SlideShare une entreprise Scribd logo
1  sur  43
Télécharger pour lire hors ligne
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Best Practices in
DR Planning and Testing
Paul F Kirvan, CISA, FBCI
Independent BC/DR Consultant
Member of the Board and Secretary
The Business Continuity Institute USA Chapter
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Agenda
1. Introduction
2. Plan Components
3. Mistakes and Pitfalls to Avoid
4. DR Technology Options
5. Tips for Planning DR Tests
6. Summary
7. Q&A
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Why is DR Important?
• Accepted way to ensure that critical data, IT systems and
networks can be recovered in an emergency
• Ensures that corporate business objectives can be
achieved, despite a disruption
• Increasingly accepted by management as a strategy for
keeping the business operational
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
Do you currently have a Disaster Recovery plan in place?
a. Yes, I have a comprehensive DR plan at my company
b. Yes, but needs more work
c. No, but would like to get one ready
d. No, and have no plans to create one
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
Do you currently have a Disaster Recovery plan in place?
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
What Do You Need?
A good disaster recovery plan needs:
• Support from senior management
• Funding approved by management
• Structured plan framework
• Access to qualified staff
• Access to relevant information
• Documentation and testing
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
What’s Your Goal with the Plan?
Build disaster recovery plans and associated
documentation based on a structured framework that is
consistent with good practices and standards.
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
DR Plan Activities
• Data gathering, interviews, analysis
• DR standards and good practice, emergency response
procedures, data backup and recovery procedures,
system recovery and restart processes, plan templates
• Tests to ensure that plan procedures and processes work
as designed
• Maintenance activities to keep plans up to date and
accurate
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Standards and Good Practice
• Standards – NFPA 1600:2010; ISO 24762:2008; ISO
27031:2011; NIST 800-34
• Regulations – NASD 2510/3520; NYSE 446
• Good Practice – BCI Good Practice Guidelines, FFIEC
Handbook
• Corporate DR policies
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
What You Need to Identify
• DR objectives of the systems, networks or other IT assets
(e.g., uninterrupted operation, max downtime 4.0 hrs)
• Risks and/or threats to the achievement of the DR
objectives
• Define and document the processes and procedures
needed to recover and reactivate the IT assets
• Identify preventive measures to mitigate DR risks to an
acceptable level
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
The following pages list the typical components found in an IT
disaster recovery plan. There may be some variations based on
your organization’s requirements, but generally the following items
should be included.
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
A good DR plan usually includes the following
components:
• Company DR policies
• DR plan documents
• Business impact analysis reports
• Risk assessment reports
• Exercise results
• IT DR procedures (in the plan)
• Supporting documents (e.g., data backup process, off-site storage
process, vendor contracts, diagrams, maintenance contracts, training
plans)
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 If there’s an existing plan, use it as a starting point
 Define plan scope, purpose, authority
 Define a policy statement
 Define management approval and funding
 Identify planning and response teams
 Identify critical IT resources
 Identify risks and their impact on IT assets
 Determine recovery time objectives (RTOs)
 Determine recovery point objectives (RPOs)
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 Preventive controls (e.g., backup power)
 Response and recovery strategies
 Data backup and recovery methods, compared to existing data
storage and retrieval procedures
 Potential use of alternate IT sites, e.g., a backup data center,
collocated data center, the cloud
 Potential use of hot sites, cold sites
 Potential use of alternate work (e.g., office) sites, and the technology
needs for those sites
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 Process for equipment replacement
 Process for obtaining spare parts
 Staff roles and responsibilities in a disaster
 Event notification procedures
 Damage assessment procedures
 Process and criteria for plan activation
 Identify who is authorized to declare a disaster
 Recovery / failover procedures
 System restart / failback procedures
 Resumption of business procedures
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 Step-by-step procedures for recovery of
 IT operations
 Desktop systems
 Data
 Hardware
 Operating systems
 Applications
 Databases
 LANs and WANs
 Voice and VoIP systems
 Servers
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
 Step-by-step procedures for recovery of
 Web sites
 Mainframes
 Distributed systems
 Wireless technology
 Specialized systems
 Information security
 User access
 Physical security
 Vital records
Plan Components
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 Step-by-step procedures for
 Alerting first responder organizations
 Alerting family members
 Alerting primary/alternate vendors
 Alerting staff, senior management
 Alerting clients, stakeholders
 Escalating recovery efforts
 Help desk support
 Using call trees
 Activating automated notification systems
 Activating conference bridges
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
 Links to emergency management and incident response plans,
business continuity plans
 Process for exercising DR plans
 Process for creating a DR awareness program
 Process for DR team training
 Process for DR training of employees
 Process for communicating with the media
 Designated company spokesperson
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
The next set of slides provides a sample DR plan
outline. While most plans will be different, this outline
includes the most common plan components and is
consistent with standards and good practice.
Plan Components
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 1
• Revision History
• Table of Contents
• Emergency Response Actions
‐ Assembly Points
‐ Emergency Call-in Number
‐ Key Personnel Contact Info
‐ Notification Calling Tree
‐ External Contacts
‐ External Contacts Calling Tree
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 2
• Policy Statement
• Objectives
• Plan Overview
• Plan Updating
• Plan Documentation Storage
• Backup Strategies
• Emergency Response
‐ Plan Triggering Events
‐ Assembly Points
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 3
• Activation of Emergency Management Team
• Technology Services Team
• Emergency Alert, Escalation and DRP Activation
• DR Procedures and Actions
‐ Contact with Employees
‐ Backup Staff
‐ Recorded Messages / Updates
‐ Alternate Recovery Facilities / Hot Site
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 4
• Personnel and Family Notification
• Communications with Media, Key Stakeholders
• Media and Key Stakeholders Contact
• Media and Key Stakeholders Team
• Rules for Dealing with Media, Key Stakeholders
• Insurance Requirements
• Financial and Legal Issues
‐ Financial Assessment
‐ Financial Requirements
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 5
• Legal Actions
• DR Plan Exercising
• Appendix A – Technology DR Plans
‐ Production Environment
‐ Private Cloud Environment
‐ Internal IT Environment at HQ
‐ Local Area Network (LAN)
‐ Voice over IP (VoIP) System
‐ Remote Connectivity / VPN
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Plan Components
DR Plan Outline - 6
• Appendix B – Forms and Reports
‐ Management of DR Activities Forms
‐ Communications and Reporting Form
‐ Disaster Recovery Incident Recording Form
‐ Disaster Recovery Activity Report Form
‐ Mobilizing the Disaster Recovery Team Form
‐ Mobilizing the Business Recovery Team Form
‐ Monitoring Business Recovery Progress Form
‐ Business Process/Function Recovery Form
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Mistakes and Pitfalls to Avoid
(the not-so-obvious things)
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Mistakes and Pitfalls to Avoid
 Failure to obtain senior management support
 No budget (i.e., no plan)
 Lack of upfront research (e.g., risks, RTO/RPO)
 Lack of documentation (e.g., assume native knowledge will be
available)
 No step-by-step procedures (assume you know what to do first,
second, who to call, etc.)
 No plan testing (e.g., rolling the dice)
 No regular plan reviews and updates
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Mistakes and Pitfalls to Avoid
 No DR team training (nobody knows what to do)
 Assume that IT staff knows what to do
 Assume that IT staff will be available in an emergency
 Assume that backup and recovery procedures will work when needed
 Assume that systems and networks will work properly when in backup
or recovery mode
 Assume that backed-up data will be available when needed
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
DR Technology Options
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
What technologies are you currently using for Disaster Recovery?
a. Local backup to disk or tape
b. Cloud backup
c. Server replication (either locally or to off-site facility)
d. Hybrid technology with local and cloud protection
e. Collocation of data center
f. Other
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
What technologies are you currently using for Disaster Recovery?
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
DR Technology Options
 Data backup and recovery to an alternate site, e.g., backup data
center
 Application backup and recovery to an alternate site, e.g., backup
data center
 Off-site data storage using a third-party firm
 Redundant components, e.g., servers, storage devices, network
components
 Diversely run networks, e.g., alternate service using a different carrier
and different paths
 System failover / failback technologies to rapidly recover and restart
disrupted systems
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Current Process New Cloud Options
Application backup and recovery
to an alternate site or data center
Application backup and recovery to
the cloud
File/data/database backup and
recovery to an alternate site /
data center
File/data/database backup and
recovery to the cloud
Server backup and recovery via
failover to an alternate site / data
center
Server backup and recovery via
failover to the cloud
Cloud-based solutions have become very popular as
primary and alternate backup and recovery strategies.
DR Technology Options
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Current Process New Cloud Options
Recover the minimum
configuration of servers,
applications, network resources if
it’s necessary to relocate to an
alternate office site
“Office virtualization”, which has
server failover, access to IP
addresses and Active Directory in
the cloud; this means rapid office
recovery and minimum downtime
Conduct DR plan tests using a
local, on-site environment or
alternate backup data center
resource
Streamline DR tests using a cloud-
based and automated DR testing
environment
Traditional DR activities can be automated and streamlined
to encourage more testing and reduce risks from disruptions.
DR Technology Options
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Tips for Planning DR Tests
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
How often do you test your DR plan and/or the ability to recover from a
disaster?
a. I don’t test
b. Once a year
c. Two to four times a year
d. Every month
e. Not as often as I should
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Quick Poll
How often do you test your DR plan and/or the ability to recover from a
disaster?
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Tips for Planning DR Tests
1. Decide what you want to test, e.g., data recovery, system failover to
a backup site
2. Determine if production systems will be negatively affected during
the test
3. Conduct the test in a non-production environment, e.g., R&D
4. Select test participants and alternates
5. Document step-by-step procedures for performing the test
6. Secure a conference room or suitably equipped work area for the
test
7. Schedule the test so as not to interfere with production activities
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Tips for Planning DR Tests
8. Notify all IT teams and groups of the test at least two weeks in
advance
9. Include a scribe / timekeeper
10. (If possible) Conduct a dry run to validate that the test procedures
will/should work
11. Complete the test, keeping notes of all actions performed, time
needed for each activity
12. Prepare an after-action report summarizing what worked, what didn’t
work and lessons learned
13. Update the DR plan based on test results
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
Summary
 Develop and document a plan .. follow it
 Senior management supports the plan
 Policies, procedures, metrics
 Document, document, document
 Test, test, test
 Maintenance and regular review
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
About Axcient
Leader in Recovery-as-a-Service
One SaaS Platform
Backup Disaster
Recovery
Business
Continuity
WAN
Optimization
Dedupe
vs.
Rapid Recovery
Physical & Virtual Application
Continuity
Cloud
Virtualization
True Cloud
Platform
CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.
For more information, visit axcient.com or call 800 715.2339
@Axcient linkedin.com/company/axcient axcient.com/facebook
Paul Kirvan, CISA, FBCI
Phone (908) 902-2586
Email pkirvan@msn.com

Contenu connexe

Tendances

Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity PlanningDipankar Ghosh
 
Effective Business Continuity Plan Powerpoint Presentation Slides
Effective Business Continuity Plan Powerpoint Presentation SlidesEffective Business Continuity Plan Powerpoint Presentation Slides
Effective Business Continuity Plan Powerpoint Presentation SlidesSlideTeam
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Planmhdpaknejad
 
Disaster Recovery Plan / Enterprise Continuity Plan
Disaster Recovery Plan / Enterprise Continuity PlanDisaster Recovery Plan / Enterprise Continuity Plan
Disaster Recovery Plan / Enterprise Continuity PlanMarcelo Silva
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Narudom Roongsiriwong, CISSP
 
Disaster recovery solution
Disaster recovery solutionDisaster recovery solution
Disaster recovery solutionAnton An
 
Disaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesDisaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesSlideTeam
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery PlanningJohn Wilson
 
IT Disaster Recovery Readiness (Maturity Assessement)
IT Disaster Recovery Readiness (Maturity Assessement) IT Disaster Recovery Readiness (Maturity Assessement)
IT Disaster Recovery Readiness (Maturity Assessement) Bashar Alkhatib
 
Disaster recovery
Disaster recoveryDisaster recovery
Disaster recoverySameeu Imad
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery PlanDavid Donovan
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery PlanningKathy Pelletier
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IThhuihhui
 
What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP) What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP) CBIZ, Inc.
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planninggcleary
 
Contingency Planning And Disaster Recovery Planning
Contingency Planning And Disaster Recovery PlanningContingency Planning And Disaster Recovery Planning
Contingency Planning And Disaster Recovery Planningmmohamme1124
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planningalanlund
 
IT Disaster Recovery & Business Continuity
IT Disaster Recovery & Business ContinuityIT Disaster Recovery & Business Continuity
IT Disaster Recovery & Business Continuitymascot4u
 

Tendances (20)

Bcp drp
Bcp drpBcp drp
Bcp drp
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Effective Business Continuity Plan Powerpoint Presentation Slides
Effective Business Continuity Plan Powerpoint Presentation SlidesEffective Business Continuity Plan Powerpoint Presentation Slides
Effective Business Continuity Plan Powerpoint Presentation Slides
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
 
Disaster Recovery Plan / Enterprise Continuity Plan
Disaster Recovery Plan / Enterprise Continuity PlanDisaster Recovery Plan / Enterprise Continuity Plan
Disaster Recovery Plan / Enterprise Continuity Plan
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
Disaster recovery solution
Disaster recovery solutionDisaster recovery solution
Disaster recovery solution
 
Disaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesDisaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation Slides
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery Planning
 
IT Disaster Recovery Readiness (Maturity Assessement)
IT Disaster Recovery Readiness (Maturity Assessement) IT Disaster Recovery Readiness (Maturity Assessement)
IT Disaster Recovery Readiness (Maturity Assessement)
 
Disaster recovery
Disaster recoveryDisaster recovery
Disaster recovery
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
 
Disaster Recovery Planning
Disaster Recovery PlanningDisaster Recovery Planning
Disaster Recovery Planning
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
 
What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP) What’s & Why’s of Business Continuity Planning (BCP)
What’s & Why’s of Business Continuity Planning (BCP)
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Contingency Planning And Disaster Recovery Planning
Contingency Planning And Disaster Recovery PlanningContingency Planning And Disaster Recovery Planning
Contingency Planning And Disaster Recovery Planning
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
IT Disaster Recovery & Business Continuity
IT Disaster Recovery & Business ContinuityIT Disaster Recovery & Business Continuity
IT Disaster Recovery & Business Continuity
 

Similaire à Best Practices in Disaster Recovery Planning and Testing

Data Centre Strategy Summit 2015 "Are you ready to embark on your Data Cent...
Data Centre Strategy Summit 2015   "Are you ready to embark on your Data Cent...Data Centre Strategy Summit 2015   "Are you ready to embark on your Data Cent...
Data Centre Strategy Summit 2015 "Are you ready to embark on your Data Cent...Gus Sabatino
 
Australian Cloud and Data Centre Strategy Summit 2016 gus sabatino
Australian Cloud and Data Centre Strategy Summit 2016   gus sabatinoAustralian Cloud and Data Centre Strategy Summit 2016   gus sabatino
Australian Cloud and Data Centre Strategy Summit 2016 gus sabatinoGus Sabatino
 
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...William Hendrickson
 
Enabling Resource Management — The Right People for the Right Projects
Enabling Resource Management — The Right People for the Right ProjectsEnabling Resource Management — The Right People for the Right Projects
Enabling Resource Management — The Right People for the Right ProjectsCA Technologies
 
Leveraging Packaged Analytics when Implementing your ERP
Leveraging Packaged Analytics when Implementing your ERPLeveraging Packaged Analytics when Implementing your ERP
Leveraging Packaged Analytics when Implementing your ERPEmtec Inc.
 
Wincere Best Practices
Wincere Best PracticesWincere Best Practices
Wincere Best PracticesWincere
 
18 May 2017 - Vuzion Love Cloud
18 May 2017 - Vuzion Love Cloud18 May 2017 - Vuzion Love Cloud
18 May 2017 - Vuzion Love CloudVuzion
 
Is it Necessary to Document the BCMS plan?
Is it Necessary to Document the BCMS plan?Is it Necessary to Document the BCMS plan?
Is it Necessary to Document the BCMS plan?PECB
 
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...Emtec Inc.
 
Abidance Cip Presentation
Abidance Cip PresentationAbidance Cip Presentation
Abidance Cip Presentationjamesholler
 
Exec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate CertificationExec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate CertificationThomas Bronack
 
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...AppDynamics
 
Monitoring As a Service
Monitoring As a ServiceMonitoring As a Service
Monitoring As a ServiceAmit Panchal
 
Key Metrics for Disaster Recovery and Business Continuity
Key Metrics for Disaster Recovery and Business ContinuityKey Metrics for Disaster Recovery and Business Continuity
Key Metrics for Disaster Recovery and Business ContinuityAxcient
 
Managed Services - Functional & Customization Support Help Desk
Managed Services - Functional & Customization Support Help DeskManaged Services - Functional & Customization Support Help Desk
Managed Services - Functional & Customization Support Help DeskAmit Panchal
 
Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)Anthony Oxley
 
Postgres in Production - Best Practices 2014
Postgres in Production - Best Practices 2014Postgres in Production - Best Practices 2014
Postgres in Production - Best Practices 2014EDB
 

Similaire à Best Practices in Disaster Recovery Planning and Testing (20)

Data Centre Strategy Summit 2015 "Are you ready to embark on your Data Cent...
Data Centre Strategy Summit 2015   "Are you ready to embark on your Data Cent...Data Centre Strategy Summit 2015   "Are you ready to embark on your Data Cent...
Data Centre Strategy Summit 2015 "Are you ready to embark on your Data Cent...
 
Australian Cloud and Data Centre Strategy Summit 2016 gus sabatino
Australian Cloud and Data Centre Strategy Summit 2016   gus sabatinoAustralian Cloud and Data Centre Strategy Summit 2016   gus sabatino
Australian Cloud and Data Centre Strategy Summit 2016 gus sabatino
 
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...
CON8438_Hendrickson-Oracle and Accenture Well Delivery Solution Presentation ...
 
Enabling Resource Management — The Right People for the Right Projects
Enabling Resource Management — The Right People for the Right ProjectsEnabling Resource Management — The Right People for the Right Projects
Enabling Resource Management — The Right People for the Right Projects
 
Leveraging Packaged Analytics when Implementing your ERP
Leveraging Packaged Analytics when Implementing your ERPLeveraging Packaged Analytics when Implementing your ERP
Leveraging Packaged Analytics when Implementing your ERP
 
Ensuring Success in the Cloud (1)
Ensuring Success in the Cloud (1)Ensuring Success in the Cloud (1)
Ensuring Success in the Cloud (1)
 
Wincere Best Practices
Wincere Best PracticesWincere Best Practices
Wincere Best Practices
 
18 May 2017 - Vuzion Love Cloud
18 May 2017 - Vuzion Love Cloud18 May 2017 - Vuzion Love Cloud
18 May 2017 - Vuzion Love Cloud
 
Is it Necessary to Document the BCMS plan?
Is it Necessary to Document the BCMS plan?Is it Necessary to Document the BCMS plan?
Is it Necessary to Document the BCMS plan?
 
Planning
PlanningPlanning
Planning
 
BiznetGio Presentation Business Continuity
BiznetGio Presentation Business ContinuityBiznetGio Presentation Business Continuity
BiznetGio Presentation Business Continuity
 
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...
Collaborate 2014: Humana Case Study - Paradigm Shift in Reporting by Deployin...
 
Abidance Cip Presentation
Abidance Cip PresentationAbidance Cip Presentation
Abidance Cip Presentation
 
Exec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate CertificationExec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate Certification
 
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...
Best Practices for Managing IaaS, PaaS, and Container-Based Deployments - App...
 
Monitoring As a Service
Monitoring As a ServiceMonitoring As a Service
Monitoring As a Service
 
Key Metrics for Disaster Recovery and Business Continuity
Key Metrics for Disaster Recovery and Business ContinuityKey Metrics for Disaster Recovery and Business Continuity
Key Metrics for Disaster Recovery and Business Continuity
 
Managed Services - Functional & Customization Support Help Desk
Managed Services - Functional & Customization Support Help DeskManaged Services - Functional & Customization Support Help Desk
Managed Services - Functional & Customization Support Help Desk
 
Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)
 
Postgres in Production - Best Practices 2014
Postgres in Production - Best Practices 2014Postgres in Production - Best Practices 2014
Postgres in Production - Best Practices 2014
 

Dernier

The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwaitdaisycvs
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPanhandleOilandGas
 
Falcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial WingsFalcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial WingsFalcon Invoice Discounting
 
Buy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From SeosmmearthBuy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From SeosmmearthBuy Verified Binance Account
 
Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030tarushabhavsar
 
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...meghakumariji156
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizharallensay1
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperityhemanthkumar470700
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Falcon Invoice Discounting
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Centuryrwgiffor
 
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165meghakumariji156
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon investment
 
Cannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 UpdatedCannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 UpdatedCannaBusinessPlans
 
Cracking the 'Career Pathing' Slideshare
Cracking the 'Career Pathing' SlideshareCracking the 'Career Pathing' Slideshare
Cracking the 'Career Pathing' SlideshareWorkforce Group
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1kcpayne
 
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...ssuserf63bd7
 
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow ChallengesFalcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow Challengeshemanthkumar470700
 
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSCROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSpanmisemningshen123
 

Dernier (20)

The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pillsMifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation Final
 
Falcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial WingsFalcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial Wings
 
Buy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From SeosmmearthBuy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From Seosmmearth
 
Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030
 
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
 
Buy gmail accounts.pdf buy Old Gmail Accounts
Buy gmail accounts.pdf buy Old Gmail AccountsBuy gmail accounts.pdf buy Old Gmail Accounts
Buy gmail accounts.pdf buy Old Gmail Accounts
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
Cannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 UpdatedCannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 Updated
 
Cracking the 'Career Pathing' Slideshare
Cracking the 'Career Pathing' SlideshareCracking the 'Career Pathing' Slideshare
Cracking the 'Career Pathing' Slideshare
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
 
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow ChallengesFalcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
 
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSCROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
 

Best Practices in Disaster Recovery Planning and Testing

  • 1. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Best Practices in DR Planning and Testing Paul F Kirvan, CISA, FBCI Independent BC/DR Consultant Member of the Board and Secretary The Business Continuity Institute USA Chapter
  • 2. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Agenda 1. Introduction 2. Plan Components 3. Mistakes and Pitfalls to Avoid 4. DR Technology Options 5. Tips for Planning DR Tests 6. Summary 7. Q&A
  • 3. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Why is DR Important? • Accepted way to ensure that critical data, IT systems and networks can be recovered in an emergency • Ensures that corporate business objectives can be achieved, despite a disruption • Increasingly accepted by management as a strategy for keeping the business operational
  • 4. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll Do you currently have a Disaster Recovery plan in place? a. Yes, I have a comprehensive DR plan at my company b. Yes, but needs more work c. No, but would like to get one ready d. No, and have no plans to create one
  • 5. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll Do you currently have a Disaster Recovery plan in place?
  • 6. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. What Do You Need? A good disaster recovery plan needs: • Support from senior management • Funding approved by management • Structured plan framework • Access to qualified staff • Access to relevant information • Documentation and testing
  • 7. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. What’s Your Goal with the Plan? Build disaster recovery plans and associated documentation based on a structured framework that is consistent with good practices and standards.
  • 8. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. DR Plan Activities • Data gathering, interviews, analysis • DR standards and good practice, emergency response procedures, data backup and recovery procedures, system recovery and restart processes, plan templates • Tests to ensure that plan procedures and processes work as designed • Maintenance activities to keep plans up to date and accurate
  • 9. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Standards and Good Practice • Standards – NFPA 1600:2010; ISO 24762:2008; ISO 27031:2011; NIST 800-34 • Regulations – NASD 2510/3520; NYSE 446 • Good Practice – BCI Good Practice Guidelines, FFIEC Handbook • Corporate DR policies
  • 10. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. What You Need to Identify • DR objectives of the systems, networks or other IT assets (e.g., uninterrupted operation, max downtime 4.0 hrs) • Risks and/or threats to the achievement of the DR objectives • Define and document the processes and procedures needed to recover and reactivate the IT assets • Identify preventive measures to mitigate DR risks to an acceptable level
  • 11. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components The following pages list the typical components found in an IT disaster recovery plan. There may be some variations based on your organization’s requirements, but generally the following items should be included.
  • 12. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components A good DR plan usually includes the following components: • Company DR policies • DR plan documents • Business impact analysis reports • Risk assessment reports • Exercise results • IT DR procedures (in the plan) • Supporting documents (e.g., data backup process, off-site storage process, vendor contracts, diagrams, maintenance contracts, training plans)
  • 13. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  If there’s an existing plan, use it as a starting point  Define plan scope, purpose, authority  Define a policy statement  Define management approval and funding  Identify planning and response teams  Identify critical IT resources  Identify risks and their impact on IT assets  Determine recovery time objectives (RTOs)  Determine recovery point objectives (RPOs)
  • 14. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  Preventive controls (e.g., backup power)  Response and recovery strategies  Data backup and recovery methods, compared to existing data storage and retrieval procedures  Potential use of alternate IT sites, e.g., a backup data center, collocated data center, the cloud  Potential use of hot sites, cold sites  Potential use of alternate work (e.g., office) sites, and the technology needs for those sites
  • 15. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  Process for equipment replacement  Process for obtaining spare parts  Staff roles and responsibilities in a disaster  Event notification procedures  Damage assessment procedures  Process and criteria for plan activation  Identify who is authorized to declare a disaster  Recovery / failover procedures  System restart / failback procedures  Resumption of business procedures
  • 16. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  Step-by-step procedures for recovery of  IT operations  Desktop systems  Data  Hardware  Operating systems  Applications  Databases  LANs and WANs  Voice and VoIP systems  Servers
  • 17. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved.  Step-by-step procedures for recovery of  Web sites  Mainframes  Distributed systems  Wireless technology  Specialized systems  Information security  User access  Physical security  Vital records Plan Components
  • 18. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  Step-by-step procedures for  Alerting first responder organizations  Alerting family members  Alerting primary/alternate vendors  Alerting staff, senior management  Alerting clients, stakeholders  Escalating recovery efforts  Help desk support  Using call trees  Activating automated notification systems  Activating conference bridges
  • 19. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components  Links to emergency management and incident response plans, business continuity plans  Process for exercising DR plans  Process for creating a DR awareness program  Process for DR team training  Process for DR training of employees  Process for communicating with the media  Designated company spokesperson
  • 20. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. The next set of slides provides a sample DR plan outline. While most plans will be different, this outline includes the most common plan components and is consistent with standards and good practice. Plan Components
  • 21. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 1 • Revision History • Table of Contents • Emergency Response Actions ‐ Assembly Points ‐ Emergency Call-in Number ‐ Key Personnel Contact Info ‐ Notification Calling Tree ‐ External Contacts ‐ External Contacts Calling Tree
  • 22. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 2 • Policy Statement • Objectives • Plan Overview • Plan Updating • Plan Documentation Storage • Backup Strategies • Emergency Response ‐ Plan Triggering Events ‐ Assembly Points
  • 23. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 3 • Activation of Emergency Management Team • Technology Services Team • Emergency Alert, Escalation and DRP Activation • DR Procedures and Actions ‐ Contact with Employees ‐ Backup Staff ‐ Recorded Messages / Updates ‐ Alternate Recovery Facilities / Hot Site
  • 24. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 4 • Personnel and Family Notification • Communications with Media, Key Stakeholders • Media and Key Stakeholders Contact • Media and Key Stakeholders Team • Rules for Dealing with Media, Key Stakeholders • Insurance Requirements • Financial and Legal Issues ‐ Financial Assessment ‐ Financial Requirements
  • 25. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 5 • Legal Actions • DR Plan Exercising • Appendix A – Technology DR Plans ‐ Production Environment ‐ Private Cloud Environment ‐ Internal IT Environment at HQ ‐ Local Area Network (LAN) ‐ Voice over IP (VoIP) System ‐ Remote Connectivity / VPN
  • 26. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Plan Components DR Plan Outline - 6 • Appendix B – Forms and Reports ‐ Management of DR Activities Forms ‐ Communications and Reporting Form ‐ Disaster Recovery Incident Recording Form ‐ Disaster Recovery Activity Report Form ‐ Mobilizing the Disaster Recovery Team Form ‐ Mobilizing the Business Recovery Team Form ‐ Monitoring Business Recovery Progress Form ‐ Business Process/Function Recovery Form
  • 27. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Mistakes and Pitfalls to Avoid (the not-so-obvious things)
  • 28. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Mistakes and Pitfalls to Avoid  Failure to obtain senior management support  No budget (i.e., no plan)  Lack of upfront research (e.g., risks, RTO/RPO)  Lack of documentation (e.g., assume native knowledge will be available)  No step-by-step procedures (assume you know what to do first, second, who to call, etc.)  No plan testing (e.g., rolling the dice)  No regular plan reviews and updates
  • 29. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Mistakes and Pitfalls to Avoid  No DR team training (nobody knows what to do)  Assume that IT staff knows what to do  Assume that IT staff will be available in an emergency  Assume that backup and recovery procedures will work when needed  Assume that systems and networks will work properly when in backup or recovery mode  Assume that backed-up data will be available when needed
  • 30. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. DR Technology Options
  • 31. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll What technologies are you currently using for Disaster Recovery? a. Local backup to disk or tape b. Cloud backup c. Server replication (either locally or to off-site facility) d. Hybrid technology with local and cloud protection e. Collocation of data center f. Other
  • 32. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll What technologies are you currently using for Disaster Recovery?
  • 33. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. DR Technology Options  Data backup and recovery to an alternate site, e.g., backup data center  Application backup and recovery to an alternate site, e.g., backup data center  Off-site data storage using a third-party firm  Redundant components, e.g., servers, storage devices, network components  Diversely run networks, e.g., alternate service using a different carrier and different paths  System failover / failback technologies to rapidly recover and restart disrupted systems
  • 34. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Current Process New Cloud Options Application backup and recovery to an alternate site or data center Application backup and recovery to the cloud File/data/database backup and recovery to an alternate site / data center File/data/database backup and recovery to the cloud Server backup and recovery via failover to an alternate site / data center Server backup and recovery via failover to the cloud Cloud-based solutions have become very popular as primary and alternate backup and recovery strategies. DR Technology Options
  • 35. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Current Process New Cloud Options Recover the minimum configuration of servers, applications, network resources if it’s necessary to relocate to an alternate office site “Office virtualization”, which has server failover, access to IP addresses and Active Directory in the cloud; this means rapid office recovery and minimum downtime Conduct DR plan tests using a local, on-site environment or alternate backup data center resource Streamline DR tests using a cloud- based and automated DR testing environment Traditional DR activities can be automated and streamlined to encourage more testing and reduce risks from disruptions. DR Technology Options
  • 36. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Tips for Planning DR Tests
  • 37. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll How often do you test your DR plan and/or the ability to recover from a disaster? a. I don’t test b. Once a year c. Two to four times a year d. Every month e. Not as often as I should
  • 38. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Quick Poll How often do you test your DR plan and/or the ability to recover from a disaster?
  • 39. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Tips for Planning DR Tests 1. Decide what you want to test, e.g., data recovery, system failover to a backup site 2. Determine if production systems will be negatively affected during the test 3. Conduct the test in a non-production environment, e.g., R&D 4. Select test participants and alternates 5. Document step-by-step procedures for performing the test 6. Secure a conference room or suitably equipped work area for the test 7. Schedule the test so as not to interfere with production activities
  • 40. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Tips for Planning DR Tests 8. Notify all IT teams and groups of the test at least two weeks in advance 9. Include a scribe / timekeeper 10. (If possible) Conduct a dry run to validate that the test procedures will/should work 11. Complete the test, keeping notes of all actions performed, time needed for each activity 12. Prepare an after-action report summarizing what worked, what didn’t work and lessons learned 13. Update the DR plan based on test results
  • 41. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. Summary  Develop and document a plan .. follow it  Senior management supports the plan  Policies, procedures, metrics  Document, document, document  Test, test, test  Maintenance and regular review
  • 42. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. About Axcient Leader in Recovery-as-a-Service One SaaS Platform Backup Disaster Recovery Business Continuity WAN Optimization Dedupe vs. Rapid Recovery Physical & Virtual Application Continuity Cloud Virtualization True Cloud Platform
  • 43. CONFIDENTIAL – DO NOT DISTRIBUTE. Copyright © 2014 Axcient, Inc. All Rights Reserved. For more information, visit axcient.com or call 800 715.2339 @Axcient linkedin.com/company/axcient axcient.com/facebook Paul Kirvan, CISA, FBCI Phone (908) 902-2586 Email pkirvan@msn.com