How to Plan for Disaster Recovery and Business Continuity



Similar documents
Attachment to Data Center Services Multisourcing Service Integrator Master Services Agreement

Continuity of Operations Planning. A step by step guide for business

Business Unit CONTINGENCY PLAN

Disaster Recovery Plan Documentation for Agencies Instructions

Technology Recovery Plan Instructions

SAMPLE IT CONTINGENCY PLAN FORMAT

External Supplier Control Requirements BCM

IT Disaster Recovery Plan Template

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

Unit Guide to Business Continuity/Resumption Planning

BUSINESS CONTINUITY PLAN OVERVIEW

Overview of how to test a. Business Continuity Plan

Fire Department Guide. Creating and Maintaining Business Continuity Plans (BCP)

Offsite Disaster Recovery Plan

Business Continuity and Disaster Recovery Planning

Disaster Recovery. Hendry Taylor Tayori Limited

STEP-BY-STEP BUSINESS CONTINUITY AND EMERGENCY PLANNING MAY

The University of Iowa. Enterprise Information Technology Disaster Plan. Version 3.1

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Western Intergovernmental Audit Forum

Creating a Business Continuity Plan for your Health Center

Best Practices in Disaster Recovery Planning and Testing

DISASTER RECOVERY PLANNING

Audit, Finance and Legislative Committee Mayor Craig Lowe, Chair Mayor-Commissioner Pro Tem Thomas Hawkins, Member

Why Should Companies Take a Closer Look at Business Continuity Planning?

Emergency Operations California State University Los Angeles

Clinic Business Continuity Plan Guidelines

Business Continuity Plan

DRAFT Disaster Recovery Policy Template

Business Continuity & Recovery Plan Summary

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

Disaster Recovery Plan

Clinic Business Continuity Plan Guidelines

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

Disaster Recovery Planning. By Janet Coggins

MARQUIS DISASTER RECOVERY PLAN (DRP)

How to write a DISASTER RECOVERY PLAN. To print to A4, print at 75%.

Disaster Recovery Plan Checklist

Business Continuity Planning for Risk Reduction

Running head: COMPONENTS OF A DISASTER RECOVERY PLAN 1

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

NCUA LETTER TO CREDIT UNIONS

JANSSEN PARTNERS, INC. Business Continuity Plan (BCP)

IF DISASTER STRIKES IS YOUR BUSINESS READY?

Business Continuity Plan (BCP)

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).

CIS 523/423 Disaster Recovery Business Continuity

D2-02_01 Disaster Recovery in the modern EPU

Disaster Recovery and Business Continuity Plan

Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP)

Business Continuity & Recovery Plan Summary

Q uick Guide to Disaster Recovery Planning An ITtoolkit.com White Paper

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

Disaster Recovery Planning

Business Continuity Planning (800)

A Professional s Guide to the Contents of a Business Continuity Plan

Disaster Recovery Plan

Facilitated By: Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services

Prudential Practice Guide

NIST SP , Revision 1 Contingency Planning Guide for Federal Information Systems

Introduction to Business Continuity Planning

Table of Contents ESF

Manual Overview. Release Date: March 18, Prepared by: Thomas Bronack

THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST. Business Continuity Plan

Building a Disaster Recovery Program By: Stieven Weidner, Senior Manager

Business Continuity Planning. Description and Framework. White Paper. Preface. Contents

Disaster Recovery Planning Process

Prudential Practice Guide

SCHEDULE 25. Business Continuity

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning FEBRUARY 2015 IT EXAMINATION H ANDBOOK

Business Continuity. Disaster Recovery Plan

How to Prepare for an Emergency: A Disaster and Business Recovery Plan

ILLINOIS INSTITUTE OF TECHNOLOGY School of Applied Technology. Dave Wallenberg, Mario Russo and Batchum Mataruke Edited by Ray Trygstad

NEEDS BASED PLANNING FOR IT DISASTER RECOVERY

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006

Disaster Recovery Plan Review Checklist. A High-Level Internal Planning Tool to Assist State Agencies with Their Disaster Recovery Plans

Disaster Recovery Plan (Business Continuity) Template

Disaster Preparedness & Response

How To Prepare For A Disaster

Overview of Business Continuity Planning Sally Meglathery Payoff

Clovis Municipal School District Information Technology (IT) Disaster Recovery Plan

Protecting Your Business

Emergency Response and Business Continuity Management Policy

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Transcription:

A TAMP Systems White Paper TAMP Systems 1-516-623-2038 www.drsbytamp.com How to Plan for Disaster Recovery and Business Continuity By Tom Abruzzo, President and CEO

Contents Introduction 1 Definitions 1 Definition Dialog 1 How to Accomplish Disaster Recovery and Business Continuity Planning 2 Summary 4 About TAMP Systems 4 Introduction Having an understanding of what it means to plan for disaster recovery and business continuity will provide you a solid framework from which to create specific plans for your business. Definitions Disaster = Any event that causes inaccessibility or inoperability to your technology, business functions or facility. Disaster Recovery Plan (DRP) = A plan to recover from inaccessibility or inoperability to your technology. Business Continuity Plan (BCP) = A plan to recover from inaccessibility or inoperability to your facility, including your business functions and technology. Definition Dialog If you ask ten people to define a disaster, you would get ten different answers. The first thing that comes to mind when you think of a disaster is an event, such as a fire, flood, tornado, terrorist attack, etc. Our industry research has shown that there are well over 200 events that can cause a disaster. Rather than planning for disaster events, we plan for the result of an event as it relates time. For example, if a disaster event causes inaccessibility to your facility or inoperability of your technology for a specific or an approximate timeframe, it would be considered a disaster. Therefore, we define a disaster as any event that causes inaccessibility or inoperability to your technology, business functions or facility, and Page 1

possibly permanently It is logical to believe if you can recover from a worst-case scenario, you will be able to recover from anything less. It should be noted that most contingency planning practitioners differentiate disaster recovery as recovery of technology after disaster and business continuity as recovery of business functions after a disaster. We strongly believe that these must be integrated. How to Accomplish Disaster Recovery and Business Continuity Planning In order to accomplish disaster recovery and business continuity planning, you must: 1. Define the scope of what you are trying to recover from a disaster. This may be one server, a complete data center or an entire facility. 2. Define your Recovery Timeframe Objective (RTO). This is the target timeframe within which you want to recover from a disaster. 3. Choose and implement the recovery strategy that will allow you to achieve your RTO. For example, if you want to recover the mission critical servers in a data center and your RTO is 24 hours, you could choose a commercial hot site as your recovery strategy. 4. Identify and document your recovery resources. These are the information resources that will assist you in your recovery activities and will allow you to achieve your RTO. Alphabetically, the categories of recovery resource information are: Page 2

a. Equipment - an inventory of the equipment you had before the disaster as well as what equipment you will need for recovery b. Facilities a description of the facilities, including contact information and directions, which would assist you in your recovery activities. These may include your offsite storage facility, hot site, command centers, alternate offices, etc. c. Forms & Stationery a description of any special forms or stationery items that would be necessary to achieve your RTO. For example, blank company checks, etc. d. Personnel detailed contact information on all your personnel will be essential for recovery e. Recovery Tasks a description of the tasks that need to be accomplished for recovery f. Software an inventory of the software you had before the disaster as well as the software you will need for recovery, including any temporary software license keys g. Supplies - a description of any special supply items that would be necessary to achieve your RTO. For example, signature plates, etc. h. Vendors a description of your vendors, including their purpose, contact information and service level agreements i. Vital Records an inventory and description of the vital records you will need for recovery. The best recovery plan will not work without your vital records. 5. Document your recovery plan. This plan must be logically organized and easily reference-able. Your plan must cover the following topics: a. Introductory Information - This section should contain the foundation information for your Plan, e.g., scope, recovery objective, recovery strategy, assumptions, etc. b. Incident Response - When an incident (potential disaster) occurs, someone must respond with a predefined sequence of events and follow the Disaster Declaration Procedures c. Notification Procedures - Once a disaster is declared by management, notification of Plan- Page 3

participants must immediately begin d. Recovery Teams Responsibilities, Staffing and Procedures - As soon as the Plan participants have been notified, they will become part of one or more recovery teams Therefore, recovery roles and responsibilities will be documented in this section e. Emergency Procedures and Information - This section is a requirement by external regulators for plans f. Mission Critical Operating Specifications - Everything you will need to quickly establish your mission critical operations should be documented in this section, e.g., command center locations, service level agreements from your vendors, etc. g. Rebuilding/Restoring Specifications and Inventories - At the same time that you are establishing your mission critical operations, restoring and rebuilding should begin immediately h. Appendices - A glossary of terms as well as testing and maintenance procedures are the main topics that should be in this section Summary Disaster recovery / business continuity planning is not a trivial task, nor is it beyond the capabilities of an intelligent person who knows your company and its needs, and has support of top management. There are two intelligent alternatives to accomplish planning. One alternative is to purchase a do-it-yourself recovery planning software product that contains the information and tools to assist you. The second alternative is to secure the services of a consulting firm that specializes in business continuity planning and can also provide you with a software tools so that you can become selfsufficient in your recovery planning maintenance efforts. About TAMP Systems TAMP provides a comprehensive resource and document management system specifically designed for disaster recovery and business continuity planning. The Disaster Recovery System (DRS TM ) is a webbased software solution that is easy to learn and features automatic updating of plan content. For over 20 years, TAMP has focused solely on developing solutions for contingency and recovery planning. Our DRS-certified consultants provide customized planning services to ensure that plans meet regulatory requirements. For more details, please visit http://www.drsbytamp.com or call 1-516-623-2038. Page 4