Week 6 Flashcards
When did Business Continuity Management become important?
Mainframe era because if one part of the business that was connected to the mainframe was compromised, it could threaten other parts of the business.
Periodic backups of the mainframe were needed.
Where did disaster recovery come from?
Bringing systems back.
Why is a business impact analysis conducted?
To identify the critical processes. These need to be back up and running ASAP. It should be the actual impact on the business if a process is down.
What are 5 recovery requirements?
1) Time - what sort of time window do you have in terms of permitted loss? is it okay to lose 2 days of customer transactions or is it okay to lose 12 days? Is this a compliance issue or how do we determine this?
2) Utilisation of occupancy of redundant resources- we may invest in infrastructure or additional resources to support recovery and business continuity. But this costs money.
3) Geography - if we have a call centre in Spain and we have to have a backup in another country, we have to assume that we have the sufficient resources to support this (are there enough trained staff to transport stuff to this country?)
4) Facilities - what’s required to complete and conduct critical business processes?
5) Assets - what are the important assets to the organisation?
What are the four types of Contingencies?
1) Internal contingencies - least riskiest option since you can see what you’re investing in.
2) External contingencies - redundant resources that can be sold several times over. Good at keeping the cost down. Bad if lots of companies are facing the same problem at the same time (because lack of supply from the provider).
3) Mutually assured - you might agree with a similar provider in a particular situation. Agreements should be formalised by both parties.
4) Displaced activity - staff could be distracted from their day job which is supporting important or critical processes and focusing on redundant resources.
5) Reactive contingencies - this may be a cost you’re going to incur
What are two types of alternatives to contingencies?
Restoration and salvage
What is business impact analysis?
It is not the motivation for BCP but should happen before BCP happens. Benchmark for financial and non-financial losses that justify contingency plans. What processes need to be up and running ASAP for the organisation?
What does a business impact analysis comprise of?
1) Scope - determining the scope fo the business impact analysis. What is the period of disruption? What’s the impact?
2) Data collection - often every process is important in the business. Trying to understand effectively what are the critical processes. You need to be careful as you don’t want to disgruntle any employees if they feel their processes are not as important.
Processes that ensure compliance are likely to become of prime focus because you can’t break the law in the enterprise. Prioritise critical business processes during a period of disruption, but secondary processes will end up being a backlog of processes.
Metrics to do with time are very important in data collection.
3) Moderate - Information gathered needs to be considered and analysed. Determine the validity of claims made by various business units in terms of op requirements
4) Report - report back to the management team the business impact analysis.
What is the recovery time objective (RTO)?
The window of time from failure to recovery before business units are considerably impaired. Works in conjunction with the MTPOD. We don’t want to RTO to be greater than the MTPOD.
What is the maximum tolerable period of downtime (MTPOD)?
The period of time from failure to recovery before an enterprise is enduringly damaged.
What is the recovery point objective (RPO)?
The period of time of permitted loss
What is data deduplication?
A process of reducing redundant data at rest and in transit. Can be considered in terms of files or blocks.
What is the challenge with compression?
We can choose a compression algorithm to fit more on the device (makes the file smaller) but this reduces the quality as we remove redundant or less important data. Need to choose what to make redundant without reducing too much the quality.
How do we consider data deduplication in terms of files?
Two files may have different names but the same content (i.e. the same binary data). We should store just one file of binary data rather than multiple files, and point to it.
How do we consider data deduplication in terms of blocks?
If we have different versions of eg a film, a large part of these films will be the same and have the same blocks of binary data. We can consider the files as blocks of binary data that you identify and store one copy of the binary data and you point all the other duplicates to this original block.