BCP Planning
Management
availability
reliability
recoverability
Reasons
response in emergency
save lives
reduce business impact
resume business functions
work with externals
reduce confusion
ensure survivability of business
get up and running asap
Standards
NIST/ISO/BS
Guidelines
1.document policy
2.BIA
3.identify preventive controls
4.recovery strategies
5.contingency plans
6.test plan
7.maintain plan
Types of Plan
business resumption plan
coop
IT contingency
crisis communications
cyber incident response
DR plan
Goals
responsibility
authority
priorities
implementation and testing
Phases
initiation phase
activation phase
recovery
reconstruction
BCP Project
components
coordinator
committee
Scope
policy
component
organisational impact
laws and regulations
good practices
gap analysis
draft policy, review and feedback
approval and publish
project mgt
SWOT and Plan
BIA
Identify threats
risk assessment
value assignment
MTD/MPTD
critical 0h (minutes to hours)
urgent 24h
important 72h
normal 7d
nonessential > 30d
interdependencies
Steps
1. select people to interview
2. create surveys
3. indentify companies critical functions
4. identify resources these functions depend upon
5. calculate ow long functions can survice without resources
6. identify vulnerabilities and threats to these functions
7. calculate risk for each function
8. document findings and report to management
preventive measures
Recovery Strategy
DR Metrics
RPO, RTO, WRT, MTO
Business process recovery
facility recovery
nondisaster <1d, disaster, catastrophe
mtbf, mttr
hot site, warm site, cold site
hot internal site
reciprocal aggreements
redundant sites
outsourcing
insurance
business interruption insurance policy
recovery teams
damage assessment
legal
media relations
relocation
restoration
salvage
security
Technology Recovery
hardware backups
software backups
documentation
HR
databackups
full backups
differential
no reset of archive bit
incremental
longest to restore-add all increments in order
electronic backups
data shadowing
vaulting
remote journaling
replication
synchronous
asynchronous
HA
redundancy
fault tolerance
Testing and Maintenance
testing
checklist
structured walkthrough
simulation test
parallel
full interruption
maintainance
maintain plan