Term
Business Continuity Plan (BCP) |
|
Definition
- policy defines how enterprise will maintain OPs in event of disruption/crisis
- preserve key docs
- est. decsion-making authority
- communication
- protect/recover assets
- maintain financial functions
- review/testing
- backups/high availability
|
|
|
Term
BCP Development Process (7 steps) |
|
Definition
- Initiate process
- Develop Goals/Objectives
- Determine Impact
- Determine Prevention
- Determine Response
- Test
- Update
|
|
|
Term
Nation Instit. of Stds and Tech. (NIST) Contingency Planning Steps (7) |
|
Definition
- Develop policy
- Conduct Biz. Analysis
- ID preventative ctrls
- Develop recovery strat.
- Develop IT Contingency plan
- Plan Test/train/exercises
- Plan Maintenance
|
|
|
Term
Project Mgt Applications (5) |
|
Definition
|
|
Term
NFPA Business Planning Framework |
|
Definition
- National Fire Protection Assoc.
- created document NFPA 1600
- standard for planning content NOT planning/process itself
|
|
|
Term
|
Definition
- Natural Hazards earthquakes, tornados, etc
- Human-caused accidental/intentional. accidental file deletion; vandalism, theft, fraud.
- Technology-caused HW/SW malfunction; not obvious
|
|
|
Term
Business Impact Analysis (BIA) |
|
Definition
- BCP phase that IDs risks and impact to critical OPs if risks happen
- vulnerability assessments/evals
- prioritization of crit. processes
- reduced effeciency
- estimated tolerable downtime
- financial loss impact
- resources needed to restore
|
|
|
Term
|
Definition
- Ensure health/safety of staff
- Enable continual operations: property, infrastructure, facilities
- Maintain continuous goods/services to customers
- Provide safe workplace environment when disaster occurs
|
|
|
Term
|
Definition
- Project Plan/Development
- Data Collection
- App/Data criticality assessment
- Data Analysis to assess vulnerabilities, other factors
|
|
|
Term
Critical Business Process |
|
Definition
- activity, that if not recovered, will cause loss and biz failure
- by Sr. Mgt on ACTUAL impact; not just internal policies
- ID Key Personnel
|
|
|
Term
|
Definition
- BIA phase where financial and operational loss impact is ID'd
- Vulnerability tables: strategic tools for completing assessment
|
|
|
Term
Max. Tolerable Downtime (MTD) |
|
Definition
- longest period of time outage may occur w/o causing serious biz failures
|
|
|
Term
Recovery Point Objectives (RPO) |
|
Definition
- point in time, where data recovery begins
- last backup before disaster happens
|
|
|
Term
Recovery Time Objectives (RTO) |
|
Definition
- time it takes to restore to NORMAL business ops/activities after a disturbance
- time to return to RPO point
- must be achieved before MTD
|
|
|
Term
|
Definition
- ideal 0 (immediate recovery)
- near 0 is $$$$
- need to determine RPO/RTO cost vs loss cost
|
|
|
Term
|
Definition
- BCP implentator/controller
- maintains and updates
- periodict meetings
- ensures BCP available
|
|
|
Term
Advisory Committee-BCP Team |
|
Definition
- Mgmt
- Security
- Business Partner
- Remote Business Assoc
- Company Personnel
- Legal Adviser
- IT Professional
|
|
|
Term
BCP Team Responsibilities |
|
Definition
- ID threats/vulner
- Provide Estimates of threats/vuln
- Perform BIA
- Prioritize Recovery efforts
- Determine disaster recovery plans
- Ensure legal req. during DRP execution
|
|
|
Term
|
Definition
- BCP vision/mission statement
- statement of authorization
- roles/respons. of team members
- Plan goals/obj/eval methods
- Applicable laws/regulations/authorities/codes of conduct
- budget
- project schedule
- record mgt practices
- Document team act.
- Document act. for due diligence (insurance/audit purposes)
|
|
|
Term
Business Plan Evaluations |
|
Definition
- Coverage of all biz areas
- Threat/Vul ID
- Response Prioritization
- Training
- Testing
- Comm.
- staffing/time allocations
- freq of updates
|
|
|
Term
Business Plan Testing (7) |
|
Definition
- Review Contents
- Analyze business continuity solution
- Using Checklists
- Perf. Walkthrus
- Parallel Testing test @ alt. site
- Conducting Simulations exercised, not actual test
- Full Interruption Testing mimics actual business disruption
|
|
|
Term
Business Plan Maintenance |
|
Definition
- Annual review
- Update baed on eval/tests
- Update for dept. changes
|
|
|
Term
Business Continuity Process |
|
Definition
- Notify Stakeholders (staff/partners)
- Begin Continuity Operations
- Assess Level of Impact
|
|
|
Term
Disaster Recovery Plan (DRP) |
|
Definition
- how people/resources are protected in disaster
- how org will recover
- DR team, inventory, procedures, contact info
|
|
|
Term
Disaster Recovery Strategy (3 factors) |
|
Definition
- Risk People, Places, Things
- People: safety of people
- Places: relocation?
- Things: equipment
- Cost vs Benefits make sure its affordable
- Prioritization what will be recovered first
|
|
|
Term
Disaster Recovery Priority Levels |
|
Definition
- Short rapid response
- Mid quick response
- Long
- Not-required hurricane in San Diego for example
|
|
|
Term
Disaster Recovery Response Approaches |
|
Definition
- Short-term
- Mirrored Sites
- Shared Location
- Long-term
|
|
|
Term
|
Definition
- Tape/disk full/incremental/differential
- Mirrored reproduced on drive in another location
- Remote Journaling (DB) transactions vs backups;off-site;less $
- Electronic Vaulting copies sent to another location
|
|
|
Term
Data Restoration Strategies |
|
Definition
- Full
- Incremental different versions
- Differential first full back up, plus last differential backup
|
|
|
Term
|
Definition
- Hot/mirrored site alt. network setup
- Warm dormant, non critical site that can be converted into full site
- Cold predetermined alt location for rebuilding
- Portable mobile site like van/trailer
|
|
|
Term
|
Definition
Individuals who implement recovery procedures and control recovery operations in the event of disaster or business disruption
- Implement/Control operations
- Provide intermediate/rapid response
- Reach RTO before MTD
|
|
|
Term
|
Definition
- Restore primary team
- clean/repair/salvage/assess
- create plan & obtain budget approval
|
|
|
Term
DRP Evaluation/Maintenance |
|
Definition
- evaluate techniques periodically
- maintain on going basis
- BRP techniques
|
|
|
Term
|
Definition
- Checklist/dropbox not as thorough, but cheap
- Offsite Restoration transport to warm site
- Mirrored site cutover cutover to alt site; easiest way
|
|
|
Term
|
Definition
- Notify Stakeholders
- Begine ER OPs
- Assess Damage
- Assess Facility
|
|
|