final Risk Management Paper for the HealthNet company
DRP and CIRT Plan
6
Executive Summary
In this paper, Disaster Recovery Plan (DRP) and Computer Incident Response Team (CIRT) Plan has implemented on a company called Health Network Inc, which is health service organization. Health Network Inc headquarter is in Minneapolis, Minnesota. And it has two branch locations in Portland, Oregon and Arlington, Virginia. This is big company with more than 600 employees and $500 Million USD business annually.
As this health service organization is big and located in three places, the storage of information related to patients and the organization data must be available in all three location. Since data safety is important and needs to have backup to recover at the time of unexpected disasters. And as sharing data among three locations is important there may be a data breaches, malware attacks and human error will occur to hand these incident organization must have Computer Incident Response Team (CIRT). So, this paper going to cover Disaster Recovery Plan (DRP) and Computer Incident Response Team (CIRT) Plan.
Disaster Recovery Plan (DRP)
A disaster recovery plan (DRP) is to restore business process or system from a disaster. This DRP can be used for wide range of disaster. DRP comes into picture when disasters like hurricanes, tornadoes, floods, earthquakes and fires from any source. DRP can be used to rebuild systems after hardware or software failures. (Gibson, 2015)
To create a good DRP, organization must have a team which will all the information about organizations and its business. With this information team will work to prepare a DRP. As part of DRP, team will check what are the possible disaster that will cause organization shut down and then team will come up with recovery plan. As part of recovery plan, team will consider below all mentioned scenarios to build a best DRP.
This organization is located on Minneapolis, Portland and Arlington. Natural disaster risks in Minneapolis are Tornadoes, floods, hurricanes, earthquakes, landslides, avalanches, volcanoes, tsunamis, Natural disaster risks at Portland are landslides, avalanches, earthquakes, flooding, and Natural disasters at Arlington are flooding, hurricanes and tropical storms, tornadoes, Winter storms (snow and ice). Since all three locations of organization have natural disaster threats, because of this organization must have data backup center in secure place. As data backup procedure suggests at least to have data backups at 2-3 places which will help continuous business running. Though all three locations have threats of natural disasters as per previous record Portland, Oregon has the best weather conditions among three locations.
While planning for backups team must cover three keys aspects, those are Critical Business function (CBF), Maximum acceptable outage (MAO), and Recovery time objectives (RTO). The RTO should be less than or equal to MAO then only system will recover with the acceptable outage time. (Gibson, 2015)
As part of recovery plan having one own data backup center at Portland, Oregon location is a good idea, which helps to keep data secure in organizations premises and control of access. Still, having one data center is always not a good plan, this is the reason going for another backup data center this data should be in a place where natural disasters are less by research team found Helena, Montana has fewer natural disasters. Since the second back up center is as different location the team must work more to have right backup plan or method depends on installation cost and maintenance cost. Depends on the cost either can go far own data center or buy a backup store in cloud.
Whenever there is a change in organization structure the updated network infrastructure documentation should provide to DRP team they will try to identify the most critical business assets and reviewing histories of previous disasters in the organization. With all this knowledge team can do testing of the plan and modify if required. The same team is responsible to maintain and do frequent audits on DRP. When there are changes in organization same team will review again and update the DRP according to new BIA.
Computer Incident Response Team (CIRT)
As business continuity is must, after any disaster or incident the business must look for a way to survive. Every organization must know how to handle incidents as fast as possible. This way business will continue smooth. For this health service organization also, same thing will apply. As this health service organization uses computers to store patient’s data, insurances information and to track appointments, for this work health service companies’ computers also running or must return to its business as fast as possible at the time of disaster incident.
Data breaches are the big catastrophic to the health service companies. Since patient’s information is important and most of the information should confidential. Data breaches or service stop in health service organization is not allowed and it should be fixed as soon as possible. As part of this incident identification and prevention, Computer Incident Response Team (CIRT) comes into action. Depends on where the incident occur concern team will work on that incident. For computer related incidents CIRT will come into action.
“CIRTs can have several different elements. There are no specific requirements stating that certain elements must be included. However, a CIRT commonly includes information on the member- ship of the CIRT and policy information. It may also include details on communications methods and incident response procedures.” (Gibson, 2015)
As mentioned above CIRT includes details of communication methods and incident response procedures. The CIRT members will work on these procedures. IT and security professionals who understand the risks that threaten networks and systems works as CIRT members. These CIRT member will work on the incidents occurred on computer.
There are different teams in CIRT, those are:
Central incident response team: Mostly single team will work on single location preferred as Portland as own data service center located there. But there is possibility they can work on all the three location on Heath Network Inc by having remote control of other two locations or if required this team will fly to the location where incident occurred.
Coordinating team: This team will have good knowledge persons who will provide advice to other teams in case of any incident. If any employee in Health Network Inc have any issue or doubt about the incident, that employee can reach this team and get help or information about that incident.
The CIRT team must have different skilled team personal as mention below.
“An administration team for decision-making: This team will control the data access to the employees depends on which team they are working. In case of unauthorized data transfer creates any catastrophe the need to report to this team. This team will work on that incident and get the business on track.
A team of Info-security: This information security will be responsible for computers security. They will handle IP access and data breach via IP through firewalls. If any incident related firewalls or any data breaches like hacking this team will be responsible for recovery of business and running.
IT Staff: This information technology team is responsible for having right tools and software’s in work computers. If an issue related to work appliances software’s this team will be responsible for fixing it.
An IT Auditor – This team is responsible for conducting frequent audits in organization on timely manner so that company’s network can run smoothly. Any system maintenance issue can be reported to this team.
Security guards for physical damage assessment: Though these days digital locks are available, at least in working hours security guards required for the safety of employees, property, and to monitor cameras. Any property damage can be reported to this team for immediate action.
A lawyer for legal advice: This teams works for keeping company safe from legal issues comes from NDA policies and for making legal documentation for company. Any legal issues will be handled by this team.
A public relations specialist: This team will work on creating nice environment between the employees and customers as well as inside the company. For any escalations for the customer they can reach this team
A financial team: This team works in salary payments to employees and any salary disputes. This will also have deferent group who will work on shopping payments and refunds.
A Human Resource representative: This team is for employees’ support. If employee has any issue with a person or with any team, employee can report here. This is HR team’s responsibility to follow up with concerned team sort out that issue.” (Pramod, 2019)
Implementing CIRT to Health Network Inc:
As part of implementing CIRT, team must follow some procedure as mention below.
Define a computer security incident: Every organization will have their own way of defining an incident. But the end purpose of defining an incident is every employee and every CIRT member should have a clear understanding of that incident.
Include policies in the CIRT plan to guide CIRT members: With the polices included the CIRT members can attack back to the attackers. And also, with these polices the team will have a idea how to investigate the incident and collect the evidences. These policies define how to communicate and safety of the information.
Providing Training: Train the team members so that they can understand the policies and their responsibilities. So that every member of CIRT will know how to respond to different incidents.
Include checklists: This checklist will help CIRT team to follow the defined way in policies. By this they won’t miss any key data.
Subscribe to security notifications: There are different security bulletins CIRT members can sign up for getting different updates on different types of threats. This will help team to have up to date updates on all the incidents.
References
Gibson, Darril. (2015). Managing Risk in Information Systems, 2nd edition. Burlington, MA: Jones & Bartlett.
What Is a Disaster Recovery Plan, p (371-372)
Elements of a CIRT Plan, p 405.