Business Continuity Planning and Disaster Recovery Planning

Slides:



Advertisements
Similar presentations
Information Technology Disaster Recovery Awareness Program.
Advertisements

Business Continuity and Disaster Recovery Planning.
1 The process of analyzing all core business functions and establishing an optimized timetable for recovery. Provides baseline for:  Justification for.
CIOassist Technologies Your CIO on Demand… Business Continuity Planning Our Offering CIOassist Technologies (
DISASTER CENTER Study Case DEMIRBANK ROMANIA “Piata Financiara” ConferenceJanuary 29, 2002 C 2002.
1 Disaster Recovery “Protecting City Data” Ron Bergman First Deputy Commissioner Gregory Neuhaus Assistant Commissioner THE CITY OF NEW YORK.
1 Continuity Planning for transportation agencies.
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP)
BCP/DRP Consultancy Project- An approach
1 Business Continuity: The sixth international payment system conference MNB, Budapest 14 November, 2007.
9 - 1 Computer-Based Information Systems Control.
Business Crisis and Continuity Management (BCCM) Class Session
TEL382 Greene Chapter /27/09 2 Outline What is a Disaster? Disaster Strikes Without Warning Understanding Roles and Responsibilities Preparing For.
Planning for Contingencies
Session 3 – Information Security Policies
Gulf Coast Energy International Business Continuity / Disaster Recovery Planning and Design Proposal Prepared by Andrew Rolf, Felipe Torres, Pranay Jaiswal.
John Graham – STRATEGIC Information Group Steve Lamb - QAD Disaster Recovery Planning MMUG Spring 2013 March 19, 2013 Cleveland, OH 03/19/2013MMUG Cleveland.
Business Continuity and You! The Ohio State University Business & Finance Enterprise Continuity Program Quarterly Update October 2008Business and Finance.
Business Crisis and Continuity Management (BCCM) Class Session
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
Discovery Planning steps (1)
Module 3 Develop the Plan Planning for Emergencies – For Small Business –
Continuity of Operations (COOP) Awareness Training.
IS 380.  Provides detailed procedures to keep the business running and minimize loss of life and money  Identifies emergency response procedures  Identifies.
Security Baseline. Definition A preliminary assessment of a newly implemented system Serves as a starting point to measure changes in configurations and.
Unit 8:COOP Plan and Procedures  Explain purpose of a COOP plan  Propose an outline for a COOP plan  Identify procedures that can effectively support.
ISA 562 Internet Security Theory & Practice
Insurance Institute for Business & Home Safety Even if the worst happens, be prepared to stay.
Incident Management By Marc-André Léger DESS, MASc, PHD(candidate) Winter 2008.
Rich Archer Partner, Risk Advisory Services KPMG LLP Auditing Business Continuity Plans.
Business Continuity & Disaster recovery
C ONNECTING FOR A R ESILIENT A MERICA Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP) Skip Breeden.
1 Availability Policy (slides from Clement Chen and Craig Lewis)
INFORMATION SECURITY & RISK MANAGEMENT SZABIST – Spring 2012.
Business Continuity and Disaster Recovery Planning.
1 Crisis Management / Emergency Management Overview.
Business Continuity and Disaster Recovery Chapter 8 Part 1 Pages 897 to 914.
Disaster Recovery and Business Continuity Planning.
INFORMATION SECURITY MANAGEMENT L ECTURE 3: P LANNING FOR C ONTINGENCIES You got to be careful if you don’t know where you’re going, because you might.
Business Continuity Program Orientation (insert presentation date) (This presentation is a template that requires adjustments to meet your needs)
INFORMATION SECURITY MANAGEMENT L ECTURE 3: P LANNING FOR C ONTINGENCIES You got to be careful if you don’t know where you’re going, because you might.
Phases of BCP The BCP process can be divided into the following life cycle phases: Creation of a business continuity and disaster recovery policy. Business.
TIJARA Provincial Economic Growth Program Business Continuity / Disaster Recovery Planning Introduction and Workshop Outline Prepared by Larry SanBoeuf.
NFPA 1600 Disaster/Emergency Management and Business Continuity Programs.
Business Continuity. Business continuity... “Drive thy business or it will drive thee.” —Benjamin Franklin ( ), American entrepreneur, statesman,
Key Terms Business Continuity Plan (BCP) – A comprehensive written plan to maintain or resume business in the event of a disruption Critical Process –
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
DRP Disaster Recovery Planning. Social Networking... It's the way the 21st century communicates today.
Chapter 3: Business Continuity Planning. Planning for Business Continuity Assess risks to business processes Minimize impact from disruptions Maintain.
A2 LEVEL ICT 13.6 LEGAL ASPECTS DISASTER RECOVERY.
Business Continuity Disaster Planning
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
Introduction to Business continuity Planning 6/9/2016 Business Continuity Planning 1.
Disaster Recovery Planning (DRP) DRP: The definition of business processes, their infrastructure supports and tolerances to interruptions, and formulation.
AUDITING BUSINESS CONTINUITY PROGRAMS AND PLANS What to Look For Presented by: Tommye White, CBCP, DRP Chuck Walts, CBCP, CRP.
Business Continuity Planning 101
Dr. Gerry Firmansyah CID Business Continuity and Disaster Recovery Planning for IT (W-I)
Welcome to the ICT Department Unit 3_5 Security Policies.
Business Continuity Steven S. Keleman, CPM. Emergency Management Prevention Response Preparation Mitigation Recovery.
Information Systems Security
Utilizing Your Business Continuity Plan.
CompTIA Security+ Study Guide (SY0-401)
MANAGEMENT of INFORMATION SECURITY, Fifth Edition
Business Continuity / Recovery
Unit 7 – Organisational Systems Security
Audit Plan Michelangelo Collura, Folake Stella Alabede, Felice Walden, Matthew Zimmerman.
Audit Planning Presentation - Disaster Recovery Plan
Business Impact Analysis
Business Continuity Program Overview
Presentation transcript:

Business Continuity Planning and Disaster Recovery Planning Ref. CISSP exam guide W.lilakiatsakun

Business Continuity Planning and Disaster Recovery Planning (1) DRP is the process of regaining access to the data, hardware and software necessary to resume critical business operations after a natural or human-induced disaster. DRP is part of a larger process known as business continuity planning (BCP). Disaster recovery is the process by which you resume business after a disruptive event.

Business Continuity Planning and Disaster Recovery Planning (2) The event might be something huge-like an earthquake or the terrorist attacks on the World Trade Center something small, like malfunctioning software caused by a computer virus. Many business executives are prone to ignoring "disaster recovery" because disaster seems an unlikely event.

Business Continuity Planning and Disaster Recovery Planning (3) All BC/DR plans need to encompass How employees will communicate Where they will go How they will keep doing their jobs. The details can vary greatly, depending on the size and scope of a company and the way it does business.

Events that necessitate disaster recovery Natural disasters Fire Power failure Terrorist attacks Organized or deliberate disruptions Theft System and/or equipment failures Human error Computer viruses Testing

Business Continuity Steps (1) 1 Develop the continuity planning policy statement - Write a policy that provides the guidance necessary to develop a BCP and assigns authority to the necessary roles to carry out these tasks 2 Conduct the business impact analysis (BIA) - Identify critical functions and systems and allow the organization to prioritize them on necessity. -Identify vulnerabilities, threats and calculate risks - Calculate MTD (Maximum Tolerable Downtime) for resources

Business Continuity Steps (2) 3 Identify preventive controls Identify and implement controls and countermeasures to reduce the organization’s risk level in an economical manner 4 Develop recovery strategies Formulate methods to ensure that systems and critical function can be brought online quickly

Business Continuity Steps (3) 5 Develop the contingency plan Write procedure and guidelines for how the organization can still stay functional in a cripple state 6 Test the plan and conduct training and exercise Test the plan to identify deficiencies in the BCP and conduct training to properly prepare individuals on their expected task 7 Maintain plan Put in place steps to ensure the BCP is a living document that is upgraded regularly

Initiation (1) Identified a business continuity coordinator (leader for the BCP team) Setup a BCP committee might consist of representative from Business units Senior management IT department Security department Communications department Legal department

Initiation (2) At this phase, the team works with management to develop the continuity planning policy statement Layout the scope of the BCP project Team member roles Goal of the project

BCP Requirement The major requirement is management support Work best in a top-down approach Management should be driving the project It is important that management set the overall goals of continuity planning It should help set priorities of what should be dealt first

Business Impact Analysis (1) The BCP committee must identify the threats to the company and map them to the following characteristics Maximum tolerable downtime Operational disruption and productivity Financial consideration Regulatory responsibilities Reputation

Business Impact Analysis (2) Data would gather from interviewing, surveying, workshops and etc Threat can be manmade, natural or technical The committee needs to step through scenarios that could produce the following results Equipment malfunction Unavailable utilities (Power, Communication) Software or data corruption

Business Impact Analysis (3) Loss criteria must applied to the individual threats Loss in reputation and public confidence Loss of competitive advantages Increase in operational expenses Violations of contract agreement Violations of legal and regulatory requirement Delays income costs Loss in revenue Loss in productivity

Business Impact Analysis (4) Example of Maximum Tolerable Downtime (MTD) Nonessential 30 days Normal 7 days Important 72 hours Urgent 24 hours Critical Minute to hours

Business Impact Analysis (5) Interdependencies Business function might depend on the other functions BCP team should carried out these tasks Define essential business function and support departments Identifies interdependencies Discover all possible disruption that could affect the mechanism Identify and document potential threats Gather quantitative and qualification information pertaining to those threat Provide alternative methods for restoring Provide a brief statement of rationale for each threat and corresponding information

BIA Steps (1) 1 Select individuals to interview for data gathering 2 Create data-gathering techniques (surveys, questionnaires, qualitative and quantitative approaches) 3 Identify the company ‘s critical business function 4 Identify the resources that these functions depend upon

BIA Steps (2) 5 Calculate how long these functions can survive without these resources 6 Identify vulnerabilities and threats to these function 7 Calculate risk for each different business function 8 Document findings and report them to management

Preventive Controls Reduce impact and mitigate risks Example of preventive measures Redundant servers and communication links Power lines coming in through different transformers UPS and generators Data backup Fire detection

Recovery strategies Business process recovery Facility recovery Business process is back to work Facility recovery Cold site/ Warm site/ Hot site Supply and technology recovery Network /computer /human resources User environment recovery Most critical department gets back first Data recovery Data Back up

Developing the BCP (1) Define goals of the plan and goals must contain certain key information such as Responsibility Each individual should have their responsibilities spell out in writing to ensure a clear understanding in a chaotic situation Authority In time of crisis, it is important to know who is in charge Clear cut authority will aid in reducing confusion and increase coorperation

Developing the BCP (2) Priorities Implement and testing It is necessary to know which department come online first which second and so on Along with the priorities of department, the priorities of systems, information and program must be established Implement and testing

Developing the BCP (3) Documenting the following Procedures Recovery solutions Roles and tasks Emergency response

Testing plan (1) Checklist test Structured walk-through test Forget anything ? Structured walk-through test Discussion by representatives Simulation test Ensure that specific steps were not left out and certain threats were not overlooked Raise awareness of people involved

Testing plan (2) Parallel test Full interruption test Ensure that the specific systems can actually perform adequately at the alternate off site facility Full interruption test Ensure that everything will be recovered as planned It can reveal many holes that need to be fixed

Maintaining the plan Organization can keep the plan updated by taking the following actions Make business continuity a part of business decision Insert the maintenance responsibilities into job descriptions Include maintenance in personnel evaluation Perform internal audits that include disaster recovery and continuity documentation and procedures Perform regular drills that use the plan Integrate BCP into the current change management process