You are on page 1of 1

A statement of actions to take before, during, and after a disruptive event

Procedures for responding to an emergency, providing backup


Introduction Motivation and Study Techniques to help
operations during a disaster Cisco
Goals and objectives you learn, remember, and pass your
CISSP
technical exams!
Providing Backup systems and facilities CEH
Reciprocal Mutual aid agreements More coming soon...

Fully configured with HVAC Visit us www.mindcert.com


F&P and Workstations
Servers with Apps
Hot Site
Allows walk in
Short time BCPs are created to prevent
interruptions to normal business
High cost
Protect critical business processes
In between hot and cold from natural or manmade disasters
HVAC Strategy to allow for the resumption of
normal business activity
Simple infrastructure
Warm Site LAN /WAN
Not all systems Subscription services Introduction
Examine all critical information areas Telecomms
Medium time
Apps and Data
Medium cost
Staff Duties
HVAC
Disruptive Events Including strikes
No hardware on site but ready for it Data processing continuity Manmade events
Cold Site
Long time The Number One priority is to preserve life
Low cost Companies operations
Variation of a cold site Create detailed account of the work
In a truck or trailer Mobile Site List resources
HVAC Define management practices

Processing spread over multiple centres management


Multiple centers BCP Committee
IT
Contract with a bureau for alternative Scope and Plan Initiation
Deal with scope of plan
backup processing Service bureau Ultimate Responsibility
Roles and responsibilities Includes all phases
Backup off site
Electronic Vaulting Support is essential
Restore from remote Senior management

Parallel processing of transactions at remote site


CISSP Concept of due diligence may hold manage‐
Remote Journaling ment responsible if a loss occurs with due care
Business Continuity
Transaction Redundancy Disaster Recovery could have prevented it
Planning and Disaster
Like journaling but creates more Planning (DRP) Business Continu‐ A document to understand the impact a
redundancy by duplicating the Recovery Planning Impact may be financial or operational
database sets ity Planning (BCP) disruptive event would have on the business
Database Shadowing
Vulnerability assessment is normally a part of the BIA
Tested on a regular basis
Criticality Prioritization
No recovery ability exists until the plan is tested
Downtime estimation maximum Tolerable Downtime (MTD)
3 primary Goals
Verifies the accuracy of the plan
Distribute plan for review Checklist Four Prime Elements Resource requirement

BIA Step 1 - Gather Assessment Materials


BU managers walk through the test
plan for review Structured Walk Through Quantitative Loss Criteria Financial Loss
Testing the Plan
All people involved go through a Step 2 - Vulnerability Assessment Loss of competitive advantage
practice session 4 Steps of the BIA Qualitative Loss Criteria
Simulation 5 DR Tests Loss of public confidence

Primary processing does not stop Step 3 - Analyze Information


Parallel Step 4 - Document results and present
Most common
recommendations
Cease normal operations
Full Interruption Create a recovery plan
Best but scary
Computing
Implement the recovery procedures in a disaster Facilities
Get critical functions operating at backup site BCP development Define the continuity Strategy
people
Recovery Team Duties Two steps
Retrieval of materials from off site storage Supplies and equipment
Installs critical systems and applications
Document the continuity strategy
Separate from Recovery team
Must contain a rapid map for
Returns primary site to normal implementation
operating conditions Salvage Team Duties
Plan Approval and Implementation Senior management approval
clear and repair the primary
NOTE THIS IS NOT A TEST OF THE PLAN
processing facility
Recovery Procedures
May be a task of the recovery team
Returning production from DR to primary
Normal Operations Team
Disaster not over until all operations have returned
to their normal location and function

External Groups
Employee Relations
Other Recovery issues
Fraud and Crime
Financial Disbursement

You might also like