Choosing BCP Software: One Organization s Story. Brenda E. Brown-Paul



Similar documents
Six Common Factors to Consider When selecting a CMS

Contingency Plan for HIPAA

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

BUSINESS CONTINUITY PLANNING. Business Continuity Management Plan. Version 1.4

Certification. Is it Right for You? 2013 Micron Technology, Inc. February 12, 2014

Services Providers. Ivan Soto

Day 1 - Technology Introduction & Digital Asset Management

Overview of how to test a. Business Continuity Plan

How to Turn the Promise of the Cloud into an Operational Reality

A web-based contact center performance analytics application that gathers information from across your customer interaction technologies and provides

Contents. About Perpetuuiti. Continuity Vault. Continuity Patrol. Ops Central. Questions & Answers. Section 2. Section 3. Section 4.

Business Continuity and Disaster Recovery Planning

EZManage SQL Pro. Quick guide for installation and implementation

1.0 Policy Statement / Intentions (FOIA - Open)

Third-Party Cybersecurity and Data Loss Prevention

WALKME WHITEPAPER. WalkMe Architecture

MS 20341B: Core Solutions of Microsoft Exchange Server 2013

Securing and Auditing Cloud Computing. Jason Alexander Chief Information Security Officer

Planning, Deploying, and Managing an Enterprise Project Management Solution

State of South Carolina Policy Guidance and Training

Factonomy Resilience. Enterprise Business Continuity

NIST SP , Revision 1 Contingency Planning Guide for Federal Information Systems

G-Cloud Framework. Page 1. Document for Service Definition Audit management System. In response to G Cloud 6 Requirements

Business Continuity (Policy & Procedure)

BUSINESS CONTINUITY PROGRAM (BCP) HANDBOOK FOR DEPARTMENT BCP TEAMS

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

Audit Report. Effectiveness of IT Controls at the Global Fund Follow-up report. GF-OIG-15-20b 26 November 2015 Geneva, Switzerland

Activity Centered Training for SharePoint

Creating a Virtual Lab for Data Science

Plan Development Getting from Principles to Paper

FINRMFS9 Facilitate Business Continuity Planning and disaster recovery for a financial services organisation

Mobile and BYOD Strategy

Course 20341B: Core Solutions of Microsoft Exchange Server 2013 OVERVIEW

Is Cloud Accounting Right for Your Business? An Educational Report

Request for Proposals Evaluation Guide

REQUEST FOR PROPOSAL Website Design and Development. DUE DATE: FEBRUARY 19, :00 p.m.

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

GET ALERTED ABOUT A T24 ERROR BEFORE IT OCCURS PROACTIVE T24 MONITORING TAMAM YOU NEED INFORMATION AND NOT MEASURED DATA

Core Solutions of Microsoft Exchange Server 2013 Course 20341B; 5 days, Instructor-led

Autodesk PLM 360 Security Whitepaper

Course 20341B: Core Solutions of Microsoft Exchange Server 2013

MS-55115: Planning, Deploying and Managing Microsoft Project Server 2013

Project Management through

EXECUTIVE CRISIS MANAGEMENT TRAINING. Presented by Roseanne Rostron, CBCP Raido Response

Core Solutions of Microsoft Exchange Server 2013

Hydrant E-Learning Management System (HELMS)

DISASTER RECOVERY/ BUSINESS CONTINUITY AUDITING: A CASE STUDY

Business Continuity in Healthcare

Adworks Local Area Marketing. The way it works

CUSTOM INTERACTIVE VOICE4NET TELEPHONY SOLUTIONS. Contact Center HD.

Measuring Continuity Planning Program. Performance

Sparx Systems Enterprise Architect for Team Players

Course 20341B: Core Solutions of Microsoft Exchange Server 2013

Core Solutions of Microsoft Exchange Server 2013

NEEDS BASED PLANNING FOR IT DISASTER RECOVERY

Filestor Digital Asset Management. The way it works

CERTIFICATION IN BUSINESS CONTINUITY By Walter G. Green III, Ph.D., CRP

Administering a SQL Database Infrastructure

Cloud Computing Security Issues

Proposal for Business Continuity Plan and Management Review 6 August 2008

Administering a SQL Database Infrastructure 20764; 5 Days; Instructor-led

Tools to Aid in 21 CFR Part 11 Compliance with EZChrom Elite Chromatography Data System. White Paper. By Frank Tontala

Product Information. Sugar vs Zoho. Features Comparison

70-414: Implementing a Cloud Based Infrastructure. Course Overview

MOC 10964C: Cloud and Datacenter Monitoring with System Center Operations Manager

LMS Evaluation Tool User Guide

All your apps & data in the cloud, all in one place.

CISM Certified Information Security Manager

IT Service Continuity Management PinkVERIFY

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006

itop: the open-source ITSM solution

Deploying Cisco Unified Contact Center Express Volume 1

10 simple rules for buying a helpdesk system

IT Disaster Recovery Plan Template

SUMMARY Moderate-High: Requires Visual Basic For Applications (VBA) skills, network file services skills and interoperability skills.

Core Solutions of Microsoft Exchange Server 2013 Course 20341A; 5 Days

Administering a SQL Database Infrastructure (MS )

How To Choose Help Desk Software For Your Company

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

10775 Administering Microsoft SQL Server Databases

a Disaster Recovery Plan

IT Sr. Systems Administrator

20341B: Core Solutions of Microsoft Exchange Server 2013

BI Project Management Software

Business Continuity Management

TERMS OF REFERENCE (TORs) OF CONSULTANTS - (EAG) 1. Reporting Function. The Applications Consultant reports directly to the CIO

Transcription:

Choosing BCP Software: One Organization s Story Brenda E. Brown-Paul

Introduction Brenda Brown-Paul Sr. Analyst for a Professional Services Company 21 years of IT experience 6 years in business continuity Certified Business Continuity Planner Primarily federal government contracting Several application review & requirements analysis projects Customer Data center

Overview Problems What were we trying to solve? Review Process How was the analysis conducted? Findings What was the final result? Lessons Learned What could have been done better?

State of Customer s Business Continuity Program The Data Center s Business Continuity Program Started in 2001 after negative audit report Includes BC Plan, OEP, Crisis Management Plan, Business Recovery Plan, & IT Contingency Plans User Training & awareness programs Supported by management Missing? Tools to support the program!

Identify the Problem What are you trying to solve? Decentralized management of BCP Documentation System owners responsible for SOP & IT Contingency Plans Documents kept in directories that cannot be accessed universally Confusion about versions among staff No easy way to collaborate or show dependencies New things keep popping up!

Overall Process in Choosing BCP Software ID Problem & Initial Requirements Identify Stakeholders & Responsibilities Requirements Analysis Set Review C riteria & Factors Software Review Findings Recommendation

1. Initial Requirements Would be a shared, Internet-based application Would be easy to administer Would be easy to use Would be browser independent (very important for this customer)

2. Stakeholders Who are the stakeholders? Customer Management Team Leaders Team Members Business Recovery Coordinator BC Consultant System Administrator(s) Project Managers

Expected Stakeholder Responsibilities Agency, Division & CIO Mgmt No interaction Office level management Interaction possible, but no assigned responsibilities Team Leaders, BRC & Consultant Responsible for updates & other tasks BC Consultant Administration (not system) & Security System Administrators Backups, recovery, contingency, etc. Project Managers May request information from system directly or through other users.

Primary Stakeholders BC Consultant & BRC BRC responsible for overall BC program Consultant will be the primary administrator & Security Officer for the software Set up users Manage web space Define backup schedule Interface with vendor Etc.

Stakeholder Skill Sets Comfort level with PCs Comfort level with the Internet Will the users follow rules & guidelines? To what degree? Past experience with these users Adherence to: Change Management Policies SOP Creation Timely updates

3. Requirements Analysis Internet Based Run in secure web space Browser independent; no Active X Should look & feel like a website Scalable How much? Ease of Use Ease of Deployment Support

Requirements Analysis (cont.) Adherence to DRII Professional Standards Security In addition to secure network, want additional level of security User login Restricted access to modules, fields, etc. Contingency Event Support

4. Software Review Criteria Three Categories of Software Category A A basic application that steps through the BCP process Category B A BCP application that steps through the process, includes a planning wizard & helps manage exercises Category C A BCP application that does all of the above & provides incident management & notification modules

Criteria Weights from.50 to 1.00 Essential 1.0 Important.70 or greater Interesting.50

8 overall criteria Criteria Criteria Ease of Use Integration Adherence to DRII/BCI Standards Security Ease of Deployment Purchase Price Support Contingency Event Support Weight 1.00 1.00 1.00 1.00.90.70.50.50

Criteria Each criterion had a list of factors. Each factor ranked from.50 to 1.50 Exceeds the factor 1.50 Meets the factor 1.00 Did not meet the factor - 0 Overall, there were 49 factors between the 8 criteria

Final Scoring Derived by multiplying the individual factor score by the factor weight, adding all of the factors by that criteria together, & dividing the result by the number of factors in the criteria. All factors do not apply to each category Maximum Score for a Category A app:.87 Maximum Score for a Category B app:.83 Finally, the score & the price were listed & ranked

5. Software Review Step 1 Where else the Internet? Review of BCP & Disaster Recovery Websites IT Industry Research organizations Warning: General web search is too broad

Software Review Step 1 Recommendations from peers Internal company business continuity group Internal customer business continuity group Association of Contingency Planners (Mid- Atlantic Chapter) Called a bunch of folks I know

Software Review Step 2 Review of vendor websites & demo SW Narrowed list to six vendors to get more information by phone. Sent questionnaire to the vendors with criteria Online demonstrations When possible, met with company representatives Asked for, and called, references!!!

Software Review - Shortcomings Only one person involved in this review Could not test the applications in the customer s environment which skewed the decision Most required application to be loaded at the customer site no could do One would not provide access to a demo site Only 2 could provide demo site access; one made it so easy that it swayed the reviewer toward their company early in the review process

6. Findings 6 Final Candidates Category As (2) Category Bs (3) Category C (1)

Findings Category A 2 Candidates Neither application met all of the criteria First Candidate Not web-accessible as advertised, though web-enabled was coming in about a year Clumsy look & feel Old Visual Basic interface; could feel the db Restricted user to completing BC Plan in a proscribed order Second Candidate This was one of several modules that had to be purchased separately Addressed only 4 of DRII Best Practices. 4 others addressed in 2 other modules Required knowledge of 3 rd -party, proprietary reporting application Cost more than all of the 5 other applications rolled together! Both applications only run on Windows Servers

Findings Category B Each met the minimum requirements to varying degrees One app was a category A until online demo was given One app could be a category C with a notification module

Findings Category B First Candidate First Candidate Over 30+ pre-defined reports Tracks application criticality, risk tolerance, dependencies, GAP analysis, etc. Comes with 1000s of pages of guidelines, a user s guide & online help Not at all intuitive & must be used in a proscribed order. Could not load existing documents, or easily cut & paste Any changes to the fields, format, reports, etc required vendor work $ Reports could not be altered until they were in WP. Not easy for customer stakeholders Security No tracking for tests or events

Findings Category B Candidate 2 Very easy to use intuitive! Longest track record of any company reviewed 21 years Built on java can run on any server Had track record with ODBC notification apps Provided starter list of tasks to help novice, but could jump around Collaborative; unlimited number of users Easy list interfaces Security

Findings Category B Candidate 2 Candidate 2 (cont.) Test/Activate module for exercises & to track actual events Versions are tracked Existing documents can be cut & pasted into the database Reports are in the same 3 rd party application as the first Training offered for free about 350 miles away at company HQ or for $1500 per day onsite

Findings Category B Candidate 3 Very easy to use! Site administrator (reviewer) had no training, but basic instructions ACCEPTS DOCUMENTS JUST AS THEY ARE!!! MS based, but can be run on any platform Application designed for the Internet and collaboration Able to manipulate the site through any HTML editor. Provides complete set of document templates based on DRII Best Practices in order Focus of the company is on government COOP processing; they speak the language Certified DRII training partner

Candidate 3 Findings Category B Database tracks all documents, files, users, lists, etc. Training is minimal; mostly for system administrator & done during installation At time of evaluation, this was a very young company (couple of years old). Staff had over 20 years in DRP At beginning of evaluation, had few customers. Better bells & whistles if you use Office 2003 on MS 2003 server, but completely functional without it.

Findings Category C All the great features of Category B apps In fact, too many features for this client! Lots of fun to play with! Very easy to use No real customers, though used in large national testing by Feds Developed for the Internet from the start

7. Recommendation Recommended third application in Category B Customer only wanted demonstration of the recommended application

Lessons Learned Analyst s vision was not the customer s vision! Internal sales job was not strong enough Needed to have one customer champion invested in the process The priorities have changed. Who is going to do the certification & accreditation for this package, which includes writing the IT Contingency Plan, justification, etc?

Questions

Suggested websites www.contingencyplanning.com www.drj.com www.metaworld.com or www.gartner.com (recently purchased metaworld Contact brenda.e.brown-paul@lmco.com