design and development Implementation Testing
How To Back Up A Virtual Machine
2010 Symantec Disaster Recovery Study Global Results Methodology Applied Research performed survey 1,700 enterprises worldwide 5,000 employees or more Cross-industry 2 Key Findings Virtualization and Cloud
This white paper describes the three reasons why backup is a strategic element of your IT plan and why it is critical to your business that you plan
This white paper describes the three reasons why backup is a strategic element of your IT plan and why it is critical to your business that you plan and execute a strategy to protect 100 percent of your
Backup Strategies for Small Business
Backup Strategies for Small Business StarTech Group, Inc. Jim Scalise 11.15.2014 1 StarTech Group, Inc. 2771-29 Monument Rd. PMB 232 Jacksonville, FL 32225 CONTENTS BACKUP STRATEGIES.. 1 CLOUD BACKUP 2
Disaster Recovery. Stanley Lopez Premier Field Engineer Premier Field Engineering Southeast Asia Customer Services and Support
Disaster Recovery Stanley Lopez Premier Field Engineer Premier Field Engineering Southeast Asia Customer Services and Support Categories of Risk Financial Operational Reputational Market share Revenue
A Study on Cloud Computing Disaster Recovery
A Study on Cloud Computing Disaster Recovery Mr.A.Srinivas, Y.Seetha Ramayya, B.Venkatesh HOD and Associate Professor, Dept. Of CSE, Coastal Institute of Technology & Management, Vizianagaram, India Students
Disaster Recovery Plan Checklist
Disaster Recovery Plan Checklist Your guide for setting up or updating a Disaster Recovery Plan for your business. ArcSource Disaster Recovery Plan Checklist 1. Compile Your Internal Contacts Information
DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS
Appendix L DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS I. GETTING READY A. Obtain written commitment from top management of support for contingency planning objectives. B. Assemble
Business Continuity Planning (BCP) / Disaster Recovery (DR)
Business Continuity Planning (BCP) / Disaster Recovery (DR) Introduction Interruptions to business functions can result from major natural disasters such as earthquakes, floods, and fires, or from man-made
Disaster Recovery 101. Sudarshan Ranganath & Matthew Phillips Ellucian
Disaster Recovery 101 Sudarshan Ranganath & Matthew Phillips Ellucian SESSION OBJECTIVES Business continuity is critical to every institution and its IT organization. How do you set up your ERP and other
How to Plan for Disaster Recovery and Business Continuity
A TAMP Systems White Paper TAMP Systems 1-516-623-2038 www.drsbytamp.com How to Plan for Disaster Recovery and Business Continuity By Tom Abruzzo, President and CEO Contents Introduction 1 Definitions
Data Backup Options for SME s
Data Backup Options for SME s As an IT Solutions company, Alchemy are often asked what is the best backup solution? The answer has changed over the years and depends a lot on your situation. We recognize
Ohio Supercomputer Center
Ohio Supercomputer Center IT Business Continuity Planning No: Effective: OSC-13 06/02/2009 Issued By: Kevin Wohlever Director of Supercomputer Operations Published By: Ohio Supercomputer Center Original
A SWOT ANALYSIS ON CISCO HIGH AVAILABILITY VIRTUALIZATION CLUSTERS DISASTER RECOVERY PLAN
A SWOT ANALYSIS ON CISCO HIGH AVAILABILITY VIRTUALIZATION CLUSTERS DISASTER RECOVERY PLAN Eman Al-Harbi [email protected] Soha S. Zaghloul [email protected] Faculty of Computer and Information
Disaster Recovery Hosting Provider Selection Criteria
Disaster Recovery Hosting Provider Selection Criteria By, Solution Director 6/18/07 As more and more companies choose to use Disaster Recovery (DR), services the questions that keep coming up are What
Course 2788A: Designing High Availability Database Solutions Using Microsoft SQL Server 2005
Course Syllabus Course 2788A: Designing High Availability Database Solutions Using Microsoft SQL Server 2005 About this Course Elements of this syllabus are subject to change. This three-day instructor-led
RLI PROFESSIONAL SERVICES GROUP PROFESSIONAL LEARNING EVENT PSGLE 125. When Disaster Strikes Are You Prepared?
RLI PROFESSIONAL SERVICES GROUP PROFESSIONAL LEARNING EVENT PSGLE 125 When Disaster Strikes Are You Prepared? Copyright Materials This presentation is protected by US and International Copyright laws.
Virtual Infrastructure Security
Virtual Infrastructure Security 2 The virtual server is a perfect alternative to using multiple physical servers: several virtual servers are hosted on one physical server and each of them functions both
ROI of IT DISASTER RECOVERY
ROI of IT DISASTER RECOVERY Acronis 2002-2015 In light of recent U.S. disasters, such as Hurricane Sandy and Katrina, disaster recovery and business continuity are now important topics that are top of
Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC
Assessing Your Disaster Recovery Plans Gregory H. Soule, CPA, CISA, CISSP, CFE Andrews Hooper Pavlik PLC Andrews Hooper Pavlik PLC Agenda Business Continuity Concepts Impact Analysis Risk Assessment Risk
Remote Backup Solution: Frequently Asked Questions
Remote Backup Solution: Frequently Updated December 2014 Contents What is ECi Remote Backup?...3 What Levels of Protection are Available?...3 Why is ECi Remote Backup Important for Disaster Recovery?...3
An Overview of Disaster Recovery Planning Under HIPPA Security Rules
Disaster Recovery Planning Under HIPAA An Overview 1 White Paper Published October 2003 - Doug Thompson - MITG, Inc. - Quincy, IL An Overview of Disaster Recovery Planning Under HIPPA Security Rules Overview
One major business challenge is maintaining and improving the efficiency and effectiveness of a company s information technology. Wouldn t it be nice
Contents Managed IT Services Life Cycle Why ProActive SM Outsource Your IT Function Professional Services How Does It Work? How Do You Benefit? Disaster Recovery/Back-up Business Partners ANALYZE MANAGE
Disaster Prevention and Recovery for School System Technology
The Optimal Reference Guide: Disaster Prevention and Recovery for School System Technology Extraordinary insight into today s education topics Glynn D. Ligon, Ph.D., ESP Solutions Group Evangelina Mangino,
Everything You Need to Know About Network Failover
Everything You Need to Know About Network Failover Worry-Proof Internet 2800 Campus Drive Suite 140 Plymouth, MN 55441 Phone (763) 694-9949 Toll Free (800) 669-6242 Overview Everything You Need to Know
Audit, Finance and Legislative Committee Mayor Craig Lowe, Chair Mayor-Commissioner Pro Tem Thomas Hawkins, Member
City of Gainesville Inter-Office Communication April 3, 2012 TO: FROM: SUBJECT: Audit, Finance and Legislative Committee Mayor Craig Lowe, Chair Mayor-Commissioner Pro Tem Thomas Hawkins, Member Brent
HIPAA Security Matrix
HIPAA Matrix Hardware : 164.308(a)(1) Management Process =Required, =Addressable Risk Analysis The Covered Entity (CE) can store its Risk Analysis document encrypted and offsite using EVault managed software
Application / Hardware - Business Impact Analysis Template. MARC Configuration Requirements. Business Impact Analysis
Application / Hardware - Business Impact Analysis Template The single most important thing we can do is help you understand the criticality of each application, supporting hardware/server/pc and the required
Surround SCM Backup and Disaster Recovery Solutions
and Disaster Recovery Solutions by Keith Vanden Eynden Investing in a source code management application, like, protects your code from accidental overwrites, deleted versions, and other common errors.
Disaster Recovery. 1.1 Introduction. 1.2 Reasons for Disaster Recovery. EKAM Solutions Ltd Disaster Recovery
Disaster Recovery 1.1 Introduction Every day, there is the chance that some sort of business interruption, crisis, disaster, or emergency will occur. Anything that prevents access to key processes and
Best practices for operational excellence (SharePoint Server 2010)
Best practices for operational excellence (SharePoint Server 2010) Published: May 12, 2011 Microsoft SharePoint Server 2010 is used for a broad set of applications and solutions, either stand-alone or
Disaster Recovery Planning for Homesteaders 2004 Paul Edwards & Associates
Disaster Recovery Planning for Homesteaders 2004 Paul Edwards & Associates Introduction The term homesteading comes from the days of the pioneers that setled in the midwest and western United States. That
New Mexico Municipal Court Automation Guide to Disaster Recovery Planning
New Mexico Municipal Court Automation Guide to Disaster Recovery Planning June 2007 New Mexico Municipal Courts Automation Program Zella Cox, Program Manager (505) 476-6943 [email protected] Tomás
EMERGENCY PREPAREDNESS PLAN Business Continuity Plan
EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic
Informix Dynamic Server May 2007. Availability Solutions with Informix Dynamic Server 11
Informix Dynamic Server May 2007 Availability Solutions with Informix Dynamic Server 11 1 Availability Solutions with IBM Informix Dynamic Server 11.10 Madison Pruet Ajay Gupta The addition of Multi-node
Incident Management, Business Continuity and IT Disaster Recovery
Incident Management, Business Continuity and IT Disaster Recovery Aggeliki Tsohou Lecturer, Ionian University, Department of Informatics, Greece [email protected] 1 Contents Information Security Incident
ivu. Software as a Service
ivu.cloud Software AS A Service Software and HOsting from one TRUSted Source Powerful standard products, professional support and reliable hosting. IVU.cloud SOFTWARE AS A SERVICE Secure, reliable, scalable
Aljex Software, Inc. Business Continuity & Disaster Recovery Plan. Last Updated: June 16, 2009
Business Continuity & Disaster Recovery Plan Last Updated: June 16, 2009 Business Continuity & Disaster Recovery Plan Page 2 of 6 Table of Contents Introduction... 3 Business Continuity... 3 Employee Structure...
Module 5 Introduction to Processes and Controls
IT Terminology 1. General IT Environment The general IT environment is the umbrella over the following IT processes: 1. Operating Systems 2. Physical and Logical Security 3. Program Changes 4. System Development
VERY IMPORTANT NOTE! - RAID
Disk drives are an integral part of any computing system. Disk drives are usually where the operating system and all of an enterprise or individual s data are stored. They are also one of the weakest links
Business Continuity Planning for Risk Reduction
Business Continuity Planning for Risk Reduction Ion PLUMB [email protected] Andreea ZAMFIR [email protected] Delia TUDOR [email protected] Faculty of Management Academy of Economic Studies
DB2 9 for LUW Advanced Database Recovery CL492; 4 days, Instructor-led
DB2 9 for LUW Advanced Database Recovery CL492; 4 days, Instructor-led Course Description Gain a deeper understanding of the advanced features of DB2 9 for Linux, UNIX, and Windows database environments
Planning and Implementing Disaster Recovery for DICOM Medical Images
Planning and Implementing Disaster Recovery for DICOM Medical Images A White Paper for Healthcare Imaging and IT Professionals I. Introduction It s a given - disaster will strike your medical imaging data
What is Business Continuity Planning (BCP) / Disaster Recovery Plan(DRP)?
Workshop on System Audit of Banks BCP Workshop on System Audit of Banks What is Business Continuity Planning (BCP) / Disaster Recovery Plan(DRP)? - Preparedness of an organisation to ensure continuity,
Protecting your Enterprise
Understanding Disaster Recovery in California Protecting your Enterprise Session Overview Why do we Prepare What is? How do I analyze (measure) it? What to do with it? How do I communicate it? What does
High Availability and Disaster Recovery Solutions for Perforce
High Availability and Disaster Recovery Solutions for Perforce This paper provides strategies for achieving high Perforce server availability and minimizing data loss in the event of a disaster. Perforce
Backups and Maintenance
Backups and Maintenance Backups and Maintenance Objectives Learn how to create a backup strategy to suit your needs. Learn how to back up a database. Learn how to restore from a backup. Use the Database
Why Email Fails MessageOne Survey of Email Outages
Why Email Fails MessageOne Survey of Email Outages White Paper MessageOne, Inc. 11044 Research Blvd. Building C, Fifth Floor Austin, TX 78759 Toll-Free: 888.367.0777 Telephone: 512.652.4500 Fax: 512.652.4504
Business Unit CONTINGENCY PLAN
Contingency Plan Template Business Unit CONTINGENCY PLAN Version 1.0 (Date submitted) Submitted By: Business Unit Date Version 1.0 Page 1 1 Plan Review and Updates... 3 2 Introduction... 3 2.1 Purpose...
5 Essential Benefits of Hybrid Cloud Backup
5 Essential Benefits of Hybrid Cloud Backup QBR is a backup, disaster recovery (BDR), and business continuity solution targeted to the small to medium business (SMB) market. QBR solutions are designed
EHRs and Information Availability: Are You At Risk?
May 2006 Issue EHRs and Information Availability: Are You At Risk? The EHR initiative is changing the face of disaster and the nature of prevention planning. By Jim Grogan On April 27, 2004, the age of
Backup and Redundancy
Backup and Redundancy White Paper NEC s UC for Business Backup and Redundancy allow businesses to operate with confidence, providing security for themselves and their customers. When a server goes down
Business Continuity and Capacity Building
Business Continuity and Capacity Building April 10, 2015 Business Continuity and Capacity Building April 10, 2015 1 / 14 Developing Institutional Business Continuity Plans and Implications for Capacity
A CommVault White Paper: Business Continuity: Commserve Licensing & Recovery Procedure
A CommVault White Paper: Business Continuity: Commserve Licensing & Recovery Procedure CommVault Corporate Headquarters 2 Crescent Place Oceanport, New Jersey 07757-0900 USA Telephone: 888.746.3849 or
Backup and Recovery by using SANWatch - Snapshot
Backup and Recovery by using SANWatch - Snapshot 2007 Infortrend Technology, Inc. All rights Reserved. Table of Contents Introduction...3 Snapshot Functionality...3 Eliminates the backup window...3 Retrieves
The case for cloud-based disaster recovery
IBM Global Technology Services IBM SmartCloud IBM SmartCloud Virtualized Server Recovery i The case for cloud-based disaster recovery Cloud technologies help meet the need for quicker restoration of service
SOLUTION BRIEF: KEY CONSIDERATIONS FOR DISASTER RECOVERY
SOLUTION BRIEF: KEY CONSIDERATIONS FOR DISASTER RECOVERY A Disaster Recovery and Business Continuity plan is specific to the circumstances, priorities and expense versus the value decisions of the organization,
ICT NETWORK AND INFRASTRUCTURE FILE SERVER POLICY
ICT NETWORK AND INFRASTRUCTURE FILE SERVER POLICY Version 1.0 Ratified By Date Ratified Author(s) Responsible Committee / Officers Issue Date Review Date Intended Audience Impact Assessed CCG Committee
Blackboard Managed Hosting SM Disaster Recovery Planning Document
BLACKBOARD MANAGED HOSTING Blackboard Managed Hosting SM Disaster Recovery Planning Document Prepared By: MH Services Modified Date: March 2009 Revision: 1.8 1. OBJECTIVES... 3 2. SCOPE... 3 3. ASSUMPTIONS...
'Namgis Information Technology Policies
'Namgis Information Technology Policies Summary August 8th 2011 Government Security Policies CONFIDENTIAL Page 2 of 17 Contents... 5 Architecture Policy... 5 Backup Policy... 6 Data Policy... 7 Data Classification
Cisco Disaster Recovery: Best Practices White Paper
Table of Contents Disaster Recovery: Best Practices White Paper...1 Introduction...1 Performance Indicators for Disaster Recovery...1 High Level Process Flow for Disaster Recovery...2 Management Awareness...2
IT Disaster Recovery Plan Template
HOPONE INTERNET CORP IT Disaster Recovery Plan Template Compliments of: Tim Sexton 1/1/2015 An information technology (IT) disaster recovery (DR) plan provides a structured approach for responding to unplanned
