Business Continuity and Disaster Recovery Planning

Size: px
Start display at page:

Download "Business Continuity and Disaster Recovery Planning"

Transcription

1 Business Continuity and Disaster Recovery Planning 1

2 More than 20% of all small medium sized businesses suffer a major disaster every 5 years. Almost all that lose their data for 10 days or more file for bankruptcy within a year.

3 Project initiation steps Recovery and continuity planning requirements Business impact analysis Selecting, developing, and implementing disaster and continuity plans Backup and offsite facilities Types of drills and tests

4 Any disruptive event (natural or man-made) that interrupts normal system in such a significant way that a considerable and coordinated effort is required to achieve a recovery.

5 Geological: earthquakes, volcanoes, lahars, tsunamis, landslides, and sinkholes Meteorological: hurricanes, tornados, wind storms, hail, ice storms, snow storms, rainstorms, and lightning

6 Other: avalanches, fires, floods, meteors and meteorites, and solar storms Health: widespread illnesses, quarantines, and pandemics (remember Anthrax? What will you do if they find Anthrax in the mailroom?)

7 Labor: strikes, walkouts, and slowdowns that disrupt services and supplies Social-political: war, terrorism, sabotage, vandalism, civil unrest, protests, demonstrations, cyber attacks, and blockades

8 Materials: fires, hazardous materials spills Utilities: power failures, communications outages, water supply shortages, fuel shortages, and radioactive fallout from power plant accidents

9 Damage to facilities and equipment Utility outages Communication outages Transportation/delivery delays Personnel unavailable (or unable to travel) to work

10 Remember CIA? Which of these security services (security pillars) does business continuity and disaster recovery planning support?

11 Disasters are a fact of life Personnel need to be trained and prepared for their occurrence

12 Plan Type Business Resumption Plan Continuity of Operations Plan (COOP) IT Contingency Plan (ITCP) Crisis Communications Plan Cyber Incident Response Plan Disaster Recovery Plan (DRP) Description Focus on necessary business processes instead of IT procedures Establishes management and headquarters after a disaster. Outlines roles and authorities, orders of succession, and individual role tasks. Plan for restoring systems, networks, major apps after a disruption at the original facility. Provides procedures for disseminating internal and external communications; means to provide critical status information and control rumors. Provides procedures for mitigating and correcting a cyber attack addresses mitigation and isolation of affected systems, clean up, and loss minimization How to recover IT mechanisms after a disaster. Focuses on disasters that require IT processing to take place at another facility.

13 BCP and DRP are two distinct, but related, plans Business Continuity Plan (BCP) - ensures that the business will continue to operate before (includes a focus on prevention), during, and after an event. A strategic (long-term) plan. Identifies alternate personnel, equipment, and facilities

14 BCP and DRP are two distinct, but related, plans Disaster Recovery Plan (DRP) Tactical, shorter-term plan that focuses on the immediate response and recovery of critical IT systems during a disruption. Contains procedures for emergency response (assessment, salvage, repair, and eventual restoration of damaged facilities and systems)

15 NIST : Contingency Planning Guide for Information Technology Systems. Seven step process for BCP and DRP projects.

16 ISO 17799: Code of Practice for Information Security Management. Section 14 addresses business continuity management. BS25999: Code of Practice for Business Continuity Management.

17 NFPA 1600: Standard on Disaster / Emergency Management and Business Continuity Programs. NFPA 1620: The Recommended Practice for Pre-Incident Planning. HIPAA: Requires a documented and tested disaster recovery plan.

18 Cheaper cyber insurance (reduced risk from long term outages) Market advantage Process improvements Improved organizational maturity

19 (ISC)2 Project initiation Business Impact Assessment Recovery strategy Plan design and development Implementation Testing Continual maintenance

20 Pre-planning Activities/Policy Integrate law and regulations Define the scope, goals, and roles Choose project team members Develop project plan and project charter Management approval BIA Identify critical functions (criticality analysis and impact statements) and resources Calculate MTD (Maximum Tolerable Downtime) and other key metrics (RTO, RPO) Identify threats Calculate risks Identify backup solutions Identify Preventive Controls Implement controls Mitigate risk

21 Develop Recovery Strategies Business process Facility Supply and technology User and user environment Data Document procedures, recovery solutions, roles and tasks, and emergency response Develop BCP Exercise test drill Test plan Improve plan Train employees

22 Maintain BCP Integrate into change control process Assign responsibility Update plan Distribute after updating

23 Identify a business continuity coordinator to lead BCP team Develop team: Business units, senior management, IT dept. Security dept. Communications department, legal department Develop a project plan Gain management approval

24 Formal method for determining how a disruption to the organization s IT systems will impact the mission. Consists of 2 processes: Identification of critical assets Comprehensive risk assessment

25 Steps Description Identify critical assets IT assets that are mission-essential and must be recovered first Identify interdependencies Conduct BCP/DRP-focused Risk Assessment Determine Maximum Tolerable Downtime (MTD) - the maximum time each business process can be inoperative before significant damage or long-term viability is threatened MTD=RTO+WRT Identify risks to each asset Conduct vulnerability analysis Statements of Impact Consists of two metrics: Recovery Time Objective (RTO) - maximum time allowed to recover business or IT systems (from disaster onset to resumption of businesses processes) Work Recovery Time (WRT) time required to configure a recovered system

26 Term Recovery Point Objective (RPO) Mean Time between Failures (MBTF) Mean Time to Repair (MTTR) Minimum Operating Requirements Definition Level of data/work loss or system inaccessibility (measured in time) resulting from a disaster that an organization can withstand counted backwards from onset of disaster Average amount of time a system or device is runs before it fails Length of time to recover a failed device or system Minimum environmental and connectivity requirements required to operate

27 RPO Technologies 8 14 days New equipment, data recovery from backup 4 7 days Cold systems, data recovery from backup 2 3 days Warm systems, data recovery from backup hours Warm systems, recovery from high speed 6 12 hours Hot systems, recovery from high speed backup media 3 6 hours Hot systems, data replication 1 3 hours Clustering, data replication <1 hour Clustering, near real time data replication Adapted from CISSP Guide to Security Essentials

28 For each process, describe the impact on the rest of the organization if the process is incapacitated Examples Inability to process payments Inability to produce invoices Inability to access customer data for support purposes

29 Fortification of facility Redundancy (clustered servers, drives, etc.) Power lines Fire suppression/detection Redundant vendor support Insurance UPS/generators Data backup technologies Media protection safeguards Inventory

30 5 Steps that we ll discuss: 1. Business process recovery 2. Facility recovery 3. Supply and technology recovery 4. User environment recovery 5. Data recovery

31 Define critical steps of a company s processes Required roles Required resources Input and output mechanisms Workflow steps Time for completion Interfaces with other processes

32 3 types of disruptions: Nondisasters disruption in service due to a device malfunction or failure Disasters An event causes the loss of the entire facility for a day or longer Catastrophes major disruption that destroys the facility, requiring moving operations to offsite facility

33 Type of offsite facility Advantages Disadvantages Hot Site fully configured with equipment and lines. Data retrieved and loaded from backup site Cold Site supplies basic environment (electrical, AC, plumbing) but no systems can also just be a reciprocal agreement Warm Site anywhere in between. High availability - can be immediately ready or within matter of hours Lowest availability longest restoration time Less expensive Expensive!!! Least Expensive Not immediately available (requires some setup and restoration Operational Testing not available Note: For CISSP exam purposes a hot site here is a subscription service not owned by the company!!!

34 Redundant Sites: Redundant site: Site is equipped and configured exactly like the production site data data can be streamed live Rolling hot site: Large truck or trailer is turned into a work area Multiple processing centers Distributed through multiple locations

35 Recovery team must be able to recreate the environment Hardware? Software? Configuration manuals? Where are your recovery plans stored? How long will it take for new equipment to arrive many have requirements within 24 hours (do you have a contract with your vendor that provides for this?) Backups do you have apps and O/Ss to support your restored data (remember that we covered types of backups last week)? Ensure that there are at least two copies available of a company s operating system software and critical apps one offsite and one offsite test these to ensure you can restore!!!!!

36 Employee Notification develop a Crisis Communications Plan Call Tree used to rapidly communicate information throughout an organization by assigning the responsibility for contacting employees to other employees (i.e. Margaret calls Bob and 9 other people, Bob then calls 10 people, who each call 10 people, etc.) Identify users who need to return to work and how they need to work Can you return to paper processes? Can you automate processes?

37 Covered last week (all in how the archive bit is handled remember?) Full Backup every file is backed up and archive bit is removed Differential Backup only files with the archive bit are backed up, but the archive bit is left on the file (so backup is cumulative until the full backup runs and removes the bits necessitating restoring the last full backup and last differential) Incremental Backup - only files with the archive bit are backed up, and the archive bit is removed from the file (necessitates layering the incremental tapes in order over the full backup during restoration)

38 Disk shadowing online backup storage (disk mirroring is a one-to-one relationship, disk shadowing uses multiple drives to create shadow sets Electronic vaulting makes copies of files as they are modified and periodically transmits them to offsite backup storage (common in banks) Remote journaling includes only moving the deltas that have taken place

39 Close enough or provision to access media? Far enough away to withstand regional disaster? Closed on weekends or holidays? Commensurate security controls to production facility? Availability of bonded transport system (Iron Mountain)? Does data need to be encrypted if leaving the production facility?

40 Method of transferring risk Cyberinsurance new type of insurance that covers DoS, malware, privacy-related lawsuits, downstream liability, etc. Business interruption insurance covers loss of revenue in the event something bad happens

41 BCP coordinator needs to define teams: Damage assessment team Determines the cause of the disaster, potential for further damage, and whether or not to activate the BCP Restoration team responsible for getting the alternate site into a working and functioning environment Salvage Team responsible for starting the recovery of the original site Media relations team Security team Telecommunications team Reconstitution phase - when a company moves back to its original site or new site

42 Test Type DRP Review Checklist (consistency) Structured Walkthrough /Tabletop Simulation Test/Walkthrough Drill Parallel Processing Partial and Complete Business Interruption Purpose Most basic reading the DRP from start to finish by the team that developed it to ensure that it is complete Often performed concurrently with a structured walkthrough or tabletop test lists all necessary components required for recovery Group walks through the process on paper Teams actually carry out the recovery process (disaster is simulated) scope of simulation can vary Recovery of crucial processing components at an alternate computing facility and then restoration from a previous backup without disrupting production) Risky! Processing is stopped at the primary location and transitioned to the alternate location

43 At least annually!! Identify test objectives and scope Identify Lessons Learned Revise the plan after testing (I look for lessons learned as an audit item) Note: BCPs are updated whenever there are significant changes to the organization

44 Determine how frequently (at least annually) Good idea to train different roles more regularly Train so that everyone knows the initial steps and where to find the plans First aid and CPR Starting emergency power Call tree

45 Plans updated whenever there is a change to the environment Plans reviewed for updates at least annually if no changes Track and document all planned changes and implement a formal approval process for all substantial changes Changes must be auditable!

46 NIST SP (now Rev. 1) ISO/IEC draft - part of ISO series addresses Information and Communications Technology (ICT) and Information Security Management System (ISMS) BS (2 parts) British business continuity standard BCI (Business Continuity Institute) 6 step Good Practice Guidelines

47 Lack of management support No coordination with vendors Lack of testing Lack of prioritization Lack of training and awareness

48 Cloud environments complicate Disaster Recovery Cloud environments can be a part of an organization s DR process Must plan on how personnel will access the cloud

49

50

51 Which of the following is the number one priority of all BCP and DRPs? A. The elimination of potential outages B. The reduction of potential outages C. Protection and welfare of employees D. The minimization of potential outages

52 Which of the following is the number one priority of all BCP and DRPs? A. The elimination of potential outages B. The reduction of potential outages C. Protection and welfare of employees D. The minimization of potential outages

53 Maximum Tolerable Downtime (MTD) comprises which two metrics? A. Recovery Point Objective (RPO) and Work Recovery Time (WRT)? B. Recovery Point Objective (RPO) and Mean Time to Repair (MTTR)? C. Recovery Time Objective (RTO) and Mean Time to Repair (MTTR)? D. Recovery Time Objective (RTO) and Work Recovery Time (WRT)?

54 Maximum Tolerable Downtime (MTD) comprises which two metrics? A. Recovery Point Objective (RPO) and Work Recovery Time (WRT)? B. Recovery Point Objective (RPO) and Mean Time to Repair (MTTR)? C. Recovery Time Objective (RTO) and Mean Time to Repair (MTTR)? D. Recovery Time Objective (RTO) and Work Recovery Time (WRT)?

55 An example of risk transference is: A. Offsite storage B. Insurance C. Maintaining spare equipment offsite D. Fire suppression

56 An example of risk transference is: A. Offsite storage B. Insurance C. Maintaining spare equipment offsite D. Fire suppression

57 What is one of the first steps in identifying a BCP? A. Identify backup solution B. Decide whether the company needs to perform a walk-through, parallel, or simulation test C. Perform a business impact analysis D. Develop a business resumption plan.

58 What is one of the first steps in identifying a BCP? A. Identify backup solution B. Decide whether the company needs to perform a walk-through, parallel, or simulation test C. Perform a business impact analysis D. Develop a business resumption plan.

59 Which plan details the steps required to restore normal business operations/mission after recovery from a disruptive event? A. Business Continuity Plan (BCP) B. Business Resumption Plan (BRP) C. Continuity of Operations Plan (COOP) D. Occupant Emergency Plan (OEP)

60 Which plan details the steps required to restore normal business operations/mission after recovery from a disruptive event? A. Business Continuity Plan (BCP) B. Business Resumption Plan (BRP) C. Continuity of Operations Plan (COOP) D. Occupant Emergency Plan (OEP)

61 Which draft Business Continuity guideline ensures continuity of Information and Communications Technology (ICT) as a part of the organization's Information Security Management System (ISMS)? A. BCI B. BS-7799 C. ISO/IEC D. NIST SP

62 Which draft Business Continuity guideline ensures continuity of Information and Communications Technology (ICT) as a part of the organization's Information Security Management System (ISMS)? A. BCI B. BS-7799 C. ISO/IEC D. NIST SP

63 Which of the following best describes the difference between an Information Systems Contingency Plan and Disaster Recovery Plan? A. Information Systems Contingency Plan procedures are developed for recovery of the system regardless of site or location after a non-disaster B. Disaster Recovery Plan procedures are developed for recovery of the system regardless of site or location C. Disaster Recovery Plan can be activated at the system's current location or at an alternate site D. Information Systems Contingency Plan is developed for disasters that require restoration of IT systems at an alternate site.

64 Which of the following best describes the difference between an Information Systems Contingency Plan and Disaster Recovery Plan? A. Information Systems Contingency Plan procedures are developed for recovery of the system regardless of site or location after a non-disaster B. Disaster Recovery Plan procedures are developed for recovery of the system regardless of site or location C. Disaster Recovery Plan can be activated at the system's current location or at an alternate site D. Information Systems Contingency Plan is developed for disasters that require restoration of IT systems at an alternate site.

65 What is the primary objective of a disaster recovery plan? a. To recover critical processes in a timely manner b. Manage public relations after a crisis c. To minimize financial loss during normal operations outage d. Re-design the security infrastructure of the organization after an emergency

66 What is the primary objective of a disaster recovery plan? a. To recover critical processes in a timely manner b. Manage public relations after a crisis c. To minimize financial loss during normal operations outage d. Re-design the security infrastructure of the organization after an emergency

67 A critical company asset would most likely have which of the following MTD values? A. Minutes to hours B. Days C. Weeks D. Months

68 A critical company asset would most likely have which of the following MTD values? A. Minutes to hours B. Days C. Weeks D. Months

69

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain 1. What is the most common planned performance duration for a continuity of operations plan (COOP)? A. 30 days B. 60 days C. 90 days D. It depends on the severity of a disaster. 2. What is the business

More information

Domain 3 Business Continuity and Disaster Recovery Planning

Domain 3 Business Continuity and Disaster Recovery Planning Domain 3 Business Continuity and Disaster Recovery Planning Steps (ISC) 2 steps [Har10] Project initiation Business Impact Analysis (BIA) Recovery strategy Plan design and development Implementation Testing

More information

CISSP Common Body of Knowledge: Business Continuity & Disaster Recovery Planning Domain Version: 5.9.2

CISSP Common Body of Knowledge: Business Continuity & Disaster Recovery Planning Domain Version: 5.9.2 CISSP Common Body of Knowledge: Business Continuity & Disaster Recovery Planning Domain Version: 5.9.2 CISSP Common Body of Knowledge Review by Alfred Ouyang is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning Business Continuity Planning and Disaster Recovery Planning Ed Crowley IAM/IEM 1 ISC 2 Key Areas of Knowledge Understand business continuity requirements 1. Develop and document project scope and plan

More information

Business Continuity Plan

Business Continuity Plan Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions

More information

Temple university. Auditing a business continuity management BCM. November, 2015

Temple university. Auditing a business continuity management BCM. November, 2015 Temple university Auditing a business continuity management BCM November, 2015 Auditing BCM Agenda 1. Introduction 2. Definitions 3. Standards 4. BCM key elements IT Governance class - IT audit program

More information

Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM

Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM Business Continuity Planning and Disaster Recovery Planning Ed Crowley IAM/IEM 1 Goals Compare and contrast aspects of business continuity Execute disaster recovery plans and procedures 2 Topics Business

More information

Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).

Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP). Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP). Ed Fortin President Fortin Consulting Paul Godden Consultant & Quotation Author Friday 24 th February 2012 Business Continuity Planning

More information

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC Assessing Your Disaster Recovery Plans Gregory H. Soule, CPA, CISA, CISSP, CFE Andrews Hooper Pavlik PLC Andrews Hooper Pavlik PLC Agenda Business Continuity Concepts Impact Analysis Risk Assessment Risk

More information

Business Continuity Glossary

Business Continuity Glossary Developed In Conjuction with Business Continuity Glossary ACTIVATION: The implementation of business continuity capabilities, procedures, activities, and plans in response to an emergency or disaster declaration;

More information

Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP)

Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP) Preface Computer systems are the core tool of today s business and are vital to every business from the smallest to giant organizations. Money transactions, customer service are just simple examples. Despite

More information

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan EMERGENCY PREPAREDNESS PLAN Business Continuity Plan GIS Bankers Insurance Group Powered by DISASTER PREPAREDNESS Implementation Small Business Guide to Business Continuity Planning Surviving a Catastrophic

More information

Contingency Planning Guide

Contingency Planning Guide Institutional and Sector Modernisation Facility ICT Standards Contingency Planning Guide Document number: ISMF-ICT/3.03 - ICT Security/MISP/SD/CP Version: 1.20 Project Funded by the European Union 1 Document

More information

Western Intergovernmental Audit Forum

Western Intergovernmental Audit Forum Western Intergovernmental Audit Forum Business Continuity & Disaster Recovery Planning September 12, 2013 Presented by: City of Phoenix City Auditor Department Aaron Cook, Sr Internal Auditor IT Audit

More information

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning The world has experienced a great deal of natural and man-made upheaval and destruction in the past few years, including tornadoes,

More information

Business Continuity and the Cloud. Aaron Shaver US Signal, Solution Architect

Business Continuity and the Cloud. Aaron Shaver US Signal, Solution Architect Business Continuity and the Cloud Aaron Shaver US Signal, Solution Architect Overview What is BC/DR? Why should businesses have a strategy? Why do many business choose not to? How does the cloud change

More information

Security+ Guide to Network Security Fundamentals, Fourth Edition. Chapter 13 Business Continuity

Security+ Guide to Network Security Fundamentals, Fourth Edition. Chapter 13 Business Continuity Security+ Guide to Network Security Fundamentals, Fourth Edition Chapter 13 Business Continuity Objectives Define environmental controls Describe the components of redundancy planning List disaster recovery

More information

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning 4 Business Continuity Planning and Disaster Recovery Planning Basic Concepts 1. Business Continuity Management: Business Continuity means maintaining the uninterrupted availability of all key business

More information

Business Continuity Planning. Presentation and. Direction

Business Continuity Planning. Presentation and. Direction Business Continuity Planning Presentation and Direction Thomas Bronack, president Data Center Assistance Group, Inc. 15180 20 th Avenue Whitestone, NY 11357 Phone: (718) 591-5553 Email: [email protected]

More information

DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS

DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS Appendix L DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS I. GETTING READY A. Obtain written commitment from top management of support for contingency planning objectives. B. Assemble

More information

Interactive-Network Disaster Recovery

Interactive-Network Disaster Recovery Interactive-Network Disaster Recovery BACKGROUND IT systems are vulnerable to a variety of disruptions, ranging from mild (e.g., short-term power outage, disk drive failure) to severe (e.g., terrorism,

More information

Why Should Companies Take a Closer Look at Business Continuity Planning?

Why Should Companies Take a Closer Look at Business Continuity Planning? whitepaper Why Should Companies Take a Closer Look at Business Continuity Planning? How Datalink s business continuity and disaster recovery solutions can help organizations lessen the impact of disasters

More information

D2-02_01 Disaster Recovery in the modern EPU

D2-02_01 Disaster Recovery in the modern EPU CONSEIL INTERNATIONAL DES GRANDS RESEAUX ELECTRIQUES INTERNATIONAL COUNCIL ON LARGE ELECTRIC SYSTEMS http:d2cigre.org STUDY COMMITTEE D2 INFORMATION SYSTEMS AND TELECOMMUNICATION 2015 Colloquium October

More information

NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems

NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems NIST SP 800-34, Revision 1 Contingency Planning Guide for Federal Information Systems Marianne Swanson NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY 1 Table Of Contents Introduction to NIST SP 800-34

More information

DISASTER RECOVERY 101 3 Steps You Need to Take (Before It s Too Late)

DISASTER RECOVERY 101 3 Steps You Need to Take (Before It s Too Late) DISASTER RECOVERY 101 3 Steps You Need to Take (Before It s Too Late) Introduction... 4 Disaster Recovery vs. Business Continuity... 4 Why You Need to Read this ebook... 5 Chapter 1: The Risks (aka, The

More information

Planning for Disaster Disaster

Planning for Disaster Disaster Planning for Disaster Ramesh Ramani CISM CGEIT Ramesh Ramani CISM CGEIT Paramount-Dubai Agenda Disaster Management-Introduction Examples BCP and IT Continuity Process of Disaster Management-PDCA Disaster

More information

Information Security Management: Business Continuity Planning. Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt.

Information Security Management: Business Continuity Planning. Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt. Information Security Management: Business Continuity Planning Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt. Overview BCP: Definition BCP: Need for (Why?) BCP: When BCP: Who

More information

HA / DR Jargon Buster High Availability / Disaster Recovery

HA / DR Jargon Buster High Availability / Disaster Recovery HA / DR Jargon Buster High Availability / Disaster Recovery Welcome to Maxava s Jargon Buster. Your quick reference guide to Maxava HA and industry technical terms related to High Availability and Disaster

More information

Beyond Disaster Recovery: Why Your Backup Plan Won t Work

Beyond Disaster Recovery: Why Your Backup Plan Won t Work Beyond Disaster Recovery: Why Your Backup Plan Won t Work Contents Introduction... 3 The Data Backup Model - Upgraded for 2015... 4 Why Disaster Recovery Isn t Enough... 5 Business Consequences with DR-Only

More information

Best Practices in Disaster Recovery Planning and Testing

Best Practices in Disaster Recovery Planning and Testing Best Practices in Disaster Recovery Planning and Testing axcient.com 2015. Axcient, Inc. All Rights Reserved. 1 Best Practices in Disaster Recovery Planning and Testing Disaster Recovery plans are widely

More information

Subject: Internal Audit of Information Technology Disaster Recovery Plan

Subject: Internal Audit of Information Technology Disaster Recovery Plan RIVERSIDE: AUDIT & ADVISORY SERVICES June 30, 2009 To: Charles Rowley, Associate Vice Chancellor Computing & Communications Subject: Internal Audit of Information Technology Disaster Recovery Plan Ref:

More information

Business Continuity and Disaster Recovery Planning

Business Continuity and Disaster Recovery Planning Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services

More information

Disaster Recovery Planning. Marcus Bendtsen Institutionen för Datavetenskap (IDA) Avdelningen för Databas- och Informationsteknik (ADIT)

Disaster Recovery Planning. Marcus Bendtsen Institutionen för Datavetenskap (IDA) Avdelningen för Databas- och Informationsteknik (ADIT) Marcus Bendtsen Institutionen för Datavetenskap (IDA) Avdelningen för Databas- och Informationsteknik (ADIT) When disaster strikes and the business continuity plan fails to prevent interruption of business

More information

MHA Consulting. Business Continuity Management 101

MHA Consulting. Business Continuity Management 101 0 MHA Consulting Business Continuity Management 101 Presented by: Michael Herrera Brandon Magestro MHA Consulting Agenda MHA Consulting Introduction Business Continuity Management (BCM) Defined 2013 Trends

More information

Ohio Conference for Payroll Professionals Disaster Recovery

Ohio Conference for Payroll Professionals Disaster Recovery Ohio Conference for Payroll Professionals Disaster Recovery Speaker Bruce E. Phipps CPP 2011 APA Payroll Man of the Year Principal Product Manager US Legislative Analyst ORACLE Corporation [email protected]

More information

Building and Maintaining a Business Continuity Program

Building and Maintaining a Business Continuity Program Building and Maintaining a Business Continuity Program Successful strategies for financial institutions for effective preparation and recovery Table of Contents Introduction...3 This white paper was written

More information

DISASTER RECOVERY PLANNING GUIDE

DISASTER RECOVERY PLANNING GUIDE DISASTER RECOVERY PLANNING GUIDE AN INTRODUCTION TO BUSINESS CONTINUITY PLANNING FOR JD EDWARDS SOFTWARE CUSTOMERS www.wts.com WTS Disaster Recovery Planning Guide Page 1 Introduction This guide will provide

More information

BUSINESS CONTINUITY PLAN OVERVIEW

BUSINESS CONTINUITY PLAN OVERVIEW BUSINESS CONTINUITY PLAN OVERVIEW INTRODUCTION The purpose of this document is to provide Loomis customers with an overview of the company s Business Continuity Plan (BCP). Because of the specific and

More information

Protecting your Enterprise

Protecting your Enterprise Understanding Disaster Recovery in California Protecting your Enterprise Session Overview Why do we Prepare What is? How do I analyze (measure) it? What to do with it? How do I communicate it? What does

More information

Virginia Commonwealth University School of Medicine Information Security Standard

Virginia Commonwealth University School of Medicine Information Security Standard Virginia Commonwealth University School of Medicine Information Security Standard Title: Scope: Business Continuity Management Standard for IT Systems This standard is applicable to all VCU School of Medicine

More information

Developing a Business Continuity Plan... More Than Disaster

Developing a Business Continuity Plan... More Than Disaster Developing a Business Continuity Plan..... More Than Disaster Recovery! April 19, 2010 UHY / MMA Business Survival Series Webinar Focus.... Understanding the components of Business Continuity Planning

More information

Ohio Supercomputer Center

Ohio Supercomputer Center Ohio Supercomputer Center IT Business Continuity Planning No: Effective: OSC-13 06/02/2009 Issued By: Kevin Wohlever Director of Supercomputer Operations Published By: Ohio Supercomputer Center Original

More information

Planning for Disaster. Ramesh Ramani CISM CGEIT [email protected] 02 June 2010

Planning for Disaster. Ramesh Ramani CISM CGEIT ramani@pcsuae.com 02 June 2010 Planning for Disaster Ramesh Ramani CISM CGEIT [email protected] 02 June 2010 Agenda Disaster Management-Introduction Examples BCP and IT Continuity Process of Disaster Management-PDCA Disaster Management

More information

Table of Contents... 1

Table of Contents... 1 ... 1 Chapter 1 Introduction... 4 1.1 Executive Summary... 4 1.2 Goals and Objectives... 5 1.3 Senior Management and Board of Directors Responsibilities... 5 1.4 Business Continuity Planning Processes...

More information

How to Design and Implement a Successful Disaster Recovery Plan

How to Design and Implement a Successful Disaster Recovery Plan How to Design and Implement a Successful Disaster Recovery Plan Feb. 21 ASA Office-Administrative Section is Sponsored by Today s ASAPro Webinar is Brought to You by the How to Ask a Question Questions

More information

Business Continuity Planning. Donna Curran, Director Audit and Risk Management February, 2014

Business Continuity Planning. Donna Curran, Director Audit and Risk Management February, 2014 Business Continuity Planning Donna Curran, Director Audit and Risk Management February, 2014 Agenda Business Continuity Defined The Importance of a Plan Determining the Costs Business Impact Analysis MTO,

More information

Abhi Rathinavelu Foster School of Business

Abhi Rathinavelu Foster School of Business Abhi Rathinavelu Foster School of Business What is Disaster? A disaster is considered any incident or event that results in a major interruption of business operations Major: Earthquake >5.0, Volcanic

More information

Building a strong business continuity plan

Building a strong business continuity plan Building a strong business continuity plan Protect your clients and firm with a well-planned business continuity plan A solid business continuity plan (BCP) is about more than simply staying in compliance.

More information

Cloud Computing. Chapter 10 Disaster Recovery and Business Continuity and the Cloud

Cloud Computing. Chapter 10 Disaster Recovery and Business Continuity and the Cloud Cloud Computing Chapter 10 Disaster Recovery and Business Continuity and the Cloud Learning Objectives Define and describe business continuity. Define and describe disaster recovery. Describe the benefits

More information

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP IT Disaster Recovery Plan Template By Paul Kirvan, CISA, CISSP, FBCI, CBCP Revision History REVISION DATE NAME DESCRIPTION Original 1.0 2 Table of Contents Information Technology Statement

More information

How to write a DISASTER RECOVERY PLAN. To print to A4, print at 75%.

How to write a DISASTER RECOVERY PLAN. To print to A4, print at 75%. How to write a DISASTER RECOVERY PLAN To print to A4, print at 75%. TABLE OF CONTENTS SUMMARY SUMMARY WHAT IS A DRP AND HOW CAN IT HELP MY COMPANY? CHAPTER PREPARING TO WRITE YOUR DISASTER RECOVERY PLAN

More information

BCP and DR. P K Patel AGM, MoF

BCP and DR. P K Patel AGM, MoF BCP and DR P K Patel AGM, MoF Key difference between BS 25999 and ISO 22301 ISO 22301 puts a much greater emphasis on setting the objectives, monitoring performance and metrics aligning BC to top management

More information

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY 27 2015 AGENDA: Emergency Management Business Continuity Planning Q & A MONTH DAY, YEAR TITLE OF THE PRESENTATION 2 CANADIAN RED CROSS Disaster

More information

Business Continuity and Disaster Recovery Planning from an Information Technology Perspective

Business Continuity and Disaster Recovery Planning from an Information Technology Perspective Business Continuity and Disaster Recovery Planning from an Information Technology Perspective Presenter: David Bird, Director of Sales, Business Technology Consultant phone: 215-672-7100 email: [email protected]

More information

Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke

Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke Agenda Key components essential to a FFIEC compliant Business Continuity Plan Recovery Time Objectives & Recovery Point

More information

Company Management System. Business Continuity in SIA

Company Management System. Business Continuity in SIA Company Management System Business Continuity in SIA Document code: Classification: Company Project/Service Year Document No. Version Public INDEX 1. INTRODUCTION... 3 2. SIA S BUSINESS CONTINUITY MANAGEMENT

More information

IT Disaster Recovery Plan Template

IT Disaster Recovery Plan Template HOPONE INTERNET CORP IT Disaster Recovery Plan Template Compliments of: Tim Sexton 1/1/2015 An information technology (IT) disaster recovery (DR) plan provides a structured approach for responding to unplanned

More information

Desktop Scenario Self Assessment Exercise Page 1

Desktop Scenario Self Assessment Exercise Page 1 Page 1 Neil Jarvis Head of IT Security & IT Risk DHL Page 2 From reputation to data loss - how important is business continuity? Neil Jarvis Head of IT Security (EMEA) DHL Logistics IT Security Taking

More information

Disaster Recovery Planning Procedures and Guidelines

Disaster Recovery Planning Procedures and Guidelines Disaster Recovery Planning Procedures and Guidelines A Mandatory Reference for ADS Chapter 545 New Reference: 06/01/2006 Responsible Office: M/DCIO File Name: 545mal_060106_cd44 Information System Security

More information

Overview of how to test a. Business Continuity Plan

Overview of how to test a. Business Continuity Plan Overview of how to test a Business Continuity Plan Prepared by: Thomas Bronack Phone: (718) 591-5553 Email: [email protected] BRP/DRP Test Plan Creation and Exercise Page: 1 Table of Contents BCP/DRP Test

More information

Toronto Public Library Disaster Recovery recommended safeguards and controls

Toronto Public Library Disaster Recovery recommended safeguards and controls BCE Security Solutions Restricted Attachment 1 Toronto Public Library Disaster Recovery recommended safeguards and controls Final Prepared by: Bell Security Solutions Inc. Professional Services 333 Preston

More information

Disaster Recovery & Business Continuity Related, but NOT the Same! Teri Stokes, Ph.D., Director GXP International

Disaster Recovery & Business Continuity Related, but NOT the Same! Teri Stokes, Ph.D., Director GXP International Disaster Recovery & Business Continuity Related, but NOT the Same! Teri Stokes, Ph.D., Director GXP International BCP Definitions Business Continuity Plan: An ongoing process supported by senior management

More information

CISM Certified Information Security Manager

CISM Certified Information Security Manager CISM Certified Information Security Manager Firebrand Custom Designed Courseware Chapter 4 Information Security Incident Management Exam Relevance Ensure that the CISM candidate Establish an effective

More information

MARQUIS DISASTER RECOVERY PLAN (DRP)

MARQUIS DISASTER RECOVERY PLAN (DRP) MARQUIS DISASTER RECOVERY PLAN (DRP) Disaster Recovery is an ongoing process to plan, develop, test and implement changes, processes and procedures supporting the recovery of the critical functions in

More information

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand

More information

Module 7. Business Continuity Management

Module 7. Business Continuity Management Module 7 Business Continuity Management MODULE 7: BUSINESS CONTINUITY MANAGEMENT Table of Contents Module 7: Business Continuity Management... 1 SECTION 1: OVERVIEW... 7 MODLULE 7: BUSINESS CONTINUITY

More information

Business Continuity Management

Business Continuity Management Business Continuity Management cliftonlarsonallen.com Introductions Brian Pye CliftonLarsonAllen Senior Manager Business Risk Services group 15 years of experience with Business Continuity Megan Moore

More information

RISK CONTROL. Strategy guide for business continuity planning. Risk Management Guide

RISK CONTROL. Strategy guide for business continuity planning. Risk Management Guide Risk Management Guide RISK CONTROL REDUCE RISK. PREVENT LOSS. SAVE LIVES. A FOUR STEP PROCESS: About this planning guide This guide discusses the fundamental process and plan components of Travelers Strategy

More information

PAPER-6 PART-4 OF 5 CA A.RAFEQ, FCA

PAPER-6 PART-4 OF 5 CA A.RAFEQ, FCA 1 Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-4 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand

More information

How to Prepare for an Emergency: A Disaster and Business Recovery Plan

How to Prepare for an Emergency: A Disaster and Business Recovery Plan How to Prepare for an Emergency: A Disaster and Business Recovery Plan Chapter 1: Overview of the Disaster and Business Recovery Plan Purpose: To develop and establish a comprehensive Disaster and Business

More information

Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0

Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0 Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0 Unless otherwise stated, these Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies

More information

Certified Disaster Recovery Engineer

Certified Disaster Recovery Engineer Cyber Security Training & Consulting Certified Disaster COURSE OVERVIEW 4 Days 32 CPE Credits $2,500 When a business is hit by a natural disaster, cyber crime or any other disruptive tragedy, how should

More information

State of South Carolina Policy Guidance and Training

State of South Carolina Policy Guidance and Training State of South Carolina Policy Guidance and Training Policy Workshop All Agencies Business Continuity Management Policy June 2014 Agenda Questions & Follow-Up Policy Workshop Overview & Timeline Policy

More information

Business Continuity Planning for Risk Reduction

Business Continuity Planning for Risk Reduction Business Continuity Planning for Risk Reduction Ion PLUMB [email protected] Andreea ZAMFIR [email protected] Delia TUDOR [email protected] Faculty of Management Academy of Economic Studies

More information

NCUA LETTER TO CREDIT UNIONS

NCUA LETTER TO CREDIT UNIONS NCUA LETTER TO CREDIT UNIONS NATIONAL CREDIT UNION ADMINISTRATION 1775 Duke Street, Alexandria, VA 22314 DATE: December 2001 LETTER NO.: 01-CU-21 TO: SUBJ: ENCL: All Federally Insured Credit Unions Disaster

More information

BUSINESS CONTINUITY PLAN

BUSINESS CONTINUITY PLAN How to Develop a BUSINESS CONTINUITY PLAN To print to A4, print at 75%. TABLE OF CONTENTS SUMMARY SUMMARY WHAT IS A BUSINESS CONTINUITY PLAN? CHAPTER PREPARING TO WRITE YOUR BUSINESS CONTINUITY PLAN CHAPTER

More information

Disaster Recovery. Hendry Taylor Tayori Limited

Disaster Recovery. Hendry Taylor Tayori Limited Disaster Recovery Hendry Taylor Tayori Limited Agenda What is Business Continuity planning (BCP) What is Disaster Recovery (DR) and Disaster Recovery Planning (DRP) Overview Lifecycle Analysis Plan design

More information

Disaster Prevention and Recovery for School System Technology

Disaster Prevention and Recovery for School System Technology The Optimal Reference Guide: Disaster Prevention and Recovery for School System Technology Extraordinary insight into today s education topics Glynn D. Ligon, Ph.D., ESP Solutions Group Evangelina Mangino,

More information

Version 8.0 2014 Copyright Janco Associates, Inc. - http://www.e-janco.com Page 1

Version 8.0 2014 Copyright Janco Associates, Inc. - http://www.e-janco.com Page 1 Version 8.0 2014 Copyright Janco Associates, Inc. - http://www.e-janco.com Page 1 Table of Contents 1 1.0 Plan Introduction... 4 1.1 Mission and Objectives... 5 Compliance... 5 ISO Compliance Process...

More information

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION Federal Financial Institutions Examination Council FFIEC Business Continuity Planning MARCH 2003 MARCH 2008 BCP IT EXAMINATION H ANDBOOK TABLE OF CONTENTS INTRODUCTION... 1 BOARD AND SENIOR MANAGEMENT

More information

How To Back Up A Virtual Machine

How To Back Up A Virtual Machine 2010 Symantec Disaster Recovery Study Global Results Methodology Applied Research performed survey 1,700 enterprises worldwide 5,000 employees or more Cross-industry 2 Key Findings Virtualization and Cloud

More information

Business Continuity Planning for Schools, Departments & Support Units

Business Continuity Planning for Schools, Departments & Support Units Business Continuity Planning for Schools, Departments & Support Units 1 What is Business Continuity Planning? Examples Planning for an adverse, major or catastrophic event that would cause a disruption

More information

Q uick Guide to Disaster Recovery Planning An ITtoolkit.com White Paper

Q uick Guide to Disaster Recovery Planning An ITtoolkit.com White Paper This quick reference guide provides an introductory overview of the key principles and issues involved in IT related disaster recovery planning, including needs evaluation, goals, objectives and related

More information

Technology Infrastructure Services

Technology Infrastructure Services LOB #303: DISASTER RECOVERY Technology Infrastructure Services Purpose Disaster Recovery (DR) for IT is a capability to restore enterprise-wide technology infrastructure, applications and data that are

More information

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK Federal Financial Institutions Examination Council FFIEC Business Continuity Planning BCP FEBRUARY 2015 IT EXAMINATION H ANDBOOK Table of Contents Introduction 1 Board and Senior Management Responsibilities

More information

Unit Guide to Business Continuity/Resumption Planning

Unit Guide to Business Continuity/Resumption Planning Unit Guide to Business Continuity/Resumption Planning (February 2009) Revised June 2011 Executive Summary... 3 Purpose and Scope for a Unit Business Continuity Plan(BCP)... 3 Resumption Planning... 4 Assumptions

More information

The Disaster Recovery Maturity Framework

The Disaster Recovery Maturity Framework The Disaster Recovery Maturity Framework A guide for understanding and improving your company s resiliency www.axcient.com Climbing The Recovery Maturity Curve Businesses are critically reliant upon IT

More information

CERTIFIED DISASTER RECOVERY ENGINEER

CERTIFIED DISASTER RECOVERY ENGINEER CERTIFIED DISASTER RECOVERY ENGINEER KEY DATA COURSE OVERVIEW ACCREDITATION Course Title: C)DRE Duration: 4 days CPE Credits: 32 Class Format Options: Instructor-led classroom Live Online Training Computer

More information

Disaster Recovery Plan Checklist

Disaster Recovery Plan Checklist Disaster Recovery Plan Checklist Your guide for setting up or updating a Disaster Recovery Plan for your business. ArcSource Disaster Recovery Plan Checklist 1. Compile Your Internal Contacts Information

More information

What is Business Continuity Planning (BCP) / Disaster Recovery Plan(DRP)?

What is Business Continuity Planning (BCP) / Disaster Recovery Plan(DRP)? Workshop on System Audit of Banks BCP Workshop on System Audit of Banks What is Business Continuity Planning (BCP) / Disaster Recovery Plan(DRP)? - Preparedness of an organisation to ensure continuity,

More information

IF DISASTER STRIKES IS YOUR BUSINESS READY?

IF DISASTER STRIKES IS YOUR BUSINESS READY? 1 IF DISASTER STRIKES IS YOUR BUSINESS READY? DISASTER RECOVERY and BUSINESS CONTINUITY: WHAT YOU NEED TO KNOW Realize the Power of Technology Many business owners put off disaster planning, perhaps thinking

More information

Proposal for Business Continuity Plan and Management Review 6 August 2008

Proposal for Business Continuity Plan and Management Review 6 August 2008 Proposal for Business Continuity Plan and Management Review 6 August 2008 2008/8/6 Contents About Newton IT / Quality of our services. BCM & BS25999 Overview 2. BCM Development in line with BS25999 3.

More information

Offsite Disaster Recovery Plan

Offsite Disaster Recovery Plan 1 Offsite Disaster Recovery Plan Offsite Disaster Recovery Plan Presented By: Natan Verkhovsky President Disty Portal Inc. 2 Offsite Disaster Recovery Plan Introduction This document is a comprehensive

More information

The 9 Ugliest Mistakes Made with Data Backup and How to Avoid Them

The 9 Ugliest Mistakes Made with Data Backup and How to Avoid Them The 9 Ugliest Mistakes Made with Data Backup and How to Avoid Them If your data is important to your business and you cannot afford to have your operations halted for days even weeks due to data loss or

More information