Continuity Planning and Disaster recovery

Description

Mind Map on Continuity Planning and Disaster recovery, created by rdgmat001 on 05/06/2014.
rdgmat001
Mind Map by rdgmat001, updated more than 1 year ago
rdgmat001
Created by rdgmat001 almost 10 years ago
279
0

Resource summary

Continuity Planning and Disaster recovery
  1. Businesses need to plan for the unexpected to safeguard the organisation in the case of a disaster
    1. Ensuring continuous IT and IS operations is a part of a firms legal responsibility
      1. BCM, BCP and DRP
        1. BCP
          1. BCP is a methodology used for developing a plan to maintain business operations during, before and after a disruption
            1. Also involves efforts to ensure primary essential functions are operational during emergencies
            2. DRP
              1. BCP are the activities that take place before a disaster happens
                1. DRP are the activities which occur once a disaster happens
                  1. Disaster recovery is a part of BCP
                  2. BCM
                    1. The umbrella term for all processes that ensure business continuity (BCP) and return a business to normal following a disaster (DRP)
                    2. Differences between DRP and BCP
                      1. DRP
                        1. DRP focuses on IT
                          1. DRP aims to ensure systems recover to previous state
                            1. Looks Back
                              1. Emphasis the importance of recovering from a disaster from unknown threats
                              2. BCP
                                1. BCP focuses on the business as a whole
                                  1. Forward looking
                                    1. Ensure plans in place are to improve organisation and maintain survival
                                      1. Emphasises the importance of preventing disasters given known threats
                                  2. Business Continuity Planning
                                    1. Business components
                                      1. Ensure continuity of business components
                                        1. People
                                          1. Consider the human component and provide training
                                          2. Technology
                                            1. Technology is an integral part of BPs and system downtime causes problems
                                            2. Business Processes
                                              1. Put recovery processes into place in case of a disaster
                                                1. Document processes for easy refferrel during disasters
                                                2. Communication
                                                  1. Maintain communication during an emergency for quick responses and recovery
                                                    1. Create communication contingencies
                                                    2. Business information
                                                      1. Enterprise wide asset and is critical for the mission of the business
                                                        1. Need good information security
                                                        2. Customers
                                                          1. Maintain customer satisfaction and business reputation
                                                            1. Allow for customer service delivery even after a disaster
                                                            2. Suppliers
                                                              1. Important part of the value chain
                                                                1. Affected during disasters
                                                                  1. Plan to maintain supplier relationships and service
                                                                2. BC Risk assessment
                                                                  1. Risk are the factors that have the potential to halt business operations if they occur
                                                                    1. Identify the likelihood of potential risks, the magnitude of the impact and the adequacy of planned measures
                                                                      1. Look at internal and external factors to the business's nature, location and BPs
                                                                        1. Can use a risk matrix to determine the risk levels
                                                                          1. Risk matrix helps with preventing, mitigating and controlling risks
                                                                        2. Business impact analysis
                                                                          1. Process used to identify mission critical business functions...
                                                                            1. ... and calculate the effects of business functions not being operational based on their dependancies
                                                                              1. Also calculates timeframe in which functions should be restored
                                                                                1. Can be expressed in terms of money and hard or soft impacts
                                                                                  1. 3 phases
                                                                                    1. 1,) Determine critical bus. functions
                                                                                      1. 2.) Determine recovery time objective and recovery point objective for each function

                                                                                        Annotations:

                                                                                        • for technology the recovery time could be the maximum possible downtime for a technology and the acceptable loss of imformation
                                                                                        1. 3.) Evaluate resources needed to support and maintain functions in the event of disaster
                                                                                      2. Risk Management
                                                                                        1. Process of identifying, assessing and responding to risks
                                                                                          1. Bus. impact analysis important for risk management
                                                                                            1. Need risk mitigation strategies
                                                                                              1. When selecting a strategy consider risks, legislation, and reliability
                                                                                            2. Concepts and Principles of a BCP
                                                                                              1. Must formulate policies and procedures to address business continuity risks
                                                                                                1. Policies and procedures can form the framework of an effective BCP
                                                                                                  1. Continuity practices should be embedded into the design of IS and processes
                                                                                                  2. Business continuity culture
                                                                                                    1. BCM should provide an environment and framework in which BC measures will be supported and owned
                                                                                                      1. Building a business continuity culture should consist of
                                                                                                        1. Executive Management Support
                                                                                                          1. Identify stakeholders
                                                                                                            1. Formation of BCP team
                                                                                                              1. Employee Engagement

                                                                                                                Annotations:

                                                                                                                • employees should be driven to perform duties in the continuity team
                                                                                                                1. Shared vision and trust

                                                                                                                  Annotations:

                                                                                                                  • Shared vision and trust of bus continuity policy among all employees
                                                                                                                  1. Communication

                                                                                                                    Annotations:

                                                                                                                    • communication of policy to employees
                                                                                                                  2. Should have a training and education culture
                                                                                                                    1. BCP is a continuous process that should be implemented as a business culture
                                                                                                                  3. Disaster Recovery Planning
                                                                                                                    1. Focuses on recovering the IT systems of the organisation so the business can continue with operations

                                                                                                                      Annotations:

                                                                                                                      • Regaining access to the database, hardware and software
                                                                                                                      1. Disaster recovery management
                                                                                                                        1. Physical assets can be replaced but data can not
                                                                                                                          1. Data is a very important asset which is crucial for survival
                                                                                                                            1. Develop a contingency plan to minimise impact of a disaster
                                                                                                                              1. DRP is a legal requirement to ensure the effects of a disaster are mitigated
                                                                                                                                1. S.A. has passed legislation (POPI and King 3 Act) to cater for the risks of the pervasiveness of technology

                                                                                                                                  Annotations:

                                                                                                                                  • King 3 => states that management must demonstrate that the business has adequete business resilience arrangements in place POPI=>A responsible person must secure the integrity and confidentiality of their personal information by taking appropriate measures
                                                                                                                                  1. Recovery procedure
                                                                                                                                    1. Backing up information from primary data centers to a secondary data centre
                                                                                                                                      1. Data backed up must also be the most recent copy
                                                                                                                                        1. Primary and secondary data centers must be in separate locations so that they are not both affected at the same time
                                                                                                                                          1. The disaster recovery service must detect that a disaster has occurred so that the services can be switched over to the backup site
                                                                                                                                            1. The separation of location of the two data centers causes delays in response times so the service must detect when to switch back to the primary data center
                                                                                                                                            2. Critical success factors of DRP
                                                                                                                                              1. Top management committment

                                                                                                                                                Annotations:

                                                                                                                                                • Management provide funding, staffing and resources They decide when and how to implement DRP and the support
                                                                                                                                                1. Policies and goals

                                                                                                                                                  Annotations:

                                                                                                                                                  • Policies to define guidelines for DRP and who is accountable for planning and implementation DRP should be driven by need for a competitive advantage through resilient systems
                                                                                                                                                  1. Steering committee

                                                                                                                                                    Annotations:

                                                                                                                                                    • Steering committee to perform risk assessments and to determine the scope and objectives of the recovery process
                                                                                                                                                    1. Prioritisation

                                                                                                                                                      Annotations:

                                                                                                                                                      • Most important systems must be given priority
                                                                                                                                                      1. Alternative site for backup
                                                                                                                                                        1. Backup storage

                                                                                                                                                          Annotations:

                                                                                                                                                          • On- site backup, off site backup, cloud computing and personnel to recover data
                                                                                                                                                          1. Recovery team
                                                                                                                                                            1. Testing

                                                                                                                                                              Annotations:

                                                                                                                                                              • testing DRP to ensure it will be effective Develop plan for testing
                                                                                                                                                              1. Training

                                                                                                                                                                Annotations:

                                                                                                                                                                • Employees must understand the plan and their positions to address arising issues (dealing with stress and miscommunication) when plan is implemented
                                                                                                                                                                1. Documentation

                                                                                                                                                                  Annotations:

                                                                                                                                                                  • Documentation of strategies, procedures and objectives of DRP for quick reference
                                                                                                                                                                  1. Maintenance of DRP plan

                                                                                                                                                                    Annotations:

                                                                                                                                                                    • Updating DRP plan as business process and data change
                                                                                                                                                                2. Disaster recovery metrics
                                                                                                                                                                  1. Recovery time objective
                                                                                                                                                                    1. Maximum amount of time IT system can be down for after a disaster
                                                                                                                                                                      1. Likely to vary across nature of the business and the business process
                                                                                                                                                                        1. Generally the lower the RTO the higher the cost associated with it
                                                                                                                                                                        2. Recovery Point Objective
                                                                                                                                                                          1. Measure of the data loss given the maximum amount of time the organisation is willing to lose data over
                                                                                                                                                                          2. RTO,RPO, perfomance and availability affect which recovery strategy to implement
                                                                                                                                                                          3. Readiness of backup strategies
                                                                                                                                                                            1. Speed of recovery affected by the type of backup mechanism and the nature of available resources
                                                                                                                                                                              1. Backup sites
                                                                                                                                                                                1. Cold backup sites

                                                                                                                                                                                  Annotations:

                                                                                                                                                                                  • Backups on a periodic basis Long time to recover data and get servers up and working High RTO
                                                                                                                                                                                  1. Warm backup sites

                                                                                                                                                                                    Annotations:

                                                                                                                                                                                    • Uses dedicated hardware to keep the organisation operating at minimal levels Recovery can take minutes to hours
                                                                                                                                                                                    1. Hot backup sites

                                                                                                                                                                                      Annotations:

                                                                                                                                                                                      • Mirrored standby servers that are always available to run in case of a disaster Recovery time within seconds or minutes Real time synchronous backups
                                                                                                                                                                                      1. Fault tolerance

                                                                                                                                                                                        Annotations:

                                                                                                                                                                                        • IT systems which can switch to the backup site with no loss of data or service during disaster RTO and RPO are close to zero Highest level of system automatic failover
                                                                                                                                                                                  2. Benefits and challenges
                                                                                                                                                                                    1. Benefits
                                                                                                                                                                                      1. Reduction in exposure to risks
                                                                                                                                                                                        1. Improved operational resilience
                                                                                                                                                                                          1. Reduced downtime through contingency plans
                                                                                                                                                                                            1. Better service delivery
                                                                                                                                                                                              1. Compliance with legislation
                                                                                                                                                                                                1. Improved BPs
                                                                                                                                                                                                  1. Maintaining credibility as a business
                                                                                                                                                                                                  2. Challenges
                                                                                                                                                                                                    1. Costly and complex requirements
                                                                                                                                                                                                      1. Time consuming to identify critical systems that must be recovered
                                                                                                                                                                                                        1. Frameworks and standards too complex for small and medium businesses
                                                                                                                                                                                                          1. DRP regulations can be ambiguous
                                                                                                                                                                                                        2. Future trends
                                                                                                                                                                                                          1. BCM will be used to support tactical and strategic resilience
                                                                                                                                                                                                          Show full summary Hide full summary

                                                                                                                                                                                                          Similar

                                                                                                                                                                                                          Reducing the Impact of Earthquakes
                                                                                                                                                                                                          siobhan.quirk
                                                                                                                                                                                                          Chemistry 1
                                                                                                                                                                                                          kelsey.le.grange
                                                                                                                                                                                                          Meriya Pinales & Malika Hurt
                                                                                                                                                                                                          hurtmalika
                                                                                                                                                                                                          Chemistry 3 Extracting Metals Core GCSE
                                                                                                                                                                                                          Chloe Roberts
                                                                                                                                                                                                          Magnetism
                                                                                                                                                                                                          joan.march
                                                                                                                                                                                                          History of Psychology
                                                                                                                                                                                                          Reuben Caruana
                                                                                                                                                                                                          MCAT Bio: Hormones
                                                                                                                                                                                                          Mike Nervo
                                                                                                                                                                                                          Macbeth Notes
                                                                                                                                                                                                          Bella Ffion Martin
                                                                                                                                                                                                          Physics Unit 2 - Force, Acceleration And Terminal Velocity
                                                                                                                                                                                                          Ryan Storey
                                                                                                                                                                                                          How Sewing Machines Work
                                                                                                                                                                                                          faithkateridarli
                                                                                                                                                                                                          EPISTEMOLOGÍA
                                                                                                                                                                                                          Dayanna Fonseca