Business Continuity Planning: Bridging the Gap Between IT and Business



Similar documents
A BCP Tale: From Theory to Practice

Tips and techniques a typical audit programme

Business Continuity Planning (800)

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

Business Continuity and Disaster Recovery Planning

Disaster Recovery and Unstable Furniture

Business Continuity Management

Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).

An Introduction to. Business Continuity Planning

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1

Business Resiliency Business Continuity Management - January 14, 2014

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

Disaster Recovery Planning

PARKES SHIRE COUNCIL BUSINESS CONTINUITY POLICY

The ABC s of BCP. Jeremy Sucharski Governance Risk and Compliance G31

Business Continuity. Port environment

Implementing and Auditing a Successful Business Continuity Plan

How to Plan for Disaster Recovery and Business Continuity

BC / DR Implementation Tying Disaster Recovery Investment to Measurable Business Value

Business Continuity Plan

BCP and DR. P K Patel AGM, MoF

SCADA Business Continuity and Disaster Recovery. Presented By: William Biehl, P.E (mobile)

Information Technology Continuity Uncensored IIA Dallas Chapter October Monthly Meeting

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

NEEDS BASED PLANNING FOR IT DISASTER RECOVERY

BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION

Disaster recovery strategic planning: How achievable will it be?

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

9/3/2009. Information Systems Disaster Recovery. Learning Objectives. Why have a plan? unexpected? APPA-Institute for Facilities Management

Taking a Proactive Approach to Crisis Management while Maintaining Business Continuity in a Tiered Environment

Contingency Planning Guide

Fundamentals of Business Continuity Planning Have a Plan!

Business Continuity Management

Business Continuity Planning and Disaster Recovery Planning

Business Continuity & Recovery Plan Summary

How to measure your business resiliency

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

CISM Certified Information Security Manager

How to Design and Implement a Successful Disaster Recovery Plan

Best Practices in Developing an IT Disaster Recovery Plan. Vijaykumar Kulkarni AGM Product Management

Domain 3 Business Continuity and Disaster Recovery Planning

NAVIGATING THROUGH A CATASTROPHIC DISASTER:

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

DISASTER RECOVERY Steps You Need to Take (Before It s Too Late)

Why Use Business Continuity Management Software? Bratislava, Slovak Republic Steve Kokol Vice President of International Sales.

Why Should Companies Take a Closer Look at Business Continuity Planning?

Building a Disaster Recovery Program By: Stieven Weidner, Senior Manager

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four

Disaster Recovery Planning Procedures and Guidelines

Business Continuity Planning Instructions

Ohio Conference for Payroll Professionals Disaster Recovery

Some companies never recover from a disaster related loss. A business that cannot operate will lose money, customers, credibility, and good will.

Security Architecture. Title Disaster Planning Procedures for Information Technology

Disaster Recovery and Business Continuity Plan

Business Continuity & Recovery Plan Summary

Application / Hardware - Business Impact Analysis Template. MARC Configuration Requirements. Business Impact Analysis

EXECUTIVE CRISIS MANAGEMENT TRAINING. Presented by Roseanne Rostron, CBCP Raido Response

Temple university. Auditing a business continuity management BCM. November, 2015

NIST SP , Revision 1 Contingency Planning Guide for Federal Information Systems

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015

Overview of how to test a. Business Continuity Plan

Plan Development Getting from Principles to Paper

Business continuity management policy

Q uick Guide to Disaster Recovery Planning An ITtoolkit.com White Paper

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

How to write a DISASTER RECOVERY PLAN. To print to A4, print at 75%.

Evaluating and Improving Your Business Continuity Plan

Staying In Business. A Business Continuity White Paper by. Paul O Brien and Gerard Joyce. LinkResQ Limited

DRAFT Disaster Recovery Policy Template

Business Continuity, Risk Management & Pandemic Planning

State of South Carolina Policy Guidance and Training

Don Stewart, MBCP, MBCI, CCP

Preparing for the Worst: Disaster Recovery and Business Continuity Planning for Investment Firms An Eze Castle Integration ebook

(Instructor-led; 2 Days)

> State Street. Corporate Continuity Program. Continuity Organizational Structure. Program Oversight

Protecting Your Business

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

CRISC Glossary. Scope Note: Risk: Can also refer to the verification of the correctness of a piece of data

BUSINESS CONTINUITY PLAN OVERVIEW

Business Continuity and Emergency Preparedness Planning. Vandita Zachariah, MA, MBA, CIA HHSC Internal Audit Division May 21, 2010

CRR Supplemental Resource Guide. Volume 6. Service Continuity Management. Version 1.1

How To Manage A Disruption Event

a Disaster Recovery Plan

The Government Cloud Protection Program: Disaster Recovery Services Transformed for the Perfect Storm

Desktop Scenario Self Assessment Exercise Page 1

Appendix 3 Disaster Recovery Plan

GETTING STARTED WITH MANAGED SERVICES

Developing a Business Continuity Plan... More Than Disaster

Best Practices in Disaster Recovery Planning and Testing

Contingency planning. DAU Marts 2013

Business Continuity Management Software

Western Intergovernmental Audit Forum

Overview Of Emergency Management Exercises

Business Continuity (Policy & Procedure)

Avoiding Disaster. A Practical Guide for Backup Systems & Disaster Recovery Planning

Disaster Recovery Journal Spring World 2014

CISM ITEM DEVELOPMENT GUIDE

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

Metro Business Continuity and Disaster Recovery Plan Response to vendor questions RFP

DESIGNING A BUSINESS CONTINUITY TRAINING PROGRAM TO MAXIMIZE VALUE & MINIMIZE COST

Transcription:

Business Continuity Planning: Bridging the Gap Between IT and Business Steve Burns, President EverGreen Data Continuity, Inc. sburns@evergreen-data.com 1

The Hard Facts One-third of businesses don t include a recovery sequence for business functions.... META Group Nearly half of the organizations that lose data as a result of a disaster never re-open and are out of business within 2 years... University of Texas, Center for Research on IS 2

Why Do Plans Fail? The answer is in the question It s a plan, not a program Programs are living and threaded throughout the organization The wrong recovery strategy was chosen It worked for IT, but not the business The technology in the plan is no longer used 3

Continuous Operations vs. Disaster Recovery Disaster recovery is traditionally an IT responsibility Covered IT infrastructure and network communications Business functions require continuous operations How do you bridge the gap? 4

Work Backwards Throw out the traditional way of thinking First Define business requirements and priorities Then Map requirements to infrastructure that supports it applications, systems, voice, networks, data center as an entity 5

How? Conduct a BIA independent of the IT staff BIA from a financial standpoint is only half the story Outage Tolerance Operational Dependency 6

The Business Perspective Get the business perspective on IT usage Perform functions Create critical prioritization of assets and IT infrastructure based on business need Viewpoints Financial Tolerance Dependency 7

IT Recoverability Conduct a Risk Assessment independent of the business staff Review all applications, systems, data centers, storage, high availability, security and disaster preparedness Define true recoverability of the IT infrastructure 8

There is a GAP! Most organizations have a tremendous gap between the time business units say they need critical functions live and how fast the IT staff says they can actually recover the functions. 9

How Do You Close the Gap? Set up a Recovery Task Force Business leaders that identify critical resources, assets and priorities IT leaders that identify system requirements and recovery procedures for critical systems Responsibility to identify interdependencies and their links Reports must outline 4-5 levels of priority 10

Defining Interdependencies Two-Phased Approach Business Process Dependencies Matrix Functions, not departments Two-way dependency IT Dependencies Matrix Recovery procedures of each system, application Two-way dependency 11

Business Continuity Planning Matrix Business Recovery Needs IT Recovery Needs Aligned by RTO and RPO 12

Formulating Recovery Strategies Multiple options hot site, cold site, internal, etc. Blend of: Best technological solution to close the gap from an IT perspective Solutions within budget constraints Close the GAP as much as you can in Year 1 of a 3 year plan to mitigate your risks 13

Business Continuity Planning Goal is to provide an actionable and streamlined Business Continuity Plan for the recovery of business operations and supporting IT Define all organizations, locations, applications, systems, assets Define recovery team structures and responsibilities 14

Business Continuity Workshop Introduce the program to business leaders Business units begin to formulate continuous operation procedures Review recovery procedures with individual business units 15

IT Workshops Introduce project to IT participants Formulate recovery procedures for applications, servers, networks, etc. Review recovery procedures with individual IT participants 16

Emergency Management Workshop Define emergency management team hierarchy Command center procedures Incident response procedures Recovery site activation procedures Communications plans Transportation plans Continuous operation management 17

Final Planning Pieces Develop change management process from an enterprise perspective Assist with management program approval and buy-in Integrate the plan with current business processes 18

Your Business Continuity Plan Chapter 1 BCP Overview Chapter 2 Potential Impacts Chapter 3 Recovery Phases & Organization Chapter 4 EMT and DRC Recovery Team Tasks Chapter 5 IT Recovery Plans Chapter 6 Business Unit Recovery Plans Appendices detailing Command Centers, Contact Lists, Recovery Requirements, Emergency Plans and a Glossary of Terms 19

Plan Testing Disaster simulation and workgroup recovery done together Identify test objectives for IT and business units Document post test report 20

Plan Maintenance Develop programs for all components in program, including risk assessments, BIA, plans and testing Teach BCP Coordinator and other critical staff to successfully manage, update and maintain the overall program 21

Critical Responsibilities Business Unit and IT Leaders (at least one per unit) Provide documentation Attend workshop(s) Define continuous operations for critical processes Manage tasks/responsibilities related to program Timely information turnaround Plan reviews/tabletop exercise Incorporation of change management 22

Pain Points Communication is Key Project Manager and Project Coordinators Lack of Understanding Why are you here, why do you want to know? Timeliness of turnaround When do you need this by? Process, Process, Process Standardize on all data output across the organization Tread Lightly Know your audience Experience Sometimes it s what they don t say 23

It s Easy if You Know How To... Communication is Key Weekly/bi-weekly scheduled reviews Lack of Understanding Pre-engagement summaries and notification schedules Checklists Timeliness of turnaround Defined escalation processes Process, Process, Process Standardize data gathering, analysis and reporting Tread Lightly Coordination of resources with project and unit coordinators Experience Create the best team possible 24

Recipe for Success Internal Software to manage the program Business Continuity program manager Business Continuity Planner 1-2 Administrators for program Internal sponsor from management Or Outsource the entire program to Experts Software Program Management Planners and Administrators at Your Location Monthly Managed Service Fees 25

26