CIOassist Technologies Your CIO on Demand… Business Continuity Planning Our Offering CIOassist Technologies (www.cioassist.in)www.cioassist.in

Slides:



Advertisements
Similar presentations
Business Continuity Planning Presentation to Management.
Advertisements

Case Study: Business Continuity Planning for Site- Level Disaster Kimberley A. Pyles Northrop Grumman Corporation
BUSINESS CONTINUITY MANAGEMENT THROUGH STANDARDS AND BEST PRACTICES Jasmina Trajkovski, CISA, CISM.
Maximizing Uptime and Your Firm's Bottom Line: Understanding risk and budget when evaluating business continuity & disaster recovery protocols Michael.
Module – 9 Introduction to Business continuity
Business Continuity Section 3(chapter 8) BC:ISMDR:BEIT:VIII:chap8:Madhu N PIIT1.
1 Disaster Recovery “Protecting City Data” Ron Bergman First Deputy Commissioner Gregory Neuhaus Assistant Commissioner THE CITY OF NEW YORK.
JOELLE QUIAPO FOLA OYEDIRAN GREG SWENSON SUKHI BEDI CHENYU GONG Disaster Recovery and Business Continuity Planning: Testing an Organization’s Plans What.
1 Continuity Planning for transportation agencies.
© 2009 EMC Corporation. All rights reserved. Introduction to Business Continuity Module 3.1.
September 14, 2010 Measuring/Monitoring for Perfect Ground Transportation Services AGTA Meeting – San Antonio 10:45 AM Michael J. Corby, CISSP, CCP, PMP.
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP)
Business Continuity Planning Jeremy Stacy. Objectives Understand the steps in Business Continuity Planning Understand the terminology used in Business.
Business Continuity Planning and Disaster Recovery Planning
1 Business Continuity: The sixth international payment system conference MNB, Budapest 14 November, 2007.
Disaster Prevention and Recovery Presented By: Sean Snodgrass and Theodore Smith.
TEL382 Greene Chapter /27/09 2 Outline What is a Disaster? Disaster Strikes Without Warning Understanding Roles and Responsibilities Preparing For.
Planning for Contingencies
Gulf Coast Energy International Business Continuity / Disaster Recovery Planning and Design Proposal Prepared by Andrew Rolf, Felipe Torres, Pranay Jaiswal.
John Graham – STRATEGIC Information Group Steve Lamb - QAD Disaster Recovery Planning MMUG Spring 2013 March 19, 2013 Cleveland, OH 03/19/2013MMUG Cleveland.
Business Crisis and Continuity Management (BCCM) Class Session
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
Business Continuity Planning
Business Continuity for Facilities Managers Peter Carr FastTrack Solutions Ltd
Evolving IT Framework Standards (Compliance and IT)
Business Continuity and Disaster Recovery Chapter 8 Part 2 Pages 914 to 945.
Making Business Continuity Child’s Play Solutions Ltd Business Continuity Management Contact details: Contact : Mick O’Regan Mobile :
IS 380.  Provides detailed procedures to keep the business running and minimize loss of life and money  Identifies emergency response procedures  Identifies.
ISA 562 Internet Security Theory & Practice
Insurance Institute for Business & Home Safety Even if the worst happens, be prepared to stay.
David N. Wozei Systems Administrator, IT Auditor.
Business Continuity & Disaster recovery
C ONNECTING FOR A R ESILIENT A MERICA Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP) Skip Breeden.
Environment for Information Security n Distributed computing n Decentralization of IS function n Outsourcing.
Business Continuity and Disaster Recovery Planning.
IT Disaster Recovery CAUBO 2008 Information Systems and Technology.
Business Continuity and Disaster Recovery Chapter 8 Part 1 Pages 897 to 914.
Business Continuity Management For Project Managers.
Disaster Recovery and Business Continuity Planning.
INFORMATION SECURITY MANAGEMENT L ECTURE 3: P LANNING FOR C ONTINGENCIES You got to be careful if you don’t know where you’re going, because you might.
E.Soundararajan R.Baskaran & M.Sai Baba Indira Gandhi Centre for Atomic Research, Kalpakkam.
CISSP For Dummies Chapter 11 Business Continuity and Disaster Recovery Planning Last updated
INFORMATION SECURITY MANAGEMENT L ECTURE 3: P LANNING FOR C ONTINGENCIES You got to be careful if you don’t know where you’re going, because you might.
Phases of BCP The BCP process can be divided into the following life cycle phases: Creation of a business continuity and disaster recovery policy. Business.
MANAGING DEMAND AND CAPACITY. Capacity is usually constant whereas demand usually fluctuates. Fluctuations could be due to various reasons, predictable.
Business Continuity. Business continuity... “Drive thy business or it will drive thee.” —Benjamin Franklin ( ), American entrepreneur, statesman,
Business Continuity and Disaster Recovery Planning
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
Business Continuity Disaster Planning
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
A Lightweight Business Continuity & Disaster Recovery Plan Motahareh Moravej Issuers’ Affairs Director at CSDI PHD. Student of Computer Engineering, UT.
Disaster Recovery Planning (DRP) DRP: The definition of business processes, their infrastructure supports and tolerances to interruptions, and formulation.
Business Continuity Planning 101
Donald JG Chiarella, PhD, CISM, CDMP, PEM, CHS-CIA, MBA.
THINK DIFFERENT. THINK SUCCESS.
MANAGEMENT of INFORMATION SECURITY, Fifth Edition
BUSINESS CONTINUITY BY HUI ZHENG.
DISASTER RECOVERY INSTITUTE INTERNATIONAL
Business Continuity / Recovery
Peggy M. Jackson, DPA, CPCU Peg Jackson & Associates
Business Continuity Plan Training
Alabede, Collura, Walden, Zimmerman
Fundamentals of a Business Impact Analysis
Audit Plan Michelangelo Collura, Folake Stella Alabede, Felice Walden, Matthew Zimmerman.
Audit Planning Presentation - Disaster Recovery Plan
Stage 1 - Business Impact Review
University of Maryland Robert H. Smith School of Business
Establishing a Continuity of Operations Planning program
Conducting a Business Impact Analysis (BIA)
Presentation transcript:

CIOassist Technologies Your CIO on Demand… Business Continuity Planning Our Offering CIOassist Technologies (

Why Business Continuity? REVENUE  Direct Loss  Deferred Losses  Compensatory Payments  Lost Future Revenue  Billing Losses  Investment Losses FINANCIAL PERFORMANCE  Lost Market Share  Revenue Recognition  Cash Flow  Lost Discounts  Payment Guarantees  Stock Price  Credit Rating OTHER EXPENSES  Temporary employees,  Equipment Rental,  Overtime,  Extra Shipping Costs,  Travel Expenses,  Etc. REPUTATION  Customers  Suppliers  Financial Markets  Banks  Business Partners  Etc. PRODUCTIVITY  Loss Of Productivity  Employees X Burdened Hourly Rate LEGAL/REGULATORY  Contractual Requirements  SLAs  Regulatory Requirements The Cost of Downtime

BCP Phases Project Management and Intonation Conduct Business Impact Analysis Develop Recovery Strategies Plan, Design and Development Testing, maintenance, awareness and training BCP Is an on-going process, not a project with a beginning and an end

Testing Maintenance Awareness Training 5 Plan, Design and Development 4 1 Project Initiation: Understand Your Business 3 Develop Strategies for Supply & Technology Recovery Data Recovery 2 Conduct Business Impact Analysis to identify Recovery Point (RPO) Service Delivery (SDO) Recover Time (RTO) Maximum Tolerable Outage (MTO) BCP BCP Phases

Developing and approval of BCP policy Define BCP committee – operational units representatives – senior management – IT security – IT specialized experts, and optionally support units like (technical affairs) Define BCP project scope and objectives Provide the necessary project funds and resourses Project Initiation

Business Impact Analysis Collect data through interviews, survey, documenting business functions, transactions, activities Develop hierarchy of business functions and apply a classification scheme to indicate each individual function’s criticality level. Identify the resources that these functions depend upon Calculate Maximum Tolerable Outage (MTO) for these functions Identify vulnerabilities and threats to these functions Calculate risk for each different business function Document findings and report them to management

Business Impact Analysis Recovery Time Objective (RTO): Time duration organization can wait between point of failure and service resumption Service Delivery Objective (SDO): Level of service in Alternate Mode Maximum Tolerable Outage: Max time in Alternate Mode Regular Service Alternate Mode Regular Service RTO Maximum Tolerable Outage SDO Interruption Time… Disaster Recovery Plan Implemented Restoration Plan Implemented

Business Impact Analysis How far back can you fail to? How long can you operate without a system? One week’s worth of data? Which services can last how long? Interruption Hour Day Week Recovery Point ObjectiveRecovery Time Objective Interruption Week Day Hour

Business Impact Analysis Move to Alternate Site Return Home Resume Business Data Synchronization Restore Technology Capability Restore Communications Restore Business Functions Notifications Vital Records Lost Data Data Recovery Objective Recovery Time Objective (If necessary) High Level Look at a Recovery Effort

Recovery strategies Supply and technology recovery Network and computer equipment Voice and data communications resources Human resources Transportation of equipment and personnel Environment issues (HVAC) Data and personnel security issues Supplies (paper, forms, cabling, and so on) Documentation Data recovery Restoring Backed-up data

Recovery Strategies Cost Time Service Downtime Alternative Recovery Strategies Optimum Cost * Hot Site * Warm Site * Cold Site Identifying the Optimum Strategy

Recovery strategies Business process recovery Facility recovery SiteCostHardware EquipmentTelecommunicationsSetup TimeLocation Cold SiteLowNone LongFixed Warm SiteMediumPartialPartial/FullMediumFixed Hot SiteMedium/HighFull ShortFixed Mobile SiteHighDependent Not Fixed Mirrored SiteHighFull NoneFixed

Plan Design and Development All finding and decisions to be developed and documented. Submission of document for approval Define execution procedure(s) for the plan.

Testing, maintenance, awareness and training Validating that decisions are suitable and correct by performing – Checklist Test – Structured Walk-Through Test – Simulation Test – Parallel Test – Full-Interruption Test Maintaining the plan – Make business continuity a part of every business decision – Insert the maintenance responsibilities into job descriptions – Perform internal audits that include disaster recovery and continuity – documentation and procedures to update the plan. – Integrate the BCP into the change management process Training and awareness programs are an integral part of the BCP process BCP Is an on-going process, not a project with a beginning and an end