Business continuity and disaster recovery planning: The basics | CSO Online

 

disaster recovery and business continuity plan

Jan 01,  · Business continuity and disaster recovery (BCDR) are closely related practices that describe an organization's preparation for unforeseen risks to continued operations. Disaster recovery plan. A disaster recovery plan (DRP) is a documented process or set of procedures to execute an organization's disaster recovery processes and recover and protect a business IT infrastructure in the event of a disaster. It is "a comprehensive statement of consistent actions to be taken before, during and after a disaster". Disaster recovery and business continuity planning are processes that help organizations prepare for disruptive events—whether those events might include a hurricane or simply a power outage Author: Derek Slater.


Disaster recovery and business continuity auditing - Wikipedia


Business continuity BC and disaster recovery DR are closely related practices that support an organization's ability to remain operational after an adverse event. As cyber threats increase and the tolerance for downtime decreases, business continuity and disaster recovery gain importance.

These practices enable an organization to get back on its feet after problems occur, reduce the risk of data loss and reputational harm, and improve operations while decreasing the chance of emergencies.

The trend of combining business continuity and disaster recovery into a single term BCDR is the result of a growing recognition that business and technology executives need to collaborate closely when planning for incident responses instead of developing schemes in isolation.

Another developing concern is around compliance. SMBs are also bound by many of the regulatory requirements that are imposed on enterprise-size organizations, so they must meet those same compliance demands. BCDR professionals can help an organization and its employees achieve resiliency.

Developing a strategy is a complex process that requires research, including conducting a business impact analysis BIA and risk analysisas well as developing BCDR plans, tests, exercises and training. You forgot to provide an Email Address.

This email address is already registered. Please login. You have exceeded the maximum character limit. Please provide a Corporate E-mail Address. Please check the box if you want to proceed. Business continuity is more proactive and generally refers to the processes and procedures an organization must implement to ensure that mission-critical functions can continue during and after a disaster.

BC involves more comprehensive planning geared toward long-term challenges to an organization's success. Disaster recovery is more reactive and comprises specific steps an organization must take to resume operations following an incident. Disaster recovery actions take place after the incident, and response times can range from seconds to days.

BC typically focuses on the organization as a whole, whereas DR zeroes in on the technology infrastructure. Disaster recovery is a piece of business continuity planning and concentrates on accessing data easily following a disaster. BC includes this element, but also takes into account risk management and other planning an organization needs to stay afloat during an event. There are similarities between business continuity and disaster recovery.

They both consider various unplanned events, from cyberattacks to human error to a natural disaster. They also have the goal of getting the business running as close to normal as possible, especially concerning mission-critical applications. In many cases, the same team will be involved with both BC and DR within an organization. As cyberthreats increase and the tolerance for downtime decreases, disaster recovery and business continuity plan, business continuity and disaster recovery gain importance.

Developing a strategy is a complex process that requires research and analysis, including conducting a business impact analysis BIA and a risk analysisand developing BCDR plans, tests, exercises and training. Plans also provide information such as employee contact lists, emergency contact lists, vendor lists, instructions for performing tests, disaster recovery and business continuity plan, equipment lists, and technical diagrams of systems and networks. BCDR expert Paul Kirvan notes several other reasons for the importance of business continuity and disaster recovery planning:.

BC and DR plans have updated contact lists, of both employees and external stakeholders, and specific procedures for how to respond to particular situations. Specifically, according to Kirvan, a disaster recovery and business continuity plan continuity plan BCP contains contact information; change management procedures; guidelines on how and when to use the plan; step-by-step procedures; and a schedule for reviewing, testing and updating.

A disaster recovery plan DRP features a summary of key action steps and contact information, the defined responsibilities of the DR team, guidelines for when to use the plan, the DR policy statement, plan goals, incident response and recovery steps, authentication tools, geographical risks and plan history.

Good business continuity and disaster recovery plans are clear about the varying levels of risks to the organization; provide well-defined and actionable steps for resilience and recovery; protect the organization's employees, disaster recovery and business continuity plan, facilities and brand; include a communications plan; and are comprehensive in detailing actions from beginning to end.

A BCDR policy is an important initial step. The policy sets the foundation for the process and typically covers the scope of the business continuity management system, which employees are responsible for it, and the activities performed such as plan development and disaster recovery and business continuity plan impact analysis.

The policy aspect is often overlooked, but it is an important business continuity auditing item. The organization identifies the most critical aspects of the business, and how quickly and to what extent they need to be running after an incident. After the organization writes the step-by-step procedures, the documents should be consistently tested, reviewed and updated, disaster recovery and business continuity plan.

While certain aspects of the process will involve select members disaster recovery and business continuity plan the organization, it's important that everyone understand the plan and is included at some point. A test of the BCDR plan, for example, is a good way to incorporate the entire organization. Determining internal and external risks is important to the business continuity and disaster recovery process. The risk analysis identifies risks and the likelihood they will occur, as well as the potential damage they could cause.

This data is used in conjunction with results of the business impact analysis. The BIA identifies the mission-critical functions an organization must maintain or restore following an incident and the resources needed to support those functions. It's important to gain management support in the undertaking of a BIA, given the intensity of the process. The BIA is a way for an organization to learn about itself and details opportunities for improvement.

An organization uses risk analysis and business impact analysis data to determine disaster recovery and business continuity plan continuity and disaster recovery strategies and the appropriate responses.

Each strategy is turned into a series of actions that will help achieve operational recovery, such as data replication, failing over to a cloud-based service, activating alternate network routes and working remotely. Change management oversees adjustments to systems, networks, infrastructure and documents.

It addresses similar situations as BCDR planning and testing, so an organization may decide to include business continuity and disaster recovery in the change management process. Maintenance is an important element. An organization improves its resilience when it updates its BC and DR plans, and then tests them continually. However, testing requires time, funding, management support and employee participation.

The testing process also includes pretest planning, training test participants and reporting on the test. SearchDisasterRecovery's free, downloadable business continuity testing template assist organizations in their BC planning.

Tests can range from simple to complex. A plan review involves a detailed discussion and examination of the document, with an eye on what's missing or problematic. A tabletop test brings together participants to walk through the disaster recovery and business continuity plan steps, disaster recovery and business continuity plan, also looking for missing information and errors.

A simulation test marks a full run-through of the plan, using backup systems and recovery sites. BCDR is not just for enterprises anymore. Using the cloud -- disaster recovery as a service DRaaS -- makes DR more accessible for smaller organizations. An organization must be careful when selecting its DRaaS provider to ensure it meets its needs. Standards continue to be an emerging trend, with many developed in recent years from such organizations as the International Organization for Standardization ISO and the International Electrotechnical Commission IEC :.

BCDR software also helps an organization build its business continuity and disaster recovery plans, by facilitating business impact analyses or providing plan templates.

Some products have an automated emergency notification feature, while others enable training. Prices range from hundreds of dollars to hundreds of thousands of dollars. Another option is to outsource the organization's BCDR needs to a consulting firm that can provide assessments, disaster recovery and business continuity plan, plan development and maintenance, and training. It's incumbent upon the business to analyze its needs before selecting a BCDR firm, nailing down such information as what it wants to outsource, what services it expects of the vendor, the risks of an outsourcing agreement and how much it plans to spend.

The protection offered by a SaaS provider for your important customer data can be minimal, so it's crucial for organizations to Cloud storage and intelligent storage can help provide DevOps teams with the reliable, fast and flexible storage they require at People are rethinking their cloud storage strategies, adjusting for hidden costs, application needs and compatibility issues in a Provisioning in hyper-convergence is often imbalanced.

Integrating more powerful, higher-capacity nodes with HCI software or Essential Guide Browse Sections. This content is part of the Essential Guide: Disaster recovery strategy guidelines: Preparation and response. This was last updated in January Related Terms business continuity plan BCP A business continuity plan BCP is a document that consists of the critical information an organization needs to continue Login Forgot your password?

Forgot your password? No problem! Submit your e-mail address below. We'll send you an email containing your password. Your password has been sent to:. Please create a username to comment. What overlap does your organization have between its disaster recovery and business continuity? A good resource to refer for beginners. Powered by:. SaaS data backup challenges and best practices The protection offered by a SaaS provider for your important customer data can be minimal, so it's crucial for organizations to Search Storage The secret to reliable storage provisioning for DevOps Cloud storage and intelligent storage can help provide DevOps teams with the reliable, disaster recovery and business continuity plan, fast and flexible storage they require at The secret to reliable storage provisioning for DevOps Disaster recovery and business continuity plan repatriation is a symptom of a wider cloud storage trend People are rethinking their cloud storage strategies, adjusting for hidden costs, application needs and compatibility issues in a Search Converged Infrastructure How to address HCI's resource provisioning challenges Provisioning in hyper-convergence is often imbalanced, disaster recovery and business continuity plan.

 

Business Continuity vs Disaster Recovery: 5 Key Differences

 

disaster recovery and business continuity plan

 

Summarizing the provisions of the O&S Plan, subsections below explain the context in which the Institute’s Business Continuity Plan operates. The Business Continuity Plan complements the strategies for restoring the data processing capabilities normally provided by Operations & Systems. This section addresses three phases of disaster recovery. Jan 01,  · Business continuity and disaster recovery (BCDR) are closely related practices that describe an organization's preparation for unforeseen risks to continued operations. May 03,  · However, each one exists independent of the other. Companies can choose to focus more on one or the other, subscribing to a Business Continuity vs. Disaster Recovery mentality. To be completely prepared, though, having both a Business Continuity plan and a Disaster Recovery plan ensures complete coverage should the unthinkable happen.