SlideShare una empresa de Scribd logo
1 de 43
Descargar para leer sin conexión
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Best Practices in
DR Planning and Testing
Paul F Kirvan, CISA, FBCI
Independent BC/DR Consultant
Member of the Board and Secretary
The Business Continuity Institute USA Chapter
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Agenda
1. Introduction
2. Plan Components
3. Mistakes and Pitfalls to Avoid
4. DR Technology Options
5. Tips for Planning DR Tests
6. Summary
7. Q&A
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Why is DR Important?
• Accepted way to ensure that critical data, IT systems and
networks can be recovered in an emergency
• Ensures that corporate business objectives can be
achieved, despite a disruption
• Increasingly accepted by management as a strategy for
keeping the business operational
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
Do you currently have a Disaster Recovery plan in place?
a. Yes, I have a comprehensive DR plan at my company
b. Yes, but needs more work
c. No, but would like to get one ready
d. No, and have no plans to create one
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
Do you currently have a Disaster Recovery plan in place?
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
What Do You Need?
A good disaster recovery plan needs:
• Support from senior management
• Funding approved by management
• Structured plan framework
• Access to qualified staff
• Access to relevant information
• Documentation and testing
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
What’s Your Goal with the Plan?
Build disaster recovery plans and associated
documentation based on a structured framework that is
consistent with good practices and standards.
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
DR Plan Activities
• Data gathering, interviews, analysis
• DR standards and good practice, emergency response
procedures, data backup and recovery procedures,
system recovery and restart processes, plan templates
• Tests to ensure that plan procedures and processes work
as designed
• Maintenance activities to keep plans up to date and
accurate
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Standards and Good Practice
• Standards – NFPA 1600:2010; ISO 24762:2008; ISO
27031:2011; NIST 800-34
• Regulations – NASD 2510/3520; NYSE 446
• Good Practice – BCI Good Practice Guidelines, FFIEC
Handbook
• Corporate DR policies
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
What You Need to Identify
• DR objectives of the systems, networks or other IT assets
(e.g., uninterrupted operation, max downtime 4.0 hrs)
• Risks and/or threats to the achievement of the DR
objectives
• Define and document the processes and procedures
needed to recover and reactivate the IT assets
• Identify preventive measures to mitigate DR risks to an
acceptable level
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
The following pages list the typical components found in an IT
disaster recovery plan. There may be some variations based on
your organization’s requirements, but generally the following items
should be included.
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
A good DR plan usually includes the following
components:
• Company DR policies
• DR plan documents
• Business impact analysis reports
• Risk assessment reports
• Exercise results
• IT DR procedures (in the plan)
• Supporting documents (e.g., data backup process, off-site storage
process, vendor contracts, diagrams, maintenance contracts, training
plans)
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 If there’s an existing plan, use it as a starting point
 Define plan scope, purpose, authority
 Define a policy statement
 Define management approval and funding
 Identify planning and response teams
 Identify critical IT resources
 Identify risks and their impact on IT assets
 Determine recovery time objectives (RTOs)
 Determine recovery point objectives (RPOs)
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 Preventive controls (e.g., backup power)
 Response and recovery strategies
 Data backup and recovery methods, compared to existing data
storage and retrieval procedures
 Potential use of alternate IT sites, e.g., a backup data center,
collocated data center, the cloud
 Potential use of hot sites, cold sites
 Potential use of alternate work (e.g., office) sites, and the technology
needs for those sites
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 Process for equipment replacement
 Process for obtaining spare parts
 Staff roles and responsibilities in a disaster
 Event notification procedures
 Damage assessment procedures
 Process and criteria for plan activation
 Identify who is authorized to declare a disaster
 Recovery / failover procedures
 System restart / failback procedures
 Resumption of business procedures
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 Step-by-step procedures for recovery of
 IT operations
 Desktop systems
 Data
 Hardware
 Operating systems
 Applications
 Databases
 LANs and WANs
 Voice and VoIP systems
 Servers
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
 Step-by-step procedures for recovery of
 Web sites
 Mainframes
 Distributed systems
 Wireless technology
 Specialized systems
 Information security
 User access
 Physical security
 Vital records
Plan Components
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 Step-by-step procedures for
 Alerting first responder organizations
 Alerting family members
 Alerting primary/alternate vendors
 Alerting staff, senior management
 Alerting clients, stakeholders
 Escalating recovery efforts
 Help desk support
 Using call trees
 Activating automated notification systems
 Activating conference bridges
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 Links to emergency management and incident response plans,
business continuity plans
 Process for exercising DR plans
 Process for creating a DR awareness program
 Process for DR team training
 Process for DR training of employees
 Process for communicating with the media
 Designated company spokesperson
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
The next set of slides provides a sample DR plan
outline. While most plans will be different, this outline
includes the most common plan components and is
consistent with standards and good practice.
Plan Components
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 1
• Revision History
• Table of Contents
• Emergency Response Actions
‐ Assembly Points
‐ Emergency Call-in Number
‐ Key Personnel Contact Info
‐ Notification Calling Tree
‐ External Contacts
‐ External Contacts Calling Tree
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 2
• Policy Statement
• Objectives
• Plan Overview
• Plan Updating
• Plan Documentation Storage
• Backup Strategies
• Emergency Response
‐ Plan Triggering Events
‐ Assembly Points
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 3
• Activation of Emergency Management Team
• Technology Services Team
• Emergency Alert, Escalation and DRP Activation
• DR Procedures and Actions
‐ Contact with Employees
‐ Backup Staff
‐ Recorded Messages / Updates
‐ Alternate Recovery Facilities / Hot Site
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 4
• Personnel and Family Notification
• Communications with Media, Key Stakeholders
• Media and Key Stakeholders Contact
• Media and Key Stakeholders Team
• Rules for Dealing with Media, Key Stakeholders
• Insurance Requirements
• Financial and Legal Issues
‐ Financial Assessment
‐ Financial Requirements
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 5
• Legal Actions
• DR Plan Exercising
• Appendix A – Technology DR Plans
‐ Production Environment
‐ Private Cloud Environment
‐ Internal IT Environment at HQ
‐ Local Area Network (LAN)
‐ Voice over IP (VoIP) System
‐ Remote Connectivity / VPN
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 6
• Appendix B – Forms and Reports
‐ Management of DR Activities Forms
‐ Communications and Reporting Form
‐ Disaster Recovery Incident Recording Form
‐ Disaster Recovery Activity Report Form
‐ Mobilizing the Disaster Recovery Team Form
‐ Mobilizing the Business Recovery Team Form
‐ Monitoring Business Recovery Progress Form
‐ Business Process/Function Recovery Form
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Mistakes and Pitfalls to Avoid
(the not-so-obvious things)
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Mistakes and Pitfalls to Avoid
 Failure to obtain senior management support
 No budget (i.e., no plan)
 Lack of upfront research (e.g., risks, RTO/RPO)
 Lack of documentation (e.g., assume native knowledge will be
available)
 No step-by-step procedures (assume you know what to do first,
second, who to call, etc.)
 No plan testing (e.g., rolling the dice)
 No regular plan reviews and updates
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Mistakes and Pitfalls to Avoid
 No DR team training (nobody knows what to do)
 Assume that IT staff knows what to do
 Assume that IT staff will be available in an emergency
 Assume that backup and recovery procedures will work when needed
 Assume that systems and networks will work properly when in backup
or recovery mode
 Assume that backed-up data will be available when needed
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
DR Technology Options
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
What technologies are you currently using for Disaster Recovery?
a. Local backup to disk or tape
b. Cloud backup
c. Server replication (either locally or to off-site facility)
d. Hybrid technology with local and cloud protection
e. Collocation of data center
f. Other
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
What technologies are you currently using for Disaster Recovery?
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
DR Technology Options
 Data backup and recovery to an alternate site, e.g., backup data
center
 Application backup and recovery to an alternate site, e.g., backup
data center
 Off-site data storage using a third-party firm
 Redundant components, e.g., servers, storage devices, network
components
 Diversely run networks, e.g., alternate service using a different carrier
and different paths
 System failover / failback technologies to rapidly recover and restart
disrupted systems
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Current Process New Cloud Options
Application backup and recovery
to an alternate site or data center
Application backup and recovery to
the cloud
File/data/database backup and
recovery to an alternate site /
data center
File/data/database backup and
recovery to the cloud
Server backup and recovery via
failover to an alternate site / data
center
Server backup and recovery via
failover to the cloud
Cloud-based solutions have become very popular as
primary and alternate backup and recovery strategies.
DR Technology Options
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Current Process New Cloud Options
Recover the minimum
configuration of servers,
applications, network resources if
it’s necessary to relocate to an
alternate office site
“Office virtualization”, which has
server failover, access to IP
addresses and Active Directory in
the cloud; this means rapid office
recovery and minimum downtime
Conduct DR plan tests using a
local, on-site environment or
alternate backup data center
resource
Streamline DR tests using a cloud-
based and automated DR testing
environment
Traditional DR activities can be automated and streamlined
to encourage more testing and reduce risks from disruptions.
DR Technology Options
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Tips for Planning DR Tests
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
How often do you test your DR plan and/or the ability to recover from a
disaster?
a. I don’t test
b. Once a year
c. Two to four times a year
d. Every month
e. Not as often as I should
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
How often do you test your DR plan and/or the ability to recover from a
disaster?
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Tips for Planning DR Tests
1. Decide what you want to test, e.g., data recovery, system failover to
a backup site
2. Determine if production systems will be negatively affected during
the test
3. Conduct the test in a non-production environment, e.g., R&D
4. Select test participants and alternates
5. Document step-by-step procedures for performing the test
6. Secure a conference room or suitably equipped work area for the
test
7. Schedule the test so as not to interfere with production activities
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Tips for Planning DR Tests
8. Notify all IT teams and groups of the test at least two weeks in
advance
9. Include a scribe / timekeeper
10. (If possible) Conduct a dry run to validate that the test procedures
will/should work
11. Complete the test, keeping notes of all actions performed, time
needed for each activity
12. Prepare an after-action report summarizing what worked, what didn’t
work and lessons learned
13. Update the DR plan based on test results
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Summary
 Develop and document a plan .. follow it
 Senior management supports the plan
 Policies, procedures, metrics
 Document, document, document
 Test, test, test
 Maintenance and regular review
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
About Axcient
Leader in Recovery-as-a-Service
One SaaS Platform
Backup Disaster
Recovery
Business
Continuity
WAN
Optimization
Dedupe
vs.
Rapid Recovery
Physical & Virtual Application
Continuity
Cloud
Virtualization
True Cloud
Platform
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
For more information, visit axcient.com or call 800 715.2339
@Axcient linkedin.com/company/axcient axcient.com/facebook
Paul Kirvan, CISA, FBCI
Phone (908) 902-2586
Email pkirvan@msn.com

Más contenido relacionado

La actualidad más candente

Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Narudom Roongsiriwong, CISSP
 
Business Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesBusiness Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesSlideTeam
 
Disaster Recovery Plan
Disaster Recovery Plan Disaster Recovery Plan
Disaster Recovery Plan Emilie Gray
 
Business Continuity & Disaster Recovery
Business Continuity & Disaster RecoveryBusiness Continuity & Disaster Recovery
Business Continuity & Disaster RecoveryEC-Council
 
Information Technology Disaster Planning
Information Technology Disaster PlanningInformation Technology Disaster Planning
Information Technology Disaster Planningguest340570
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planningalanlund
 
Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planingHanaysha
 
Data center disaster recovery.ppt
Data center disaster recovery.ppt Data center disaster recovery.ppt
Data center disaster recovery.ppt omalreda
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery PlanDavid Donovan
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcpAdv Prashant Mali
 
Disaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesDisaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesSlideTeam
 
Business Continuity Planning Presentation Overview
Business Continuity Planning Presentation OverviewBusiness Continuity Planning Presentation Overview
Business Continuity Planning Presentation OverviewBob Winkler
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery PlanningJohn Wilson
 
Business Continuity Workshop Final
Business Continuity Workshop   FinalBusiness Continuity Workshop   Final
Business Continuity Workshop FinalBill Lisse
 
Cyber Security Incident Response
Cyber Security Incident ResponseCyber Security Incident Response
Cyber Security Incident ResponsePECB
 

La actualidad más candente (20)

Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
Business Continuity Planning Presentation
Business Continuity Planning PresentationBusiness Continuity Planning Presentation
Business Continuity Planning Presentation
 
Business Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesBusiness Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation Slides
 
Disaster Recovery Plan
Disaster Recovery Plan Disaster Recovery Plan
Disaster Recovery Plan
 
Bcp drp
Bcp drpBcp drp
Bcp drp
 
Business Continuity & Disaster Recovery
Business Continuity & Disaster RecoveryBusiness Continuity & Disaster Recovery
Business Continuity & Disaster Recovery
 
Information Technology Disaster Planning
Information Technology Disaster PlanningInformation Technology Disaster Planning
Information Technology Disaster Planning
 
Disaster Recovery
Disaster RecoveryDisaster Recovery
Disaster Recovery
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planing
 
Data center disaster recovery.ppt
Data center disaster recovery.ppt Data center disaster recovery.ppt
Data center disaster recovery.ppt
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcp
 
BUSINESS CONTINUITY PLANNING
BUSINESS CONTINUITY PLANNINGBUSINESS CONTINUITY PLANNING
BUSINESS CONTINUITY PLANNING
 
Bcp
BcpBcp
Bcp
 
Disaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesDisaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation Slides
 
Business Continuity Planning Presentation Overview
Business Continuity Planning Presentation OverviewBusiness Continuity Planning Presentation Overview
Business Continuity Planning Presentation Overview
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery Planning
 
Business Continuity Workshop Final
Business Continuity Workshop   FinalBusiness Continuity Workshop   Final
Business Continuity Workshop Final
 
Cyber Security Incident Response
Cyber Security Incident ResponseCyber Security Incident Response
Cyber Security Incident Response
 

Similar a Best Practices in Disaster Recovery Planning and Testing

Data Centre Strategy Summit 2015 "Are you ready to embark on your Data Cent...
Data Centre Strategy Summit 2015   "Are you ready to embark on your Data Cent...Data Centre Strategy Summit 2015   "Are you ready to embark on your Data Cent...
Data Centre Strategy Summit 2015 "Are you ready to embark on your Data Cent...Gus Sabatino
 
Australian Cloud and Data Centre Strategy Summit 2016 gus sabatino
Australian Cloud and Data Centre Strategy Summit 2016   gus sabatinoAustralian Cloud and Data Centre Strategy Summit 2016   gus sabatino
Australian Cloud and Data Centre Strategy Summit 2016 gus sabatinoGus Sabatino
 
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...William Hendrickson
 
Enabling Resource Management — The Right People for the Right Projects
Enabling Resource Management — The Right People for the Right ProjectsEnabling Resource Management — The Right People for the Right Projects
Enabling Resource Management — The Right People for the Right ProjectsCA Technologies
 
Leveraging Packaged Analytics when Implementing your ERP
Leveraging Packaged Analytics when Implementing your ERPLeveraging Packaged Analytics when Implementing your ERP
Leveraging Packaged Analytics when Implementing your ERPEmtec Inc.
 
Wincere Best Practices
Wincere Best PracticesWincere Best Practices
Wincere Best PracticesWincere
 
18 May 2017 - Vuzion Love Cloud
18 May 2017 - Vuzion Love Cloud18 May 2017 - Vuzion Love Cloud
18 May 2017 - Vuzion Love CloudVuzion
 
Is it Necessary to Document the BCMS plan?
Is it Necessary to Document the BCMS plan?Is it Necessary to Document the BCMS plan?
Is it Necessary to Document the BCMS plan?PECB
 
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...Emtec Inc.
 
Abidance Cip Presentation
Abidance Cip PresentationAbidance Cip Presentation
Abidance Cip Presentationjamesholler
 
Exec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate CertificationExec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate CertificationThomas Bronack
 
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...AppDynamics
 
Monitoring As a Service
Monitoring As a ServiceMonitoring As a Service
Monitoring As a ServiceAmit Panchal
 
Key Metrics for Disaster Recovery and Business Continuity
Key Metrics for Disaster Recovery and Business ContinuityKey Metrics for Disaster Recovery and Business Continuity
Key Metrics for Disaster Recovery and Business ContinuityAxcient
 
Managed Services - Functional & Customization Support Help Desk
Managed Services - Functional & Customization Support Help DeskManaged Services - Functional & Customization Support Help Desk
Managed Services - Functional & Customization Support Help DeskAmit Panchal
 
Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)Anthony Oxley
 
Postgres in Production - Best Practices 2014
Postgres in Production - Best Practices 2014Postgres in Production - Best Practices 2014
Postgres in Production - Best Practices 2014EDB
 

Similar a Best Practices in Disaster Recovery Planning and Testing (20)

Data Centre Strategy Summit 2015 "Are you ready to embark on your Data Cent...
Data Centre Strategy Summit 2015   "Are you ready to embark on your Data Cent...Data Centre Strategy Summit 2015   "Are you ready to embark on your Data Cent...
Data Centre Strategy Summit 2015 "Are you ready to embark on your Data Cent...
 
Australian Cloud and Data Centre Strategy Summit 2016 gus sabatino
Australian Cloud and Data Centre Strategy Summit 2016   gus sabatinoAustralian Cloud and Data Centre Strategy Summit 2016   gus sabatino
Australian Cloud and Data Centre Strategy Summit 2016 gus sabatino
 
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...
 
Enabling Resource Management — The Right People for the Right Projects
Enabling Resource Management — The Right People for the Right ProjectsEnabling Resource Management — The Right People for the Right Projects
Enabling Resource Management — The Right People for the Right Projects
 
Leveraging Packaged Analytics when Implementing your ERP
Leveraging Packaged Analytics when Implementing your ERPLeveraging Packaged Analytics when Implementing your ERP
Leveraging Packaged Analytics when Implementing your ERP
 
Ensuring Success in the Cloud (1)
Ensuring Success in the Cloud (1)Ensuring Success in the Cloud (1)
Ensuring Success in the Cloud (1)
 
Wincere Best Practices
Wincere Best PracticesWincere Best Practices
Wincere Best Practices
 
18 May 2017 - Vuzion Love Cloud
18 May 2017 - Vuzion Love Cloud18 May 2017 - Vuzion Love Cloud
18 May 2017 - Vuzion Love Cloud
 
Is it Necessary to Document the BCMS plan?
Is it Necessary to Document the BCMS plan?Is it Necessary to Document the BCMS plan?
Is it Necessary to Document the BCMS plan?
 
Planning
PlanningPlanning
Planning
 
BiznetGio Presentation Business Continuity
BiznetGio Presentation Business ContinuityBiznetGio Presentation Business Continuity
BiznetGio Presentation Business Continuity
 
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...
 
Abidance Cip Presentation
Abidance Cip PresentationAbidance Cip Presentation
Abidance Cip Presentation
 
Exec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate CertificationExec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate Certification
 
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...
 
Monitoring As a Service
Monitoring As a ServiceMonitoring As a Service
Monitoring As a Service
 
Key Metrics for Disaster Recovery and Business Continuity
Key Metrics for Disaster Recovery and Business ContinuityKey Metrics for Disaster Recovery and Business Continuity
Key Metrics for Disaster Recovery and Business Continuity
 
Managed Services - Functional & Customization Support Help Desk
Managed Services - Functional & Customization Support Help DeskManaged Services - Functional & Customization Support Help Desk
Managed Services - Functional & Customization Support Help Desk
 
Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)
 
Postgres in Production - Best Practices 2014
Postgres in Production - Best Practices 2014Postgres in Production - Best Practices 2014
Postgres in Production - Best Practices 2014
 

Último

Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear RegressionRavindra Nath Shukla
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxWorkforce Group
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyEthan lee
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...amitlee9823
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Delhi Call girls
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Lviv Startup Club
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxpriyanshujha201
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...Any kyc Account
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756dollysharma2066
 

Último (20)

Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear Regression
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 

Best Practices in Disaster Recovery Planning and Testing

  • 1. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Best Practices in DR Planning and Testing Paul F Kirvan, CISA, FBCI Independent BC/DR Consultant Member of the Board and Secretary The Business Continuity Institute USA Chapter
  • 2. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Agenda 1. Introduction 2. Plan Components 3. Mistakes and Pitfalls to Avoid 4. DR Technology Options 5. Tips for Planning DR Tests 6. Summary 7. Q&A
  • 3. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Why is DR Important? • Accepted way to ensure that critical data, IT systems and networks can be recovered in an emergency • Ensures that corporate business objectives can be achieved, despite a disruption • Increasingly accepted by management as a strategy for keeping the business operational
  • 4. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll Do you currently have a Disaster Recovery plan in place? a. Yes, I have a comprehensive DR plan at my company b. Yes, but needs more work c. No, but would like to get one ready d. No, and have no plans to create one
  • 5. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll Do you currently have a Disaster Recovery plan in place?
  • 6. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. What Do You Need? A good disaster recovery plan needs: • Support from senior management • Funding approved by management • Structured plan framework • Access to qualified staff • Access to relevant information • Documentation and testing
  • 7. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. What’s Your Goal with the Plan? Build disaster recovery plans and associated documentation based on a structured framework that is consistent with good practices and standards.
  • 8. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. DR Plan Activities • Data gathering, interviews, analysis • DR standards and good practice, emergency response procedures, data backup and recovery procedures, system recovery and restart processes, plan templates • Tests to ensure that plan procedures and processes work as designed • Maintenance activities to keep plans up to date and accurate
  • 9. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Standards and Good Practice • Standards – NFPA 1600:2010; ISO 24762:2008; ISO 27031:2011; NIST 800-34 • Regulations – NASD 2510/3520; NYSE 446 • Good Practice – BCI Good Practice Guidelines, FFIEC Handbook • Corporate DR policies
  • 10. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. What You Need to Identify • DR objectives of the systems, networks or other IT assets (e.g., uninterrupted operation, max downtime 4.0 hrs) • Risks and/or threats to the achievement of the DR objectives • Define and document the processes and procedures needed to recover and reactivate the IT assets • Identify preventive measures to mitigate DR risks to an acceptable level
  • 11. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components The following pages list the typical components found in an IT disaster recovery plan. There may be some variations based on your organization’s requirements, but generally the following items should be included.
  • 12. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components A good DR plan usually includes the following components: • Company DR policies • DR plan documents • Business impact analysis reports • Risk assessment reports • Exercise results • IT DR procedures (in the plan) • Supporting documents (e.g., data backup process, off-site storage process, vendor contracts, diagrams, maintenance contracts, training plans)
  • 13. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  If there’s an existing plan, use it as a starting point  Define plan scope, purpose, authority  Define a policy statement  Define management approval and funding  Identify planning and response teams  Identify critical IT resources  Identify risks and their impact on IT assets  Determine recovery time objectives (RTOs)  Determine recovery point objectives (RPOs)
  • 14. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  Preventive controls (e.g., backup power)  Response and recovery strategies  Data backup and recovery methods, compared to existing data storage and retrieval procedures  Potential use of alternate IT sites, e.g., a backup data center, collocated data center, the cloud  Potential use of hot sites, cold sites  Potential use of alternate work (e.g., office) sites, and the technology needs for those sites
  • 15. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  Process for equipment replacement  Process for obtaining spare parts  Staff roles and responsibilities in a disaster  Event notification procedures  Damage assessment procedures  Process and criteria for plan activation  Identify who is authorized to declare a disaster  Recovery / failover procedures  System restart / failback procedures  Resumption of business procedures
  • 16. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  Step-by-step procedures for recovery of  IT operations  Desktop systems  Data  Hardware  Operating systems  Applications  Databases  LANs and WANs  Voice and VoIP systems  Servers
  • 17. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.  Step-by-step procedures for recovery of  Web sites  Mainframes  Distributed systems  Wireless technology  Specialized systems  Information security  User access  Physical security  Vital records Plan Components
  • 18. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  Step-by-step procedures for  Alerting first responder organizations  Alerting family members  Alerting primary/alternate vendors  Alerting staff, senior management  Alerting clients, stakeholders  Escalating recovery efforts  Help desk support  Using call trees  Activating automated notification systems  Activating conference bridges
  • 19. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  Links to emergency management and incident response plans, business continuity plans  Process for exercising DR plans  Process for creating a DR awareness program  Process for DR team training  Process for DR training of employees  Process for communicating with the media  Designated company spokesperson
  • 20. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. The next set of slides provides a sample DR plan outline. While most plans will be different, this outline includes the most common plan components and is consistent with standards and good practice. Plan Components
  • 21. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 1 • Revision History • Table of Contents • Emergency Response Actions ‐ Assembly Points ‐ Emergency Call-in Number ‐ Key Personnel Contact Info ‐ Notification Calling Tree ‐ External Contacts ‐ External Contacts Calling Tree
  • 22. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 2 • Policy Statement • Objectives • Plan Overview • Plan Updating • Plan Documentation Storage • Backup Strategies • Emergency Response ‐ Plan Triggering Events ‐ Assembly Points
  • 23. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 3 • Activation of Emergency Management Team • Technology Services Team • Emergency Alert, Escalation and DRP Activation • DR Procedures and Actions ‐ Contact with Employees ‐ Backup Staff ‐ Recorded Messages / Updates ‐ Alternate Recovery Facilities / Hot Site
  • 24. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 4 • Personnel and Family Notification • Communications with Media, Key Stakeholders • Media and Key Stakeholders Contact • Media and Key Stakeholders Team • Rules for Dealing with Media, Key Stakeholders • Insurance Requirements • Financial and Legal Issues ‐ Financial Assessment ‐ Financial Requirements
  • 25. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 5 • Legal Actions • DR Plan Exercising • Appendix A – Technology DR Plans ‐ Production Environment ‐ Private Cloud Environment ‐ Internal IT Environment at HQ ‐ Local Area Network (LAN) ‐ Voice over IP (VoIP) System ‐ Remote Connectivity / VPN
  • 26. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 6 • Appendix B – Forms and Reports ‐ Management of DR Activities Forms ‐ Communications and Reporting Form ‐ Disaster Recovery Incident Recording Form ‐ Disaster Recovery Activity Report Form ‐ Mobilizing the Disaster Recovery Team Form ‐ Mobilizing the Business Recovery Team Form ‐ Monitoring Business Recovery Progress Form ‐ Business Process/Function Recovery Form
  • 27. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Mistakes and Pitfalls to Avoid (the not-so-obvious things)
  • 28. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Mistakes and Pitfalls to Avoid  Failure to obtain senior management support  No budget (i.e., no plan)  Lack of upfront research (e.g., risks, RTO/RPO)  Lack of documentation (e.g., assume native knowledge will be available)  No step-by-step procedures (assume you know what to do first, second, who to call, etc.)  No plan testing (e.g., rolling the dice)  No regular plan reviews and updates
  • 29. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Mistakes and Pitfalls to Avoid  No DR team training (nobody knows what to do)  Assume that IT staff knows what to do  Assume that IT staff will be available in an emergency  Assume that backup and recovery procedures will work when needed  Assume that systems and networks will work properly when in backup or recovery mode  Assume that backed-up data will be available when needed
  • 30. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. DR Technology Options
  • 31. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll What technologies are you currently using for Disaster Recovery? a. Local backup to disk or tape b. Cloud backup c. Server replication (either locally or to off-site facility) d. Hybrid technology with local and cloud protection e. Collocation of data center f. Other
  • 32. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll What technologies are you currently using for Disaster Recovery?
  • 33. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. DR Technology Options  Data backup and recovery to an alternate site, e.g., backup data center  Application backup and recovery to an alternate site, e.g., backup data center  Off-site data storage using a third-party firm  Redundant components, e.g., servers, storage devices, network components  Diversely run networks, e.g., alternate service using a different carrier and different paths  System failover / failback technologies to rapidly recover and restart disrupted systems
  • 34. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Current Process New Cloud Options Application backup and recovery to an alternate site or data center Application backup and recovery to the cloud File/data/database backup and recovery to an alternate site / data center File/data/database backup and recovery to the cloud Server backup and recovery via failover to an alternate site / data center Server backup and recovery via failover to the cloud Cloud-based solutions have become very popular as primary and alternate backup and recovery strategies. DR Technology Options
  • 35. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Current Process New Cloud Options Recover the minimum configuration of servers, applications, network resources if it’s necessary to relocate to an alternate office site “Office virtualization”, which has server failover, access to IP addresses and Active Directory in the cloud; this means rapid office recovery and minimum downtime Conduct DR plan tests using a local, on-site environment or alternate backup data center resource Streamline DR tests using a cloud- based and automated DR testing environment Traditional DR activities can be automated and streamlined to encourage more testing and reduce risks from disruptions. DR Technology Options
  • 36. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Tips for Planning DR Tests
  • 37. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll How often do you test your DR plan and/or the ability to recover from a disaster? a. I don’t test b. Once a year c. Two to four times a year d. Every month e. Not as often as I should
  • 38. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll How often do you test your DR plan and/or the ability to recover from a disaster?
  • 39. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Tips for Planning DR Tests 1. Decide what you want to test, e.g., data recovery, system failover to a backup site 2. Determine if production systems will be negatively affected during the test 3. Conduct the test in a non-production environment, e.g., R&D 4. Select test participants and alternates 5. Document step-by-step procedures for performing the test 6. Secure a conference room or suitably equipped work area for the test 7. Schedule the test so as not to interfere with production activities
  • 40. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Tips for Planning DR Tests 8. Notify all IT teams and groups of the test at least two weeks in advance 9. Include a scribe / timekeeper 10. (If possible) Conduct a dry run to validate that the test procedures will/should work 11. Complete the test, keeping notes of all actions performed, time needed for each activity 12. Prepare an after-action report summarizing what worked, what didn’t work and lessons learned 13. Update the DR plan based on test results
  • 41. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Summary  Develop and document a plan .. follow it  Senior management supports the plan  Policies, procedures, metrics  Document, document, document  Test, test, test  Maintenance and regular review
  • 42. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. About Axcient Leader in Recovery-as-a-Service One SaaS Platform Backup Disaster Recovery Business Continuity WAN Optimization Dedupe vs. Rapid Recovery Physical & Virtual Application Continuity Cloud Virtualization True Cloud Platform
  • 43. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. For more information, visit axcient.com or call 800 715.2339 @Axcient linkedin.com/company/axcient axcient.com/facebook Paul Kirvan, CISA, FBCI Phone (908) 902-2586 Email pkirvan@msn.com