Business Continuity Flashcards
BCP
BCP: Is concerned with keeping critical business services running throughout and after a disaster has struck.
BCP Subplans
BRP: Business Recovery Plan
DRP: Is concerned with immediate and temporary restoration of critical business functions. Short term and tactical regarding IT systems
COOP (Continuity of Operations Planning): strategic function at alternate site
Phases of Business Continuity Planning
Phases of Business Continuity Planning • Project Initiation-Scope the project • Business Impact Analysis • Identify preventative controls- prevent events from occurring; improves security • Recovery Strategy • Plan Design & Development • Implementation • Testing • Maintenance
Project Initiation Steps
Project Initiation Steps
• Establish need for BCP- establish business contingency policy statement
• Obtain management support- C-level management needed
• Select team Members-
o project manager (must have negotiation/people skills);
o CPPT (Continuity Planning Project Team) made from stakeholders (HR, IT, PR, mgrs) needed for critical business functions
Scoping Project
• ID what assets will be protected
• ID emergencies
• ID resources required
• Determine objectives and deliverables
Purposes of a Business Impact Analysis
Purposes of a Business Impact Analysis: (analyzing all business functions to determine the impact of a disruption)
• Identify and prioritize all business processes
• Document the impact of outages
• Identify concerns if operation is degraded
• Analyze outage impact
• Determine recovery windows (for each business function)
Steps of a Business Impact Analysis
Steps of a Business Impact Analysis: • Identify and prioritize all business processes- BIA and critical state asset list for every IT system • Conduct BCP-focused risk assessment- vulnerability analysis for each system; then risk BIA Metrics to use: o SLO o MTD or MAD o RTO o WRT o RPO o MTBF o MTTR o MOR o System Criticality
MTD
MTD (Maximum Tolerable or Allowable (MAD) Downtime) = RTO + WRT; The maximum time a business function can be down before the business fails.
SLO
SLO (Service Level Objectives)
RTO
RTO (Recovery Time Objective)- the maximum time allowed to recover system
WRT
WRT (Work Recovery Time)- time to configure a recovered system
RPO
RPO (Recovery Point Objective)- amount of data loss or system inaccessibility that an org can withstand (determines backup, etc)
MTBF
Mean Time Between Failure (MTBF): == component quantity X days X hours/day
MTTR
Mean Time to Repair (MTTR)- how long to repair
MOR
Minimum Operating Requirements (MOR)
System Importance
System Importance- how relevant the system is for the business (e.g. auditing)