IBM s Approach to Disaster Recovery and Business Continuity



Similar documents
Table of Contents... 1

Business Resiliency Business Continuity Management - January 14, 2014

Clinic Business Continuity Plan Guidelines

Risk mitigation for business resilience White paper. A comprehensive, best-practices approach to business resilience and risk mitigation.

Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).

CRITICAL INFRASTRUCTURE PROTECTION BUILDING ORGANIZATIONAL RESILIENCE

Business Continuity Planning in IT

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

Clinic Business Continuity Plan Guidelines

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four

Business Continuity Planning Guide

Disaster Recovery. Hendry Taylor Tayori Limited

Operational Risk Management Policy

Offsite Disaster Recovery Plan

Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP)

Business resilience: The best defense is a good offense

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

Temple university. Auditing a business continuity management BCM. November, 2015

Cisco Disaster Recovery: Best Practices White Paper

Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM

DISASTER RECOVERY PLANNING GUIDE

Business Continuity Planning for Risk Reduction

Business Continuity and Risk Management. Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

Managing business risk

Assessment of natural hazards, man made hazards, technical and societal related risks and associated impact.

Overview TECHIS Manage information security business resilience activities

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1

IT Disaster Recovery Plan Template

Unit Guide to Business Continuity/Resumption Planning

Disaster Recovery Planning Process

CIS 523/423 Disaster Recovery Business Continuity

How To Manage A Disruption Event

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

Business Continuity Planning Preparing Your Organization

Joint ICTP-IAEA School of Nuclear Energy Management November Nuclear Security Fundamentals Module 9 topic 2

ICT Business Continuity & Disaster Recovery for Local Authorities. White Paper

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

Desktop Scenario Self Assessment Exercise Page 1

TO AN EFFECTIVE BUSINESS CONTINUITY PLAN

Business Continuity Planning for Schools, Departments & Support Units

Data Loss in a Virtual Environment An Emerging Problem

Business Continuity and Disaster Planning

Business Continuity. Is your Business Prepared for the worse? What is Business Continuity? Why use a Business Continuity Plan?

Disaster Recovery and Business Continuity What Every Executive Needs to Know

eet Business continuity and disaster recovery Enhancing enterprise resiliency for the power and utilities industry Power and Utilities Fact Sheet

Disaster Recovery and Business Continuity Plan

Creating a Business Continuity Plan for your Health Center

Continuity of Operations Planning. A step by step guide for business

10533A: Deploying, Configuring, and Administering Microsoft Lync Server 2010

Business Continuity and Disaster Recovery Planning

Business Continuity Planning and Disaster Recovery Planning

Address C-level Cybersecurity issues to enable and secure Digital transformation

Business Continuity Management

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity

10533: Deploying, Configuring, and Administering Microsoft Lync Server 2010 Duration: Five Days

Interactive-Network Disaster Recovery

WFT - SAP Disaster Recovery Solution Brief Planning and Automating an SAP Landscape Remote Recovery Procedure

Protecting your Enterprise

The PNC Financial Services Group, Inc. Business Continuity Program

ITSM Maturity Model. 1- Ad Hoc 2 - Repeatable 3 - Defined 4 - Managed 5 - Optimizing No standardized incident management process exists

ICT & Communications Services Disaster & Recovery Plan

Intel Business Continuity Practices

NEEDS BASED PLANNING FOR IT DISASTER RECOVERY

Business Continuity Planning (BCP) / Disaster Recovery (DR)

BT Conferencing Business Continuity Management. Planning to stay in business

Disaster Recovery Planning Procedures and Guidelines

South West Lincolnshire NHS Clinical Commissioning Group Business Continuity Policy

How to Design and Implement a Successful Disaster Recovery Plan

Business Continuity & Disaster Recovery

NCUA LETTER TO CREDIT UNIONS

Disaster Recovery. Stanley Lopez Premier Field Engineer Premier Field Engineering Southeast Asia Customer Services and Support

Company Management System. Business Continuity in SIA

Business Continuity Management Planning Methodology

Creating a Business Continuity Plan

Coping with a major business disruption. Some practical advice

ISO 22301: Societal Security Terminology ISO 22313: BCMS Guidance ISO 22398: Exercises and Testing - Guidance

THE PROCESS APPROACH IN ISO 9001:2015

D2-02_01 Disaster Recovery in the modern EPU

Overview of Business Continuity Planning Sally Meglathery Payoff

Business resilience: Providing targeted resilience solutions for the enterprise

BUSINESS CONTINUITY POLICY

Information Technology Project Management (ITPM)

Disaster Recovery Planning

MS Planning and Designing a Microsoft Lync Server 2010 Solution

Enhanced resilience for major emergencies Proven capability solutions to deliver the resilience you need

Beyond Disaster Recovery: The Business Resilience Transformation Methodology

Transcription:

IBM Global Services IBM s Approach to Disaster Recovery and Business Continuity Lausanne, May, 2008 Gérard Vanel, IBM certified Managing Consultant IT infrastructure, BCRS Integrated Technology Services

Gérard Vanel IBM certified Managing Consultant, IT infrastructure, Multi-industry Profile Gérard Vanel is a IBM Certified Managing Consultant within IBM Switzerland ITS, focusing on Business Continuity and Recovery Services and IT infrastructure consulting in multi industry sectors. He as over 24 years of experience in the IT business including 17 years in IT architecture on project such directories design & implementation for worldwide project and 6 years in IT consulting with BCRS and IT infrastructure consulting projects for bank, communication and food industrial sector. Professional Experience Managing & Senior Consultant Performed various projects for large international companies, BCRS, working in ITIL implementation processes projects, system management consolidation, IT optimization, service delivery reorganisation, companies IT mergers. Senior IT Specialist Recognized as architect for various directories Microsoft Active Directory, Novell NDS environments projects for companies at Worldwide, EMEA, country and local levels. Instructor For 7 years, teaching in the IT community. CV G.Vanel

The objective of this presentation is to introduce IBM approach in regard to disaster recovery. Objectives Present Business Continuity and Recovery Services (BCRS) Methodology 3

Reaching your Business Resilience goals involves choosing viable security, availability, and continuity solutions based on business needs. Different BCRS modules exists to reach the goal but what are their meaning? 4

An effective recovery solution must fully support the requirements of the business. In order to insure that the solution is aligned with those requirements. This lifecycle is based on the IT Service Management process (ITIL, ITPM) 5

Initiate the project Define scope of the project, staff, organization, and methodology. Allocate resources in ad equation with project scope. Build a project plan and agree on goals. 6

Business Impact Analysis 1. Vital Business Processes and supporting applications. 2. Maximum tolerable outage 3. Data vintage requirements 4. Financial Impact 5. Impact intangible 6. Definition of a disaster for the company 7

The objective is to quantify the impact on Client resulting directly or indirectly from a disaster. Each business process is assessed. gandalf dialin 3174 7171 3174 3725 Accounting Budget Locals WANG S/9000 Links to DEC IDNX/20 Dial RJE Corporate Accounting World Wide Procurement Human? Resources Operations Manufacturing Assumptions The following assumptions and guidelines were used when conducting this study and while analyzing the data gathered: 1) A major disruption of the Information Technology systems has occurred at your location and all computer systems will be unavailable for up to thirty days. 2) Due to the outage, all network data lines are inaccessible. 3) Assume that this event happens at "your" worst time of the year, quarter, month, etc. 8

Impact tangible and intangible are also evaluated Index Relationships with transport providers Work load fluidity of work Impact on donors loss of market share Credibility Litigation Regulatory Compliance Index Fines, Penalties Organization image Employee morale Data integrity Quality of Service to member states, donors, partners 0 20 40 60 80 100 120 140 9

Business Impact analysis outcome (1of2) 10

Application prioritization (2of2) Applications can be classified in 4 type of emergency prioritization. Classe 1 and 2 are critical for the company busines business continuity 11

Risk Assessment 8. The objective is to identify the risks that pose the gravest threat to your employees, business assets, business operations and IT Security. 9. The outcome allows an organization to measure, integrate, and consider cost effective mitigation and security efforts based on scenario. 12

4 Example: As an output of the questionnaire, the risk assessment chart show that fire, Intentional damage, carelessness, water, sabotage, technical faults and are main risks Occurence probability 1 2 3 4 5 5 Lev Risk Groups (Legend): el Fire of Imp Technical act Faults ( air-conditioning etc). 4 3 2 Level of Impact Water (water pipes, extinguisher water) Employees intentional damage, carelessness Criminal Actions (Theft, Fraud, Burglary ) Sabotage, Terror (Vandalism, occupation) Environmental Risks (Transport roads, tramlines, gaz station) Natural threats (Earthquake, flooding). Plane crash 1 13

Based on the risk assessment 3 disaster scenario are elaborated Scenario for site 1 1. Destruction of main building system room (fire, water, sabotage) 2. Destruction of annex system room (fire, water) 3. Destruction main building (fire, Sabotage) 14

Recoverability Assessment 10. The ability of the current IT to recover the business processes in the specified Return Time Objective 15

A cartography is build showing the problematic points. Recoverability capabilities are analyzed 16

Recoverability assessment facts, finding and conclusion 17

Business Continuity Startegy 11. The strategy is build based on the requirements 18

Disaster Recovery Plan 12. Disaster Recovery Plan (IT) 19

Disaster Recovery Plan support in an organized manner the company in case of a disaster Potential Loss Preventive Measures Impact Analysis Risk Assessment Strategy Selection Recoverability Assessment CONTINUITY PLAN Plan Development Test/Update/Maintain 20

Disaster Recovery Macro-Plan 21

Initial test of the Disaster Recovery Plan Initial tests. A test needs to involved all stand-by arrangements, including the recovery of business processes and the participation of external parties. This tests completeness of the plans and confirms: time objectives staff preparedness Commitment of key resources Responsiveness, effectiveness and awareness of external parties. 13. Test the DRP 22

Operations Training. Training the IT members to ensure that they have the necessary level of competence to facilitate recovery. Review Regular review of all of the deliverables needs to be undertaken to ensure that they remain current. Testing Following the initial test it is necessary to establish a test program to ensure that the critical components are tested at least annually. Change control Following tests and reviews and, there is a need for the plans to be updated. It must be included as part of Change Management. Assurance The last process in the lifecycle involves obtaining assurance that the quality of the deliverables is acceptable 23

Business Continuity Plan and Disaster Recovery Plan. Business Impact Analysis Recoverability Capabilities Risk Evaluation Disaster recovery Plan Disaster Recovery Business Continuity Plan Personnel capabilities Business Operations analysis Facilities, power Communications, analysis Business support function analysis Business Continuity Planning Business Continuity Disaster Recovery Plan The The availability availability of of IT IT services services is is required required for for the the continuity continuity of of business business processes processes The The Disaster Disaster Recovery Recovery Plan Plan is is a part part of of Business Business Continuity Continuity Plan Plan 24

IBM Global Services Thank you for your attention Gérard Vanel Managing Consultant IGS Consulting gva@ch.ibm.com Integrated Technology Services

Contact Gérard Vanel Managing Consultant Certified Professional IBM Global Business Services IBM Suisse Chemin de Blandonnet 8 Mobile No:+41 79 4482741 CH-1214 Vernier E-mail:gva@ch.ibm.com Switzerland 26