Project Part 4: Business Impact Analysis (BIA) and Business Continuity Plan (BCP)

spy1950
RISKMANAGEMENTPROJECTPART4new.docx

Running head: 1

RISK MANAGEMENT PROJECT PART 4 3

RISK MANAGEMENT PROJECT PART 4

Aditya Chimbalkar

University of the Cumberlands

RISK MANAGEMENT PROJECT PART 4

Task 1

Business impacts analysis (BIA)

The overview

This Business Impact Analysis (BIA) is always developed as a major part of the contingency planning in the process of sorting the company issue for the HNetexcahnge Message system, the HNetconnect Directory system and the HNetpay payment system. This has been made for the health network, Inc. (Health Network)

The system description

The health care network and its operation are divided into three data branches and they are all over the company product line. The data has many servers like 1000 and 350 laptops and that helps to provide the services to the employee called mobile devices. The organization is huge and its headquarters is in Minneapolis and the other two branches are in Portland, Arlington, Virginia and Oregon. Each of the offices has its data center in which the actual production server and its system are operated by the vendors who are the third party (Mohapatra & Sachdeva, 2018).

Its infrastructure has the HNET Exchange server, HNET Pay Payment Database as well as HNET Connect Database Directory. In addition to that, it also has the other where HNET Exchange Server has been termed as the main generator of the company revenue. The services are all secure since they are conducted in the electronic medium and that is done between the customer and the clinic. The HNetpay so the portal that is used for the payments and it is used by the HNetExchange’s customers that helps to facilitate the secure payments

The HNetcoonect is the database that has been given the list of health care practitioners and doctors, the hospitals and the clinics. This helps the customers to be able to locate their specialist or the health care they need just like any other e-commerce websites whereby all customer and service providers can get information and profile, contact information as well as other information that can be required to get proper service (Devlen, 2009). The other operational firewall, as well as the server, are like:

· External Firewall

· Web Server

· Internal Firewall

· Email Server

· Database Server

Business Function or Process

Business

Impact

Factor

Recovery

Time

Objective

(hours/days

IT Systems/Apps

Infrastructure Impacts

Telephonic Customer Service

Level 3

24

System Application

Domain

Email Customer Service

Level 1

5

System Application

Domain

Domain Servers

Level 2

22

LAN to WAN Domain

Email and Messaging Service

Level 2

24

System Application

Domain

Internet and Intranet

Level 2

24

Remote Access Domain

Website

Level 2

24

System Application

Domain

HR resource and Accounts

Level 2

24

LAN Domain

Chat-based Customer Service

Level 2

24

LAN Domain

Technical Support

Level 3

1-2 days

LAN Domain

Accounting and Finance Support

Level 4

24

System Application

Domain

Marketing and Events

Level 4

2-3 days

System Application

Domain

Sales

Level 1

24

System Application

Domain

Communication with another

department

Level 2

24

System Application

Domain

Identify Outage Impacts and Estimated Downtime

The estimated downtime

The table that I will draw below will show the MTD, RPO and the RTO for the entire healthcare processes that depend on the HNetConnect Directory system, HNetExchange Message system and the HNetPay Payment system

Mission/Business Process

For HNetExchange

MTD

RTO

RPO

Telephonic Customer service

48 hours

24 hour

5 hours

Email Customer Service

48 hours

24 hours

4 hours

Mission/Business Process

For HNetConnect

MTD

RTO

RPO

Internet and Intranet

48 hours

24 hours

3 hours

Email and messaging

48 hours

24 hours

4 hours

Mission/Business Process

For HNetPay

MTD

RTO

RPO

Accounting and Finance

Support

48 hours

24 hours

4 hours

Website

48 hours

24 hours

4 hours

Task 2 Business Continuity Plan

Emergency management standards

Data backup policy

This is an activity that needs to be conducted on any organization regularly so that no data is lost. This entails the audit logs as well as the irreplaceable file. This is because they are expensive to replace. The storage media used as a backup should be stored in secure places and a geographically isolated place away from the original data. Health care also needs to have a policy that helps to dictate the data and documents and their retention and for how long that information is to be retained (Savage, 2002). The IT team has the role of backing up data and they follow the following standards when doing backup and archiving.

Tape retention policy.

The backup media is in the store that is secure location and they are always from environmental hazards and they are geographically isolated from the original data or location that housing the system.

Billing tapes.

The tapes that are more than 3 years are in this case destroyed every six months. The tapes that are less than three years old should be stored in another locally off-site.

System image tapes.

This entails the making of a copy of the images and that copy is made once every week. This is also stored off-site and this is done by the system supervisor of the activity.

Task 3- Disaster Recovery Plan

DISASTER RECOVERY PLAN FOR <HNETPAY>

OVERVIEW

PRODUCTION

SERVER

Location: Minneapolis, Portland, Arlington

IT

INFRASTRUCTURE

HNET Connect Directory Database

BACKUP STRATEGY

FOR SYSTEM ONE

DAILY / MONTHLY /

QUARTERLY

Daily

DISASTER

RECOVERY

PROCEDURE

RISK #1: LOSS OF

COMPANY DATA DUE

TO HNETCONNECT

HARDWARE

REMOVED FROM

PRODUCTION

SYSTEMS.

Online services are disrupted, and clients find difficulty in

Viewing and comparing the doctors and clinics. This results

In finding the correct doctor and clinic for superior care.

Regular Backups should be done, and standard access

Control techniques should be followed.

RISK #2: LOSS OF

CUSTOMERS DUE TO

PRODUCTION

OUTAGES.

Supported clinic and the right doctor cannot be allocated to the

customer and maintain DRP in case of the primary server

Collapses.

DISASTER RECOVERY PLAN FOR <HNETEXCHANGE>

OVERVIEW

PRODUCTION SERVER

Location: Portland, Minneapolis, Arlington

IT INFRASTRUCTURE

HNET Exchange Server

BACKUP STRATEGY

FOR SYSTEM ONE

DAILY / MONTHLY /

QUARTERLY

Daily

SYSTEM DISASTER

RECOVERY

PROCEDURE

RISK #1: LOSS OF

COMPANY DATA DUE

TO HNETEXCHANGE

HARDWARE REMOVED

FROM PRODUCTION

SYSTEMS.

Exchange of the information between the customers and

staff members is improper and results in organizations

Revenue. Scheduling regular backups and ACT (Access

Control Techniques) should be implemented

RISK #2: LOSS OF

CUSTOMERS DUE TO

PRODUCTION

OUTAGES.

Supported care cannot be assigned to the customers.

Maintaining an effective DRP and servers can reduce the

Impact.

Task 4: Computer Incident Response Team Plan

Appendix A the incident response worksheet

Preparation: the tools, the applications, the laptops and communications devices that are needed so that to address the computer incidence responses of the different breaches?

Identification: whenever the incident has been reported it needs to be identified, then classified and then documented in this step and this information below is required.

Identify the nature of the incident

What if the organization's process has been most impacted? HNET Connect, HNET pay as well as NET Exchange

What of the threats was identified? Loss of the highly confidential data and information

Which are the risk factors of the incidents? Which are highly crucial

What are the RPO, RTO, and MTD and the assigned process in the business? RTO -4 hours, RPO-3 Hours, MTD12Hours

Containment: the main objective is mainly to limit the scope as well as the magnitude of the security incident as fast as possible rather than allowing the incident to proceed to gain the evidence of identification of the perpetrator.

· Involved the communication that happens between staff and the user

Eradication: removal of the computer-related incidents or the cases of breaches and their effects.

· The data and information can only be access by the authorized user and persons.

Recovery: this step is responsible for bringing back the system and the production of the IT system, the applications as well as the assets that have been affected by the security incident.

· Backup is used to restore the data that was lost

· In this case, if incident business continuity is always implemented

· The plans including the BIA, BCP as well as DRP, they also need to update that so that to reduce the impacts of the incident.

References Mohapatra, S. C., & Sachdeva, P. (2018). Business Impact Analysis (BIA) in Health Sector: The call for the day. Indian Journal of Preventive & Social Medicine, 49(3), 4-4.

Savage, M. (2002). Business continuity planning. Work study.

Devlen, A. (2009). How to build a comprehensive business continuity programme for a healthcare organisation. Journal of business continuity & emergency planning4(1), 47-61.