Showing posts with label Ch11. Show all posts
Showing posts with label Ch11. Show all posts

Friday, January 11, 2013

Business Continuity Planning

Business continuity can be defined as the

'strategic and tactical capability of the organisation to plan for and respond to incidents and business disruptions in order to continue business operations at an acceptable predefined level*"

Business continuity planning is the main answer to the risk of an unexpected business interruption. The objectives of a BCP are

1. Survival
2. Protection of corporate assets
3. Control of risks and exposures
4. Preventative measures of business interruption - see physical protection and logical access.
5. Management business interruption

It should provide a balance between acceptable potential losses as a result of a disaster and acceptable one-off and recurring costs related to business continuity management. Other benefits include

- providing customer confidence/satisfaction
- protecting reputation

BS25999 1 - 2006 (code of practice) and 2 - 2007 (specification) are the standards related to business continuity.

Features of an effective plan per BS25999

1. BC management policy -
2. Managing the BCM programme
3. Understanding the organisation and its requirements (incl. sufficiently robust and wide-ranging business risk identification (e.g. scenario planning, stress testing, what if planning) MTPD, RTO setting, available resources etc)
4. Determining the BC strategy (timescales, sequence of recovery)
5. Developing the plan (link to actions taken to respond to specific threats, incident management teams)
6. Exercising and maintaining the BCP. - ie test ongoing effectiveness and adjust for biz changes
7. Embed into the business culture. Ensure all stakeholders understand their responsibilities within the overall plan. (incident management team)

The overall plan needs to be realistic and achievable or it will be useless when called into action.

Recovery options

- Inhouse v outsourced
- recovery sequence (usually customer focused systems first)
- partnership with a similar firm?
- Readiness of facilities - hot, warm, cold, mobile

*What is an acceptable predefined level? Business would describe MTPD = maximum time period of disruption meaning the time that a business process can remain functioning in a limited way. IT woudl target RTO = recovery time objective meaning the time beyond which the non-availability of a service or function would be unacceptable.

Disaster Recovery

The process of recovering IT systems and services. DR can be seen as a sub-set of business continuity planning. The following are important elements of DR.
  • Risk assessment
  • Identification of most critical systems
  • Putting suitable DR arrangements in place (including suitable authorisations)
Risks within DR
  • Over-reliance on one supplier
  • Failure to test
  • Failure to update plans
 Commitment to resource disaster recovery process

Back Up

Taking back up copies of essential business information and software should be done to ensure that data and systems can be easily and quickly recovered in the case of a system problem.

Here are the minimal requirements for central IT departments;
  1. Remote location
  2. Accurate and complete
  3. Generations
  4. Restoration procedures
  5. Environment and physical protection in line with main location
  6. Access controls in line with original data
  7. Regularly Tested (incl. the operation of the control, the integrity of the backups and the effectiveness and timeliness of restoration)
Typical back-up cycle - daily, weekly, monthly, annual

Business with greater speed of data change may back-up more frequently or consider electronic vaulting whereby data is written twice, once locally and also to a remote machine.

However, sometimes backups are the responsibility of departments or individuals. In this case, clear guidance is required on responsibilities and protocols especially around handling of removable storage media.

System Recovery

System recovery is an important element of IT security.

Elements of system recovery are
Risks which arise within the above are as follows;

1. Completeness of recovery (quality)
2. Speed of recovery (time)
3. Expense of recovery (cost)

Auditing effort might focus on the above risks to check whether they have been diligently mitigated.