Video Content Lesson 6 Flashcards
Business Continuity Plans (Project Scope)
Industry and Professional Standards Legislative Compliance Overview Organization Analysis Planning Team Resource Requirements Legal Requirements
Industry and Professional Standards
National Standard on Preparedness (NFPA 1600)
ISO 17799 (Comprehensive set of controls comprising best practices in Information Security)
DSS (Defense Security Service) (Personnel Security Investigation, Industrial Security, Security Education)
NIST (National Institute of Standards and Technology)
Good Business Practice and Standard of Due Care (what would a reasonable man do under normal circumstances?)
Legislative Compliance
HIPAA (Health Insurance Portability and Accountability Act) (document retention, mandatory document destruction)
GLB (Graham-Leach-Bliley) (protect customer information from any anticipated threats or hazards)
Patriot Act (several sections that require information be available when required)
International Regulations
Industry Regulations and Requirements
Overview
Business Continuity Plan (BCP)
Ensures business can continue in the event of an interruption
4 Distinct Phases of BCP
1-Business Organization Analysis
2-Planning Team
3-Required Resource Assessment
4-Legal and Regulatory Resource Requirements
Organization Analysis
Understand business and business practices
1-Critical Business Functions
2-Tangible and Intangible Value
Identify All Stakeholders in Business Continuity Plan (Operational Departments, Critical Support Services, Senior Executives)
Planning Team
Involve personnel from various levels and areas in the organization
Consider representatives from (Core Services Departments, Critical Support Departments, IT Department, Security Department, Legal Department, Upper Management (requires support from them for time committments, interruption of regular service, budget))
Resource Requirements
Planning team must fully consider all required resources
Budget to purchase resources (Time requirements)
BCP testing, training, and maintaining phase (may require substantial equipment purchases)
BCP Implementation (to enforce business continuity because it has been interrupted)
Legal Requirements
Legal requirements may supersede business requirements
BCP may be required to be maintained according to published standards
Business may have contractual obligations to customers
BCP may be a contract stipulation
A sound BCP may satisfy due care and due diligence requirements
Business Impact Analysis
Overview Interruption Resource Prioritization Continuity Strategy BCP Approval
Overview
Identifies Critical resources and threats to those resources
1-Establish business priortie (Biggest business impact is top priority)
2-Risk assessment (identify and categorize risks, quantify as much as possible)
3-Identify Alternative means (can business be done a different way)
Interruption
Loss of revenue/profits (some losses may be unrecoverable)
Loss of reputation (can customers trust be recovered?)
Legal or regulatory violations (penalties could be severe)
Resource Prioritization
Business Unit Priorities (What business functions are the most important?)
Allocate BCP budget to most severe risks first, then countinue dow the prioritized list
Consider both qualitative and quantitative risk priority rankings
Continuity Strategy
BCP team establishes procedures to protect provisions and processes (People are highest priority-no exceptions) (protect and provide for their immediate needs)
Building and facilities (protect facilities or offer alternatives)
Infrastructure (communications, protect and provide alternatives)
BCP Approval
Put BCP together
Document BCP
Submit BCP for approval (ensure upper MGT fully endorses the plan)
Implement the BCP (Put all controls in place, Acquire and install any necessary hareward and software)
Train BCP participants
DRP Planning and Recovery
Overview Identification Crisis management Recovery Data Center Alternatives More Alternatives Processing Agreement