Audit Planning Presentation - Disaster Recovery Plan

Slides:



Advertisements
Similar presentations
Business Continuity Training & Awareness by Sulia Toutai (ANZ)
Advertisements

Reliability of the electrical service Business Continuity Management Business Impact Analysis (BIA) Critical ITC Services Minimum Business Continuity Objective.
CIOassist Technologies Your CIO on Demand… Business Continuity Planning Our Offering CIOassist Technologies (
1 Disaster Recovery “Protecting City Data” Ron Bergman First Deputy Commissioner Gregory Neuhaus Assistant Commissioner THE CITY OF NEW YORK.
Business Continuity Planning and Disaster Recovery Planning
TEL382 Greene Chapter /27/09 2 Outline What is a Disaster? Disaster Strikes Without Warning Understanding Roles and Responsibilities Preparing For.
Disaster Recovery and Business Continuity Ensuring Member Service in Times of Crisis.
Business Continuity & Disaster Recovery Planning at The Chicago Board of Trade Presented By: Bryan Durkin Sr. Vice President The Chicago Board of Trade.
Gulf Coast Energy International Business Continuity / Disaster Recovery Planning and Design Proposal Prepared by Andrew Rolf, Felipe Torres, Pranay Jaiswal.
Business Continuity and You! The Ohio State University Business & Finance Enterprise Continuity Program Quarterly Update October 2008Business and Finance.
Services Tailored Around You® Business Contingency Planning Overview July 2013.
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
Continuity of Operations Planning COOP Overview for Leadership (Date)
RBTC: Business Continuity 101 July 18, What is Business Continuity? Scenario Part 1 Why is BC important? What types of plans are needed? How do.
Module 3 Develop the Plan Planning for Emergencies – For Small Business –
Unit 8:COOP Plan and Procedures  Explain purpose of a COOP plan  Propose an outline for a COOP plan  Identify procedures that can effectively support.
ISA 562 Internet Security Theory & Practice
David N. Wozei Systems Administrator, IT Auditor.
Rich Archer Partner, Risk Advisory Services KPMG LLP Auditing Business Continuity Plans.
1. 2 Cost to Recover Time to Recover Last Backup Work Backlog Created Lost Data Recovery Operations Time Cost Disaster Recovery Time Frame Reconstruct.
Business Continuity and Disaster Recovery Planning.
Business Continuity and Disaster Recovery Chapter 8 Part 1 Pages 897 to 914.
Developing Plans and Procedures
National Archives and Records Administration, Preparing for the Unexpected ESSENTIAL ELEMENTS: ANALYSIS.
Key Terms Business Continuity Plan (BCP) – A comprehensive written plan to maintain or resume business in the event of a disruption Critical Process –
Disaster Recovery: Can Your Business Survive Data Loss? DR Strategies for Today and Tomorrow.
Chapter 3: Business Continuity Planning. Planning for Business Continuity Assess risks to business processes Minimize impact from disruptions Maintain.
Business Continuity Disaster Planning
AUDITING BUSINESS CONTINUITY PROGRAMS AND PLANS What to Look For Presented by: Tommye White, CBCP, DRP Chuck Walts, CBCP, CRP.
Disaster Recovery Management By: Chris Rozic COSC 481.
INFORMATION ASSURANCE POLICY. Information Assurance Information operations that protect and defend information and information systems by ensuring their.
Business Continuity Planning 101
Advanced Planning Brief to Industry Jerry L. Davis DAS, Office of Information Security June 9, 2011.
MANAGEMENT of INFORMATION SECURITY, Fifth Edition.
Business Continuity and Disaster Recovery
THINK DIFFERENT. THINK SUCCESS.
Utilizing Your Business Continuity Plan.
Business Impact Analysis
MANAGEMENT of INFORMATION SECURITY, Fifth Edition
Making Incident Management Work for Your Organization
Continuity of operations planning
Business Continuity / Recovery
Business Continuity Plan Training
Business Continuity Planning and IT Risk Management
Description of Revision
Alabede, Collura, Walden, Zimmerman
Berry College Disaster Recovery Soft Exit
Fundamentals of a Business Impact Analysis
Mission Essential Functions Identification and Prioritization
“The Link” - Continuity of Operations and Emergency Management
Audit Plan Michelangelo Collura, Folake Stella Alabede, Felice Walden, Matthew Zimmerman.
SQL Database Audit Planning
Technology Audit Plan ----BCSY University
Heritage Fund - Disaster Planning 101
Business Contingency Planning
Disaster Recovery Plan
Boeing Business Continuity
Business Continuity Planning
Disaster Recovery at UNC
Continuity of Operations Planning
BUSINESS CONTINUITY PLAN
Business Continuity Program Overview
Emerging Audit and Internal Control Issues
Ken M. Shaurette, CISSP, CISA, CISM, CRISC FIPCO Director IT Services
The Survival Plan.
BUSINESS CONTINUITY PROGRAM
{Project Name} Organizational Chart, Roles and Responsibilities
Establishing a Continuity of Operations Planning program
Conducting a Business Impact Analysis (BIA)
BUSINESS CONTINUITY PLAN
Presentation transcript:

Audit Planning Presentation - Disaster Recovery Plan Rouying Tang Karabo Ntokwane Jason Mays Linlan Chen Chenhui Lai

Agenda Background & Objectives Scope Risk Assessment Roles and responsibilities Resource Allocation Timeline

Background Written disaster recovery plan: refers to a coordinated strategy involving plans, procedures, and technical measures that enable the recovery of information systems, operations, and data after a disruption. Written disaster recovery plan Auditing: A key step provides instructions, recommendations, and considerations to make sure organization can recover data and continue operations. Should be audited periodically

Background Berry College: An independent, coeducational college founded in 1902 provides comprehensive and balanced education and firsthand educational experience for approximately 2100 students. The current Information technology disaster recovery plan has been reviewed and appareled on December 7th, 2012.

Objectives As the guide for Berry College Office for Information Technology management and staff in the recovery and restoration of the information technology systems operated by OIT in the event that a disaster destroys all or part of those systems To minimize the effects of a disaster and allow the college to either maintain or quickly resume mission-critical functions To protect Berry’s computing resources and employees, To safeguard the vital records of which the Office for Information To guarantee the continued availability of essential IT services. To document the procedures for responding to a disaster that involves the data center and OIT services.

Objectives To validate that a disaster recovery plan has been developed, examine its adequacy and effectiveness and ensure that tests have been scheduled to prepare for potential declared disaster.

Scope Disaster declaration RPO and RTO Application recovery priorities Communication plan Responsibilities of members of DR management team Training. Review test plans and reports ·

Out of Scope Backup procedures Alternative site operation/data center rebuild ·

Risk assessment Risk will be assessed in 3 security objective areas of Confidentiality | Integrity | Accessibility Risk will be assessed on 3 levels of potential impact Low | Medium | High Personal Identifiable Information (PII) will be given additional consideration using PII confidentiality impact level factors Identifiability | Quantity | Data Field Sensitivity | Context of Use Obligation to Protect | Access to and Location Risk will be assessed in 3 security objective areas on 3 levels of potential impact as defined by FIPS Publication 199. The security objective areas are: Confidentiality | Integrity | Accessibility The levels of potential impact are: Low | Medium | High Defined by FIPS Publication 199 & 199 NIST Special Publication 800-34 Rev. 1

Key Risk Areas and Risk Rating High Recovery Time Objectives (RTO) and Recovery Point Objective (RPO) do not meet the Maximum Tolerable Downtime (MTD) noted in the BIA for network service and data protection Distribution of the Disaster Recovery Plan Ability to communicate effectively during disaster Application recovery priorities

Key Risk Areas and Risk Rating Moderate IT Disaster Recovery Management Team understanding of responsibilities Effective training of team participants who are required to execute plan segments in the event of a disaster. Communication between DR Coordinator, Command Center, Team leaders and team members.

Key Risk Areas and Risk Rating Low Review of test plans and reports Disaster declaration process

Prior Findings | Major Changes | Significant Projects There are no prior findings or significant changes to the disaster recovery process or document expected to affect the audit. Significant Projects There is a current project to implement a new offsite backup facility. Completion may occur during the audit. While the site is out of scope it may cause an update in responsibilities and processes within scope.

IT Audit team members’ roles and responsibilities in this audit Name Roles Responsibilities Chenhui Lai Team Leader Review test plans and reports. Responsible for the overall coordination of the disaster recovery process. Jason Mays Senior Auditor Planning. Data analysis. Verifying vendor contact rosters. Karabo Ntokwane Reporting. Schedule team leaders for recovery plan communications test. Record results of recovery plan communications test.

IT Audit team members’ roles and responsibilities in this audit Name Roles Responsibilities Linlan Chen IT Auditor Be the liaison to upper management Planing Rouying Tang Back up Testing

Audit hours for planning, testing, reporting phases The table below is time allocation for the internal auditing process. Name Chenhui Lai Jason Mays Karabo Ntokwane Rouying Tang Linlan Chen Time allocated to each step of auditing Total hours 108 hours 74 hours 114 hours 83 hours 26 hours Planning Testing Reporting 72 hours 30 hours 6 hours 1 hour 96 hours 6 hour 12 hour 10 hour 24 hours 1 hour http://www.berry.edu/uploadedFiles/Website/Business_Finance/Information_Technology/_Assets/Documents/ITDisasterRecoveryPlan.pdf DISASTER RECOVERY PLAN TESTING FORMS P.41 Chenhui Lai Audit Team Leader Jason Mays Senior Auditor Schedule team leaders for recovery plan communications test (3 days) Record results of recovery plan communications test ( 1 hour)

Key dates and deliverable ‘p

Questions?

Thank You

Citation Abram, Bill (14 June 2012). "5 Tips to Build an Effective Disaster Recovery Plan". Small Business Computing. Retrieved 9 August 2012. https://www.ibm.com/support/knowledgecenter/en/ssw_ibm_i_73/rzarm/rzarmdisastr.htm http://www.all.net/books/audit/kits/bkrecpgm.html National Institute of Standards and Technology (NIST) Contingency Planning Guide for Federal Information Systems Special Publication 800-34 Rev.1.