6. System Disruption/Resolution Flashcards
What kind of disasters are there?
- Natural: earthquakes, floods, tornados, fire
- Unintentional human: loss of power, telecommunications, delivery, gas leak
- Intentional human: terrorist attacks, hackers, viruses, vengeful employees
What are example of vendors for data back up and recovery?
- DEVSource
- Rackspace Hosting
- Kaufman/Rossin
Disaster recovery planing: what must be determined beforehand and how is it determined?
- If disruption - recovery point objective - acceptable data loss recovery time objective - acceptable does time.
- Determined by; criticality of application, cost, time to recover, security
- Contracting - complex and important
Disaster recovery: what are back up facility types?
- Cold site: no computers ($)
- Warm site: computer no data ($$)
- Hot site: everything ($$$)
- Mirrored site: fully redundant ($$$$)
- Reciprocal agreement ($?$)
Disaster recovery: what is cold site?
- Off-site location with electrical and other physical requirements for processing
- No equipment or files (added when needed)
- 1-3 days start-up
- Cheaper
Disaster recovery: what is warm site?
- Off-site location with similar computer hardware
- Does not include backed-up data (delivered when needed)
- More $
Disaster recovery: what is hot site?
- Completely equipped including data
- Near-immediate (within hours) operation
- Big $$$ (e.g. medical, credit card systems)
Disaster recovery: what is mirrored site?
- Fully redundant, fully staffed, fully equipped
- Real-time replication of mission critical system,s
- e.g. credit card processing
Disaster recovery: what is reciprocal agreement?
- Mutual aid pact
- Agreement between 2 or more organizations to aid each other with data processing if disaster strikes
- May be cold, warm, or hot
What are the purposes of organizational continuity planning (OCP)?
- Identify and plan for disruptions
- Integrate into business culture
- Recall risk management lesson/discussion (CGIC) - Interate OCP into risk management
What is BRM or ORM?
Business risk management / Organizational risk management
What is BCP or OCP?
Business continuity planning / Organizational continuity plan
*Process of risk assessment, contingency planning, and long-term continuity maintenance
What is BIA?
Business impact analysis: Risk analysis portion of BCP.
*Identifies maximum tolerable interruption periods of an organization by function and activity to assess risk importance and consequences.
What are 6 steps of OCP and BCP?
- Create a OCP policy and program
- Determine critical functions/business risks
- Determine continuity strategies
- Develop and implement BCM response
- Exercise, maintain, and update plan
- Embed BCP plan into the culture
What is incident management?
Map level of incidents to events to responses.
- E.g. 0=negligible event (e.g. power spike), 7=crisis (pandemic virus and World Trade Center attack)
- Responses mapped to level of incidents
What are 3 important functions of an organization?
- Mission critical: customer facing services, manufacturing, financials
- Business critical: ERP systems, payroll, order entry
- Task critical: print service, file service
Backup plans: What does an organization want to recover from?
From equipment failures, power failures and errors.
Backup plans: what should be done?
- Maintain at least one remote archive off-site
* Use redundant (multiple) backups (the “Whack-a-Mole” plan)
Backup plans: what are 8 control principles?
- At least one off-site archive
- Controls over storage libraries mirror those for data processing sites
- Many organizations outsource - choosing a vendor, consider availability, standardization, capacity, speed, and price
- Backup procedures may be full (all data), increment (data changed from a certain time) or differential (data changed since the last full backup)
- Maintain inventory of backups that identifies data set name, volume serial number, data created, accounting period, and storage location (e.g. bin)
- Consider privacy, security and confidentiality of the data (e.g. HIPPA)
- Restoration procedures integrated into organization’s continuity plan (OCP)
- Backup and restoration procedures regularly tested and reviewed
What is a backup procedure: archive procedures - old school?
“Grandfather, father, son” system:
- son - newest
- father - one generation
- grandfather - two generations
- Mostly related to batch processing