Lecture 11 Notes Flashcards
Business Continuity Planning (BCP)
focuses on maintaining business operations with reduced or restricted infrastructure capabilities or resources
As long as the continuity of the organization’s mission-critical tasks is maintained, BCP can be used to manage and restore the environment
Disaster Recovery Planning (DRP)
If the continuity is broken, then business processes have stopped and the organization is in disaster mode
BCP Steps
1 Project scope and planning
2 Business impact assessment
3 Continuity planning
4 Approval and implementation
Step 1 – Project Scope and Planning
Business Organization Analysis
BCP Team Selection
Resource Requirements
Legal and Regulatory Requirements
Business Organization Analysis
Project Scope and Planning
analyze the business organization and identify departments and individuals who have a stake in the process
Consider
Operational departments
Critical support services
Senior executives
BCP Team Selection
Project Scope and Planning
Representatives from each of the organization’s core departments
Representatives from the key support departments
IT professionals with technical expertise in areas covered by the BCP
Security representatives with knowledge of the BCP process
Legal representatives familiar with corporate legal, regulatory, and contractual responsibilities
Representatives from senior management
Resource Requirements
Project Scope and Planning
BCP development
BCP testing, training, and maintenance
BCP implementation
Legal and Regulatory Requirements
Project Scope and Planning
Federal, state, and local laws may mandate certain elements or degrees of BCP
Step 2 - Business Impact Assessment
identifies critical resources and the threats posed to those resources
Maximum Tolerable Downtime (MTD)
The maximum length of time a business function can be inoperable without causing irreparable harm to the business
Recovery Time Objective (RTO)
amount of time in which you think you can feasibly recover the function
Goal of BCP (RTO vs MTD)
RTOs are less than MTDs
Step 3 – Continuity Planning
focuses on developing and implementing a continuity strategy
Strategy Development (Continuity Planning)
Determine which risks are acceptable vs. those that must be mitigated or otherwise addressed
Provisions and Processes (Continuity Planning)
designs the specific procedures and mechanisms that will mitigate the risks deemed unacceptable during the strategy development stage
Categories of assets
People
Buildings and facilities
Infrastructure
Step 4 - Plan Approval & Implementation
Once the BCP team completes the design phase of the BCP document, senior management must review and approve developed BCP plan
Training and Education (BCP)
Everyone in the organization should receive at least a plan overview briefing
Disaster Recovery Plan
When a disaster strikes and a business continuity plan fails to prevent interruption of business activities, the disaster recovery plan guides the actions of emergency-response personnel until the end goal is reached:
Restoring the business to full operating capacity
Disaster Recovery Strategy Subtasks
Business Unit Priorities Crisis Management Emergency Communications Work Group Recovery Alternate Processing Sites Mutual Assistance Agreements Database Recovery
Business Unit and Functional Priorities (Disaster Recovery Strategy Subtasks)
Business units and/or functions with the highest priority must be recovered first
You might find that it would be best to restore highest-priority units to 50 percent capacity
Crisis Management (Disaster Recovery Strategy Subtasks)
If your training budget permits, investing in crisis training for your key employees is a good idea
Emergency Communications (Disaster Recovery Strategy Subtasks)
When a disaster strikes, it is important that the organization be able to communicate internally as well as with the outside world
Have alternate means of communication available
Work Group Recovery (Disaster Recovery Strategy Subtasks)
When designing a disaster recovery plan, it’s important to consider the restoration of work groups to the point that they can resume their activities
To facilitate this effort, it’s sometimes best to develop separate recovery facilities for different work groups
Alternate Processing Sites (Disaster Recovery Strategy Subtasks)
Cold sites
Standby facilities large enough to handle the processing load of an organization, equipped with electrical/environmental support systems
Hot site
Backup facilities maintained in constant working order, with servers, etc.
Ready to assume primary operations responsibilities
Warm site
Similar to hot sites, but do not typically contain copies of the client’s data
Mobile site
Self-contained trailers or other easily relocated units
Service Bureaus
Companies that lease computer time
Mutual Assistance Agreements (Disaster Recovery Strategy Subtasks)
Under an MAA, two organizations pledge to assist each other in the event of a disaster by sharing computing facilities or other resources
Database Recovery (Disaster Recovery Strategy Subtasks)
Electronic vaulting
Database backups are transferred to a remote site using bulk transfers
Remote journaling
Only transfers copies of the database transaction logs containing the transactions that occurred since the previous transfer
Remote mirroring
A live database server is maintained at the backup site
Disaster Recovery Plan Development
- Emergency Response
- Personnel Notification
- Backups and Off-Site Storage
- Software Escrow Arrangements
- External Communications
- Utilities
- Logistics and Supplies
- Recovery vs. Restoration
Emergency Response (Disaster Recovery Plan Development)
contain simple yet comprehensive instructions for essential personnel to follow immediately upon recognizing that a disaster is in progress or is imminent
Often in the form of checklist
Personnel Notification (Disaster Recovery Plan Development)
A disaster recovery plan should also contain a list of personnel to contact in the event of a disaster
Backups and Off-Site Storage (Disaster Recovery Plan Development)
Access to backed up data is often essential for recovery from a disaster
Full backups: store a complete copy of the data
Incremental and differential backups: store only files that have been modified since the most recent full or incremental backup
Software Escrow Arrangements (Disaster Recovery Plan Development)
Protect against the failure of a software development contractor
Source code is held in third-party escrow
Recovery vs. Restoration
Recovery involves restoring business operations and processes to a working state
The recovery team members have a very short time frame in which to operate (MTD/RTO)
Restoration involves restoring a business facility and environment to a workable state
The salvage team has more time to work than the recovery team