project*
Disaster and Recovery
Business Impact Analysis
System Description/Purpose
Impact to business if degradation
Estimated Downtime
Resource Requirements.
Business Contingency Plan
Incident Response Policy
Purpose
Identifying and Reporting Incidents
Mitigation and Containment
Questions?
Overview
Shawn Kirkland
Purpose
Determine mission/business processes and recovery criticality.
Identify resource requirements.
Identify recovery priorities for system resources.
System Description/Purpose
Impact to business if degradation
Estimated Downtime
Resource Requirements.
Business Impact Analysis
Shawn Kirkland
Determine mission/business processes and recovery criticality. Mission/business processes supported by the system are identified and the impact of a system disruption to those processes is determined along with outage impacts and estimated downtime. The downtime should reflect the maximum that an organization can tolerate while still maintaining the mission.
Identify resource requirements. Realistic recovery efforts require a thorough evaluation of the resources required to resume mission/business processes and related interdependencies as quickly as possible. Examples of resources that should be identified include facilities, personnel, equipment, software, data files, system components, and vital records.
Identify recovery priorities for system resources. Based upon the results from the previous activities, system resources can more clearly be linked to critical mission/business processes. Priority levels can be established for sequencing recovery activities and resources.
This document is used to build the Dream Landing’s Database Server Information System Contingency Plan (ISCP) and is included as a key component of the ISCP. It also may be used to support the development of other contingency plans associated with the system, including, but not limited to, the Disaster Recovery Plan (DRP) or Cyber Incident Response Plan.
3
Operating System
Microsoft Windows Server 2008 R2
Application
Microsoft SQL Server 2008 Enterprise Edition
Hardware
Dell R720
Location
Server Rack on second floor server room.
Connection
System Administrator connects via local area network.
Other users connect remotely
DR Method
1 Full backup weekly and dailies every day.
3 hours after close of business.
System Description
Shawn Kirkland
The Dream Landing’s database server is comprised of Microsoft SQL Server 2008 Enterprise Edition installed and running on Microsoft Windows Server 2008 R2; this platform is housed on a Dell R720 server-class system. The database server is located in the server rack located on the second floor server room. Local administrators connect directly through the local area network; other users connect indirectly through the web server. Daily snapshot backup operations are conducted every day 3 hours after close of business.
4
Impact
| Mission/Business Process | Description |
| Query customer record | Database retrieval of customer information (e.g. address, phone, payment information) |
| Store customer transaction | Recording of customer purchases and credits |
| Authenticate user name and password | Stored procedure verifying user credentials |
Impact values
Severe = $100,000
Moderate = $50,000
Minimal = $10,000
| Mission/Business Process | Impact Category | ||||
| Minimal | Moderate | High | Severe | Impact | |
| Query customer record | x | Minimal | |||
| Store customer transaction | x | Severe | |||
| Authenticate user name and password | x | Moderate |
Jamarcus White
Impact values for assessing category impact:
Severe = $100,000
Moderate = $50,000
Minimal = $10,000
Mission/Business Process
Impact Category
Minimal Moderate High Severe Impact
Query customer record x Minimal
Store customer transaction x Severe
Authenticate user name and password x Moderate
5
Estimated Downtime
| Mission/Business Process | MTD | RTO | RPO |
| Query customer record | 48 hours | 24 hours | 8 hours |
| Store customer transaction | 24 hours | 12 hours | 4 hours |
| Authenticate user name and password | 36 hours | 24 hours | 8 hours |
MTD
RTO
RPO
Jamarcus White
Maximum Tolerable Downtime (MTD). The MTD represents the total amount of time leaders/managers are willing to accept for a mission/business process outage or disruption and includes all impact considerations. Determining MTD is important because it could leave continuity planners with imprecise direction on (1) selection of an appropriate recovery method, and (2) the depth of detail which will be required when developing recovery procedures, including their scope and content.
Recovery Time Objective (RTO). RTO defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources, supported mission/business processes, and the MTD. Determining the information system resource RTO is important for selecting appropriate technologies that are best suited for meeting the MTD.
Recovery Point Objective (RPO). The RPO represents the point in time, prior to a disruption or system outage, to which mission/business process data must be recovered (given the most recent backup copy of the data) after an outage.
6
Resource Requirements
| System Resource/Component | Platform/OS/Version (as applicable) | Description |
| Server-class System | Dell R720 | Rack-mounted system |
| Windows Server | 2008 R2 | Host operating system |
| Microsoft SQL Server | 2008 | Database management system |
| Database files | Latest, or latest snapshot if needed | Binary files containing data |
Garrett Grey
System Resource/Component Platform/OS/Version (as applicable) Description
Server-class System Dell R720 Rack-mounted system
Windows Server 2008 R2 Host operating system
Microsoft SQL Server 2008 Database management system
Database files Latest, or latest snapshot if needed Binary files containing data
7
CEO consults department leads to consider time for recovery and determine need for business contingency.
CEO announces business contingency is in effect.
CEO works with local authorities to ensure human safety as needed.
Network managers and technicians move network operations to warm site.
IT managers and technicians assess ability to move existing systems to warm site.
IT managers and technicians requisition new equipment to be delivered to warm site as needed.
Technicians validate warm site's network infrastructure and telecommunications capabilities.
IT managers and technicians install/restore systems at warm site.
Technicians connect systems to warm site network.
Technicians update public domain name records.
Technicians inform customer service representatives of changes to telephone numbers, public IP addresses, etc.
Customer service representatives contact customers with new contact information.
Business Contingency plan
Garrett Grey
Try to summarize this the best you can. Don’t read word for word as that will bore the planet into sleeping. Use the imagination.
8
Purpose
Scope
Definitions
Incident Response Policy
Garrett Grey
Just say “ In the IR Policy we have Purpose, Scope, and Definitions. This slide is just for show really.
9
Purpose
Scope
Definitions
Information Systems
Security Incident
Physical Security
Purpose
Dallas Jones
1.2 Purpose
The purpose of this policy is to outlay protocols and guidelines on how to effectively respond to incidents or events that affects the computers, data, or networks of Dream Land Department of Information Resources.
1.3 Scope
This policy explicitly applies to all departments and individual users of Dream Landing. Users who travel remotely and VPN into the main office shall also adhere to this policy. Any individual who has been issued an electronic or compute device, which includes cell phones, pagers, PDAs, iPads, and Android devices, maintains a fiduciary obligation to this organization. All networking resources, including servers, PCs, switches, routers, firewalls, and additional compute equipment is included within this policy.
1.4 Definitions
Information Systems: is defined as computers/mainframes that are used for collecting, storing processing data and delivering information. The primary operating system used for this information system is Microsoft Operating System (OS). Servers are also defined as information systems because they provide resources to be utilized for employees of Dream Land organization and external users.
Security Incident: is defined as an event in which there is a diversion from the normal security regulations. The unintentional disclosure, compromise of data, an unauthorized activity that disrupts the confidentiality, integrity, and/or the availability of Information systems.
Physical Security: physical protocols put into place to prevent human intrusion into a secure of confidential area. These protocols include key-pads, dead-bolt lock doors, security cameras, and personnel.
10
Employees
IT Technicians
Severity Levels
Level 1
Level 2
Level 3
Level 4
Identifying and Reporting Incidents
Dallas Jones
i. Employees: In the event of a Security incident, including suspicious events, all users must report promptly to the Computer Security Incident Response Team (CSIRT)/IT Technician, and/or company owner for issues relating to but not limited worms, viruses, spyware, malware, denial of service attacks, or other unusual encounters.
ii. IT Technician: The IT Technician must examine and determine if the attack is real and designate a severity level. If the severity is of significant level to alert and seek additional CSIRT support, the IT Technician will do so. The technician may also contact the CERT Coordination Center, which has the most recent information on viruses and worms.
Severity Levels
a) Severity Level One- a security incident that detected on an internal system that can be handled by anti-virus software (AVG)
b) Severity Level Two- small numbers of system probes detected on external systems
c) Severity Level Three- if a penetration or denial of service attempt(s) with limited impact on operations is detected and anti-virus software cannot handle it, this severity should be used because of potential risk to finances and public relation.
d) Severity Level Four- a threat to public safety or life
11
Eradication
Restoration
Log Of Security Incident
Annual Report
Mitigation and Containment
Dallas Jones
Eradication & Restoration
i. Eradication- Once the origins of the problem are identified, all malicious code and corrupting Security incidents are removed. The magnitude of damage must be assessed and a plan of action prepared and communicated to the appropriate parties
ii. Restoration- Once the above protocols are taken care of and upon authorization by the CSIRT/IT Technician and owner, the availability of affected systems, devices and network can be restored.
Documentation
i. Log of Security Incident – CSIRT/IT Technician shall maintain a log of all Security Incidents recording the date, time of recognition, the affected computer or device, a summary of the intrusion and the corrective measure taken to solve the issue.
I . Annual Report - CSIRT/IT Technician shall report annually to the CEO providing statistics and summary-level information about significant incidents reported, and provide recommendation to mitigate from known risk.
12
Questions?