ISSAP Session 7 Technology Based Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP) 21 September 2011.

Slides:



Advertisements
Similar presentations
1 The Basics of Business Continuity Presented by Mary F. Sandy, CBCP Business Continuity/Disaster Recovery Class DePaul University ©Mary F. Sandy, 2006.
Advertisements

Information Technology Disaster Recovery Awareness Program.
Creating a Data Disaster Recovery Plan. What is a DR Plan? Is your best solution to: Continuous business services Prompt and smooth recovery Prepare for.
Case Study: Business Continuity Planning for Site- Level Disaster Kimberley A. Pyles Northrop Grumman Corporation
CIOassist Technologies Your CIO on Demand… Business Continuity Planning Our Offering CIOassist Technologies (
The Arab Academy for Banking & Finance Science Faculty of Information System & Technology Department Of Management Information Systems The Disaster Recovery.
Service Design – Section 4.5 Service Continuity Management.
DISASTER CENTER Study Case DEMIRBANK ROMANIA “Piata Financiara” ConferenceJanuary 29, 2002 C 2002.
1 Disaster Recovery “Protecting City Data” Ron Bergman First Deputy Commissioner Gregory Neuhaus Assistant Commissioner THE CITY OF NEW YORK.
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP)
Business Continuity Planning and Disaster Recovery Planning
CISA REVIEW The material provided in this slide show came directly from Certified Information Systems Auditor (CISA) Review Material 2010 by ISACA.
The Business of Security Chapter 4. Building a Business Case A business exists to satisfy business objectives –Security programs are there to support.
Disaster Protection and Recovery By: Michael Morrell Ross Ashenfelter Teresa Furnish Karla Maddox.
Processing Integrity and Availability Controls
Disaster Recovery and Business Continuity Ensuring Member Service in Times of Crisis.
1 Disaster Recovery Planning & Cross-Border Backup of Data among AMEDA Members Vipin Mahabirsingh Managing Director, CDS Mauritius For Workgroup on Cross-Border.
Gulf Coast Energy International Business Continuity / Disaster Recovery Planning and Design Proposal Prepared by Andrew Rolf, Felipe Torres, Pranay Jaiswal.
Chapter 10 Information Systems Controls for System Reliability—Part 3: Processing Integrity and Availability Copyright © 2012 Pearson Education, Inc.
November 2009 Network Disaster Recovery October 2014.
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
CISA REVIEW The material provided in this slide show came directly from Certified Information Systems Auditor (CISA) Review Material 2010 by ISACA.
Business Continuity & Disaster Recovery Daniel Griggs Solutions Architect Ohio Valley September 30, 2008.
Discovery Planning steps (1)
Security+ All-In-One Edition Chapter 16 – Disaster Recovery and Business Continuity Brian E. Brzezicki.
Business Continuity and Disaster Recovery Chapter 8 Part 2 Pages 914 to 945.
Server Virtualization: Navy Network Operations Centers
Module 3 Develop the Plan Planning for Emergencies – For Small Business –
Incident Management By Marc-André Léger DESS, MASc, PHD(candidate) Winter 2008.
IS 380.  Provides detailed procedures to keep the business running and minimize loss of life and money  Identifies emergency response procedures  Identifies.
ISA 562 Internet Security Theory & Practice
David N. Wozei Systems Administrator, IT Auditor.
Business Continuity & Disaster recovery
C ONNECTING FOR A R ESILIENT A MERICA Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP) Skip Breeden.
1 Availability Policy (slides from Clement Chen and Craig Lewis)
By Srosh Abdali.  Disaster recovery is the process, policies and procedures related to preparing for recovery or continuation of technology infrastructure.
©2006 Merge eMed. All Rights Reserved. Energize Your Workflow 2006 User Group Meeting May 7-9, 2006 Disaster Recovery Michael Leonard.
Business Continuity and Disaster Recovery Planning.
Disaster Recovery and Business Continuity Planning.
INFORMATION SECURITY MANAGEMENT L ECTURE 3: P LANNING FOR C ONTINGENCIES You got to be careful if you don’t know where you’re going, because you might.
INFORMATION SECURITY MANAGEMENT L ECTURE 3: P LANNING FOR C ONTINGENCIES You got to be careful if you don’t know where you’re going, because you might.
Phases of BCP The BCP process can be divided into the following life cycle phases: Creation of a business continuity and disaster recovery policy. Business.
Risk Management CS5493. Risk Management The process of ● identifying, ● assessing, ● prioritizing, and ● mitigating risks.
National Archives and Records Administration, Preparing for the Unexpected ESSENTIAL ELEMENTS: ANALYSIS.
TIJARA Provincial Economic Growth Program Business Continuity / Disaster Recovery Planning Introduction and Workshop Outline Prepared by Larry SanBoeuf.
Key Terms Business Continuity Plan (BCP) – A comprehensive written plan to maintain or resume business in the event of a disruption Critical Process –
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
Chapter 3: Business Continuity Planning. Planning for Business Continuity Assess risks to business processes Minimize impact from disruptions Maintain.
Business Continuity Disaster Planning
DISASTER RECOVERY PLAN By: Matthew Morrow. WHAT HAPPENS WHEN A DISASTER OCCURS  What happens to a business during a disaster?  What steps does a business.
Disaster Recovery Planning (DRP) DRP: The definition of business processes, their infrastructure supports and tolerances to interruptions, and formulation.
Information Security Crisis Management Daryl Goodwin.
Business Continuity Planning 101
Planning for Application Recovery
Utilizing Your Business Continuity Plan.
CompTIA Security+ Study Guide (SY0-401)
MANAGEMENT of INFORMATION SECURITY, Fifth Edition
Business Continuity / Recovery
Security on the Move & In the Clouds
Processing Integrity and Availability Controls
Berry College Disaster Recovery Soft Exit
Audit Planning Presentation - Disaster Recovery Plan
CompTIA Security+ Study Guide (SY0-501)
Understanding Back-End Systems
1 2 Please stand by! The webinar will begin shortly.
BUSINESS CONTINUITY PLAN
Business Continuity Program Overview
Developing and testing the Plan
BUSINESS CONTINUITY PLAN
Presentation transcript:

ISSAP Session 7 Technology Based Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP) 21 September 2011

BCP & DRP Questions from Session 6 ? Prior sessions handouts are posted on www.silverbulletinc.com/DM2 Contact Shelton Lee for credentials Shelton.lee@lmco.com

Requirements Schedule – Ten Sessions 08/24/2011 Organization 08/29/2011 Access Control pg 3-62 08/31/2011 Access Control pg 62-117 09/07/2011 Cryptography pg 125-172 09/12/2011 Cryptography pg 173-212 09/14/2011 Physical Security pg 222-285 09/19/2011 Requirements pg 293-351 09/21/2011 BCP & DRP pg 357-371 Telecom pt 1 pg 379-399 09/26/2011 Telecomm pt 2 pg 399-440 09/28/2011 Review

BCP & DRP Identicication and planning for adverse events Once identified, develop countermeasures BCP must meet business needs Fey areas of expertise Evaluating recovery requirements and strategy Designing and devloping the BCP Assessing the BCP and DRP

BCP & DRP BCP: avoid loss DRP: recover from loss (subset of BCP) Preparation that facilitates rapid recovery of business critical operations DRP: recover from loss (subset of BCP) Procedure for emergency response Results from planning and is part of the life cyle

BCP & DRP Planning Phases and Deliverables Identify the team and staff Validate vital records: whet will be needed to recover, includes backups Conduct risk and business impact analysis Whet needs to be mitigated, what must be recovered and in what order Develop recovery strategy Select strategy options and select: cost/benefit. Must/want. Alternate site selection: functional alternate site: capacity Document the plan Testing, maintenance, and update

BCP & DRP Risk Analysis or assessment What could happen What is likely to happen Industry risks Location risks Transportation Other nearby elements For example would a chemical spill impact transportation

BCP & DRP Natural hazards Earthquake Tornado Flood Himmicane Ice Storm (major problem in DFW) Blizzard Tsunami

BCP & DRP Industry Risks Robbery & theft Workplace violence Money laundering Identity Theft Theft of trade secrets Fraud Loan Defaults Market risk Credit risk Labor disputes

BCP & DRP Location Nuclear power plants FBI/CIA (government buildings) Oil storage Hazardous waste Chemical factories Biomedical research (activists)

BCP & DRP Risk Business Impact Analysis (BIA) Risk reduction (controls) Risk acceptance (small) Risk transfer (insurance) Business Impact Analysis (BIA) Foundation for plans What must be protected/restored Use time sensitive, not critical or essential Classify functions as to recovery priority

BCP & DRP BIA Recovery Time Objective (RTO) Usually used for applications Once all functions are prioritized, establish RTOs Anything that has not left building is at risk How much is acceptable determines backups Used for Recovery Point Objective

BCP & DRP Data Stored Electronically Determined by RTO and RPO Most sensitive is offloaded either synchronously or asynchronously (batch) Other data uses tape/media backup and physical transportation Consider time to pack and transport in the RTO. Consider transportation means in calculating time. Consider that all images, OS, applications, & data are needed to restore plus hardware.

BCP & DRP Remote replication and off site journaling Involves moving over network to secondary storage devices Expensive but needed if RTO is short Synchronous replication requires store and acknowledge Asynchronous: queue, batch, store Frequency depends on need for currency Does not impact real time operation

BCP & DRP Backup Strategies Remote Replication Does not eliminate need for backup Single logical event could take out both Point in time copies need to be maintained Backup Strategies Incremental vs complete/full Incremental (change archive bit) Differential backup (does not) Depends on RTO

BCP & DRP Selecting Recovery Strategy Dual Data Center Internal hot site External hot site Warm site (partially configured, needs hardware) Cold site: space only Reciprocal agreement With other similar business Agreed excess capacity Mobile unit – trailer or COW Outsourced

BCP & DRP Cost-Benefit Analysis Implementing Recovery Strategy Consider each Eliminate outliers Included sunk, fixed, and variable costs plus testing Implementing Recovery Strategy Negotiation Site surveys Cost of installation Separate project

BCP & DRP Document the plan Plan activation Recovery procedures Detailed enough to allow unfsmiliar person to proceed Stored at recovery site and used for all testing Updated as needed Test with untrained personnel

BCP & DRP Human Factor Logistics Hardship Availability Consideration of family Logistics How will event be declared How team will be contacted (possibly multiple) Travel and reservations – who will pay Where documentation is stored and how to retrieve How off-site backups will be retrieved. Who will do, & time Address. Phone numbers and directions to alternate site Command center location and phone number Problem reporting and management Public affairs

BCP & DRP Plan Maintenance Strategies Version control Maintenance Review and update at least annually Test Protect production environment Walkthrough with all personnel affected Simulated vs actual Actual production is moved Compact Exercise scenario After action report Action items & tracking Plan update

BCP & DRP Summary BCP and DRP is evolving process Virtualization will have impact Cloud: technology on demand Require new concepts

BCP & DRP End of BCP & DRP session Will continue with Telecom pt 2 on 26 September Questions ?