Disaster Recovery Plan / Enterprise Continuity Plan

Marcelo Silva
Marcelo SilvaInformation Security Engineer
DRP/ECP
Disaster Recovery Plan / Enterprise
Continuity Plan
Marcelo Silva
Agenda









Introduction
Roles of DRP/ECP
The 6 Resilience Layers
Training for the DRP team
Choosing outside expertise to assist with
development of a DRP
Developing a DRP/ECP awareness campaign
Implementing a DRP/ECP awareness campaign
Introduction





Why DRP/ECP?
Benefits of a DRP/ECP
Three vital Ingredients of a successful DRP/ECP
Defensive Posture / Offensive Posture
Roles of DRP/ECP








Emergency Management team (EMT)
Damage Assessment Team
Restoration Team
Operations Team
Customer Support Team
Salvage/Reclamation Team
Administrative Support Team
The 6 Resilience Layers
1.
2.
3.
4.
5.
6.

Strategy
Organization
Business and IT Processes
Data and Applications
Technology
Facilities and security
The 6 Resilience Layers
1.Strategy
Strategy is the first layer to be discussed
On this layer, the below components will be
assessed and examined:
 Vulnerabilities
 Risks
 Competitive edge
 baseline organizational culture
The 6 Resilience Layers
2.Organization






Executive sponsor
Roles, Responsibilities and Accountabilities
Well defined communication protocol
Cross-line-of-business linkage
Skills that are critical to the company
The 6 Resilience Layers
3.Business and IT Process
A successful plan requires identify:










The minimum required functionalities during disruptive
events
Alternate process/procedure that will allow operations to
continue
Processes to achieve better workload balance

All processes and the contingency plan must be
clear to all organization’s stakeholders
Business processes that support Virtual, flexible and
distributed workplaces
The 6 Resilience Layers
4.Data and Applications





Good, valuable and reliable information
Data and Application diversification
Architectures standardization
Ensure performance, availability and scalability
The 6 Resilience Layers
5.Technology
Technology components when
planning resiliency:
 Hardware architecture
 System software
 Middleware
 Networks
 Security Solutions

Levels of availability that
should be aligned to the
resiliency objectives:
 Reliability
 Redundancy
 Failover
The 6 Resilience Layers
6.Facilities and Security
Level of the enterprise’s facilities:
 Environment considerations
 Geographical location
 Dispersion
 Security Access (Physical and logical security)
 Power protection
 Heating and cooling
The 6 Resilience Layers
Examples
1.

2.

3.

4.

5.

6.

Strategy

The university position in comparison to others
Organization

Executive support
Business and IT Processes

IT Processes changing
Data and Applications

SharePoint Server for all data – Diversification is required
Technology

No additional Exchange or SharePoint server
Facilities and security

Eminent power outage in case of disaster
Training for the DRP team








Risk evaluation and control
Business impact analysis
Emergency response and operations
Incident management
Developing and implementing DRP/ECPs
Maintaining and exercising BCPs
Public relations, media and crisis communication
Choosing outside expertise to
assist with development of a DRP
Consultant that:

Acts as a facilitator whenever it is appropriate

Produces solid lasting solutions

Understands and acts to further the client’s mission

Only makes promises when they can be kept

Minimizes dependency of the client on the consultant

Encourages the client’s competence, confidence and commitment

Works with the client on the problem solution

Focuses on the relationship with the client and technical problems

Doesn’t take on any of the client’s responsibilities.
Developing a DRP/ECP awareness
campaign





Establish goals and Components
Define the training/awareness method
Identify the target / audience
Implementing the awareness program
Implementing a DRP/ECP
awareness campaign






Include DRP/ECP in the New Hire Orientation
Formal training
Awareness seminars and Brown bag sessions
Newsletter and Intranet
DRP/ECP quizzes
References












Hiles, A. (2007). The Definitive Handbook of Business Continuity
Management, Second Edition. John Wiley & Sons.
Hiles, A. (2011). The Definitive Handbook of Business Continuity
Management, Third Edition. John Wiley & Sons.
Goble, G., Fields, H., & Cocchiara, R. (2002). Resilient Infrastructure:
improving your business resilience. IBM Global Services.
Maiwald, E., & Sieglein, W. (2002). Security Planning & Disaster Recovery.
Berkeley, CA: McGraw-Hill/Osborne.
BS 25999-1 (2006). Business Continuity Management - Code of Practice.
BSI.
BS 25999-2 (2007). Business Continuity Management - Specification. BSI.
1 de 17

Recomendados

Disaster Recovery Plan por
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery PlanIndeevari Ramanayake
5.5K visualizações49 slides
IT-Centric Disaster Recovery & Business Continuity por
IT-Centric Disaster Recovery & Business ContinuityIT-Centric Disaster Recovery & Business Continuity
IT-Centric Disaster Recovery & Business ContinuitySteve Susina
2.4K visualizações23 slides
Disaster Recovery Plan for IT por
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IThhuihhui
36.1K visualizações11 slides
business-continuity-management-awareness-presentation-for-mampu2929 por
business-continuity-management-awareness-presentation-for-mampu2929business-continuity-management-awareness-presentation-for-mampu2929
business-continuity-management-awareness-presentation-for-mampu2929Andy Willams
868 visualizações49 slides
Disaster Recovery Plan por
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Planmhdpaknejad
667 visualizações12 slides
Bcp drp por
Bcp drpBcp drp
Bcp drpaqel aqel
3.6K visualizações29 slides

Mais conteúdo relacionado

Mais procurados

Business Continuity Planning por
Business Continuity PlanningBusiness Continuity Planning
Business Continuity PlanningDipankar Ghosh
2.2K visualizações24 slides
Disaster Recovery Plan por
Disaster Recovery Plan Disaster Recovery Plan
Disaster Recovery Plan Emilie Gray
460 visualizações11 slides
Business Continuity Workshop Final por
Business Continuity Workshop   FinalBusiness Continuity Workshop   Final
Business Continuity Workshop FinalBill Lisse
3.7K visualizações51 slides
Disaster Recovery Planning por
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery PlanningJohn Wilson
1.3K visualizações26 slides
How to write an IT DR plan por
How to write an IT DR planHow to write an IT DR plan
How to write an IT DR planDatabarracks
5.6K visualizações20 slides
Building a Business Continuity Capability por
Building a Business Continuity CapabilityBuilding a Business Continuity Capability
Building a Business Continuity CapabilityRod Davis
754 visualizações58 slides

Mais procurados(20)

Business Continuity Planning por Dipankar Ghosh
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
Dipankar Ghosh2.2K visualizações
Disaster Recovery Plan por Emilie Gray
Disaster Recovery Plan Disaster Recovery Plan
Disaster Recovery Plan
Emilie Gray460 visualizações
Business Continuity Workshop Final por Bill Lisse
Business Continuity Workshop   FinalBusiness Continuity Workshop   Final
Business Continuity Workshop Final
Bill Lisse3.7K visualizações
Disaster Recovery Planning por John Wilson
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery Planning
John Wilson1.3K visualizações
How to write an IT DR plan por Databarracks
How to write an IT DR planHow to write an IT DR plan
How to write an IT DR plan
Databarracks5.6K visualizações
Building a Business Continuity Capability por Rod Davis
Building a Business Continuity CapabilityBuilding a Business Continuity Capability
Building a Business Continuity Capability
Rod Davis754 visualizações
Business Continuity Planning Presentation Overview por Bob Winkler
Business Continuity Planning Presentation OverviewBusiness Continuity Planning Presentation Overview
Business Continuity Planning Presentation Overview
Bob Winkler7.3K visualizações
BCP Awareness por Imad Almurib
BCP Awareness BCP Awareness
BCP Awareness
Imad Almurib7.3K visualizações
Business continuity & Disaster recovery planing por Hanaysha
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planing
Hanaysha5.5K visualizações
Business continuity planning and disaster recovery por madunix
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recovery
madunix3.2K visualizações
Effective Business Continuity Plan Powerpoint Presentation Slides por SlideTeam
Effective Business Continuity Plan Powerpoint Presentation SlidesEffective Business Continuity Plan Powerpoint Presentation Slides
Effective Business Continuity Plan Powerpoint Presentation Slides
SlideTeam188 visualizações
Developing and Managing Business Continuity Plan (BCP) por Goutama Bachtiar
Developing and Managing Business Continuity Plan (BCP)Developing and Managing Business Continuity Plan (BCP)
Developing and Managing Business Continuity Plan (BCP)
Goutama Bachtiar8.3K visualizações
Business continuity & disaster recovery planning (BCP & DRP) por Narudom Roongsiriwong, CISSP
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
Narudom Roongsiriwong, CISSP51.6K visualizações
Business Continuity & Disaster Recovery por EC-Council
Business Continuity & Disaster RecoveryBusiness Continuity & Disaster Recovery
Business Continuity & Disaster Recovery
EC-Council759 visualizações
Disaster Recovery Plan por David Donovan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
David Donovan2.3K visualizações
Best Practices in Disaster Recovery Planning and Testing por Axcient
Best Practices in Disaster Recovery Planning and TestingBest Practices in Disaster Recovery Planning and Testing
Best Practices in Disaster Recovery Planning and Testing
Axcient9.3K visualizações
Disaster Recovery Planning PowerPoint Presentation Slides por SlideTeam
Disaster Recovery Planning PowerPoint Presentation SlidesDisaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation Slides
SlideTeam1.7K visualizações
Business continuity and disaster recovery por Adeel Javaid
Business continuity and disaster recoveryBusiness continuity and disaster recovery
Business continuity and disaster recovery
Adeel Javaid6.3K visualizações
Business continuity planning and disaster recovery por KrutiShah114
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recovery
KrutiShah114492 visualizações
What is business continuity planning-bcp por Adv Prashant Mali
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcp
Adv Prashant Mali5.5K visualizações

Destaque

An Introduction to Disaster Recovery Planning por
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery PlanningNEBizRecovery
30.8K visualizações20 slides
Disaster Recovery Presentation por
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery PresentationTimSchaefer
11.3K visualizações30 slides
The A to Z Guide to Business Continuity and Disaster Recovery por
The A to Z Guide to Business Continuity and Disaster RecoveryThe A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoverySirius
32.8K visualizações87 slides
Disaster Recovery & Data Backup Strategies por
Disaster Recovery & Data Backup StrategiesDisaster Recovery & Data Backup Strategies
Disaster Recovery & Data Backup StrategiesSpiceworks
25.8K visualizações36 slides
Business Continuity And Disaster Recovery Notes por
Business Continuity And Disaster Recovery NotesBusiness Continuity And Disaster Recovery Notes
Business Continuity And Disaster Recovery NotesAlan McSweeney
11.7K visualizações32 slides

Destaque(19)

An Introduction to Disaster Recovery Planning por NEBizRecovery
An Introduction to Disaster Recovery PlanningAn Introduction to Disaster Recovery Planning
An Introduction to Disaster Recovery Planning
NEBizRecovery30.8K visualizações
Disaster Recovery Presentation por TimSchaefer
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery Presentation
TimSchaefer11.3K visualizações
The A to Z Guide to Business Continuity and Disaster Recovery por Sirius
The A to Z Guide to Business Continuity and Disaster RecoveryThe A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster Recovery
Sirius32.8K visualizações
Disaster Recovery & Data Backup Strategies por Spiceworks
Disaster Recovery & Data Backup StrategiesDisaster Recovery & Data Backup Strategies
Disaster Recovery & Data Backup Strategies
Spiceworks25.8K visualizações
Business Continuity And Disaster Recovery Notes por Alan McSweeney
Business Continuity And Disaster Recovery NotesBusiness Continuity And Disaster Recovery Notes
Business Continuity And Disaster Recovery Notes
Alan McSweeney11.7K visualizações
DoS Attack - Incident Handling por Marcelo Silva
DoS Attack - Incident HandlingDoS Attack - Incident Handling
DoS Attack - Incident Handling
Marcelo Silva4.9K visualizações
5 Things Every IT Disaster Recovery Plan Should Include por CWPS
5 Things Every IT Disaster Recovery Plan Should Include5 Things Every IT Disaster Recovery Plan Should Include
5 Things Every IT Disaster Recovery Plan Should Include
CWPS 357 visualizações
Drp For Menora por Pini Cohen
Drp For MenoraDrp For Menora
Drp For Menora
Pini Cohen1K visualizações
02 Practical Strategies of Conducting BIA por BCM Institute
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA
BCM Institute3.5K visualizações
Assessment task 3 powerpoint presentation por Byron Polley
Assessment task 3   powerpoint presentationAssessment task 3   powerpoint presentation
Assessment task 3 powerpoint presentation
Byron Polley3.1K visualizações
Why inspection? por Saiko Shiroto
Why inspection?Why inspection?
Why inspection?
Saiko Shiroto309 visualizações
System Architecture v3.0 por Jon Fortman
System Architecture v3.0System Architecture v3.0
System Architecture v3.0
Jon Fortman272 visualizações
Introduction to the Enterprise Architecture Toolkit - Japanese por Mike Walker
Introduction to the Enterprise Architecture Toolkit - JapaneseIntroduction to the Enterprise Architecture Toolkit - Japanese
Introduction to the Enterprise Architecture Toolkit - Japanese
Mike Walker1.6K visualizações
Improving on How Architectures are Described por Mike Walker
Improving on How Architectures are DescribedImproving on How Architectures are Described
Improving on How Architectures are Described
Mike Walker1K visualizações
ARC 2015 Business Continuity por SWIFT
ARC 2015 Business Continuity ARC 2015 Business Continuity
ARC 2015 Business Continuity
SWIFT878 visualizações
Business Impact Analysis - The Most Important Step during BCMS Implementation por PECB
Business Impact Analysis - The Most Important Step during BCMS ImplementationBusiness Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS Implementation
PECB 3.6K visualizações
A Board Perspective on Enterprise Risk Management por Turlough Guerin GAICD FGIA
A Board Perspective on Enterprise Risk ManagementA Board Perspective on Enterprise Risk Management
A Board Perspective on Enterprise Risk Management
Turlough Guerin GAICD FGIA961 visualizações

Similar a Disaster Recovery Plan / Enterprise Continuity Plan

Integrating Resiliency As A Strategic Priority por
Integrating Resiliency As A Strategic PriorityIntegrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic PriorityGeoff Rodrigues
321 visualizações35 slides
Integrating Resiliency As A Strategic Priority por
Integrating Resiliency As A Strategic PriorityIntegrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic PriorityGeoff Rodrigues
358 visualizações35 slides
Product Management And Service Delivery Process - FlackVentures Example por
Product Management And Service Delivery Process - FlackVentures ExampleProduct Management And Service Delivery Process - FlackVentures Example
Product Management And Service Delivery Process - FlackVentures ExampleKate Pynn
23.9K visualizações32 slides
CERTIFIED INFORMATION TECHNOLOGY MANAGER por
CERTIFIED INFORMATION TECHNOLOGY MANAGERCERTIFIED INFORMATION TECHNOLOGY MANAGER
CERTIFIED INFORMATION TECHNOLOGY MANAGERDee Smith & Associates
246 visualizações4 slides
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl Davey por
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl DaveyRisk Leadership Perspectives Breakfast Risk Manager of the Year Karl Davey
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl Daveykarld
509 visualizações35 slides
Data analysis and interpretation flyer por
Data analysis and interpretation flyerData analysis and interpretation flyer
Data analysis and interpretation flyerKALVI World
249 visualizações3 slides

Similar a Disaster Recovery Plan / Enterprise Continuity Plan(20)

Integrating Resiliency As A Strategic Priority por Geoff Rodrigues
Integrating Resiliency As A Strategic PriorityIntegrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic Priority
Geoff Rodrigues321 visualizações
Integrating Resiliency As A Strategic Priority por Geoff Rodrigues
Integrating Resiliency As A Strategic PriorityIntegrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic Priority
Geoff Rodrigues358 visualizações
Product Management And Service Delivery Process - FlackVentures Example por Kate Pynn
Product Management And Service Delivery Process - FlackVentures ExampleProduct Management And Service Delivery Process - FlackVentures Example
Product Management And Service Delivery Process - FlackVentures Example
Kate Pynn23.9K visualizações
CERTIFIED INFORMATION TECHNOLOGY MANAGER por Dee Smith & Associates
CERTIFIED INFORMATION TECHNOLOGY MANAGERCERTIFIED INFORMATION TECHNOLOGY MANAGER
CERTIFIED INFORMATION TECHNOLOGY MANAGER
Dee Smith & Associates246 visualizações
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl Davey por karld
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl DaveyRisk Leadership Perspectives Breakfast Risk Manager of the Year Karl Davey
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl Davey
karld509 visualizações
Data analysis and interpretation flyer por KALVI World
Data analysis and interpretation flyerData analysis and interpretation flyer
Data analysis and interpretation flyer
KALVI World249 visualizações
Orlando SFDC User Group 8/2009 por Joshua Hoskins
Orlando SFDC User Group 8/2009Orlando SFDC User Group 8/2009
Orlando SFDC User Group 8/2009
Joshua Hoskins406 visualizações
Do data leaders face unique challenges as leaders? por Paul Laughlin
Do data leaders face unique challenges as leaders?Do data leaders face unique challenges as leaders?
Do data leaders face unique challenges as leaders?
Paul Laughlin164 visualizações
Business Analytics por Prem Anand
Business AnalyticsBusiness Analytics
Business Analytics
Prem Anand204 visualizações
110430 bcm presentation v0.1 mj por Mike Jackson - LION
110430 bcm presentation v0.1 mj110430 bcm presentation v0.1 mj
110430 bcm presentation v0.1 mj
Mike Jackson - LION311 visualizações
Enterprise Content Management (ECM) System por Anand Subramaniam
Enterprise Content Management (ECM) SystemEnterprise Content Management (ECM) System
Enterprise Content Management (ECM) System
Anand Subramaniam27.3K visualizações
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docx por mydrynan
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docxCRM Training and Simulation Programs ASCI 516Module 7 Presen.docx
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docx
mydrynan2 visualizações
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docx por Jack632244
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docxCRM Training and Simulation Programs ASCI 516Module 7 Presen.docx
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docx
Jack6322446 visualizações
Feb2008 Service Desk Maturity Models & Fram por IT Service and Support
Feb2008 Service Desk Maturity Models & FramFeb2008 Service Desk Maturity Models & Fram
Feb2008 Service Desk Maturity Models & Fram
IT Service and Support4.7K visualizações
TalentGuider - Capability Development in Pharma functions por Markus Moravek
TalentGuider - Capability Development in Pharma functionsTalentGuider - Capability Development in Pharma functions
TalentGuider - Capability Development in Pharma functions
Markus Moravek2.1K visualizações
4 Steps To Boost Agent Productivity por Nicolas Rodriguez
4 Steps To Boost Agent Productivity4 Steps To Boost Agent Productivity
4 Steps To Boost Agent Productivity
Nicolas Rodriguez559 visualizações
4 Strategies To Boost Agent Productivity por Aggregage
4 Strategies To Boost Agent Productivity4 Strategies To Boost Agent Productivity
4 Strategies To Boost Agent Productivity
Aggregage233 visualizações
Talent Management por Doug Young
Talent Management Talent Management
Talent Management
Doug Young12.9K visualizações
TCG Svcs Pres 2011 por mcourton
TCG Svcs Pres 2011TCG Svcs Pres 2011
TCG Svcs Pres 2011
mcourton198 visualizações

Último

Super Solar Mounting Solutions 20230509(1).pdf por
Super Solar Mounting Solutions 20230509(1).pdfSuper Solar Mounting Solutions 20230509(1).pdf
Super Solar Mounting Solutions 20230509(1).pdfcarrie55bradshaw
12 visualizações25 slides
PMU Launch - Guaranteed Slides por
PMU Launch - Guaranteed SlidesPMU Launch - Guaranteed Slides
PMU Launch - Guaranteed Slidespmulaunch
18 visualizações64 slides
The Talent Management Navigator Performance Management por
The Talent Management Navigator Performance ManagementThe Talent Management Navigator Performance Management
The Talent Management Navigator Performance ManagementSeta Wicaksana
35 visualizações36 slides
case study of Insertion Type Magnetic Flowmeter exports to Australia_ (1).docx por
case study of Insertion Type Magnetic Flowmeter exports to Australia_ (1).docxcase study of Insertion Type Magnetic Flowmeter exports to Australia_ (1).docx
case study of Insertion Type Magnetic Flowmeter exports to Australia_ (1).docxDalian Zero Instrument Technology Co., Ltd China
32 visualizações5 slides
voice logger software aegis.pdf por
voice logger software aegis.pdfvoice logger software aegis.pdf
voice logger software aegis.pdfNirmal Sharma
47 visualizações1 slide
Better Appeals and Solicitations - Bloomerang.pdf por
Better Appeals and Solicitations - Bloomerang.pdfBetter Appeals and Solicitations - Bloomerang.pdf
Better Appeals and Solicitations - Bloomerang.pdfBloomerang
81 visualizações51 slides

Último(20)

Super Solar Mounting Solutions 20230509(1).pdf por carrie55bradshaw
Super Solar Mounting Solutions 20230509(1).pdfSuper Solar Mounting Solutions 20230509(1).pdf
Super Solar Mounting Solutions 20230509(1).pdf
carrie55bradshaw12 visualizações
PMU Launch - Guaranteed Slides por pmulaunch
PMU Launch - Guaranteed SlidesPMU Launch - Guaranteed Slides
PMU Launch - Guaranteed Slides
pmulaunch18 visualizações
The Talent Management Navigator Performance Management por Seta Wicaksana
The Talent Management Navigator Performance ManagementThe Talent Management Navigator Performance Management
The Talent Management Navigator Performance Management
Seta Wicaksana35 visualizações
voice logger software aegis.pdf por Nirmal Sharma
voice logger software aegis.pdfvoice logger software aegis.pdf
voice logger software aegis.pdf
Nirmal Sharma47 visualizações
Better Appeals and Solicitations - Bloomerang.pdf por Bloomerang
Better Appeals and Solicitations - Bloomerang.pdfBetter Appeals and Solicitations - Bloomerang.pdf
Better Appeals and Solicitations - Bloomerang.pdf
Bloomerang81 visualizações
Nevigating Sucess.pdf por TEWMAGAZINE
Nevigating Sucess.pdfNevigating Sucess.pdf
Nevigating Sucess.pdf
TEWMAGAZINE26 visualizações
Bloomerang_Forecasting Your Fundraising Revenue 2024.pptx.pdf por Bloomerang
Bloomerang_Forecasting Your Fundraising Revenue 2024.pptx.pdfBloomerang_Forecasting Your Fundraising Revenue 2024.pptx.pdf
Bloomerang_Forecasting Your Fundraising Revenue 2024.pptx.pdf
Bloomerang167 visualizações
The Truth About Customer Journey Mapping por Aggregage
The Truth About Customer Journey MappingThe Truth About Customer Journey Mapping
The Truth About Customer Journey Mapping
Aggregage117 visualizações
Pitch Deck Teardown: Scalestack's $1M AI sales tech Seed deck por HajeJanKamps
Pitch Deck Teardown: Scalestack's $1M AI sales tech Seed deckPitch Deck Teardown: Scalestack's $1M AI sales tech Seed deck
Pitch Deck Teardown: Scalestack's $1M AI sales tech Seed deck
HajeJanKamps663 visualizações
On the Concept of Discovery Power of Enterprise Modeling Languages and its Re... por Ilia Bider
On the Concept of Discovery Power of Enterprise Modeling Languages and its Re...On the Concept of Discovery Power of Enterprise Modeling Languages and its Re...
On the Concept of Discovery Power of Enterprise Modeling Languages and its Re...
Ilia Bider15 visualizações
Engaging Senior Leaders to Accelerate Your Continuous Improvement Program por KaiNexus
Engaging Senior Leaders to Accelerate Your Continuous Improvement ProgramEngaging Senior Leaders to Accelerate Your Continuous Improvement Program
Engaging Senior Leaders to Accelerate Your Continuous Improvement Program
KaiNexus12 visualizações
Accel_Series_2023Autumn_En.pptx por NTTDATA INTRAMART
Accel_Series_2023Autumn_En.pptxAccel_Series_2023Autumn_En.pptx
Accel_Series_2023Autumn_En.pptx
NTTDATA INTRAMART209 visualizações
port23_2023121_resize2.pdf por Sivaphan Wuttingam
port23_2023121_resize2.pdfport23_2023121_resize2.pdf
port23_2023121_resize2.pdf
Sivaphan Wuttingam32 visualizações
Basic of Air Ticketing & IATA Geography por Md Shaifullar Rabbi
Basic of Air Ticketing & IATA GeographyBasic of Air Ticketing & IATA Geography
Basic of Air Ticketing & IATA Geography
Md Shaifullar Rabbi 69 visualizações
2023 Photo Contest.pptx por culhama
2023 Photo Contest.pptx2023 Photo Contest.pptx
2023 Photo Contest.pptx
culhama35 visualizações
Netflix Inc. por 125071027
Netflix Inc.Netflix Inc.
Netflix Inc.
12507102711 visualizações
Valuation Quarterly Webinar Dec23.pdf por FelixPerez547899
Valuation Quarterly Webinar Dec23.pdfValuation Quarterly Webinar Dec23.pdf
Valuation Quarterly Webinar Dec23.pdf
FelixPerez54789942 visualizações
Top 10 Web Development Companies in California por TopCSSGallery
Top 10 Web Development Companies in CaliforniaTop 10 Web Development Companies in California
Top 10 Web Development Companies in California
TopCSSGallery76 visualizações

Disaster Recovery Plan / Enterprise Continuity Plan

  • 1. DRP/ECP Disaster Recovery Plan / Enterprise Continuity Plan Marcelo Silva
  • 2. Agenda        Introduction Roles of DRP/ECP The 6 Resilience Layers Training for the DRP team Choosing outside expertise to assist with development of a DRP Developing a DRP/ECP awareness campaign Implementing a DRP/ECP awareness campaign
  • 3. Introduction     Why DRP/ECP? Benefits of a DRP/ECP Three vital Ingredients of a successful DRP/ECP Defensive Posture / Offensive Posture
  • 4. Roles of DRP/ECP        Emergency Management team (EMT) Damage Assessment Team Restoration Team Operations Team Customer Support Team Salvage/Reclamation Team Administrative Support Team
  • 5. The 6 Resilience Layers 1. 2. 3. 4. 5. 6. Strategy Organization Business and IT Processes Data and Applications Technology Facilities and security
  • 6. The 6 Resilience Layers 1.Strategy Strategy is the first layer to be discussed On this layer, the below components will be assessed and examined:  Vulnerabilities  Risks  Competitive edge  baseline organizational culture
  • 7. The 6 Resilience Layers 2.Organization      Executive sponsor Roles, Responsibilities and Accountabilities Well defined communication protocol Cross-line-of-business linkage Skills that are critical to the company
  • 8. The 6 Resilience Layers 3.Business and IT Process A successful plan requires identify:      The minimum required functionalities during disruptive events Alternate process/procedure that will allow operations to continue Processes to achieve better workload balance All processes and the contingency plan must be clear to all organization’s stakeholders Business processes that support Virtual, flexible and distributed workplaces
  • 9. The 6 Resilience Layers 4.Data and Applications     Good, valuable and reliable information Data and Application diversification Architectures standardization Ensure performance, availability and scalability
  • 10. The 6 Resilience Layers 5.Technology Technology components when planning resiliency:  Hardware architecture  System software  Middleware  Networks  Security Solutions Levels of availability that should be aligned to the resiliency objectives:  Reliability  Redundancy  Failover
  • 11. The 6 Resilience Layers 6.Facilities and Security Level of the enterprise’s facilities:  Environment considerations  Geographical location  Dispersion  Security Access (Physical and logical security)  Power protection  Heating and cooling
  • 12. The 6 Resilience Layers Examples 1. 2. 3. 4. 5. 6. Strategy  The university position in comparison to others Organization  Executive support Business and IT Processes  IT Processes changing Data and Applications  SharePoint Server for all data – Diversification is required Technology  No additional Exchange or SharePoint server Facilities and security  Eminent power outage in case of disaster
  • 13. Training for the DRP team        Risk evaluation and control Business impact analysis Emergency response and operations Incident management Developing and implementing DRP/ECPs Maintaining and exercising BCPs Public relations, media and crisis communication
  • 14. Choosing outside expertise to assist with development of a DRP Consultant that:  Acts as a facilitator whenever it is appropriate  Produces solid lasting solutions  Understands and acts to further the client’s mission  Only makes promises when they can be kept  Minimizes dependency of the client on the consultant  Encourages the client’s competence, confidence and commitment  Works with the client on the problem solution  Focuses on the relationship with the client and technical problems  Doesn’t take on any of the client’s responsibilities.
  • 15. Developing a DRP/ECP awareness campaign     Establish goals and Components Define the training/awareness method Identify the target / audience Implementing the awareness program
  • 16. Implementing a DRP/ECP awareness campaign      Include DRP/ECP in the New Hire Orientation Formal training Awareness seminars and Brown bag sessions Newsletter and Intranet DRP/ECP quizzes
  • 17. References       Hiles, A. (2007). The Definitive Handbook of Business Continuity Management, Second Edition. John Wiley & Sons. Hiles, A. (2011). The Definitive Handbook of Business Continuity Management, Third Edition. John Wiley & Sons. Goble, G., Fields, H., & Cocchiara, R. (2002). Resilient Infrastructure: improving your business resilience. IBM Global Services. Maiwald, E., & Sieglein, W. (2002). Security Planning & Disaster Recovery. Berkeley, CA: McGraw-Hill/Osborne. BS 25999-1 (2006). Business Continuity Management - Code of Practice. BSI. BS 25999-2 (2007). Business Continuity Management - Specification. BSI.

Notas do Editor

  1. Western Governors UniversityMaster of Science, Information Security and AssuranceFXT2 – Disaster Recovery Planning, Prevention and ResponseMarcelo Braga SilvaStudent ID: 000200452
  2. This Agenda will cover the requirements for the Task 1 of the FXT2 course, part of the Master of Science, Information Security and Assurance program at WGU.January, 2014.
  3. According to Goble, Fields, & Cocchiara (2002), resilient infrastructures are those ones that are “capable of proactively responding to both anticipated and unexpected stress and strains” (p. 2).Thus, following below an introduction on the Disaster recovery Plan and Enterprise Continuity Plan:Why DRP/ECP?In case some infrastructure failure, if the university is not well prepared to respond to such unexpected event, it can lose some business opportunities, students and partners, reputation and credibility, research data, and even its most valuable information and applications.Benefits of a DRP/ECPIdentification of critical applications and services for the businessIdentification and preparedness for the major risksReduce the downtimes of applications and services Improve operational effectiveness and resilienceProtection of assetsBe compliance with national and international laws and standardsImprove securityDemonstrate continuity capabilities for the market, including customers, partners and shareholdersThree vital Ingredients of a successful DRP/ECP (Goble, G., Fields, H., & Cocchiara, R. 2002, p. 9)Recovery  Safe, rapid, offsite data recoveryHardening  The fortification of all or part of the infrastructureRedundancy  The duplication of all or part of the infrastructure Defensive Posture / Offensive PostureDefensive Posture components:Recovery Hardening Redundancy Offensive Posture components:AccessibilityDiversificationAutonomic computing
  4. The DRP/ECP team are composed by different teams. One of the key teams is the Emergency Management Team (EMT)According to Hiles (2007), the EMT’s role is “to take business decisions, assess and make judgments on business priorities and to facilitate and support the business continuity manager. It also has an important role in marketing, public relations and media management issues.”Following below some roles of the DRP/ECP team members:Emergency Management Team Composed by key senior managers, Public relations and marketing and Business continuity manager or coordinator.Damage Assessment TeamThe Damage Assessment Team assesses the damage to the Data Center and reports to the EMT.Restoration TeamThis team brings the Production site systems and applications to operational mode in a DR site. And also brings they back to the production site.Operations TeamThe Operations Team assists in the recovery operations of infrastructure, systems and services.Customer Support TeamThis is the team that assists the customers (external/internal) during the disaster, until operations are resumed.Salvage/Reclamation TeamThe Salvage/Reclamation Team manages the restoration or rebuilding of the Data Center.Administrative Support TeamThe Administrative Support Team cooperate with logistical and organizational support for all other teams.
  5. This six layers represent the “Framework for resiliency” (Goble, Fields, & Cocchiara, 2002).This framework enables management and technical teams to lead the Enterprise to a successful Disaster Recovery Plan.
  6. When we talk about preparedness for anticipated and unexpected events, the Strategy layer is the first one to be discussed. On this layer, some assessments will examine components such as vulnerabilities and risks regarding to the enterprise, taking in account its industry position and its competitively. Also, the enterprise’s strategies and the baseline organizational culture will be examined. (Goble, Fields, & Cocchiara, 2002)
  7. Organizational changes are required to build a successful resiliency plan.It requires an Executive sponsor, usually a senior business leader or a Vice President.Roles, Responsibilities and AccountabilitiesWell defined communication protocolCross-line-of-business linkageSkills that are critical to the company
  8. The resiliency plan should focus on the business and IT process and procedures that are critical for the organization’s operation and its infrastructure. A successful plan requires identify:What are the minimum required functionalities during disruptive eventsAlternate process and procedure that will allow operations to continueProcesses to achieve better workload balanceAll processes and the contingency plan must be clear to all organization’s stakeholdersBusiness processes that support Virtual, flexible and distributed workplaces. (Goble, Fields, & Cocchiara, 2002).
  9. 21st Century organizations rely on good, valuable and reliable information, whether they are about customers, employees, competitors, products or suppliers, and the systems responsible for processing and analysing those information as well. Thus, multiples data and application sources are required. Data and Application diversificationArchitectures standardizationEnsure performance, availability and scalability
  10. Technology is a key component to create a resilient business. The IT infrastructure and the budget assigned to it must be aligned to the organization’s resiliency goals.Technology components when planning resiliency:Hardware architectureSystem softwareMiddlewareNetworksSecurity Solutions Levels of availability that should be aligned to the resiliency objectives:ReliabilityRedundancyFailoverSingle point of failure: Should be known and addressedHigh-Availability (HA) components in the infrastructure should be examined.Continuous replication across different sites (Primary/Secondary)
  11. When examining the resiliency level of the enterprise’s facilities:Environment considerationsGeographical locationDispersionSecurity Access (Physical and logical security)Power protection (UPS, batteries, Generators, etc.)Heating and cooling (Pods, Racks, small rooms, UPS rooms)Provide and testing the security mechanisms and equipment.
  12. Strategy: Risks, Vulnerabilities and competitively will be assessed, taking in account the position the university has in comparison to the other universities, regional and national.Organization: The university needs a executive support for the plan, and for all organizational changes that the university will need for a successful DRP.Business and IT Processes: The university will have to change some IT process in order to enable employees and students to leverage the university’s infrastructure beyond of the three-floor facilities that it has currently.Data and Applications: Currently the university uses the Microsoft SharePoint for all data. However, for a good resilient plan, some diversification of data and application should be implemented, and high availability by implementing redundant servers across different sites also recommended.Technology: The university has only one server for each application: One Exchange Server and one SharePoint Server. Currently there is no redundancy neither additional servers for failover in case of disaster, or even to recover from a simple hardware failure. Thus, there is a single point of failure and it’s something that will be addressed in the technology layer of the Framework for Resiliency.Facilities: There are physical risks to the operations. Blizzards could potentially knock out power and earthquakes could damage the building.
  13. BS 25999-1 (2006) requires that “the organization should have a process for identifying and delivering the BCM awareness requirements of the organization and evaluating the effectiveness of its delivery.”Risk evaluation and controlBusiness impact analysisEmergency response and operationsIncident managementDeveloping and implementing DRP/ECPsMaintaining and exercising BCPsPublic relations, media and crisis communication
  14. The university should look for the following characteristics on outside expertise to assist with the development of a DRP:Acts as a facilitator whenever it is appropriateAvoids “quick fixes” and produces solid lasting solutionsUnderstands and acts to further the client’s missionDoes not confuse the client by talking in a different languageOnly makes promises when they can be keptKeeps a good relationship with others in the companyMinimizes dependency of the client on the consultantEncourages the client’s competence, confidence and commitmentWorks with the client on the problem solutionFocuses on the relationship with the client and technical problemsDoesn’t take on any of the client’s responsibilities.Hiles, A. (2007).
  15. BSI 25999-1 Business Continuity Management Code of Practice requires that “the organization should have a process for identifying and delivering the BCM awareness requirements of the organization and evaluating the effectiveness of its delivery.” (Hiles, 2011)Establish goals and ComponentsTraining the team leaders (“Train the trainers”) and other team membersCover the skills gaps in the Enterprise Continuity team, indicated in BS 25999/DRII Common Body of KnowledgeTrain the EC team through exercising the plan (Hiles, 2011).Disseminate all information related to the Disaster Recovery Plan and Enterprise Continuity Plan and Policy, including priorities and objectives, deliverables, level of acceptance of disruption and recovery time.Define the training/awareness methodInduction training for new hiresArticles, news and letters in corporate newslettersUse of internal web pages, blogs and Intranet.Conducting tests and exercises, with observersIdentify the target / audienceAll stakeholders: members of the Business Continuity team and other enterprise staff (Employees, contractors and consultants).Implementing the awareness program (next slide)
  16. Maiwald & Sieglein (2002) stated that we “should take advantage of every possible method to keep users interested and engaged”. Therefore, following below some training methods to be implemented as part of the DRP/ECP awareness campaign:Include DRP/ECP in the New Hire OrientationThe organization’s information security policies and procedures should be covered during the Orientation (Maiwald & Sieglein, 2002)The new hires should be compliant with all security policies and proceduresThe new hires should read and sign the Acceptable Use Policy and any other document related to the Information SecurityFormal trainingVendor’s specific training for the infrastructure and security teams: Network devices (Switches, routers, load balancers, gateways); Security solutions (Firewalls, proxies, IDS, IPS, Antivirus, HSMs); Servers (hardware, Operating Systems, Virtualization) among others.Internal training in accordance with each stakeholders group.Awareness seminars and Brown bag sessionsProvide information about new technologies within the company and the security related to themProvide the latest and useful information regards the DRP/ECPTell them how they can help in case of some unexpected event comes upExplain how the company is counting on them to have a successful DRP/ECP implementedNewsletter and IntranetImplement a quarterly Awareness Newsletter for end-usersCreate an area in the company Intranet dedicated to the DRP/ECP awarenessAdd some security-related information, including external links to vendor’s website and articlesDRP/ECP quizzesPeriodically enable some quizzes in the Intranet and also during some seminars and trainings, and promote some raffles as an way to encourage them.