University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems 4/6/2004 1



Similar documents
PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Business Continuity Management

Developing a Business Continuity Plan... More Than Disaster

Business Continuity Plan

Disaster Recovery Journal Spring World 2014

Business Continuity Planning (800)

William Rider Manager Disaster Recovery & Data Security The Johns Hopkins Health System & University

Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.

Fundamentals of Business Continuity Planning Have a Plan!

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four

Unit Guide to Business Continuity/Resumption Planning

Desktop Scenario Self Assessment Exercise Page 1

Business Continuity and Disaster Recovery Planning

Temple university. Auditing a business continuity management BCM. November, 2015

a Disaster Recovery Plan

Consider the cash demands of a financial institution's customers; Anticipate funding needs in late 1999 and early 2000;

By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd

Business Resiliency Business Continuity Management - January 14, 2014

PBSi Business Continuity Planning

Leveraging the IT Service Continuity Management framework Gord Novoselnik Business Continuity Office Enterprise Solutions Division

CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

Western Intergovernmental Audit Forum

Preparing for the Worst: Disaster Recovery and Business Continuity Planning for Investment Firms An Eze Castle Integration ebook

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Three

SCADA Business Continuity and Disaster Recovery. Presented By: William Biehl, P.E (mobile)

Disaster Recovery Plan The Business Imperatives

Principles for BCM requirements for the Dutch financial sector and its providers.

DISASTER RECOVERY PLANNING FOR CITY COMPUTER FACILITIES

Success or Failure? Your Keys to Business Continuity Planning. An Ingenuity Whitepaper

Proposal for Business Continuity Plan and Management Review 6 August 2008

Overview of how to test a. Business Continuity Plan

Why Should Companies Take a Closer Look at Business Continuity Planning?

DISASTER RECOVERY PLANNING GUIDE

How to measure your business resiliency

Business Continuity Management

Overview TECHIS Manage information security business resilience activities

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard

GETTING STARTED WITH DISASTER RECOVERY PLANNING

The Shift Cloud Computing Brings to Disaster Recovery

NIST SP , Revision 1 Contingency Planning Guide for Federal Information Systems

Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

Audit of the Disaster Recovery Plan

Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015

Beyond Disaster Recovery: Why Your Backup Plan Won t Work

Top 10 Disaster Recovery Pitfalls

The PNC Financial Services Group, Inc. Business Continuity Program

Contingency planning. DAU Marts 2013

THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST. Business Continuity Plan

University of Ulster Policy Cover Sheet

IT DISASTER RECOVEry

Business Continuity Planning: Bridging the Gap Between IT and Business

Business Continuity and Disaster Recovery Planning from an Information Technology Perspective

The Business Continuity Maturity Continuum

Disaster recovery strategic planning: How achievable will it be?

Disaster Recovery Planning. By Janet Coggins

Ohio Conference for Payroll Professionals Disaster Recovery

NHS 24 - Business Continuity Strategy

Business Continuity and Disaster Planning

BUSINESS CONTINUITY PLANNING GUIDELINES

Some companies never recover from a disaster related loss. A business that cannot operate will lose money, customers, credibility, and good will.

BCP and DR. P K Patel AGM, MoF

Protecting Your Business

Virginia Commonwealth University School of Medicine Information Security Standard

Yale University Business Continuity Planning (BCP) Quick Start Guide

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006

Midsize Enterprise Summit Business Continuity Questions

This is the third and final presentation on HIPAA Security Administrative Safeguards. This presentation focuses on the last 2 standards under the

ACTUALLY TEST YOUR PLAN. Disaster Recovery using Shadow Protect. March Madness Lunch & Learn. 1 AGENDA

PARKES SHIRE COUNCIL BUSINESS CONTINUITY POLICY

Table of contents. Maintaining Continuity of Operations with a Disaster Tolerance Strategy

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

Attachment to Data Center Services Multisourcing Service Integrator Master Services Agreement

FINRMFS9 Facilitate Business Continuity Planning and disaster recovery for a financial services organisation

Best Practices in Disaster Recovery Planning and Testing

Documentation. Disclaimer

The Disaster Recovery Self-Assessment Guide and Validation Model. Jim Kates Cognizant Technology Solutions

Disaster Recovery and Business Continuity Plan

NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00)

2014 NABRICO Conference

State of South Carolina Policy Guidance and Training

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

Broadridge Business Process Outsourcing, LLC Business Continuity Plan Disclosure

TO AN EFFECTIVE BUSINESS CONTINUITY PLAN

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

Business Continuity Planning. Presentation and. Direction

The Difference Between Disaster Recovery and Business Continuance

Best Practices in Healthcare IT Disaster Recovery Planning

Business Continuity Glossary

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

2015 CEO & Board University Taking Your Business Continuity Plan To The Next Level. Tracy L. Hall, MBCP

Business Continuity Part 2 Converting Risk Assessments to Risk Mitigation Activities to Business Recovery Plans

Disaster Recovery Plan Review Checklist. A High-Level Internal Planning Tool to Assist State Agencies with Their Disaster Recovery Plans

CIS 523/423 Disaster Recovery Business Continuity

Operational Continuity

AUDIT REPORT INTERNAL AUDIT DIVISION. Audit of business continuity and disaster recovery planning at UNON

Business Continuity Planning Toolkit. (For Deployment of BCP to Campus Departments in Phase 2)

Justifying an Investment in Disaster Recovery

Transcription:

University of Michigan Disaster Recovery / Business Continuity Administrative Information Systems. 1

Michigan Administrative Information Services (MAIS) MAIS is responsible for the production support of information technology systems that support the university s mission-critical business processes. Disaster Recovery / Business Continuity Officer 2

History of Disaster Recovery 1950s: off site storage of critical hardcopies 1960s: periodic file backups stored off site 1970s: regular back up and off site storage 1980s: use of alternate sites 1990s: network recovery planning 3

Today: Enterprise-wide Contingency Planning Critical business processes Dependence on systems / internet Facility recovery requirements Reduce outage time Ensure Recovery Point Objective (RPO) 4

Project Background From 1996 2001, the university converted almost all of its major administrative systems to new software applications running in a new technical infrastructure A plan did not exist for restoring the new environment Executive office issued the mandate for a disaster recovery / business continuity project 5

BCP Objectives Protect staff ensure safety with fire alarms & extinguishers, security, training, etc. Avoid systems disruptions identify failure modes or weaknesses; Raise awareness Safeguard systems assets items that generate direct benefits or they add value by supporting other assets Minimize confusion / miscommunications locating and contacting personnel; Predetermined meeting place 6

Priorities Reduce exposure Determine business needs Set long-term goals and priorities 7

Standard Business Continuity Planning Steps Risk assessment: understand threats and risks Business Impact Analysis (BIA): understand impact to business in lost income, image, etc. Mitigate risks: prevent disruptions Recover Business: Planned contingencies Resume Business: full restored business 8

Mitigate Risks: Prevent Disruptions Generator Machine room location Personnel travel 9

Recover Business: Planned Contingencies Work around processes Evaluate risks and impacts to develop scenarios Set business priorities to determine recovery order 10

Risk Management Contradictions What is the level of risk stakeholders are willing to assume? What risk is actually reduced? What budget is available? Fort Knox-like protection means high cost 11

Project Was Divided Into Three Phases Phase I, stop gap measures Phase II, implement recovery solution Phase III, test solution 12

Phase I, Stop Gap Measures Identify and apply the best value solutions to big gaps first Prioritize Hundreds of opportunities for risk reduction arise during analysis Organization must decide which of these should be implemented and in what sequence 13

Phase I, Stop Gap Measures Use existing tools, materials and staff Disaster occurs in the midst of respective, critical business cycles Nature of the disaster is unknown Duration of system outage is unknown 14

Phase I Output: Recovery Time Objective Business unit contingency plans MAIS technical infrastructure recovery plans Evaluated contingencies and timelines to derive RTO RTO used to determine recovery solution 15

Phase II, Implement Recovery Solution Select Vendor Review Risk Assessment Update plans Implement readiness preparations and procedures Develop continuous planning process 16

Select Vendor Size Stability Technology Local presence Experience in actual recoveries Range of services 17

Vendors responding to RFP SunGard IBM Various small companies 18

Vendor Size 42 locations in north America 50 mobile data centers 19

Vendor Stability 70% of NASDAQ trades flow through SunGard systems Customers include 47 of the world s 50 largest financial institutions 15 trillion dollars investment assets worldwide pass through Sungard systems daily 20

Vendor Technology 30 different technology platforms, but dependent on facility 21

Vendor Local Presence Southfield Office 22

Vendor Experience 25 years experience 1500 recoveries all successful Over 100,000 tests 23

Vendor Range of services Testing Silhouette OS Partnership with Iron Mountain Mobile recovery Professional services 24

SunGard Purchased Services Performed Information Protection Analysis Purchased Sillouette OS Assistance with technical recovery planning Purchased PreCovery software for plan management 25

Phase II, Review Risk Assessment Business Impact Analysis (BIA): Understand Impact to Business Don t collect data by unplugging equipment and monitoring the accumulation of losses! List assets, estimates of impact, likelihood and resulting exposure Compare the reduction in risk per dollar spent for each measure, giving relative value to the business and a basis for comparison 26

Phase II, Blackout of 2003 and BIA 50 million people / 9,300 square miles Students Research Visitors Personnel 27

Phase II, Blackout Lessons Learned Be prepared Involve sr. Management in planning Communicate have clear decision making authority Practice 28

Phase II, Update plans Tech recovery Business continuity develop MAIS business continuity 29

Phase II, Continuous Planning Plan maintenance New products and services - sometimes at reducing cost Many services are contracted - improved terms can frequently be negotiated Budgets are set according to stakeholder perception of the risks - continual awareness Align budget with expectations 30

Phase III, Testing Plan effectiveness Metrics Enterprise operations Contingency planning 31

Approach Planning With a Sense of Urgency Higher user demands / dependence on technology Enterprise wide planning Understand business impact Critical business processes Reduce outage time Ensure Recovery Point Objective (RPO) 32

Remain Focused On solutions not scenarios On business dependence on systems / internet On recovery requirements RPO, RTO On filling big holes first 33

Next Steps University shared recovery solution 34