module 4
2
Disaster Recovery Plan
Disaster Recovery Plan
By
Students name
Course Name_ year_ term quarter Rasmussen College
Professor’s Name
Deliverable 4: Disaster Recovery Plan
Introduction
Mandatory
This Disaster Recovery Plan (DRP) captures, in a single repository, all of the information that describes <<Organization’s Name>>’s ability to withstand a disaster as well as the processes that must be followed to achieve disaster recovery.
This section should be completed by all organizations. It helps position the DRP, detailing what is included in the plan and what areas are addressed. Edit this section to suit your organization’s needs, lists and paragraphs should be made relevant to your organization.
Definition of a Disaster
Elective
A disaster can be caused by man or nature and results in <<Organization Name>>’s IT department not being able to perform all or some of their regular roles and responsibilities for a period of time. <<Organization Name>> defines disasters as the following:
· Edit this list to reflect your organization
· One or more vital systems are non-functional
· The building is not available for an extended period of time but all systems are functional within it
· The building is available but all systems are non-functional
· The building and all systems are non functional
The following events can result in a disaster, requiring this Disaster Recovery document to be activated:
· Edit this list to reflect your organization
· Fire
· Flash flood
· Pandemic
· Power Outage
· War
· Theft
· Terrorist Attack
Purpose
Mandatory
The purpose of this DRP document is twofold: first to capture all of the information relevant to the enterprise’s ability to withstand a disaster, and second to document the steps that the enterprise will follow if a disaster occurs.
Note that in the event of a disaster the first priority of <<Organization Name>> is to prevent the loss of life. Before any secondary measures are undertaken, <<Organization Name>> will ensure that all employees, and any other individuals on the organization’s premises, are safe and secure.
After all individuals have been brought to safety, the next goal of <<Organization Name>> will be to enact the steps outlined in this DRP to bring all of the organization’s groups and departments back to business-as-usual as quickly as possible. This includes:
· Edit this list to reflect your organization
· Preventing the loss of the organization’s resources such as hardware, data and physical IT assets
· Minimizing downtime related to IT
· Keeping the business running in the event of a disaster
This DRP document will also detail how this document is to be maintained and tested.
Scope
Mandatory
The <<Organization Name>> DRP takes all of the following areas into consideration:
· Edit this list to reflect your organization
· Network Infrastructure
· Servers Infrastructure
· Telephony System
· Data Storage and Backup Systems
· Data Output Devices
· End-user Computers
· Organizational Software Systems
· Database Systems
· IT Documentation
This DRP does not take into consideration any non-IT, personnel, Human Resources and real estate related disasters. For any disasters that are not addressed in this document, please refer to the business continuity plan created by <<Organization Name>> or contact <<Business Continuity Lead>> at <<Business Continuity Lead Contact Information>>.
Version Information & Changes
Mandatory
Any changes, edits and updates made to the DRP will be recorded in here. It is the responsibility of the Disaster Recovery Lead to ensure that all existing copies of the DRP are up to date. Whenever there is an update to the DRP, <<Organization Name>> requires that the version number be updated to indicate this.
Add rows as required as the DR Plan is amended.
|
Name of Person Making Change |
Role of Person Making Change |
Date of Change |
Version Number |
Notes |
|
John Smith |
DR Lead |
01/01/09 |
1.0 |
Initial version of DR Plan |
|
John Smith |
DR Lead |
01/01/10 |
2.0 |
Revised to include new standby facilities |
|
Fred Jones |
CEO |
01/03/10 |
2.1 |
Replaced John Smith as DR Lead |
|
|
|
|
|
|
|
|
|
|
|
|
Disaster Recovery Teams & Responsibilities
Mandatory
In the event of a disaster, different groups will be required to assist the IT department in their effort to restore normal functionality to the employees of <<Organization Name>>. The different groups and their responsibilities are as follows:
· Edit this list to reflect your organization
· Disaster Recovery Lead(s)
· Disaster Management Team
· Facilities Team
· Network Team
· Server Team
· Applications Team
· Operations Team
· Management Team
· Communications Team
· Finance Team
The lists of roles and responsibilities in this section have been created by <<Organization Name>> and reflect the likely tasks that team members will have to perform. Disaster Recovery Team members will be responsible for performing all of the tasks below. In some disaster situations, Disaster Recovery Team members will be called upon to perform tasks not described in this section.
Please note that the following teams will vary depending on the size of your organization. Some teams/roles may be combined or may be split into more than one team.
Disaster Recovery Lead
Mandatory
The Disaster Recovery Lead is responsible for making all decisions related to the Disaster Recovery efforts. This person’s primary role will be to guide the disaster recovery process and all other individuals involved in the disaster recovery process will report to this person in the event that a disaster occurs at <<Organization Name>>, regardless of their department and existing managers. All efforts will be made to ensure that this person be separate from the rest of the disaster management teams to keep his/her decisions unbiased; the Disaster Recovery Lead will not be a member of other Disaster Recovery groups in <<Organization Name>>.
Role and Responsibilities
· Edit this list to reflect your organization
· Make the determination that a disaster has occurred and trigger the DRP and related processes.
· Initiate the DR Call Tree.
· Be the single point of contact for and oversee all of the DR Teams.
· Organize and chair regular meetings of the DR Team leads throughout the disaster.
· Present to the Management Team on the state of the disaster and the decisions that need to be made.
· Organize, supervise and manage all DRP test and author all DRP updates.
Contact Information
Add or delete rows to reflect the size the Disaster Recovery Team in your organization.
|
Name |
Role/Title |
Work Phone Number |
Home Phone Number |
Mobile Phone Number |
|
John Smith |
Primary Disaster Lead |
111-222-3333 |
111-222-3333 |
111-222-3333 |
|
Fred Jones |
Secondary Disaster Lead |
111-222-3333 |
111-222-3333 |
111-222-3333 |
Disaster Management Team
Elective
The Disaster Management Team that will oversee the entire disaster recovery process. They will be the first team that will need to take action in the event of a disaster. This team will evaluate the disaster and will determine what steps need to be taken to get the organization back to business as usual.
Please note than in a small organization, these roles may be performed by the Disaster Recovery Lead.
Role & Responsibilities
· Edit this list to reflect your organization
· Set the DRP into motion after the Disaster Recovery Lead has declared a disaster
· Determine the magnitude and class of the disaster
· Determine what systems and processes have been affected by the disaster
· Communicate the disaster to the other disaster recovery teams
· Determine what first steps need to be taken by the disaster recovery teams
· Keep the disaster recovery teams on track with pre-determined expectations and goals
· Keep a record of money spent during the disaster recovery process
· Ensure that all decisions made abide by the DRP and policies set by <<Organization Name>>
· Get the secondary site ready to restore business operations
· Ensure that the secondary site is fully functional and secure
· Create a detailed report of all the steps undertaken in the disaster recovery process
· Notify the relevant parties once the disaster is over and normal business functionality has been restored
· After <<Organization Name>> is back to business as usual, this team will be required to summarize any and all costs and will provide a report to the Disaster Recovery Lead summarizing their activities during the disaster
Contact Information
Add or delete rows to reflect the size the Disaster Management Team in your organization.
|
Name |
Role/Title |
Work Phone Number |
Home Phone Number |
Mobile Phone Number |
|
John Smith |
“Normal” title |
111-222-3333 |
111-222-3333 |
111-222-3333 |
|
Fred Jones |
“Normal” title |
111-222-3333 |
111-222-3333 |
111-222-3333 |
Network Team
Mandatory
The Network Team will be responsible for assessing damage specific to any network infrastructure and for provisioning data and voice network connectivity including WAN, LAN, and any telephony connections internally within the enterprise as well as telephony and data connections with the outside world. They will be primarily responsible for providing baseline network functionality and may assist other IT DR Teams as required.
Role & Responsibilities
· Edit this list to reflect your organization
· In the event of a disaster that does not require migration to standby facilities, the team will determine which network services are not functioning at the primary facility
· If multiple network services are impacted, the team will prioritize the recovery of services in the manner and order that has the least business impact.
· If network services are provided by third parties, the team will communicate and co-ordinate with these third parties to ensure recovery of connectivity.
· In the event of a disaster that does require migration to standby facilities the team will ensure that all network services are brought online at the secondary facility
· Once critical systems have been provided with connectivity, employees will be provided with connectivity in the following order:
· All members of the DR Teams
· All C-level and Executive Staff
· All IT employees
· All remaining employees
· Install and implement any tools, hardware, software and systems required in the standby facility
· Install and implement any tools, hardware, software and systems required in the primary facility
· After <<Organization Name>> is back to business as usual, this team will be summarize any and all costs and will provide a report to the Disaster Recovery Lead summarizing their activities during the disaster
Contact Information
Add or delete rows to reflect the size of the Network Team in your organization.
|
Name |
Role/Title |
Work Phone Number |
Home Phone Number |
Mobile Phone Number |
|
John Smith |
Network Manager |
111-222-3333 |
111-222-3333 |
111-222-3333 |
|
Fred Jones |
Network Administrator |
111-222-3333 |
111-222-3333 |
111-222-3333 |
Server Team
Mandatory
The Server Team will be responsible for providing the physical server infrastructure required for the enterprise to run its IT operations and applications in the event of and during a disaster. They will be primarily responsible for providing baseline server functionality and may assist other IT DR Teams as required.
Role & Responsibilities
· Edit this list to reflect your organization
· In the event of a disaster that does not require migration to standby facilities, the team will determine which servers are not functioning at the primary facility
· If multiple servers are impacted, the team will prioritize the recovery of servers in the manner and order that has the least business impact. Recovery will include the following tasks:
· Assess the damage to any servers
· Restart and refresh servers if necessary
· Ensure that secondary servers located in standby facilities are kept up-to-date with system patches
· Ensure that secondary servers located in standby facilities are kept up-to-date with application patches
· Ensure that secondary servers located in standby facilities are kept up-to-date with data copies
· Ensure that the secondary servers located in the standby facility are backed up appropriately
· Ensure that all of the servers in the standby facility abide by <<Organization Name>>’s server policy
· Install and implement any tools, hardware, and systems required in the standby facility
· Install and implement any tools, hardware, and systems required in the primary facility
· After <<Organization Name>> is back to business as usual, this team will be summarize any and all costs and will provide a report to the Disaster Recovery Lead summarizing their activities during the disaster
Contact Information
Add or delete rows to reflect the size of the Server Team in your organization.
|
Name |
Role/Title |
Work Phone Number |
Home Phone Number |
Mobile Phone Number |
|
John Smith |
Operations Manager |
111-222-3333 |
111-222-3333 |
111-222-3333 |
|
Fred Jones |
Systems Administrator |
111-222-3333 |
111-222-3333 |
111-222-3333 |
Applications Team
Mandatory
The Applications Team will be responsible for ensuring that all enterprise applications operates as required to meet business objectives in the event of and during a disaster. They will be primarily responsible for ensuring and validating appropriate application performance and may assist other IT DR Teams as required.
Role & Responsibilities
· Edit this list to reflect your organization
· In the event of a disaster that does not require migration to standby facilities, the team will determine which applications are not functioning at the primary facility
· If multiple applications are impacted, the team will prioritize the recovery of applications in the manner and order that has the least business impact. Recovery will include the following tasks:
· Assess the impact to application processes
· Restart applications as required
· Patch, recode or rewrite applications as required
· Ensure that secondary servers located in standby facilities are kept up-to-date with application patches
· Ensure that secondary servers located in standby facilities are kept up-to-date with data copies
· Install and implement any tools, software and patches required in the standby facility
· Install and implement any tools, software and patches required in the primary facility
· After <<Organization Name>> is back to business as usual, this team will be summarize any and all costs and will provide a report to the Disaster Recovery Lead summarizing their activities during the disaster
Contact Information
Add or delete rows to reflect the size of the Application Team in your organization.
|
Name |
Role/Title |
Work Phone Number |
Home Phone Number |
Mobile Phone Number |
|
John Smith |
Program Manager |
111-222-3333 |
111-222-3333 |
111-222-3333 |
|
Fred Jones |
Systems Administrator |
111-222-3333 |
111-222-3333 |
111-222-3333 |
Operations Team
Mandatory
This team’s primary goal will be to provide employees with the tools they need to perform their roles as quickly and efficiently as possible. They will need to provision all <<Organization Name>> employees in the standby facility and those working from home with the tools that their specific role requires.
Role & Responsibilities
· Edit this list to reflect your organization
· Maintain lists of all essential supplies that will be required in the event of a disaster
· Ensure that these supplies are provisioned appropriately in the event of a disaster
· Ensure sufficient spare computers and laptops are on hand so that work is not significantly disrupted in a disaster
· Ensure that spare computers and laptops have the required software and patches
· Ensure sufficient computer and laptop related supplies such as cables, wireless cards, laptop locks, mice, printers and docking stations are on hand so that work is not significantly disrupted in a disaster
· Ensure that all employees that require access to a computer/laptop and other related supplies are provisioned in an appropriate timeframe
· If insufficient computers/laptops or related supplies are not available the team will prioritize distribution in the manner and order that has the least business impact
· This team will be required to maintain a log of where all of the supplies and equipment were used
· After <<Organization Name>> is back to business as usual, this team will be required to summarize any and all costs and will provide a report to the Disaster Recovery Lead summarizing their activities during the disaster
Contact Information
Add or delete rows to reflect the size of the Operations Team in your organization.
|
Name |
Role/Title |
Work Phone Number |
Home Phone Number |
Mobile Phone Number |
|
John Smith |
Helpdesk Manager |
111-222-3333 |
111-222-3333 |
111-222-3333 |
|
Fred Jones |
Systems Administrator |
111-222-3333 |
111-222-3333 |
111-222-3333 |
Senior Management Team
Mandatory
The Senior Management Team will make any business decisions that are out of scope for the Disaster Recovery Lead. Decisions such as constructing a new data center, relocating the primary site etc. should be make by the Senior Management Team. The Disaster Recovery Lead will ultimately report to this team.
Role & Responsibilities
· Edit this list to reflect your organization
· Ensure that the Disaster Recovery Team Lead is help accountable for his/her role
· Assist the Disaster Recovery Team Lead in his/her role as required
· Make decisions that will impact the company. This can include decisions concerning:
· Rebuilding of the primary facilities
· Rebuilding of data centers
· Significant hardware and software investments and upgrades
· Other financial and business decisions
Contact Information
Add or delete rows to reflect the size of the Management Team in your organization.
|
Name |
Role/Title |
Work Phone Number |
Home Phone Number |
Mobile Phone Number |
|
John Smith |
CEO |
111-222-3333 |
111-222-3333 |
111-222-3333 |
|
Fred Jones |
COO |
111-222-3333 |
111-222-3333 |
111-222-3333 |
Communication Team
Elective
This will be the team responsible for all communication during a disaster. Specifically, they will communicate with <<Organization Name>>’s employees, clients, vendors and suppliers, banks, and even the media if required.
Role & Responsibilities
· Edit this list to reflect your organization
· Communicate the occurrence of a disaster and the impact of that disaster to all <<Organization Name>>‘s employees
· Communicate the occurrence of a disaster and the impact of that disaster to authorities, as required
· Communicate the occurrence of a disaster and the impact of that disaster to all <<Organization Name>>‘s partners
· Communicate the occurrence of a disaster and the impact of that disaster to all <<Organization Name>>‘s clients
· Communicate the occurrence of a disaster and the impact of that disaster to all <<Organization Name>>‘s vendors
· Communicate the occurrence of a disaster and the impact of that disaster to media contacts, as required
· After <<Organization Name>> is back to business as usual, this team will be required to summarize any and all costs and will provide a report to the Disaster Recovery Lead summarizing their activities during the disaster
Contact Information
Add or delete rows to reflect the size of the Communications Team in your organization.
|
Name |
Role/Title |
Work Phone Number |
Home Phone Number |
Mobile Phone Number |
|
John Smith |
VP HR |
111-222-3333 |
111-222-3333 |
111-222-3333 |
|
Fred Jones |
Media Relations |
111-222-3333 |
111-222-3333 |
111-222-3333 |
Disaster Recovery Call Tree
Mandatory
In a disaster recovery or business continuity emergency, time is of the essence so <<Organization Name>> will make use of a Call Tree to ensure that appropriate individuals are contacted in a timely manner.
· The Disaster Recovery Team Lead calls all Level 1 Members (Blue cells)
· Level 1 members call all Level 2 team members over whom they are responsible (Green cells)
· Level 1 members call all Level 3 team members over whom they are directly responsible (Beige cells)
· Level 2 Members call all Level 3 team members over whom they are responsible (Beige cells)
· In the event a team member is unavailable, the initial caller assumes responsibility for subsequent calls (i.e. if a Level 2 team member is inaccessible, the Level 1 team member directly contacts Level 3 team members).
Add as many levels as you need for your organization.
|
Contact |
Office |
Mobile |
Home |
|
|
DR Lead John Smith |
111-222-3333 |
111-222-3333 |
111-222-3333 |
|
|
|
DR Management Team Lead
|
|
|
|
|
|
DR Management Team 1
|
|
|
|
|
|
DR Management Team 2
|
|
|
|
|
|
Network Team Lead
|
|
|
|
|
|
LAN Team Lead
|
|
|
|
|
|
LAN Team 1
|
|
|
|
|
|
WAN Team Lead
|
|
|
|
|
|
WAN Team 1
|
|
|
|
|
|
Server Team Lead
|
|
|
|
|
|
Server Type 1 Team Lead
|
|
|
|
|
|
Server Type 1 Team 1
|
|
|
|
|
|
Server Type 2 Team Lead
|
|
|
|
|
|
Server Type 2 Team 1
|
|
|
|
|
|
Applications Team Lead
|
|
|
|
|
|
App 1 Team Lead
|
|
|
|
|
|
App1 Team 1
|
|
|
|
|
|
App 2 Team Lead
|
|
|
|
|
|
App 2 Team 1
|
|
|
|
|
|
Management Team Lead
|
|
|
|
|
|
Management Team 1
|
|
|
|
|
|
Communications Team Lead
|
|
|
|
|
|
Communications Team 1
|
|
|
|
Data and Backups
Mandatory
This section explains where all of the organization’s data resides as well as where it is backed up to. Use this information to locate and restore data in the event of a disaster.
In this section it is important to explain where the organization’s data resides. Discuss the location of all the organization’s servers, backups and offsite backups and list what information is stored on each of these.
Data in Order of Criticality
Please list all of the data in your organization in order of their criticality. Add or delete rows as needed to the table below.
|
Rank |
Data |
Data Type |
Back-up Frequency |
Backup Location(s) |
|
1 |
<<Data Name or Group>> |
<<Confidential, Public, Personally identifying information>> |
<<Frequency that data is backed up>> |
<<Where data is backed up to>> |
|
2 |
|
|
|
|
|
3 |
|
|
|
|
|
4 |
|
|
|
|
|
5 |
|
|
|
|
|
6 |
|
|
|
|
|
7 |
|
|
|
|
|
8 |
|
|
|
|
|
9 |
|
|
|
|
|
10 |
|
|
|
|
Dealing with a Disaster
Mandatory
If a disaster occurs in <<Organization Name>>, the first priority is to ensure that all employees are safe and accounted for. After this, steps must be taken to mitigate any further damage to the facility and to reduce the impact of the disaster to the organization.
Regardless of the category that the disaster falls into, dealing with a disaster can be broken down into the following steps:
· Edit this list to reflect your organization
1) Disaster identification and declaration
2) DRP activation
3) Communicating the disaster
4) Assessment of current and and prevention of further damage
5) Standby facility activation
6) Establish IT operations
7) Repair and rebuilding of primary facility
Disaster Identification and Declaration
Mandatory
Since it is almost impossible to predict when and how a disaster might occur, <<Organization Name>> must be prepared to find out about disasters from a variety of possible avenues. These can include:
· Edit this list to reflect your organization
· First hand observation
· System Alarms and Network Monitors
· Environmental and Security Alarms in the Primary Facility
· Security staff
· Facilities staff
· End users
· 3rd Party Vendors
· Media reports
Once the Disaster Recovery Lead has determined that a disaster had occurred, s/he must officially declare that the company is in an official state of disaster. It is during this phase that the Disaster Recovery Lead must ensure that anyone that was in the primary facility at the time of the disaster has been accounted for and evacuated to safety according to the company’s Evacuation Policy.
While employees are being brought to safety, the Disaster Recovery Lead will instruct the Communications Team to begin contacting the Authorities and all employees not at the impacted facility that a disaster has occurred.
DRP Activation
Mandatory
Once the Disaster Recovery Lead has formally declared that a disaster has occurred s/he will initiate the activation of the DRP by triggering the Disaster Recovery Call Tree. The following information will be provided in the calls that the Disaster Recovery Lead makes and should be passed during subsequent calls:
· Edit this list as required
· That a disaster has occurred
· The nature of the disaster (if known)
· The initial estimation of the magnitude of the disaster (if known)
· The initial estimation of the impact of the disaster (if known)
· The initial estimation of the expected duration of the disaster (if known)
· Actions that have been taken to this point
· Actions that are to be taken prior to the meeting of Disaster Recovery Team Leads
· Scheduled meeting place for the meeting of Disaster Recovery Team Leads
· Scheduled meeting time for the meeting of Disaster Recovery Team Leads
· Any other pertinent information
If the Disaster Recovery Lead is unavailable to trigger the Disaster Recovery Call Tree, that responsibility shall fall to the Disaster Management Team Lead
Communicating the Disaster
Refer to the “Communicating During a Disaster” section of this document.
Assessment of Current and Prevention of Further Damage
Mandatory
Before any employees from <<Organization Name>> can enter the primary facility after a disaster, appropriate authorities must first ensure that the premises are safe to enter.
The first team that will be allowed to examine the primary facilities once it has been deemed safe to do so will be the Facilities Team. Once the Facilities Team has completed an examination of the building and submitted its report to the Disaster Recovery Lead, the Disaster Management, Networks, Servers, and Operations Teams will be allowed to examine the building. All teams will be required to create an initial report on the damage and provide this to the Disaster Recovery Lead within <<state timeframe>> of the initial disaster.
During each team’s review of their relevant areas, they must assess any areas where further damage can be prevented and take the necessary means to protect <<Organization Name>>’s assets. Any necessary repairs or preventative measures must be taken to protect the facilities; these costs must first be approved by the Disaster Recovery Team Lead.
Restoring IT Functionality
Mandatory
Should a disaster actually occur and <<Organization Name>> need to exercise this plan, this section will be referred to frequently as it will contain all of the information that describes the manner in which <<Organization Names>>’s information system will be recovered.
This section will contain all of the information needed for the organization to get back to its regular functionality after a disaster has occurred. It is important to include all Standard Operating Procedures documents, run-books, network diagrams, software format information etc. in this section.
Current System Architecture
Mandatory
In this section, include a detailed system architecture diagram. Ensure that all of the organization’s systems and their locations are clearly indicated.
<<System Architecture Diagram>>
IT Systems
Mandatory
Please list all of the IT Systems in your organization in order of their criticality. Next, list each system’s components that will need to be brought back online in the event of a disaster. Add or delete rows as needed to the table below.
|
Rank |
IT System |
System Components (In order of importance) |
|
1 |
|
|
|
2 |
|
|
|
3 |
|
|
|
4 |
|
|
|
5 |
|
|
|
6 |
|
|
|
7 |
|
|
|
8 |
|
|
Rasmussen College