5 - 4: Disaster Recovery Flashcards
Disaster Recovery
Designed to restore a business as quickly as possible
Disaster types
Environmental or human
Disaster sources
Internal or external
Communication
Initial activation, status updates, tactical
Basic steps
Contain, recover, triage
Recovery time objective
Target time to restore a service to operation
Recovery point objective
Maximum time period from which data may be lost
Recovery service level
Percentage of a service that must be available
When does recovery end?
When operations are restored to %100
Backup media
Tape, disk-to-disk, write to cloud
Backup types
Full, snapshot, differential, incremental
Full backup
Complete copy of the data
Snapshot backups
Quickly created point-in-time
Differential
Backups of data that changed since the last full backup
Incremental
Changes since last full OR incremental
Backups are most commonly restored because of….
Human or technical error
Non-persistence
Back up only unique data
Live boot media
Using a device to run software, able to recover data from a device with a corrupted operating system
Disaster recovery site
Alternate data processing facility
Hot sites
Fully operational data centers with continuous operation and equipment and data present. Can activate at a moment’s notice
Cold sites
Stacked with core equipment, networks, and environment, but takes a long time to activate for resumed use
Warm sites
Stacked with all needed equipment and data, not maintained in parallel
Offsite storage
Keep geographically distant to avoid the same risks, manual transfer or site replication to maintain data (SAN or VM)
Testing goals
1) Validate that the plan functions correctly
2) Identify necessary updates
Types of testing
Read-through, walk-through, simulation, parallel test, full-interruption test
Read-through
Ask each team member to read the plan and provide feedback/review procedures
Walkthroughs
Everyone reads through the plan at the same time AKA tabletops
Simulation
Uses a practice scenario with the entire recovery team
Parallel test
A simulation including activation of the DR plan itself, activating the recovery environment but not switching operations
Full-interruption
Switching operations to the alternate environment and attempt to recover from it
After action report
A formal review of every BC/DR event. Should be written after every event, even if successful
Executive summary
Written in an AAR assuming the reader will only read that section
AAR components
Versions, external factors, other variables, summary of facts leading into the event, 5 W questions, lessons learned section, conclude with clear next steps