560 likes | 576 Views
Comprehensive guide on BCP and DRP, covering project phases, policy, management, incident readiness, and success indicators. Learn the essentials for a robust continuity plan.
E N D
Dr. Bhavani ThuraisinghamThe University of Texas at Dallas (UTD)June 2011 Business Continuity and Disaster Recovery Planning
Domain Agenda • Project Scope Development and Planning • Business Impact Analysis (BIA) and Functional Requirements • Business Continuity and Recovery Strategy • Plan Design and Development • Implementation • Restoration / Disaster Recovery • Feedback and Plan Management
Domain Objectives • Understand the planning process • Integrating BCP into the organization • Defining inputs and outputs of process • Understand the difference between BCP and DRP
Sources of Information • Disaster Recovery Institute International • Business Continuity Institute • ISO 25999 • ISO 27001, Section 10 • NIST SP 800-34
ISO 25999: Business Continuity Management • Risk management • Disaster recovery • Facilities management • Supply chain management • Quality management • Health and safety • Knowledge management • Emergency management • Security • Crisis communications and PR
Overview of BCP • Direct benefits • Indirect benefits • Overlap with Risk Management • BCM vs. BCP vs. COOP
The Enterprise BCP • DRP • Backup strategies • Emergency procedures • Contracts and provisioning • BIA • Reciprocal agreements • Alternate sites • Incident response planning • Succession Plan • Incidence Response Team
The Enterprise BCP (cont.) • Risk analysis • Safeguards / countermeasures • Insurance plan • Corporate communication plan • User awareness training • Media/stakeholder relations plan
The Business Continuity Life Cycle • Analyze the business • Assess the risks • Develop the BC strategy • Develop the BC plan • Rehearse the plan
BC Project Phases • Project Scope Development and Planning • Business Impact Analysis (BIA) and Functional Requirements • Business Continuity and Recovery Strategy • Plan Design and Development • Implementation • Restoration / Disaster Recovery • Feedback and Plan Management
Reflecting Organizational Context • Policy is the driver • Aligned with requirements • Provides direction and focus • Use Business Impact Analysis • Identify inputs • Outcomes and deliverables • Reviewed annually
Policy • Organizational authority • Policy document • Program scope • Resources • Outsourcing
Policy contents • Framework • Tools and techniques • Policy contents • Change is infrequent
Outsourced Activities • You are still responsible • Resilience in outsourcing • Supplier continuity
Scope and Choices • Limit scope • Ensure clarity of scope • Strategy, Return on Investment (ROI), and SWOT (Strengths, Weaknesses, Opportunities, Threats) • Review yearly
Program Management • Assigning responsibilities • Initiating BCP in the organization • Project management • Ongoing management • Documentation • Incident readiness and response
Documentation • Review current BCP if available • Documentation may not equal capability • Staff must be trained to use any necessary software • Types of documentation • Review as directed by policy
Initiating BCP • Awareness, data, implementation • Staff and budget • Result must be a long-term, sustainable program • Review progress monthly
Incident Readiness & Response • Planners become leaders • Be prepared • Triage • Incident management • Success = Return to Operations • Immediate lessons learned
Key Indicators of Success • Senior management commitment • Policy content • BCP Resources • Project management • Documentation
BCP Project Phases • Project Scope Development and Planning • Business Impact Analysis (BIA) and Functional Requirements • Business Continuity and Recovery Strategy • Plan Design and Development • Implementation • Restoration / Disaster Recovery • Feedback and Plan Management
Understanding the Organization • Business Impact Analysis (BIA) • Benefits • Objectives • Evaluating Threats (Risk Assessment) • Emergency Assessment • Indicators of Critical Business Functions
Business Impact Analysis • Identifies, quantifies and qualifies loss • Scope and support required • Documents impact and dependencies • MTD, RPO • Business impact analysis process • Workshops, questionnaires, interviews • Business justifications for budget
Estimating Continuity Requirements • Total budget for disaster recovery • Identification of necessary resources • Outcomes feed BCP strategy selection • Reviewed with BIA
Evaluating Threats (Risk Assessment) • Risk equation + time element • Risk = Threat impact * probability • Prioritize key processes and assets • Outcomes
Key Indicators or Success • Corporate governance • BIA practice • Risk assessment practice
BCP Project Phases • Project Scope Development and Planning • Business Impact Analysis (BIA) and Functional Requirements • Business Continuity and Recovery Strategy • Plan Design and Development • Implementation • Restoration / Disaster Recovery • Feedback and Plan Management
Determining Business Continuity Strategy • High-level strategies • RTO < MTPD • Separation distance • Resilience • Address specific business types
Determining Strategy • Determining BC strategies • Strategy options • Activity continuity options • Resource-level consolidation
Activity Continuity Options • Selecting recovery tactics • Reliability • Extent of planning • Cost/benefit analysis • Outcome
BCP Project Phases • Project Scope Development and Planning • Business Impact Analysis (BIA) and Functional Requirements • Business Continuity and Recovery Strategy • Plan Design and Development • Implementation • Restoration / Disaster Recovery • Feedback and Plan Management
Resource Level Consolidation • Consolidation plan • Availability of solutions • Consolidate, approve, implement • Methods and techniques • Outcomes and deliverables
Business Continuity Plan • Master plan • Modular in design • Executive endorsement • Review quarterly
Business Continuity Plan Contents • When team will be activated • Means by which the team will be activated • Places to meet • Action plans/task list created
Business Continuity Plan Contents • Responsibilities of the team or of specific individuals • Liaising with Emergency Services (fire, police ambulance) • Receiving or seeking information from response teams • Reporting information to the Incident Management Team • Mobilizing third party suppliers of salvage and recovery services • Allocating available resources to recovery teams • Invocation / mobilization instructions
Developing and Implementing Response • Incident response structure • Emergency response procedures • Personnel notification • Communications • Restoration
BCP Project Phases • Project Scope Development and Planning • Business Impact Analysis (BIA) and Functional Requirements • Business Continuity and Recovery Strategy • Plan Design and Development • Implementation • Restoration / Disaster Recovery • Feedback and Plan Management
Implementing Incident Management Plan • Rapid response is critical • Crisis management • Steps to develop an Incident Management Plan • Action plans
Incident Response Structure • Strategic • Tactical • Operational
Key Indicators of Success • Development and acceptance of Recovery Strategies and Business Continuity Plans
BCP Project Phases • Project Scope Development and Planning • Business Impact Analysis (BIA) and Functional Requirements • Business Continuity and Recovery Strategy • Plan Design and Development • Implementation • Restoration / Disaster Recovery • Feedback and Plan Management
Disaster Recovery • Salvage • Separate function and team • Facility restoration • System recovery
BCP Project Phases • Project Scope Development and Planning • Business Impact Analysis (BIA) and Functional Requirements • Business Continuity and Recovery Strategy • Plan Design and Development • Implementation • Restoration / Disaster Recovery • Feedback and Plan Management
Testing the Program • Find the flaws • Outsourcing • Timetable for tests • Test design process
Embedding BCP • Assessing level of awareness and training • Developing BCP within the Culture • Monitoring cultural change
Test BCP Arrangements • Test, rehearsal, exercise • Combine all plan activities • Stringency, realism and minimal exposure • Contents of a test • Outcomes