An Archive Audit to Support Disaster Recovery



Similar documents
Business Continuity and Disaster Recovery Planning from an Information Technology Perspective

DISASTER RECOVERY PLANNING GUIDE

Managing business risk

Disaster Recovery Planning for Homesteaders 2004 Paul Edwards & Associates

Why Should Companies Take a Closer Look at Business Continuity Planning?

Disaster Recovery for Small Businesses

Prepared by Rod Davis, ABCP, MCSA November, 2011

MOVING INTO THE DATA CENTRE: BEST PRACTICES FOR SUCCESSFUL COLOCATION

Top 10 Disaster Recovery Pitfalls

Expecting the Unexpected. Disaster Preparedness Strategies for Small Business

Business Continuity and Disaster Survival Strategies for the Small and Mid Size Business.

How To Back Up A Virtual Machine

disaster recovery - the importance of having a plan

FORMULATING YOUR BUSINESS CONTINUITY PLAN

Service Availability Metrics

Disaster Recovery (DR) Planning with the Cloud Desktop

Frequently Asked Questions about Cloud and Online Backup

How Small/ Mid Size Companies Can Protect Their Business. Introduction

Disaster Recovery Business Continuity Premium Edition

Protecting Microsoft SQL Server

DISASTER RECOVERY WITH AWS

Protecting your Enterprise

Disaster Recovery Remote off-site Storage for single server environment

Disaster Recovery Planning Save Your Business

This white paper describes the three reasons why backup is a strategic element of your IT plan and why it is critical to your business that you plan

Disaster Recovery Planning

How to Design and Implement a Successful Disaster Recovery Plan

Business Continuity Planning Guide

BACKUP SECURITY GUIDELINE

White Paper: ISO Business Continuity Management An Overview. ISO Business Continuity Management An Overview

CONSIDERATIONS BEFORE MOVING TO THE CLOUD

Vital Records Identification, Protection, and Disaster Recovery June 16, Wess Jolley, CRM, Records Manager 1

Availability Digest. Banks Use Synchronous Replication for Zero RPO February 2010

New Clerk Academy. August 13, 2015

The IDG 9074 Remote Access Controller

Cloud Computing. Chapter 10 Disaster Recovery and Business Continuity and the Cloud

Disaster Recovery Plan (Business Continuity) Template

PROTECTING MICROSOFT SQL SERVER TM

Disaster Recovery & Business Continuity Dell IT Executive Learning Series

Temple university. Auditing a business continuity management BCM. November, 2015

Version Copyright Janco Associates, Inc. - Page 1

The Benefits of Continuous Data Protection (CDP) for IBM i and AIX Environments

2008 Small Business Technology Trends Survey: A Peer Perspective on IT in Small Business

OKHAHLAMBA LOCAL MUNICIPALITY

Technology Infrastructure Services

Maximizing Data Center Uptime with Business Continuity Planning Next to ensuring the safety of your employees, the most important business continuity

HOSTED VOIP. 61 Greenheys Business Centre Manchester Science Park Manchester M15 6JJ

IBM Virtualization Engine TS7700 GRID Solutions for Business Continuity

The Difference Between Disaster Recovery and Business Continuance

Nine Steps to Smart Security for Small Businesses

Website Disaster Recovery

Business Continuity Planning in IT

courtesy of F5 NETWORKS New Technologies For Disaster Recovery/Business Continuity overview f5 networks P

Enterprise Risk Services. Aware vs. committed where do you stand? Business continuity management

Disaster Recovery Feature of Symfoware DBMS

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION

Continuity of Operations Planning. A step by step guide for business

Planning and Implementing Disaster Recovery for DICOM Medical Images

Audit of the Disaster Recovery Plan

Hosted Exchange Services

Security+ Guide to Network Security Fundamentals, Fourth Edition. Chapter 13 Business Continuity

Business Continuity Management and The Extended Enterprise

Transaction Processing and Enterprise Resource Planning Systems. Goal of Transaction Processing. Characteristics of Transaction Processing

[Insert Company Logo]

Disaster Recovery. Continuity in an Uncertain World

Disaster Recovery for Ingres. Abstract

DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS

Disaster Recovery, Business Continuity & Other Lessons Learned

W H I T E P A P E R T h e C r i t i c a l N e e d t o P r o t e c t M a i n f r a m e B u s i n e s s - C r i t i c a l A p p l i c a t i o n s

Virtual Infrastructure Security

Documentation for data centre migrations

Disaster recovery planning: a strategy for data security

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

White paper. SAS Solutions OnDemand Hosting Overview

Four Steps to Disaster Recovery and Business Continuity using iscsi

BACKUP IS DEAD: Introducing the Data Protection Lifecycle, a new paradigm for data protection and recovery WHITE PAPER

Transcription:

An Archive Audit to Support Disaster Recovery Linda Kempster IMERGE Consulting 6115 Winchester Place Sarasota, FL 34243-5320 Phone/FAX: +1-941-358-7560 E-mail: lskempster@hotmail.com www.imergeconsult.com Presented at the THIC Meeting at the Del Mar Hilton Del Mar CA 92130-2539 on January 22, 2002

2001 The Year of Vulnerability Awareness Two Groups: Those affected directly Those affected indirectly

Up in Smoke US Customs Bureau of ATF IRS investigators CIA Investment brokers Financial firms Insurance companies Family members

The Search Begins PCs: (computers or paper collectors?) 12% increase in paper usage since 1995. 5% increase in use of computers. US spends $25B/year filing, storing and retrieving paper documents.

The Data Cloud Paper Floppies CDs Laptops Mainframes Servers Networks Archives

Pre-Sept 11 Buzz Words Disaster Recovery Awareness emerged in 1993 after first attack Y2K Forced us to clean up our act

Disaster Recovery Plus! Carrie Lewis, The Yankee Group: Disaster recovery must go beyond simply saving data; a plan must also protect business processes. How much time will it take to get things up and running again? Do you want a separate site running - a mirrored site - so there is no interruption in service, and how often do you want backups done?"

NYSE and DR In the wake of the Sept. 11 attacks, disaster recovery planning will be a key focus of New York Stock Exchange inspections, executive VP Edward Kwalwasser of NYSE stated. Congress is very interested in this so the NYSE will inspect member firms' disaster recovery plans during routine examinations and may propose new rules in this area.

FBI Requirements "Right now, the FBI has a large number of computers that cannot even send pictures of potential terrorists to other FBI terminals because they do not have the adequate computer capacity," Rep. David Obey (D-Wis.) The supplemental spending bill, for example, gives the FBI $56 million for data backup and warehousing and $237 million to speed up its Trilogy program to modernize its IT infrastructure

IRS Funding The Internal Revenue Service received $16 million, of which $13.5 million is for backup systems in case its systems are compromised.

US Customs The Commercial Recovery Services program includes building a primary backup facility at least 20 miles from Customs' Springfield, VA, data center and a second facility at least 350 miles away. Customs officials said they are seeking firms to replicate the agency's computer systems and regularly backup their data.

US Customs (cont d) In the event of a disaster, Customs wants to have fallback systems up and running with data that is no more than 36 hours old for its missioncritical applications, including its Automated Commercial System, which handles imports at the nation's borders. The cost of the project is estimated at more than $1 million, according to Federal Sources Inc. Total of FBI, IRS and Customs: $300M

Types of Damaging Events Sustained loss of telecommunications Structural damage Sustained electrical supply failures Restricted facility access Smoke damage Gas leaks Hazardous materials release Water damage

Vulnerability Analysis A matrix chart can indicate the relationship between the probability of the event occurring, the operational impact and the resources required to implement preventative measures during and after an event causing casualty. Vulnerability varies with the size of an organization

Size of Business Someone once measured businesses impacted by the first World Trade Center bombing and a California earthquake. "Small to Medium" businesses (under 500 users on site) experienced a 50% rate of going out of business if they could not get to their data. Lesson: D/R is actually more important for small/medium businesses - since they are more volatile to any changes in their operating model

2002 Buzz Words Crisis Management Business Continuity Convergence Continuous Availability Disaster Recovery Planning Service Decentralization (critical resources) 2002 may see businesses pulling out of deluxe office HQs and moving into discrete, distributed office environments.

Crisis Management Probably the biggest failure experienced by businesses during September 11th was in their crisis management plans. This will be an important business continuity driver in 2002, as companies seek to develop crisis management plans that are tried, tested and guaranteed to work. This area of the market will see many new entrants as CM companies tap into a potentially lucrative market for their specialist services.

Business Continuity and Record Storage The demand for records storage for legislative reasons will be a driver for business continuity. Digital records are now legally admissible evidence in most countries. Legislation demands that data is stored for many years in a highly available and absolutely resilient system. Business continuity measures are essential in achieving this requirement.

Business Continuity and Information Security Around the world, information security legislation is increasingly demanding business continuity measures. Examples include Gramm-Leach-Bliley and HIPAA, in the US, and the Data Protection Act in the UK. This trend will continue in 2002 and will, in turn, encourage the uptake of the international information security standard ISO 17799

Convergence Convergence issues will become one of the most talked about areas of business continuity in 2002. Telecommunication systems and information technology were once thought of as separate networks, they are now interlinked and are increasingly missioncritical.

Convergence (cont d) Information systems will continue to be more tied to data and document storage technologies so that an enterprise is served by a single system. To accomplish this, archive systems must be tied closer to nearline systems and nearline systems must be tied closer to online systems

Continuous Availability Many mission-critical processes have moved from requiring high availability (HA) to continuous (100 percent) availability. Expect to see the refining of products for this market in 2002, with continuous availability making HA offerings obsolete in some markets. In other markets, the difference between HA (keeping the users productive) and DR (keeping the data survivable) is important so that user and management expectations are set correctly.

Continuous Availability of Archives Evaluate and potentially decrease the number of media per drive Evaluate and potentially increase number of drives per JB Re-evaluate most efficient use of JB clusters

Continuous Availability of the Internet Internet availability will become more important in 2002, and not just for e-commerce firms. Business use of the Internet is growing rapidly and mission-critical processes are being transferred to the IP network, making the continuous availability of Internet services increasingly important. 2002 will see a greater focus upon availability, security and resilience of e-mail processing systems

Disaster Recovery Planning The key to remember that no company has as much as stake during your disaster as you do. Jason Buffington, NSI Software

DR Plans and Tests Is there a plan? Has it been tested? Are there update procedures in place? Do operators have copies? Office, home, car,?? Critical folks have access to emergency resources? Cash for cars, flights, hotels?

Systems Recovery Who has the license keys? Does the DR plan include 800 numbers? Do the right people have the codes to provide and start back-up recovery activities? Are tapes clearly marked? Who has computer room access? Vendors? Users? Consultants? When? During/after shift times?

Data Recovery Plans Does your plan include mail, email, incoming data and output requirements? Do you know what the mission critical data is? Do you know who the owners are? Are they on your backup distribution list?

Initiating the Plans A place to start the DR process is to examine the system as it operates on a day-to-day basis. Departments where poor design or overly complicated "solutions" are in place may hamper the development of the DR plan.

Sample Recovery Details In order to get back into operational status, an inventory needs to be available for possible repurchasing equipment. Digital camera or sensor specifications Batch mode specifications Data conversion specifications Output specifications Storage and HSM specifications Tape supplies, spare drives

DR Not for Systems Alone A DR plan does not end with the data or the servers. If the plan does not include the people, there will be no one sitting at the consoles of those newly shipped PC's, redundant servers and mirrored archives. A key to successful DR is that the redundant facility must be far enough away that it is not susceptible to the outage (i.e. power grid, hurricane, flood, etc) but close enough that key people can get there if necessary.

The Critical Human Elements

A Vacuum of Organization How long can you afford to be down?

Downtime Cost Estimates Elusive estimates span a vast spectrum, from $1,000 to $100,000 per hour - even $100,000 per minute for real-time transactions. Server downtime is tied to the applications environment, producing much higher costs for transaction processing and manufacturing environments. The Gartner Group points out that downtime cost computations typically only figure productivity loss to an organization but they ignore transaction loss, loss of business, or customer dissatisfaction.

Statistics from CTR Most companies value 100 MB at more than $1M. (Jon Toigo). 43% of lost or stolen data is valued at $5M. (Jon Toigo). 43% of companies experiencing disasters never reopen and 29% close within 2 years. (McGladrey and Pullen) 1 out of 500 data centers will have a severe disaster each year. (McGladrey and Pullen)

The Heart of DoD

Hope and Refocus