project*

profilemr.obi
disaster_and_recovery.pptx

Disaster and Recovery

Business Impact Analysis

System Description/Purpose

Impact to business if degradation

Estimated Downtime

Resource Requirements.

Business Contingency Plan

Incident Response Policy

Purpose

Identifying and Reporting Incidents

Mitigation and Containment

Questions?

Overview

Shawn Kirkland

Purpose

Determine mission/business processes and recovery criticality.

Identify resource requirements.

Identify recovery priorities for system resources.

System Description/Purpose

Impact to business if degradation

Estimated Downtime

Resource Requirements.

Business Impact Analysis

Shawn Kirkland

Determine mission/business processes and recovery criticality. Mission/business processes supported by the system are identified and the impact of a system disruption to those processes is determined along with outage impacts and estimated downtime. The downtime should reflect the maximum that an organization can tolerate while still maintaining the mission. 

Identify resource requirements. Realistic recovery efforts require a thorough evaluation of the resources required to resume mission/business processes and related interdependencies as quickly as possible.  Examples of resources that should be identified include facilities, personnel, equipment, software, data files, system components, and vital records.

Identify recovery priorities for system resources. Based upon the results from the previous activities, system resources can more clearly be linked to critical mission/business processes. Priority levels can be established for sequencing recovery activities and resources.

This document is used to build the Dream Landing’s Database Server Information System Contingency Plan (ISCP) and is included as a key component of the ISCP. It also may be used to support the development of other contingency plans associated with the system, including, but not limited to, the Disaster Recovery Plan (DRP) or Cyber Incident Response Plan.

3

Operating System

Microsoft Windows Server 2008 R2

Application

Microsoft SQL Server 2008 Enterprise Edition

Hardware

Dell R720

Location

Server Rack on second floor server room.

Connection

System Administrator connects via local area network.

Other users connect remotely

DR Method

1 Full backup weekly and dailies every day.

3 hours after close of business.

System Description

Shawn Kirkland

The Dream Landing’s database server is comprised of Microsoft SQL Server 2008 Enterprise Edition installed and running on Microsoft Windows Server 2008 R2; this platform is housed on a Dell R720 server-class system. The database server is located in the server rack located on the second floor server room. Local administrators connect directly through the local area network; other users connect indirectly through the web server. Daily snapshot backup operations are conducted every day 3 hours after close of business.

4

Impact

Mission/Business Process Description
Query customer record Database retrieval of customer information (e.g. address, phone, payment information)
Store customer transaction Recording of customer purchases and credits
Authenticate user name and password Stored procedure verifying user credentials

Impact values

Severe = $100,000

Moderate = $50,000

Minimal = $10,000

Mission/Business Process Impact Category
Minimal Moderate High Severe Impact
Query customer record x       Minimal
Store customer transaction       x Severe
Authenticate user name and password   x     Moderate

Jamarcus White

Impact values for assessing category impact:

Severe = $100,000

Moderate = $50,000

Minimal = $10,000

Mission/Business Process

Impact Category

Minimal Moderate High Severe Impact

Query customer record x Minimal

Store customer transaction x Severe

Authenticate user name and password x Moderate

5

Estimated Downtime

Mission/Business Process MTD RTO RPO
Query customer record 48 hours 24 hours 8 hours
Store customer transaction 24 hours 12 hours 4 hours
Authenticate user name and password 36 hours 24 hours 8 hours

MTD

RTO

RPO

Jamarcus White

Maximum Tolerable Downtime (MTD). The MTD represents the total amount of time leaders/managers are willing to accept for a mission/business process outage or disruption and includes all impact considerations. Determining MTD is important because it could leave continuity planners with imprecise direction on (1) selection of an appropriate recovery method, and (2) the depth of detail which will be required when developing recovery procedures, including their scope and content.

Recovery Time Objective (RTO). RTO defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources, supported mission/business processes, and the MTD. Determining the information system resource RTO is important for selecting appropriate technologies that are best suited for meeting the MTD.

Recovery Point Objective (RPO). The RPO represents the point in time, prior to a disruption or system outage, to which mission/business process data must be recovered (given the most recent backup copy of the data) after an outage.

6

Resource Requirements

System Resource/Component Platform/OS/Version (as applicable) Description
Server-class System Dell R720 Rack-mounted system
Windows Server 2008 R2 Host operating system
Microsoft SQL Server 2008 Database management system
Database files Latest, or latest snapshot if needed Binary files containing data

Garrett Grey

System Resource/Component Platform/OS/Version (as applicable) Description

Server-class System Dell R720 Rack-mounted system

Windows Server 2008 R2 Host operating system

Microsoft SQL Server 2008 Database management system

Database files Latest, or latest snapshot if needed Binary files containing data

7

CEO consults department leads to consider time for recovery and determine need for business contingency.

CEO announces business contingency is in effect.

CEO works with local authorities to ensure human safety as needed.

Network managers and technicians move network operations to warm site.

IT managers and technicians assess ability to move existing systems to warm site.

IT managers and technicians requisition new equipment to be delivered to warm site as needed.

Technicians validate warm site's network infrastructure and telecommunications capabilities.

IT managers and technicians install/restore systems at warm site.

Technicians connect systems to warm site network.

Technicians update public domain name records.

Technicians inform customer service representatives of changes to telephone numbers, public IP addresses, etc.

Customer service representatives contact customers with new contact information.

Business Contingency plan

Garrett Grey

Try to summarize this the best you can. Don’t read word for word as that will bore the planet into sleeping. Use the imagination.

8

Purpose

Scope

Definitions

Incident Response Policy

Garrett Grey

Just say “ In the IR Policy we have Purpose, Scope, and Definitions. This slide is just for show really.

9

Purpose

Scope

Definitions

Information Systems

Security Incident

Physical Security

Purpose

Dallas Jones

1.2 Purpose

The purpose of this policy is to outlay protocols and guidelines on how to effectively respond to incidents or events that affects the computers, data, or networks of Dream Land Department of Information Resources.

1.3 Scope

This policy explicitly applies to all departments and individual users of Dream Landing. Users who travel remotely and VPN into the main office shall also adhere to this policy. Any individual who has been issued an electronic or compute device, which includes cell phones, pagers, PDAs, iPads, and Android devices, maintains a fiduciary obligation to this organization. All networking resources, including servers, PCs, switches, routers, firewalls, and additional compute equipment is included within this policy.

1.4 Definitions

Information Systems: is defined as computers/mainframes that are used for collecting, storing processing data and delivering information. The primary operating system used for this information system is Microsoft Operating System (OS). Servers are also defined as information systems because they provide resources to be utilized for employees of Dream Land organization and external users.

Security Incident: is defined as an event in which there is a diversion from the normal security regulations. The unintentional disclosure, compromise of data, an unauthorized activity that disrupts the confidentiality, integrity, and/or the availability of Information systems.

Physical Security: physical protocols put into place to prevent human intrusion into a secure of confidential area. These protocols include key-pads, dead-bolt lock doors, security cameras, and personnel.

10

Employees

IT Technicians

Severity Levels

Level 1

Level 2

Level 3

Level 4

Identifying and Reporting Incidents

Dallas Jones

i. Employees: In the event of a Security incident, including suspicious events, all users must report promptly to the Computer Security Incident Response Team (CSIRT)/IT Technician, and/or company owner for issues relating to but not limited worms, viruses, spyware, malware, denial of service attacks, or other unusual encounters.

ii. IT Technician: The IT Technician must examine and determine if the attack is real and designate a severity level. If the severity is of significant level to alert and seek additional CSIRT support, the IT Technician will do so. The technician may also contact the CERT Coordination Center, which has the most recent information on viruses and worms.

Severity Levels

a) Severity Level One- a security incident that detected on an internal system that can be handled by anti-virus software (AVG)

b) Severity Level Two- small numbers of system probes detected on external systems

c) Severity Level Three- if a penetration or denial of service attempt(s) with limited impact on operations is detected and anti-virus software cannot handle it, this severity should be used because of potential risk to finances and public relation.

d) Severity Level Four- a threat to public safety or life

11

Eradication

Restoration

Log Of Security Incident

Annual Report

Mitigation and Containment

Dallas Jones

Eradication & Restoration

i. Eradication- Once the origins of the problem are identified, all malicious code and corrupting Security incidents are removed. The magnitude of damage must be assessed and a plan of action prepared and communicated to the appropriate parties

ii. Restoration- Once the above protocols are taken care of and upon authorization by the CSIRT/IT Technician and owner, the availability of affected systems, devices and network can be restored.

Documentation

i. Log of Security Incident – CSIRT/IT Technician shall maintain a log of all Security Incidents recording the date, time of recognition, the affected computer or device, a summary of the intrusion and the corrective measure taken to solve the issue.

 

I . Annual Report - CSIRT/IT Technician shall report annually to the CEO providing statistics and summary-level information about significant incidents reported, and provide recommendation to mitigate from known risk.

12

Questions?