Business Continuity and Disaster Recovery Planning
|
|
|
- Ophelia Hicks
- 9 years ago
- Views:
Transcription
1 Business Continuity and Disaster Recovery Planning 1
2 More than 20% of all small medium sized businesses suffer a major disaster every 5 years. Almost all that lose their data for 10 days or more file for bankruptcy within a year.
3 Project initiation steps Recovery and continuity planning requirements Business impact analysis Selecting, developing, and implementing disaster and continuity plans Backup and offsite facilities Types of drills and tests
4 Any disruptive event (natural or man-made) that interrupts normal system in such a significant way that a considerable and coordinated effort is required to achieve a recovery.
5 Geological: earthquakes, volcanoes, lahars, tsunamis, landslides, and sinkholes Meteorological: hurricanes, tornados, wind storms, hail, ice storms, snow storms, rainstorms, and lightning
6 Other: avalanches, fires, floods, meteors and meteorites, and solar storms Health: widespread illnesses, quarantines, and pandemics (remember Anthrax? What will you do if they find Anthrax in the mailroom?)
7 Labor: strikes, walkouts, and slowdowns that disrupt services and supplies Social-political: war, terrorism, sabotage, vandalism, civil unrest, protests, demonstrations, cyber attacks, and blockades
8 Materials: fires, hazardous materials spills Utilities: power failures, communications outages, water supply shortages, fuel shortages, and radioactive fallout from power plant accidents
9 Damage to facilities and equipment Utility outages Communication outages Transportation/delivery delays Personnel unavailable (or unable to travel) to work
10 Remember CIA? Which of these security services (security pillars) does business continuity and disaster recovery planning support?
11 Disasters are a fact of life Personnel need to be trained and prepared for their occurrence
12 Plan Type Business Resumption Plan Continuity of Operations Plan (COOP) IT Contingency Plan (ITCP) Crisis Communications Plan Cyber Incident Response Plan Disaster Recovery Plan (DRP) Description Focus on necessary business processes instead of IT procedures Establishes management and headquarters after a disaster. Outlines roles and authorities, orders of succession, and individual role tasks. Plan for restoring systems, networks, major apps after a disruption at the original facility. Provides procedures for disseminating internal and external communications; means to provide critical status information and control rumors. Provides procedures for mitigating and correcting a cyber attack addresses mitigation and isolation of affected systems, clean up, and loss minimization How to recover IT mechanisms after a disaster. Focuses on disasters that require IT processing to take place at another facility.
13 BCP and DRP are two distinct, but related, plans Business Continuity Plan (BCP) - ensures that the business will continue to operate before (includes a focus on prevention), during, and after an event. A strategic (long-term) plan. Identifies alternate personnel, equipment, and facilities
14 BCP and DRP are two distinct, but related, plans Disaster Recovery Plan (DRP) Tactical, shorter-term plan that focuses on the immediate response and recovery of critical IT systems during a disruption. Contains procedures for emergency response (assessment, salvage, repair, and eventual restoration of damaged facilities and systems)
15 NIST : Contingency Planning Guide for Information Technology Systems. Seven step process for BCP and DRP projects.
16 ISO 17799: Code of Practice for Information Security Management. Section 14 addresses business continuity management. BS25999: Code of Practice for Business Continuity Management.
17 NFPA 1600: Standard on Disaster / Emergency Management and Business Continuity Programs. NFPA 1620: The Recommended Practice for Pre-Incident Planning. HIPAA: Requires a documented and tested disaster recovery plan.
18 Cheaper cyber insurance (reduced risk from long term outages) Market advantage Process improvements Improved organizational maturity
19 (ISC)2 Project initiation Business Impact Assessment Recovery strategy Plan design and development Implementation Testing Continual maintenance
20 Pre-planning Activities/Policy Integrate law and regulations Define the scope, goals, and roles Choose project team members Develop project plan and project charter Management approval BIA Identify critical functions (criticality analysis and impact statements) and resources Calculate MTD (Maximum Tolerable Downtime) and other key metrics (RTO, RPO) Identify threats Calculate risks Identify backup solutions Identify Preventive Controls Implement controls Mitigate risk
21 Develop Recovery Strategies Business process Facility Supply and technology User and user environment Data Document procedures, recovery solutions, roles and tasks, and emergency response Develop BCP Exercise test drill Test plan Improve plan Train employees
22 Maintain BCP Integrate into change control process Assign responsibility Update plan Distribute after updating
23 Identify a business continuity coordinator to lead BCP team Develop team: Business units, senior management, IT dept. Security dept. Communications department, legal department Develop a project plan Gain management approval
24 Formal method for determining how a disruption to the organization s IT systems will impact the mission. Consists of 2 processes: Identification of critical assets Comprehensive risk assessment
25 Steps Description Identify critical assets IT assets that are mission-essential and must be recovered first Identify interdependencies Conduct BCP/DRP-focused Risk Assessment Determine Maximum Tolerable Downtime (MTD) - the maximum time each business process can be inoperative before significant damage or long-term viability is threatened MTD=RTO+WRT Identify risks to each asset Conduct vulnerability analysis Statements of Impact Consists of two metrics: Recovery Time Objective (RTO) - maximum time allowed to recover business or IT systems (from disaster onset to resumption of businesses processes) Work Recovery Time (WRT) time required to configure a recovered system
26 Term Recovery Point Objective (RPO) Mean Time between Failures (MBTF) Mean Time to Repair (MTTR) Minimum Operating Requirements Definition Level of data/work loss or system inaccessibility (measured in time) resulting from a disaster that an organization can withstand counted backwards from onset of disaster Average amount of time a system or device is runs before it fails Length of time to recover a failed device or system Minimum environmental and connectivity requirements required to operate
27 RPO Technologies 8 14 days New equipment, data recovery from backup 4 7 days Cold systems, data recovery from backup 2 3 days Warm systems, data recovery from backup hours Warm systems, recovery from high speed 6 12 hours Hot systems, recovery from high speed backup media 3 6 hours Hot systems, data replication 1 3 hours Clustering, data replication <1 hour Clustering, near real time data replication Adapted from CISSP Guide to Security Essentials
28 For each process, describe the impact on the rest of the organization if the process is incapacitated Examples Inability to process payments Inability to produce invoices Inability to access customer data for support purposes
29 Fortification of facility Redundancy (clustered servers, drives, etc.) Power lines Fire suppression/detection Redundant vendor support Insurance UPS/generators Data backup technologies Media protection safeguards Inventory
30 5 Steps that we ll discuss: 1. Business process recovery 2. Facility recovery 3. Supply and technology recovery 4. User environment recovery 5. Data recovery
31 Define critical steps of a company s processes Required roles Required resources Input and output mechanisms Workflow steps Time for completion Interfaces with other processes
32 3 types of disruptions: Nondisasters disruption in service due to a device malfunction or failure Disasters An event causes the loss of the entire facility for a day or longer Catastrophes major disruption that destroys the facility, requiring moving operations to offsite facility
33 Type of offsite facility Advantages Disadvantages Hot Site fully configured with equipment and lines. Data retrieved and loaded from backup site Cold Site supplies basic environment (electrical, AC, plumbing) but no systems can also just be a reciprocal agreement Warm Site anywhere in between. High availability - can be immediately ready or within matter of hours Lowest availability longest restoration time Less expensive Expensive!!! Least Expensive Not immediately available (requires some setup and restoration Operational Testing not available Note: For CISSP exam purposes a hot site here is a subscription service not owned by the company!!!
34 Redundant Sites: Redundant site: Site is equipped and configured exactly like the production site data data can be streamed live Rolling hot site: Large truck or trailer is turned into a work area Multiple processing centers Distributed through multiple locations
35 Recovery team must be able to recreate the environment Hardware? Software? Configuration manuals? Where are your recovery plans stored? How long will it take for new equipment to arrive many have requirements within 24 hours (do you have a contract with your vendor that provides for this?) Backups do you have apps and O/Ss to support your restored data (remember that we covered types of backups last week)? Ensure that there are at least two copies available of a company s operating system software and critical apps one offsite and one offsite test these to ensure you can restore!!!!!
36 Employee Notification develop a Crisis Communications Plan Call Tree used to rapidly communicate information throughout an organization by assigning the responsibility for contacting employees to other employees (i.e. Margaret calls Bob and 9 other people, Bob then calls 10 people, who each call 10 people, etc.) Identify users who need to return to work and how they need to work Can you return to paper processes? Can you automate processes?
37 Covered last week (all in how the archive bit is handled remember?) Full Backup every file is backed up and archive bit is removed Differential Backup only files with the archive bit are backed up, but the archive bit is left on the file (so backup is cumulative until the full backup runs and removes the bits necessitating restoring the last full backup and last differential) Incremental Backup - only files with the archive bit are backed up, and the archive bit is removed from the file (necessitates layering the incremental tapes in order over the full backup during restoration)
38 Disk shadowing online backup storage (disk mirroring is a one-to-one relationship, disk shadowing uses multiple drives to create shadow sets Electronic vaulting makes copies of files as they are modified and periodically transmits them to offsite backup storage (common in banks) Remote journaling includes only moving the deltas that have taken place
39 Close enough or provision to access media? Far enough away to withstand regional disaster? Closed on weekends or holidays? Commensurate security controls to production facility? Availability of bonded transport system (Iron Mountain)? Does data need to be encrypted if leaving the production facility?
40 Method of transferring risk Cyberinsurance new type of insurance that covers DoS, malware, privacy-related lawsuits, downstream liability, etc. Business interruption insurance covers loss of revenue in the event something bad happens
41 BCP coordinator needs to define teams: Damage assessment team Determines the cause of the disaster, potential for further damage, and whether or not to activate the BCP Restoration team responsible for getting the alternate site into a working and functioning environment Salvage Team responsible for starting the recovery of the original site Media relations team Security team Telecommunications team Reconstitution phase - when a company moves back to its original site or new site
42 Test Type DRP Review Checklist (consistency) Structured Walkthrough /Tabletop Simulation Test/Walkthrough Drill Parallel Processing Partial and Complete Business Interruption Purpose Most basic reading the DRP from start to finish by the team that developed it to ensure that it is complete Often performed concurrently with a structured walkthrough or tabletop test lists all necessary components required for recovery Group walks through the process on paper Teams actually carry out the recovery process (disaster is simulated) scope of simulation can vary Recovery of crucial processing components at an alternate computing facility and then restoration from a previous backup without disrupting production) Risky! Processing is stopped at the primary location and transitioned to the alternate location
43 At least annually!! Identify test objectives and scope Identify Lessons Learned Revise the plan after testing (I look for lessons learned as an audit item) Note: BCPs are updated whenever there are significant changes to the organization
44 Determine how frequently (at least annually) Good idea to train different roles more regularly Train so that everyone knows the initial steps and where to find the plans First aid and CPR Starting emergency power Call tree
45 Plans updated whenever there is a change to the environment Plans reviewed for updates at least annually if no changes Track and document all planned changes and implement a formal approval process for all substantial changes Changes must be auditable!
46 NIST SP (now Rev. 1) ISO/IEC draft - part of ISO series addresses Information and Communications Technology (ICT) and Information Security Management System (ISMS) BS (2 parts) British business continuity standard BCI (Business Continuity Institute) 6 step Good Practice Guidelines
47 Lack of management support No coordination with vendors Lack of testing Lack of prioritization Lack of training and awareness
48 Cloud environments complicate Disaster Recovery Cloud environments can be a part of an organization s DR process Must plan on how personnel will access the cloud
49
50
51 Which of the following is the number one priority of all BCP and DRPs? A. The elimination of potential outages B. The reduction of potential outages C. Protection and welfare of employees D. The minimization of potential outages
52 Which of the following is the number one priority of all BCP and DRPs? A. The elimination of potential outages B. The reduction of potential outages C. Protection and welfare of employees D. The minimization of potential outages
53 Maximum Tolerable Downtime (MTD) comprises which two metrics? A. Recovery Point Objective (RPO) and Work Recovery Time (WRT)? B. Recovery Point Objective (RPO) and Mean Time to Repair (MTTR)? C. Recovery Time Objective (RTO) and Mean Time to Repair (MTTR)? D. Recovery Time Objective (RTO) and Work Recovery Time (WRT)?
54 Maximum Tolerable Downtime (MTD) comprises which two metrics? A. Recovery Point Objective (RPO) and Work Recovery Time (WRT)? B. Recovery Point Objective (RPO) and Mean Time to Repair (MTTR)? C. Recovery Time Objective (RTO) and Mean Time to Repair (MTTR)? D. Recovery Time Objective (RTO) and Work Recovery Time (WRT)?
55 An example of risk transference is: A. Offsite storage B. Insurance C. Maintaining spare equipment offsite D. Fire suppression
56 An example of risk transference is: A. Offsite storage B. Insurance C. Maintaining spare equipment offsite D. Fire suppression
57 What is one of the first steps in identifying a BCP? A. Identify backup solution B. Decide whether the company needs to perform a walk-through, parallel, or simulation test C. Perform a business impact analysis D. Develop a business resumption plan.
58 What is one of the first steps in identifying a BCP? A. Identify backup solution B. Decide whether the company needs to perform a walk-through, parallel, or simulation test C. Perform a business impact analysis D. Develop a business resumption plan.
59 Which plan details the steps required to restore normal business operations/mission after recovery from a disruptive event? A. Business Continuity Plan (BCP) B. Business Resumption Plan (BRP) C. Continuity of Operations Plan (COOP) D. Occupant Emergency Plan (OEP)
60 Which plan details the steps required to restore normal business operations/mission after recovery from a disruptive event? A. Business Continuity Plan (BCP) B. Business Resumption Plan (BRP) C. Continuity of Operations Plan (COOP) D. Occupant Emergency Plan (OEP)
61 Which draft Business Continuity guideline ensures continuity of Information and Communications Technology (ICT) as a part of the organization's Information Security Management System (ISMS)? A. BCI B. BS-7799 C. ISO/IEC D. NIST SP
62 Which draft Business Continuity guideline ensures continuity of Information and Communications Technology (ICT) as a part of the organization's Information Security Management System (ISMS)? A. BCI B. BS-7799 C. ISO/IEC D. NIST SP
63 Which of the following best describes the difference between an Information Systems Contingency Plan and Disaster Recovery Plan? A. Information Systems Contingency Plan procedures are developed for recovery of the system regardless of site or location after a non-disaster B. Disaster Recovery Plan procedures are developed for recovery of the system regardless of site or location C. Disaster Recovery Plan can be activated at the system's current location or at an alternate site D. Information Systems Contingency Plan is developed for disasters that require restoration of IT systems at an alternate site.
64 Which of the following best describes the difference between an Information Systems Contingency Plan and Disaster Recovery Plan? A. Information Systems Contingency Plan procedures are developed for recovery of the system regardless of site or location after a non-disaster B. Disaster Recovery Plan procedures are developed for recovery of the system regardless of site or location C. Disaster Recovery Plan can be activated at the system's current location or at an alternate site D. Information Systems Contingency Plan is developed for disasters that require restoration of IT systems at an alternate site.
65 What is the primary objective of a disaster recovery plan? a. To recover critical processes in a timely manner b. Manage public relations after a crisis c. To minimize financial loss during normal operations outage d. Re-design the security infrastructure of the organization after an emergency
66 What is the primary objective of a disaster recovery plan? a. To recover critical processes in a timely manner b. Manage public relations after a crisis c. To minimize financial loss during normal operations outage d. Re-design the security infrastructure of the organization after an emergency
67 A critical company asset would most likely have which of the following MTD values? A. Minutes to hours B. Days C. Weeks D. Months
68 A critical company asset would most likely have which of the following MTD values? A. Minutes to hours B. Days C. Weeks D. Months
69
Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain
1. What is the most common planned performance duration for a continuity of operations plan (COOP)? A. 30 days B. 60 days C. 90 days D. It depends on the severity of a disaster. 2. What is the business
Domain 3 Business Continuity and Disaster Recovery Planning
Domain 3 Business Continuity and Disaster Recovery Planning Steps (ISC) 2 steps [Har10] Project initiation Business Impact Analysis (BIA) Recovery strategy Plan design and development Implementation Testing
CISSP Common Body of Knowledge: Business Continuity & Disaster Recovery Planning Domain Version: 5.9.2
CISSP Common Body of Knowledge: Business Continuity & Disaster Recovery Planning Domain Version: 5.9.2 CISSP Common Body of Knowledge Review by Alfred Ouyang is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike
Business Continuity Planning and Disaster Recovery Planning
Business Continuity Planning and Disaster Recovery Planning Ed Crowley IAM/IEM 1 ISC 2 Key Areas of Knowledge Understand business continuity requirements 1. Develop and document project scope and plan
Business Continuity Plan
Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions
Temple university. Auditing a business continuity management BCM. November, 2015
Temple university Auditing a business continuity management BCM November, 2015 Auditing BCM Agenda 1. Introduction 2. Definitions 3. Standards 4. BCM key elements IT Governance class - IT audit program
Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM
Business Continuity Planning and Disaster Recovery Planning Ed Crowley IAM/IEM 1 Goals Compare and contrast aspects of business continuity Execute disaster recovery plans and procedures 2 Topics Business
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP). Ed Fortin President Fortin Consulting Paul Godden Consultant & Quotation Author Friday 24 th February 2012 Business Continuity Planning
Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC
Assessing Your Disaster Recovery Plans Gregory H. Soule, CPA, CISA, CISSP, CFE Andrews Hooper Pavlik PLC Andrews Hooper Pavlik PLC Agenda Business Continuity Concepts Impact Analysis Risk Assessment Risk
Business Continuity Glossary
Developed In Conjuction with Business Continuity Glossary ACTIVATION: The implementation of business continuity capabilities, procedures, activities, and plans in response to an emergency or disaster declaration;
Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP)
Preface Computer systems are the core tool of today s business and are vital to every business from the smallest to giant organizations. Money transactions, customer service are just simple examples. Despite
EMERGENCY PREPAREDNESS PLAN Business Continuity Plan
EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic
Contingency Planning Guide
Institutional and Sector Modernisation Facility ICT Standards Contingency Planning Guide Document number: ISMF-ICT/3.03 - ICT Security/MISP/SD/CP Version: 1.20 Project Funded by the European Union 1 Document
Western Intergovernmental Audit Forum
Western Intergovernmental Audit Forum Business Continuity & Disaster Recovery Planning September 12, 2013 Presented by: City of Phoenix City Auditor Department Aaron Cook, Sr Internal Auditor IT Audit
With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS
How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning The world has experienced a great deal of natural and man-made upheaval and destruction in the past few years, including tornadoes,
Business Continuity and the Cloud. Aaron Shaver US Signal, Solution Architect
Business Continuity and the Cloud Aaron Shaver US Signal, Solution Architect Overview What is BC/DR? Why should businesses have a strategy? Why do many business choose not to? How does the cloud change
Security+ Guide to Network Security Fundamentals, Fourth Edition. Chapter 13 Business Continuity
Security+ Guide to Network Security Fundamentals, Fourth Edition Chapter 13 Business Continuity Objectives Define environmental controls Describe the components of redundancy planning List disaster recovery
Business Continuity Planning and Disaster Recovery Planning
4 Business Continuity Planning and Disaster Recovery Planning Basic Concepts 1. Business Continuity Management: Business Continuity means maintaining the uninterrupted availability of all key business
Business Continuity Planning. Presentation and. Direction
Business Continuity Planning Presentation and Direction Thomas Bronack, president Data Center Assistance Group, Inc. 15180 20 th Avenue Whitestone, NY 11357 Phone: (718) 591-5553 Email: [email protected]
DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS
Appendix L DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS I. GETTING READY A. Obtain written commitment from top management of support for contingency planning objectives. B. Assemble
Interactive-Network Disaster Recovery
Interactive-Network Disaster Recovery BACKGROUND IT systems are vulnerable to a variety of disruptions, ranging from mild (e.g., short-term power outage, disk drive failure) to severe (e.g., terrorism,
Why Should Companies Take a Closer Look at Business Continuity Planning?
whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters
D2-02_01 Disaster Recovery in the modern EPU
CONSEIL INTERNATIONAL DES GRANDS RESEAUX ELECTRIQUES INTERNATIONAL COUNCIL ON LARGE ELECTRIC SYSTEMS http:d2cigre.org STUDY COMMITTEE D2 INFORMATION SYSTEMS AND TELECOMMUNICATION 2015 Colloquium October
NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems
NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems Marianne Swanson NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY 1 Table Of Contents Introduction to NIST SP 800-34
DISASTER RECOVERY 101 3 Steps You Need to Take (Before It s Too Late)
DISASTER RECOVERY 101 3 Steps You Need to Take (Before It s Too Late) Introduction... 4 Disaster Recovery vs. Business Continuity... 4 Why You Need to Read this ebook... 5 Chapter 1: The Risks (aka, The
Planning for Disaster Disaster
Planning for Disaster Ramesh Ramani CISM CGEIT Ramesh Ramani CISM CGEIT Paramount-Dubai Agenda Disaster Management-Introduction Examples BCP and IT Continuity Process of Disaster Management-PDCA Disaster
Information Security Management: Business Continuity Planning. Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt.
Information Security Management: Business Continuity Planning Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt. Overview BCP: Definition BCP: Need for (Why?) BCP: When BCP: Who
HA / DR Jargon Buster High Availability / Disaster Recovery
HA / DR Jargon Buster High Availability / Disaster Recovery Welcome to Maxava s Jargon Buster. Your quick reference guide to Maxava HA and industry technical terms related to High Availability and Disaster
Beyond Disaster Recovery: Why Your Backup Plan Won t Work
Beyond Disaster Recovery: Why Your Backup Plan Won t Work Contents Introduction... 3 The Data Backup Model - Upgraded for 2015... 4 Why Disaster Recovery Isn t Enough... 5 Business Consequences with DR-Only
Best Practices in Disaster Recovery Planning and Testing
Best Practices in Disaster Recovery Planning and Testing axcient.com 2015. Axcient, Inc. All Rights Reserved. 1 Best Practices in Disaster Recovery Planning and Testing Disaster Recovery plans are widely
Subject: Internal Audit of Information Technology Disaster Recovery Plan
RIVERSIDE: AUDIT & ADVISORY SERVICES June 30, 2009 To: Charles Rowley, Associate Vice Chancellor Computing & Communications Subject: Internal Audit of Information Technology Disaster Recovery Plan Ref:
Business Continuity and Disaster Recovery Planning
Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services
Disaster Recovery Planning. Marcus Bendtsen Institutionen för Datavetenskap (IDA) Avdelningen för Databas- och Informationsteknik (ADIT)
Marcus Bendtsen Institutionen för Datavetenskap (IDA) Avdelningen för Databas- och Informationsteknik (ADIT) When disaster strikes and the business continuity plan fails to prevent interruption of business
MHA Consulting. Business Continuity Management 101
0 MHA Consulting Business Continuity Management 101 Presented by: Michael Herrera Brandon Magestro MHA Consulting Agenda MHA Consulting Introduction Business Continuity Management (BCM) Defined 2013 Trends
Ohio Conference for Payroll Professionals Disaster Recovery
Ohio Conference for Payroll Professionals Disaster Recovery Speaker Bruce E. Phipps CPP 2011 APA Payroll Man of the Year Principal Product Manager US Legislative Analyst ORACLE Corporation [email protected]
Building and Maintaining a Business Continuity Program
Building and Maintaining a Business Continuity Program Successful strategies for financial institutions for effective preparation and recovery Table of Contents Introduction...3 This white paper was written
DISASTER RECOVERY PLANNING GUIDE
DISASTER RECOVERY PLANNING GUIDE AN INTRODUCTION TO BUSINESS CONTINUITY PLANNING FOR JD EDWARDS SOFTWARE CUSTOMERS www.wts.com WTS Disaster Recovery Planning Guide Page 1 Introduction This guide will provide
BUSINESS CONTINUITY PLAN OVERVIEW
BUSINESS CONTINUITY PLAN OVERVIEW INTRODUCTION The purpose of this document is to provide Loomis customers with an overview of the company s Business Continuity Plan (BCP). Because of the specific and
Protecting your Enterprise
Understanding Disaster Recovery in California Protecting your Enterprise Session Overview Why do we Prepare What is? How do I analyze (measure) it? What to do with it? How do I communicate it? What does
Virginia Commonwealth University School of Medicine Information Security Standard
Virginia Commonwealth University School of Medicine Information Security Standard Title: Scope: Business Continuity Management Standard for IT Systems This standard is applicable to all VCU School of Medicine
Developing a Business Continuity Plan... More Than Disaster
Developing a Business Continuity Plan..... More Than Disaster Recovery! April 19, 2010 UHY / MMA Business Survival Series Webinar Focus.... Understanding the components of Business Continuity Planning
Ohio Supercomputer Center
Ohio Supercomputer Center IT Business Continuity Planning No: Effective: OSC-13 06/02/2009 Issued By: Kevin Wohlever Director of Supercomputer Operations Published By: Ohio Supercomputer Center Original
Planning for Disaster. Ramesh Ramani CISM CGEIT [email protected] 02 June 2010
Planning for Disaster Ramesh Ramani CISM CGEIT [email protected] 02 June 2010 Agenda Disaster Management-Introduction Examples BCP and IT Continuity Process of Disaster Management-PDCA Disaster Management
Table of Contents... 1
... 1 Chapter 1 Introduction... 4 1.1 Executive Summary... 4 1.2 Goals and Objectives... 5 1.3 Senior Management and Board of Directors Responsibilities... 5 1.4 Business Continuity Planning Processes...
How to Design and Implement a Successful Disaster Recovery Plan
How to Design and Implement a Successful Disaster Recovery Plan Feb. 21 ASA Office-Administrative Section is Sponsored by Today s ASAPro Webinar is Brought to You by the How to Ask a Question Questions
Business Continuity Planning. Donna Curran, Director Audit and Risk Management February, 2014
Business Continuity Planning Donna Curran, Director Audit and Risk Management February, 2014 Agenda Business Continuity Defined The Importance of a Plan Determining the Costs Business Impact Analysis MTO,
Abhi Rathinavelu Foster School of Business
Abhi Rathinavelu Foster School of Business What is Disaster? A disaster is considered any incident or event that results in a major interruption of business operations Major: Earthquake >5.0, Volcanic
Building a strong business continuity plan
Building a strong business continuity plan Protect your clients and firm with a well-planned business continuity plan A solid business continuity plan (BCP) is about more than simply staying in compliance.
Cloud Computing. Chapter 10 Disaster Recovery and Business Continuity and the Cloud
Cloud Computing Chapter 10 Disaster Recovery and Business Continuity and the Cloud Learning Objectives Define and describe business continuity. Define and describe disaster recovery. Describe the benefits
<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP
IT Disaster Recovery Plan Template By Paul Kirvan, CISA, CISSP, FBCI, CBCP Revision History REVISION DATE NAME DESCRIPTION Original 1.0 2 Table of Contents Information Technology Statement
How to write a DISASTER RECOVERY PLAN. To print to A4, print at 75%.
How to write a DISASTER RECOVERY PLAN To print to A4, print at 75%. TABLE OF CONTENTS SUMMARY SUMMARY WHAT IS A DRP AND HOW CAN IT HELP MY COMPANY? CHAPTER PREPARING TO WRITE YOUR DISASTER RECOVERY PLAN
BCP and DR. P K Patel AGM, MoF
BCP and DR P K Patel AGM, MoF Key difference between BS 25999 and ISO 22301 ISO 22301 puts a much greater emphasis on setting the objectives, monitoring performance and metrics aligning BC to top management
STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015
STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 AGENDA: Emergency Management Business Continuity Planning Q & A MONTH DAY, YEAR TITLE OF THE PRESENTATION 2 CANADIAN RED CROSS Disaster
Business Continuity and Disaster Recovery Planning from an Information Technology Perspective
Business Continuity and Disaster Recovery Planning from an Information Technology Perspective Presenter: David Bird, Director of Sales, Business Technology Consultant phone: 215-672-7100 email: [email protected]
Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke
Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke Agenda Key components essential to a FFIEC compliant Business Continuity Plan Recovery Time Objectives & Recovery Point
Company Management System. Business Continuity in SIA
Company Management System Business Continuity in SIA Document code: Classification: Company Project/Service Year Document No. Version Public INDEX 1. INTRODUCTION... 3 2. SIA S BUSINESS CONTINUITY MANAGEMENT
IT Disaster Recovery Plan Template
HOPONE INTERNET CORP IT Disaster Recovery Plan Template Compliments of: Tim Sexton 1/1/2015 An information technology (IT) disaster recovery (DR) plan provides a structured approach for responding to unplanned
Desktop Scenario Self Assessment Exercise Page 1
Page 1 Neil Jarvis Head of IT Security & IT Risk DHL Page 2 From reputation to data loss - how important is business continuity? Neil Jarvis Head of IT Security (EMEA) DHL Logistics IT Security Taking
Disaster Recovery Planning Procedures and Guidelines
Disaster Recovery Planning Procedures and Guidelines A Mandatory Reference for ADS Chapter 545 New Reference: 06/01/2006 Responsible Office: M/DCIO File Name: 545mal_060106_cd44 Information System Security
Overview of how to test a. Business Continuity Plan
Overview of how to test a Business Continuity Plan Prepared by: Thomas Bronack Phone: (718) 591-5553 Email: [email protected] BRP/DRP Test Plan Creation and Exercise Page: 1 Table of Contents BCP/DRP Test
Toronto Public Library Disaster Recovery recommended safeguards and controls
BCE Security Solutions Restricted Attachment 1 Toronto Public Library Disaster Recovery recommended safeguards and controls Final Prepared by: Bell Security Solutions Inc. Professional Services 333 Preston
Disaster Recovery & Business Continuity Related, but NOT the Same! Teri Stokes, Ph.D., Director GXP International
Disaster Recovery & Business Continuity Related, but NOT the Same! Teri Stokes, Ph.D., Director GXP International BCP Definitions Business Continuity Plan: An ongoing process supported by senior management
CISM Certified Information Security Manager
CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective
MARQUIS DISASTER RECOVERY PLAN (DRP)
MARQUIS DISASTER RECOVERY PLAN (DRP) Disaster Recovery is an ongoing process to plan, develop, test and implement changes, processes and procedures supporting the recovery of the critical functions in
PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA
Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand
Module 7. Business Continuity Management
Module 7 Business Continuity Management MODULE 7: BUSINESS CONTINUITY MANAGEMENT Table of Contents Module 7: Business Continuity Management... 1 SECTION 1: OVERVIEW... 7 MODLULE 7: BUSINESS CONTINUITY
Business Continuity Management
Business Continuity Management cliftonlarsonallen.com Introductions Brian Pye CliftonLarsonAllen Senior Manager Business Risk Services group 15 years of experience with Business Continuity Megan Moore
RISK CONTROL. Strategy guide for business continuity planning. Risk Management Guide
Risk Management Guide RISK CONTROL REDUCE RISK. PREVENT LOSS. SAVE LIVES. A FOUR STEP PROCESS: About this planning guide This guide discusses the fundamental process and plan components of Travelers Strategy
PAPER-6 PART-4 OF 5 CA A.RAFEQ, FCA
1 Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-4 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand
How to Prepare for an Emergency: A Disaster and Business Recovery Plan
How to Prepare for an Emergency: A Disaster and Business Recovery Plan Chapter 1: Overview of the Disaster and Business Recovery Plan Purpose: To develop and establish a comprehensive Disaster and Business
Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0
Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0 Unless otherwise stated, these Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies
Certified Disaster Recovery Engineer
Cyber Security Training & Consulting Certified Disaster COURSE OVERVIEW 4 Days 32 CPE Credits $2,500 When a business is hit by a natural disaster, cyber crime or any other disruptive tragedy, how should
State of South Carolina Policy Guidance and Training
State of South Carolina Policy Guidance and Training Policy Workshop All Agencies Business Continuity Management Policy June 2014 Agenda Questions & Follow-Up Policy Workshop Overview & Timeline Policy
Business Continuity Planning for Risk Reduction
Business Continuity Planning for Risk Reduction Ion PLUMB [email protected] Andreea ZAMFIR [email protected] Delia TUDOR [email protected] Faculty of Management Academy of Economic Studies
NCUA LETTER TO CREDIT UNIONS
NCUA LETTER TO CREDIT UNIONS NATIONAL CREDIT UNION ADMINISTRATION 1775 Duke Street, Alexandria, VA 22314 DATE: December 2001 LETTER NO.: 01-CU-21 TO: SUBJ: ENCL: All Federally Insured Credit Unions Disaster
BUSINESS CONTINUITY PLAN
How to Develop a BUSINESS CONTINUITY PLAN To print to A4, print at 75%. TABLE OF CONTENTS SUMMARY SUMMARY WHAT IS A BUSINESS CONTINUITY PLAN? CHAPTER PREPARING TO WRITE YOUR BUSINESS CONTINUITY PLAN CHAPTER
Disaster Recovery. Hendry Taylor Tayori Limited
Disaster Recovery Hendry Taylor Tayori Limited Agenda What is Business Continuity planning (BCP) What is Disaster Recovery (DR) and Disaster Recovery Planning (DRP) Overview Lifecycle Analysis Plan design
Disaster Prevention and Recovery for School System Technology
The Optimal Reference Guide: Disaster Prevention and Recovery for School System Technology Extraordinary insight into today s education topics Glynn D. Ligon, Ph.D., ESP Solutions Group Evangelina Mangino,
Version 8.0 2014 Copyright Janco Associates, Inc. - http://www.e-janco.com Page 1
Version 8.0 2014 Copyright Janco Associates, Inc. - http://www.e-janco.com Page 1 Table of Contents 1 1.0 Plan Introduction... 4 1.1 Mission and Objectives... 5 Compliance... 5 ISO Compliance Process...
Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION
Federal Financial Institutions Examination Council FFIEC Business Continuity Planning MARCH 2003 MARCH 2008 BCP IT EXAMINATION H ANDBOOK TABLE OF CONTENTS INTRODUCTION... 1 BOARD AND SENIOR MANAGEMENT
How To Back Up A Virtual Machine
2010 Symantec Disaster Recovery Study Global Results Methodology Applied Research performed survey 1,700 enterprises worldwide 5,000 employees or more Cross-industry 2 Key Findings Virtualization and Cloud
Business Continuity Planning for Schools, Departments & Support Units
Business Continuity Planning for Schools, Departments & Support Units 1 What is Business Continuity Planning? Examples Planning for an adverse, major or catastrophic event that would cause a disruption
Q uick Guide to Disaster Recovery Planning An ITtoolkit.com White Paper
This quick reference guide provides an introductory overview of the key principles and issues involved in IT related disaster recovery planning, including needs evaluation, goals, objectives and related
Technology Infrastructure Services
LOB #303: DISASTER RECOVERY Technology Infrastructure Services Purpose Disaster Recovery (DR) for IT is a capability to restore enterprise-wide technology infrastructure, applications and data that are
Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK
Federal Financial Institutions Examination Council FFIEC Business Continuity Planning BCP FEBRUARY 2015 IT EXAMINATION H ANDBOOK Table of Contents Introduction 1 Board and Senior Management Responsibilities
Unit Guide to Business Continuity/Resumption Planning
Unit Guide to Business Continuity/Resumption Planning (February 2009) Revised June 2011 Executive Summary... 3 Purpose and Scope for a Unit Business Continuity Plan(BCP)... 3 Resumption Planning... 4 Assumptions
The Disaster Recovery Maturity Framework
The Disaster Recovery Maturity Framework A guide for understanding and improving your company s resiliency www.axcient.com Climbing The Recovery Maturity Curve Businesses are critically reliant upon IT
CERTIFIED DISASTER RECOVERY ENGINEER
CERTIFIED DISASTER RECOVERY ENGINEER KEY DATA COURSE OVERVIEW ACCREDITATION Course Title: C)DRE Duration: 4 days CPE Credits: 32 Class Format Options: Instructor-led classroom Live Online Training Computer
Disaster Recovery Plan Checklist
Disaster Recovery Plan Checklist Your guide for setting up or updating a Disaster Recovery Plan for your business. ArcSource Disaster Recovery Plan Checklist 1. Compile Your Internal Contacts Information
What is Business Continuity Planning (BCP) / Disaster Recovery Plan(DRP)?
Workshop on System Audit of Banks BCP Workshop on System Audit of Banks What is Business Continuity Planning (BCP) / Disaster Recovery Plan(DRP)? - Preparedness of an organisation to ensure continuity,
IF DISASTER STRIKES IS YOUR BUSINESS READY?
1 IF DISASTER STRIKES IS YOUR BUSINESS READY? DISASTER RECOVERY and BUSINESS CONTINUITY: WHAT YOU NEED TO KNOW Realize the Power of Technology Many business owners put off disaster planning, perhaps thinking
Proposal for Business Continuity Plan and Management Review 6 August 2008
Proposal for Business Continuity Plan and Management Review 6 August 2008 2008/8/6 Contents About Newton IT / Quality of our services. BCM & BS25999 Overview 2. BCM Development in line with BS25999 3.
Offsite Disaster Recovery Plan
1 Offsite Disaster Recovery Plan Offsite Disaster Recovery Plan Presented By: Natan Verkhovsky President Disty Portal Inc. 2 Offsite Disaster Recovery Plan Introduction This document is a comprehensive
The 9 Ugliest Mistakes Made with Data Backup and How to Avoid Them
The 9 Ugliest Mistakes Made with Data Backup and How to Avoid Them If your data is important to your business and you cannot afford to have your operations halted for days even weeks due to data loss or
