Business Continuity and Disaster Recovery Planning

Slides:



Advertisements
Similar presentations
Business Continuity Planning DavisLogicDavisLogic & All Hands ConsultingAll Hands Consulting.
Advertisements

Making Business Continuity Childs Play Business Continuity Management Presentation to January 2006 Mick
Business Continuity Training & Awareness by Sulia Toutai (ANZ)
Disaster Preparedness I Lessons Learned Don Hall Thomson Prometric 2006 Annual ConferenceAlexandria, Virginia Council on Licensure, Enforcement and Regulation.
CIOassist Technologies Your CIO on Demand… Business Continuity Planning Our Offering CIOassist Technologies (
Service Design – Section 4.5 Service Continuity Management.
@TxSchoolSafety Continuity of Operations Planning Workshop Devolution & Reconstitution.
Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP)
BCP/DRP Consultancy Project- An approach
Business Continuity Planning and Disaster Recovery Planning
Security Controls – What Works
Implementing BCM Lynda McMullan CBCI Business Continuity Manager.
Managing the Information Technology Resource Jerry N. Luftman
The Australian/New Zealand Standard on Risk Management
TEL382 Greene Chapter /27/09 2 Outline What is a Disaster? Disaster Strikes Without Warning Understanding Roles and Responsibilities Preparing For.
Disaster Recovery and Business Continuity Gretchen Grey.
Pertemuan Matakuliah: A0214/Audit Sistem Informasi Tahun: 2007.
Planning for Contingencies
Managing Project Risk.
Business Continuation Plan / Program Overview State CIO Council Meeting June 24, 2008.
Services Tailored Around You® Business Contingency Planning Overview July 2013.
1 BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNING Reducing your Risk Profile MIDWEST DATA RECOVERY INC.
Resiliency Rules: 7 Steps for Critical Infrastructure Protection.
EASTERN MICHIGAN UNIVERSITY Continuity of Operations Planning (COOP)
Business Continuity Planning
What is Business Analysis Planning & Monitoring?
Continuity of Operations Planning COOP Overview for Leadership (Date)
Corporate Support Richard Brown, Business Director.
Making Business Continuity Child’s Play Solutions Ltd Business Continuity Management Contact details: Contact : Mick O’Regan Mobile :
ISA 562 Internet Security Theory & Practice
David N. Wozei Systems Administrator, IT Auditor.
Rich Archer Partner, Risk Advisory Services KPMG LLP Auditing Business Continuity Plans.
Business Continuity & Disaster recovery
C ONNECTING FOR A R ESILIENT A MERICA Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP) Skip Breeden.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
GBA IT Project Management Final Project - Establishment of a Project Management Management Office 10 July, 2003.
Business Continuity & Disaster Recovery
2010 Virginia RIMS and PRIMA Conference October 5, 2010 Business Impact Analysis: The Road Map to Managing Risks.
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
Business Continuity and Disaster Recovery Planning.
Disaster Recovery and Business Continuity Planning.
DRP World Class Operations - Impact Workshop Info-Tech Research Group, Inc. Is a global leader in providing IT research and advice. Info-Tech’s products.
INFORMATION SECURITY MANAGEMENT L ECTURE 3: P LANNING FOR C ONTINGENCIES You got to be careful if you don’t know where you’re going, because you might.
Business Continuity Program Orientation (insert presentation date) (This presentation is a template that requires adjustments to meet your needs)
INFORMATION SECURITY MANAGEMENT L ECTURE 3: P LANNING FOR C ONTINGENCIES You got to be careful if you don’t know where you’re going, because you might.
Phases of BCP The BCP process can be divided into the following life cycle phases: Creation of a business continuity and disaster recovery policy. Business.
WEC MADRID 18 TH MARCH 2004 ASTRAZENECA’S APPROACH TO SUPPLIER RISK MANAGEMENT.
Chapter 3 Strategic Information Systems Planning.
Business Continuity. Business continuity... “Drive thy business or it will drive thee.” —Benjamin Franklin ( ), American entrepreneur, statesman,
Chapter 12 Implementation and Maintenance
Author(s): Don M. Blumenthal, 2010 License: Unless otherwise noted, this material is made available under the terms of the Attribution – Non-commercial.
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
Chapter 3: Business Continuity Planning. Planning for Business Continuity Assess risks to business processes Minimize impact from disruptions Maintain.
Business Continuity Disaster Planning
Alex Ezrakhovich Process Approach for an Integrated Management System Change driven.
CBIZ RISK & ADVISORY SERVICES BUSINESS CONTINUITY PLANNING Developing a Readiness Strategy that Mitigates Risk and is Actionable and Easy to Implement.
A Lightweight Business Continuity & Disaster Recovery Plan Motahareh Moravej Issuers’ Affairs Director at CSDI PHD. Student of Computer Engineering, UT.
Disaster Recovery Planning (DRP) DRP: The definition of business processes, their infrastructure supports and tolerances to interruptions, and formulation.
AUDITING BUSINESS CONTINUITY PROGRAMS AND PLANS What to Look For Presented by: Tommye White, CBCP, DRP Chuck Walts, CBCP, CRP.
Business Continuity Awareness Steve Lambert Biscon Planning Ltd.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Business Continuity Planning 101
Donald JG Chiarella, PhD, CISM, CDMP, PEM, CHS-CIA, MBA.
MANAGEMENT of INFORMATION SECURITY, Fifth Edition
Fundamentals of a Business Impact Analysis
Audit Planning Presentation - Disaster Recovery Plan
Personal Introduction
Business Continuity Program Overview
Establishing a Continuity of Operations Planning program
Presentation transcript:

Business Continuity and Disaster Recovery Planning Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2015 Business Continuity and Disaster Recovery Planning

Domain Agenda Project Scope Development and Planning Business Impact Analysis (BIA) and Functional Requirements Business Continuity and Recovery Strategy Plan Design and Development Implementation Restoration / Disaster Recovery Feedback and Plan Management

Domain Objectives Understand the planning process Integrating BCP into the organization Defining inputs and outputs of process Understand the difference between BCP and DRP

Sources of Information Disaster Recovery Institute International Business Continuity Institute ISO 25999 ISO 27001, Section 10 NIST SP 800-34

ISO 25999: Business Continuity Management Risk management Disaster recovery Facilities management Supply chain management Quality management Health and safety Knowledge management Emergency management Security Crisis communications and PR

Overview of BCP Direct benefits Indirect benefits Overlap with Risk Management BCM vs. BCP vs. COOP

The Enterprise BCP DRP BIA Incident response planning Backup strategies Emergency procedures Contracts and provisioning BIA Reciprocal agreements Alternate sites Incident response planning Succession Plan Incidence Response Team

The Enterprise BCP (cont.) Risk analysis Safeguards / countermeasures Insurance plan Corporate communication plan User awareness training Media/stakeholder relations plan

The Business Continuity Life Cycle Analyze the business Assess the risks Develop the BC strategy Develop the BC plan Rehearse the plan

BC Project Phases Project Scope Development and Planning Business Impact Analysis (BIA) and Functional Requirements Business Continuity and Recovery Strategy Plan Design and Development Implementation Restoration / Disaster Recovery Feedback and Plan Management

Reflecting Organizational Context Policy is the driver Aligned with requirements Provides direction and focus Use Business Impact Analysis Identify inputs Outcomes and deliverables Reviewed annually

Policy Organizational authority Policy document Program scope Resources Outsourcing

Policy contents Framework Tools and techniques Policy contents Change is infrequent

Outsourced Activities You are still responsible Resilience in outsourcing Supplier continuity

Scope and Choices Limit scope Ensure clarity of scope Strategy, Return on Investment (ROI), and SWOT (Strengths, Weaknesses, Opportunities, Threats) Review yearly

Program Management Assigning responsibilities Initiating BCP in the organization Project management Ongoing management Documentation Incident readiness and response

Documentation Review current BCP if available Documentation may not equal capability Staff must be trained to use any necessary software Types of documentation Review as directed by policy

Initiating BCP Awareness, data, implementation Staff and budget Result must be a long-term, sustainable program Review progress monthly

Incident Readiness & Response Planners become leaders Be prepared Triage Incident management Success = Return to Operations Immediate lessons learned

Key Indicators of Success Senior management commitment Policy content BCP Resources Project management Documentation

BCP Project Phases Project Scope Development and Planning Business Impact Analysis (BIA) and Functional Requirements Business Continuity and Recovery Strategy Plan Design and Development Implementation Restoration / Disaster Recovery Feedback and Plan Management

Understanding the Organization Business Impact Analysis (BIA) Benefits Objectives Evaluating Threats (Risk Assessment) Emergency Assessment Indicators of Critical Business Functions

Business Impact Analysis Identifies, quantifies and qualifies loss Scope and support required Documents impact and dependencies MTD, RPO Business impact analysis process Workshops, questionnaires, interviews Business justifications for budget

Maximum Tolerable Period of Disruption Item Required recovery time following a disaster Non-essential 30 days Normal 7 days Important 72 hours Urgent 24 hours Critical/Essential Minutes to hours

Estimating Continuity Requirements Total budget for disaster recovery Identification of necessary resources Outcomes feed BCP strategy selection Reviewed with BIA

Evaluating Threats (Risk Assessment) Risk equation + time element Risk = Threat impact * probability Prioritize key processes and assets Outcomes

Key Indicators or Success Corporate governance BIA practice Risk assessment practice

BCP Project Phases Project Scope Development and Planning Business Impact Analysis (BIA) and Functional Requirements Business Continuity and Recovery Strategy Plan Design and Development Implementation Restoration / Disaster Recovery Feedback and Plan Management

Determining Business Continuity Strategy High-level strategies RTO < MTPD Separation distance Resilience Address specific business types

Determining Strategy Determining BC strategies Strategy options Activity continuity options Resource-level consolidation

Activity Continuity Options Selecting recovery tactics Reliability Extent of planning Cost/benefit analysis Outcome

Recovery Alternatives Description Readiness Cost Multiple processing/ mirrored site Fully redundant identical equipment and data Highest level of availability and readiness Highest Mobile site/trailer Designed, self-contained IT and communications Variable drive time; load data and test systems High Hot site Fully provisioned IT and office, HVAC, infrastructure and communications Short time to load data, test systems. May be yours or vendor staff Warm site Partially IT equipped, some office, data and voice, infrastructure Days of weeks. Need equipment, data communications Moderate Cold site Minimal infrastructure, HVAC Weeks or more. Need all IT, office equipment and communications Lowest

Processing Agreements Description Consideration Reciprocal or Mutual Aid Two or more organizations agree to recover critical operations for each other. Technology upgrades/ obsolescence or business growth. Security and access by partner users Contingency Alternate arrangements if primary provider is interrupted, i.e. voice or data communications Providers may share paths or lease from each other. Question them. Service Bureau Agreement with application service provider to process critical business functions. Evaluate their loading geography and ask about backup mode.

BCP Project Phases Project Scope Development and Planning Business Impact Analysis (BIA) and Functional Requirements Business Continuity and Recovery Strategy Plan Design and Development Implementation Restoration / Disaster Recovery Feedback and Plan Management

Resource Level Consolidation Consolidation plan Availability of solutions Consolidate, approve, implement Methods and techniques Outcomes and deliverables

Business Continuity Plan Master plan Modular in design Executive endorsement Review quarterly

Business Continuity Plan Contents When team will be activated Means by which the team will be activated Places to meet Action plans/task list created

Business Continuity Plan Contents Responsibilities of the team or of specific individuals Liaising with Emergency Services (fire, police ambulance) Receiving or seeking information from response teams Reporting information to the Incident Management Team Mobilizing third party suppliers of salvage and recovery services Allocating available resources to recovery teams Invocation / mobilization instructions

Developing and Implementing Response Incident response structure Emergency response procedures Personnel notification Communications Restoration

BCP Project Phases Project Scope Development and Planning Business Impact Analysis (BIA) and Functional Requirements Business Continuity and Recovery Strategy Plan Design and Development Implementation Restoration / Disaster Recovery Feedback and Plan Management

Implementing Incident Management Plan Rapid response is critical Crisis management Steps to develop an Incident Management Plan Action plans

Incident Response Structure Strategic Tactical Operational

Key Indicators of Success Development and acceptance of Recovery Strategies and Business Continuity Plans

BCP Project Phases Project Scope Development and Planning Business Impact Analysis (BIA) and Functional Requirements Business Continuity and Recovery Strategy Plan Design and Development Implementation Restoration / Disaster Recovery Feedback and Plan Management

Disaster Recovery Salvage Separate function and team Facility restoration System recovery

BCP Project Phases Project Scope Development and Planning Business Impact Analysis (BIA) and Functional Requirements Business Continuity and Recovery Strategy Plan Design and Development Implementation Restoration / Disaster Recovery Feedback and Plan Management

Testing the Program Find the flaws Outsourcing Timetable for tests Test design process

Testing Types Types Process Participants Frequency Complexity Desk Check Check the contents of the plan, aid in maintenance. Author Often LOW Walk-through Check interaction and roles of participants. Author and main people Simulation Includes: business plans, buildings, communications Main people and auditors Parallel testing Moves work to another site. Recreates the existing work from the displaced site. Everyone at location Full Shuts down and relocates all work Everyone at both locations Rare HIGH

Embedding BCP Assessing level of awareness and training Developing BCP within the Culture Monitoring cultural change

Test BCP Arrangements Test, rehearsal, exercise Combine all plan activities Stringency, realism and minimal exposure Contents of a test Outcomes

Maintaining BCP Arrangements Ready and embedded Triggered by change management Owners keep information current Documented Review as needed

Reviewing BCP Arrangements Audit Independent BCP audit opinion As directed by audit policy

Factors for Success Supported by senior management Everyone is aware Everyone is invested Consensus

Assessing the Level of Awareness and Training Where are we now What does the policy state Current vs. desired levels Training framework in place

Developing a BCP Within the Organization’s Culture Training, education, awareness Well-implemented policy Design Delivery planning Delivery Cost effective delivery Higher awareness

Domain Summary Project Scope Development and Planning Business Impact Analysis (BIA) and Functional Requirements Business Continuity and Recovery Strategy Plan Design and Development Implementation Restoration / Disaster Recovery Feedback and Plan Management