Project Part 4: Business Impact Analysis (BIA) and Business Continuity Plan (BCP)
Running head: 1
RISK MANAGEMENT PROJECT PART 4 3
RISK MANAGEMENT PROJECT PART 4
Aditya Chimbalkar
University of the Cumberlands
RISK MANAGEMENT PROJECT PART 4
Task 1
Business impacts analysis (BIA)
The overview
This Business Impact Analysis (BIA) is always developed as a major part of the contingency planning in the process of sorting the company issue for the HNetexcahnge Message system, the HNetconnect Directory system and the HNetpay payment system. This has been made for the health network, Inc. (Health Network)
The system description
The health care network and its operation are divided into three data branches and they are all over the company product line. The data has many servers like 1000 and 350 laptops and that helps to provide the services to the employee called mobile devices. The organization is huge and its headquarters is in Minneapolis and the other two branches are in Portland, Arlington, Virginia and Oregon. Each of the offices has its data center in which the actual production server and its system are operated by the vendors who are the third party (Mohapatra & Sachdeva, 2018).
Its infrastructure has the HNET Exchange server, HNET Pay Payment Database as well as HNET Connect Database Directory. In addition to that, it also has the other where HNET Exchange Server has been termed as the main generator of the company revenue. The services are all secure since they are conducted in the electronic medium and that is done between the customer and the clinic. The HNetpay so the portal that is used for the payments and it is used by the HNetExchange’s customers that helps to facilitate the secure payments
The HNetcoonect is the database that has been given the list of health care practitioners and doctors, the hospitals and the clinics. This helps the customers to be able to locate their specialist or the health care they need just like any other e-commerce websites whereby all customer and service providers can get information and profile, contact information as well as other information that can be required to get proper service (Devlen, 2009). The other operational firewall, as well as the server, are like:
· External Firewall
· Web Server
· Internal Firewall
· Email Server
· Database Server
|
Business Function or Process |
Business Impact Factor |
Recovery Time Objective (hours/days |
IT Systems/Apps Infrastructure Impacts |
|
Telephonic Customer Service |
Level 3 |
24 |
System Application Domain |
|
Email Customer Service |
Level 1 |
5 |
System Application Domain |
|
Domain Servers |
Level 2 |
22 |
LAN to WAN Domain |
|
Email and Messaging Service |
Level 2 |
24 |
System Application Domain |
|
Internet and Intranet |
Level 2 |
24 |
Remote Access Domain |
|
Website |
Level 2 |
24 |
System Application Domain |
|
HR resource and Accounts |
Level 2 |
24 |
LAN Domain |
|
Chat-based Customer Service |
Level 2 |
24 |
LAN Domain |
|
Technical Support |
Level 3 |
1-2 days |
LAN Domain |
|
Accounting and Finance Support |
Level 4 |
24 |
System Application Domain |
|
Marketing and Events |
Level 4 |
2-3 days |
System Application Domain |
|
Sales |
Level 1 |
24 |
System Application Domain |
|
Communication with another department |
Level 2 |
24 |
System Application Domain |
Identify Outage Impacts and Estimated Downtime
The estimated downtime
The table that I will draw below will show the MTD, RPO and the RTO for the entire healthcare processes that depend on the HNetConnect Directory system, HNetExchange Message system and the HNetPay Payment system
|
Mission/Business Process For HNetExchange |
MTD
|
RTO |
RPO |
|
Telephonic Customer service |
48 hours |
24 hour |
5 hours |
|
Email Customer Service |
48 hours |
24 hours |
4 hours |
|
Mission/Business Process For HNetConnect |
MTD
|
RTO |
RPO |
|
Internet and Intranet |
48 hours |
24 hours |
3 hours |
|
Email and messaging |
48 hours |
24 hours |
4 hours |
|
Mission/Business Process For HNetPay |
MTD
|
RTO |
RPO |
|
Accounting and Finance Support |
48 hours |
24 hours |
4 hours |
|
Website |
48 hours |
24 hours |
4 hours |
Task 2 Business Continuity Plan
Emergency management standards
Data backup policy
This is an activity that needs to be conducted on any organization regularly so that no data is lost. This entails the audit logs as well as the irreplaceable file. This is because they are expensive to replace. The storage media used as a backup should be stored in secure places and a geographically isolated place away from the original data. Health care also needs to have a policy that helps to dictate the data and documents and their retention and for how long that information is to be retained (Savage, 2002). The IT team has the role of backing up data and they follow the following standards when doing backup and archiving.
Tape retention policy.
The backup media is in the store that is secure location and they are always from environmental hazards and they are geographically isolated from the original data or location that housing the system.
Billing tapes.
The tapes that are more than 3 years are in this case destroyed every six months. The tapes that are less than three years old should be stored in another locally off-site.
System image tapes.
This entails the making of a copy of the images and that copy is made once every week. This is also stored off-site and this is done by the system supervisor of the activity.
Task 3- Disaster Recovery Plan
DISASTER RECOVERY PLAN FOR <HNETPAY>
|
OVERVIEW |
|
|
PRODUCTION SERVER |
Location: Minneapolis, Portland, Arlington |
|
IT INFRASTRUCTURE |
HNET Connect Directory Database |
|
BACKUP STRATEGY FOR SYSTEM ONE |
|
|
DAILY / MONTHLY / QUARTERLY |
Daily |
|
DISASTER RECOVERY PROCEDURE |
|
|
RISK #1: LOSS OF COMPANY DATA DUE TO HNETCONNECT HARDWARE REMOVED FROM PRODUCTION SYSTEMS. |
Online services are disrupted, and clients find difficulty in Viewing and comparing the doctors and clinics. This results In finding the correct doctor and clinic for superior care. Regular Backups should be done, and standard access Control techniques should be followed. |
|
RISK #2: LOSS OF CUSTOMERS DUE TO PRODUCTION OUTAGES. |
Supported clinic and the right doctor cannot be allocated to the customer and maintain DRP in case of the primary server Collapses. |
DISASTER RECOVERY PLAN FOR <HNETEXCHANGE>
|
OVERVIEW |
|
|
PRODUCTION SERVER |
Location: Portland, Minneapolis, Arlington |
|
IT INFRASTRUCTURE |
HNET Exchange Server |
|
BACKUP STRATEGY FOR SYSTEM ONE |
|
|
DAILY / MONTHLY / QUARTERLY |
Daily |
|
SYSTEM DISASTER RECOVERY PROCEDURE |
|
|
RISK #1: LOSS OF COMPANY DATA DUE TO HNETEXCHANGE HARDWARE REMOVED FROM PRODUCTION SYSTEMS. |
Exchange of the information between the customers and staff members is improper and results in organizations Revenue. Scheduling regular backups and ACT (Access Control Techniques) should be implemented |
|
RISK #2: LOSS OF CUSTOMERS DUE TO PRODUCTION OUTAGES. |
Supported care cannot be assigned to the customers. Maintaining an effective DRP and servers can reduce the Impact. |
Task 4: Computer Incident Response Team Plan
Appendix A the incident response worksheet
Preparation: the tools, the applications, the laptops and communications devices that are needed so that to address the computer incidence responses of the different breaches?
Identification: whenever the incident has been reported it needs to be identified, then classified and then documented in this step and this information below is required.
Identify the nature of the incident
What if the organization's process has been most impacted? HNET Connect, HNET pay as well as NET Exchange
What of the threats was identified? Loss of the highly confidential data and information
Which are the risk factors of the incidents? Which are highly crucial
What are the RPO, RTO, and MTD and the assigned process in the business? RTO -4 hours, RPO-3 Hours, MTD12Hours
Containment: the main objective is mainly to limit the scope as well as the magnitude of the security incident as fast as possible rather than allowing the incident to proceed to gain the evidence of identification of the perpetrator.
· Involved the communication that happens between staff and the user
Eradication: removal of the computer-related incidents or the cases of breaches and their effects.
· The data and information can only be access by the authorized user and persons.
Recovery: this step is responsible for bringing back the system and the production of the IT system, the applications as well as the assets that have been affected by the security incident.
· Backup is used to restore the data that was lost
· In this case, if incident business continuity is always implemented
· The plans including the BIA, BCP as well as DRP, they also need to update that so that to reduce the impacts of the incident.
References Mohapatra, S. C., & Sachdeva, P. (2018). Business Impact Analysis (BIA) in Health Sector: The call for the day. Indian Journal of Preventive & Social Medicine, 49(3), 4-4.
Savage, M. (2002). Business continuity planning. Work study.
Devlen, A. (2009). How to build a comprehensive business continuity programme for a healthcare organisation. Journal of business continuity & emergency planning, 4(1), 47-61.